Getting your Trinity Audio player ready...

Author: Lenin Lopez

null

Artificial intelligence has rapidly evolved from a promising business technology to an enterprise-wide governance issue.

For boards of directors, the question has moved well beyond whether AI deserves attention. Now, the more practical question is how directors can effectively oversee AI in a way that's appropriately scaled to the company's business, risk profile, regulatory environment and public disclosures.

This article will discuss:

  • Why AI has become a board-level governance issue
  • How large public companies are structuring AI oversight
  • How AI governance failures can evolve into regulatory, litigation and insurance issues
  • Practical steps boards and management teams can consider as they establish and enhance their AI governance programs
  • AI-related insurance considerations

AI is now an enterprise risk

When used effectively, AI can create meaningful opportunities, including faster product development, improved customer insights, greater operational efficiency and better data analysis. However, those opportunities come with risks that must be evaluated at the enterprise level. Depending on how companies use AI, they may need to consider several categories of risk: cybersecurity, privacy, intellectual property, employment practices, discrimination, financial reporting, records retention, disclosure controls and regulatory compliance.

Given these risks, AI governance is increasingly resembling cybersecurity governance. Boards aren't expected to manage the technology itself. Rather, they're expected to oversee whether management has the appropriate systems, controls, reporting structures and accountability mechanisms in place.

What we're seeing in public company governance disclosures

Recent proxy statements suggest that companies aren't converging on a single AI governance model. Instead, AI oversight is increasingly being integrated into existing board and management structures.

A recent review of S&P 100 company disclosures found that just over half disclosed board-level oversight of AI. Of those companies, the majority assigned AI oversight to a specific board committee, most commonly the audit committee or a technology committee, while others retained AI oversight at the full board level. Fewer companies disclosed having both board-level AI oversight and a formal AI policy or governance framework.1

These disclosures point to several AI-governance approaches:

  • Some companies retain AI oversight with the full board, especially where AI may be central to corporate strategy or where management provides periodic enterprise-wide updates on AI use, risk and investment.
  • Some companies assign AI oversight to the audit committee, particularly where AI may be viewed through an enterprise risk management, internal controls, cybersecurity, compliance or financial reporting lens.
  • Some companies assign AI oversight to a technology, innovation or product-focused committee, particularly where AI is closely tied to product strategy, software development or digital transformation.
  • Some companies use a hybrid model, with the full board maintaining primary oversight and specific committees addressing discrete aspects of AI, like risk management, privacy, product compliance, cybersecurity, ethics, workforce impact or financial controls.
  • At the management level, many companies are relying on cross-functional governance structures. These may include representatives from legal, compliance, information security, privacy, technology, internal audit, procurement, human resources and business units responsible for deploying AI tools.

One of the most notable takeaways from these varying approaches to AI governance is that it's not a one-size-fits-all approach. This makes sense. Governance should be tailored, and one way for a board to pressure-test its AI governance structure is to confirm whether the board can clearly explain where AI oversight sits, how information flows to directors, who within management owns AI governance and how AI-related risks are escalated.

Along those lines, what should a board's role be in all of this?

The board's role: Good questions aren't enough

The board's role is oversight, not day-to-day management. Like cybersecurity, financial reporting or compliance, the board's role in AI isn't to manage the technology, but to oversee the governance, controls and accountability surrounding its use.

To carry out those oversight responsibilities, directors will need to understand how AI fits into the company's strategy and risk profile. For some companies, AI could be the core product, revenue driver or competitive differentiator. For others, AI might just be an internal productivity tool. For many, it will be both.

In that spirit, below are some AI-related questions that directors may want to ask of their management teams:

  • Do we have an inventory of AI use cases across the company?
  • Which AI use cases are considered high risk, and why?
  • Who's responsible for approving new AI tools?
  • Who owns AI governance within the organization?
  • Have we adopted an AI governance policy or framework?
  • Are employees trained on the appropriate use of AI tools?
  • How are third-party AI vendors evaluated and monitored?
  • Are AI-related risks integrated into our enterprise risk management program?
  • How are AI-related incidents identified, escalated and reported to the board?
  • How are the company's AI-related public disclosures reviewed, and who does it?
  • How are we documenting our oversight of AI?

Asking questions and creating a record of this level of engagement are among the best ways directors can position themselves to defend against claims of AI oversight failure by regulators, shareholders or plaintiffs' firms. It also helps demonstrate that directors were actively engaging management to better understand AI in the context of the company's business, including related risks and opportunities.

As important as asking good questions is, asking them alone is unlikely to be enough. Effective oversight requires directors to have sufficient familiarity with AI to critically evaluate management's responses, identify potential gaps and ask informed follow-up questions. This doesn't mean every director has to become a technical expert. However, it does mean boards should commit to ongoing education through management presentations, tabletop exercises and outside advisors. They should also get periodic updates on evolving technologies, regulatory developments and industry practices.

Disclosure and "AI washing" risk

What is "AI washing"?

Like environmental "green washing," "AI washing"3 comes in a variety of shapes and sizes. It can refer to companies:
  • Exaggerating the ability or value of its AI
  • Suggesting its AI solutions are operational when they’re not
  • Bolting an existing AI chatbot onto its non-AI software
  • Claiming a service is powered by AI when it’s using less-sophisticated computing

Regulators have already brought enforcement actions involving allegedly false or misleading statements about AI use. The Securities and Exchange Commission (SEC) has also signaled concern around "AI washing," a term often used to describe overstated or unsupported claims about AI capabilities.2

For public companies, the risk is broader than enforcement. AI-related statements can appear in earnings calls, investor presentations, annual reports, proxy statements, sustainability reports, product announcements and marketing materials. If a company publicly touts its AI capabilities but lacks governance, controls or substantiation, plaintiffs' firms may later argue that those statements were misleading.

Filtering AI-related statements through a diligence checklist should help companies limit the risk of making misleading claims. One approach would be to confirm that proposed AI-related statements meet certain standard criteria. For example, the statements must be:

  • Accurate
  • Appropriately qualified
  • Consistent across public-facing materials
  • Supported by internal documentation
  • Reviewed by legal, finance, investor relations and relevant technical personnel

The SEC's Investor Advisory Committee has also recommended that public companies define what they mean when they use the term "artificial intelligence," disclose board oversight mechanisms for AI deployment and report separately on any material effects of AI deployment on internal operations and consumer-facing matters.4,5 Even if formal SEC rulemaking doesn't immediately follow, these recommendations provide a useful signal of investor and regulatory expectations.

What an AI governance failure could look like

AI governance failures are unlikely to begin with a board meeting. They're more likely to begin quietly, inside the business.

A realistic scenario might include elements like this:

  • Employees begin using generative AI tools outside of company policy, perhaps on a personal device.
  • An employee enters sensitive company, customer or employee data into one of these AI tools.
  • The employee uses this AI-generated output in driving operational, financial, employment or customer-facing decisions.
  • The company has been proactive in describing itself publicly as using AI to improve efficiency, decision-making or product performance.
  • An error, bias issue, data incident, intellectual property claim, customer complaint or regulatory inquiry emerges. Perhaps it even leads to a significant drop in stock price.
  • The company determines that the issue may be broader than a one-off event.
  • Investors, regulators or plaintiffs begin asking whether the company's AI-related disclosures were accurate.
  • The board's oversight process is questioned and becomes part of the factual record.
  • The company scrambles to determine how and whether insurance will cover the potential fallout from these issues.

These types of events reinforce the point that documentation matters. Board minutes, committee materials, management presentations, policies, training records, vendor diligence files and incident response materials may all become relevant if an AI issue later leads to an investigation or claim.

A practical AI governance roadmap

For many companies, AI governance can be developed in phases. The following roadmap outlines considerations for companies, boards and management teams as they develop their own tailored AI governance structure.

Phase one: Understanding current use

The first step is understanding where AI is being used within the company. Management can develop an AI inventory, identify high-risk use cases, determine whether employees are using publicly available AI tools and assess whether vendors are embedding AI into existing products or services.

Phase two: Assigning ownership

Companies should clearly identify who owns AI governance at the management level and where AI oversight sits at the board level. Expect this to involve a discussion at the board level, with an existing committee or with a combination of committees. Several companies have disclosed their approaches to AI governance in their proxy statements. It may be worthwhile to look at some of those examples for inspiration.

Phase three: Adopting policies and controls

Companies should develop and adopt policies governing AI use, data protection, vendor diligence, documentation, employee training and incident escalation.

Phase four: Integrating into existing governance processes

AI considerations should also be incorporated into enterprise risk management, cybersecurity, privacy, compliance, internal audit, disclosure controls and incident response processes.

Phase five: Reporting to the board

Management should give periodic updates to the board or the relevant committee. Cadence will depend on the company, but those updates could cover AI strategy, important proposed use cases and their associated expenditures, risk management, regulatory developments, incidents, training and disclosure considerations.

Insurance considerations

AI doesn't fit neatly into a single insurance product. Depending on the facts, an AI incident could implicate Directors and Officers (D&O) insurance, cyber insurance, technology errors and omissions (E&O) insurance, media liability coverage, employment practices liability (EPL) insurance, fiduciary liability insurance or commercial general liability insurance.

For example:

  • A securities claim alleging misleading AI-related statements could implicate D&O insurance.
  • A derivative claim alleging failure of board oversight is another instance where D&O insurance would likely be in play.
  • A data breach involving AI tools could implicate cyber insurance.
  • A customer claim involving an AI-enabled product or service may implicate technology E&O coverage.
  • A copyright or content-related claim could implicate media liability coverage.
  • An employment-related claim involving AI-enabled hiring, performance management or workforce decisions may implicate EPL coverage.

Boards and management teams would be wise not to wait until an AI incident becomes an investigation or lawsuit before involving their insurance advisors. Early coordination can help companies evaluate notice obligations, privilege considerations, insurer expectations and potential coverage pathways.

Parting thoughts

AI governance is becoming a core board oversight issue, if it isn't already. The most prepared companies aren't necessarily those that create the most elaborate governance structure. They're the companies that can clearly explain how AI is used, who is accountable, how risks are monitored, how incidents are escalated and how disclosures are supported.

As AI becomes more embedded in business operations, directors should expect investors, regulators, plaintiffs' firms and insurers to ask increasingly practical questions: What did the company know? Who was responsible? What did the board oversee? Were public statements accurate? Were risks escalated? Were controls in place?

Those are governance questions and may be best considered alongside corporate strategy. In the end, they're exactly the questions that boards should be asking now.

Published August 2026

Author Information


Sources

1 Wenger, Sarah. "US AI Oversight Through Three Lenses: Investor Expectations, the S&P 100 and Company-Specific Analysis," Harvard Law School Forum on Corporate Governance, 11 Mar 2026.

2 "SEC Charges Two Investment Advisers with Making False and Misleading Statements About Their Use of Artificial Intelligence," U.S. Securities and Exchange Commission, 18 Mar 2024.

3 Woollacott, Emma. "What is 'AI washing' and why is it a problem?" BBC.com, 27 Jun 2024.

4 "Recommendation of the SEC Investor Advisory Committee's Disclosure Subcommittee Regarding the Disclosure of Artificial Intelligence's Impact on Operations," U.S. Securities and Exchange Commission, Investor Advisory Committee, 2025. PDF file.

5 Uyeda, Mark T. "Remarks for Investor Advisory Committee Meeting," U.S. Securities and Exchange Commission, 4 Dec 2025.


Disclaimer

The information contained herein is offered as general industry guidance regarding current market risks, available coverages, and provisions of current federal and state laws and regulations. It is intended for informational and discussion purposes only. This publication is not intended to offer financial, tax, legal or client-specific insurance or risk management advice. No attorney-client or broker-client relationship is or may be created by your receipt or use of this material or the information contained herein. We are not obligated to provide updates on the information contained herein, and we shall have no liability to you arising out of this publication. Woodruff Sawyer & Co, a Gallagher Company, CA Lic. #0329598. © 2026 Arthur J. Gallagher & Co., and affiliates & subsidiaries