On this page
- What is board AI governance?
- Why AI is a board issue now
- The two failure modes
- The frameworks landscape
- The STAR framework
- Five board responsibilities in an AI era
- The cadence gap
- What the board cannot see
- The engaged and augmented board
- The disclosure mirror
- Twelve questions directors should ask
- Sources and further reading
Most boards are not governing AI. They are receiving updates about it. A sanitized two-page summary arrives in the quarterly board pack, the directors nod, and the company’s most consequential technology shift is treated as a status report rather than a matter of oversight. That gap, between what AI is doing to the business and what the board can show it did about it, is the largest single governance exposure sitting on public and private boards today.
This guide is written for directors, chairs, corporate secretaries, general counsel, and the investors and lawyers who examine board work. It does not tell you how to build AI. It tells you what the board must be able to see, decide, and prove.
What is board AI governance?
Board AI governance is the board-level oversight of how a company creates value with AI and manages the risks that come with it. It is a fiduciary duty, not a technical one. Directors do not need to build models, tune parameters, or write code. They need to be able to verify that management is being competent, realistic, and honest about what AI is doing to the business, and that red flags reach the board in time to act on them.
That definition draws a hard line between two things that are often conflated. Enterprise AI governance is what management does: designing, deploying, monitoring, and controlling AI systems day to day. It is operational. Board AI governance is what directors do: ensuring management is running those systems well, that risks are sized and owned, that capital is allocated with discipline, that disclosure is accurate, and that oversight can be shown, not just described. It is fiduciary. Both are needed. They are not the same job.
Most published AI governance guidance describes the first thing and is assumed to cover the second. It does not. A board does not run an AI risk management program. A board oversees whether management is running one well. That oversight requires a different set of questions, a different rhythm, and a different information architecture. Those are the subject of this guide.
Why AI is a board issue now
AI became a board issue the moment it started breaking the control assumptions directors had treated as stable. In early 2024, criminals used deepfake video and voice to impersonate senior leaders on a live video call and induce a transfer of roughly HK$200 million at Arup’s Hong Kong office. The failure was not in AI strategy. It was in a control design that assumed voice, video, and executive authority could be trusted at face value. When identity itself can be simulated at machine speed, oversight has to do what it did not have to do before.
The market has been arriving at the same conclusion faster than boards. In February 2026, roughly $1 trillion disappeared from global software and services stocks in about a week on the fear that AI agents could dissolve the moats of incumbents including Salesforce, ServiceNow, and Workday. Chegg had already shown the pattern for a single company: closing down about 48 percent in a single session in 2023 after its CEO named generative AI as the reason customers were leaving. The market can now reprice a business model on what it believes AI will do, before the damage shows up in reported results. No regulator has to declare AI material for this to happen.
The legal frame has moved in the same direction. In Delaware, the doctrine runs from In re Caremark through Marchand v. Barnhill: where a risk is mission-critical, board-level information and reporting systems are required. No court has yet decided an AI-specific Caremark claim, and commentators expect the standard to apply where AI is mission-critical. Leo Strine, the former Chief Justice of the Delaware Supreme Court, has put the coming test about as plainly as it can be put: if a company’s AI causes compensable harm, ignorance by the corporation as to how the AI works should be the exact opposite of a defense.
The international pattern points the same way, from UK Companies Act duties to the EU AI Act’s board-level literacy obligations with extraterritorial reach. None of this requires a director to become a technologist. What boards must be able to do is verify that the systems, controls, and people responsible for AI are competent, adequately resourced, and independently reviewed, and that red flags reach the room in time to matter.
The two failure modes
Across board conversations, two failure modes come up again and again, often at the same firm. They are not confined to particular industries or regions. They reflect structural features of how boards engage with AI, or fail to.
The Clueless Board produces value leakage. Directors do not understand enough about AI to set strategic direction or challenge management’s proposals. Investment decisions are approved without serious scrutiny, or deferred indefinitely. Pilots multiply with no scaling criteria. AI-native competitors capture the upside incumbents leave on the table. Invisible in the short term, devastating over a strategic horizon.
The FOMO Board produces value destruction. Directors push for rapid deployment before controls, data, and the operating model are ready. Algorithmic discrimination in hiring. AI outputs that mislead customers. Data breaches from unsanctioned tools. Public claims regulators call into question. Visible, costly, and hard to reverse.
Most organizations are exposed to both at once. The polite term is governance gap. The direct term is flying blind.
“I call it vibe governance. We have a policy, we follow a framework, we train our employees, we bought a tool. It’s reassuring. But who owns the outcome, what controls are in place, and what evidence shows they work?” Nora Denzel, Lead Independent Director at AMD; director at Sony Group, Gen Digital, and NACD
The challenge is not primarily one of awareness. It is one of architecture. The rest of this guide addresses that gap.
The frameworks landscape
Management needs an operational framework for building and running AI: the NIST AI Risk Management Framework, ISO/IEC 42001, the EU AI Act, Singapore’s Model AI Governance Framework, and the NACD Director’s Handbook are the main references. All of them are operational tools for the people who build, deploy, or comply. None of them tells a board what to review, on what cadence, or how to spot a governance gap before it becomes a headline. That is the layer above, and the layer this guide addresses. STAR is that discipline.
The STAR framework
Effective AI governance works like power steering. It lets you move nimbly with directional control. You cannot scale AI across your operations without governance that enables agile, informed decisions about what to approve, what to watch, and what to stop.
STAR is the review discipline. Four pillars, applied every quarter:
- S. Shareholder Value Thesis. Is this initiative creating value worth capturing, and where does the value accrue? Every major AI initiative should have a named business owner, a clear value thesis, milestones, and defined conditions under which it scales, pauses, or stops.
- T. Threat Parity. Do the defenses evolve as fast as the AI-driven threats? Have we stress-tested the business against AI-native competitors and AI-enabled attackers? The board should have a specific, current view of what its most aggressive competitors are doing.
- A. Ability. Does the organization have the talent, data foundation, and process discipline to execute what management is describing? Licences and pilots are not capability. Individual productivity is not enterprise value.
- R. Risk Budget. Have we defined how much AI-related risk this company is willing to accept, in writing? Are high-risk uses inventoried with named owners and monitoring? If an AI system caused a public failure tomorrow, could the board show what it did beforehand?
The two failure modes map cleanly onto STAR. The Clueless Board fails on S and A. The FOMO Board fails on T and R. STAR exists so neither goes undetected quarter to quarter.
STAR treats risk as a portfolio to manage, not a binary switch. The question is not “is AI risky?” It is “can we manage the risks well enough to capture the value?” Good banks do not reject all loans. They price risk correctly and hold appropriate reserves. Good AI governance does not reject all use cases. It assesses the blast radius of each, applies controls sized to the risk, and keeps decision receipts.
The Board AI Readiness Check is a free, anonymous 18-question diagnostic that scores a board across six dimensions: the four STAR pillars plus Ownership and Augmentation. It takes about five minutes, no email required. Full method published.
Five board responsibilities in an AI era
AI does not create new board duties. It changes what the existing ones require. The board’s AI-related work organizes into five responsibilities, each with a governing proposition and a small set of evidence requirements.
1. Purpose, ethics, and compliance
Governing proposition: the board must ensure the ends AI serves remain consistent with why the firm exists. Compliance is what is legal. Ethics is what is responsible. Purpose is what is worth doing. AI widens the distance between all three, and the board must govern them as a hierarchy, not separately.
Evidence to require: accuracy and reliability testing before deployment; bias testing in hiring, lending, and customer-facing uses; documentation practices; explicit human-decision boundaries where outcomes are consequential.
2. Business model and strategy
Governing proposition: the board’s question is not whether AI creates value but where the value accrues and what the firm must control to retain it. AI can reshape the competitive environment itself: lowering barriers, commoditizing incumbent advantages, and compressing the competitive cycle from decades to months.
Evidence to require: a named owner, value thesis, milestones, and stopping rules for every major AI initiative; a defensible view of which incumbent advantages AI is eroding; disclosure of full cost of ownership, including inference.
3. Assets, capabilities, and capital allocation
Governing proposition: a sound AI strategy fails without the assets and discipline to execute it. In AI, the binding constraints are usually organizational, not strategic: data quality, process standardization, technical architecture, and specialist talent.
Evidence to require: which of the three stages management is pursuing (tools, workflows, or orchestration); AI investment concentrated in prime value-creating processes rather than scattered pilots; a clear capability strategy behind build/buy/partner decisions.
4. Risk profile
Governing proposition: AI does not create a separate risk category. It changes the firm’s overall risk profile across strategy, operations, compliance, reputation, cyber, and conduct. Controls must be sized to consequence, not applied uniformly.
Evidence to require: AI use cases classified by risk tier with named owners and monitoring; the AI instruction layer governed with the same rigor as other critical assets; independent assurance on a defined cadence; a documented trail for every high-risk system.
5. Leadership selection, evaluation, and succession
Governing proposition: AI changes what the board looks for in senior executives. The question is not whether the CEO understands the technology. It is whether the team can lead an organization in which judgment, data, automation, and human work are being recombined at speed.
Evidence to require: the ability to redesign workflows rather than just sponsor pilots; a CEO who accelerates the board’s AI literacy rather than sole gatekeeper of translation; succession candidates evaluated against AI-era leadership demands.
The capability response most boards use so far is educational rather than structural. In the Society for Corporate Governance and Deloitte survey (March-April 2026), 77 percent of companies reported management briefings or education sessions for directors, while only 14 percent included AI expertise in director recruitment, 12 percent added AI to the director skills matrix, and 4 percent made AI competence a factor in evaluations. Briefings build fluency in the room. Skills matrices, recruitment criteria, and evaluations are what carry that fluency across director turnover.
The cadence gap
A typical large-company board meets seven or eight times a year. In 2025, S&P 500 boards averaged 7.1 meetings, per the Spencer Stuart Board Index. Those plenary sessions total roughly 48 hours a year. That was defensible when strategy moved in years. It is not defensible now.
Between any two scheduled meetings, frontier labs ship new models, competitors deploy capabilities that did not exist last time, and autonomous agents inside the company take thousands of actions no human individually reviewed. The board calendar is annual. The company is now weekly.
The reporting data confirms the picture. In a February 2026 Society for Corporate Governance and Diligent benchmarking survey, AI-related reporting to boards is most commonly ad hoc or issue-driven (40 percent) or at least quarterly (39 percent); semi-annual (11 percent) and annual (8 percent) are less common; and 16 percent of boards receive no AI-specific information at all.
Concrete case: in April 2025, Shopify’s CEO issued a memo requiring managers to justify new headcount against AI capability first. Days later, Duolingo declared itself “AI-first,” absorbed a backlash, and walked back key elements within weeks. A strategy and its partial reversal, inside a single board interval. Engineers have a name for what happens when you sample below the rate of change. You do not see a slower version of reality. You see a distorted one.
What the board cannot see
The most important finding in the newest survey evidence is not that board use of AI remains limited. It is that the people responsible for governance often cannot tell whether directors are using it.
Evidence · Society for Corporate Governance and Deloitte, March-April 2026
What the board cannot see
- 71 percent of public-company respondents were unsure whether directors had used AI in meeting-related activities over the prior six months.
- 72 percent were unsure whether boards had used it for oversight activities such as risk sensing, strategy, and competitive analysis.
- 51 percent reported no board-specific AI policy, guidance, or governance practices.
- 33 percent reported no specific measures for managing directors’ use of non-approved AI tools.
An activity the governance system cannot see is an activity it cannot govern. This is not primarily an adoption gap. It is an information, policy, and accountability gap.
Provenance: public-company figures from corporate secretaries, in-house counsel, and governance professionals; response counts vary by question. The survey establishes uncertainty, not its cause; do not infer that directors are definitely using personal tools. The private-company sample (14 respondents) is too small for broad inference and is not used here.
The engaged and augmented board
The cadence gap has a fix, and it is not more meetings. It is a different operating model that AI has both made necessary and made affordable at the same time.
The engaged board was proposed as Board 3.0 by Gilson and Gordon in 2019: import the private-equity director model, where board members are “thickly informed, well-resourced, and highly motivated,” to replace public-company directors who are “thinly informed, under-resourced, and boundedly motivated.” The destination was mapped for twenty years. Almost nobody arrived, because the cost of being thickly informed as a part-time outsider was prohibitively expensive. AI has collapsed that cost.
The operating model has three architectures, anchored by the quarterly STAR review. Cadence: a continuous director brief between meetings, plus fewer and deeper plenary sessions when the board convenes. Information: director rights to primary data, plus a board-approved AI research assistant that lets a director test what management’s briefing says. Engagement: named board owners for every material AI initiative and every committee’s AI responsibility written into its charter.
The boundary stays bright. AI can help a director find facts, test assumptions, and frame questions. It cannot exercise fiduciary judgment, cast a vote, or become the reason the board decided as it did. Delaware directors have broad statutory and common-law rights to corporate information, including under DGCL Section 220(d). The augmented board makes those rights usable at contemporary speed, without giving directors management authority they do not have. It reads more. It does not manage more.
The corporate secretary’s role changes in this model. What was custodian of the pack becomes architect of the board’s information system: designing the records discipline, scoping the AI-use protocol for directors, running the continuous brief. The augmented board does not sideline that role. It promotes it.
The full argument, with the cost-curve derivation, the Board 3.0 history, the operating-model design details, and the ten assumptions the episodic board rests on that no longer hold, is in the 48-Hour Board summary and in the SSRN paper.
The disclosure mirror
Sooner or later someone pulls the car over: a large investor, a proxy adviser, an activist, a plaintiff’s lawyer, a reporter. And the market does not wait to be asked; it reprices. Glass Lewis’s 2026 benchmark policy now evaluates board oversight of AI directly and may recommend voting against directors after a material AI-related incident. ISS’s 2026 benchmark carries no equivalent AI provision.
Flip the questions an investor asks about AI oversight, and they are the questions the company must be able to answer, should disclose when material, and a plaintiff’s lawyer may seek in discovery. The board should already be able to answer, in writing:
- Which AI uses are high-risk, and who owns each?
- What is our written risk appetite?
- Which committees have AI in their charters?
- How fast can material AI facts reach the board between meetings, and has that path been tested?
- Is management paid for launching AI, or for the value it produces after the cost of controls and the risk it carries?
Vibe governance fails this mirror. Overclaiming is worse than staying quiet, because it turns a governance gap into a disclosure problem a regulator or plaintiff can use. Denzel’s test: will this hold up when a regulator or a plaintiff’s attorney comes knocking? If the answer is “probably,” you do not have governance. You just have hope.
Twelve questions directors should ask
Twelve questions to bring to your next board meeting. For each, the test is simple: can our board answer this today, with evidence in writing? If not, that is where governance work is most urgently needed.
- Value thesis and capture. What is the one-sentence value thesis for our largest AI initiative, and where does the value accrue if it works?
- Competitive threat. Which of our current competitive advantages is AI most likely to erode, and what is management doing about it?
- Organizational ability. Are our core processes standardized enough for AI to operate reliably, or would we be automating chaos?
- Risk appetite. What is our written AI risk appetite, when was it last reviewed, and who approved it?
- High-risk inventory. Which AI use cases inside the company are high-risk, who owns each, and how are they monitored after launch?
- Human decision points. Where in our consequential AI systems are the human decision checkpoints, and have they been tested?
- Independent assurance. When was the last independent assurance review of our AI governance, and what did it find?
- Committee and initiative ownership. Which committee owns each STAR dimension in writing, and does every major AI initiative have a named board owner?
- Leadership capability. Does our leadership team have the capability to redesign workflows and operating models, not just adopt tools?
- Information rights. What primary data can directors examine directly today, without asking management, and how quickly?
- Between-meeting escalation. How does a material AI change reach the board in days rather than months, and has that path been tested?
- Board AI-use protocol. Do we have a written protocol for how directors themselves use AI, and are directors equipped with an approved tool?
Sources and further reading
Source papers by the author. Power Steering, Not a Brake: How Boards Should Actually Govern AI (de Jong, Maciejko, Samila, Wollersheim, 2026) · The 48-Hour Board: How AI Makes Episodic Governance Obsolete and the Engaged Board Possible (Maciejko, 2026)
Delaware oversight doctrine. In re Caremark International Inc. Derivative Litigation, 698 A.2d 959 (Del. Ch. 1996) · Stone v. Ritter, 911 A.2d 362 (Del. 2006) · Marchand v. Barnhill, 212 A.3d 805 (Del. 2019) · In re Boeing Co. Derivative Litigation (Del. Ch. 2021) · In re McDonald’s Corp. Stockholder Derivative Litigation, 289 A.3d 343 (Del. Ch. 2023).
Board practice evidence used on this page. Deloitte Global Boardroom Program, Governance of AI, 2nd ed., 2025 · EY Center for Board Matters, Cyber and AI Oversight Disclosures, 2025 · Society for Corporate Governance and Deloitte, Board Practices Quarterly: Board Use of AI, March-April 2026 · Society for Corporate Governance and Diligent, Board Oversight of AI benchmarking survey, February 2026 · Spencer Stuart Board Index, 2025.
Governance research foundations. Gilson & Gordon, Board 3.0 (The Business Lawyer, 2019) · Charan, Carey & Useem, Boards That Lead (HBR Press, 2014) · Sonnenfeld, What Makes Great Boards Great (HBR, 2002) · Larcker, Seru, Tayan & Yoler, The Artificially Intelligent Boardroom (Stanford Closer Look, 2025) · Weill et al., Digitally savvy boards (MIT CISR, 2025).
Related insights on this site. The 48-Hour Board summary · The Board’s AI Opportunity · AI’s Boardroom Blind Spot · Don’t Expect Adults in the Room on AI · Who Owns the Frontier Now?