Son GΓΌncelleme / Last Updated: September 7, 2026
By the Kurums.com Corporate Governance Desk
AI governance in the boardroom has moved from a technology committee side-topic to a core fiduciary duty in 2026. Boards face three converging pressures: regulators now expect documented AI literacy and oversight (the EU AI Act’s general rules took effect August 2, 2026), generative AI has expanded organizational attack surfaces by roughly 67%, and adoption is outpacing policy β 66% of directors already use AI for board work but only 22% of boards have a formal AI usage policy. Directors who cannot show a working oversight process face rising litigation and disclosure risk.
Key Takeaways
What is the single biggest AI governance risk for boards right now? The gap between how fast directors and management are adopting AI tools and how slowly boards are building the policies, committees, and reporting lines needed to oversee that use.
Do boards legally have to understand AI now? In the EU, yes for staff and operators under AI Act Article 4’s literacy obligation; elsewhere it is fast becoming a de facto fiduciary standard even without a named statute.
How much has generative AI increased cyber risk? Industry analysis puts the increase in organizational attack surface at approximately 67%, driven by AI-assisted phishing, data exposure through public chatbots, and expanded software supply chains.
What should a board do in the next quarter? Put AI on the standing board agenda, assign clear oversight ownership (audit, risk, or a dedicated technology committee), and require management to report AI inventory, incidents, and usage-policy compliance at every meeting.
What Is AI Governance in the Boardroom?
AI governance in the boardroom is the set of policies, oversight structures, and reporting practices a board uses to supervise how a company builds, buys, and deploys artificial intelligence, including generative AI. It covers risk, ethics, disclosure, and the board’s own AI use.
Historically this sat with a technology committee that met occasionally. In 2026, advisers describe it as a continuous, board-wide obligation rather than a delegable, episodic check-in β comparable to how cybersecurity oversight evolved a decade earlier. Russell Reynolds Associates, writing on the Harvard Law School Forum on Corporate Governance in March 2026, notes boards globally are now expected to demonstrate baseline AI literacy to capture opportunity while containing material risk.
Why Are Boards Under Pressure to Build AI Literacy in 2026?
Boards face pressure because AI use inside companies has scaled faster than director understanding of it, creating a widening gap between how AI is deployed and how well it is supervised at the top.
Directors are using AI to digest board materials, benchmark peers, and run scenario planning, narrowing the information gap between management and the board when handled carefully, per the Harvard Forum’s February 2026 trends review. The takeaway: AI literacy is no longer optional for director recruitment; search committees now actively screen for it.
Diligent’s 2026 governance research finds 66% of directors now use AI for some aspect of board work, and 50% use it for meeting preparation β yet only 22% of boards have adopted a formal AI usage policy. That imbalance is why literacy has jumped up the agenda: directors already rely on tools whose confidentiality, accuracy, and bias limits most boards have not formally assessed.
| Metric | 2026 Figure | Source |
|---|---|---|
| Directors using AI for board work | 66% | Diligent, 2026 governance trends |
| Boards with a formal AI usage policy | 22% | Diligent, 2026 governance trends |
| Boards integrating AI into oversight activities | 35% | PwC director survey, cited by Harvard Law School Forum |
| Increase in attack surface attributed to generative AI | ~67% | Diligent, 2026 governance trends |
| Projected global data breach cost by 2028 | $13.82 trillion | Diligent, 2026 governance trends |
What New AI Regulatory Requirements Take Effect for Boards in 2026?
Several binding obligations reach corporate boards in 2026, most notably the EU AI Act’s general application on August 2, 2026, alongside AI-specific supervisory board guidance emerging in individual European markets.
The EU AI Act’s literacy obligation under Article 4 has technically been in force since February 2, 2025, requiring organizations to ensure staff and anyone operating AI systems on their behalf have sufficient understanding of the technology. The bigger inflection point is August 2, 2026, when most remaining general provisions became applicable, expanding documentation, transparency, and human-oversight expectations for companies serving the EU market. Russell Reynolds Associates noted in Harvard’s March 2026 roundup that several European jurisdictions, including Germany, are issuing supervisory-board guidance treating AI oversight as a growing, non-delegable responsibility. Outside the EU, state-level AI statutes in the U.S. continue to proliferate, raising the stakes of a defensible oversight record even without a single federal AI law.
For a deeper walkthrough of what the August 2026 milestone specifically requires, see kurums.com’s dedicated analysis of the EU AI Act’s August 2026 enforcement requirements for boards.
How Is Generative AI Increasing Cyber Risk for Companies?
Generative AI increases cyber risk by giving attackers faster tools to craft convincing phishing, clone voices and documents, and probe for weaknesses, while also creating new internal exposure through employees pasting sensitive data into public chatbots.
Diligent’s 2026 research estimates generative AI has expanded organizations’ overall attack surface by approximately 67%, and separately projects global data breach costs will climb from about $9.22 trillion in 2024 to $13.82 trillion by 2028. The takeaway for boards: cyber risk oversight and AI oversight can no longer sit on separate committee agendas, since the same generative tools that boost productivity also expand exposure. Cyber breaches now rank among the top organizational risks directors track, and Diligent flags cybersecurity as the single most “underrated risk” boards carry into 2026.
A quieter risk is data leakage: directors who feed confidential board materials into consumer-grade AI chatbots create exposure traditional cyber controls were never built to catch β a guardrail the Harvard Forum’s February 2026 review says boards need to set for their own conduct, not only management’s.
What Should a Board’s AI Oversight Framework Include?
An effective AI oversight framework should include a current inventory of where AI is used, named ownership of AI risk at the board level, a written usage policy, incident reporting, and periodic independent review of management’s own AI governance claims.
- AI inventory and classification: a maintained list of where AI and generative AI tools are deployed internally and in products, tiered by risk level.
- Clear ownership: a specific committee (audit, risk, or technology) or the full board holds explicit responsibility for AI oversight, with the assignment written into the committee charter rather than left implicit.
- A board-level usage policy: rules covering what data can and cannot be entered into AI tools, including tools directors themselves use to prepare for meetings.
- Human-in-the-loop verification: confirmation that human review of AI-assisted decisions is operating in practice, not simply documented on paper, particularly for decisions touching employment, credit, or safety.
- Recurring reporting cadence: AI risk, incidents, and policy compliance appear on the board agenda at defined intervals rather than only when a problem surfaces.
Only around 23% of boards currently make even moderate use of AI-powered dashboards for their own risk oversight work, per Diligent’s 2026 data β meaning most boards still supervise a fast-moving risk with slow, manual reporting tools.
How Are Boards Using AI Themselves, and What Are the Risks?
Boards increasingly use AI to summarize lengthy board packs, benchmark against peer companies, and model scenarios, but the same tools introduce confidentiality, accuracy, and bias risks that require explicit safeguards.
Used carefully, AI can compress hours of pre-read material into a workable briefing and surface questions a director might miss, closing part of the information gap described in Harvard’s February 2026 coverage. The risk: outputs can be confidently wrong, can encode bias, and β if fed non-public information β create data-handling exposure that never existed with a printed board pack. Most advisers recommend disclosure of which tools directors use, plus basic training on their limitations, rather than an outright ban.
What Happens When a Board Fails at AI Oversight?
Boards that fail at AI oversight face two escalating consequences in 2026: securities litigation tied to AI-related disclosures, and renewed judicial scrutiny of whether directors met their duty to monitor known risks.
Cooley LLP’s August 2026 litigation-trends analysis, published on the Harvard Law School Forum, documents a surge in securities class actions built around AI-related disclosures, with alleged investor losses and settlement values both climbing through 2026. Separately, a September 2026 Delaware decision in the Boeing matter, also covered on the Forum, narrowed potential Caremark oversight liability for directors in a manufacturing-safety context; governance lawyers are watching for how that reasoning might extend to AI-oversight claims, since Caremark liability turns on whether a board had β and used β a system for monitoring known, mission-critical risks. The takeaway: a documented, functioning monitoring system separates defensible oversight from a plausible Caremark claim.
How Should Boards Structure AI Committees and Reporting Lines?
Most boards should extend an existing committee’s mandate, typically audit, risk, or technology, to cover AI explicitly, rather than creating a brand-new standing committee, unless AI is central to the company’s core business.
Extending an existing committee keeps AI oversight connected to the broader enterprise risk process instead of siloing it, while the full board still receives periodic summaries. Diligent’s 2026 data shows directors now rank AI deployment as their second-highest organizational priority and top area for planned capital investment β reason enough for the full board, not just one committee, to see how that investment is being risk-managed, not only how it performs financially.
What Questions Should Directors Ask Management About AI Risk?
Directors should ask where AI is deployed today, what data feeds it, who is accountable if it fails, how incidents are detected, and how the company’s usage policy is enforced in practice rather than only on paper.
Useful standing questions: What is our current AI inventory, and how often is it updated? Which AI decisions still require human sign-off, and how do we verify that? What did our most recent AI-related security incident look like, and what changed afterward? How does our policy address employees pasting confidential data into external chatbots?
Frequently Asked Questions
Is AI governance now a legal requirement for corporate boards?
In the EU, AI literacy and oversight obligations are legally binding under the AI Act, with general provisions applicable from August 2, 2026. In most other jurisdictions it is not yet a standalone statute but is increasingly treated as part of existing fiduciary duty of oversight standards.
What percentage of directors already use AI tools?
Diligent’s 2026 governance research found 66% of directors use AI for some form of board work and 50% use it specifically to prepare for meetings, while only 22% of boards have a formal policy governing that use.
How much has generative AI increased cybersecurity risk?
Industry analysis from Diligent estimates generative AI has expanded organizational attack surfaces by approximately 67%, driven by AI-enabled phishing, deepfakes, and new data-exposure pathways through public AI tools.
Should every board create a separate AI committee?
Not necessarily. Most boards fold AI oversight into an existing audit, risk, or technology committee’s mandate and report to the full board periodically, reserving a standalone AI committee for companies where AI is central to the core business.
What is the single most important first step for a board with no formal AI oversight yet?
Commission a current inventory of where AI and generative AI are used across the business, then assign explicit board-level ownership for reviewing that inventory on a recurring schedule, before drafting policy language.
Does the EU AI Act apply to non-EU companies?
Yes. The Act applies to any organization whose AI systems affect people in the EU, regardless of where the company is headquartered, which is why non-EU boards are also reviewing their exposure ahead of the August 2026 enforcement milestone.
For related governance context, kurums.com’s Corporate Governance desk has also covered the widening gap between AI adoption and board oversight readiness and the fundamentals of how board structure and director responsibilities work. For the full library of governance guides, visit the Corporate Governance department hub.
Sources
- Harvard Law School Forum on Corporate Governance, “2026 Corporate Governance Trends to Watch” (Feb 8, 2026) β corpgov.law.harvard.edu
- Harvard Law School Forum on Corporate Governance, “Global Corporate Governance Trends for 2026,” Russell Reynolds Associates (Mar 23, 2026) β corpgov.law.harvard.edu
- Diligent, “Corporate Governance Trends 2026: AI, Cyber and ESG” β diligent.com
- White & Case, “2026 Horizon Scanning β What General Counsel and Company Secretaries Need to Know for 2026” β whitecase.com
- Harvard Law School Forum on Corporate Governance, “Securities Class Action Trends: AI Filings Surge, Alleged Losses and Settlement Values Climb,” Cooley LLP (Aug 30, 2026) β corpgov.law.harvard.edu
- Harvard Law School Forum on Corporate Governance, “Boeing Decision Appears to Narrow Potential Caremark Liability for Directors and Officers,” Fried Frank (Sep 6, 2026) β corpgov.law.harvard.edu
- WilmerHale, “Board Oversight and Artificial Intelligence: Key Governance Priorities for 2026” β wilmerhale.com
Discover more from Kurums | Business Intelligence
Subscribe to get the latest posts sent to your email.

