By Rupali Patel Shah, Head of Legal Solutions, DiliTrust
…
The budget gets approved in the spring. By the time the strategy offsite comes around, artificial intelligence is on nearly every slide: in the growth plan, the productivity targets, the competitive threat assessment, the capital request. The board nods it through, because the alternative, falling behind, is worse. Then, somewhere near the end of the session, a director asks the simple question: “So who actually owns this?”
And the room goes quiet.
That silence is the AI governance gap, and most enterprise boards are living in it right now. They have funded AI. They have blessed the strategy that depends on it. What they have not done is decide, clearly and on the record, who is accountable for it, where oversight lives, and what “responsible” actually requires. For a while, that was survivable. It is not anymore. The can has reached the end of the road.
Why deferral just stopped being an option
For a couple of years, boards could treat AI as an operational matter, something for management to pilot and report back on later. That posture made a kind of sense when AI was a set of experiments at the edge of the business. It makes no sense once AI is baked into the strategy the board is charged with overseeing.
The directors themselves feel the shift. Seventy-five percent of corporate directors say their roles and responsibilities are expanding, and digital expertise has now overtaken both strategic planning and financial expertise as the single most sought-after board skill. Read that again: for the first time, boards are being told the most valuable thing they can add to the room is technological fluency, ahead of the two disciplines that have defined board work for a generation.
And yet only 24 percent of private company directors say they are satisfied with their board’s understanding of generative AI risk. That is not a knowledge problem management can brief away. It is a governance problem the board has to own, because the gap sits inside the body responsible for oversight.
Here is the part that makes deferral genuinely dangerous, rather than merely awkward: AI is already regulated. Boards that treat it as a lawless frontier they can wait out are misreading the terrain.
The frontier myth
The most common mistake I see at the board level is the assumption that because there is no single, comprehensive AI statute, there are no rules yet. The opposite is true. Existing law reaches AI from every direction:
- Privacy law governs the data your AI consumes.
- Intellectual property governs what it trains on and who owns what it produces.
- Consumer protection prohibits overstating what it can do.
- Securities law requires accurate, consistent disclosure of how you use it and what it risks.
- Anti-discrimination law applies the moment AI touches hiring, lending, or housing decisions.
- Product liability attaches when an AI-enabled product causes harm.
The dedicated AI regime is the part that is still forming: no comprehensive US federal law, the EU’s AI Act moving first, states legislating in narrow slices, and frameworks like the NIST AI Risk Management Framework and the OECD AI Principles emerging as the common reference points. That patchwork is exactly why boards cannot outsource judgment to “wait and see.” The law that already applies is enough to create real exposure, and the law that is coming will not wait for your board to get comfortable.
Two ideas every board needs to internalize
Strip away the complexity and the board’s job here rests on two principles.
First, AI governance is part of governance, not a side project. If AI is going to change how the company competes, then oversight cannot be designed for business as usual. You cannot steer a transformation with a governance structure built for steady state. When AI shows up in the strategy, it has to show up in the oversight, with the same seriousness the board brings to capital allocation or succession.
Second, a human has to stay in the loop, and that human has to be named. Regulators, courts, and increasingly shareholders are all looking for the same thing: accountability. Someone has to own the decision, understand the system’s limits, and be able to step in and override it. “The model recommended it” is not a defense. The accountability never transfers to the machine, which means the board’s real task is not to understand every algorithm. It is to make sure a person, with authority and understanding, is answerable for each one that matters.
The questions worth asking before the next budget cycle
Boards do not oversee AI by adding a standing “AI update” to the agenda and letting management fill the time. They oversee it by asking questions the current reporting does not answer, and by being honest about what the silence means. A few worth putting on the table:
- Where is AI actually used in this company today, and who signed off on each use? A good answer is a real inventory with named owners. If nobody can produce one, that is the finding.
- What could we not defend if it went wrong tomorrow? A good answer names the two or three highest-risk uses. If every use feels equally low-risk, no one has looked hard enough.
- Who is the human accountable for our highest-stakes AI decisions? A good answer is a name and a role, not a committee and a shrug.
- Are our public statements about AI in filings, in marketing, and to customers accurate and consistent? A good answer is that someone coordinates them. If legal, IR, and marketing are each speaking on their own, that is the exposure.
- Does this board have the fluency to oversee what we just funded? A good answer is candid. If the honest response is no, that is a composition and education decision, not an embarrassment to avoid.
Most boards, asked these today, would answer one or two with confidence. That gap between what the company is doing with AI and what its board actually understands about it is where governance quietly fails.
Where oversight should live
One of the most practical decisions a board faces is deceptively boring: which body owns AI oversight? There is no single right answer, and that is the point. It might sit with the audit committee if AI reads primarily as a risk and compliance matter, with a technology or risk committee, with nominating and governance committee, with the full board, or with a dedicated AI committee if the stakes justify one. The right home depends on your risk profile, your use cases, your size, and what your investors expect.
What matters is that the choice is deliberate and documented, not defaulted. And increasingly, investors want to see AI fluency on the board itself, not just access to an outside expert on call. Composition is becoming part of the answer.
The trap that already has a name
If your board needs a concrete reason to move now, here it is: overstating AI capability is already an enforcement priority. The SEC, DOJ, and FTC have brought a wave of “AI washing” cases against companies that claimed their AI did more than it did. The discipline that prevents it is unglamorous and entirely within a board’s power to demand: know where AI is used, coordinate before speaking publicly, be accurate, stay consistent across filings and marketing, surface issues early, and keep the board informed. None of that requires a data scientist. It requires governance.
The point
Boards are not being asked to become technologists. They are being asked to do the thing boards exist to do: provide accountable oversight of the strategy they fund, at a moment when that strategy runs on a technology most directors are still getting comfortable with. Only about a third of board time is spent on strategy as it is; the temptation to leave AI in the “later” pile is understandable. It is also, now, a risk in its own right.
The companies that get this right will not be the ones with the flashiest AI. They will be the ones where, where a director can ask “Who owns this?”, someone can answer without the room going quiet.
That answer starts at the top. It starts now.
Frequently Asked Questions About AI Governance as a Board Responsibility
No. Privacy law, securities disclosure rules, anti-discrimination statutes, product liability, and consumer protection law all reach AI systems already in use. The EU AI Act adds a dedicated regulatory layer. Boards waiting for a unified AI statute are exposed under existing law while that statute is still forming.
Directors can be held personally liable under a “knew or should have known” standard. The SEC has charged executives for misleading AI claims in filings, marketing, and investor communications, and the DOJ brought its first criminal AI-washing case in 2025. Coordinating disclosures across legal, IR, and marketing before publication is the board-level control that reduces this exposure.
The SEC scrutinizes AI claims equally across all public channels; inconsistency between a filing and a product page is itself a red flag. Boards should verify that a named person or function coordinates AI-related statements before release, and that those statements are grounded in a verified internal AI inventory rather than aspirational positioning.
Anti-discrimination law attaches to the outcome, not the tool. The organization and the named human accountable for that AI system bear the liability. “The model recommended it” is not a legal defense. Boards need to confirm that a person with authority and sufficient understanding of the system’s limits is answerable for each high-stakes AI use.




