The CEO’s AI Dashboard, Part 5: Governance

July 17, 2026

Welcome to a new edition of *The Board: Distillation Aftershots* (*)

This is an online copy of a newsletter shares curious and interesting insights and data points resulting from distilling information to find what’s notable in enterprise technology. If you want to get these in your inbox every Sunday, subscribe here.

In this issue, I want to focus on the area that will determine how much autonomy the enterprise is actually willing to grant AI: governance. Governance for AI is not an extension of traditional enterprise technology governance. Enterprise systems usually support decisions, record activity, and enforce process – but with human supervision. AI is being built to automate interactions, recommend actions, and increasingly execute low-level decisions without human intervention. That raises the level of accountability and responsibility the enterprise has to carry.

First, my take.

When an automated action produces an unsatisfactory, harmful, biased, noncompliant, or simply wrong outcome, the enterprise still owns the consequence. The automation does not absorb responsibility. It only compresses the time between decision and impact. That is what makes AI governance different. Traditional governance models were built around systems that people operated. AI systems increasingly operate with people supervising from further away, or eventually not at all. AI governance stops being theoretical the moment an agent can act, commit, deny, approve, or escalate on behalf of the enterprise without waiting for a human to intervene.

That shift matters because many governance assumptions in the enterprise still depend on human presence. Trust is often embedded in transient responsibility and authorization models: a person has a role, an approval path, an escalation point, and a manager who can intervene. Once interactions are automated, those assumptions weaken. The question is no longer only who had access to the system. It is how the decision was reached, what data was used, what rules were applied, what limits were in force, and who is accountable when the agent acts inside or across workflows.

The market is already showing the tension. Deloitte reports that by 2027, 74% of organizations expect to use AI agents at least moderately, while only 21% say they have a mature governance model for them. That gap should concern CEOs more than the adoption number. It means enterprises are moving faster on delegated action than on delegated accountability. McKinsey’s 2025 State of AI adds another important point: CEO oversight of AI governance is one of the elements most correlated with higher self-reported bottom-line impact. AI governance determines how far the enterprise is willing to trust the system to act.

One way to make that manageable is to define tiers of autonomy in advance: recommend, assist, execute with approval, execute with post-review, and execute autonomously within hard bounds (your framework, and mileage, will vary). Most enterprises will need more than one tier at the same time, depending on the workflow, the risk, and the consequence of failure.

Other governance elements become more sensitive under AI as well. Confidentiality determines who or what can see and use which data. Privacy determines how personal data is captured, interpreted, retained, and reused. Access determines how far the enterprise is willing to relax controls to let agents operate across systems. If the interaction crosses enterprise boundaries into partner platforms, third-party models, shared workflows, or vendor systems, the governance question gets harder. Existing rules usually stop at the edge of the firm; AI may not.

This is why I do not think enterprises can rely on existing governance models or wait for regulation to catch up. Anthropic CEO Dario Amodei wrote recently that policy needs to move at the pace of AI progress, not the pace of traditional rulemaking, and called frontier models tools of strategic consequence that may require government authority to block or restrain dangerous deployments. External regulation is lagging while internal deployment is accelerating. That leaves enterprises with a self-regulation problem whether they want one or not.

Self-regulation here should not be confused with internal policy memos. It needs to extend into legal, ethical, operational, and auditable decision logic. It also has to be dynamic. Existing governance frameworks were not built for new processes and new outcomes being created in real time. They were built to manage known systems and known controls. If agents are allowed to assemble their own working patterns inside defined objectives, then the governance model has to account for decision-making and empowerment beyond what was explicitly scripted in advance.

That is why I would be careful about borrowing governance models from other organizations too literally. We do not yet have enough shared experience in domesticating agents for one model to travel cleanly across firms. Governance will be closely tied to industry, risk appetite, operating model, data exposure, regulatory context, and the tiers of autonomy the enterprise is actually prepared to allow.

The CEO question is straightforward: when the human “fuses” and roadblocks are removed from low-level decision making, how will the enterprise decide what the agent may do, how that decision will be monitored, and who will remain accountable for the outcome?

Recommended CEO actions*

  1. Assign an ELT executive with clear authority to coordinate AI governance across systems, vendors, data, and operating policies, with the power to review, approve, pause, or stop deployments.
  2. Invest in monitoring and auditability that document how decisions were made, what data was used, what rules were triggered, and where escalation or override should have occurred.
  3. Bring the board into the governance design early, especially where private platforms, cross-enterprise workflows, and dynamic self-regulation are involved. The board does not need to design the controls, but it does need to understand the accountability model.

Here are some reading resources

  1. McKinsey’s board article is useful because it shows how underprepared many boards still are on AI and why governance has moved closer to the CEO.
  2. McKinsey’s 2025 State of AI is useful because it links CEO oversight of AI governance with higher self-reported bottom-line impact.
  3. Deloitte’s 2026 State of AI in the Enterprise is useful because it shows how quickly agentic AI adoption is rising relative to governance maturity.
  4. Deloitte’s article on agentic AI guardrails is useful because it makes the governance gap around agents more explicit.
  5. Anthropic’s “Policy on the AI Exponential” is useful because it makes the external-regulation gap explicit and argues for faster governance mechanisms for frontier models.
  6. IBM’s AI governance report is useful because it frames governance as an operating discipline, not only a compliance layer.
  7. IBM’s CEO research is useful because it ties AI governance to operating-model decisions and executive accountability.
  8. PwC’s responsible AI governance work is useful because it covers control design, model risk, explainability, and accountability in enterprise settings.
  9. KPMG’s AI Pulse is useful because it shows the gap between AI ambition and governance maturity in large organizations.
  10. The World Economic Forum’s governance work is useful because it treats AI governance as a live management problem rather than a future policy topic.

What’s your take? We are fostering a community of executives who want to discuss these issues in depth. This newsletter is but a part of it. We welcome your feedback and look forward to engaging in these conversations.

If you are interested in exploring the full report, discussing the Board’s offering further, or have any additional questions, please contact me at [email protected], and I will be happy to connect with you.

(*) A normal distillation process produces byproducts: primary, simple ones called foreshots, and secondary, more complex and nuanced ones called aftershots. This newsletter highlights remnants from the distillation process, the “cutting room floor” elements, and shares insights to complement the monthly report.