AI Governance Institute
← News

AI Incidents Surged Over 32% in 2024, NACD Guidance Urges Boards to Adapt Oversight Frameworks

Source

Tuning Corporate Governance for AI Adoption

National Association of Corporate Directors (NACD)

What happened

The National Association of Corporate Directors (NACD) has published Tuning Corporate Governance for AI Adoption as part of its 2025 Governance Outlook series, targeting US-based corporate boards. The guidance presents a structured approach for directors to refine existing oversight mechanisms rather than build entirely new governance structures from scratch, emphasizing integration of AI considerations into established risk, audit, and reporting frameworks. Two key data points anchor the document: a 26% year-over-year increase in AI incidents from 2022 to 2023, followed by an acceleration to more than 32% growth in 2024. The NACD specifically directs boards to assess how AI deployment shifts company-wide risk profiles and to define clear escalation and reporting pathways between management and the board. The guidance also aligns with emerging ISO 42001 implementation practice, which similarly encourages integration of AI management into established organizational systems rather than siloed programs.

Why it matters

  • ·Boards at US-listed companies face growing regulatory exposure as the SEC has signaled expectations around material risk disclosure, making the absence of structured board-level AI oversight a potential disclosure liability rather than merely a governance gap.
  • ·The documented acceleration in AI incident rates, exceeding 32% growth in 2024, means operational risk profiles are shifting faster than most governance frameworks have been updated, creating tangible gaps in incident escalation, model monitoring, and third-party vendor oversight.
  • ·Organizations without formally documented AI reporting lines and risk classification processes face organizational risk during shareholder engagement seasons and regulatory inquiries, particularly in sectors subject to California, Colorado, or federal financial and healthcare AI requirements.

Governance controls affected

What to do now

  • Formally embed AI risk into the existing enterprise risk management cycle and document board reporting lines before the next governance review or shareholder engagement season.
  • Produce a current-state inventory of all AI systems in production and map each system against the company's existing risk tolerance thresholds to support board-level reporting with specificity.
  • Audit existing incident response and escalation procedures to confirm they explicitly cover AI-specific failure modes including model drift, data integrity failures, and third-party AI vendor incidents.
  • Review board reporting on AI for organizations subject to SEC disclosure obligations or state-level transparency laws in California and Colorado to assess whether frequency and specificity meet emerging regulatory and investor expectations.
  • Engage legal, risk, and technology teams jointly to evaluate whether current AI governance structures reflect the NACD and ISO 42001 principle of integration into established organizational systems rather than parallel or siloed programs.

What to watch next

Compliance teams should monitor whether the SEC issues further guidance or enforcement actions clarifying materiality thresholds for AI-related risk disclosures, as board-level accountability expectations are likely to sharpen in 2025. Ongoing rulemaking and enforcement patterns in California and Colorado regarding AI transparency obligations will also be relevant for organizations operating across multiple US jurisdictions. Teams should additionally track updates to ISO 42001 implementation guidance and any NACD follow-on publications that may provide more granular board reporting templates or incident classification frameworks.

Stay ahead of stories like this

Get every US AI governance development like this one, plus the rest of the week's developments. Every Thursday.

Powered by Buttondown.

Related Coverage

Research2026-09-07

OpenAI's Wiki-Hijack Non-Disclosure Tests EU AI Act Incident Reporting

A Cloud Security Alliance briefing identified OpenAI's reported non-disclosure of a wiki-hijacking incident as an active test case for the EU AI Act's serious-incident reporting obligations. The incident exposes a gap shared by developers and enterprise deployers alike: the absence of predefined triage criteria that determine when model misuse becomes a legally reportable event. Compliance teams deploying high-capability models should treat this as a prompt to formalize their incident escalation thresholds now.

Corporate Policy2026-09-03

Simultaneous ChatGPT, Grok, and Claude Outage Exposes AI Concentration Risk

On September 3, 2026, OpenAI's ChatGPT, xAI's Grok, and Anthropic's Claude experienced simultaneous outages affecting millions of users globally. ChatGPT reported elevated errors across logins, file uploads, voice mode, and image generation, while Anthropic attributed its disruption to an infrastructure issue resolved by 12:15 PM ET. The concurrent nature of the failures raises unresolved questions about shared upstream dependencies and leaves enterprise business continuity programs exposed.

Enforcement2026-09-02

30 New Lawsuits Against OpenAI Test Aiding-and-Abetting Theory in AI Safety

Edelson PC filed 30 additional civil complaints against OpenAI in September 2026 tied to the February 2026 Tumbler Ridge school shooting in British Columbia. The new filings escalate earlier negligence claims by alleging that OpenAI aided and abetted the attack. The complaints directly contest the adequacy of OpenAI's internal threat-assessment structure, safety decision authority, and incident-reporting consistency.