Author: IRPA AI Senior Analyst, Kieran Gilmurray
This article explores what corporate boards must realistically ask, decide, and oversee as generative AI tools such as ChatGPT and emerging agentic AI systems reshape business operations.
After reading this article, you will understand the specific questions to ask management, the governance structures to implement, the regulatory implications to monitor across the UK, EU and US, and the practical steps required to turn AI from a boardroom anxiety into a governed strategic asset.
Introduction: AI Is No Longer Optional Oversight
Artificial intelligence has moved decisively from innovation labs into core business functions. Generative AI drafts contracts, summarises financial reports, and answers customer queries. Agentic AI systems can now plan tasks, trigger workflows, and interact with other systems autonomously. These technologies are already shaping operational and strategic decisions in many organisations.
Recent regulatory developments and oversight reports have pushed AI firmly into the boardroom. Financial regulators now dedicate sections of annual reports to generative and agentic AI risks. Governments are introducing new frameworks and executive actions. Boards are expected to understand not only opportunity but governance implications.
Generative AI vs Agentic AI: Why the Distinction Matters
Generative AI refers to systems that produce content in response to prompts. These systems generate text, images, code, and analysis. They are reactive tools designed to assist human decision making.
Agentic AI goes further. These systems pursue defined goals with limited human intervention. They select actions, call tools, and execute tasks autonomously. They are proactive and can operate across systems once deployed.
The shift from output generation to autonomous action alters the risk profile. A hallucinated paragraph can be edited. An autonomous AI agent triggering transactions or modifying workflows may create operational, legal, or reputational consequences before human review occurs. Boards must understand this difference because governance requirements scale with autonomy.
Rapid Adoption and the Oversight Gap
AI adoption is accelerating across sectors. Surveys show that a significant proportion of directors now rank AI among the most impactful issues shaping 2026. Financial regulators have observed a substantial expansion of AI use cases within regulated firms over the past year. Meanwhile, frameworks for agentic AI governance are emerging internationally.
Despite this, many boards lack formal AI governance policies. Only a minority of companies have documented AI oversight structures. In many organisations, experimentation proceeds at departmental level without centralised visibility or consistent escalation protocols.
This gap between adoption and oversight creates strategic vulnerability. Boards that fail to formalise governance risk being reactive when incidents arise.
The Board’s Duty in the AI Era
Board oversight of AI sits squarely within existing governance and oversight responsibilities. Directors are expected to monitor material risks and ensure appropriate reporting and compliance systems are in place. As AI increasingly influences customer decisions, financial outputs, workforce management, and regulatory compliance, it becomes a material enterprise risk that boards must actively supervise.
Legal commentary has highlighted that failure to implement oversight systems for emerging risks may expose boards to claims of insufficient supervision. Boards should be able to demonstrate that AI risks are identified, discussed, and governed.
AI governance is therefore an extension of established oversight principles.
What Boards Should Be Asking Management
Boards do not need to master technical detail, but they do need disciplined inquiry. At a minimum, directors should be able to answer four questions with confidence:
Where exactly are we using AI, and how does each use support our strategic objectives?
What measurable value are we expecting, and how are we tracking performance and return on investment?
What are the highest risks associated with these systems, and how are they being tested, monitored, and escalated?
Who is accountable for AI governance, and what happens if something goes wrong?
If management cannot provide clear answers to these four areas, governance maturity is likely insufficient.
Building the Governance Framework
Effective AI oversight starts with visibility. Boards should ensure management has a clear inventory of all AI systems in use, including embedded vendor tools, and that each use case is classified by impact and risk.
Accountability must be explicit. A designated executive should own AI governance, with defined reporting to the appropriate board committee. Higher risk systems require structured testing, monitoring, and clear escalation thresholds.
A formal AI governance policy, aligned with recognised frameworks such as the NIST AI Risk Management Framework, should set standards for development, procurement, data use, and vendor oversight. Employee guidelines must address acceptable use of generative AI tools to reduce shadow AI exposure. AI governance should be integrated into enterprise risk management rather than treated as a standalone initiative.
Regional Regulatory Landscape
The EU AI Act moves toward full enforcement by 2026, imposing strict obligations on high risk AI systems including documentation and human oversight requirements.
In the United States, recent executive actions aim to shape a coordinated national AI framework while sector regulators such as FINRA emphasise governance and supervision.
The United Kingdom continues to apply a principles-based, regulator-led approach. Boards operating across jurisdictions must align governance to the strictest applicable standards.
Mini Case Studies: Governance in Practice
Samsung’s internal code leak into ChatGPT demonstrated the risks of employee use of generative AI without policy controls. In 2023, engineers accidentally uploaded sensitive source code into ChatGPT, prompting Samsung to ban generative AI tools on company devices.
Morgan Stanley deployed a GPT-4 powered assistant to support 16,000 financial advisors, initially piloting it with 1,000 advisors before broader rollout. Human advisors retained full decision authority.
Allen and Overy introduced an AI tool to assist more than 3,500 lawyers with drafting and research tasks while maintaining mandatory human review of outputs.
These examples show that structured governance enables responsible AI adoption.
Conclusion: From Anxiety to Structured Oversight
AI is reshaping corporate strategy in real time. Boards cannot rely on informal awareness or fragmented controls.
Structured oversight grounded in accountability, monitoring, and regulatory awareness allows organisations to capture value while managing risk. Boards that embed AI governance today will protect their organisations and enable sustainable growth.
About the author: Kieran Gilmurray
Kieran is a globally recognized authority on AI, automation, and digital transformation, having authored multiple influential books and hundreds of articles that have earned him prestigious accolades, including being named a Top 50 Global Thought Leader and Influencer on Generative AI in 2024, a Best LinkedIn Influencer for AI and Marketing, Top 50 Global Thought Leaders and Influencers on Manufacturing 2024, Top 14 people to follow in data and one of the World’s Top 200 Business and Technology Innovators.
CLICK HERE TO SCHEDULE AN ANALYST CHAT
Links:
Originally posted on 2025-01-28 in the IRPA AI Network — Announcements & Updates