Essay · Governance & AI
Boards have spent the last two years asking management "what's our AI strategy," which was a reasonable question to ask in 2024. It's an increasingly weak one now. The organizations running into real trouble in 2026 aren't the ones without an AI strategy — nearly every company of any size has a deck by now. They're the ones where the board cannot meaningfully evaluate whether that strategy is sound, because the fluency gap between management and the boardroom has quietly become a governance risk in its own right, distinct from whatever risk the technology itself carries.
The data on this gap is more encouraging than I expected, and also more worrying once you look past the headline number. NACD's 2026 Governance Outlook survey found that more than sixty-two percent of directors now set aside dedicated agenda time for full-board AI discussions, a dramatic increase from prior years.[1] That's the encouraging part — attention has clearly arrived. The worrying part sits one layer down: fewer than twenty-five percent of companies have a board-approved, structured AI policy, and only twenty-three percent of boards have actually assessed how AI-driven disruption might happen to their own business or where it's most likely to come from.[1] Attention without structure produces long discussions and thin oversight. Forty-seven percent of directors surveyed identified simply selecting the right AI tools as a current challenge for their board.[1] Boards are in the room. Most aren't yet equipped to ask the questions that matter most once they're there.
This isn't a call to become a data scientist
None of this is an argument for directors to develop technical fluency in model architecture, and boards that chase that goal are usually solving the wrong problem. It's an argument for a specific, learnable set of oversight competencies that most boards currently lack, and that are becoming as fundamental to good governance as financial statement literacy has been for the last several decades. Nobody expects a director to be able to build a balance sheet from scratch. Every competent director is expected to be able to interrogate one, ask where the estimates are soft, and know what questions expose weak assumptions. AI oversight needs to reach that same bar, and right now, for most boards, it doesn't.
Failure modes, not just capabilities
Most AI updates delivered to a board are capability demonstrations: look what the model can now do, look how the pilot performed, look at the efficiency gain in the quarter. Far fewer boards are asking the harder companion question — what happens when it's wrong, how often, and who specifically is accountable for the consequence when it is. A model that's correct ninety-five percent of the time sounds genuinely impressive in a slide, right up until someone asks what the other five percent costs, who absorbs that cost, and whether anyone in the organization is actually tracking it in a way that would surface a pattern before it becomes a crisis. Directors should expect an error-and-consequence discussion paired with every capability discussion as a standing agenda item, not as an occasional exception raised only after something has already gone wrong.
Data provenance as a board-level question
Every AI capability is downstream of a data strategy, and most boards have never had a substantive conversation about where the training and operating data actually comes from, what it's licensed to be used for, and what liability sits underneath it. This has stopped being purely an IT question. The legal landscape shifted meaningfully in the past year: in May 2026, a group of major publishers and a novelist filed a class-action copyright infringement suit against a large technology company over AI training data, seeking both an injunction and monetary damages.[2] Separately, Anthropic agreed to a $1.5 billion settlement with writers whose books had been used to train its models.[2] A federal ruling in the Thomson Reuters v. Ross Intelligence case established that using an AI tool trained on infringing data can create downstream liability for the company deploying the tool, not only for the company that built it — which means the vendor's data practices are now the deploying company's legal exposure, whether or not anyone read that far into the contract.[2] One analysis found that ninety-two percent of AI vendor contracts claim data usage rights that go beyond what's strictly necessary to deliver the service, well above the broader software market average of sixty-three percent.[2] This is a legal, competitive, and increasingly reputational question, and it belongs at the board level the same way a supply chain risk review does — not buried in a vendor management spreadsheet three layers below anyone the board would recognize.
Vendor dependency deserves lease-level scrutiny
Boards routinely approve significant AI vendor relationships with less formal scrutiny than they would apply to a real estate lease, despite those relationships frequently carrying more strategic lock-in risk than the lease does. What happens to the business if this vendor's pricing triples at renewal, or the vendor is acquired by a direct competitor, or the specific model the company has built workflows around is deprecated with six months' notice? Directors should expect management to have answered this before the contract is signed, not after the dependency has become expensive to unwind.
The uncomfortable fourth competency
The fourth competency is the one boards are least comfortable discussing directly: workforce and trust impact. Boards carry fiduciary and increasingly reputational exposure tied to how AI deployment affects the workforce and how that deployment is communicated, both internally and externally. Survey data from 2026 shows a twenty-seven-point perception gap between employers who view AI positively, at seventy-eight percent, and employees who do, at fifty-one percent, with trust in AI itself emerging as the central adoption challenge inside organizations.[3] A deployment that is technically sound and financially well-justified but handled in a way that damages that trust — with employees, customers, or eventually regulators — is a governance failure even when it is, by every technical measure, a genuine technology success.
The honest caveat
It's worth being direct about the limits of board oversight here. No amount of director fluency substitutes for a management team that is itself rigorous about AI governance; boards oversee, they don't operate, and a board that tries to manage AI deployment decisions directly is overstepping its role in a way that usually produces worse outcomes, not better ones. The goal of building this fluency isn't for directors to run the AI program. It's for them to ask sharp enough questions, early enough, that a weak management answer becomes visible to everyone in the room before it becomes an expensive lesson learned in public.
None of this requires directors to understand transformer architecture. It requires boards willing to treat AI oversight as its own distinct competency, with the same seriousness that cybersecurity oversight eventually received after a decade of expensive lessons taught the hard way. The boards building this fluency now will be the ones asking the right question before the mistake. Which kind of board is yours currently equipped to be?
Sources
- NACD 2026 Governance Outlook survey data, National Association of Corporate Directors. https://www.nacdonline.org/all-governance/governance-resources/governance-research/outlook-and-challenges/2026-governance-outlook/2026-governance-outlook-survey-data/growth-drivers/
- AI training data litigation and contract analysis, including the May 2026 publisher class action, the Anthropic settlement, and the Thomson Reuters v. Ross Intelligence ruling, as summarized in AI Vortex, "AI Copyright Training Data Lawsuits 2026," and related legal analysis. https://www.aivortex.io/legal/guides/ai-copyright-training-data-2026-landscape/
- Minds, "AI Workplace Trust, Global Knowledge Workers 2026" survey data. https://getminds.ai/studies/ai-workplace-trust-knowledge-workers-2026
Juan Vegarra is the author of An Outsider's Playbook (forthcoming). The views here are his own. More essays · Write me