<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[The Director Brief]]></title><description><![CDATA[Practitioner-authored AI intelligence for board directors. Free, every Thursday. ]]></description><link>https://www.thedirectorbrief.com</link><image><url>https://substackcdn.com/image/fetch/$s_!Qgl5!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F63b7bce4-815e-4528-a299-c4afa8f19d7f_256x256.png</url><title>The Director Brief</title><link>https://www.thedirectorbrief.com</link></image><generator>Substack</generator><lastBuildDate>Sun, 28 Jun 2026 10:48:03 GMT</lastBuildDate><atom:link href="https://www.thedirectorbrief.com/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[Dharmash Mistry]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[thedirectorbrief@substack.com]]></webMaster><itunes:owner><itunes:email><![CDATA[thedirectorbrief@substack.com]]></itunes:email><itunes:name><![CDATA[Dharmash Mistry]]></itunes:name></itunes:owner><itunes:author><![CDATA[Dharmash Mistry]]></itunes:author><googleplay:owner><![CDATA[thedirectorbrief@substack.com]]></googleplay:owner><googleplay:email><![CDATA[thedirectorbrief@substack.com]]></googleplay:email><googleplay:author><![CDATA[Dharmash Mistry]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[Your AI governance isn’t an IT policy. That’s why it’s failing.]]></title><description><![CDATA[AI governance as a working system. The Four-Domain Frame, the board&#8217;s four jobs reframed around agency, and the six questions that test whether your governance is real.]]></description><link>https://www.thedirectorbrief.com/p/your-ai-governance-isnt-an-it-policy</link><guid isPermaLink="false">https://www.thedirectorbrief.com/p/your-ai-governance-isnt-an-it-policy</guid><dc:creator><![CDATA[Dharmash Mistry]]></dc:creator><pubDate>Thu, 25 Jun 2026 14:26:27 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!nwt6!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb6d4749-46cb-4978-92c5-d4b3e66e6156_4056x2057.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em><strong>This week in The Frame: &#8220;<a href="https://www.thedirectorbrief.com/p/your-board-isnt-slow-on-ai-its-flying">Your board isn&#8217;t slow on AI. It&#8217;s flying blind at speed.</a>&#8221; </strong>The urgency case &#8212; and the new first-order board question is no longer how much risk, but how much agency. Read first. This Library piece is the manual.</em></p><h1>Standing topic, or system?</h1><p>I have watched boards spend ninety minutes on AI in which the CIO ran model accuracy charts, the CISO covered prompt injection testing and the General Counsel summarised the EU AI Act timetable. Nobody asked who owned the AI agenda at executive level. Nobody asked how much agency had been delegated to which agents, what guiderails we had hard coded or who was responsible for each. Nobody asked what the board would see on the dashboard next quarter. Three hours of update across two cycles; zero hours of governance. That gap is what this manual page is built to close.</p><p>Most boards now treat AI as a standing topic. Far fewer treat it as a system. And the system you need now must govern a non-human actor at machine speed &#8212; not a person at quarterly cadence.</p><blockquote><p><em><strong><span>Standing topic produces an update. System produces evidence (real time).</span></strong></em></p></blockquote><p><strong><span>The Stat This Week</span></strong><span><br></span><em><span>65% of organisations now use generative AI in at least one business function. Three in four are running agentic AI in their systems. Fewer than one in five has a defined AI governance operating model that names who is accountable for each agent. Adoption up, agency unowned, evidence flat.</span></em></p><h1>The shorthand</h1><p>Strip the leading frameworks back. OECD&#8217;s updated 2024 principles set the values &#8212; human-centred, transparent, accountable. NIST&#8217;s AI Risk Management Framework reframes them as an operating loop &#8212; Govern, Map, Measure, Manage. The EU AI Act bolts on legal obligation, phased: prohibited practices live since February 2025, general-purpose AI obligations since August 2025, high-risk system obligations from August 2026. The UK&#8217;s principles-led approach leaves more discretion but demands the same outcomes. McKinsey, KPMG/INSEAD, the WEF AI Governance Alliance and the Harvard Law School Forum on Corporate Governance translate the same idea into board-level decisions: align posture, allocate capital, classify risk, govern the lifecycle, evidence the controls.</p><blockquote><p><em><strong><span>AI governance is value + risk + trust, governed as one system. The first-order board question is no longer &#8220;how much risk?&#8221; It is &#8220;how much agency?&#8221;</span></strong></em></p></blockquote><h1>What changes when the actor isn&#8217;t a person</h1><p>Every board operating model in use today rests on a hidden assumption: the actor executing a decision is a human who can be instructed, supervised, slowed down and held to account. Once decisions and actions are delegated to autonomous agents &#8212; pricing engines, customer-routing models, refund bots, credit-check agents &#8212; that assumption breaks. This is not a new agenda item. It changes the substance of nearly every board responsibility.</p><blockquote><p><em><strong><span>AI doesn&#8217;t replace the board&#8217;s duties. It raises the metabolic rate at which they must be discharged.</span></strong></em></p></blockquote><p>The Frame this week works through the structural break; this Library page operationalises the response.</p><h1>The Four-Domain Frame, working as a system</h1><p>The Manifesto introduces the Four-Domain Frame as the navigation grammar of this publication. The Library makes it operational &#8212; the same four domains, the same map, applied as a connected system rather than a list.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!nwt6!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb6d4749-46cb-4978-92c5-d4b3e66e6156_4056x2057.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!nwt6!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb6d4749-46cb-4978-92c5-d4b3e66e6156_4056x2057.png 424w, https://substackcdn.com/image/fetch/$s_!nwt6!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb6d4749-46cb-4978-92c5-d4b3e66e6156_4056x2057.png 848w, https://substackcdn.com/image/fetch/$s_!nwt6!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb6d4749-46cb-4978-92c5-d4b3e66e6156_4056x2057.png 1272w, https://substackcdn.com/image/fetch/$s_!nwt6!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb6d4749-46cb-4978-92c5-d4b3e66e6156_4056x2057.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!nwt6!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb6d4749-46cb-4978-92c5-d4b3e66e6156_4056x2057.png" width="1456" height="738" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/db6d4749-46cb-4978-92c5-d4b3e66e6156_4056x2057.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:738,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:619024,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.thedirectorbrief.com/i/203559174?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb6d4749-46cb-4978-92c5-d4b3e66e6156_4056x2057.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!nwt6!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb6d4749-46cb-4978-92c5-d4b3e66e6156_4056x2057.png 424w, https://substackcdn.com/image/fetch/$s_!nwt6!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb6d4749-46cb-4978-92c5-d4b3e66e6156_4056x2057.png 848w, https://substackcdn.com/image/fetch/$s_!nwt6!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb6d4749-46cb-4978-92c5-d4b3e66e6156_4056x2057.png 1272w, https://substackcdn.com/image/fetch/$s_!nwt6!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb6d4749-46cb-4978-92c5-d4b3e66e6156_4056x2057.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p style="text-align: center;"><strong><span>The Four-Domain Frame</span></strong><em><span> &#183; the navigation grammar of TheDirectorBrief. Cross-cutting: 6-dimension scorecard (Value &#183; Adoption &#183; Risk &#183; Compliance &#183; Capability &#183; Trust), 10 building blocks, 6-month implementation arc.</span></em></p><p>The board&#8217;s job is not to approve every tool or model. It is to ensure four things, one for each domain:</p><blockquote><p><span>&#8226; </span><strong>Strategic intent</strong> &#8212; AI is linked to value, not pilot proliferation. (Strategy &amp; Innovation.)</p><p><span>&#8226; </span><strong>Risk discipline</strong> &#8212; use cases classified, agency assigned explicitly, controls embedded before deployed. (Risk &amp; Resilience.)</p><p><span>&#8226; </span><strong>Agency and accountability</strong> &#8212; every material agent has a named human owner; agency appetite (autonomous / recommend-only / prohibited) decided in advance; accountability never transfers to the agent. (Governance &amp; Accountability.)</p><p><span>&#8226; </span><strong>Capability and trust</strong> &#8212; AI is explainable, fair, secure, lawful and defensible &#8212; and the board itself has the literacy to test that. (Capability &amp; Culture, with Governance.)</p></blockquote><p>A board doing only the first will be blindsided. A board doing only the third will miss the upside. The board that does all four turns AI from a risk to be contained into a capability to be governed.</p><p>Caremark exposure is not theoretical. Since Marchand v. Barnhill (2019) confirmed that boards owe an oversight duty for mission-critical risks, AI has steadily moved into the centre of that line. ISS and Glass Lewis both updated 2024 stewardship guidance to reference AI oversight and disclosure. If your minutes do not show evidence-based AI oversight &#8212; including who owns each material agent &#8212; the question is not whether you should worry. It is when.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.thedirectorbrief.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading The Director Brief! Subscribe for free to receive new posts </p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><h1>The six questions that test whether your governance is real</h1><p>The full Primer carries twenty questions, five per domain. Six are load-bearing. Use these in your next committee. If any of them produces a fluent description rather than a piece of evidence, you have governance theatre.</p><p><strong><span>1. </span>Where does AI create the most value in our business &#8212; and where could it destroy the most value?</strong></p><p>Tests whether AI is integrated into strategy or banished to the cost line. (Strategy &amp; Innovation.)</p><p><strong><span>2. </span>Do we have a complete live inventory of AI use cases &#8212; including GenAI, agents, copilots, shadow agents and vendor-embedded AI?</strong></p><p>Tests whether the board has visibility &#8212; or only the slice management chooses to show. (Risk &amp; Resilience.)</p><p><strong><span>3. </span>Are there AI uses we should prohibit because they are unethical, unlawful or inconsistent with our values?</strong></p><p>Tests whether the board has set a floor. (Governance &amp; Accountability.)</p><p><strong><span>4. </span>How much agency have we delegated to each material AI use case &#8212; autonomous, recommend-only or prohibited &#8212; and is a named human accountable for each?</strong></p><p>Tests whether the operating model is defined or improvised. The new first-order question. (Governance &amp; Accountability.)</p><p><strong><span>5. </span>Can we explain and defend AI-driven decisions to customers, regulators, courts or the media &#8212; and would the logs survive disclosure?</strong></p><p>Tests whether you are defensible. (Risk &amp; Resilience + Governance.)</p><p><strong><span>6. </span>What is the one AI failure scenario that could cause the most reputational harm &#8212; and have we imagined it concretely enough to plan for it?</strong></p><p>Tests whether the board has imagined its worst day in enough detail to act. (Risk &amp; Resilience + Capability &amp; Culture.)</p><h1>Watch, ask, decide</h1><blockquote><p><span>&#8226; </span><strong>Watch.</strong> The gap between the board&#8217;s confidence and management&#8217;s evidence. If the dashboard contains adjectives, not metrics, the gap is wide. If you cannot name who owns each material agent, the gap is wider.</p><p><span>&#8226; </span><strong>Ask.</strong> The chair and the SID &#8212; separately &#8212; who owns AI at executive level, which committee owns which risks, and when the board last received an end-to-end view rather than a topic-by-topic update. Inconsistent answers are the signal.</p><p><span>&#8226; </span><strong>Decide.</strong> Before the next cycle, that the board will receive a single integrated AI dashboard, that the AI inventory will be presented live (not quarterly), and that every material agent will carry a named owner, a documented agency appetite and a tested kill switch.</p></blockquote><h2>Next week in The Library</h2><p><em><strong>Eight ways AI can blow up your business &#8212; and the control architecture that catches them. </strong>The eight risk families tagged to the Four-Domain Frame, the agentic overlay (what changes when the actor is a machine), the ownership map updated for agency, three lines of defence, and the six-dimension scorecard. The Watch companion lands Tuesday; this Library piece lands Thursday.</em></p><h2>About The Library</h2><p><strong>The Library</strong> is the manual and repository &#8212; primers, tools, templates, prompts, checklists, training material, implementation plans, reading lists and courses, plus the weekly <strong>Monday-Morning build</strong>: one tool to test and one prompt to use in your own director workflow, always with a safety note on what not to put into a public LLM. The first three issues are pinned anchors: this framework page, next week&#8217;s risk taxonomy, and the six-month implementation plan in week three.</p><p><strong>What this is, what it isn&#8217;t. </strong>This is one sitting director writing for fellow sitting directors. It is not NACD certification. Not Big Four broadcast. Not Board Agenda observation. Not LinkedIn governance commentary. Not vendor evangelism. UK and Anglo-European, with the regulatory rigour of FRC, FCA, EU AI Act and SEC. Read in thirty minutes. Used by Monday.</p><p><strong>TheDirectorBrief</strong> publishes every Tuesday &#8212; <em>AI for boards.</em> Each issue carries five sections: <strong>The Frame</strong> (strategy), <strong>The Watch</strong> (governance and risk pulse), <strong>Five for the Chair</strong> (board and committee debate), <strong>Signal</strong> (AI news that matters, with STAT and CHART of the week), and <strong>The Library</strong> (primers, tools, templates, prompts and Monday-Morning builds). One read. Thirty minutes. In your inbox before Monday&#8217;s pack.</p><p><em>Subscribe free at <strong>TheDirectorBrief.com</strong> &#8212; or reply to this email. I read every response.</em></p><p><strong>Dharmash Mistry</strong> sits on the boards of Halma plc, Rathbones Group, the Premier League and the Football Association. He has held board positions across more than thirty organisations spanning listed companies, regulated financial institutions, major sporting bodies and venture-backed businesses, including the BBC, British Business Bank, the Competition and Markets Authority, Hargreaves Lansdown plc, Dixons plc, Revolut and Lovefilm. Prior to this he was a Partner at the venture capital firms Balderton and Lakestar. <em>AI for Boards</em> is written from inside the boardroom, not from outside it.</p><h2>Sources</h2><p>1. McKinsey, State of AI 2024 &#8212; generative AI adoption by function. [Primary.]</p><p>2. Grant Thornton, 2026 AI Impact Survey &#8212; agentic AI deployment and incident response. [Primary.]</p><p>3. NACD, 2024 Public Company Governance Survey &#8212; AI in the top three director risks. [Primary.]</p><p>4. Stanford HAI, AI Index Report 2024 &#8212; regulatory mentions across major jurisdictions. [Primary.]</p><p>5. Marchand v. Barnhill (Del. 2019) &#8212; board oversight duty for mission-critical risks. [Primary.]</p><p>6. ISS and Glass Lewis, 2024 stewardship guidance updates. [Primary.]</p><p>7. Working paper: Governing AI Agents in the Enterprise (May 2026) &#8212; the 6-dimension shift and 8-phase continuous loop drawn from internal research; full table sits in The Watch (this week) and the Primer Section B.</p><p>Frameworks referenced: OECD AI Principles (updated 2024); NIST AI RMF 1.0 (2023); EU AI Act 2024/1689; UK DSIT principles; KPMG/INSEAD Global AI Governance Principles 2026; WEF AI Governance Alliance 2024&#8211;25; Harvard Law School Forum on Corporate Governance. [Primary, all.]</p>]]></content:encoded></item><item><title><![CDATA[Your board isn’t slow on AI. It’s flying blind at speed.]]></title><description><![CDATA[The governance gap in 2026 isn&#8217;t caution. It&#8217;s confidence without comprehension. Ten questions, across four domains, and the frame that holds them together.]]></description><link>https://www.thedirectorbrief.com/p/your-board-isnt-slow-on-ai-its-flying</link><guid isPermaLink="false">https://www.thedirectorbrief.com/p/your-board-isnt-slow-on-ai-its-flying</guid><dc:creator><![CDATA[Dharmash Mistry]]></dc:creator><pubDate>Thu, 25 Jun 2026 13:39:36 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!Qgl5!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F63b7bce4-815e-4528-a299-c4afa8f19d7f_256x256.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h1>The finding that should stop every Chair in their tracks</h1><p>A BCG survey of 625 CEOs and board members published last month (May 2026) found that 61% of CEOs believe their boards are rushing AI transformation. Not dragging their feet. Rushing it.</p><p>The explanation buried in the data is worse than the headline: the directors with the lowest confidence in their own AI knowledge are the most likely to believe their organisation is moving too slowly.&#185;</p><blockquote><p><em><strong><span>The directors who understand AI least are the ones pushing hardest for speed.</span></strong></em></p></blockquote><p>This inverts the conventional narrative &#8212; that boards are too cautious, too analogue, too late for the AI moment. The 2026 evidence says something more uncomfortable: boards are not behind AI. They are ahead of what they understand. And that combination &#8212; urgency without literacy, momentum without oversight &#8212; is precisely how consequential decisions get made badly, and at scale.</p><p><strong><span>The Stat This Week</span></strong><span><br></span><em><span>61% of CEOs say their boards are rushing AI transformation &#8212; and directors with the lowest AI literacy are the most likely to believe they are moving too slowly. Urgency is being generated by uncertainty, not by analysis. (BCG, May 2026, n=625.)</span></em></p><h1>The silence in the room</h1><p>I have sat in more than thirty boardrooms across eight countries &#8212; start-ups to government-owned entities, regulators to multi-billion dollar listed organisations, across every seat at the table. The pattern is consistent: creative destruction gets treated as business-as-usual until it isn&#8217;t. I have watched AI strategy presentations receive twenty minutes of agenda time, wedged between the CFO&#8217;s report and AOB. How many of us have sat in meetings approving AI spend with no clear value logic, approving the tech stack without challenging the design choices, treating AI governance as a checklist, measuring success by pilots or tokens, accepting &#8216;human oversight&#8217; without testing if it&#8217;s for real?</p><p>Are we asking the right strategic and governance questions of a technology now reshaping how organisations fundamentally compete and operate &#8212; price, recruit, source, credit-check, market &#8212; where <em>agents, not humans</em>, are increasingly making the decisions?</p><p>What I have not heard &#8212; not once, in any of those rooms &#8212; is the question that matters most:</p><blockquote><p><em><strong><span>If a well-capitalised competitor rebuilt our core product around AI in the next eighteen months, what would remain of our competitive position?</span></strong></em></p></blockquote><p>That silence is the governance gap. Not speed. Not caution. The absence of the question that wasn&#8217;t on the agenda.</p><h1>The numbers no longer allow a comfortable interpretation</h1><p>Two findings now sit alongside each other in a way the boardroom cannot ignore.</p><p><strong>Deployment is happening regardless of readiness. </strong>Grant Thornton&#8217;s 2026 AI Impact Survey finds nearly three in four organisations are giving agentic AI access to their systems and processes &#8212; piloting, scaling or running it in production. Just 20% have a tested AI incident response plan for when it fails.&#178;</p><p><strong>Capital is moving at the same speed. </strong>BCG&#8217;s AI Radar finds corporations expect to lift AI spending from 0.8% to 1.7% of revenues in 2026, with more than half directed at agentic systems.&#179; These are not experimental budgets. They are material capital commitments made into a technology most boards do not yet have the fluency to interrogate.</p><h1>What changes when the actor isn&#8217;t a person</h1><p>Every board operating model in use today rests on a hidden assumption: the actor executing a decision is a human who can be instructed, supervised, slowed down and held to account. Once decisions and actions are delegated to autonomous agents &#8212; pricing engines, customer-routing models, recruitment screens, refund bots, credit-check agents &#8212; that assumption breaks. And once it breaks, the substance of nearly every board responsibility changes with it.</p><p><strong>Governance</strong> moves from directing human actors making occasional, reviewable decisions to deciding how much agency to delegate to a non-human actor in the first place. <strong>Risk</strong> moves from slow, visible and auditable-after-the-fact to fast, opaque and emergent &#8212; errors propagating at machine speed before controls catch them. <strong>Controls</strong> move from detective to preventive, embedded and real-time &#8212; hard caps, whitelists, kill switches built inside the agent. <strong>Compliance</strong> moves from periodic and sample-based to continuous and designed-in. <strong>Assurance</strong> moves from tracing the decision to validating the guardrails under stress, because the reasoning isn&#8217;t transparent. <strong>Accountability</strong> stays exactly where it has always sat &#8212; with a named human &#8212; because it can never transfer to the agent.</p><p>The new first-order board question is no longer <em>&#8220;how much risk are we willing to take?&#8221;</em> It is <em><strong>&#8220;how much agency are we willing to delegate?&#8221;</strong></em> &#8212; where agents may act autonomously, recommend-only, or are banned outright; each with a named human owner; each with a tested kill switch.</p><blockquote><p><em><strong><span>AI doesn&#8217;t replace the board&#8217;s duties. It raises the metabolic rate at which they must be discharged.</span></strong></em></p></blockquote><p>This is why the Four-Domain Frame is not a synthesis of consulting research. It is the operating system the new reality requires &#8212; Strategy, Risk, Governance and Capability held at the same time, because the existing machinery was built for a different actor.</p><h1>The mechanism &#8212; it isn&#8217;t ignorance, it&#8217;s information architecture</h1><p>The problem is not that directors are unintelligent. I want to be clear about that &#8212; and direct about something more uncomfortable.</p><p>The board&#8217;s understanding of AI is almost entirely constructed by either a vendor pitch disguised as &#8216;advice&#8217; or by management. Every briefing, every strategy update, every risk summary &#8212; shaped by people whose incentives run toward demonstrating competence, maintaining momentum and presenting AI as a controlled programme rather than an existential variable. This is not cynicism. It is a structural observation about how boards receive information and how management teams, rationally, frame it.</p><blockquote><p><em><strong><span>The board hears what the risk framework caught. It is almost never told what the risk framework was incapable of seeing.</span></strong></em></p></blockquote><h1>We have been here before &#8212; and we did not learn the right lesson</h1><p>When the internet arrived, boards appointed Chief Digital Officers. The CDO became the governance pressure valve &#8212; the person who ran the digital programme, attended the right conferences, brought in an army of vendors, seeded experiments and then asked to launch a venture fund. Boards called it digital strategy. Meanwhile insurgent entrepreneurs backed by smart VC money went directly after their core profit pools &#8212; disciplined quarterly sprints, real-time customer metrics, not waterfall two-year IT projects out of date at the point of committing funds. Reinvention using technology, not technology applied to what they already did.</p><p>The companies that navigated that transition had something different: a willingness to self-disrupt &#8212; challenging their own legacy economics before someone else did &#8212; and boards and management teams who took a long view of what technology might do to their market, treated governance as part of product quality, and were clear about the problem they were solving and why their solution was meaningfully better. The best live example is Google, managing an AI transition where Search still accounts for over $225 billion &#8212; more than 55% of total revenues. The counter-example: Air Canada&#8217;s chatbot hallucination case, where no one was governing the model end-to-end.</p><p>Stripe and Square went after incumbents&#8217; payment economics; Spotify rebuilt music distribution around access, not ownership; Airbnb did the same to hotels&#8217; fixed-cost economics. On the other side of those bets sat the boards that watched it happen &#8212; Kodak, Blockbuster, Nokia, BlackBerry, Sears &#8212; and many more will follow. The governance failure was not a failure to understand technology. It was a failure to understand what technology did &#8212; to competitive dynamics, to cost structures, to who controlled the customer relationship. Crucially, digital was the CEO&#8217;s job, treated as a cross-business imperative with a board-level strategy. Not delegated to one function. Not run as an IT project.</p><p>The same structural deficit is repeating itself, in compressed time. We are, in 2026, roughly where we were in 2000 &#8212; when the boards that believed they were governing digital transformation were, in most cases, ratifying management&#8217;s story about it. The difference is that the cycle is compressed, the capital commitments are larger, and the competitive and regulatory environment is hardening around boards that cannot demonstrate they asked the right questions.</p><h1>The Four-Domain Frame &#8212; the navigation grammar</h1><p>Stripped back to first principles, the WEF Oversight Toolkit, KPMG/INSEAD&#8217;s Global Principles, McKinsey&#8217;s AI Trust framework and BCG&#8217;s board guidance converge on four domains a board must now own at the same time. Together they are this publication&#8217;s single organising scaffold &#8212; the Four-Domain Frame. Every weekly issue navigates against it.</p><p><strong><span>1/ Strategy &amp; Innovation: </span></strong><em><span>where AI changes the moat</span></em></p><p><span>Posture &#183; capital &#183; value. Disruption &#183; advantage</span></p><p><span>Decisions changed, not just automated</span></p><p><span>2/ </span><strong><span>Risk &amp; Resilience: </span></strong><em><span>what the framework cannot see</span></em></p><p><span>8 risk families; 3 lines of defence. Preventive &#183; real-time</span></p><p><span>3/ </span><strong><span>Governance &amp; Accountability: </span></strong><em><span>how much agency, evidenced</span></em></p><p><span>Agency appetite &#183; named owner. Reserved matters &#183; cadence</span></p><p><span>Evidence, not attestation</span></p><p><span>4/ </span><strong><span>Capability &amp; Culture: </span></strong><em><span>whether the board can govern this</span></em></p><p><span>AI literacy &#183; composition. NomCo trajectory. Personal practice</span></p><p><strong><span>The Four-Domain Frame</span></strong><em><span> &#183; the navigation grammar of TheDirectorBrief. Cross-cutting: 6-dimension scorecard (Value &#183; Adoption &#183; Risk &#183; Compliance &#183; Capability &#183; Trust), 10 building blocks, 6-month implementation arc.</span></em></p><p>Most boards govern one of these well. A few govern two. Almost none govern all four simultaneously &#8212; which is the only configuration that survives this transition. </p><p>The ten questions every board should be asking sit across the four domains. Each carries a consequence: the cost of it going unasked. That cost is the point.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.thedirectorbrief.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading The Director Brief! Subscribe for free to receive new posts</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><h2>Strategy &amp; Innovation</h2><p><strong><span>1. </span>If a well-capitalised competitor rebuilt our core product around AI in the next eighteen months, what would remain of our competitive position?</strong></p><p>Most boards govern AI risk inside the existing business. Almost none ask the disruption question &#8212; not whether AI creates risk in our operations, but whether it lets a rival make our operations irrelevant. Management is paid to defend the model that exists. The board owns the question of whether that model survives.</p><p><strong><span>2. </span>Is our AI investment buying competitive advantage &#8212; or operational parity that every rival will also reach?</strong></p><p>Boards are approving AI spending that doubles in a single year. The right governance question is not how much. It is what for. Efficiency gains from AI are real and accessible to every competitor. The organisations building durable advantage are redefining the product, the customer relationship or the cost architecture in ways that are hard to replicate. Does the board know which category its spend falls into?</p><p><strong><span>3. </span>Is AI changing how this organisation makes decisions &#8212; or simply automating the decisions it already makes?</strong></p><p>This is the line that separates real transformation from expensive process improvement. Most organisations use AI to do existing things faster. Fewer use it to do things differently &#8212; to make decisions with information they could not previously access, at speeds the operating model precluded, at a level of personalisation the old margin structure could not support. The board should know which category describes its programme.</p><h2>Risk &amp; Resilience</h2><p><strong><span>4. </span>What is our AI risk framework built to catch &#8212; and what is it structurally incapable of seeing?</strong></p><p>Risk frameworks identify the risks they were designed to identify. AI introduces categories no pre-AI framework was built to surface: emergent model behaviour, training-data bias at scale, adversarial manipulation, hallucination in high-stakes outputs, and &#8212; new in 2026 &#8212; agentic systems taking sequences of autonomous decisions across connected processes. An audit committee receiving a RAG status update on AI risk is not governing AI risk. It is receiving a summary of classified risks &#8212; which is a different thing entirely.</p><p><strong><span>5. </span>How much agency have we delegated to non-human actors &#8212; and did we decide that, or has it happened to us?</strong></p><p>Three in four organisations now give agentic AI access to their systems; only one in five has tested what happens when it fails.&#178; The board&#8217;s instinct is to ask how much risk. The question that survives the next two years is how much agency. For every material AI use case &#8212; pricing, credit, recruitment, customer routing, supply chain, refund handling &#8212; there are three possible answers: autonomous, recommend-only, prohibited. Each with a named human owner. Each with a tested kill switch. The boards that have made those calls explicitly will be governing. The boards that haven&#8217;t will discover their agency appetite the way pricing committees once discovered their FX exposure: in the incident report.</p><h2>Governance &amp; Accountability</h2><p><strong><span>6. </span>Where does accountability sit when an AI-driven decision causes harm &#8212; and has the board formally assigned it to a named human?</strong></p><p>This is not hypothetical. The EU AI Act&#8217;s requirements are now effective across European markets. The FCA&#8217;s AI governance expectations are hardening. D&amp;O exposure on AI-related harm is live and being tested. Most boards have not formally assigned AI accountability &#8212; not in committee terms of reference, not in management responsibilities, not in the schedule of matters reserved. Accountability never transfers to the agent. The answer, when it matters, will be found in what was documented. Not in what was assumed.</p><p><strong><span>7. </span>Is AI a standing item on the board agenda &#8212; or does it appear only when something goes wrong or management asks for a budget?</strong></p><p>Reactive governance is incident response with a board letterhead. The boards building real oversight treat AI as a live strategic conversation &#8212; at the frequency and seriousness of financial performance &#8212; not as a technology update in the CTO&#8217;s slot once a quarter.</p><h2>Capability &amp; Culture</h2><p><strong><span>8. </span>Are we asking management the questions that matter &#8212; or the questions management has prepared us to ask?</strong></p><p>This is the meta-question, and the one I find most difficult to answer honestly about my own board contribution. When I have been on the presenting side of the table, I knew which questions were coming. I had prepared answers. The questions I had not prepared for were the ones that changed the dynamic &#8212; and they were almost never on the agenda. The BCG finding cuts both ways: if boards are pushing faster than management, the question is whether that pressure is informed or anxious. Governance is not about speed. It is about the quality of the decision.</p><p><strong><span>9. </span>Who in this boardroom has used an AI tool to do something consequential in the last thirty days?</strong></p><p>I include myself in this question. If your understanding of AI is entirely briefing-derived, your pressure for speed cannot be informed. The board cannot meaningfully challenge management&#8217;s AI strategy if its understanding of AI is entirely second-hand. This is not about becoming data scientists. It is the same standard of practical engagement expected of any director overseeing a material business transformation. The board that governed digital without digital experience was the first wave&#8217;s structural error. Repeating it knowingly is harder to excuse.</p><p><strong><span>10. </span>Do we have the board composition to govern the company we are building &#8212; not just the one we have?</strong></p><p>The NomCo&#8217;s job has always been to ensure the board has the skills the strategy requires. If the strategy now includes material AI transformation, agentic systems deployment and regulatory navigation under the EU AI Act, the skills required have changed. Not more technologists &#8212; more directors with the economic intuition to read what AI does to competitive dynamics, cost structures and the value of human judgment. A board effectiveness review that does not address this is answering the wrong question.</p><h1>What good looks like</h1><p>The boards I have seen govern AI substantively well were not, in most cases, the ones with more technical expertise on the register. The difference was a Chair who treated AI as a strategy and accountability question before a technology question &#8212; and who created space for the board to interrogate the framing rather than the numbers.</p><p>In one such room, the Chair stopped an AI strategy presentation forty minutes in and asked a single question: <em>&#8220;What happens to this business if this plays through &#8212; what happens to the market we operate in?&#8221;</em> The conversation that followed was the most productive AI strategy and governance discussion I have been part of. It changed the decision &#8212; not the investment level, the <em>question</em> the investment was designed to answer.</p><p>I have also seen the operating model done well: a three-session board sequence on a single strategic debate &#8212; market and technology understanding with external experts (information gap closed), options without a proposal (expertise drawn out across the table without bias), then a decision with clear success criteria and risks. That beats forty minutes between the CFO report and AOB. It also beats the 45-minute management pitch with 15 minutes for questions. Given the speed of AI development, this cannot be reserved for the annual strategy away day.</p><p>And &#8212; increasingly often &#8212; the board has had to make the agency question explicit. I sat through a debate on an autonomous customer-routing agent where the discussion moved from <em>&#8220;is the model accurate enough?&#8221;</em> to <em>&#8220;how much can this agent spend per case without human approval; where does the human pick up; what&#8217;s the kill-switch test; who gets paged when an anomaly hits?&#8221;</em> That conversation took ninety minutes. It was the most useful ninety minutes the board spent that year &#8212; because the agency appetite was decided <em>before</em> the agent shipped, not discovered <em>after</em> the incident.</p><blockquote><p><em><strong><span>Effective AI governance is not a framework. It is a quality of attention &#8212; and the willingness to ask the question that was not prepared for.</span></strong></em></p></blockquote><h1>Before your next board meeting</h1><p>Three things. Not ten.</p><blockquote><p><span>&#8226; </span><strong>Watch.</strong> Which agenda items involve AI decisions &#8212; directly, or in the assumptions behind them &#8212; that the board has not explicitly discussed as AI decisions?</p><p><span>&#8226; </span><strong>Ask.</strong> Of the ten questions above, which three would most change your board&#8217;s current AI conversation? Take those three in. One is enough to shift the dynamic.</p><p><span>&#8226; </span><strong>Decide.</strong> Does your board&#8217;s current composition give you the experiential authority to govern the AI strategy you are approving? If the honest answer is no, what are you and the NomCo going to do about it today &#8212; not as a future problem?</p></blockquote><h2>This week in The Library</h2><p><em><strong>Your AI governance isn&#8217;t an IT policy. That&#8217;s why it&#8217;s failing. </strong>The companion to this Manifesto &#8212; the framework, the board&#8217;s four jobs and the six diagnostic questions that test whether your governance is real. Read after this.</em></p><h2>Next week in The Frame</h2><p><em>The scientists who built AI are calibrating real harm in double digits. The regulators are catching up. Next Tuesday&#8217;s Frame works through what that means for fiduciary duty &#8212; and why the boards that build governance because Brussels told them to will build the wrong thing. <strong>&#8220;Skynet didn&#8217;t have a board. Your company does.&#8221;</strong></em></p><h2>About The Frame</h2><p><strong>The Frame</strong> carries the editorial argument of the week &#8212; one strategic question worked through with evidence, in-the-seat experience and a so-what a director can act on. Short version in your inbox; long version on Substack for subscribers. </p><p><strong>What this is, what it isn&#8217;t. </strong>This is one sitting director writing for fellow sitting directors. It is not NACD certification. Not Big Four broadcast. Not Board Agenda observation. Not LinkedIn governance commentary. Not vendor evangelism. UK and Anglo-European, with the regulatory rigour of FRC, FCA, EU AI Act and SEC. Read in thirty minutes. Used by Monday.</p><p><strong>TheDirectorBrief</strong> publishes every Tuesday &#8212; <em>AI for boards.</em> Each issue carries five sections: <strong>The Frame</strong> (strategy), <strong>The Watch</strong> (governance and risk pulse), <strong>Five for the Chair</strong> (board and committee debate), <strong>Signal</strong> (AI news that matters, with STAT and CHART of the week), and <strong>The Library</strong> (primers, tools, templates, prompts and Monday-Morning builds). One read. Thirty minutes. In your inbox before Monday&#8217;s pack.</p><p><em>Subscribe free at <strong>TheDirectorBrief.com</strong> &#8212; or reply to this email. I read every response.</em></p><p><strong>Dharmash Mistry</strong> sits on the boards of Halma plc, Rathbones Group, the Premier League and the Football Association. He has held board positions across more than thirty organisations spanning listed companies, regulated financial institutions, major sporting bodies and venture-backed businesses, including the BBC, British Business Bank, the Competition and Markets Authority, Hargreaves Lansdown plc, Dixons plc, Revolut and Lovefilm. Prior to this he was a Partner at the venture capital firms Balderton and Lakestar. <em>AI for Boards</em> is written from inside the boardroom, not from outside it.</p><h2>Sources</h2><p>1. BCG, AI in the Boardroom, May 2026 &#8212; survey of 625 CEOs and board members. [Primary &#8212; verify release.]</p><p>2. Grant Thornton, 2026 AI Impact Survey &#8212; agentic AI deployment and incident response readiness. [Primary.]</p><p>3. BCG, AI Radar 2026 &#8212; corporate AI spend as percentage of revenue. [Primary.]</p><p>Performance reference: MIT CISR, Board Digital Fluency and Performance, March 2025 &#8212; AI-fluent boards outperform peers by 10.9 percentage points in ROE; non-fluent boards trail by 3.8%. Carried in The Library&#8217;s board-effectiveness primer. [Secondary.]</p><p>Frameworks referenced: WEF AI Governance Toolkit (2024&#8211;25); KPMG/INSEAD Global AI Governance Principles (April 2026); McKinsey, State of AI Trust 2026 &#8212; Shifting to the Agentic Era; BCG AI Radar 2026. Agentic governance logic drawn from working paper Governing AI Agents in the Enterprise (Library, May 2026). [Primary, all.]</p>]]></content:encoded></item></channel></rss>