AI Governance Institute
← News

AI Incidents Rose 26% From 2022 to 2023, NACD Guidance Urges Boards to Adapt Oversight

Source

Tuning Corporate Governance for AI Adoption

National Association of Corporate Directors

What happened

The National Association of Corporate Directors published Tuning Corporate Governance for AI Adoption in January 2025 as part of its 2025 Governance Outlook series, directing its guidance at US corporate boards and the directors who serve on them. The document identifies hallucinations, data privacy vulnerabilities, and algorithmic bias as the primary AI-specific risk categories requiring dedicated board-level attention. It grounds these concerns in quantitative data from the AI Incident Database, which recorded a 26 percent year-over-year increase in AI incidents between 2022 and 2023. Preliminary 2024 figures cited in the document indicate the trend is accelerating, with incidents expected to have grown by more than 32 percent. The guidance stops short of prescribing specific oversight structures but frames the core challenge as a mismatch between legacy corporate governance mechanisms and the pace of AI-related risk, calling on boards to actively adapt rather than apply existing frameworks by analogy.

Why it matters

  • ·Regulatory exposure is increasing as boards that fail to demonstrate active AI risk oversight may face heightened scrutiny from regulators and institutional investors who are treating AI governance as a fiduciary matter rather than a technical concern.
  • ·Operationally, the accelerating incident rate documented by the AI Incident Database signals that organizations relying on existing risk management frameworks without AI-specific adaptations are likely underestimating their exposure to hallucinations, bias events, and data privacy failures.
  • ·Organizationally, the guidance creates a reputational risk for companies whose boards cannot demonstrate familiarity with AI incident trends, as the NACD is positioning AI risk oversight as a core competency expectation for directors at US corporations.

Governance controls affected

What to do now

  • ☐Map your organization's current AI risk classification process against HOC-001 to identify gaps that board-level oversight mechanisms are not yet addressing.
  • ☐Brief the board or relevant board committee on AI incident trends using the AI Incident Database figures cited in the NACD guidance as a benchmark for your own incident tracking.
  • ☐Review your AI incident response playbook under IRC-001 to confirm it covers hallucination events, bias incidents, and data privacy failures as distinct severity categories.
  • ☐Assess whether existing bias and fairness monitoring controls under MON-003 are generating reportable outputs suitable for board-level consumption on a regular cadence.
  • ☐Document the board's AI oversight mandate explicitly in governance charters or risk committee terms of reference to align with the NACD's framing of AI oversight as a core director responsibility.

What to watch next

Compliance teams should monitor whether the NACD follows this guidance with more prescriptive recommendations on board committee structures or director competency standards for AI oversight, as the current document deliberately avoids structural mandates. Teams should also track whether US securities regulators reference incident rate data or NACD guidance in future disclosure rulemaking related to AI risk. The accelerating incident figures for 2024, once formally published by the AI Incident Database, are likely to intensify pressure on boards and may prompt institutional investors to introduce AI governance criteria into proxy voting policies.

Stay ahead of stories like this

Get every US AI governance development like this one, plus the rest of the week's developments. Every Thursday.

Powered by Buttondown.

Related Coverage

Enforcement2026-09-21

DOJ Signals Criminal Enforcement for AI-Linked Violations

U.S. Attorney General Pam Blanche stated that the Department of Justice will investigate and prosecute anyone connected with AI who violates criminal law. The statement was broad and named no specific company or conduct type. It signals that criminal liability is now an explicit dimension of the AI enforcement landscape for enterprises.

Corporate Policy2026-09-22

US-China AI Incident Notification Proposal Creates Cross-Border Reporting Gap

Treasury Secretary Scott Bessent announced that the US has proposed a bilateral notification mechanism for AI incidents that could affect national security. The proposal was raised in talks with Chinese Vice Premier He Lifeng ahead of a potential Trump-Xi summit. No formal agreement exists yet, but analysts say the proposal could set a precedent for enterprise AI incident reporting obligations.

Enforcement2026-09-22

NY Comptroller Audit Finds SUNY Lacked AI Definition, Inventory, or Approval Workflows

New York State Comptroller Thomas DiNapoli released an audit finding that SUNY Administration had no effective AI governance framework, no standard definition of AI, and no documented policies or approval workflows for AI development and use. The audit identified specific weaknesses in inventory management, policy controls, and internal accountability. The findings create a public-sector governance benchmark that compliance teams in both government and regulated industries should treat as a checklist.