We get it: you might not even have made it to this first sentence once you saw the title included “AI.” We are not even 3 years into the generative artificial intelligence era introduced by OpenAI and others. While there is still plenty of wonder around the nifty things AI can do, many are already jaded about, if not sick of, the articles and hype around this technology.
But one cannot deny generative artificial intelligence has been, and will continue to be, transformative in at least two ways. The first is, naturally, AI’s utility as a business tool. We are already seeing upheavals in traditional ways of doing things. While giants like Apple and Google are struggling to adapt Siri and Google Search to compete with new tools, there are many new options for users.
The other transformation is societal. In other words, how individuals, institutions and nations are reacting to AI is affecting everything from regulation to tariffs. This has obvious implications for organizations and their boards.
It is impossible to predict where AI technology will lead us in the coming weeks, let alone years, but that does not mean directors can ignore the consequences “until things shake out.” That may never happen. Much like delaying a computer purchase because the next model will be better, we risk missing out on huge opportunities, and are more susceptible to risks, if a board does not proactively attack the AI landscape.
Directors can be forgiven if they see this as an alarming increase in their already heavy responsibilities. There is no getting around that, but simply ignoring artificial intelligence is not the right course. Even though we cannot predict the nature of AI in the future, there are fundamental steps that can and should be taken to maximize the chances of future success.
Indeed, most of the steps needed for good AI governance are similar to other forms of risk management. That is a key point to remember. Yes, AI is new, often obtuse, and changing daily, but so are other dangers we face in our organizations. That is the nature of risk: preparing and adjusting to the unknown. Most directors are not IT experts, for example, but they can construct systems and processes to help gain information and make informed decisions for the future.
The IT example is appropriate for AI. Artificial intelligence depends on complex computer systems, for one, so they share many risks. As well, as much as almost any other type of potential risk, IT usually requires expert advice to boards so they are aware of the salient points and understand their consequences. AI is the same, and even boards in AI-oriented businesses usually need extra information and advisors to help them.
Given these factors, there are a few key categories a board should look at when developing AI governance policies. Some of these are philosophical and cultural, others are more process oriented and can lend themselves to written policies. Here are a few to start with. We are not assessing the technical details of AI. That is a whole discussion itself, but for these purposes, we can look at artificial intelligence as a risk sometimes like others, and sometimes with special considerations.
Risk assessment
While these are in no special order, this phase is almost always first. The Board should actively identify and assess potential risks arising from AI, such as bias in algorithms, data privacy breaches, security vulnerabilities, and potential legal implications. This implies a key point: the organization will be using AI. It is arguable that it must, to stay competitive. Obviously there will be cases where using generative AI is too dangerous, particularly in industries like defense contracting or similar organizations subject to national security implications. But if an ordinary organization believes that AI is a fad and the world will return to the good old days, well…
Ethical considerations
Another important step is developing and implementing clear ethical guidelines for AI use, including principles such as fairness, transparency, accountability, and human oversight. Like many ethical questions, there are rarely clear-cut guidelines and the ground shifts quickly and often. Those changes are especially present with AI, so directors must keep a constant eye on this category.
Transparency and explainability
An ongoing problem with generative AI systems is their black box nature. Not only is it almost impossible for users to peer into how information is generated, and what data is used, but the developers of AI platforms are unsure themselves of many consequences. Boards should ensure that AI systems are designed with transparency in mind, allowing for clear understanding of how decisions are made and the rationale behind them.
Data governance
One of the biggest risks organizations using AI tools face is confidentiality, which can be threatened if their data is fed into or made accessible to a large language model. This suggests establishing robust data governance practices to ensure data quality, integrity, and compliance with privacy regulations when training AI models. This will include rules and policies for all personnel when using AI to confirm the organization’s proprietary information is not disclosed.
Accountability framework
The opaqueness of AI can create an environment where everyone believes the risks are not their problem. This mindset must be attacked, by defining clear lines of accountability for AI decisions, including who is responsible for potential errors or negative outcomes. Like many HR issues, this can require a deft touch, and there must be a balance between encouraging the use of AI (which can of course lead to mistakes) and an attitude of support, against prohibiting those activities which are clearly dangerous to the organization. Communication is key here, and the board must ensure management is implementing good practices in that regard.
Performance monitoring
Boards must regularly monitor the performance of AI systems, including their accuracy, bias, and impact on business objectives, making adjustments as needed. This will not be done by directors themselves, of course, but every board meeting should have at least some opportunity for directors to question management about monitoring and results received.
Stakeholder engagement
Boards already have extensive obligations to communicate and manage relations with stakeholders. AI is no different, but given its hold on the public’s imagination, there may be a higher duty to ensure everyone understands the organization’s approach to AI. Engage with relevant stakeholders, including customers, employees, and regulatory bodies, to address concerns and build trust regarding AI implementation.
Cross-functional team
An issue with AI is that it is not just a technology problem. It is literally affecting every sector of society, and creating a silo for artificial intelligence within the organization might mean that AI policies are at cross purposes with other endeavours. This can be combated by creating a cross-functional team with expertise in AI, legal, ethics, business, and technology to oversee AI initiatives and decision-making. This will likely begin at the management level, but the board may create policies or committees to ensure it is maintaining effective stewardship.
Training and education
Ensure board members and management have adequate understanding of AI capabilities, limitations, and potential risks to make informed decisions.
Regulatory compliance
It is still an open question how AI will be regulated in the future. Some countries, like the United States, are signaling a hands-off attitude. Other jurisdictions, such as the EU, may be much more active. Canada’s situation is in flux, as the proposed Artificial Intelligence and Data Act died with Parliament’s prorogation in early 2025, and it is anybody’s guess what a future government might do. Boards must stay informed about evolving regulations regarding AI use and ensure compliance with relevant laws and standards.
As is the case with almost anything in governance, treat these categories as a starting point. More may be necessary, depending on the organization, its industry, outside influences, and more. If the organization does not already have a robust risk management regime, that should be the starting point, ensuring that AI is noted as an important component of the risk profile.
Procido’s Governance Group is experienced in working with these types of risks, and has particular experience in IT and AI matters. Please reach out to us with questions or for more information.
Disclaimer
This publication is provided as an information service and may include items reported from other sources. We do not warrant its accuracy. This information is not meant as legal opinion or advice. Contact Procido LLP (www.procido.com) if you require legal advice on the topics discussed in this article.
