I do not think artificial intelligence has created a new category of governance failure. I think it has simply found the fastest route yet to a familiar one: boards that treat oversight as something to be delegated rather than exercised.
That is the argument of this piece, and I want to test it against evidence from four places that rarely get discussed together: the UK's Corporate Governance Code, Canada's prudential and securities regulators, one of the world's fastest-growing emerging markets, and the anti-money-laundering compliance world. Taken together, they tell a more useful story than any single jurisdiction can on its own, and they point to the same underlying governance question.
Not "is AI good or bad," but "who, precisely, inside this organisation, is accountable for it, and how do we know?"
The law has moved further than most directors realise
Start in the UK, because the legal position there has shifted more than many boards have absorbed. The 2024 Corporate Governance Code is now fully in force: boards must monitor, annually assess, and publicly account for the effectiveness of their risk management and internal controls, and disclose any material control failure. It says nothing about artificial intelligence specifically, and it does not need to. Any AI system that materially touches decisions, operations or reporting is already inside that perimeter. The Code deliberately avoids defining "material controls" precisely, which means the judgement about whether an AI system counts is the board's to make, not management's to assume away [4].
Layer on the long-standing duty of care, judged against what a reasonably diligent director would do, and the direction of travel is unambiguous. This is where the governance angle really bites. "Reasonable care" has always been assessed partly objectively, meaning what any competent director would do, and partly subjectively, meaning what this particular director, with this particular skill set, knows or ought to know. As AI moves from a back-office tool to something that prices a loan, screens a candidate, or drafts a regulatory filing, the objective bar rises for every board. A director who cannot explain, in outline, how a material AI-driven decision was reached is increasingly hard-pressed to argue they exercised reasonable care, however unfamiliar the technology feels to them personally.
This has a direct consequence for board composition and training that I do not think enough nomination committees have grappled with yet. A skills matrix that lists "digital" as a single line item is no longer fit for purpose. Boards need at least one or two directors, or access to independent advisers, capable of asking a hard technical question and recognising an evasive answer. Not to replace management's expertise, but to discharge the board's own duty of informed challenge.
Canada's quieter proof of the same point
Canada offers a more interesting version of the same story, precisely because we have chosen not to legislate AI directly. Bill C-27, and the Artificial Intelligence and Data Act it would have created, died on the order paper when Parliament prorogued in January 2025, and Ottawa has since preferred to regulate AI through existing privacy, human-rights and competition law rather than a single AI statute [3]. It would be easy to mistake that for a governance vacuum. It is not one.
The Canada Business Corporations Act's duty of care requires the care, diligence and skill of a reasonably prudent person in comparable circumstances. That already covers AI oversight, whether or not Parliament ever passes a dedicated Act [3]. Our sectoral regulators have, in fact, been unambiguous where Parliament has stayed quiet. OSFI's newly finalised Guideline E-23, effective in 2027, now explicitly brings AI and machine-learning models into its model-risk-management regime for every federally regulated financial institution, including insurers as well as deposit-takers [1].
What I find governance-relevant about E-23 is not just its scope but its architecture. It leans on the classic three-lines-of-defence model: the business line that owns and uses the model, an independent model-risk function that validates it, and internal audit that tests whether the first two are actually doing their jobs. And it expects that structure to report upward in a form the board can genuinely question, not merely receive.
The Canadian Securities Administrators followed in December 2024 with Staff Notice and Consultation 11-348, confirming that existing securities law already applies to issuers' and registrants' use of AI, and setting an expectation that boards demonstrate governance over AI risk: accountability, oversight, human review, staff training and lifecycle controls, well before any new rule is finalised [2]. Their guiding principle, that it is the activity being conducted rather than the technology itself that is regulated, is quietly one of the more sophisticated governance statements to come out of any regulator in recent years.
The absence of an omnibus AI law tells you nothing about whether the duty exists. It only tells you where to go looking for it.
Where AI oversight should actually sit
This raises a practical governance question boards keep asking me: does AI need its own board committee, or can it sit inside risk, audit, or technology committees that already exist? I do not think there is one right answer, but there is a wrong one, which is leaving it unassigned.
Smaller boards can reasonably fold AI oversight into an existing risk or audit committee's mandate, provided the terms of reference are updated explicitly to name AI risk, and provided that committee has, or can call on, genuine technical literacy. Larger or more AI-exposed organisations are increasingly creating a dedicated technology or AI oversight committee, precisely because model risk, data governance, cyber exposure and algorithmic bias each demand a depth of attention that a general risk committee's already-crowded agenda struggles to give them.
Either way, the terms of reference should specify three things: what gets escalated automatically, what the board reviews on a standing cycle, and who has the authority to pause or withdraw an AI system if something looks wrong. Without that last point in writing, "oversight" is aspirational rather than operational.
Frameworks are necessary; culture is what actually decides
Rules matter, but I want to be honest that they are not sufficient on their own. Good frameworks sitting on top of a weak governance culture achieve very little.
India is the sharpest illustration I have come across this year: genuinely serious national AI ambition, and three new regulatory frameworks from its securities regulator, its central bank and its IT ministry inside a single six-month window, operating within a corporate landscape where promoter groups, many of them family-controlled, still hold roughly half the equity of companies listed on the National Stock Exchange, and where boardroom disputes at some of the country's best-regarded conglomerates have made headlines this year. One recent global survey of large companies found that almost all of them had already suffered a financial loss traceable to AI-related risk, yet barely one in eight of their most senior executives could correctly name the controls needed to prevent it [5].
A board-approved AI policy, in that context, is only as strong as the independence of the board that approved it. A promoter-controlled or founder-dominated board can sign off on an impeccably worded AI governance policy and still fail entirely at governance, because the document was never subjected to genuine independent challenge in the first place. That is not a criticism specific to India. It is a caution for every jurisdiction, including our own, where the temptation is to treat a signed policy as proof of governance rather than as the starting point for it.
The real test of an AI governance framework is not whether it exists on paper, but whether an independent director has ever used it to say no.
The pattern regulators keep repeating
That same instinct, extending the frameworks you already trust rather than inventing new ones, shows up again in anti-money-laundering compliance, a field I follow closely because it is usually years ahead of general corporate practice on model governance. Financial institutions collectively spend an estimated US$206 billion a year on compliance, yet current systems are estimated to catch less than 1% of the roughly US$2 trillion laundered globally each year [6]. Those numbers are stark enough that regulators there have concluded AI adoption is not optional. Only ungoverned adoption is dangerous.
Their answer, consistently, is to fold AI models into the model-risk-management disciplines institutions already run for credit and capital decisions. In governance terms, that means four specific, checkable things.
- Independent validation, performed by a team that did not build the model, before it ever reaches production.
- Ongoing monitoring for model drift, so a system trained on yesterday's patterns of behaviour does not quietly stop working as those patterns change.
- A full audit trail recording which model version made which decision, so the answer to "why did this happen" never depends on someone's memory.
- Explainability techniques robust enough that a non-technical director, auditor or regulator can be walked through the reasoning behind a specific alert or decision.
None of that is exotic. It is the same governance vocabulary boards already use for credit risk models, simply extended to a new asset class.
Two governance blind spots worth naming
Two problems deserve more board attention than they currently get, in every jurisdiction discussed here.
The first is visibility. Employees increasingly build their own AI tools on no-code and low-code platforms, entirely outside IT or governance's line of sight. Even organisations with a formal policy prohibiting this report real gaps in what they can actually see happening day to day. From a governance perspective, this is really a familiar problem in new clothing. It is the same challenge as unauthorised expenditure or shadow IT, and it should be handled the same way: clear policy, genuine detection capability, and a route for staff to disclose what they are already doing without fear of punishment for having tried to solve a real problem.
The second is delegation. As AI systems move from suggesting a decision to taking action with minimal human intervention, what the field now calls agentic AI, traditional schemes of delegated authority start to strain. They were written for humans reporting to other humans. The most useful mental model I have found in board discussions is to treat an autonomous system rather like a junior member of staff: capable, useful, and worth empowering, but operating within clearly defined boundaries, explicit escalation thresholds, and a named human who remains accountable for the outcome.
The moment a board cannot say who that named human is for a given system, delegation has quietly become abdication.
The six questions I actually ask
If I had to compress all of this into something usable at a board meeting, it would be six questions rather than a framework.
- Do we know where AI is being used across the organisation, including tools staff have quietly built for themselves?
- Who is the named individual or committee accountable for it, and does that sit clearly within our existing committee structure?
- Could we explain a material AI-driven decision to a regulator, a court, or an angry customer, using an actual audit trail rather than a reconstruction after the fact?
- What happens, procedurally, when the system gets it wrong, and who has the authority to pause it?
- Is our oversight keeping pace with how autonomous these systems are becoming, or still assuming a human checks everything?
- And, underneath all of that: are we asking whether we should do something, or only whether we can?
That last question is the one I keep returning to. Somewhere in this summer's headlines about a government ordering an American company to withhold its most advanced model from the rest of the world, and a continent scrambling in response to build its own AI independence, sits a smaller and more useful lesson for the rest of us [7].
Whoever controls the intelligence controls the decision, at the level of nations and equally at the level of a single organisation.
Boards that have not yet decided, deliberately, who controls it inside their own walls are not being cautious. They are simply late, and in governance, as in most things, being late is itself a decision.
References & further reading
- Office of the Superintendent of Financial Institutions. Guideline E-23: Model Risk Management. Finalised September 2025; effective 1 May 2027. Brings AI and machine-learning models into the model-risk-management regime for all federally regulated financial institutions.
- Canadian Securities Administrators. Staff Notice and Consultation 11-348, 5 December 2024. Confirms that existing securities law applies to issuers' and registrants' use of artificial intelligence.
- Canada Business Corporations Act, s. 122 (duty of care); and Bill C-27, the proposed Artificial Intelligence and Data Act, which died on the order paper in January 2025.
- The Chartered Governance Institute UK & Ireland. Governance and Compliance, Issue 3, May 2026. Analysis of Provision 29 of the 2024 UK Corporate Governance Code.
- EY. Responsible AI Pulse survey, October 2025. On the gap between AI-related financial loss and senior executive awareness of the relevant controls.
- LexisNexis Risk Solutions, True Cost of Financial Crime Compliance (2023); and ACAMS Today (2026), AI in AML governance series.
- The Economist, June 2026. Coverage of the US export-control directive on advanced AI models and the European response.
Could your board answer those six questions today?
The Governance 360 Health Check is a 90-second diagnostic across structure, process, people, compliance, and oversight & risk. You'll get an instant score and a candid read on where to focus first.