The people building and backing artificial intelligence are increasingly asking governments to govern it before its most serious risks become harder to contain
The debate over artificial intelligence regulation has shifted.
Only a few years ago, much of the argument focused on whether governments might regulate AI too quickly and constrain innovation. In September 2026, some of the industry’s most prominent figures were discussing something different: whether development of the most advanced systems should itself be paced so that safety mechanisms, institutions and regulation can catch up.
Anthropic chief executive Dario Amodei, whose company develops Claude, became one of the most prominent voices in that debate when he called for the AI industry to slow the rate at which frontier capabilities improve. Reporting by The Washington Post said OpenAI chief executive Sam Altman and Elon Musk subsequently expressed support for the broad concern, although major questions remain around implementation, competition and international coordination.
Amodei’s intervention did not emerge in isolation. Anthropic’s Advanced AI Framework argues for a regulatory ladder in which obligations become stronger as AI capability and risk increase. At higher levels, Anthropic proposes independent evaluation, stronger incident reporting, robust security requirements and, in extreme circumstances, legal authority for governments to block or deter dangerous deployments.
Bill Gates is approaching the same problem from a wider institutional perspective. In his August 2026 essay The turbulent AI era is here. The choices we make now are critical, Gates argues that governments need stronger national and international frameworks for AI because the technology could affect employment, education, healthcare, taxation, security and the distribution of economic gains at the same time.
Meanwhile, regulation is no longer theoretical. The European Union’s AI Act has moved further into implementation, with transparency obligations under Article 50 applying from 2 August 2026. The European Commission has also issued detailed guidance for providers and deployers on how those obligations should operate.
These approaches differ considerably.
Some concentrate on catastrophic frontier-model risks. Others focus on employment, inequality and institutional adaptation. Regulators are also addressing transparency, high-risk applications, safety evaluation and consumer protection.
However, they increasingly converge on one central proposition:
AI cannot be governed through technology companies acting alone.
For boards, this debate is not abstract.
Organisations are already deploying AI into recruitment, customer service, financial decisions, cybersecurity, legal work, healthcare, marketing and internal operations.
The governance question has therefore arrived before regulatory certainty.
Who inside your organisation is accountable for what AI is allowed to do?
Read More: Corporate Governance Support
Executive Takeaway
The current AI regulation debate is producing several distinct proposals.
Dario Amodei and Anthropic are arguing for risk-based frontier AI regulation
Their proposals include:
- Capability-based regulation
- Mandatory safety evaluation
- Independent external testing
- Public transparency around catastrophic-risk assessments
- Stronger cybersecurity around advanced models
- Serious-incident reporting
- Government powers to restrict exceptionally dangerous deployments
- Regulatory obligations that increase as capabilities increase
Anthropic’s own policy material states that frontier AI companies should not be the only parties deciding whether their systems are safe and argues for external testing, transparency and stronger government oversight as capability increases.
Bill Gates is arguing for wider institutional redesign
His proposals extend beyond model safety and include:
- Stronger national coordination across government
- International AI governance mechanisms
- Workforce transition planning
- Stronger support for displaced workers
- Debate over activities that should remain human led
- Potential taxation of AI and robotics
- Greater attention to how AI’s economic benefits are distributed
Gates also says he would likely support a credible global slowdown in AI development, although he doubts geopolitical and economic incentives would make such an agreement easy to achieve.
OpenAI is calling for mandatory frontier AI safety requirements
In September 2026, OpenAI publicly supported mandatory, capability-based national AI safety regulation, alongside independent safety assessments and stronger safety infrastructure.
The European Union is already implementing binding regulation
The EU AI Act uses a risk-based framework and now imposes specific transparency obligations on certain providers and deployers, with Article 50 applying from 2 August 2026.
Despite substantial disagreement over detail, one idea increasingly sits at the centre of the debate:
AI risk needs institutional accountability, not simply voluntary promises.
For companies deploying AI, that creates another question.
Even where regulation has not yet required a particular control, should the board already expect one?
Why this debate has suddenly become more urgent
AI regulation has been debated for years.
What has changed is capability.
Frontier AI systems are becoming more capable in coding, cybersecurity, scientific research, reasoning and autonomous task execution. Consequently, the policy discussion is moving from hypothetical harms towards questions about systems that could perform increasingly complex activities with less direct human intervention.
Anthropic’s Responsible Scaling Policy reflects this development by linking stronger safeguards with increasing model capabilities and associated risks. Its related roadmap also envisages deeper external testing, stronger incident reporting and more intensive government oversight as risk rises.
That principle now appears repeatedly across the wider regulatory debate:
The more capable the system becomes, the stronger the governance should become.
This sounds straightforward.
Implementing it is much harder.
Governments still need to determine:
- Which capabilities trigger regulation
- Who tests them
- Which companies fall within scope
- Which evaluation methods are sufficiently reliable
- How confidential model information is protected
- What happens when a model fails a safety test
- Who can restrict deployment
- How obligations apply across borders
The result is a regulatory problem unlike most traditional corporate regulation.
AI capability can change considerably between legislative cycles.
The law therefore needs to govern something that may evolve faster than the rules themselves.
1. Dario Amodei’s central argument: regulate capability, not simply technology
Anthropic has become one of the strongest corporate advocates for formal frontier AI regulation.
Its position is not that every AI system should face identical requirements.
Instead, Anthropic argues for a regulatory ladder, under which regulation becomes progressively stronger as models become more capable and risks become more significant.
That approach attempts to solve an important regulatory problem.
A customer-service chatbot should not necessarily be governed in the same way as a frontier model capable of sophisticated cyber operations or other high-consequence activity.
Risk-based regulation therefore asks a different question:
What can the system actually do?
Under Anthropic’s approach, increasingly capable frontier models could face requirements involving:
- Safety testing
- Independent evaluation
- Security
- Transparency
- Incident reporting
- Risk mitigation
- Government supervision
At sufficiently serious levels of risk, Anthropic argues that governments should have legal authority to block or deter dangerous deployments.
For corporate boards, this principle travels well beyond frontier-model developers.
Organisations deploying AI should also distinguish between low-risk and high-risk uses.
An employee using AI to reformat an internal document creates a very different governance problem from AI influencing:
- Credit decisions
- Recruitment
- Medical recommendations
- Financial advice
- Critical infrastructure
- Customer eligibility
- Fraud investigations
- Safety-critical processes
The governance response should rise with the consequence of failure.
2. Amodei’s newer argument goes further: the frontier itself may need pacing
The September 2026 debate introduced a more controversial proposition.
According to The Washington Post, Amodei called for slowing the pace of frontier capability development so that safety measures could catch up. Sam Altman and Elon Musk expressed support for the broad concern, although significant practical questions remain around how an industry-wide slowdown could operate.
Anthropic has also committed to deeper third-party scrutiny. Its recent research on measuring the pace of AI development says the company plans to embed independent evaluators with access comparable to internal risk-assessment teams so they can verify safety practices, report incidents and monitor important development metrics.
This matters from a corporate governance perspective.
Independent scrutiny is not unusual elsewhere.
Auditors challenge financial reporting.
Independent directors challenge executives.
Regulators supervise financial institutions.
Safety regulators inspect high-risk industries.
AI is confronting the same institutional question.
At what point does internal assurance cease to be enough?
A company developing a highly capable model has strong incentives to ensure it is safe.
It also has powerful commercial incentives to release it.
Those incentives can coexist.
That is precisely why independent challenge can matter.
3. Bill Gates is asking a wider question: can existing institutions govern the AI transition at all?
Bill Gates approaches the problem differently.
His August 2026 Gates Notes essay does not focus only on catastrophic frontier-model safety.
Instead, Gates argues that AI could transform employment, taxation, education, healthcare, national security, public services and the distribution of wealth simultaneously. He says governments should prepare for that broader social and economic transition rather than treating each consequence in isolation.
His conclusion is institutional.
Existing structures may struggle to govern a technology whose effects cut across multiple policy areas at once.
Gates therefore argues for stronger national coordination and an international framework capable of addressing risks that cross borders.
This is a fundamentally different regulatory idea.
Amodei asks:
How should governments control exceptionally capable AI models?
Gates asks:
How should society govern the transition created by AI itself?
Both questions matter.
A safe frontier model could still create substantial labour-market disruption.
A well-regulated AI company could still contribute to wider inequality if the economic benefits from automation are distributed narrowly.
Governance therefore operates on at least two levels.
One concerns the safety of the technology.
The other concerns the consequences of deploying it across society.
4. Gates wants policymakers to prepare for labour disruption before it arrives
Employment sits at the centre of Gates’s argument.
He believes AI may displace significant categories of cognitive work more quickly than previous technological transitions, particularly as systems become capable of performing work that previously required human cognition.
The precise scale and timing remain uncertain.
However, the governance problem is already relevant to boards.
Organisations adopting AI should ask:
- Which jobs will change?
- Which roles may shrink or disappear?
- Which employees require retraining?
- Where should human judgement remain mandatory?
- How will productivity gains be used?
- Which workforce risks should reach the board?
- What responsibility does the company have during transition?
These are not simply HR questions.
They concern organisational design, culture, incentives, reputation and long-term legitimacy.
A board approving a major AI transformation should therefore understand both sides of the investment case.
What productivity does AI create, and what organisational consequences follow?
5. Human Reserved work raises a difficult governance question
One of Gates’s more distinctive ideas concerns activities society may decide should remain substantially human even where machines could technically perform them.
His argument is not that automation should be rejected.
Rather, some areas may carry intrinsic human value or require continuing human responsibility.
That idea will remain contested.
Businesses may worry about competitiveness, while economists may question deliberate constraints on productivity. Others may argue that healthcare, education, justice, caregiving and other high-consequence activities require forms of human accountability that should not disappear simply because automation becomes possible.
Boards do not need to wait for governments to settle this debate.
They can already identify activities where meaningful human involvement should remain.
Examples might include:
- Final hiring decisions
- Employee disciplinary decisions
- High-impact customer complaints
- Medical or safety decisions
- Material investment judgements
- Whistleblowing investigations
- Significant credit decisions
- Board decisions
The right boundary will differ by organisation.
What matters is that somebody deliberately sets it.
6. Gates’s tax argument puts distribution at the centre of AI governance
Gates has also revived his argument that tax systems may need to change when machines replace human labour.
His August 2026 essay again supports the idea of taxing robots and discusses wider fiscal questions around AI, while emphasising the need to direct additional support towards workers and communities affected by automation.
This is a policy proposal rather than an established consensus.
Critics may argue that such taxes could slow productivity growth, create difficult measurement problems or weaken competitiveness.
Supporters may contend that automation could shift economic returns from labour towards capital and that tax systems should adapt accordingly.
The governance significance lies in the underlying question:
Who captures the gains from AI?
That question will increasingly reach boards.
AI investment may reduce costs and improve margins, yet organisations will also face decisions about:
- Workforce transition
- Reskilling
- Employee participation
- Productivity sharing
- Community impacts
- Tax
- Social licence
AI governance is therefore unlikely to remain confined to cybersecurity and model accuracy.
It will increasingly involve the economic consequences of automation.
7. OpenAI is also calling for mandatory regulation, not voluntary commitments alone
The current debate is notable because calls for mandatory regulation are now coming from several major developers.
In September 2026, OpenAI said it supports mandatory, capability-based national AI safety regulation. Its proposals include stronger national requirements and support for independent safety assessments.
The significance is not that major AI companies agree on every regulatory detail.
They do not.
Rather, several leading developers increasingly accept that voluntary corporate policies may not be sufficient for the most capable systems.
That is a meaningful shift in the governance debate.
8. Europe has moved beyond debate and into implementation
The European Union provides the clearest example of binding risk-based AI regulation already operating.
From 2 August 2026, transparency obligations under Article 50 of the AI Act began to apply to relevant providers and deployers. The European Commission’s guidance explains how those obligations apply and how enforcement will operate.
The EU framework distinguishes among different risk levels rather than regulating every AI system identically.
For multinational organisations, this matters even where headquarters sits elsewhere.
A business deploying AI in Europe may need to understand:
- Which AI systems it uses
- Where they operate
- What they are used for
- Which vendors provide them
- Whether relevant risk classifications apply
- Which documentation exists
- How human oversight works
- Whether transparency obligations are satisfied
The regulatory question increasingly begins with something basic:
Do we actually know where AI is being used inside the organisation?
9. AI regulation is moving towards testing rather than assertion
One of the strongest themes across current AI policy is the move towards evidence.
It is increasingly insufficient for an organisation simply to state that an AI system is safe, responsible or appropriately governed.
Regulators and policymakers are increasingly interested in how those claims were tested.
Anthropic’s Advanced AI Framework calls for independent evaluation of sufficiently advanced frontier systems, while OpenAI is supporting stronger independent safety assessment.
This matters because AI governance contains a structural conflict.
Developers know their systems better than almost anyone.
Yet developers also benefit commercially from deployment.
Self-assessment therefore remains necessary, but it may not always be sufficient.
Boards should apply the same logic internally.
Where AI can materially affect people, assets or regulatory outcomes, assurance should not depend exclusively on the team that developed or purchased the system.
Depending on the risk, challenge might come from:
- Risk
- Compliance
- Legal
- Internal audit
- Cybersecurity
- Independent specialists
- External assurance
The higher the consequence of failure, the stronger the case for independent challenge.
10. Incident reporting could become a core AI governance control
Another theme gaining momentum is serious-incident reporting.
The rationale is straightforward.
Regulators cannot understand emerging risk if material failures remain within individual companies.
OpenAI’s September 2026 policy proposal supports mandatory national AI safety requirements, while Anthropic’s framework argues for stronger incident reporting as model capability rises.
For companies using AI, this raises an immediate governance question.
What counts as an AI incident?
Possibilities include:
- Harmful autonomous behaviour
- Significant model errors
- Discriminatory outcomes
- Data exposure
- Security breaches
- Manipulative behaviour
- False decisions affecting customers
- Failed human oversight
- Use outside approved purposes
Organisations need incident definitions before they need incident statistics.
Without clear escalation criteria, serious AI failures may remain classified as isolated operational problems rather than governance events.
11. AI regulation increasingly intersects with cybersecurity
The connection between AI and cyber risk is becoming harder to separate.
Advanced models can strengthen cyber defence.
They can also increase offensive capability or gain access to systems and information that create new vulnerabilities.
Anthropic’s policy work explicitly identifies advanced cyber operations among the serious risks governments should consider when governing frontier AI.
For boards, the implications extend well beyond AI developers.
Corporate AI tools may have access to:
- Source code
- Customer information
- Financial systems
- Board documents
- Employee data
- Intellectual property
- Operational infrastructure
Agentic systems raise the stakes further because they can take actions rather than merely generate information.
The board should therefore understand not only:
What can our AI read?
but also:
What can our AI do?
That distinction may become one of the defining governance questions of agentic AI.
12. International coordination may prove harder than national regulation
Both Gates and leading AI developers increasingly discuss international coordination.
The rationale is obvious.
Models cross borders.
Research travels.
Compute infrastructure spans jurisdictions.
Cyber and other high-consequence risks are international.
Yet global regulation is difficult because countries have different economic interests, national-security priorities and technological strategies.
Amodei’s proposed slowdown has already exposed that difficulty. The Washington Post reported opposition from the current US administration and scepticism from China, illustrating how geopolitical competition can complicate international coordination even where some industry leaders favour common safeguards.
For multinational boards, the likely result is regulatory fragmentation before regulatory convergence.
Organisations should therefore expect overlapping regimes rather than waiting for one global AI rulebook.
What the main proposals have in common
The debate contains substantial disagreement, yet several recurring principles are emerging.

This is not yet a global regulatory settlement.
It is the outline of one.
Where the stakeholders still disagree
The differences remain significant.
How much should development itself be slowed?
Calls to pace frontier development are more interventionist than many earlier AI-policy proposals.
How powerful should regulators become?
Anthropic’s advanced proposals envisage meaningful government authority over dangerous deployment. Other stakeholders may prefer narrower intervention.
How should economic disruption be addressed?
Gates places particularly strong emphasis on jobs, social protection and taxation, while technical safety frameworks concentrate more heavily on model capability and catastrophic risk.
How should governments balance innovation and safety?
Different jurisdictions are taking different approaches, and the trade-off remains contested.
How should international competition be handled?
National-security and economic competition make global coordination particularly difficult.
How much regulation is proportionate?
Requirements appropriate for frontier laboratories may be unnecessarily burdensome for low-risk business applications.
These are genuine policy choices.
For corporate boards, however, one practical point remains constant.
Regulatory uncertainty does not remove AI accountability.
The board should not wait for the final AI law
This may be the most important corporate-governance lesson from the current debate.
Boards cannot outsource responsibility to future regulation.
If an organisation is already using AI materially, governance already needs to exist.
At minimum, boards should expect management to answer:
- Where are we using AI?
- Which uses could materially affect people or the business?
- Who is accountable for each system?
- What data does it access?
- Which decisions can it make or influence?
- Where is human review required?
- How was the system tested?
- How do we monitor performance after deployment?
- What constitutes an AI incident?
- How are incidents escalated?
- Which laws apply in each jurisdiction?
- Can we stop or isolate the system if something goes wrong?
If the organisation cannot answer those questions, the governance problem exists regardless of whether the regulator has arrived.
Before regulating the technology, boards should test the governance around it
The current AI debate contains a useful lesson for boards.
Regulators are debating whether AI development is moving faster than society’s capacity to supervise it.
Boards should ask whether the same gap exists inside their own organisations.
Perhaps the business has adopted AI rapidly, yet board oversight remains unclear.
Maybe directors receive technology updates but have never assessed whether decision rights, skills, information flows and escalation arrangements remain fit for purpose.
In other organisations, AI may simply expose weaknesses that already existed before the technology arrived.
That is where a broader board diagnostic can be useful.
The Lumorus Board Health Check provides boards, Chairs, Company Secretaries and governance leaders with a practical starting point for examining how well the board itself is operating.
It can help prompt discussion around questions such as:
- Does the board have the right mix of skills for emerging technology risk?
- Is accountability sufficiently clear?
- Does management provide information that supports effective challenge?
- Are major risks reaching the board early enough?
- Do committees have clear responsibilities?
- Are important decisions followed through?
- Can directors challenge management constructively?
- Is the governance architecture keeping pace with organisational change?
The Board Health Check is not an AI compliance assessment and should not be treated as regulatory assurance.
Its value is different.
AI can expose governance weaknesses that were already present. The Board Health Check helps boards ask whether the underlying governance system is strong enough to deal with the next wave of complexity.
Assess your board: Take the Lumorus Board Health Check
A board-level AI governance architecture
Organisations can begin by structuring oversight around the AI lifecycle.

This does not require the entire board to become technically expert.
It does require directors to understand how accountability operates.
Seven warning signs your organisation is moving faster on AI than on governance
1. Nobody can produce a reliable inventory of AI use
Shadow AI makes governance difficult if management cannot identify where systems are operating.
2. AI pilots can become permanent without formal approval
Experimentation should not quietly become operational dependency.
3. Human oversight is assumed rather than defined
A person technically being present does not mean meaningful human control exists.
4. Vendor assurances substitute for internal assessment
A third-party system can still create first-party accountability.
5. AI incidents have no dedicated escalation route
Serious failures may disappear into ordinary operational reporting.
6. Workforce consequences are absent from AI investment proposals
Productivity assumptions should not ignore organisational transition.
7. The board receives technology presentations rather than governance information
Directors need decisions, accountability, controls and risk, not simply demonstrations of capability.
Several of these signs together indicate that AI adoption may have moved ahead of governance capability.
What boards can learn from Amodei, Gates and the wider regulatory debate
Different proposals point towards several practical lessons.
First, scale governance with risk
Low-consequence automation does not require the same controls as systems making material decisions.
Second, separate innovation from self-supervision
The people developing or deploying AI should not always be the only people judging its risks.
Third, govern the consequences, not simply the model
Workforce, customers, communities and inequality can matter alongside technical performance.
Fourth, build escalation before an incident
Governance designed after failure is crisis management.
Fifth, preserve accountability
AI may execute tasks autonomously.
The organisation must not become autonomous from responsibility.
Why this is ultimately a corporate governance issue
AI regulation is often discussed as technology policy.
For boards, its deeper significance is governance.
AI changes the allocation of decision-making power.
Activities previously performed by employees may increasingly be performed by systems.
Judgements once made by managers may become automated recommendations.
Information that once flowed through people may move directly between AI agents and digital infrastructure.
As that happens, boards need to ask:
Where has authority moved?
That is the governance question.
If authority moves from humans to systems while accountability remains vague, the organisation creates a governance gap.
Regulation will eventually define some of those boundaries.
Boards must define the others.
Read More: Governance Review
The Lumorus View
The most important question in AI regulation is not whether governments should regulate innovation. It is whether power can move into increasingly autonomous systems without an equivalent increase in accountability.
That is the issue boards should focus on.
Dario Amodei’s proposals concentrate attention on the most powerful models and the safeguards surrounding them.
Bill Gates broadens the discussion towards institutions, workers and economic distribution.
OpenAI is arguing for mandatory frontier-safety requirements.
The European Union is already implementing legally binding requirements.
These approaches differ, and governments will continue to make different choices about regulation, competitiveness and acceptable risk.
For companies, however, several principles are already clear.
Authority needs to be visible.
High-risk use needs stronger controls.
Human responsibility needs to remain identifiable.
Independent challenge should increase with consequence.
Boards also need evidence that the organisation understands where AI operates and what happens when it fails.
Technology may develop faster than governance.
That is precisely why governance matters.
How healthy is your board’s governance before AI increases the pressure?
AI governance does not sit in isolation.
It depends on whether the board already has strong foundations around skills, information, challenge, accountability, risk oversight and decision follow-through.
A sophisticated AI policy will achieve little if directors do not receive the right information.
Clear AI responsibilities will still fail if material issues do not reach the board.
Strong technical controls can also be undermined where committee responsibilities are blurred or challenge is weak.
Before adding another AI governance layer, boards should therefore ask whether the underlying governance architecture is healthy enough to support it.
The Lumorus Board Health Check provides a practical diagnostic starting point.
It can help boards identify potential strengths and areas that may deserve deeper examination before rapid technological change places additional pressure on existing governance.
The assessment can be particularly useful for boards asking:
- Do we have the right capabilities for the next stage of technological change?
- Is challenge sufficiently effective?
- Are risk responsibilities understood?
- Do directors receive decision-useful information?
- Are board and committee roles clear?
- Does the organisation follow important decisions through?
- Is our governance model resilient enough for faster change?
Where the diagnostic identifies more significant concerns, boards can then consider a deeper Governance Review, Board Evaluation & Assessment or Board Skills Audit.
This creates a proportionate pathway:
Assess → Understand → Prioritise → Improve → Reassess
Start with your board: Take the Lumorus Board Health Check
The Bottom Line
AI regulation has become one of the defining governance debates of 2026.
In September, Anthropic chief executive Dario Amodei called for pacing frontier AI development so that safety measures could better keep up, while other prominent industry leaders expressed support for the broad concern.
Anthropic is separately advocating capability-based regulation, independent evaluation, transparency, stronger security and government powers for the most dangerous frontier systems.
Bill Gates has widened the discussion further, arguing for national and international institutional responses, workforce-transition planning and policy choices addressing the distributional effects of AI.
OpenAI is publicly supporting mandatory capability-based AI safety regulation, while the EU AI Act is already imposing binding requirements on parts of the AI ecosystem.
The regulatory answers remain contested.
The governance direction is much clearer.
Boards should expect more focus on:
- Risk-based regulation
- Independent testing
- Transparency
- AI incident reporting
- Human oversight
- Cybersecurity
- Board accountability
- International coordination
- Workforce impacts
- Evidence of AI risk management
The immediate board response should not be panic, nor should it be passive waiting for the final law.
It should be stronger governance.
Start by understanding where AI is already operating, who owns the risk, which decisions require human oversight and whether directors themselves have the information, capability and governance architecture required to provide meaningful challenge.
Then test the board.
Take the Lumorus Board Health Check to identify potential strengths and governance gaps before AI complexity exposes them under greater pressure.
The central question is no longer whether AI regulation is coming. It is whether accountability is keeping pace with the power organisations are already giving AI.
Continue Exploring
- Assess the current health of your board: Lumorus Board Health Check
- Review whether your governance architecture is ready for AI: Governance Review
- Strengthen board oversight and governance structures: Corporate Governance Support
- Assess whether your board has the skills required for AI-era governance: Board Skills Audit
- Evaluate the effectiveness of board oversight: Board Evaluation & Assessment
- Improve board information, decisions and meeting governance: Board & Shareholder Meetings
- Strengthen regulatory monitoring and compliance: Statutory & Regulatory Compliance
What should boards do now?
Waiting for complete regulatory certainty would leave organisations exposed to risks they are already creating.
Boards can begin with six practical actions.
1. Establish an AI inventory
Identify material AI systems, vendors, applications and business processes across the organisation.
2. Classify risk
Separate low-risk productivity tools from systems capable of affecting people, assets, regulated decisions or critical operations.
3. Clarify accountability
Every material AI system should have a named executive owner, clearly defined approval route and escalation process.
4. Define human oversight
State explicitly where human judgement must remain and what meaningful human intervention requires.
5. Test the governance system
Ask whether the organisation could explain to a regulator, customer or employee how a material AI decision was made, reviewed and challenged.
6. Test the board itself
AI governance will only be as strong as the board providing oversight.
Use the Lumorus Board Health Check to assess whether board composition, information, challenge, accountability and decision processes are strong enough to deal with rapidly changing technology.
If those foundations are weak, another AI policy will not solve the problem.
The board’s governance architecture needs attention.
Lumorus: Governance for the AI Era
Lumorus is a UK headquartered global governance, ESG, Company Secretary and advisory firm supporting organisations across Europe, Africa, Asia, the Caribbean, Canada, the Middle East and international markets.
AI raises a governance problem before it raises a compliance problem.
As technology becomes more capable, organisations need stronger clarity around:
- Decision rights
- Board oversight
- Risk ownership
- Delegated authority
- Information flows
- Internal controls
- Human accountability
- Regulatory monitoring
- Board competence
- Assurance
Lumorus helps boards and leadership teams examine whether governance arrangements remain fit for organisations in which technology increasingly influences decisions and execution.
Our governance capabilities include:
The Lumorus Board Health Check provides a lower-friction starting point for boards that want an initial view of governance health before considering deeper independent evaluation or review. Lumorus describes the diagnostic as a way to assess board effectiveness, governance maturity and improvement priorities.
Could your board explain today who is accountable for every material AI system operating inside your organisation, and demonstrate that directors themselves are equipped to provide effective oversight?
If the answer is uncertain, waiting for the next regulation will not solve the underlying issue.
Start by examining the board.
Take the Lumorus Board Health Check or explore Lumorus to strengthen board oversight, AI-era accountability and governance readiness.
Lumorus: Better Business, Built on Purpose.
Sources
- Anthropic: Advanced AI Framework – Anthropic’s proposals for capability-based regulation of highly advanced AI, including independent evaluation and government authority concerning dangerous deployments.
- Anthropic: AI Policy – Anthropic’s current policy priorities covering model safety, transparency, external oversight and catastrophic-risk governance.
- Anthropic: Frontier Safety Roadmap – Anthropic’s current roadmap for safety research, model oversight and its policy approach to increasingly capable AI.
- Anthropic: Measuring the Pace of AI Development – Current work on independent third-party evaluators and greater external visibility into frontier AI development.
- The Washington Post: Top AI leaders unite to warn the technology is advancing too fast – September 2026 reporting on Dario Amodei’s call to pace frontier development and responses from other AI leaders.
- Bill Gates: The turbulent AI era is here. The choices we make now are critical – Gates’s August 2026 analysis of AI, employment, public institutions, taxation and international coordination.
- OpenAI: The AI Policy Window Is Open – OpenAI’s September 2026 support for mandatory capability-based national AI safety regulation and independent safety assessment.
- European Commission: Transparency Obligations Under Article 50 of the AI Act – Current Commission guidance confirming the application of Article 50 transparency obligations from 2 August 2026.
- European Commission: Guidelines on AI Act Transparency Obligations – Practical guidance for providers and deployers on implementing the AI Act’s transparency requirements.
- Lumorus: Board Effectiveness Reviews for FCA-Regulated Firms – Lumorus analysis of board effectiveness, governance evidence and the role of the Board Health Check as an initial diagnostic.
- Lumorus Board Health Check – Board diagnostic designed to help boards and governance leaders assess board health, governance maturity and areas that may require deeper examination.
