AI Governance Institute logo
AI Governance Institute

Intelligence for Compliance and GRC Teams

← News

AI Incidents Up 32% in 2024, NACD Urges Boards to Strengthen Oversight Structures

What happened

The National Association of Corporate Directors (NACD) has published its 2025 Governance Outlook, a guidance document directed at corporate boards across the United States calling for strengthened AI oversight structures in response to a measurable rise in AI-related incidents. Drawing on data from the AI Incident Database, the NACD reports that AI incidents increased 26% between 2022 and 2023, followed by a further increase exceeding 32% in 2024. The guidance identifies hallucinations, bias, and data privacy failures as the primary risk categories driving this trend. In response, the NACD calls on boards to implement updated governance frameworks and reporting structures that provide directors with meaningful visibility into AI risk. Although the document is non-binding, NACD guidance carries significant weight among directors and institutional investors who use it as a benchmark for evaluating governance adequacy.

Why it matters

  • ·Regulatory exposure: Although non-binding, NACD guidance is used by institutional investors and regulators as a benchmark for governance adequacy, meaning organizations that lack board-level AI oversight documentation may face heightened scrutiny during regulatory inquiries or investor reviews.
  • ·Operational impact: The identification of hallucinations, bias, and data privacy failures as primary risk areas signals that organizations must operationalize monitoring and mitigation controls for these specific categories, not treat AI risk as a single undifferentiated concern.
  • ·Organizational risk: The shift of AI oversight from an operational concern to a board-level accountability expectation means compliance and risk teams must establish clear escalation pathways to senior leadership, creating structural and resourcing obligations that many organizations have not yet addressed.

Governance controls affected

What to do now

  • Audit current board reporting materials to determine whether AI risk is explicitly surfaced and whether named accountability owners are identified for each primary risk category.
  • Establish or update a responsible AI policy that addresses the three risk areas named by the NACD: hallucinations, bias, and data privacy failures, with defined escalation pathways to the board.
  • Map existing AI governance controls to board-level visibility requirements and identify gaps where incident data, bias assessments, or privacy failures are not currently reported upward.
  • Prepare documentation demonstrating board engagement on AI risk that can be produced in response to regulatory inquiry, investor scrutiny, or an AI-related incident.
  • Review and strengthen the AI incident response playbook to ensure it includes escalation procedures that reach board level for incidents meeting defined severity thresholds.

What to watch next

Compliance teams should monitor whether the Securities and Exchange Commission or state-level regulators in the United States begin referencing NACD guidance as an informal standard when evaluating board-level AI governance adequacy in disclosure reviews or enforcement actions. The continued rise in AI incident volumes tracked by the AI Incident Database suggests that incident-driven regulatory and investor pressure on boards is likely to intensify through 2025, making the maturity of escalation and reporting structures an increasingly visible governance metric. Teams should also watch for follow-on NACD publications or peer governance body guidance that may further specify director competency expectations or required reporting cadences for AI risk.

Stay ahead of stories like this

Get every US AI governance development like this one, plus the rest of the week's developments. Every Thursday.

Powered by Buttondown.

Related Coverage

Research2026-08-19

EU AI Act Enforcement Has Begun: Documentation Gaps Now Draw Regulator Attention

The Future of Life Institute's EU AI Act Newsletter #108 reports that enforcement activity under the EU AI Act is now underway, shifting the regulation from a planning horizon to an active compliance obligation. The newsletter tracks emerging enforcement patterns and flags documentation and transparency obligations as the most immediate areas of exposure. Compliance teams operating in EU-regulated markets should use enforcement signals to stress-test existing control mappings and update their conformity assessment processes.

Enforcement2026-08-17

$3.2M DOJ Settlement Puts AI-Assisted Hiring Workflows on Civil Rights Notice

The U.S. Department of Justice Civil Rights Division announced a $3.2 million settlement with OpenAI OpCo and its subsidiary Statsig over alleged citizenship-status discrimination in PERM recruitment workflows assisted by AI. The case is among the first federal civil rights enforcement actions directly tied to an AI-assisted hiring pipeline. It signals that deployers of automated recruiting tools bear liability for discriminatory outcomes regardless of intent.

Research2026-08-17

KPMG Frames AI Governance as a Model Risk Problem, Not a Separate Silo

KPMG has published a guide positioning AI oversight as an extension of existing model risk management structures rather than a standalone governance program. The guide organizes AI oversight around four pillars: governance, development, validation, and monitoring. Compliance teams are advised to integrate AI controls into familiar model risk frameworks rather than build parallel processes.