AI is becoming powerful enough to influence corporate decisions.
For years, board conversations about artificial intelligence were largely technology conversations. Directors wanted to understand what AI could do, how much organisations should invest, whether competitors were moving faster and where automation could improve productivity.
Those questions still matter. However, they are rapidly being overtaken by something more fundamental.
Who is accountable when AI materially shapes a corporate decision?
That question becomes harder as AI moves beyond drafting, summarising and analysing information. Increasingly capable systems can identify opportunities, rank candidates, recommend investments, assess customers, detect fraud, allocate resources and influence strategic choices.
Agentic systems take the issue further because they may execute sequences of actions rather than merely recommend them.
Corporate governance was built around identifiable human authority. Boards delegate to executives, executives delegate through management structures, committees exercise defined responsibilities and people remain accountable for the powers they exercise.
AI introduces something different.
An algorithm may possess no formal authority while exercising considerable practical influence. The person approving a decision can therefore remain human even though the analysis, options, recommendation and perceived risk behind that decision have been substantially shaped by a machine.
This is where AI stops being principally a technology issue.
It becomes a question about power, judgement and accountability.
Boston Consulting Group’s 2026 research on CEOs, boards and AI found that 61 per cent of CEOs believe their boards are rushing AI transformation, while 35 per cent think boards overestimate the human capabilities AI can replace.
PwC’s 2026 Annual Corporate Directors Survey exposes another part of the problem. Some 71 per cent of directors said their boards need stronger AI skills for effective oversight. More strikingly, 82 per cent rated the information connecting AI outcomes, risks and business performance as only fair, poor or not provided.
Research from the Chartered Governance Institute UK & Ireland reaches a similar conclusion. Organisations are embedding AI into decision making faster than governance systems are evolving to oversee it.
The emerging challenge is therefore not simply that boards need to understand AI better.
Boards need to understand where human authority is quietly becoming algorithmic influence, and whether accountability still follows the power to shape the decision.
That is the governance challenge of AI.
Read More: How Board Governance Strengthens Regulatory Compliance
Executive Takeaway
The board’s most important AI responsibility is not choosing technology. Nor should directors attempt to manage implementation, which remains an executive responsibility.
Instead, the board must ensure that the organisation has a defensible system of authority, oversight and accountability around AI.
That requires answers to several questions:
- Where is AI actually being used?
- Which material decisions does it influence?
- Who owns those decisions?
- What judgement must remain human?
- Can people genuinely challenge an algorithmic recommendation?
- Who has authority to stop a system?
- What information reaches the board when something goes wrong?
- Can the organisation reconstruct how a significant AI-assisted decision was made?
If those questions cannot be answered clearly, the organisation may have an AI strategy.
It does not yet have mature AI governance.
The evidence points to an accountability gap
The most interesting feature of current AI research is not that directors recognise AI as important. Almost everyone does.
The tension lies between ambition and governance readiness.
BCG’s 2026 research found considerable alignment between CEOs and directors at the level of principle. Beneath that agreement, important differences appear.
Around 61 per cent of CEOs believe boards are rushing AI transformation, while 35 per cent think directors overestimate AI’s ability to replace human expertise. BCG also found that 37 per cent of CEOs believe boards lack an informed view of how AI is reshaping growth strategy.
Perhaps most revealing is the confidence gap. Three-quarters of directors surveyed by BCG considered their AI understanding comparable with or better than that of their peers. Yet chief executives expressed significantly more doubt about whether boards really understand what the technology can and cannot do.
Confidence without sufficient understanding can create a dangerous governance combination.
Boards may push management to move faster while lacking enough technical and commercial understanding to judge whether the organisation is moving intelligently.
AI oversight therefore requires boards to distinguish strategic urgency from institutional impatience.
Boards cannot govern what they cannot see
PwC’s research exposes another weakness.
Some 82 per cent of directors rated the information connecting AI outcomes, risks and business performance as fair, poor or absent.
Even a highly capable board cannot oversee what it cannot see.
That principle becomes particularly important because AI can spread through an organisation remarkably quickly. Employees use general-purpose tools, business units purchase specialised systems and existing software providers introduce AI features. Meanwhile, functions experiment with automation before formal policies have caught up.
As a result, official AI strategy and actual AI adoption can become two different things.
The Chartered Governance Institute’s 2026 research highlights precisely this problem, with boards often lacking sufficient visibility over how AI is being used.
An inventory is a useful starting point.
It is not enough.
Boards need to know where AI affects decisions, people, risk and value.
Boards need an AI decision map, not simply an AI register
Consider two systems.
One helps employees summarise internal documents. Another ranks candidates for senior appointments.
Both use AI.
Their governance significance is entirely different.
A mature governance framework should therefore connect technology with consequence.

This changes the governance conversation.
Rather than asking how many AI applications the organisation has, directors can focus on where algorithmic influence becomes materially important.
The unit of AI governance should increasingly be the decision, not merely the technology.
Responsible AI begins with understanding who bears the consequences
Accountability is not solely an internal governance question.
AI decisions affect people.
Recruitment systems affect candidates. Credit models influence customers, while workforce tools affect employees. Automated procurement decisions can influence suppliers, and algorithms used in investment or resource allocation may have broader environmental and social consequences.
That means responsible AI cannot be separated neatly from responsible business.
Boards should ask not only whether an AI system works, but also whose interests are affected when it works as designed.
A technically accurate system can still create poor outcomes if its objectives, data or decision criteria are badly designed.
Materiality therefore matters.
A structured ESG Materiality & Risk Assessment can help organisations distinguish between peripheral concerns and environmental, social or governance issues capable of affecting stakeholders, reputation, regulatory exposure and long-term value.
AI should increasingly form part of that assessment where its deployment materially affects people or organisational outcomes.
Technology risk is only one dimension.
Responsible impact begins when the organisation examines the consequences of how technology is actually used.
The ownership problem becomes harder as AI enters decisions
Traditional governance assumes significant decisions have identifiable owners.
AI can blur that principle.
Imagine an algorithm recommends rejecting a customer.
A vendor supplied the model. Internal technology teams integrated it, while a business unit selected relevant parameters. Risk approved the control environment and an employee accepted the recommendation.
Who owns the outcome?
Several parties have participated.
That should not allow accountability to become so distributed that nobody is responsible.
The NIST AI Risk Management Framework places governance across the AI lifecycle and emphasises organisational accountability, roles and responsibilities.
Likewise, the OECD AI Principles connect responsible AI with accountability, traceability and human oversight.
A sensible corporate principle follows.
Every material AI-assisted decision should still have an identifiable human owner.
Algorithms may recommend.
Technology can analyse.
Automated systems may execute predefined actions.
Accountability should remain capable of locating someone with authority and responsibility.
Algorithmic discretion is becoming delegated power
Boards already understand delegated authority.
Frameworks determine who can sign contracts, commit capital, recruit senior executives or approve significant expenditure.
AI creates a less visible form of delegation.
Suppose an algorithm cannot formally approve a major investment. It can, however, rank the opportunities.
Another model forecasts returns.
A third assesses risk.
Management then receives an AI-supported recommendation before exercising formal approval.
No legal authority has moved to the machine.
Practical influence clearly has.
This distinction matters because governance should follow the real distribution of power rather than the organisation chart alone.
Boards should therefore distinguish between systems that:
- Provide information
- Prioritise alternatives
- Recommend outcomes
- Initiate actions
- Execute actions without further approval
Governance requirements should increase as practical discretion increases.
Formal authority can remain human while real influence quietly becomes algorithmic.
Human in the loop is not a governance framework
Many organisations respond to AI risk with a reassuring phrase.
A human remains in the loop.
The statement sounds stronger than it may be.
Imagine an employee receives hundreds of algorithmic recommendations every day and accepts almost all of them. Human oversight technically exists, but meaningful judgement may not.
Automation bias can encourage people to trust machine outputs. Time pressure may make challenge difficult, while inadequate understanding leaves employees unsure when disagreement is justified.
Organisational incentives matter as well.
If an AI system is presented internally as more accurate than human judgement, challenging it may gradually feel irrational.
Boards should therefore test whether human oversight has substance.
Can the reviewer understand the recommendation?
Do they have authority to reject it?
Is enough time available for consideration?
Does the organisation monitor overrides?
Can disagreement be escalated?
Are employees penalised for slowing an automated process?
The answers reveal whether the human is exercising judgement or merely legitimising the machine.
What should remain irreducibly human?
Boards should not attempt to preserve human intervention everywhere.
That would defeat much of the value of automation.
The harder question concerns where human judgement remains essential.
Context matters enormously.
An AI system processing routine administrative information presents a different governance problem from one influencing employment, credit, safety, investment, healthcare or significant strategic decisions.
Human judgement becomes particularly important where decisions involve serious uncertainty, ethical trade-offs, stakeholder consequences or difficult questions of organisational purpose.
Likewise, decisions that could materially affect rights, reputation, safety or long-term organisational direction deserve stronger human authority.
The board itself occupies a special category.
Directors may use AI to support analysis, prepare questions or understand information. However, fiduciary judgement cannot simply be transferred to a model.
The board can automate information processing. It cannot automate away responsibility for judgement.
AI governance is also a stakeholder governance issue
The consequences of AI do not stop at the organisation’s legal boundary.
Customers may experience automated decisions without understanding how they were reached.
Employees can find their work monitored, evaluated or restructured by algorithmic systems. Communities may be affected by technology-enabled operating decisions, while suppliers can encounter automated procurement and risk assessments.
Good governance therefore requires organisations to understand stakeholder experience.
Meaningful Stakeholder Engagement can provide information that internal technology metrics cannot.
A model may appear highly successful while affected stakeholders experience unfairness, confusion or loss of trust.
Complaints can become an important governance signal.
Employee feedback may reveal that human review is weaker than management believes. Customer experience can expose unintended consequences, while external stakeholders may identify risks overlooked during system design.
Responsible AI should therefore incorporate stakeholder evidence into governance.
The people affected by an algorithm may understand its consequences before the board sees them in a dashboard.
The right to stop may matter as much as the right to approve
Governance is not only about who can authorise something.
It is also about who can stop it.
The OECD AI Principles recognise the importance of mechanisms for overriding, repairing or safely decommissioning systems displaying harmful or unwanted behaviour.
Corporate governance should translate that principle into clear decision rights.
For material AI systems, organisations need to know who can suspend deployment, which incidents trigger intervention and whether risk or compliance functions can stop a system.
Third-party dependence matters too.
Can a vendor restrict the organisation’s ability to intervene?
What happens to operations if the technology is withdrawn?
How quickly can permissions be removed from an autonomous agent?
A system without a credible stopping mechanism creates a governance weakness.
The ability to deploy AI is an operational capability. The ability to constrain it is a governance capability.
Agentic AI turns governance into an authority question
The stakes increase when AI begins to act rather than merely advise.
An agent may interact with software, communicate with suppliers, modify records, initiate workflows or perform sequences of tasks.
At that point, familiar technology-risk language becomes insufficient.
The organisation is allocating operational authority.
Boards and management should approach agentic AI with questions similar to those used for human delegation.
What may the agent do?
Which systems can it access?
What financial limits apply?
Which actions require approval?
How are exceptions handled?
Who reviews performance?
What activity is logged?
How quickly can permissions be withdrawn?
These answers should not remain buried inside technical documentation.
They belong within the organisation’s governance framework.
AI agents may be technologically novel. The governance problem is familiar: who has authority to do what, on whose behalf and within which limits?
The board needs to govern decision formation, not merely final approval
One of AI’s most important effects may occur before a formal decision.
Algorithms determine which options people see.
Models rank alternatives.
Systems frame risk.
Generative AI can summarise complex evidence.
Prediction tools may make one outcome appear substantially more attractive than another.
By the time a human enters the process, the boundaries of judgement may already have been shaped.
Boards should therefore pay attention to decision formation.
A person clicking approve does not necessarily demonstrate independent judgement.
The important questions sit upstream.
Which alternatives were excluded?
What assumptions were embedded?
Where did the data come from?
Was the model challenged?
What uncertainty disappeared from the final recommendation?
The most consequential algorithmic decision may be the one that determines what the human decision maker gets to see.
AI governance belongs inside strategy, not beside it
Treating responsible AI as a separate policy exercise creates another weakness.
The technology increasingly affects strategy itself.
AI can change operating models, workforce requirements, customer relationships, investment priorities and competitive advantage.
Governance should therefore connect AI with the organisation’s wider strategic and responsible business objectives.
A coherent ESG Strategy Development process can help organisations connect environmental, social and governance considerations with strategic priorities rather than treating responsible impact as a parallel reporting exercise.
The same principle applies to AI.
Where deployment affects workforce structure, customers, suppliers, communities or long-term value creation, those consequences should form part of strategic decision making.
Boards should resist a false choice between innovation and responsibility.
Poorly governed innovation can destroy value.
Responsible innovation can strengthen trust, resilience and organisational legitimacy.
AI should influence investment decisions differently according to materiality
The same governance principle applies to capital allocation.
Not every AI opportunity deserves the same level of scrutiny.
An organisation considering a small productivity tool faces different questions from an investment fund considering a business whose valuation depends heavily on autonomous AI systems.
Investors increasingly need to understand technology governance as part of wider ESG analysis.
A company’s AI governance may affect regulatory exposure, workforce relations, intellectual property, customer trust, operational resilience and reputation.
Consequently, AI capability without credible governance may itself become an investment risk.
Lumorus’s work on ESG Integration in Investment Decisions reflects the wider principle: responsible impact information should improve investment analysis rather than exist solely for reporting.
For investors, AI governance should increasingly be examined through the same lens.
What value does the technology create?
Which risks accompany that value?
Who is accountable?
How credible are the controls?
Could poor AI governance undermine the investment thesis?
Good responsible investment analysis asks not simply what technology can do, but whether the organisation deploying it can govern the consequences.
Boards need better AI information, not more AI information
PwC’s finding that 82 per cent of directors see weaknesses in information connecting AI outcomes, risks and business performance deserves particular attention.
The solution is not more slides.
Boards need decision-useful information.
A useful reporting framework might include:
- Material AI use cases
- Value delivered
- Significant stakeholder impacts
- Deployment stage
- Material incidents
- Human overrides
- Control failures
- Model deterioration
- Regulatory exposure
- Customer or workforce complaints
- Significant third-party dependencies
- Systems suspended or withdrawn
Trends matter more than snapshots.
If human override rates suddenly fall, the board may need to understand whether the model improved or people stopped challenging it.
A sharp increase in complaints can indicate a problem before conventional risk indicators react.
Repeated exceptions may reveal that the system does not fit real-world conditions.
Good reporting should make the governance story visible.
Boards need AI fluency, not technical theatre
PwC found that 71 per cent of directors believe their boards need stronger AI skills.
The answer is not turning every director into a machine-learning specialist.
AI fluency means understanding enough to ask intelligent governance questions.
Why are we using this system?
What business problem does it solve?
How reliable is the evidence?
Where can it fail?
What assumptions matter?
Who could be affected?
Where does human judgement enter?
Who owns the outcome?
How would management identify deterioration?
Can we stop it?
Directors asking these questions are not pretending to be engineers.
They are governing.
McKinsey’s work on emerging AI risks similarly identifies governance, accountability, real-time risk management and board AI fluency as important priorities.
The board does not need to understand every line of code.
It needs to understand the organisation’s exposure to the consequences.
Explore More: Board Skills Audit
Cybersecurity is only one part of responsible AI
Cyber risk understandably dominates many board conversations.
It should not become the container for every AI issue.
AI can create risks involving:
- Discrimination
- Consumer treatment
- Employment
- Intellectual property
- Data quality
- Misinformation
- Reputation
- Third-party dependence
- Operational resilience
- Regulatory compliance
- Human judgement
- Strategic misallocation
- Environmental impact
- Accountability
Several of these risks extend beyond the natural remit of technology or cybersecurity teams.
That makes AI a cross-functional governance issue.
Responsible AI requires technology, risk, legal, compliance, HR, strategy and sustainability perspectives to connect rather than operate independently.
Fragmentation is itself a risk.
Responsible impact needs to be measured, not merely promised
Corporate commitments to responsible AI are multiplying.
Principles such as fairness, transparency, safety and human oversight increasingly appear in policies.
The harder question is whether organisations can demonstrate outcomes.
That is where Social Impact Measurement and Management becomes relevant.
Where AI materially affects employees, customers or communities, organisations should consider how those impacts can be identified and monitored.
Useful indicators might include:
- Complaints associated with automated decisions
- Differences in outcomes across affected groups
- Human override patterns
- Workforce displacement and redeployment
- Employee confidence in AI-supported processes
- Accessibility impacts
- Customer trust
- Remediation outcomes
Measurement should remain proportionate.
The objective is not creating an enormous new reporting bureaucracy.
It is ensuring that claims about responsible AI can be tested against evidence.
Responsible AI is not what the policy says. It is what the system does to people in practice.
Transparency should explain governance, not simply technology
AI reporting is likely to become increasingly important.
However, organisations should avoid producing disclosure that describes technology without explaining accountability.
Strong ESG Reporting and Disclosure should help stakeholders understand material risks, governance arrangements and outcomes.
Applied to AI, meaningful disclosure may eventually need to explain:
- How material AI risks are governed
- Where board oversight sits
- Which principles guide deployment
- How significant stakeholder impacts are assessed
- How human oversight operates
- How incidents are managed
- How performance and impacts are monitored
Transparency should remain material and decision useful.
Publishing an exhaustive list of tools may add little value.
Explaining how the organisation governs high-consequence AI is considerably more meaningful.
AI governance should preserve evidence of judgement
Accountability becomes difficult without evidence.
Imagine a significant AI-assisted decision is challenged eighteen months later.
Can the organisation reconstruct what happened?
Which system was used?
What information did it receive?
What recommendation did it produce?
Did a human reviewer challenge the output?
Were alternatives considered?
Who approved the decision?
What controls operated?
Was an exception recorded?
These questions matter to regulators, auditors and boards.
They also matter for institutional learning.
The NIST AI Risk Management Framework emphasises documentation, governance and clearly defined responsibilities. The OECD similarly connects accountability with traceability.
Not every automated action requires a board-level record.
Material decisions need enough evidence to explain where machine analysis ended and accountable human judgement began.
Who owns the kill switch?
This may become one of the most important governance questions of the AI era.
Not technically.
Institutionally.
Imagine an AI system is delivering substantial revenue but begins producing evidence of serious harm.
Technology wants additional testing.
The business wants continued deployment.
Legal raises concerns.
Risk recommends suspension.
Who decides?
Governance becomes real at precisely this moment.
Policies matter. Risk appetite matters. Delegated authority matters.
Most importantly, decision rights matter.
The organisation should know in advance who possesses authority to constrain a profitable system when risk exceeds tolerance.
Otherwise, commercial incentives may overpower governance precisely when governance is most necessary.
A board that knows who can approve AI but not who can stop it has designed only half the control system.
A practical Board AI Accountability Framework
Boards need something more useful than broad statements about responsible AI.
A practical framework can begin with nine disciplines.

Models will change.
Regulation will evolve.
Applications will become more sophisticated.
These governance fundamentals remain remarkably stable.
Power needs limits.
Authority needs clarity.
Material impacts need attention.
Decisions need evidence.
Accountability needs an owner.
Ten questions every board should ask now
A serious board conversation about AI could begin here:
- Where is AI currently influencing material decisions?
- Which of those uses are visible to the board?
- Who is accountable for each material AI-assisted decision?
- Which stakeholders could experience significant consequences?
- Where can AI recommend and where can it act?
- Which decisions must remain substantively human?
- How do we know human oversight is meaningful?
- Who can suspend a system when risk exceeds tolerance?
- Which AI incidents must reach the board?
- Could we explain a material AI-assisted decision confidently after something went wrong?
The answers reveal considerably more than whether the organisation has an AI policy.
They reveal whether governance has kept pace with capability.
Seven warning signs AI has moved ahead of governance
1. The board knows the AI strategy but not where AI is actually being used
Strategy without visibility creates false assurance.
2. Management can identify system owners but not decision owners
Technology ownership is not accountability.
3. Human oversight exists on paper but meaningful challenge is rare
The organisation should understand why.
4. Stakeholder impacts are treated as reputational issues rather than governance information
Important consequences may remain outside board reporting.
5. Nobody outside technology knows who can stop a material system
Control authority is unclear.
6. Board reporting focuses on investment and productivity but says little about accountability or impact
Value and responsibility have become separated.
7. AI principles exist, but the organisation cannot demonstrate whether they affect real decisions
Responsible AI has become a statement rather than an operating discipline.
Several of these symptoms together suggest more than an AI risk problem.
They indicate an accountability architecture problem.
Does the board itself have the governance capability AI requires?
Eventually, the discussion returns to board effectiveness.
PwC’s finding that 71 per cent of directors believe their boards need stronger AI skills should prompt more than another training session.
Boards need to examine whether their wider governance architecture can cope with technological change.
Does the board receive decision-useful information?
Are committee responsibilities clear?
Can directors challenge management confidently?
Does the skills matrix reflect emerging risks?
Are significant decisions followed through?
Can bad news move quickly enough?
AI amplifies weaknesses in each of these areas.
The Lumorus Board Health Check provides Chairs and directors with a practical starting point for assessing whether the underlying governance system supports effective oversight.
It is not an AI compliance assessment.
Instead, it examines the board foundations on which credible AI governance depends, including information, capability, challenge, decision making and accountability.
Where deeper assessment is needed, organisations can consider a Governance Review, Board Evaluation & Assessment or Board Skills Audit.
Assess the governance beneath your AI strategy: Take the Lumorus Board Health Check
The Lumorus View
The corporate AI debate is still asking too many technology questions.
How powerful is the model?
How much productivity can we capture?
What are competitors doing?
How quickly can we deploy?
Those questions matter, but governance begins somewhere else.
It begins by asking where power has moved.
AI can influence what people see, which alternatives they consider, how risks are ranked and which recommendation appears most credible.
Increasingly autonomous systems may also possess authority to act.
Once that happens, governance architecture must evolve.
Boards should know where algorithmic influence exists. Management should identify accountable human owners, while meaningful challenge must remain possible.
Stakeholder consequences should be understood rather than discovered after harm occurs.
Decision records need sufficient traceability.
Escalation thresholds should be clear.
Someone must possess authority to stop a system.
Above all, technological complexity cannot become an excuse for accountability ambiguity.
The defining principle of responsible AI should be simple: accountability must travel at least as fast as capability.
If a machine gains greater influence over a material decision, the organisation should become clearer, not less clear, about who owns the judgement and who bears the consequences.
The Bottom Line
The evidence from 2026 is becoming difficult to ignore.
BCG finds substantial tension between boards and CEOs over AI speed, capability and strategic understanding.
PwC reports that 71 per cent of directors believe their boards need stronger AI skills, while 82 per cent see shortcomings in information connecting AI outcomes, risks and business performance.
CGI finds AI adoption advancing faster than governance oversight.
McKinsey emphasises stronger accountability, board fluency and more responsive risk management.
Meanwhile, NIST and the OECD place governance, accountability, human oversight and traceability at the centre of responsible AI.
Taken together, the message is not that boards should slow every AI initiative.
Nor should they accelerate indiscriminately.
The real task is to ensure that organisations can innovate without losing the ability to locate responsibility, understand consequences and constrain power.
Boards need to know where AI operates.
Directors should understand where it influences decisions.
Management must define what remains human.
Stakeholder impacts need to become visible.
People require genuine authority to challenge systems.
Evidence must be preserved.
Someone must be able to stop the technology.
Most importantly, somebody must still own the outcome.
The defining board question of the AI era may therefore be surprisingly old-fashioned:
Who is accountable?
If the answer is a model, a vendor, a process, a committee or everyone collectively, the governance is not yet strong enough.
Continue Exploring
- Understand how board governance strengthens accountability and compliance: Board Governance and Regulatory Compliance
- Assess whether your board has the foundations for emerging-risk oversight: Lumorus Board Health Check
- Review your wider governance architecture: Governance Review
- Evaluate board effectiveness, information and challenge: Board Evaluation & Assessment
- Assess whether the board has the capabilities needed for AI and emerging risks: Board Skills Audit
- Identify material sustainability and responsible-business risks: ESG Materiality & Risk Assessment
- Connect responsible business considerations with organisational strategy: ESG Strategy Development
- Understand stakeholder expectations and impacts: Stakeholder Engagement
- Measure and manage social outcomes: Social Impact Measurement and Management
- Integrate responsible impact into investment decisions: ESG Integration in Investment Decisions
Lumorus: Better Business, Built on Purpose
At Lumorus, we believe responsible technology is ultimately a governance question.
AI can create enormous commercial value. However, organisations also need governance capable of ensuring that innovation remains accountable, material impacts are understood and human responsibility does not disappear behind technological complexity.
Lumorus is a UK headquartered global governance, ESG, Company Secretary and advisory firm supporting organisations across Europe, Africa, Asia, the Caribbean, Canada, the Middle East and international markets.
For organisations navigating AI and other emerging risks, our relevant capabilities include:
Whether an organisation is deploying AI, redesigning its governance architecture or considering the wider impact of technology on employees, customers, investors and society, the challenge is increasingly the same.
Innovation creates capability. Governance determines how that capability is exercised, constrained and held accountable.
A useful starting question for every board is therefore:
Can you identify every material decision AI currently influences, the stakeholders who may be affected and the human being accountable for the outcome?
If not, AI capability may already have moved ahead of governance.
Take the Lumorus Board Health Check or visit Lumorus to strengthen the governance and responsible-impact architecture around emerging technology.
Lumorus: Better Business, Built on Purpose.
Sources
Boston Consulting Group: CEOs and Boards Are Aligned on AI in Theory, but Divided in Practice
BCG’s 2026 global research examines differences between directors and chief executives over AI capability, transformation speed and strategic understanding.
PwC: 2026 Annual Corporate Directors Survey
PwC examines board AI capability, information quality, emerging risk and director confidence.
Chartered Governance Institute UK & Ireland: AI Adoption Is Outpacing Governance Oversight
CGI examines the gap between AI adoption and governance maturity, including board visibility and accountability.
McKinsey & Company: The Board’s Role in Managing Emerging AI Risks
McKinsey examines AI accountability, emerging risks, board fluency and more responsive risk management.
NIST: Artificial Intelligence Risk Management Framework
NIST provides a structured framework for governing, mapping, measuring and managing AI risks.
The OECD principles address human agency, oversight, transparency, accountability, traceability and systematic risk management.
