Governance & oversight

The largest theme in the research: 222 of 268 documents, 81 organizations. Decomposed into 7 topics, each with its own issues, evidence and steps.

222documents in the theme
32issues named
99sourced citations
28organizations cited
37sourced statistics

The topics

Each opens a dossier with the same shape: what the state of it is, the issues ranked by how many independent organizations name them - or marked as our own analysis where none does - the disagreements, the numbers, and the concrete steps under each remedy.

Board oversight & reporting

What the board is shown, how often, and whether it can tell a working system from a demo.

  • Directors rate their own AI literacy as adequate; the executives reporting to them do not agree 5
  • AI reaches the board when something happens, not on a fixed cadence 2
  • Nobody has enumerated the AI the organization is already running 2
  • and 5 more

76 documents · 33 organizations · 8 issues · 52 steps

Audit trails & explainability

Whether you can reconstruct why the system did what it did.

  • Agents take actions, and the chain leading to them cannot be reconstructed 2
  • Retrieval from unstructured sources breaks the traceability model governance assumes 1
  • Explainability protocols exist on paper and have not been tested ours
  • and 1 more

43 documents · 26 organizations · 4 issues · 11 steps

Regulatory compliance

The EU AI Act, sectoral regulators, and what has to be demonstrable.

  • The three major regimes are not reconcilable into one compliance posture 2
  • Obligations attach to a role you may not have worked out you occupy 1
  • Regulatory uncertainty is being managed by avoiding use cases, not by building capability 1
  • and 2 more

35 documents · 22 organizations · 5 issues · 22 steps

Third-party & vendor risk

The model you did not build and the supply chain behind it.

  • The switching cost has moved from the model to the harness around it 2
  • There is no exit plan, and the data makes one harder every month 2
  • Vendor diligence for AI is ordinary IT diligence with AI words added 1
  • and 1 more

34 documents · 23 organizations · 4 issues · 16 steps

Accountability & decision rights

Who is allowed to deploy what, and who answers when it goes wrong.

  • Autonomy widens the gap between the decision and the person answerable for it 4
  • No one person owns policy, infrastructure, outcome and risk together 2
  • Activity is being mistaken for a change in the operating model 2
  • and 1 more

30 documents · 20 organizations · 4 issues · 14 steps

Model risk management

Treating a model as a controlled asset with an owner, a lifecycle, and limits.

  • Pretrained and open-source models enter production without validation 2
  • Models degrade quietly, and the first signal is usually a customer 1
  • Validation is treated as a launch gate, not a continuing cost 1
  • and 1 more

28 documents · 21 organizations · 4 issues · 14 steps

Shadow AI & unsanctioned use

What employees are already running that nobody approved.

  • Most organizations are already running AI the board has never seen 5
  • Blocking tools produces unsanctioned use rather than abstention 3
  • It shows up as untracked spend before it shows up as a breach ours

19 documents · 14 organizations · 3 issues · 9 steps

Where the sources disagree

Every recorded contradiction across the theme, in one place. These only exist because the documents were read against each other; no single publisher reveals them.

AI reaches the board when something happens, not on a fixed cadenceBoard oversight & reportingInfosys dissents — Puts 86% of boards taking AI as a scheduled agenda item - 72% at regularly scheduled meetings and 14% at every meeting - against 14% who take it only ad hoc, from 300 directors at North American companies above $1bn revenue.