Picture a fairly ordinary risk committee meeting at a large listed company sometime this year. The agenda has a standing item on artificial intelligence: model bias in a lending algorithm, data exposure in a customer-facing chatbot, a vendor contract that quietly shifts liability back onto the company. The directors ask sharp questions of the chief risk officer, debate a framework, and leave satisfied that oversight has been exercised. What almost never makes it into the minutes is that at least one person at that table probably pasted a summary of the confidential board pack into a consumer chatbot on their personal laptop the night before, just to prepare faster.
That quiet irony is no longer a footnote. It is becoming one of the more consequential governance failures of this decade, and most boards have not noticed it is happening to them.

Board intelligence platform Diligent’s Q2 2026 director confidence survey found that 82 percent of public company directors had used generative AI for board work in the prior six months, up sharply from 66 percent in September 2025. Nearly half, 49 percent, said they were aware of fellow directors using publicly available consumer AI tools, rather than any company-approved system, for that work. Yet 54 percent reported that their company had no guidance at all on how directors should use AI, and only 6 percent said a formal board-level AI policy actually existed. Adoption is running years ahead of governance, inside the one room in the company whose entire job is governance.
This matters for a reason most commentary on AI and the boardroom misses. The conversation about artificial intelligence at board level has, until now, almost always been framed as an oversight question: are directors asking management the right questions about the company’s use of AI. That framing quietly assumes the board itself is a stable, well-governed observation post from which oversight can be exercised. The Diligent data suggests the observation post is compromised. A director who cannot say with confidence where their own AI-assisted notes and summaries have gone is not well positioned to certify, in a board minute or a 10-K risk disclosure, that the company has AI governance under control.
Where the exposure is actually coming from
The legal system is starting to test exactly that gap, and it is doing so faster than most general counsel expected. In January 2025, the U.S. Securities and Exchange Commission settled charges against Presto Automation over its drive-through voice ordering technology, finding the company had overstated what its AI could do on its own, when in practice a large share of orders were still being processed by human staff overseas. The settlement carried no financial penalty, only a cease-and-desist order, but it confirmed that “AI washing,” dressing up ordinary automation or human labour as autonomous intelligence, is now an active SEC enforcement category rather than a theoretical one.
A newer and more direct threat to directors personally is what one legal commentator has termed the “copyright shareholder derivative” suit. Adobe was the first major company hit with it; Microsoft became the second in mid-2026, when a shareholder filed a derivative claim alleging that Microsoft’s board and officers breached their fiduciary duties by approving continued investment in, and infrastructure support for, OpenAI’s use of allegedly unlicensed training data, while signing off on proxy statements that described the company’s data practices as consistent with copyright law. The claim does not simply argue that the company infringed copyright. It argues that the directors themselves are personally liable for approving the exposure and for the accuracy of what shareholders were told about it. That is a materially different and more personal kind of risk than a corporate compliance failure, and it is precisely the kind of theory that tends to spread once it survives an early motion to dismiss.
Regulators are converging on the same point from the other direction. The European Union’s AI Act reaches its next major compliance milestone in August 2026, when the substantive obligations for high-risk systems, covering everything from data governance to human oversight mechanisms and mandatory incident reporting, become enforceable, with penalties reaching 7 percent of global annual turnover for the most serious violations, a ceiling that exceeds even the GDPR’s. Yet compliance trackers estimate that roughly 78 percent of affected organisations had not begun meaningful compliance work as enforcement approached, and more than half still lack a basic inventory of the AI systems they operate. A board that cannot answer a simple question, how many AI systems does this company actually run, is not in a position to certify compliance with a regulation that fines by revenue rather than by incident.

India’s regulators are, unusually, ahead of this curve
It is worth noting that on this particular question, Indian financial regulation is not trailing global practice; it is arguably setting the template others will eventually copy. The Reserve Bank of India’s FREE-AI framework, built around what its authors call seven “sutras,” states its accountability principle in language most Western regulators have avoided: “the deploying entity is accountable for AI decisions, no matter how autonomous the system. There is no shifting blame to the model.” Practically, this translates into concrete board duties for regulated banks, NBFCs and payment operators: a board-approved institutional AI policy reviewed annually, quarterly board-level reviews of AI risk, a named senior executive personally accountable for AI governance, and public disclosure of AI use and grievance mechanisms in annual reports.
Compare that to the pattern in the United States, where accountability is currently being established retroactively, through litigation and after-the-fact SEC settlements, or in the EU, where at least twelve member states missed their own deadlines to appoint the regulators meant to enforce the AI Act. The RBI’s approach, mandatory, prospective, and explicitly designed to prevent a board from later claiming it did not understand a system it approved, is a more mature piece of governance design than most global companies currently operate under voluntarily. SEBI has separately signalled it intends to strengthen risk and governance frameworks for India’s roughly 5,900 listed companies as AI and cyber threats grow, which suggests the RBI’s sector-specific rigour may not stay confined to banking for long.
What this should change for boards now
The practical implication for CEOs and chairs is not another slide about “responsible AI” at the annual strategy offsite. It is that AI oversight needs its own governance infrastructure, distinct from the audit or technology committee’s existing remit, built on the same non-negotiable principle the RBI has already codified: the board is accountable for what the company’s systems decide, and no vendor contract or model architecture can absorb that accountability on its behalf. That starts with something almost embarrassingly basic that most boards still lack: a written, board-approved policy governing how directors themselves may use AI tools with confidential company information, backed by an approved platform rather than a tacit assumption that everyone is being careful. A board that cannot govern its own laptops has little standing to certify, to regulators, to shareholders, or to itself, that it is governing the company’s.
The deeper shift is this: for two decades, boards treated technology risk as something delegated downward, to a CIO or CISO who reported up periodically. AI is dismantling that division of labour, because the technology in question is now being used, unsupervised, by the people at the very top of the reporting chain. The next material governance failure at a major company is unlikely to be announced as an AI failure. It will look like a fiduciary duty case, a securities disclosure case, or a data protection fine, with the AI buried in the fact pattern. Boards that keep treating AI oversight as a briefing they receive, rather than a discipline they personally practise, are building the fact pattern for that case right now.


