Almost every company now runs on AI in some form. Far fewer boards can say they govern it. In 2025, 88% of organizations used AI, with generative AI live in at least one business function at 70% (Stanford HAI, 2026 AI Index). Yet only 26% of boards discuss AI at every meeting (Protiviti & BoardProspects), and just 35% of directors say their boards have actually incorporated AI into their oversight role, as reported by the Harvard Law School Forum on Corporate Governance, citing the PwC 2025 Annual Corporate Directors Survey (corpgov.law.harvard.edu).

That gap is the story of 2026. The technology is already inside the business; the governance is still catching up. In the boardrooms we sit in, the questions have shifted from "should we be doing AI" to four sharper ones that directors now ask out loud. Here is how we answer them, and which answers survive contact with a running system.

Question 1What is our actual AI exposure?

This is the question that should be asked first, and usually is not. The honest answer in 2026 is that exposure is rising on every measure that matters. Reported AI incidents hit a record, climbing to 233 in 2024, up 56.4% over the prior year, and then to 362 in 2025 (Stanford HAI AI Index, AI Incident Database). The curve is going the wrong way precisely because adoption is going the right way.

The reliability picture underneath those incidents is sobering. Across 26 leading models, measured hallucination rates range from 22% to 94% (Stanford HAI, 2026 AI Index). A board cannot treat model output as fact when, depending on the model and the task, anywhere from a fifth to nearly all of it can be wrong. And leaders know where the soft spots are: they name inaccuracy (64%), regulatory compliance (63%), and cybersecurity (60%) as their top responsible-AI concerns, while not all of them are taking active steps to address those risks, as reported by Stanford HAI, citing a McKinsey survey (2025 AI Index).

Exposure is not a slide. It is the list of systems where a wrong answer reaches a customer, a regulator, or a balance sheet before a human sees it.

The answer that holds up: stop treating exposure as a category and start treating it as an inventory. Where does AI touch a decision, a customer, or a control? Which of those paths has a human in the loop, and which does not? That map, kept current, is the difference between a board that oversees AI and one that merely hears about it. We would push it one step further: rank each path by what a wrong answer actually costs, then govern the top of that list first. Most organizations have a handful of high-consequence AI surfaces and a long tail of low-stakes ones, and treating them as equal is how boards end up policing the harmless and ignoring the dangerous.

Question 2Are we compliant, and what is coming?

The regulatory ground has stopped being theoretical. The EU AI Act entered into force on August 1, 2024, with obligations phasing in on a fixed schedule: prohibited practices and AI-literacy duties from February 2, 2025; general-purpose AI model obligations from August 2, 2025; most provisions, including the general high-risk rules, from August 2, 2026; certain high-risk areas from December 2, 2027; and high-risk systems embedded in regulated products from August 2, 2028 (European Commission). The August 2, 2026 milestone is the one most boards are underestimating, because it is the closest.

The penalties are not symbolic. Under Article 99 of the Act (Regulation (EU) 2024/1689), the maximum fine for prohibited practices reaches up to EUR 35,000,000 or 7% of total worldwide annual turnover, whichever is higher (EU AI Act, Article 99). That is a turnover-based exposure on par with the heaviest regimes a board already knows.

For a credible framework that travels across jurisdictions, the NIST AI Risk Management Framework, released January 26, 2023, is the reference point we default to. It is voluntary, and built on four functions, Govern, Map, Measure, and Manage, that map cleanly onto how a board already thinks about risk (NIST). And enforcement is no longer hypothetical in the US either: the SEC brought its first AI-washing actions on March 18, 2024, settling with Delphia (USA) Inc. and Global Predictions Inc. over false or misleading AI claims, for a combined $400,000 in penalties (SEC press release 2024-36). The lesson there is blunt: what you say about your AI in public is now a compliance surface, not just a marketing one.

Question 3Where is the ROI, and who owns it?

Adoption without governance does not just create risk; it leaves money on the table. The capability that is supposed to drive the next wave of return, agentic AI, is largely ungoverned: only 21% of organizations report a mature model for agentic-AI governance, which means roughly four in five are scaling autonomous systems without the controls to match (Deloitte, State of AI in the Enterprise 2026).

Here is the part boards should sit up for: governance and return move together. Among high-AI-ROI organizations, 63% discuss AI at every board meeting, versus just 13% of low-ROI organizations (Protiviti & BoardProspects). The boards that pay attention are also the boards that get paid. Attention is not a tax on returns; it is a leading indicator of them.

The answer that holds up: name an owner. ROI that belongs to everyone belongs to no one. Someone in the leadership team should own the AI portfolio the way a CFO owns capital allocation, with the board reviewing it on that cadence. Ownership is what turns a pile of pilots into a portfolio with a return.

Question 4Are we even equipped to oversee this?

This is the most uncomfortable question, and the most important. The candid answer is that boards are improving fast but starting from behind. 66% of boards report limited to no AI knowledge or experience, down from 79%, and the share saying AI is not even on the board agenda fell to 31% from 45% (Deloitte Global Boardroom Program, Governance of AI). Real progress, but two-thirds of boards still concede they lack the fluency to challenge what management brings them.

The structural response is already underway. More than 62% of directors now set aside full-board agenda time for AI (NACD, 2025 Public Company Board Practices & Oversight Survey). And the policy scaffolding is finally being built: the share of businesses with no responsible-AI policy fell from 24% to 11% (Stanford HAI, 2026 AI Index). Boards are clearing the time and the organizations beneath them are writing the rules. What is often missing is the bridge between the two: the fluency to know whether those policies are real or decorative.

What good oversight looks like

The practical playbook is not exotic. NACD recommends boards embed AI into oversight by revising committee charters, clarifying responsibilities, and adopting clear metrics (NACD). Charters that say who owns AI risk. Responsibilities that do not evaporate between the audit and technology committees. Metrics that let a director tell, at a glance, whether the AI portfolio is compounding value or accumulating exposure.

The harder part is judgment, and judgment comes from operating. We build and run the AI systems we advise on, so when a board asks whether an answer holds up, we are not reasoning from a framework deck. We are reasoning from systems that have already met production, with the incidents, the controls, and the audit trails that come with it. That is the difference between an oversight answer that sounds right in the room and one that survives the quarter after.

Bring the operator into the boardroom.

If your board is asking these questions and wants answers grounded in systems that actually run, that is the conversation we have. No pitch, just an executive read of where your AI oversight stands and what to do next.

Get in touch

Sources

  1. Deloitte Global Boardroom Program, "Governance of AI." deloitte.com
  2. NACD, 2025 Public Company Board Practices & Oversight Survey. nacdonline.org
  3. Protiviti & BoardProspects, Global Board Governance Survey. protiviti.com
  4. PwC 2025 Annual Corporate Directors Survey, as reported by the Harvard Law School Forum on Corporate Governance. corpgov.law.harvard.edu
  5. Deloitte, State of AI in the Enterprise 2026. deloitte.com
  6. Stanford HAI, 2026 AI Index Report (Responsible AI). hai.stanford.edu
  7. European Commission, Regulatory framework for AI (EU AI Act timeline). digital-strategy.ec.europa.eu
  8. EU AI Act, Article 99 (Regulation (EU) 2024/1689), penalties. artificialintelligenceact.eu
  9. NIST, AI Risk Management Framework. nist.gov
  10. SEC, press release 2024-36 (first AI-washing enforcement actions). sec.gov
  11. Stanford HAI, 2025 AI Index Report (Responsible AI), citing a McKinsey survey. hai.stanford.edu
  12. Stanford HAI, 2026 AI Index Report (Economy). hai.stanford.edu
  13. NACD report on board priorities (oversight recommendations). prnewswire.com