Quick answer: AI governance is not a compliance checkbox. It is a leadership judgment about restraint. AI is a force multiplier, one unit in, ten out, and it amplifies whatever it touches, good or bad. So the board’s real job is not to ask “are we doing enough AI?” The board’s job is to set the restraint perimeter: to decide what must NOT be multiplied yet. Governance is how you make sure the company is not multiplying the wrong things at machine speed. Watch the risk register, yes. But watch the human capital harder, because that is where a flawless rollout does its quietest damage.
By Andreas Pettersson, founder of Leaders ADAPT and a former Canon AI executive who built and sold an AI company before ChatGPT existed.
Let me be direct. Most boards get AI governance backwards.
They treat it as a compliance problem. A checklist. A risk register with a new row on it. The audit committee gets a quarterly update, somebody nods, and everyone agrees the company is “managing AI risk.” It feels responsible. It isn’t. Governance built as a checkbox watches for the failures it already knows how to name. Bias. Data leakage. A model nobody can explain. Those are real. But the board that asks only “are we compliant?” never asks the question that matters most: where are we multiplying force we cannot yet control?
I have lived on both sides of this table. I built and sold an AI company that did machine learning at scale years before ChatGPT made any of this a boardroom topic, then watched the market commoditize the exact thing we had built from scratch. Here is what that taught me. The technology was never the advantage, and it was never the real risk either. Both lived in one place: judgment about where to point the thing. That is what a board governs. Not the model. The placement.
This guide to AI for boardrooms is part of the AI for CEOs series. The companion pieces on AI leadership blind spots and the fractional Chief AI Officer model cover the executive side of the same problem.
What is AI governance leadership, really?
AI governance leadership is the board’s job of deciding what the company should and should not multiply with AI, and holding the line on the second half of that sentence.
That second half is the part everyone skips. Let me explain why it matters so much.
Picture what AI actually is at the level a board operates. It is a force multiplier. One unit of effort in, ten units out. A lever. And like any lever, it amplifies whatever it touches. Point it at a strong process and you get a much stronger one. Point it at a broken process and you scale the brokenness, faster and at lower cost. Point it at a weak culture and you get a weaker one, at speed.
So governance is not mainly about stopping a model from misbehaving. Governance is about making sure the company is not multiplying the wrong things in the first place. A force multiplier pointed at the wrong target does not fail loudly. It succeeds, efficiently, at the wrong objective. That is far more dangerous, because nothing trips an alarm.
Here is the reframe that changes how a board should think. Most boards walk in asking a growth question. “Are we doing enough AI? Are we behind? What are competitors shipping?” Reasonable instincts. Wrong starting point. The better question, the one that actually protects shareholder value, is a restraint question.
Where are we multiplying force we cannot yet control?
Ask that first. Before the AI strategy update. Before the vendor roundup. Before anyone shows the board a dashboard of adoption metrics. Because adoption is not the risk. Unconsidered adoption is.
Why is AI governance a leadership call and not a compliance checkbox?
Because the most important governance decisions are judgment calls about restraint, and a checklist cannot make a judgment call.
A compliance checklist answers a closed question: did we do the required thing, yes or no. Useful. Necessary. But the decisions that separate the boards that win from the boards that get blindsided are open questions. Should we multiply this decision at all, given our culture today? Is this process strong enough to amplify, or will scaling it scale a mess? Do we trust this part of the business enough to let it run ten times faster before a human looks at it? No checkbox answers those. Only judgment does, and judgment is exactly what a board exists to supply.
This is where the MOMENTA restraint question becomes the heart of AI governance. In the operating system I teach the CEOs I work with, the single highest-return question is this: what must NOT be multiplied yet? Most leaders never ask it. They ask where they can deploy, what they can automate, which vendor demos best. Those questions produce activity. The restraint question produces a perimeter.
Think of that perimeter as the board’s real deliverable. Not a policy document. A short, explicit list of what the company will not point AI at yet, and why, given the trust, the data quality, and the incentives as they stand right now. It is the one thing only the board can authorize. Management is paid to move. The board is positioned to say “not that, not yet.” That is not caution. That is the strategy. The boards that win at AI are not the ones that deploy the fastest. They are the ones most deliberate about what they leave untouched while everyone around them scales without thinking.
The IT delegation trap, applied to the board
Here’s a failure pattern I see constantly, and it is the board version of a trap that sinks companies.
A board realizes it needs AI oversight. So it does the responsible thing. It delegates governance to IT, or to legal, or to both. IT handles the technical risk. Legal handles the regulatory exposure. The board gets a clean report. Everyone feels covered.
And the business-leverage question vanishes completely.
Here is why this fails, and it is not because IT or legal do their jobs badly. It is because they do their jobs exactly as designed. IT is built to secure, integrate, and contain. Legal is built to limit liability. Both are essential. Neither is accountable for where the business should be multiplying force, or for what it must not multiply yet. Hand AI governance purely to those functions and you get a containment plan and a liability memo. You do not get a restraint perimeter tied to the business. The single most important judgment, the one about leverage and restraint across the whole enterprise, falls into the gap between departments, because no department owns the whole board. You do.
The trap is not that IT or legal fail you. The trap is that they succeed at exactly what they were built for, and in doing so they quietly answer a smaller question than the one that matters. Governance handed purely to IT or legal misses the business-leverage question entirely. That is a leadership miss, and only the board can correct it, because only the board sees the whole picture.
The AI Culture Trap: when a flawless rollout still erodes the company
Here is the failure that almost no risk register catches, and it is the one I would put at the top of any board’s AI watchlist. You can run a technically flawless AI rollout and still hollow out the company.
I call it the AI Culture Trap. The deployment works. The tools are adopted. The metrics look great. And underneath the clean numbers, something corrosive is happening to your people. They are shifting, quietly, from deciding to approving. From owning the work to rubber-stamping a machine’s version of it. The judgment muscle atrophies. Ownership thins out. Morale follows, even when nobody can point to a single thing that went wrong. A risk checklist will never catch this, because nothing failed. The rollout was a success. The culture was the casualty.
So a board governing AI well has to watch the human capital, not just the risk register. And most boards are not equipped to see it. Deloitte surveyed 695 board members and executives across 56 countries in early 2025 and found that 66% of boards still have limited or no knowledge and experience with AI, and that nearly a third do not have AI on the board agenda at all. A signal that lives in employee sentiment, not in any model audit, has no chance of reaching a boardroom that is not yet even discussing the technology.
The encouraging half of the same survey points to the fix. Boards that treat AI as a standing leadership topic are closing the gap: the share of boards with AI missing from the agenda fell from 45% to 31% between the 2024 and 2025 editions of the Deloitte survey, and 40% of respondents now say AI has changed how they think about the makeup of the board itself. Oversight of the human side of AI is a capability a board builds deliberately, meeting by meeting. It does not appear on its own.
Put those two findings together and the governance instruction is clear. The board’s job is not to maximize AI adoption. It is to make sure AI amplifies people instead of replacing their judgment, and to build the board literacy to tell the difference. That belongs on the board agenda next to the risk one, not buried under it. Watch the morale data the way you watch the financials, because in the age of the force multiplier, the culture is the early warning system.
Why do most AI initiatives fail, and why does governance decide it?
Because the judgment is missing, not the technology. And governance is where a board supplies that judgment, or fails to.
Here is the hook stat I want every director to remember. MIT studied corporate AI and found that 95% of AI initiatives fail to turn a profit. The other 5% see rapid revenue and profit acceleration. Same models, same tools, same off-the-shelf availability for everyone. So the gap between the 5% and the 95% cannot be the technology. The gap is judgment about where to place it, and what to leave alone. That is a governance finding hiding inside a performance stat. The 5% win partly because somebody with authority decided what not to multiply, protected the parts of the business that were not ready, and refused to scale a broken process just because the tool made it cheap. At the level where it counts most, that somebody is the board.
The corroborating data tells the same story. RAND found that more than 80% of AI projects fail, about twice the rate of regular IT projects. S&P Global reported that the share of companies abandoning most of their AI initiatives jumped from 17% in 2024 to 42% in 2025. Those are not model failures. They are placement failures, what happens when nobody set a restraint perimeter and the company multiplied force into the wrong corners until it gave up.
So governance is part of why the 5% win. Not because the board picked the right algorithm, but because it asked the restraint question, held the perimeter, and watched the human capital while management chased the upside. For the deeper anatomy of these failures, the leadership case is laid out in AI Strategy for CEOs.
What does good AI governance actually look like on the agenda?
It looks like a board that stops asking only “are we doing enough?” and starts asking “where are we multiplying force we cannot yet control?” Concretely, here is what I would put in front of a board that wants to govern AI like leaders instead of compliance officers.
Make the restraint perimeter a standing item. Once a quarter, management brings the board the explicit list of what the company is choosing not to multiply yet, and why. Not a list of what it is deploying. A list of what it is holding back. If management cannot produce that list, you have found your first governance gap.
Put one human-capital metric next to every AI initiative. Adoption is not enough. Ask for the morale and ownership signal alongside it. Are people still deciding, or have they slid into approving? A flawless rollout with falling ownership is a yellow flag, and only the board is positioned to call it.
Keep the business-leverage question out of the gap between departments. IT reports on technical risk. Legal reports on exposure. Good. But the board itself, not a delegated function, owns the question of where the company should and should not be pointing the lever. That cannot be outsourced, because the accountability cannot be outsourced.
And ask the restraint question out loud, every time, and write down that you asked it. Where are we multiplying force we cannot yet control? Document the answer. Governance is judgment exercised on the record, not a policy filed and forgotten.
That is the whole motion. A perimeter, not a checklist. A human-capital signal, not just a risk row. One question, asked relentlessly. Do that, and the board is leading AI instead of merely auditing it.
Two outside anchors help structure those questions, and they are the two your audit committee will hear about first. The EU AI Act is now phasing in: prohibitions on certain AI systems and AI literacy duties have applied since February 2, 2025, obligations for general-purpose AI models since August 2, 2025, and most remaining obligations, including those for high-risk systems, apply from August 2, 2026. If the company touches the EU market, ask management which bucket it falls into and when. The second anchor is the NIST AI Risk Management Framework, the voluntary US framework released in January 2023 that gives boards a shared vocabulary of govern, map, measure, and manage. Neither replaces the restraint question. They give it a calendar and a language.
The security-productivity slider is the board-level setting that decides how much AI capability employees get in exchange for how much control the company keeps: security on one end, productivity on the other, and a deliberate mark in between. Every board sets this slider whether it admits it or not. Most set it by default, through accumulated policies, rather than by decision. Setting it on purpose, and recording where and why, is governance in one sentence.
How do regulated firms balance security and productivity?
Badly, in most cases, and in one predictable direction. A lot of organizations haven’t had time to figure out what their AI policy is, so they restrict rather than enable, just to be on the safe side. It feels like governance. It’s actually the absence of it.
I watched this from inside a compliance-heavy firm. Lower-level employees had quietly found ways to automate about 80% of their own work. Real output, real hours back. Leadership’s response was policy after policy to slow them down until the top of the company could understand what was happening, partly because some senior leaders felt the automation indirectly challenged their own worth. The employees didn’t stop believing in AI. They stopped believing in leadership.
I’ve seen the same posture at a software company with thousands of employees that rejected simple AI debugging tools over hack fears. That company is now losing engineers who feel they’re going stale against the market. The pattern repeats: they wait too long, competitors adopt AI, and now they also have to fight the controlling compliance culture they already put in place.
The enable posture looks different. One SEC-regulated advisory firm I worked with took the fears seriously (ransomware, examination exposure, inexperienced misuse) and then set the slider deliberately: team accounts only, data held outside the AI tools on company-controlled drives, read-only access where write access wasn’t needed, zero-retention and no-training terms in the vendor agreement, and an internal policy that keeps a human in the loop on anything client-facing. Same regulator. Same risks. Working tools.
The two postures side by side:
| Question | Restrict posture | Enable posture |
|---|---|---|
| Default answer to a new AI use case | No, until proven safe | Yes, inside named guardrails |
| Who decides | Accumulated policies | The board, on the record, quarterly |
| Data location | Wherever each tool puts it | Company drives, outside the tools |
| Accounts | Mixed personal and corporate | Team accounts only, tracked history |
| Risk that grows over time | Shadow AI, talent loss, competitive lag | Bounded tool risk, actively audited |
| What employees learn | Ask forgiveness or leave | Ask early, build in the open |
What disclosure obligations surprise boards?
The one almost nobody scopes: meeting recordings. At SEC-regulated firms I’ve advised, meetings attended by a regulator’s representative carry disclosure obligations for the full recorded content, and an AI note-taker joining that meeting creates exactly such a record. The fix is procedural, not technological: the AI policy has to say which meetings recorders may join, who is told, and how external versus internal communication is treated under the regulation. If your board has never seen the meeting-recorder clause of your AI policy, that’s because it doesn’t exist yet.
The AI governance guardrail checklist
Guardrails beat gates. A gate stops movement until someone opens it; a guardrail lets the company drive at speed without leaving the road. This is the checklist I walk boards through, and every item traces to a failure I’ve seen firsthand:
- Name the executive owner. AI is never delegated wholly to IT or legal.
- Write the restraint perimeter: the explicit list of what the company will not multiply yet, reviewed quarterly.
- Set the security-productivity slider on purpose, and record where it sits and why.
- Team AI accounts only. No personal accounts touch company work.
- Company data lives outside the AI tools, on drives the organization controls; prompts and history sit at team level. Done right, an employee’s AI skills keep working for the company after they leave.
- A written AI policy that covers meeting recorders and note-takers, including disclosure exposure in regulated settings.
- A human-capital metric next to every AI initiative: are people still deciding, or merely approving?
- A quality-control gate for AI output, with coaching first and consequences after; unreviewed AI output shipped to customers is a people problem, not a tool problem.
- Map your regulatory bucket: EU AI Act timeline if you touch the EU market, NIST AI RMF vocabulary either way.
- Ask the restraint question out loud at every meeting, and document that you asked it.
Boards that can check all ten govern AI. Boards that can’t are auditing it, and the difference shows up first in why AI rollouts fail at the leadership level, and next in how the workforce reorganizes around the tools, which is moving fast enough that I track it in the 2026 AI workforce management trends.
Where to go next
For the full picture of leading AI without being technical, start with the hub, AI for CEOs. For the leadership case that AI strategy belongs to leaders and not to IT or a vendor, read AI Strategy for CEOs.
If you want to make these calls in a room of leaders facing the same governance questions, that is what the AI Executive Mastermind is built for. And if you want the restraint question, the seven traps, and the full operating system in one place, it is all in the book, AI Leadership Mastermind.
Your one move before the next board meeting: ask management for the list of what the company is choosing not to multiply yet. If that list does not exist, you have just found the most important agenda item you have.
Join the AI Executive Mastermind | Get the book
Frequently asked questions
What is AI governance leadership?
AI governance leadership is the board’s job of deciding what the company should and should not multiply with AI, and holding the line on restraint. AI is a force multiplier, one unit in and ten out, so it amplifies whatever it touches, including weak processes and a fragile culture. Governance is how the board makes sure the company is not multiplying the wrong things at machine speed. The core question is not “are we doing enough AI?” but “where are we multiplying force we cannot yet control?”
Is AI governance a compliance issue or a leadership issue?
It is a leadership issue first. A compliance checklist answers closed questions, such as whether a required control exists. The decisions that actually protect shareholder value are open judgment calls about restraint: whether to multiply a given process at all, given the company’s culture, data quality, and trust as they stand today. A checkbox cannot make that judgment. Only the board can, which is why governance is a leadership call and not a paperwork exercise.
What should a board ask about AI?
The most important question is the restraint question: what must NOT be multiplied yet, and where are we multiplying force we cannot yet control? Boards should also ask for the explicit list of what management is choosing to hold back and why, a human-capital signal next to every AI initiative, and proof that the business-leverage decision is owned by the board rather than lost in the gap between IT and legal. Document that these questions were asked.
How does AI affect employees and company culture?
It can quietly erode them even when a rollout succeeds technically. People shift from deciding to approving, ownership thins, and morale drops. Most boards are not positioned to catch this: Deloitte found in early 2025 that 66% of boards still have limited or no knowledge and experience with AI, and 31% do not have AI on the agenda at all. Good governance watches this human capital, not just the risk register, and builds the literacy to see it.
Why do most corporate AI initiatives fail?
Because the judgment is missing, not the technology. MIT found 95% of AI initiatives fail to turn a profit while 5% win with the same tools. RAND found more than 80% of AI projects fail, about twice the rate of regular IT projects, and S&P Global reported companies abandoning most of their AI initiatives rose from 17% in 2024 to 42% in 2025. These are placement failures, not model failures. Governance is part of why the 5% win, because the board sets the restraint perimeter the others never set.
What does good AI governance look like on a board agenda?
The post says good AI governance shows up as recurring board attention to where AI creates leverage and risk, not a one-time compliance sign-off. The board asks who owns the AI strategy, what could go wrong, and how it changes the workforce and culture. Governance becomes a standing agenda item that shapes the AI decision, rather than a checkbox after the fact.
What belongs in an AI governance guardrail checklist?
Ten items cover the core: a named executive owner, a quarterly restraint perimeter, a deliberately set security-productivity slider, team-only AI accounts, company data held outside the tools, a written AI policy covering meeting recorders, a human-capital metric per initiative, a quality-control gate for AI output, a mapped regulatory bucket (EU AI Act, NIST AI RMF), and the restraint question asked on the record at every meeting.
Do AI note-takers create compliance obligations?
In regulated settings, yes. At SEC-regulated firms, meetings attended by a regulator’s representative can carry disclosure obligations for recorded content, and an AI note-taker joining such a meeting creates that record. AI policies should state which meetings recorders may join, who is informed, and how external communication is treated under the applicable regulation. Most policies written before 2026 never mention recorders at all.
Sources
- MIT, The GenAI Divide: State of AI in Business 2025
- RAND, The Root Causes of Failure for AI Projects
- S&P Global Market Intelligence, Generative AI shows rapid growth but yields mixed results
- Deloitte Global Boardroom Program, Governance of AI: A critical imperative for today’s boards, 2nd edition (2025)
- EU AI Act Implementation Timeline, Future of Life Institute
- NIST AI Risk Management Framework


