AI Trust Is A Board-Level Issue

For AI, boards need a repeatable oversight discipline, not a collection of presentations about pilots. Answering these five questions can help.
Top down aerial view of boardroom table
AdobeStock

I have never met a director who needed convincing that AI is moving faster than governance. What I hear instead is something more revealing: I can ask good questions in the room, but I still don’t know what I’m supposed to do about this.

That is the governance gap boards now have to close. Directors can challenge management and review risk updates. But most board processes were not built to oversee systems that make millions of decisions in real time, producing outcomes their creators may not fully anticipate.

The question facing boards is no longer whether AI belongs on the governance agenda. It is whether directors know where AI decisions are made, who is accountable and what happens when a system stops behaving as intended. AI governance is rapidly becoming a test of board effectiveness.

What operating experience taught me about board oversight

I spent decades on the other side of that governance gap. I ran complaints organizations at USAA, Visa and Capital One that answered directly to regulators including the CFPB, OCC and FINRA. Later, I led customer experience for Amazon’s Devices, Alexa and Prime Video businesses.

Across financial services and technology, I learned that the most damaging failures rarely begin as board-level crises. They begin as operating signals: an unusual complaint pattern, an unexplained outcome, a control exception someone dismissed. By the time those signals reach the boardroom, the cost of intervention has often multiplied.

That experience changed how I think about trust. It is not protected by asking sharper questions once a quarter. It has to be built into the operating rhythm of the enterprise, much like financial controls. For AI, boards need a repeatable oversight discipline, not a collection of presentations about pilots.

The AI Trust Oversight Framework

If I sat on a board today, I would organize oversight around five questions.

1. Where is AI making consequential decisions?

Start with an inventory, not a project list. Most boards see AI as a portfolio: a chatbot here, a fraud model there, a pilot in claims. That framing can hide what matters most, the decisions those systems are making or materially influencing.

I would ask management for a living inventory of AI systems that can take action or materially shape an outcome, along with the decision each makes, the data it can access, who it can affect and the executive accountable if it gets the outcome wrong. This should not be a slide shown once at launch. It belongs in the board’s recurring risk rhythm, the same way boards track regulatory matters or cybersecurity exposure.

2. Which decisions could materially harm a person or the enterprise?

Not every AI decision deserves the same scrutiny. A system recommending a product is not the same as one that approves credit or denies a claim. Management should tier decisions by consequence: how reversible, and could it affect someone’s money, health or legal standing? Low-consequence systems warrant periodic review; high-consequence ones need stronger controls and, where appropriate, human intervention. The board does not need to design the tiering. It needs to insist one exists, and challenge where the lines were drawn.

3. How do we know the system is still behaving as intended?

Boards are accustomed to approving an initiative and moving on. AI does not hold still. A system that performed as intended at launch can drift as its data or environment changes, and sometimes the first person to discover the problem is a customer, regulator or reporter.

The board-level question should shift from did we approve this to what has changed. Directors should understand how management monitors drift, and how often changes are reported upward. If nobody in the room can explain how a system’s behavior changed last quarter, the board does not have oversight. It has a launch memo gathering dust.

4. Who can stop it, and how quickly?

One question has served me well in every operating role I have held: Who has the authority to stop this, and how fast can they act? Every high-consequence AI system should have predetermined intervention authority, before anyone needs it. The board should know who can suspend it, what would trigger that action and whether the accountable leader can move without waiting for a board meeting. Organizations lose valuable time in a crisis when authority is ambiguous.

5. Who owns the outcome?

The gap I encounter most often is not a missing policy. It is a missing name. When an AI system causes material harm, a specific executive must be accountable, not technology, the AI team, or a governance council. Someone already owns the financial statements. Someone owns cybersecurity. AI should not be different. If the answer does not come quickly and clearly, that hesitation is the finding.

Data access is a board-level risk decision

Every AI system runs on data, and what it can see is not a technical footnote. It is a risk decision. No board would let management deploy significant capital without understanding how and why. Access to sensitive customer and employee data deserves the same discipline: What does the system touch, why is that access necessary and would the company be comfortable explaining it to a regulator or shareholder? If that question creates discomfort in the room, pay attention.

What should appear on the board’s AI Trust Dashboard?

Boards do not need dozens of technical metrics. They need a concise view of exposure, change and exceptions, covering five areas:

CategoryWhat the board needs to know
ExposureWhich high-consequence AI systems are operating, and where has exposure grown?
PerformanceAre material systems producing the outcomes management expected?
DriftWhat has changed in system behavior, data or outcomes?
IncidentsWhat failures, customer harms or escalations occurred?
AccountabilityWho owns each material system, and is intervention authority clear?
Good governance should make responsible speed possible

Boards should not interpret stronger AI governance as an instruction to slow innovation. The opposite is true. When management understands the boundaries, who owns the outcome and when a system must be stopped, the company can move faster with greater confidence.

Trust should be viewed not only as risk protection, but as an enterprise value discipline. Companies that scale AI while maintaining customer, regulator and shareholder confidence will have an advantage over those that treat governance as an afterthought. The board’s role is not to choose between innovation and control. It is to insist on the discipline that allows both.

Five questions every director should be able to answer
  • Where is AI making decisions that materially affect customers, employees, capital or reputation?
  • Which of those decisions have been classified as high consequence, and why?
  • What evidence tells us those systems are still performing as intended?
  • Who has authority to stop a material AI system immediately?
  • Which executive is personally accountable when the system gets something wrong?

What this asks of a board

None of this requires a director to become a data scientist. It asks boards to apply disciplines they already understand to a new class of risk and opportunity.

The boards that get this right will not necessarily be those with the most AI expertise. They will be the ones that establish accountability before something fails, demand evidence rather than reassurance and understand that trust is not a constraint on innovation. It is what allows innovation to scale.

History will not remember which company deployed AI first. It will remember which created value with it without sacrificing the trust of customers, employees, regulators and shareholders. The choice facing every director is not whether to govern AI. It is whether to govern it before the damage is done, or after.

MORE LIKE THIS

Get the Corporate Board Member Newsletter

Timely analysis and practical perspective on the governance, risk and oversight issues shaping today’s board agendas.

UPCOMING EVENTS

Boardroom Summit

Agentic AI Immersion | Chicago

Directors Forum