By John Marcante
Many AI pilots are moving into production, productivity tools are spreading and vendors are increasingly embedding generative and agentic AI across enterprise platforms. As this momentum continues, AI governance should evolve just as quickly.
For boards, the challenge is to maintain sufficient AI literacy to set strategic direction and effectively challenge management, while ensuring clear accountability, proportionate risk oversight and measurable enterprise value. AI governance should not be treated as a compliance checklist but as an operating discipline.
A recent Deloitte Global survey finds that 66% of C-suite and board members cite open, transparent communication between the board and management as the top factor influencing organisational resilience.
Seventy-one per cent say strategic risk oversight and scenario planning are where boards can best help enhance organisational resilience. Nearly three-quarters (73%) of survey respondents say their boards have stepped up their involvement in strategy development and scenario planning.
As boards take on a greater role in governing AI, several priorities and structures should remain top of mind.
Five AI governance priorities
Based on my experience leading enterprise technology transformations and advising executives and boards, five governance priorities can help distinguish organisations building durable AI capabilities from those still experimenting.
Govern AI as a portfolio of enterprise capabilities:
Many organisations still track AI initiatives as an innovation activity.
Boards should instead expect AI to be managed as a portfolio of investments, categorised by business impact, autonomy level, and risk exposure.
This portfolio view may allow directors to identify concentration risk, value dependency, and operational reliance before AI becomes embedded in critical workflows.
Separate model governance from decision accountability:
Technical validation is necessary but often insufficient. The central governance question is ownership:
- Who is accountable for decisions influenced by AI?
- Who authorises deployment into production workflows?
- Who monitors performance drifts?
- Who has the authority to suspend the system when risk emerges?
Without clear decision rights, AI risk likely becomes organisational risk.
**Treat third-party AI as enterprise exposure: **
AI capabilities are increasingly embedded in enterprise software, from finance and HR systems to cybersecurity and customer engagement tools. This extends AI governance beyond internally developed models.
Boards should expect management to maintain visibility into vendor AI usage, data rights, model update controls, and audit provisions. Vendor AI risk is enterprise risk.
Establish proportional risk tiering:
Not all AI requires board-level visibility. Customer-facing AI, financial decision-making systems, and agentic systems with autonomous authority are likely to warrant higher scrutiny than internal productivity tools, for example.
Risk tiering allows oversight to scale with impact rather than fear.
Require measurable enterprise value:
AI should appear in operating metrics, not just innovation briefings. Boards should expect reporting tied to cycle-time reduction, cost efficiency, revenue impact, or improved risk detection.
Layers of a practical governance structure
A practical AI governance structure consists of several layers, which together can help create clarity without slowing innovation. They include:
Board oversight– Defines strategy, risk appetite, and accountability.*Executive AI council –*Prioritises investment and risk tiering.Decision accountability– Assigns ownership for AI-related decisions across business, technology and risk, including business outcomes, model performance and controls.Model and data governance– Establishes processes for validation and ongoing monitoring.Infrastructure and third-party control– Ensures security and vendor discipline.
The following questions, meanwhile, can help boards assess AI governance maturity:
- Where is AI materially influencing enterprise decisions today?
- Which systems operate with agentic authority?
- What third-party AI exposure touches sensitive enterprise data?
- How is AI-driven value measured and reported?
- Who is accountable if an AI-enabled decision fails publicly?
AI should not replace leadership. But it can help magnify the consequences of unclear accountability and weak governance.
Organisations that capture value with AI will not necessarily be those running the most pilots. They will more likely be those that establish governance discipline early – before AI becomes inseparable from enterprise operations.
John Marcante is former global CIO, Vanguard, and CIO-in-residence, Deloitte US CIO Program.
This article first appeared in The Australian as Govern AI before it governs you.
Related Topics #
UNLOCK INSIGHTS
Discover the untold stories of emerging ASX stocks.
Daily news and expert analysis, it's free to subscribe.
By proceeding, you confirm you understand that we handle personal information in accordance with our Privacy Policy.