AI Governance Institute
← News
Research2026-06-10

NACD Calls on Boards to Restructure AI Oversight, Flagging Bias, Hallucination, and Privacy as Core Governance Risks

Source

Tuning Corporate Governance for AI Adoption

National Association of Corporate Directors

What happened

The National Association of Corporate Directors (NACD) published Tuning Corporate Governance for AI Adoption as part of its 2025 Governance Outlook series, targeting boards of directors at companies of all sizes and sectors globally. The guidance argues that existing board oversight frameworks were not designed with AI in mind and require deliberate adaptation rather than mere extension of current committee mandates. It identifies four priority control areas: bias management, hallucination risk in generative AI outputs, data privacy, and continuous monitoring of AI's evolving impact on the enterprise risk profile. The document emphasizes cross-functional governance structures that bridge technology, legal, risk, and business functions under board-level visibility. While non-binding, the guidance carries practitioner weight given NACD's role as the primary professional body for U.S. corporate directors.

Why it matters

  • ·Regulatory exposure is rising as securities regulators and institutional investors increasingly scrutinize whether boards have adequate AI oversight structures in place, meaning gaps identified in NACD-aligned governance benchmarks can surface directly in shareholder engagement, proxy advisory assessments, and SEC disclosure reviews.
  • ·Operational impact is significant because the guidance explicitly links hallucination risk and model drift to board-level reporting obligations, requiring compliance teams to translate technical AI failure modes into risk metrics that non-technical directors can assess and act on.
  • ·Organizational risk is compounded by the cross-functional mandate: without a defined committee charter or clear decision rights for AI governance, accountability gaps between legal, technology, and risk functions will persist and become harder to defend in litigation or regulatory inquiries.

Governance controls affected

What to do now

  • Assess whether your board or a designated committee has a documented AI oversight charter with defined decision rights, escalation thresholds, and reporting cadences, and remediate gaps against the NACD framework.
  • Map the four NACD control areas (bias, hallucination risk, privacy, and risk profile monitoring) to existing internal controls and identify which lack board-visible metrics or reporting owners.
  • Build or update a board AI risk reporting template that translates technical AI performance indicators into business risk language, covering at minimum model drift, fairness metrics, and privacy incident trends.
  • Conduct a director AI literacy assessment to determine whether current board members have sufficient competency to evaluate AI risk reports, and design a targeted education program to close identified gaps.
  • Review your AI risk tolerance and appetite documentation to confirm it has been formally approved at board level and reflects AI-specific scenarios including generative AI hallucination events and third-party model failures.

What to watch next

Compliance teams should monitor whether institutional proxy advisory firms such as ISS and Glass Lewis incorporate AI board oversight criteria into their 2025 and 2026 governance scoring frameworks, as NACD guidance frequently precedes such shifts. The SEC's ongoing review of AI-related disclosure obligations under existing securities rules may also create formal reporting requirements that align closely with the NACD recommendations, particularly around material AI risks. Additionally, the emergence of investor-facing AI governance frameworks, including work from the Oxford Martin School on investor AI governance, signals that voluntary board-level guidance is converging toward investor-enforceable expectations.

Stay ahead of stories like this

Get every Global AI governance development like this one, plus the rest of the week's developments. Every Thursday.

Powered by Buttondown.

Related Coverage

Research2026-08-24

Experian Frames AI Governance as an Adaptive Extension of Model Risk Management

Experian has published practitioner guidance positioning AI governance as an evolution of model risk management rather than a separate discipline. The piece, aimed at financial institutions managing large model portfolios, argues that validation and monitoring must become continuous rather than point-in-time. Compliance teams can use it as a benchmark for modernizing model oversight without abandoning regulatory discipline.

Research2026-08-24

PwC India Sets Board-Approved Risk Appetite as the Anchor for AI Model Governance

PwC India published guidance titled 'Governing models in the AI era' recommending that organizations establish board-approved AI model risk appetite thresholds, build complete model inventories with ownership and validation metadata, and apply AI-specific due diligence to third-party solutions. The guidance addresses a persistent implementation gap: most enterprises have neither a formal definition of what counts as a model nor a complete register of model-like tools in production. Compliance teams can adopt the framework as a practical operating model for cataloguing AI systems and governing external vendors.

Corporate Policy2026-08-22

Anthropic IPO Prospectus Makes AI Backlash a Material Investor Risk

Anthropic's forthcoming IPO prospectus is expected to formally list public opposition to AI and data center construction as a material risk factor, according to sources cited by CNBC. The company, privately valued near $1 trillion, will also disclose compute capacity constraints and open-source competition as investor-facing risks. The filing will be the first SEC-reviewed document from a major frontier lab to characterize societal AI opposition this way.