Barrier Consulting Group

AI governance / June 2026

What the board should ask about AI


Most boards discuss artificial intelligence without any structure that can decide something about it. The fix is a small standing committee whose first output is a list of what is already live, a written test for what needs approval, and one named executive who reports to it every quarter. Adoption is gated on two questions, and neither of them is how visible the use case looks.

The Gap

Directors are not confused about whether this matters.

The National Association of Corporate Directors, in its 2023 public company board practices survey, reported that 28 percent of directors said artificial intelligence featured regularly in their board discussions, while 95 percent said they expected AI to affect their business in the years immediately ahead. The distance between those two figures is the whole argument.

Directors already know the subject is material. What almost none of them have is a structure with the authority to decide anything. A board without that structure responds to a fast-moving technology in one of two ways. Silence, where the subject never gets real agenda time. Or theatre, where the subject gets a slide and nothing else.

Waiting is not a neutral choice. Every quarter without a structure is a quarter in which product, human resources and marketing teams adopt with no board visibility, and a quarter that adds to the set of live use cases the eventual committee inherits without having chosen any of them.

Placement

The audit committee is the reflex answer and the wrong one.

The instinct is to give AI to whichever committee already owns risk, which for most boards means audit. That committee already owns financial controls, external auditor oversight, whistleblower matters and cyber risk. The Securities and Exchange Commission's cybersecurity disclosure rule, which took effect for fiscal years ending on or after 15 December 2023, requires a public company to describe how its board oversees cyber risk in the annual report. Audit committees absorbed that because cyber maps onto controls and disclosure, which is their native vocabulary.

AI does not map that way. A model that screens applicants touches employment law. A customer-facing assistant touches brand and product liability. A contract for an external model raises procurement and data rights. Privacy is raised by any model trained on customer records. Stretched across all of that, audit produces a fifteen-minute item squeezed in between internal audit and the whistleblower log, read by directors chosen for their financial expertise.

First Output

The first meeting produces a list, not a charter.

A committee that spends its first quarter writing a mission statement while several business units already run customer-facing features has lost the thread before it started. Inventory first. What is in production, what is in pilot, which data each one reasons over, who approved it, and who would answer if it produced an outcome the company had to explain publicly.

The charter is easier to write once the list exists, because the list shows which decisions it has to cover. Written the other way round, it covers the decisions somebody imagined.

The Gate

Two axes decide who signs a use case off.

The first axis is who sees the output, customers and the public or only people inside the organization. The second is what the system reasons over, either regulated, biometric or employment data or general business content. Four outcomes follow.

  • External output, sensitive data. Committee approval before launch. A lending or underwriting aid that reads a customer's financial record belongs here, along with anything that could reasonably end up in a letter from a regulator.
  • External output, general data. Notice to the committee plus a named risk owner. A support assistant trained on published product documentation is real exposure but does not need the review a credit decision needs.
  • Internal output, sensitive data. Committee approval before launch. A tool that scores candidates has the same employment-law exposure whether a customer or a recruiter sees the output. The smaller audience does not reduce the legal risk.
  • Internal output, general data. Delegated to the business unit and logged. A drafting aid or a meeting summarizer belongs here. Pushing it through committee review only teaches people to route around the committee.

Boards attempting this usually score on visibility alone. That is the error the test prevents. An internal scoring model is quieter than a public assistant and considerably more dangerous.

The Questions

Six questions a director should ask every quarter.

  1. 1. What is live today that this committee has never reviewed, and who approved it?
  2. 2. What can this committee actually stop, and under what written authority?
  3. 3. Which risk category has two owners between us and the audit committee, and which has none?
  4. 4. Is the same executive briefing us each quarter, or does the briefing rotate?
  5. 5. Which third parties reach material company data through a model we did not build?
  6. 6. If a model produced an outcome we had to explain to a regulator, who would answer and with what evidence?

The last question is the stress test. A committee that cannot answer it in one sentence has been briefed but not equipped.

Charter And Cadence

Small membership, standing quarterly slot, and the authority to call an urgent session.

Put at least one director with operating experience in technology or product alongside directors whose background is legal, risk or regulatory. A group with no operating background asks the same three questions every quarter and lacks the vocabulary to press past whatever answer comes back. The chief information officer, the security lead and the general counsel attend as standing advisors without a vote. Business units escalate a proposed use case to the committee directly, not through the technology function.

Cadence matters less than the escape hatch. A committee whose only meetings are the full board meetings will always react to decisions made two quarters earlier. Pair the standing quarterly review of the inventory with authority to convene on short notice for anything in the top tier, or a customer-facing launch will pass by while the next meeting is ten weeks away.

Two published references help when drafting. The AI Risk Management Framework issued by the National Institute of Standards and Technology in January 2023 divides AI risk into four functions of govern, map, measure and manage. A technology team can supply the last three. Govern requires an authority that belongs to a board committee and not to an engineering team, and closing that gap is the whole reason the committee exists. ISO/IEC 42001, published in December 2023 as an AI management system standard, forces documented decisions on roles, competence and evidence.

34% Efficiency gain

A commercial insurer had eleven pilots running across four functions and no record of which ones touched customer data. We wrote the committee charter, ran the inventory, and scored every pilot on output exposure and data sensitivity. Four use cases were stopped outright, and concentrating the rest on document intake cut processing effort in that function by 34 percent.

What To Do Next

Six steps, in this order.

  1. 1. Inventory every use case that is live or piloted today, and do it before anyone drafts a policy document.
  2. 2. Score each one on output exposure and data sensitivity, and assign it to one of the four tiers.
  3. 3. Appoint one accountable executive to present to the committee each quarter, and keep that person constant.
  4. 4. Write down the boundary between this committee and the audit and technology committees, so no risk category ends up with two owners or with none.
  5. 5. Grant authority to convene outside the board calendar for top-tier cases.
  6. 6. Review the charter after twelve months against the cases that were actually escalated, and not against the ones it predicted.

The boards that get this right are not the ones with the tidiest policy document. They are the ones that can say in one sentence what their committee has the power to stop.

Related Service

AI Governance and Adoption

We draft the charter and run the first inventory, then step back once the committee can decide without us.

AI governance and adoption

Back to Insights

Start A Conversation

If your board has asked for an AI update and nobody owns the answer, start there.

ryan@barrierconsultinggroup.com