Skip to main content
AI Governance
Board Briefing

AI Governance

Governance people route around fails to govern; the task is governing AI the Board cannot fully see without strangling adoption.

10 articles 3 audio Updated 12 July 2026

Start here

Two short reads before you go deeper: what this subject actually asks of a Board, and how to work through the briefing.

Start with this

If People Route Around It, It Is Not Governance

What AI governance now has to cover, why well-built frameworks still fail, and the judgement to bring back to your own boardroom.

2 minute read · Read →

Then read this

From the Six Concerns to the Amnesty

The order this briefing was built to be read in, and what each section adds as you go.

2 minute read · Read →

Core reading

The core sequence runs from what a Board must govern, through the operating principle that makes governance work, to the amnesty that brings shadow AI into the light.

  1. AI is transforming governance: Six key Boardroom priorities

    AI takes Boards from overseeing hundreds of decisions a day to millions a second, each needing to be transparent, explainable and correct: six priorities follow.

    10 minute read · 4 February 2025

  2. Minimum Lovable Governance: The AI Operating Principle Boards Should Use

    Minimum lovable governance replaces episodic compliance with continuous, embedded oversight people actually want to use: guardrails that earn adoption rather than enforce it.

    13 minute read · 30 November 2025

    Read the article →or listen to the podcast version → 17 minute listen

  3. Shadow AI and the Case for an AI Amnesty

    Shadow AI is surging and most employees would use AI tools without permission. An AI amnesty turns that hidden risk into governed, employee-validated innovation.

    15 minute read · 21 September 2025

  4. After the AI Amnesty: Practical Steps to Operationalise Discovered Shadow AI

    After the amnesty, speed matters: employees who disclosed expect enablement, not restriction. A roadmap for turning discovered shadow AI into governed capability.

    12 minute read · 28 September 2025

Further reading

Remake

The mechanisms beneath the thinking: the model, diagnostic, methodology, and principle from the Remake Library that turn this briefing into apparatus a Board can use.

Questions

The questions directors put to me most often on this subject, answered from the work in this briefing.

We cannot see most of the AI our people use. How do we govern it?

Not by pretending the visibility problem away. Menlo Security documented a 68% year-on-year surge in shadow generative AI usage in 2025, and most of it never touches a formal approval process. The practical first step is a time-limited AI amnesty: a disclosure window, without punishment, that converts an invisible risk into an inventory the Board can actually govern, and surfaces the use cases employees have already validated.

Should we simply block unapproved AI tools?

The evidence says blocking does not stop the use; it hides it. BCG’s 2025 AI at Work research found 54% of employees would use AI tools even if the organisation had not authorised them, and Gigster’s 2025 research found 57% already hide their usage. Prohibition drives the activity further underground, where the data exposure is worst. The better questions are why people route around the sanctioned route, and what would make them choose it instead.

Is lighter-touch governance not just weaker governance?

No. Minimum Lovable Governance is not less governance; it is governance matched to risk. A credit decisioning system warrants heavier scrutiny than a meeting summariser, continuous assurance beats the annual audit scramble, and controls embedded in the workflow get used where separate approval queues get bypassed. The test is whether the organisation could demonstrate its compliance posture tomorrow, not after weeks of preparation.

Whose values is our AI actually running?

The provider’s, unless the Board has decided otherwise. Every foundation model arrives with a value system built upstream in pre-training and alignment, and system prompts, retrieval, and guardrails constrain that standard without re-authoring it. The choice for each material deployment is to accept, reject, or build, and the failure mode is accepting everywhere by default without ever naming the decision.

What does the Board itself need to learn to govern AI credibly?

Not technical fluency. Directorial AI literacy is four specific capacities: interrogating maturity claims, distinguishing operational governance from governance theatre, identifying material AI risk, and exercising independent judgement rather than ratifying management’s framing. Deloitte’s 2025 Global Board Survey found two-thirds of Boards still report limited or no AI knowledge, so most directors will find gaps. Finding them is the point.

Where should our AI Centre of Excellence report?

To the Board, through the risk and compliance committee, not to IT. That has been my position since the article introducing the Six Board Concerns model: the AI Centre of Excellence is a governance mechanism for decision-making at machine speed, not another technology function, and a reporting line through IT tends to narrow it to technical implementation. My 2022 article The Board in the machine made the same point in earlier language, placing oversight with the Audit and Risk Committee. Independence from operational pressure is the point; the case for the Centre sets out the mandate, authority, and resources the Board resolution should carry.

Who owns the intellectual property our people create with public AI tools?

Often nobody can say. When people use public tools to create content or code, ownership of the output can be unclear, and the provider’s terms of service may be the only text on the point. The article introducing the Six Board Concerns model raises the question because organisations have been discovering intellectual property built in unapproved tools. The Board’s job is to require an answer for each material use case and to bring that work into the open. The AI Amnesty methodology does that, and the post-amnesty triage treats IP created without controls as a first-week, high-risk item.

Does ISO 42001 certification mean we are governing AI well?

Not on its own. ISO 42001 sets requirements for an AI management system, and ISO/IEC 42006:2025 adds the audit and certification requirements, but a certificate says a system exists, not that governance happens in practice. The diagnosis piece describes organisations that tick the boxes, implement ISO 42001, and still fail, because the Six Board Concerns model is an interconnected system and they worked through it one concern at a time. Certification pursued too early also tends to produce the heavyweight governance people route around. The Minimum Lovable Governance principle is the progressive path: embedded, proportionate, continuous governance first, maturing towards certification.

References

The research houses, institutes, and regulators these articles draw on; go here for the primary evidence.

Institute of Directors

AI Governance in the Boardroom

The IoD business paper on Board-level AI governance, including the expectation that a Board can pause or reverse an AI system whose behaviour proves unacceptable.

IoD NEDs Reimagined Commission

NEDs Reimagined

Formally names the directorial AI literacy gap and calls on NEDs to build their own understanding and independent sources of insight.

Deloitte Global Board Survey

Governance of AI: A critical imperative for today’s boards

Finds 69% of Boards discuss AI regularly while only a third feel equipped to oversee it, and two-thirds report limited or no AI knowledge.

BCG

AI at Work 2025: Momentum Builds, but Gaps Remain

The source of the 54% figure: employees who would use AI tools whether or not the organisation authorises them.

MIT NANDA

The GenAI Divide: State of AI in Business 2025

The research behind the 95% pilot failure figure and the GenAI Divide between individual adoption and organisational readiness.

Menlo Security

Menlo Security’s 2025 Report Uncovers 68% Surge in “Shadow” Generative AI Usage in the Modern Enterprise

Menlo Security’s 2025 report on AI in the modern workspace, documenting a 68% year-on-year surge in shadow generative AI use (vendor research, press release).

Harmonic Security

GenAI Data Exposure: What GenAI Usage Is Really Costing Enterprises

Quantifies what shadow AI actually leaks: sensitive content in uploaded files and prompts, much of it through personal accounts.

Stanford CRFM

The Foundation Model Transparency Index

Scores foundation model providers on disclosure; the 2025 edition averaged roughly 40 out of 100, which is why an inherited value system cannot be fully read.

EUR-Lex

Regulation (EU) 2024/1689 (Artificial Intelligence Act)

The risk-tiered architecture of Regulation (EU) 2024/1689 that makes proportionate governance a legal expectation rather than a preference, with the high-risk obligations deferred in 2026 to December 2027 and August 2028.

PwC

PwC’s 2025 Responsible AI survey: From policy to practice

Evidence that adaptive, embedded governance correlates with 30 to 40% faster innovation cycles.

Gigster

The Dangers of Shadow AI and Need for an Enterprise AI Plan

Gigster, 2025: 57% of employees using AI tools at work conceal their usage, the shadow-AI figure the governance articles cite.

arXiv

Alignment Drift in Multimodal LLMs: A Two-Phase, Longitudinal Evaluation of Harm Across Eight Model Releases

The 2026 pre-print on alignment drift in multimodal models: why governance cannot assume a model’s behaviour is fixed between versions.

Concepts

The ideas beneath this briefing

Ideas I’ve named and matured writing about AI Governance: what each one means, and where it started.

Emergent Threat Paradox

AI risks evolve through learning, adaptation and interaction in ways traditional risk frameworks cannot anticipate, so established controls fail against systems that continuously learn and change.

Read the article →

Multi-Speed Collision

When functions align AI to their own objectives at different velocities, their individual successes actively undermine each other, for example marketing generating demand that supply chain AI cannot fulfil.

Read the article →

Trust Multiplier Effect

How stakeholder confidence cascades, employee doubt breeding customer suspicion, alerting regulators, spooking investors, so lost trust in one group turns technical triumphs into organisational disasters.

Read the article →

Value Attribution Crisis

The difficulty of measuring AI value that emerges through compound effects defying simple attribution, causing project-based evaluation to systematically undervalue transformation while overvaluing incrementalism.

Read the article →

Velocity Mismatch

The gap between AI's rapid development pace and traditional quarterly board governance cycles, where the capability justifying a business case in January may be obsolete by June.

Read the article →

More Board Briefings

More complete resources on AI and emerging technology for the Boards that need the full picture.

I use cookies to understand how my website is used. This data is collected and processed directly by me, not shared with any third parties, and helps me improve my website. See my privacy and cookie policies for more details.