Governance & oversight
The largest theme in the research: 222 of 268 documents, 81 organizations. Decomposed into 7 topics, each with its own issues, evidence and steps.
222 documents in the theme
32 issues named
96 sourced citations
28 organizations cited
37 sourced statistics
The topics
Each opens a dossier with the same shape: what the state of it is, the issues ranked by how many independent organizations name them - or marked as our own analysis where none does - the disagreements, the numbers, and the concrete steps under each remedy.
Board oversight & reporting
What the board is shown, how often, and whether it can tell a working system from a demo.
Directors rate their own AI literacy as adequate; the executives reporting to them do not agree 5
AI reaches the board when something happens, not on a fixed cadence 2
Nobody has enumerated the AI the organization is already running 2
and 5 more
76 documents · 33 organizations · 8 issues · 52 steps
Audit trails & explainability
Whether you can reconstruct why the system did what it did.
Agents take actions, and the chain leading to them cannot be reconstructed 2
Retrieval from unstructured sources breaks the traceability model governance assumes 1
Explainability protocols exist on paper and have not been tested ours
and 1 more
43 documents · 26 organizations · 4 issues · 11 steps
Regulatory compliance
The EU AI Act, sectoral regulators, and what has to be demonstrable.
The three major regimes are not reconcilable into one compliance posture 2
Obligations attach to a role you may not have worked out you occupy 1
Regulatory uncertainty is being managed by avoiding use cases, not by building capability 1
and 2 more
35 documents · 22 organizations · 5 issues · 22 steps
Third-party & vendor risk
The model you did not build and the supply chain behind it.
The switching cost has moved from the model to the harness around it 2
There is no exit plan, and the data makes one harder every month 2
Vendor diligence for AI is ordinary IT diligence with AI words added 1
and 1 more
34 documents · 23 organizations · 4 issues · 16 steps
Accountability & decision rights
Who is allowed to deploy what, and who answers when it goes wrong.
Autonomy widens the gap between the decision and the person answerable for it 4
No one person owns policy, infrastructure, outcome and risk together 2
Activity is being mistaken for a change in the operating model 2
and 1 more
30 documents · 20 organizations · 4 issues · 14 steps
Model risk management
Treating a model as a controlled asset with an owner, a lifecycle, and limits.
Pretrained and open-source models enter production without validation 2
Models degrade quietly, and the first signal is usually a customer 1
Validation is treated as a launch gate, not a continuing cost 1
and 1 more
28 documents · 21 organizations · 4 issues · 14 steps
Shadow AI & unsanctioned use
What employees are already running that nobody approved.
Most organizations are already running AI the board has never seen 5
Blocking tools produces unsanctioned use rather than abstention 3
It shows up as untracked spend before it shows up as a breach ours
19 documents · 14 organizations · 3 issues · 9 steps
Where the sources disagree
Every recorded contradiction across the theme, in one place. These only exist because the documents were read against each other; no single publisher reveals them.
AI reaches the board when something happens, not on a fixed cadence Board oversight & reporting Infosys dissents — Puts 86% of boards taking AI as a scheduled agenda item - 72% at regularly scheduled meetings and 14% at every meeting - against 14% who take it only ad hoc, from 300 directors at North American companies above $1bn revenue.
From the toolkit
Governance & oversight — the implementation kit
The whole of Governance & oversight, turned into something you can run. A diagnostic that tells you which of these problems you have, and an action plan with every step owned and time-boxed.
A diagnostic you can run in a room 32 questions across 7 areas, each written so a yes or no tells you whether you have that problem. No scoring model to learn.
An action plan that names who does it 138 actions, each carrying a role and a time-box, and every fix states what exists when it is done - so you can tell a fix that landed from one that was attempted.
The same actions, sorted by person An owner map, so one column goes to one person, and a sequence that says what to do first rather than leaving you to guess.
Written for your situation Three editions - listed company, private company or scale-up, and advisory - so the owner names match the room you are actually in.
Yours to use in front of a client Every word is original work. No third-party research is reproduced in it, which is what makes it safe to hand on.
32 diagnostic questions · 138 owned actions · 54 pages · one-off, updates included
Issues were named by hand after reading the documents cited under each one. Consensus counts distinct organizations, not documents, and counts only evidence a human has verified against a located passage.
Every link opens the publishing organization's own page. Summaries and characterisations are written here; no publisher prose is reproduced.