Europe · Technology and digital assets

AI Governance: How the Board of Directors Manages the Risks of Artificial Intelligence

Erich Rath12 min read

Mainstream

AI Governance at board level is not a matter of technology. It is a matter of personal responsibility, business reputation and access to the European Union market.

The question is not whether the company is using artificial intelligence. The question is whether the board can prove that it has fulfilled its oversight duty when something goes wrong.

Effective AI risk management begins with three checks:

  1. Does the board know all of the company’s AI systems and their regulatory classification under the EU AI Act?
  2. Is AI supervision built into the corporate governance system, rather than left solely to the IT department?
  3. Is there any evidence of due diligence at the board level?

If these three issues are not resolved, the company risks more than a fine of up to 35 million euros, or 7% of global turnover. It risks personal liability of directors, product shutdown, loss of investor confidence and exclusion from the European market.

When AI Governance is Needed at Board Level

Systematic AI risk management at the board level is mandatory if:

  • the company develops or implements AI systems in the EU market;
  • AI is used to make decisions that affect people (hiring, credit scoring, employee evaluation).
  • The product is classified as high-risk AI under the EU AI Act.
  • The company acts as a provider or distributor of AI solutions;
  • Investors or auditors ask questions about the maturity of AI Governance.
  • The insurance company requires confirmation of risk management of AI to extend the D&O.
  • an incident involving discrimination, data breach or AI error;
  • The company operates in regulated sectors (finance, healthtech, HR, automotive, energy);
  • M&A deals are planned with an asset whose value depends on AI technologies.

The mistake most boards of directors make

Many tips start with the question:

Which of the CIOs are responsible for AI?

That's the wrong first question.

The right question is:

How can the board prove that it acted with due diligence in overseeing AI risks if the regulator or the affected party makes a claim?

Sometimes the best result is the creation of a separate AI committee of the council. Sometimes, the integration of supervision into the audit committee. Sometimes, an external AI governance audit is performed before a high-risk system is launched. Sometimes, it is a documented decision of the board not to use AI in certain processes.

Managing AI risks requires not a response to tech trends, but a corporate governance structure.

Step 1. To take an inventory of AI systems and determine their regulatory classification

The first thing to do is not to choose an AI tool for the board of directors, but to choose a complete registry of the company’s AI systems.

Key questions:

  • What AI systems the company develops, uses, sells or embeds in products
  • Whether they are subject to prophibited AI practices under Article 5 of the EU AI Act;
  • which systems are high-risk (high-risk) – according to the application to the EU AI Act or sectoral legislation;
  • (b) whether there is a limited risk or a minimum risk;
  • who is the provider and who is the user (deployer) in terms of the regulator;
  • where people interact (transparency)
  • Whether there are systems that make fully automated, legally relevant decisions

If the board of directors cannot affirmatively say that it has such a registry, the regulator’s first claim is already ready.

Step 2. Assessing the risks for businesses and stakeholders

The importance of the council is not technical parameters, but business consequences.

We need to analyze:

  • risk of discrimination and violation of fundamental rights;
  • reputational damage from an opaque or mistaken AI solution
  • Liability for damage caused by AI (Product Liability Directive, AI Liability Directive)
  • penalties under the EU AI Act and national law;
  • GDPR violation in the processing of AI data;
  • loss of key contracts due to non-compliance with the requirements of counterparties;
  • risks to D&O insurance directors;
  • Threat of revocation of licenses in regulated sectors.

Especially dangerous are situations where the risk was known but the board did not take documented action.

Step 3. Identify applicable regulation

The AI risk is not limited to the EU AI Act. The board of directors must see the full picture.

It includes:

  • EU AI Act (prohibited practices, high-risk, obligations of providers and users);
  • GDPR and e Privacy (automated solutions, transparency, DPIA)
  • Product Liability Directive and the AI Liability Directive
  • Sectoral regulation (MDR, IVDR for medtech) financial directives; (a) automotive regulation;
  • National laws on corporate governance and directors’ duties;
  • ISO/IEC 42001, NIST AI RMF standards, which the regulator may consider as evidence of due diligence.
  • Disclosure requirements for public companies (ESG, non-financial reporting, CSRD).

Error at this stage leads to fragmented compliance and blind spots of the council.

Step 4. Incorporate AI Governance into the corporate governance system

The Board of Directors cannot transfer responsibility to the IT department. It's his own function.

Structure options:

  • Creation of the Board of Directors Committee on AI and Technological Risks;
  • Including AI oversight in the mandate of the Audit Committee or Risk Committee
  • Appointment of an AI Officer or Chief AI Governance Officer with a direct line of reporting to the board
  • Approval of the AI risk escalation matrix: When the issue is brought to the council level.

The key principle: AI Governance should be visible in the subpoenas, protocols and decisions of the board.

Step 5. Develop and approve the AI Policy of the Board of Directors

The board should approve a policy that sets the rules of the game for the entire company.

The document should include:

  • Risk Appetite Statement for AI
  • banning certain AI practices that are beyond the scope of acceptable risk;
  • mandatory principles: Human oversight, transparency, fairness, accountability;
  • Fundamental Rights Impact Assessment (FRIA) requirements for high-risk AI
  • Procedure for validating AI systems before launch (sign-off procedure);
  • Third-party AI (Vendor Due Diligence)
  • A policy of disclosing the use of AI to customers and employees;
  • The procedure for investigating AI incidents and escalating to the council.

Without such policies, the council has no tool of control – and will not be able to defend itself.

Step 6. Ensure documentation of all AI board decisions

From the regulator's and the court's perspective, the key will not be what the council thought but what is documented.

Necessary:

  • Council decisions on approval of the AI registry and classification of systems;
  • Protocols for discussing high-risk AI projects;
  • Evidence of considering AI risks before launching a product
  • Reports of the AI Officer or external auditor reviewed by the Board;
  • records that the board has been informed of mitigation measures;
  • Confirmation that the board understood the limitations of AI and made an informed decision.

The absence of documents is interpreted as a lack of supervision.

Step 7. Implement continuous monitoring and the board’s right to independent audit

AI risks are not static. The board must be sure that it is not receiving a “success report” but an objective picture.

Mechanisms:

  • Regular (at least quarterly) reports to the board on the state of AI risks;
  • the right of the Board to initiate an external audit of AI Governance and technical audit of high-risk systems;
  • performance and bias monitoring (model drift);
  • Monitoring of regulatory changes (EU AI Act provides delegated acts, standards are evolving);
  • Early warning procedure for incidents.

A board that does not have access to independent review carries the full risk of management failure.

Step 8. Prepare to interact with regulators

The EU AI Act establishes a supervisory framework for: national market surveillance authorities, European Artificial Intelligence Board, notifying bodies.

The board should understand in advance:

  • who is authorized to interact with the regulator on behalf of the company;
  • How will the response to the request for information be organized?
  • Notification of serious incidents (for high-risk AI)
  • Product recall or corrective action procedure;
  • Communication strategy in case of public investigation.

A spontaneous reaction to a regulator’s visit without a plan is a direct path to exacerbating the situation and losing control of the narrative.

Step 9. Integrate AI Risks into the Common Risk Management and Compliance System

AI Governance cannot exist in a vacuum. For the council, it is part of the overall system:

  • Update of the Corporate Risk Register (including AI as a separate strategic risk)
  • Compliance program (Code of Conduct, whistleblowing, internal investigations)
  • Communication with cyber security (AI-systems – a new attack surface);
  • ESG-reporting and due diligence of the supply chain (EU CSDDD);
  • Impact of AI Governance on D&O Insurance Insurers are increasingly testing AI risk maturity.

The board should make sure that AI is not a standalone initiative of enthusiasts, but part of the corporate DNA.

Step 10. Ensure the competence of the Board of Directors

You can't control what you don't understand. The EU AI Act explicitly requires AI literacy for staff, and for the board, it becomes a duty of care element.

What is needed:

  • regular educational sessions of the board on AI regulation and technology aspects;
  • Understanding the difference between automation, machine learning and generative AI
  • Ability to ask the right questions about data, bias, model validation, and human oversight
  • Knowledge of the personal risks of the directors in the event of a breach.

The court will not accept the argument “we did not understand the technology” as an exemption from liability.

Create an AI committee of the council or leave it to IT: pick

CriteriaAI committee of the board of directorsIT/Legal delegation without committee
Provability of supervisionHigh (protocols, expertise)Low (council distanced)
Responsibility of directorsClear distribution, documented decision-makingBlurred, risk of personal claims
Quality of strategic decisionsAI is managed as a business risk, not as an IT projectAI is perceived as a technical function
Speed of response to incidentsControlled escalationRisk of delayed informing council
Impact of D&O InsuranceStrengthen the position in underwritingMay make it difficult to extend or raise the premium
Costs and resourcesHigher at the start (engagement of experts)Lower at the start, but higher long-term risks

The choice does not depend on the size of the company, but on how much AI is a significant risk factor for the business model. If AI affects security, people’s rights, or basic income, a committee or clearly defined function of the board is mandatory.

How to strengthen the position of the board of directors before the implementation of AI

The best protection is built before the AI system touches the first user.

The Board of Directors should initiate:

  • Approval of the AI Governance Charter, which defines the role of the board;
  • Principal decision on unacceptable AI practices (red lines);
  • the procedure of mandatory AI due diligence before buying an AI vendor or M&A;
  • Incorporating AI compliance into the Internal Control System (ICS)
  • Checking the adequacy of D&O coverage, taking into account AI risks;
  • Pre-agreed scheme of interaction with PR and IR in the event of an AI incident (crisis communication);
  • The requirement for management to provide not only technical metrics, but also a regulatory assurance map.

The board should be prepared for the worst-case scenario, not the best press release on innovation.

Typical Board Mistakes in Managing AI Risks

1. The regulator asks not from the developer, but from the management body.

2. Shadow AI (shadow AI) today is the sanctions of tomorrow.

3. Even an internal HR tool can be high-risk and require full compliance.

4. Do not document the discussion of the board.Without protocol, it is impossible to prove due diligence.

5. A policy “on paper” in the absence of an audit is an aggravating circumstance.

6. Rely on the vendor without verification.The responsibility of the provider does not relieve the duties of the deployer, and the board is responsible for choosing the vendor.

7. Ignorance of the law is no excuse. Ignorance of AI under the EU AI Act.

8. In case of serious violation, disqualification, personal fines and reputational loss are possible.

Board of Directors checklist for AI Governance

Before approving an AI strategy or launching a new system, the board must answer 15 questions:

  1. Does the company have a complete registry of AI systems and their classification under the EU AI Act?
  2. Are prohibited practices defined and guaranteed to be absent?
  3. What are the high-risk systems and are all applicable requirements met?
  4. Which of the board members or committees is responsible for overseeing AI?
  5. Is the AI Policy and Risk Appetite Statement approved?
  6. Are the AI Projects Council’s decisions documented?
  7. Was there an independent audit of AI Governance or specific high-risk systems?
  8. Is there a procedure for escalating AI incidents to the council?
  9. Are the risks of D&O insurance being extended?
  10. Are AI risks integrated into the Corporate Risk Register?
  11. Is there evidence of AI training of the board of directors?
  12. Are third-party AI vendors verified for compliance?
  13. Is there a plan to interact with the regulator in case of a serious incident?
  14. Are AI disclosures included in the ESG and annual report?
  15. Can the council today prove that it acted informed and diligent?

What a strong AI Governance strategy looks like at board level

A strong strategy usually includes five levels:

1. Board Awareness & Education: Understanding technology and regulation, and asking the right questions.

2. Governance Structure & Policy AI Charter, committee or dedicated responsibility, documented policy.

3. Risk Identification & Classification Registry AI, FRIA, DPIA, high-risk classification, legal assessment.

4. Monitoring, Audit & Escalation Regular reporting, audit rights, incident escalation procedures

5. Culture & Accountability Tone from the top: AI Ethics as Value, Consequences for Violations, and Protection of Whistleblowers.

Without the fifth level, the first four will not stand the test of a real crisis.

FAQ

Is the board of directors required to personally examine AI under the EU AI Act? The EU AI Act introduces the obligation of AI literacy, and EU and Member States corporate law requires directors to make informed decisions. Incompetence is not a defense.

Can the board of directors be held personally liable for breach of AI regulation? In addition to fines on the company, in some jurisdictions, personal sanctions, disqualification of directors, as well as claims for damages against directors by the company or shareholders, if it is proved that gross neglect of supervisory duties is shown.

Require AI inventory management with a legal classification and hold at least one strategic session on AI risks and board responsibilities, documenting the results.

Is it enough to rely on CIO's assurances that "we compliant"? The Board shall obtain independent confirmation, through internal audit, external legal counsel or compliance review, and document its review of these confirmations.

How does AI Governance affect D&O insurance? Insurers are increasingly eliminating AI-related claims or requesting evidence of AI governance frameworks. The lack of mature AI Governance can lead to a denial of payment or a higher cost of the policy.

Not always necessary, but if AI is a significant risk factor or strategic asset, a dedicated committee or a fixed function greatly enhances director protection.

What to do if the company uses AI solutions of third-party vendors?Responsibility for the selection, implementation and control of the vendor lies with the company. The Council must ensure that vendor AI due diligence and contractual compliance guarantees are in place with the EU AI Act.

Can AI Governance be postponed until all EU AI Act regulations come into force? Transition periods are limited, and reputational and civil-law risks are already present. In addition, the demonstration of proactive compliance softens the position in case of any incident.

More importantly: To avoid fines or to preserve reputation?Both issues are critical for the board. But in terms of long-term business value, losing the trust of customers, investors and regulators is often worth more than any penalty. AI Governance is not compliance exercise, but duty of loyalty and care.

Related services

  • EU AI Act Compliance & AI Governance
  • Corporate Governance, Directors’ Duties & Board Advisory
  • Technology, Data & Digital Regulation
  • Regulatory Investigations & White-Collar Defence
  • D&O Liability & Insurance Advisory
  • Cross-Border M&A and Tech Due Diligence
  • ESG, Sustainability & Non-Financial Reporting
  • Internal Investigations & Corporate Integrity

Related material

  • EU AI Act: Full overview of business requirements
  • Classification of AI systems: practical guide
  • High-risk AI: Compliance roadmap for the provider and user
  • AI Liability: What is changing the new EU directives
  • GDPR and Artificial Intelligence: How to combine the two modes
  • How to build AI Literacy in a company according to the EU AI Act
  • D&O Insurance and Technology Risks: What the Board of Directors Needs to Know
  • AI Governance for the financial sector: special requirements
  • Algorithmic Bias: How to manage the risk of discrimination
  • Crisis management in the AI incident: board-manager

Conclusion

AI Governance at board level is not a technology project or a formal compliance document. It is the exercise of fiduciary duties in a world where artificial intelligence directly affects people’s rights, security, capitalization and business freedom.

A strong position is based on knowledge of their AI systems, their regulatory classification, built into the oversight management structure, documented council decisions and readiness for external audit.

In regulating AI, the winner is not the first to launch the technology. The winner is the one whose board of directors can at any time prove: We knew, we controlled, we acted wisely. This is what separates responsible leadership from inevitable claims.

Have a question about the topic of this article?

Write to us and we will respond within one business day.