Most boards are not governing AI. They are receiving updates about it. A sanitized two-page summary arrives in the quarterly board pack, the directors nod, and the company's most consequential technology shift is treated as a status report rather than a matter of oversight. That gap, between what AI is doing to the business and what the board actually governs, is the subject of this guide.
Board AI governance is not a technology problem. It is a board, strategy, risk, and fiduciary problem. The companies that get it right will not necessarily have the most sophisticated technology committees. They will ask the right questions, insist on evidence, and hold management accountable. The stance throughout this guide is simple: good governance of AI is power steering, not a brake. It exists to let the company move faster with control, not to slow it down.
This page explains what board AI governance is, why it has become a fiduciary issue, the two ways boards most often fail, and a practical operating model, the STAR framework, that a board can apply quarter after quarter.
What is board AI governance?
Board AI governance is the work directors do to oversee how a company creates and protects value with artificial intelligence, and to ensure that the risks are understood, owned, and managed. It is distinct from enterprise or operational AI governance, which is management's job.
The distinction matters. Management builds, buys, and deploys AI. It writes the model policies, runs the controls, and owns the day-to-day. The board does not do any of that, and should not try to. The board's job is oversight: setting expectations, requiring the right information, testing whether management's approach is sound, and intervening when it is not. When directors confuse the two, they either drift into management's lane or, more commonly, abdicate oversight entirely on the grounds that AI is "too technical." Neither serves shareholders.
Put plainly: enterprise AI governance asks "how do we run AI well?" Board AI governance asks "how do we know management is running AI well, and what do we do if it isn't?"
Why AI is now a fiduciary issue
For most of the last decade, AI sat comfortably in the realm of the chief technology officer. That era is over, and the numbers show it.
Two-thirds of directors say their boards do not know enough about AI (EY, 2025).1 Only about a quarter discuss it at every board meeting (Protiviti/BoardProspects, 2026),2 and roughly the same share have formally added AI governance to a committee charter (NACD, 2025).3 Meanwhile, the share of large-cap public companies disclosing AI as a material risk jumped from 12 percent in 2023 to 83 percent in 2025, even as only 23 percent of directors describe themselves as fluent in it (Conference Board, 2026).4 The fluency gap is now embedded in SEC filings.
The legal floor is rising underneath all of this. Under Delaware's Caremark standard,5 boards have a fiduciary duty to implement and monitor reporting systems for mission-critical risks, and to respond to the red flags those systems surface. As AI becomes central to how companies make money and where they can cause harm, it becomes exactly such a risk. As former Delaware Chief Justice Leo Strine has written, a corporation's ignorance of how its own AI works should be the opposite of a defense.6 The EU AI Act, which reaches any company whose AI touches the EU market, sharpens the point further, and the United States provides no comprehensive federal framework, which makes board-level governance not optional but the primary line of defense.
The conclusion is uncomfortable but clear. A board that treats AI as a technology briefing rather than an oversight obligation is exposed, legally and competitively.
The two failure modes: the clueless board and the FOMO board
In advising boards and CEOs across industries, two recurring failure patterns show up worldwide.
The clueless board has never seriously discussed AI. It delegates everything to the chief technology officer and receives a sanitized update once a quarter. Investment decisions get waved through without scrutiny or deferred indefinitely. The result is value leakage: scattered experimentation, incoherent investment, and competitors capturing the value the company leaves on the table. The damage is often invisible in the short term, which is precisely what makes it dangerous.
The FOMO board does the opposite. It chases every AI opportunity because competitors are moving, pushing for rapid deployment before controls, data infrastructure, and the operating model are ready. The result is value destruction: algorithmic discrimination, misleading AI claims, data breaches from unapproved tools, and regulatory action. Unlike the clueless board's quiet erosion, the FOMO board's failures generate headlines and lawsuits.
Most boards are some blend of the two: moving too slowly to capture value and too carelessly to manage risk. Both patterns raise Caremark concerns. The clueless board fails the duty to implement a reporting system. The FOMO board fails the duty to monitor the system once it exists.
A useful term for the comfortable middle is "vibe governance," a phrase coined by Nora Denzel, lead independent director of AMD and a director of Sony Group and the NACD: a board has a policy, follows a framework, trained its employees, and bought a tool, and it feels reassuring. But who owns the outcome, what controls are in place, and what evidence shows they work?
The STAR framework for board AI governance
Boards cannot review every AI question from scratch at every meeting. They need a small set of recurring questions that cut across the board's responsibilities and can be applied consistently, quarter after quarter. The STAR framework is built for that purpose.
S: Shareholder Value Thesis. Where exactly will AI create or destroy value, who is responsible for the outcome, and under what conditions do we stop or scale back? AI investment should face the same discipline as any other capital allocation decision.
T: Threat Parity. Are our defenses evolving as fast as AI-powered threats? Deepfake fraud, automated vulnerability exploitation, and attacks aimed at AI systems themselves are no longer rare. If the board has not asked whether security governance keeps pace with the threat environment, the company is exposed.
A: Ability. Can we actually execute? Do we have the data quality, process readiness, and talent to move beyond pilots? Too many organizations buy licenses, run pilots, and declare victory. Real adoption means AI embedded in redesigned workflows, not bolted onto broken processes.
R: Risk Budget. Have we explicitly defined where AI risk is acceptable, where it is not, and who is accountable when something goes wrong? The best-governed organizations treat AI risk like a portfolio: explicit green, yellow, and red lanes, clear no-go zones, and a named executive accountable for every high-impact system.
The two failure modes map directly onto STAR. The clueless board is a failure of S and A: no value thesis, no honest assessment of readiness. The FOMO board is a failure of T and R: deployment without controls, no risk tiers, no one accountable. Run consistently, STAR ensures neither goes undetected.
The key insight is that STAR treats risk as a portfolio to manage, not a danger to eliminate. The question is not "is AI risky?" but "can we manage its risks well enough to capture the value?" Think of it like credit risk in banking. Good banks do not reject all loans. They price risk correctly and hold appropriate reserves. Good AI governance does not reject all use cases. It assesses the dangers, applies proportionate controls, and keeps decision receipts.
| STAR question | Board owner | Quarterly metric | Escalation trigger |
|---|---|---|---|
| S · Shareholder Value Thesis | Strategy or full board | Where AI is creating measurable value, and where spending is rising without results. | Spending rises but impact stays flat. |
| T · Threat Parity | Risk committee | How well controls keep pace with AI-powered threats, and where unauthorized AI use is appearing inside the company. | A high-risk system shows a control gap. |
| A · Ability | Audit, Human Capital, full board | Data quality, talent, and depth of adoption beyond pilots. | Rollouts stall or pilots fail to scale. |
| R · Risk Budget | Risk committee | Which AI use cases the board has approved, where overrides are happening, and any incidents. | AI deployed in a use case the board placed off limits. |
Five board responsibilities, none of them new
AI governance does not require inventing new board duties. It requires applying established duties under changed conditions. Drawing on the UK Corporate Governance Code, the G20/OECD Principles, and US governance doctrine, the board's AI-related work organizes into five responsibilities:
- Purpose, ethics, and compliance
- Business model and strategy
- Assets, capabilities, and capital allocation
- Risk profile
- Leadership selection, evaluation, and succession
Purpose, ethics, and compliance belong together because AI uniquely widens the gap between what is legal, what is operationally feasible, and what is consistent with the firm's stated purpose. Assets and capabilities sit apart from strategy because in AI, execution constraints, data quality, process standardization, and talent, are often decisive even when the strategic direction is sound.
Committee ownership: distribute, do not concentrate
The instinct to create a single new AI committee is usually a mistake. AI touches strategy, risk, disclosure, and people, and concentrating it in one place isolates it from the committees that already own those domains. The better approach is to distribute AI governance across the existing committee structure:
- Risk committee: controls, risk appetite, and the AI risk budget.
- Audit committee: assurance and the accuracy of AI-related disclosure.
- Human capital / compensation committee: workforce impact and leadership readiness.
- Strategy or full board: the shareholder value thesis and major capital allocation.
The full board retains accountability. Committees do the detailed work and escalate.
Metrics and escalation triggers
A framework is only useful if someone reports against it and the board knows when to act. Each STAR question maps to a few quarterly indicators with clear escalation rules. Few boards receive this kind of reporting today, but the ones that govern AI well will demand it.
- Shareholder Value Thesis: where AI is creating measurable value, where it is not, and where spending is rising without results. Escalate when spending rises but impact stays flat.
- Threat Parity: how well controls keep pace with AI-powered threats, and where unauthorized AI use is appearing inside the company. Escalate when a high-risk system shows a control gap.
- Ability: whether the organization can actually execute, including data quality, talent, and depth of adoption. Escalate when rollouts stall.
- Risk Budget: which AI use cases the board has approved, where overrides are happening, and any incidents. Escalate when AI is deployed in a use case the board placed off limits.
Questions directors should ask
A board does not need to become technical. It needs to ask demanding questions and insist on evidence. A starting set:
- How does this company use AI to make money, specifically?
- Where would AI failure hurt us most, and who owns that risk?
- What AI is running in the business today that the board has never reviewed?
- Do our defenses evolve as fast as AI-powered threats against us?
- Can we actually execute, or are we mistaking pilots for adoption?
- Have we defined where AI risk is acceptable and where it is not?
- Who is the named, accountable executive for each high-impact AI system?
- Does our AI-related public disclosure match what is actually happening inside the company?
- What evidence, not assurances, shows our controls work?
- If we designed this board today, for this company, at this speed, would we design the board we have?
Governance is power steering, not a brake
Boards that treat AI purely as a compliance exercise risk watching their companies become irrelevant. The real competitive threat is not that AI will go wrong. It is that competitors will get AI right faster. The board's job is to equip the company to move as quickly as possible, with guardrails that enable speed rather than prevent it.
Some boards freeze because they feel they do not know enough to push back on management. Others wave AI initiatives through because no one wants to be the person who slowed things down. Both are failures of governance, and both destroy value. The boards that govern AI well move from principles to proof. Power steering, not a brake.
Board AI governance FAQ
What is board AI governance?
It is the oversight directors provide over how a company creates value with AI and manages the associated risks. It is distinct from enterprise AI governance, which is management's responsibility for building and running AI.
How is board AI governance different from enterprise AI governance?
Management runs AI; the board oversees that it is being run well. Enterprise AI governance is operational. Board AI governance is fiduciary.
Is AI governance a fiduciary duty?
Increasingly, yes. Under the Caremark standard, boards must maintain reporting systems for mission-critical risks and respond to red flags. As AI becomes central to how companies make money and where they can cause harm, board oversight of it falls within that duty.
Do we need a separate AI committee?
Usually not. Distributing AI governance across the existing risk, audit, human capital, and strategy committees is more effective than isolating it in a new one, with the full board retaining accountability.
How often should the board review AI?
The STAR questions are designed to be applied every quarter, with defined escalation triggers so urgent issues do not wait for the next scheduled meeting.
What is the STAR framework?
STAR is a recurring set of four board-level questions: Shareholder Value Thesis, Threat Parity, Ability, and Risk Budget. It gives the board a consistent way to oversee AI quarter after quarter.
Sources and further reading
- EY Center for Board Matters, Board priorities for 2025: how AI is reshaping governance, 2025.
- Protiviti and BoardProspects, Board priorities survey: AI and risk oversight, 2026.
- National Association of Corporate Directors (NACD), 2025 Board Practices Report, 2025.
- The Conference Board, AI risk disclosure trends in S&P 500 filings, 2026.
- In re Caremark International Inc. Derivative Litigation, 698 A.2d 959 (Del. Ch. 1996), and the line of Delaware authority following it (Marchand, Boeing).
- Leo E. Strine Jr., commentary on board oversight of mission-critical risks, Harvard Law School Forum on Corporate Governance.
- EU AI Act (Regulation 2024/1689), official text and implementation timeline.
- OECD AI Principles, benchmark for board-level risk framing across OECD member states.
- NIST AI Risk Management Framework, US-government reference for AI risk controls boards can reasonably expect management to adopt.
- Robert Maciejko et al., Power Steering, Not a Brake: How Boards Should Actually Govern AI, SSRN, 2026, co-authored with IESE Business School and Egon Zehnder.
- Robert Maciejko, The 48-Hour Board: How AI Makes Episodic Governance Obsolete and the Engaged Board Possible, SSRN, 2026.
Go deeper
- Take the free, anonymous Board AI Readiness Check to see where your board stands.
- Read the underlying research: "Power Steering, Not a Brake: How Boards Should Actually Govern AI" on SSRN, with the practitioner summaries on Egon Zehnder and the Columbia Law School Blue Sky Blog.
- Bring a STAR review to your board: request a board session, or discuss a custom engagement.
Robert Maciejko is the founder of the Board AI Institute and co-founder of the INSEAD AI community. He created the STAR framework for board AI governance and advises boards, chairs, and CEOs.