Who Is Accountable for AI Governance?
I recently asked a board how they oversee AI governance. The audit committee chair said it was a risk issue. The risk committee chair said it was a technology issue. The technology committee chair said it was a strategy issue. The strategy committee chair said it was an operational issue.
Everyone was right. And no one was accountable.
This is the central challenge of AI governance: it does not fit neatly into any existing committee structure. And when something does not fit neatly, it is at risk of falling through the cracks entirely.
Why Traditional Structures Fall Short
Most boards organise oversight through a set of committees: audit, risk, remuneration, nomination, and sometimes technology or digital. Each committee has a defined scope. AI touches all of them.
- Audit committee: AI systems affect financial reporting, internal controls, and regulatory compliance.
- Risk committee: AI introduces new categories of risk — model risk, data risk, accountability risk — that sit outside traditional frameworks.
- Technology committee: AI is a technology deployment, but its governance implications go far beyond technical architecture.
- Strategy committee: AI is a competitive opportunity, but also a source of strategic risk.
- Remuneration committee: AI-driven performance metrics and automated decision-making affect how people are evaluated and compensated.
The problem is not that any one committee cannot handle AI. It is that when every committee has a piece of the puzzle, no one has the full picture.
Three Models for AI Accountability
There is no single right answer. But there are three models that boards are beginning to adopt.
Model 1: The AI Lead Committee
One committee — typically the risk committee or a dedicated technology committee — takes primary ownership of AI governance. Other committees are required to refer AI-related matters to the lead committee, which maintains a consolidated view.
Best for: Boards that want clarity and single-point accountability. Risk: The lead committee can become a bottleneck, and other committees may disengage from AI oversight altogether.
Model 2: Distributed Oversight with Coordination
Each committee addresses AI within its existing scope. A cross-committee coordination mechanism — a regular joint meeting, a shared briefing paper, or a designated board-level AI champion — ensures no gaps emerge.
Best for: Boards that want AI integrated into existing governance processes. Risk: Coordination fatigue. Without a strong champion, the model defaults to the status quo — which is exactly the problem.
Model 3: The Board-Level AI Champion
The board appoints one director to maintain a cross-cutting view of AI governance. That director is not responsible for AI oversight themselves — they are responsible for ensuring the board as a whole is addressing it sufficiently.
Best for: Boards that want a lightweight, flexible approach. Risk: The champion becomes a single point of failure. If they leave, institutional knowledge leaves with them.
What Matters Most
The model you choose matters less than the fact that you choose one — and document it.
The most dangerous position is the one most boards are in today: assuming that AI governance is being addressed somewhere, without being able to say where, how, or by whom.
A Practical Recommendation
At your next board meeting, address this directly:
- Identify which committee (or director) will be accountable for maintaining a consolidated view of AI governance.
- Document how AI-related matters will be escalated between committees.
- Require a consolidated AI governance report at least twice a year.
- Review the model annually — AI governance is evolving, and your structure should evolve with it.
The question is not whether AI governance is someone's problem. It is whether your board has explicitly decided whose problem it is.