Author: Lenin Lopez
Artificial intelligence has rapidly evolved from a promising business technology to an enterprise-wide governance issue.
For boards of directors, the question has moved well beyond whether AI deserves attention. Now, the more practical question is how directors can effectively oversee AI in a way that's appropriately scaled to the company's business, risk profile, regulatory environment and public disclosures.
This article will discuss:
- Why AI has become a board-level governance issue
- How large public companies are structuring AI oversight
- How AI governance failures can evolve into regulatory, litigation and insurance issues
- Practical steps boards and management teams can consider as they establish and enhance their AI governance programs
- AI-related insurance considerations
AI is now an enterprise risk
When used effectively, AI can create meaningful opportunities, including faster product development, improved customer insights, greater operational efficiency and better data analysis. However, those opportunities come with risks that must be evaluated at the enterprise level. Depending on how companies use AI, they may need to consider several categories of risk: cybersecurity, privacy, intellectual property, employment practices, discrimination, financial reporting, records retention, disclosure controls and regulatory compliance.
Given these risks, AI governance is increasingly resembling cybersecurity governance. Boards aren't expected to manage the technology itself. Rather, they're expected to oversee whether management has the appropriate systems, controls, reporting structures and accountability mechanisms in place.
What we're seeing in public company governance disclosures
Recent proxy statements suggest that companies aren't converging on a single AI governance model. Instead, AI oversight is increasingly being integrated into existing board and management structures.
A recent review of S&P 100 company disclosures found that just over half disclosed board-level oversight of AI. Of those companies, the majority assigned AI oversight to a specific board committee, most commonly the audit committee or a technology committee, while others retained AI oversight at the full board level. Fewer companies disclosed having both board-level AI oversight and a formal AI policy or governance framework.1
These disclosures point to several AI-governance approaches:
- Some companies retain AI oversight with the full board, especially where AI may be central to corporate strategy or where management provides periodic enterprise-wide updates on AI use, risk and investment.
- Some companies assign AI oversight to the audit committee, particularly where AI may be viewed through an enterprise risk management, internal controls, cybersecurity, compliance or financial reporting lens.
- Some companies assign AI oversight to a technology, innovation or product-focused committee, particularly where AI is closely tied to product strategy, software development or digital transformation.
- Some companies use a hybrid model, with the full board maintaining primary oversight and specific committees addressing discrete aspects of AI, like risk management, privacy, product compliance, cybersecurity, ethics, workforce impact or financial controls.
- At the management level, many companies are relying on cross-functional governance structures. These may include representatives from legal, compliance, information security, privacy, technology, internal audit, procurement, human resources and business units responsible for deploying AI tools.
One of the most notable takeaways from these varying approaches to AI governance is that it's not a one-size-fits-all approach. This makes sense. Governance should be tailored, and one way for a board to pressure-test its AI governance structure is to confirm whether the board can clearly explain where AI oversight sits, how information flows to directors, who within management owns AI governance and how AI-related risks are escalated.
Along those lines, what should a board's role be in all of this?
The board's role: Good questions aren't enough
The board's role is oversight, not day-to-day management. Like cybersecurity, financial reporting or compliance, the board's role in AI isn't to manage the technology, but to oversee the governance, controls and accountability surrounding its use.
To carry out those oversight responsibilities, directors will need to understand how AI fits into the company's strategy and risk profile. For some companies, AI could be the core product, revenue driver or competitive differentiator. For others, AI might just be an internal productivity tool. For many, it will be both.
In that spirit, below are some AI-related questions that directors may want to ask of their management teams: