Governance

Why AI is a board problem, not an IT problem.

thedailybrief · 14 July 2026 · 4 min read

For a decade, "our AI" was a sentence finished by the technology team. That era is ending. The moment a model shapes a decision a customer, employee or regulator would care about, accountability stops being a technical detail and becomes a question for the people who sign the accounts.

Most organisations still file artificial intelligence under IT. It is a reasonable habit — the systems are technical, the vendors are technical, the people who deploy them are technical. But the habit now hides a growing exposure, because the thing that has changed about AI is not its capability. It is its reach into decisions.

The line has moved

When AI summarised documents or suggested code, the stakes were contained. When AI sets a price, screens a candidate, approves a claim, or flags a transaction, it is making a call that lands on a real person — and someone, by name, is accountable for that call. Regulators across the major markets have begun to say this explicitly: responsibility for an automated decision sits with the organisation that deploys the model, not the lab that trained it.

The vendor supplies the engine. You are driving.

That single shift reclassifies AI risk. It moves it out of the server room and onto the same shelf as financial controls, health and safety, and data protection — the risks a board is expected to understand, own, and be able to explain. "The vendor's model did it" is not a defence a chair wants to offer a regulator, an insurer, or a front page.

The uncomfortable first question

Here is the test we put to executives: where in this business does an AI already shape a decision a customer would care about — and who, by name, owns it? In most organisations the room goes quiet. Not because the answer is bad, but because no one has drawn the map. Models have entered production through pilots, procurement and shadow adoption, and the accountability never caught up.

That quiet is the finding. It means the exposure exists and is simply undocumented — which is the worst state to be in, because it is real without being managed.

What a board should actually do

The move is not to panic, ban, or over-engineer. It is to make one person responsible for producing three things: an inventory of where AI touches consequential decisions, an owner named against each, and a reversibility rating — how expensive is it to undo a wrong call, and would you even notice. You will not like the first draft. That is precisely why it is worth doing before someone external asks for it.

None of this requires the board to become technical. It requires the board to treat AI the way it treats any capability that can create or destroy value at scale: as something governed, owned and minuted. The organisations that make that shift now will separate, quietly, from the ones still filing it under IT.

This is how every edition reads.

One signal, its meaning, and the move it leaves on your desk — every weekday at 05:59. Free to join the ledger.

Join the ledger →