AI Governance Institute
← News
Research2026-06-10

NACD Calls on Boards to Restructure AI Oversight, Flagging Bias, Hallucination, and Privacy as Core Governance Risks

Source

Tuning Corporate Governance for AI Adoption

National Association of Corporate Directors

What happened

The National Association of Corporate Directors (NACD) published Tuning Corporate Governance for AI Adoption as part of its 2025 Governance Outlook series, targeting boards of directors at companies of all sizes and sectors globally. The guidance argues that existing board oversight frameworks were not designed with AI in mind and require deliberate adaptation rather than mere extension of current committee mandates. It identifies four priority control areas: bias management, hallucination risk in generative AI outputs, data privacy, and continuous monitoring of AI's evolving impact on the enterprise risk profile. The document emphasizes cross-functional governance structures that bridge technology, legal, risk, and business functions under board-level visibility. While non-binding, the guidance carries practitioner weight given NACD's role as the primary professional body for U.S. corporate directors.

Why it matters

  • ·Regulatory exposure is rising as securities regulators and institutional investors increasingly scrutinize whether boards have adequate AI oversight structures in place, meaning gaps identified in NACD-aligned governance benchmarks can surface directly in shareholder engagement, proxy advisory assessments, and SEC disclosure reviews.
  • ·Operational impact is significant because the guidance explicitly links hallucination risk and model drift to board-level reporting obligations, requiring compliance teams to translate technical AI failure modes into risk metrics that non-technical directors can assess and act on.
  • ·Organizational risk is compounded by the cross-functional mandate: without a defined committee charter or clear decision rights for AI governance, accountability gaps between legal, technology, and risk functions will persist and become harder to defend in litigation or regulatory inquiries.

Governance controls affected

What to do now

  • ☐Assess whether your board or a designated committee has a documented AI oversight charter with defined decision rights, escalation thresholds, and reporting cadences, and remediate gaps against the NACD framework.
  • ☐Map the four NACD control areas (bias, hallucination risk, privacy, and risk profile monitoring) to existing internal controls and identify which lack board-visible metrics or reporting owners.
  • ☐Build or update a board AI risk reporting template that translates technical AI performance indicators into business risk language, covering at minimum model drift, fairness metrics, and privacy incident trends.
  • ☐Conduct a director AI literacy assessment to determine whether current board members have sufficient competency to evaluate AI risk reports, and design a targeted education program to close identified gaps.
  • ☐Review your AI risk tolerance and appetite documentation to confirm it has been formally approved at board level and reflects AI-specific scenarios including generative AI hallucination events and third-party model failures.

What to watch next

Compliance teams should monitor whether institutional proxy advisory firms such as ISS and Glass Lewis incorporate AI board oversight criteria into their 2025 and 2026 governance scoring frameworks, as NACD guidance frequently precedes such shifts. The SEC's ongoing review of AI-related disclosure obligations under existing securities rules may also create formal reporting requirements that align closely with the NACD recommendations, particularly around material AI risks. Additionally, the emergence of investor-facing AI governance frameworks, including work from the Oxford Martin School on investor AI governance, signals that voluntary board-level guidance is converging toward investor-enforceable expectations.

Related Coverage

Research2026-10-02

PwC: AI Attacks Top Threat List, But Only 22% Back Autonomous Cyber Defense

PwC's 2027 Global Digital Trust Insights report is based on nearly 4,000 leaders across 70-plus countries. It finds that attacks targeting AI systems rank as the threat enterprises feel least prepared to handle. Only 22% of respondents would deploy fully autonomous AI agents for cyber defense without human oversight, with governance skill gaps cited as a barrier. A parallel readiness failure appears in quantum-resistant security, where just 21% of organizations have begun adopting protections against future decryption attacks.

Corporate Policy2026-10-05

Chakra's 500,000 Interviews Make AI Hiring Compliance Obligations Concrete

HackerRank has made Chakra, an AI agent that conducts and scores technical job interviews, generally available after completing more than 500,000 beta interviews. The system evaluates candidates on process and judgment, placing it directly within AI hiring regulations that require independent bias audits and candidate disclosure. HackerRank's CEO publicly acknowledged that AI hiring tools can inherit bias from underlying data, raising the due diligence bar for deploying organizations.

Corporate Policy2026-10-05

Altman's 'Accept Bad Things' Statement Exposes a Vendor Safety Culture Gap

OpenAI CEO Sam Altman publicly stated that society should accept harms such as hacks and scams as a trade-off for AI's broad benefits. His remarks coincided with a safety expert's resignation citing a broken internal safety culture and a White House agreement endorsing AI company self-policing over binding rules. Together, these developments challenge the vendor safety assumptions underlying enterprise AI risk programs.