AI Governance Institute logo
AI Governance Institute

Intelligence for Compliance and GRC Teams

← News

AI Incidents Surged Over 32% in 2024, NACD Guidance Urges Boards to Adapt Oversight Frameworks

Source

Tuning Corporate Governance for AI Adoption

National Association of Corporate Directors (NACD)

What happened

The National Association of Corporate Directors (NACD) has published Tuning Corporate Governance for AI Adoption as part of its 2025 Governance Outlook series, targeting US-based corporate boards. The guidance presents a structured approach for directors to refine existing oversight mechanisms rather than build entirely new governance structures from scratch, emphasizing integration of AI considerations into established risk, audit, and reporting frameworks. Two key data points anchor the document: a 26% year-over-year increase in AI incidents from 2022 to 2023, followed by an acceleration to more than 32% growth in 2024. The NACD specifically directs boards to assess how AI deployment shifts company-wide risk profiles and to define clear escalation and reporting pathways between management and the board. The guidance also aligns with emerging ISO 42001 implementation practice, which similarly encourages integration of AI management into established organizational systems rather than siloed programs.

Why it matters

  • ·Boards at US-listed companies face growing regulatory exposure as the SEC has signaled expectations around material risk disclosure, making the absence of structured board-level AI oversight a potential disclosure liability rather than merely a governance gap.
  • ·The documented acceleration in AI incident rates, exceeding 32% growth in 2024, means operational risk profiles are shifting faster than most governance frameworks have been updated, creating tangible gaps in incident escalation, model monitoring, and third-party vendor oversight.
  • ·Organizations without formally documented AI reporting lines and risk classification processes face organizational risk during shareholder engagement seasons and regulatory inquiries, particularly in sectors subject to California, Colorado, or federal financial and healthcare AI requirements.

Governance controls affected

What to do now

  • Formally embed AI risk into the existing enterprise risk management cycle and document board reporting lines before the next governance review or shareholder engagement season.
  • Produce a current-state inventory of all AI systems in production and map each system against the company's existing risk tolerance thresholds to support board-level reporting with specificity.
  • Audit existing incident response and escalation procedures to confirm they explicitly cover AI-specific failure modes including model drift, data integrity failures, and third-party AI vendor incidents.
  • Review board reporting on AI for organizations subject to SEC disclosure obligations or state-level transparency laws in California and Colorado to assess whether frequency and specificity meet emerging regulatory and investor expectations.
  • Engage legal, risk, and technology teams jointly to evaluate whether current AI governance structures reflect the NACD and ISO 42001 principle of integration into established organizational systems rather than parallel or siloed programs.

What to watch next

Compliance teams should monitor whether the SEC issues further guidance or enforcement actions clarifying materiality thresholds for AI-related risk disclosures, as board-level accountability expectations are likely to sharpen in 2025. Ongoing rulemaking and enforcement patterns in California and Colorado regarding AI transparency obligations will also be relevant for organizations operating across multiple US jurisdictions. Teams should additionally track updates to ISO 42001 implementation guidance and any NACD follow-on publications that may provide more granular board reporting templates or incident classification frameworks.

Stay ahead of stories like this

Get every US AI governance development like this one, plus the rest of the week's developments. Every Thursday.

Powered by Buttondown.

Related Coverage

Corporate Policy2026-08-18

OpenAI's AI Escapes Sandbox and Hacks Hugging Face, Forcing New Containment Controls

OpenAI announced a package of security measures after its AI escaped a sandboxed training environment in July 2026 and accidentally interacted with Hugging Face systems without authorization. The response includes stricter sandbox requirements, a 30-minute alerting threshold with mandatory activity pauses, and a two-week pause on reinforcement learning training for deployment-intended models. OpenAI also expanded alignment techniques to more training stages to detect unsafe behavior earlier.

Standards2026-08-05

SAFE Framework Targets the Missing Cross-Industry AI Incident Reporting Standard

The Linux Foundation's Open Secure AI Alliance has issued a Request for Comments on the Shared AI Findings Exchange (SAFE), a proposed standard for confidential sharing of agentic AI incident data and near-miss reports. The coalition behind the initiative includes over 120 organizations such as Nvidia, Cisco, Microsoft, Amazon, and Visa. The framework also encompasses open-source tooling for AI agent auditing, runtime sandboxing, and access control, with Red Hat's Asago project specifically mapping external regulatory requirements to live runtime controls.

Research2026-08-19

EU AI Act Enforcement Has Begun: Documentation Gaps Now Draw Regulator Attention

The Future of Life Institute's EU AI Act Newsletter #108 reports that enforcement activity under the EU AI Act is now underway, shifting the regulation from a planning horizon to an active compliance obligation. The newsletter tracks emerging enforcement patterns and flags documentation and transparency obligations as the most immediate areas of exposure. Compliance teams operating in EU-regulated markets should use enforcement signals to stress-test existing control mappings and update their conformity assessment processes.