AI Governance Institute
← News

Boards Urged to Overhaul AI Oversight as Deepfakes, Data Leaks Expose Governance Gaps, NACD Warns

What happened

The National Association of Corporate Directors (NACD) published Tuning Corporate Governance for AI Adoption in January 2025, urging U.S. corporate boards to refine existing oversight mechanisms to address AI-specific governance failures. The guidance cites real-world incidents involving AI-generated deepfakes, confidential data leaks, and algorithmic bias as evidence that current board structures are inadequate for managing AI risk. NACD identifies a cross-functional leadership model as central to effective AI governance, placing the Chief AI Officer in coordination with the Chief Risk Officer, Chief Compliance Officer, Chief Legal Officer, and Chief Data Officer. The guidance signals growing boardroom pressure on compliance teams to formalize AI accountability chains and integrate AI risk into existing enterprise risk management frameworks. Boards are expected to request clearer reporting lines, defined AI risk tolerances, and documented incident response protocols as standard governance requirements.

Why it matters

  • ·U.S. corporate boards are now being formally advised to treat AI governance failures as a material risk, increasing the likelihood that inadequate AI oversight structures will draw scrutiny from regulators, investors, and auditors.
  • ·Compliance and legal teams face operational pressure to build and document cross-functional AI governance structures, including defined roles for Chief AI Officers and coordinated accountability between risk, legal, and data functions.
  • ·Organizations without formalized AI incident response protocols, risk tolerances, and accountability chains are exposed to reputational and liability risks if deepfake misuse, data leaks, or algorithmic bias incidents occur and escalate to board level.

Governance controls affected

What to do now

  • Map your current AI accountability chain and identify whether a Chief AI Officer role or equivalent coordination function exists and is formally documented for board reporting.
  • Review your AI risk classification framework to ensure it captures deepfake-related risks, confidential data leakage scenarios, and algorithmic bias as distinct risk categories.
  • Assess whether your AI incident response playbook addresses board-level escalation paths and includes severity classifications for AI-specific incidents such as deepfakes and data exposure.
  • Document defined AI risk tolerances and present them to the board or relevant board committee for formal approval and integration into enterprise risk management frameworks.
  • Schedule a tabletop exercise simulating an AI-related incident, such as a deepfake or data leak, to test cross-functional coordination between the Chief AI Officer, Chief Risk Officer, Chief Compliance Officer, and Chief Legal Officer.

What to watch next

Compliance teams should monitor whether NACD follows this guidance with more prescriptive board-level reporting standards or metrics for AI governance maturity, particularly as 2025 proxy season approaches and investors increase scrutiny of AI risk disclosures. Pending U.S. federal and state-level AI legislation may reference or align with NACD recommendations, making early adoption of the cross-functional governance model a potential safe harbor signal. Enforcement patterns at the SEC regarding material AI risk disclosures should also be tracked, as board-level AI governance gaps could increasingly feature in securities and fiduciary liability contexts.

Stay ahead of stories like this

Get every US AI governance development like this one, plus the rest of the week's developments. Every Thursday.

Powered by Buttondown.

Related Coverage

Research2026-08-24

PwC India Sets Board-Approved Risk Appetite as the Anchor for AI Model Governance

PwC India published guidance titled 'Governing models in the AI era' recommending that organizations establish board-approved AI model risk appetite thresholds, build complete model inventories with ownership and validation metadata, and apply AI-specific due diligence to third-party solutions. The guidance addresses a persistent implementation gap: most enterprises have neither a formal definition of what counts as a model nor a complete register of model-like tools in production. Compliance teams can adopt the framework as a practical operating model for cataloguing AI systems and governing external vendors.

Research2026-09-01

SR 26-2 Forces Banks to Rethink Model Governance From Inventory to Board Oversight

The OCC and Federal Reserve's revised model risk management guidance, SR 26-2, resets supervisory expectations for U.S. banks by shifting to a materiality-based approach that covers both traditional statistical models and AI systems, replacing the SR 11-7 framework that had governed bank model governance since 2011. Practitioner analysis from CRA identifies four areas banks must redesign: inventory scope, model tiering, validation independence, and governance alignment up to the board. A companion implementation guide from Lumenova AI adds concrete steps, including inventory rationalization and a distinct governance lane for agentic and generative AI, while a proposed academic framework maps a six-layer control architecture for bringing GenAI systems into SR 26-2 scope. Banks that still run AI governance and model risk management as separate programs face the most immediate pressure to harmonize them.

Research2026-08-25

Cisco Talos: AI Cuts Attack-to-Compromise Timeline for UAT-10147

Cisco Talos has identified a Chinese-speaking threat group, UAT-10147, using AI-generated guidance to troubleshoot failed exploits and automate post-access activity against internet-facing Windows and Linux servers. The finding compresses the assumed defender response window and directly challenges CVSS-only vulnerability prioritization frameworks. Enterprise incident response programs that rely on human approval chains calibrated to slower attack progression are now materially exposed.