Your board isn’t slow on AI. Maybe it's flying blind at speed?
A new framework to avoid the trap & 10 questions every board should be asking?
The finding that should stop every Chair in their tracks
A BCG survey of 625 CEOs and board members published last month (May 2026) found that 61% of CEOs believe their boards are rushing AI transformation. Not dragging their feet. Rushing it.
The explanation buried in the data is worse than the headline: the directors with the lowest confidence in their own AI knowledge are the most likely to believe their organisation is moving too slowly.¹
The directors who understand AI least are the ones pushing hardest for speed.
This inverts the conventional narrative — that boards are too cautious, too analogue, too late for the AI moment. The 2026 evidence says something more uncomfortable: boards are not behind AI. Some are ahead of what they understand. And that combination — urgency without literacy, momentum without oversight — is precisely how consequential decisions can get made badly, and at scale.
The Stat This Week
61% of CEOs say their boards are rushing AI transformation — and directors with the lowest AI literacy are the most likely to believe they are moving too slowly. Urgency is being generated by uncertainty, not by analysis. (BCG, May 2026, n=625.)
The silence in the room
The history of disruption rhymes. The pattern is common: creative destruction gets treated as business-as-usual until it isn’t. Have you sat in meetings approving AI spend with no clear value logic, approving the tech stack without challenging the design choices, treating AI governance as a checklist, measuring success by pilots or tokens, accepting ‘human oversight’ without testing if it’s for real? No need to put your hand up.
Are we asking the right strategic and governance questions of a technology now reshaping how organisations fundamentally compete and operate — price, recruit, source, credit-check, market — where agents, not humans, are increasingly making the decisions?
The question that matters most:
If a well-capitalised competitor rebuilt our core product around AI in the next eighteen months, what would remain of our competitive position?
That absence of that question that wasn’t on the agenda is the governance gap. Not speed. Not caution.
The numbers no longer allow a comfortable interpretation
Two findings now sit alongside each other in a way the boardroom cannot ignore.
Deployment is happening regardless of readiness. Grant Thornton’s 2026 AI Impact Survey finds nearly three in four organisations are giving agentic AI access to their systems and processes — piloting, scaling or running it in production. Just 20% have a tested AI incident response plan for when it fails.²
Capital is moving at the same speed. BCG’s AI Radar finds corporations expect to lift AI spending from 0.8% to 1.7% of revenues in 2026, with more than half directed at agentic systems.³ These are not experimental budgets. They are material capital commitments made into a technology most boards do not yet have the fluency to interrogate.
What changes when the actor isn’t a person
Today’s operating model rests on a hidden assumption: the actor executing a decision is a human who can be instructed, supervised, slowed down and held to account. Once decisions and actions are delegated to autonomous agents — pricing engines, customer-routing models, recruitment screens, refund bots, credit-check agents — that assumption breaks. And once it breaks, the substance of executive & board responsibility changes with it.
Governance moves from directing human actors making occasional, reviewable decisions to deciding how much agency to delegate to a non-human actor in the first place. Risk moves from slow, visible and auditable-after-the-fact to fast, opaque and emergent — errors propagating at machine speed before controls catch them. Controls move from detective to preventive, embedded (in the code) and real-time — hard caps, whitelists, kill switches built inside the agent. Compliance moves from periodic and sample-based to continuous and designed-in. Assurance moves from tracing the decision to validating the guardrails under stress, because the reasoning isn’t transparent. Accountability stays exactly where it has always sat — with a named human — because it can never transfer to the agent.
The new first-order board question is no longer “how much risk are we willing to take?” It is “how much agency are we willing to delegate?” — where agents may act autonomously, recommend-only, or are banned outright; each with a named human owner; each with a tested kill switch.
AI doesn’t replace the board’s duties. It raises the metabolic rate at which they must be discharged.
We have been here before — and we didn’t learn the right lesson
When the internet arrived, large incumbent organisations appointed Chief Digital Officers. The CDO became the governance pressure valve — the person who ran the digital programme, attended the right conferences, brought in an army of vendors, seeded experiments and then asked to launch a venture fund. Boards called it digital strategy. Meanwhile insurgent entrepreneurs backed by smart VC money went directly after their core profit pools — reinventing the economic model, new distribution, ‘product’ as marketing, disciplined quarterly sprints, real-time customer metrics, not waterfall two-year IT projects out of date at the point of committing funds. Reinvention using technology, not technology applied to what they already did.
The companies that navigated that transition had something different: a willingness to self-disrupt — challenging their own legacy economics before someone else did — and boards and management teams who took a long view of what technology might do to their market, treated governance as part of product quality, and were clear about the problem they were solving and why their solution was 50%+ better. The best live example today is Google, managing an AI transition where Search still accounts for over $225 billion — more than 55% of total revenues.
Stripe and Square went after incumbents’ payment economics; Spotify rebuilt music distribution around access, not ownership; Airbnb did the same to hotels’ fixed-cost economics. On the other side of those bets sat the boards that watched it happen — Kodak, Blockbuster, Nokia, BlackBerry, Sears — others will follow. The governance failure was not a failure to understand technology. It was a failure to understand what technology did — to competitive dynamics, to cost structures, to who controlled the customer relationship. Crucially, digital was the CEO’s job, treated as a cross-business imperative with a board-level strategy. Not delegated to one function. Not run as an IT project.
The same structural deficit is repeating itself. We are, in 2026, roughly where we were in 2000 — the difference is that the cycle is compressed, the capital commitments are larger, and the competitive and regulatory environment is hardening.
The Four-Domain Frame — the navigation grammar
Stripped back to first principles, the WEF Oversight Toolkit, KPMG/INSEAD’s Global Principles, McKinsey’s AI Trust framework and BCG’s board guidance converge on ‘four domains’ a board must now own at the same time:
The Four-Domain Frame - Most boards govern one of these well. A few govern two. Not many govern all four simultaneously — this is not a surprise in a fast moving world of ambiguity, hype and uncertain outcomes. Nevertheless, the discipline is important.
The ten questions every board should be asking sit across the four domains. Each carries a consequence: the cost of it going unasked. That cost is the point.
Strategy & Innovation
1. If a well-capitalised competitor rebuilt our core product around AI in the next eighteen months, what would remain of our competitive position?
Most boards govern AI risk inside the existing business. Not many ask the disruption question — not whether AI creates risk in our operations, but whether it lets a rival make our operations irrelevant. Management is paid to defend the model that exists. The board owns the question of whether that model survives.
2. Is our AI investment buying competitive advantage — or operational parity that every rival will also reach?
Boards are approving AI spending that doubles in a single year. The right governance question is not how much. It is what for. Efficiency gains from AI are real and accessible to every competitor. The organisations building durable advantage are redefining the product, the customer relationship or the cost architecture in ways that are hard to replicate. Does the board know which category its spend falls into?
3. Is AI changing how this organisation makes decisions — or simply automating the decisions it already makes?
This is the line that separates real transformation from expensive process improvement. Most organisations use AI to do existing things faster. Fewer use it to do things differently — to make decisions with information they could not previously access, at speeds the operating model precluded, at a level of personalisation the old margin structure could not support. The board should know which category describes its programme.
Risk & Resilience
4. What is our AI risk framework built to catch — and what is it structurally incapable of seeing?
Risk frameworks identify the risks they were designed to identify. AI introduces categories no pre-AI framework was built to surface: emergent model behaviour, training-data bias at scale, adversarial manipulation, hallucination in high-stakes outputs, and — new in 2026 — agentic systems taking sequences of autonomous decisions across connected processes. An audit committee receiving a RAG status update on AI risk is not governing AI risk. It is receiving a summary of classified risks — which is a different thing entirely.
5. How much agency have we delegated to non-human actors — and did we decide that, or has it happened to us?
Three in four organisations now give agentic AI access to their systems; only one in five has tested what happens when it fails.² The board’s instinct is to ask how much risk. The question that survives the next two years is how much agency. For every material AI use case — pricing, credit, recruitment, customer routing, supply chain, refund handling — there are three possible answers: autonomous, recommend-only, prohibited. Each with a named human owner. Each with a tested kill switch.
Governance & Accountability
6. Where does accountability sit when an AI-driven decision causes harm — and has the board formally assigned it to a named human?
This is not hypothetical. The EU AI Act’s requirements are now effective across European markets. The FCA’s AI governance expectations are hardening. D&O exposure on AI-related harm is live and being tested. Most boards have not formally assigned AI accountability — not in committee terms of reference, not in management responsibilities, not in the schedule of matters reserved. Accountability never transfers to the agent. The answer, when it matters, will be found in what was documented. Not in what was assumed.
7. Is AI a standing item on the board agenda — or does it appear only when something goes wrong or management asks for a budget?
Reactive governance is incident response with a board letterhead. The boards building real oversight treat AI as a live strategic conversation — at the frequency and seriousness of financial performance — not as a technology update in the CTO’s slot once a quarter.
Capability & Culture
8. Are we asking management the questions that matter — or the questions management has prepared us to ask?
This is the meta-question, and the one I find most difficult to answer honestly about my own contribution. When I have been on the presenting side of the table, I knew which questions were coming. I had prepared answers. The questions I had not prepared for were the ones that changed the dynamic — and they were almost never on the agenda. The BCG finding cuts both ways: if boards are pushing faster than management, the question is whether that pressure is informed or anxious. Governance is not about speed. It is about the quality of the decision.
9. Who in this boardroom has used an AI tool to do something consequential in the last thirty days?
I include myself in this question. If your understanding of AI is entirely briefing-derived, your pressure for speed cannot be informed. The board cannot meaningfully challenge management’s AI strategy if its understanding of AI is entirely second-hand. This is not about becoming data scientists. It is the same standard of practical engagement expected of any director overseeing a material business transformation. The board that governed digital without digital experience was the first wave’s structural error. Repeating it knowingly is harder to excuse.
10. Do we have the board composition to govern the company we are building — not just the one we have?
The NomCo’s job has always been to ensure the board has the skills the strategy requires. If the strategy now includes material AI transformation, agentic systems deployment and regulatory navigation under the EU AI Act, the skills required have changed. Not more technologists — more directors with the economic intuition to read what AI does to competitive dynamics, cost structures and the value of human judgment. A board effectiveness review that does not address this is answering the wrong question.
Effective AI governance is not a framework. It is a quality of attention — and the willingness to ask the question that was not prepared for.
Before your next board meeting
Of the ten questions above, which three would most change your board’s current AI conversation?
This week in The Library
Your AI governance isn’t an IT policy. That’s why it’s failing. The companion to this Manifesto — the framework, the board’s four jobs and the six diagnostic questions that test whether your governance is real. Read after this.
Next week in The Frame
Next week we discuss 10 ways AI can blow up your business. In a world where AI is probabilistic, it doesn’t sit still & it moves at machine speed - what are the risks and what is the emerging augmentation to the traditional governance model.
Disclaimer: These are my personal views, shaped in a fast-moving environment and open to revision. They should not be taken as representing the perspectives of any boards or advisory roles, past or present.
TheDirectorBrief What you get. Free, each week. Thirty minutes:
A practical discussion of an AI related topic, centered on strategy, risk, governance & capability. A decision useful take - with examples, facts, useful frameworks and key questions to ask. Exposes common misconceptions and cuts through the hype (The Frame)
Five board-ready questions for your next meeting (Five for the Chair)
Curated decision ready AI news. What you need to know, why it matters and how you might factor into decision making (The Signal)
Practical tools, how to guides, primers and prompts ready to (customise &) use in your business. (The Library)
AI education for board directors What to play with, build, read, watch or listen to. Not one off. Building AI fluency on going. (Monday morning)
Signal, not noise. Judgement, not updates.
Subscribe free at TheDirectorBrief.com — or reply to this email. I read every response.
Sources
1. BCG, AI in the Boardroom, May 2026 — survey of 625 CEOs and board members.
2. Grant Thornton, 2026 AI Impact Survey — agentic AI deployment and incident response readiness.
3. BCG, AI Radar 2026 — corporate AI spend as percentage of revenue.
Performance reference: MIT CISR, Board Digital Fluency and Performance, March 2025 — AI-fluent boards outperform peers by 10.9 percentage points in ROE; non-fluent boards trail by 3.8%. Carried in The Library’s board-effectiveness primer.
Frameworks referenced: WEF AI Governance Toolkit (2024–25); KPMG/INSEAD Global AI Governance Principles (April 2026); McKinsey, State of AI Trust 2026 — Shifting to the Agentic Era; BCG AI Radar 2026. Agentic governance logic drawn from working paper Governing AI Agents in the Enterprise (Library, May 2026).




