AI Governance Institute
← News

AI Incidents Up 32% in 2024, NACD Urges Boards to Strengthen Oversight Structures

What happened

The National Association of Corporate Directors (NACD) has published its 2025 Governance Outlook, a guidance document directed at corporate boards across the United States calling for strengthened AI oversight structures in response to a measurable rise in AI-related incidents. Drawing on data from the AI Incident Database, the NACD reports that AI incidents increased 26% between 2022 and 2023, followed by a further increase exceeding 32% in 2024. The guidance identifies hallucinations, bias, and data privacy failures as the primary risk categories driving this trend. In response, the NACD calls on boards to implement updated governance frameworks and reporting structures that provide directors with meaningful visibility into AI risk. Although the document is non-binding, NACD guidance carries significant weight among directors and institutional investors who use it as a benchmark for evaluating governance adequacy.

Why it matters

  • ·Regulatory exposure: Although non-binding, NACD guidance is used by institutional investors and regulators as a benchmark for governance adequacy, meaning organizations that lack board-level AI oversight documentation may face heightened scrutiny during regulatory inquiries or investor reviews.
  • ·Operational impact: The identification of hallucinations, bias, and data privacy failures as primary risk areas signals that organizations must operationalize monitoring and mitigation controls for these specific categories, not treat AI risk as a single undifferentiated concern.
  • ·Organizational risk: The shift of AI oversight from an operational concern to a board-level accountability expectation means compliance and risk teams must establish clear escalation pathways to senior leadership, creating structural and resourcing obligations that many organizations have not yet addressed.

Governance controls affected

What to do now

  • Audit current board reporting materials to determine whether AI risk is explicitly surfaced and whether named accountability owners are identified for each primary risk category.
  • Establish or update a responsible AI policy that addresses the three risk areas named by the NACD: hallucinations, bias, and data privacy failures, with defined escalation pathways to the board.
  • Map existing AI governance controls to board-level visibility requirements and identify gaps where incident data, bias assessments, or privacy failures are not currently reported upward.
  • Prepare documentation demonstrating board engagement on AI risk that can be produced in response to regulatory inquiry, investor scrutiny, or an AI-related incident.
  • Review and strengthen the AI incident response playbook to ensure it includes escalation procedures that reach board level for incidents meeting defined severity thresholds.

What to watch next

Compliance teams should monitor whether the Securities and Exchange Commission or state-level regulators in the United States begin referencing NACD guidance as an informal standard when evaluating board-level AI governance adequacy in disclosure reviews or enforcement actions. The continued rise in AI incident volumes tracked by the AI Incident Database suggests that incident-driven regulatory and investor pressure on boards is likely to intensify through 2025, making the maturity of escalation and reporting structures an increasingly visible governance metric. Teams should also watch for follow-on NACD publications or peer governance body guidance that may further specify director competency expectations or required reporting cadences for AI risk.

Stay ahead of stories like this

Get every US AI governance development like this one, plus the rest of the week's developments. Every Thursday.

Powered by Buttondown.

Related Coverage

Enforcement2026-09-05

Mount Shasta Rescue Puts AI Use-Case Boundary Controls on Notice

Three hikers required emergency rescue from California's Mount Shasta after relying on Google Gemini for expedition planning, with the Siskiyou County sheriff's office stating the chatbot advised them to bring significantly insufficient food and water. The incident is a documented public safety failure tied to a named AI product, and the sheriff's office issued an explicit warning against sole reliance on AI for trip planning. For compliance teams, the event crystallizes the liability risk of deploying general-purpose AI in guidance roles without enforced use-case boundaries and adequate safety disclaimers.

Research2026-09-01

SR 26-2 Forces Banks to Rethink Model Governance From Inventory to Board Oversight

The OCC and Federal Reserve's revised model risk management guidance, SR 26-2, resets supervisory expectations for U.S. banks by shifting to a materiality-based approach that covers both traditional statistical models and AI systems, replacing the SR 11-7 framework that had governed bank model governance since 2011. Practitioner analysis from CRA identifies four areas banks must redesign: inventory scope, model tiering, validation independence, and governance alignment up to the board. A companion implementation guide from Lumenova AI adds concrete steps, including inventory rationalization and a distinct governance lane for agentic and generative AI, while a proposed academic framework maps a six-layer control architecture for bringing GenAI systems into SR 26-2 scope. Banks that still run AI governance and model risk management as separate programs face the most immediate pressure to harmonize them.

Corporate Policy2026-08-29

OpenAI's Zero Data Retention Option Shifts Audit Log Burden to Enterprise

OpenAI has introduced a zero data retention option for eligible API customers using frontier models, under which prompts and model responses are not stored after processing. The offering resolves a data minimization concern but transfers responsibility for audit-trail capture entirely to the enterprise customer. Regulated organizations must now ensure their own logging infrastructure compensates for the absence of vendor-side retention.