The artificial intelligence boom initially caught corporate boards off guard. Historically not particularly technology-literate, they struggled to define and seize control of the governance challenges bubbling up from below.
By all accounts they have come a long way. “Boards are asking where AI is being used, what risks it introduces, who is accountable, and whether management teams have appropriate oversight and reporting in place,” observes Dylan Sandlin of the National Association of Corporate Directors (NACD).
“As AI implementations have progressed and matured, they are also disclosing AI risks in greater specificity, highlighting particular risks such as cyber threats that could materially affect the business,” says Sandlin, the group’s program manager, digital & cybersecurity content.
In a Wall Street Journal CEO Perspectives piece, Deloitte US Chair Lara Abrash described a higher level of sophistication: “Directors are still focused on controls and compliance. But the conversation is now broader: Can leadership leverage AI to create long-term value? Where could it unlock growth or reshape business models? And does the organization have the governance, talent, and capabilities to scale it responsibly? . . .
Lara Abrash, Deloitte US
“The shift I’ve noticed most: Boards used to start and end the AI conversation with risk. Now they evaluate risk hand-in-hand with strategy and opportunity. A director who once asked, ‘What’s our AI policy?’ is now asking ‘Where will AI reshape our competitive position in three years?’”
At the same time, awareness not only of the technology, but also of the pace of change and disruption, raises additional concerns and calls for new and agile responses.
McKinsey & Co., for one, tracks the rapid scaling of AI, in which larger, well-managed enterprises tend be gaining ground the fastest.
Deloitte, introducing a paper citing its Trustworthy AI Governance Index benchmark of large banks globally, said, “AI governance frameworks are not evolving at the same pace as AI capabilities. Strengthening AI governance is becoming essential to manage risks, meet regulatory expectations and enable responsible AI scaling.”
Compliance advisory firm ACA Group concluded from a recent financial services industry survey, “AI adoption is becoming widespread, but governance maturity is not keeping pace. That gap helps explain why AI governance is becoming a greater focus of supervisory activity.”
Regulators, ACA said, are not waiting for AI-specific rules, but are applying existing governance, risk and compliance frameworks even as the technology rapidly evolves.
AI oversight activities performed by boards, according to a National Association of Corporate Directors 2025 survey (211 respondents).
At the board level, AI governance is being challenged by a significant gap between aggressive operational adoption and formal risk oversight, explains Paul Dongha, co-author of Governing the Machine and head of responsible AI and AI strategy at NatWest Group in the U.K.
In financial services, Dongha says regulatory mandates including the EU AI Act and heightened model risk management (MRM) guidance are forcing elevation of such AI risk specifics into core board responsibilities. The NatWest officer sees a current focus “on upskilling board members, defining explicit risk appetites for AI and establishing clear lines of accountability.”
Paul Dongha
Mature regulatory, risk and governance environments can be put to good use. While many firms work on integrating AI into existing risk processes, says Sandlin, they look to assign clear ownership, maintain human accountability for significant decisions, evaluate third-party providers, and ensure that boards receive meaningful reporting on both business value and risk.
“Financial institutions are not starting from scratch,” notes Ryan Johnson, data privacy, security and AI governance attorney and founder, The Technology Law Group. “They already have established frameworks for model risk, fair lending, privacy, cybersecurity, third-party oversight, operational resilience, and consumer protection. The practical approach is to adapt and connect those frameworks rather than build an entirely separate AI compliance bureaucracy.”
One difficulty is heterogeneity. A generative AI assistant, fraud-detection tool, automated underwriting system, and autonomous software agent each create different exposures. It may require a broader governance model for determining which controls apply, where additional safeguards are necessary, and who is accountable for each use case, Johnson says.
Cybersecurity is becoming inseparable from AI governance. AI introduces additional attack surfaces and related data and intrusion vulnerabilities.
“For boards, the important question is increasingly not just ‘Is this AI system accurate?’, but also ‘Can we trust, secure, monitor, and control it?’” says Ryan Sheridan, director, regulatory intelligence, at Global Relay.
“What is the blast radius of the AI if something goes wrong,” Sheridan goes on, “and do we have kill switches in place to provide off-ramps? As AI becomes more deeply integrated into critical business processes, cyber resilience must be considered throughout the AI lifecycle.”
Then there is the increasingly agentic or autonomous nature of AI models and bots.
NACD’s Sandlin says that recent discussions around rogue AI deceptively evading security safeguards underline the importance of both adopting and supplementing standard frameworks such as those of the National Institute of Standards and Technology (NIST).
Those frontier models bring about a new balance between defense and resilience. Sandlin contends many cyber-risk assumptions and resource-allocation decisions are subject to revision in anticipation of autonomous cyberattacks, advanced vulnerability discovery and exploitation.
Boards should understand how AI systems are secured and that the necessary guardrails ensure that AI and agent behavior aligns with organization values, policies, and regulatory requirements, Sandlin explains. The task extends to identity and access management policies for AI agents, strict data governance policies for AI systems detailing what can and cannot be accessed, how identities and permissions are managed, and preparations for responding when systems are compromised.
Findings from the Trustworthy AI Governance Index, Deloitte said, “suggest that while progress has been made, most banks still have significant room to strengthen their governance frameworks.”
McKinsey offers a Trust Maturity Model (above) across “five dimensions of responsible AI (RAI)”: strategy, risk management, data and technology, governance, and AI agent governance and controls.
Among the emerging risks and challenges: “Security and risk concerns are the top barrier to scaling agentic AI; inaccuracy and cybersecurity remain the most frequently cited AI risks as adoption expands; active mitigation lags behind risk awareness across nearly every AI risk category.”
The strongest programs assign both an executive owner and a business owner. Technology Law Group’s Johnson says accountability thus should not get lost in committees.
Ryan Johnson
While neither the NIST AI Risk Management Framework nor any other single standard will meet all emerging needs, Johnson says they can be combined and managed productively, and organizations with a global footprint should map their higher-risk use cases against privacy, employment, and industry-specific laws.
At a minimum, Johnson advises maintaining a current inventory of AI systems and use cases, classifying them according to potential impact, identifying accountable owners, documenting approved and prohibited uses, and conducting enhanced reviews before deploying higher-risk applications.
In terms of committee structure, as boards transition from reactive and siloed oversight to a more hybrid, forward-looking approach, Dongha says that existing Audit and Risk committees may be supported by a cross-functional Executive AI Governance Committee that includes the CRO, Head of Responsible AI, CISO, and perhaps the General Counsel.
This ensures that daily execution aligns directly with the board-approved AI Risk Appetite Statement, Dongha says. Some firms are also dedicating a Technology Advisory Board to provide deep domain expertise on emerging technical trends.
“Boards are also implementing mandatory reporting dashboards that track high-risk AI deployments, vendor dependencies and incident metrics,” Dongha states. “A governance, risk and compliance platform, which provides a real-time bank-wide view of the landscape of deployed AI models and performance monitoring, is an additional benefit.”
“The most important point is that AI governance should not be viewed simply as a compliance exercise,” Global Relay’s Sheridan says. “For financial institutions, it is fundamentally about trust, accountability, resilience, and managing risk while still enabling innovation.”
Jeffrey Kutler of GARP contributed reporting for this article.