Why AI Still Lacks the Standing Board Briefing Cadence Cybersecurity Already Has
Who answers the board's questions about AI?
Someone does. It’s rarely the person who owns it.
The Situation
Posted AI officer and Head of AI roles from the last few months at banks, insurers, and health care organizations now split along a fairly clean line: some focus on driving AI value and adoption, and the others on ensuring AI governance and risk are managed. But those two mandates rarely appear in the same job description. The seats almost always report one or even two levels below the traditional C-suite, which is unremarkable on its own, but what's different is that AI risk now carries the same director-level exposure cybersecurity does, and cyber earned a standing board review while AI is still briefed by exception.
The Exposure
EY's review of 2025 10-K and proxy filings of companies in the Fortune 100 found that 99% disclosed how often management reports to the board on cybersecurity versus only 9% for AI, and 89% named a management role that briefs the board on cyber against only 8% for AI. All in the same proxies, drafted in the same season, for the same board. The EY report also found 48% disclosed AI as a focus of board risk oversight, so the oversight is being claimed in regulatory compliance documents while the cadence and the briefer go unnamed. On paper, your board oversees AI. On the calendar, nobody's scheduled to tell them anything.
The Judgment Call
Not every function can have a direct line to the board, and the executive layer exists so directors hear a synthesized view instead of fourteen operating updates, so the burden is on AI to earn the slot. A recurring item on an oversubscribed audit committee agenda is a real cost, and a standing slot filled with a dashboard nobody reads is worse than no slot at all. Cyber oversight works because the CISO presents it, which means directors can question the person who knows what actually happened, instead of the executive above them. So give AI a standing place on the audit or risk committee calendar, put the executive who owns the deployments in the seat, and set the cadence in advance rather than being incident-driven. The scarce skill in that seat is knowing what to leave out: enough technical substance for the committee to judge the exposure, and enough business awareness that oversight doesn’t turn into a management review. Neither of the current mandates for this role asks for that.
Risk: The executive who currently carries the AI story to the board will likely feel marginalized, and if the person going into the seat can’t balance both sides then the committee gets a briefing where it can’t tell a real exposure from a technical detail.
Benefit: Directors question the person who knows what's deployed, and weigh the benefits with the risks on your firm’s schedule instead of an incident timetable.
This Week’s Action
What to do: Pull the agendas and minutes for your last four audit or risk committee meetings. For each one, mark whether AI appeared as its own item or only inside another update, and write down who presented it.
Who to involve: Your corporate secretary or whoever builds the committee agenda, and the executive who currently carries AI to the board.
What outcome to achieve: A one-page summary showing, for each of the four meetings, whether AI had its own item and who presented it. If AI never appeared on its own, or the presenter was never the executive who owns the deployments, that's what to take to your committee chair before the next agenda gets set.
Time required: 75 minutes; 45 to pull four meeting agendas and minutes and mark them, 30 to build the comparison and draft the ask.
Artifact
Answer for your last 4 audit or risk committee meetings, in order:
1. Did AI appear as its own agenda item?
Not inside the technology update, not inside the enterprise risk report - is it its own line, with its own time allocation?
→ In 3-4 of the meetings: Continue to Question 2.
→ In 0-2: Stop here and count cyber for the same four meetings. The gap between those two numbers is your case to bring forward.
2. Who presented it?
Name the person who was in the room answering questions, not the person whose name was on the deck.
→ The executive who owns AI deployments: Continue to Question 3.
→ Someone above them, or a functional executive summarizing others' work: Your directors have been questioning a narrator; name the owner and put them on the next agenda.
3. Was the timing set in advance?
Verify whether the item was on the annual committee calendar before the meeting year started, or added in response to something.
→ On the calendar in advance: Continue to Question 4.
→ Added in response to an incident, an audit finding, a regulator, or a vendor issue: You have exception reporting. Ask the chair to put AI on next year's calendar now, while nothing is wrong.
4. Could the committee act on what they heard?
Read the minutes. Look for a director question that changed a decision, requested a follow-up, or placed a condition on a deployment.
→ Yes, the directors substantially engaged: Your structure works. Recheck it annually and confirm the owner hasn't changed.
→ No, only receipt of the report or cursory board feedback: The cadence is in place but the seat isn't doing its job. That's a leader problem, not a calendar problem, and needs to be addressed.
If your audit committee chair hasn't checked whether AI appears anywhere on next year's agenda calendar the way cybersecurity does, that takes ten minutes and it's the version of this finding they can act on without waiting for you.
Working through a specific AI decision right now? Reply to this email and tell me what it is. I read every response and answer directly.
When the stakes exceed your internal capacity:
AI Exposure Diagnostic: A 2-hour strategic evaluation for risk, compliance, and legal leaders to identify your highest-priority governance gaps and deliver a 90-day remediation roadmap.
12-Week Governance Sprint: Translate regulatory requirements into audit-ready policies, control frameworks, and accountability structures.
Fractional Chief AI Officer: Embedded ownership of governance, intake, and board reporting before the function is formalized, with the eventual role scoped and the search supported when it's time to hire.
Reply with "Diagnostic," "Sprint," or "Fractional" to schedule a conversation for next month.
Chris Cook writes Judgment Call weekly for compliance and risk officers navigating AI governance.
Former IBM Vice President and Deputy Chief Auditor. Published in the AI Journal, speaker at Yale.
Chris Cook
Managing Partner & Founder
Blackbox Zero
Forwarded this by a colleague? Subscribe to Judgment Call