AI Governance Institute
← News
Research2026-05-06

Three Structural Gaps Where AI Undermines Corporate Governance, Seattle University Law Review Finds

What happened

The AI, New Technologies, and Corporate Governance: Three Phenomena article was published in Volume 47, Issue 5 of the Seattle University Law Review by Seattle University School of Law researchers. The peer-reviewed article presents a legal-structural analysis identifying three discrete phenomena that destabilize traditional corporate governance doctrine: the erosion of firm boundaries through reliance on externally provided AI services, the emergence of strategic access arrangements in which enterprises use AI capabilities without owning underlying assets or models, and the hybrid nature of online platforms that simultaneously operate as infrastructure providers and competitive market actors. The authors argue that neither corporate law nor existing sector-specific regulatory frameworks adequately address the accountability gaps created by these three conditions. The analysis is framed as a global structural assessment without focus on a single jurisdiction, though it engages directly with developments including the EU AI Act, the EU Digital Services Act, and proposed frameworks such as the EU Digital Networks Act. The article adds a corporate governance lens to a conversation that has previously been dominated by public law and consumer protection perspectives.

Why it matters

  • ·Regulatory exposure is increasing as legislative efforts such as the EU AI Act begin codifying supply chain accountability, meaning organizations that access AI capabilities through third-party services rather than owning them may face affirmative compliance obligations they have not yet mapped.
  • ·Operational impact is significant for enterprises relying on platform intermediaries for AI services, because those platforms' dual roles as both infrastructure providers and market participants create conflicts of interest that may affect service reliability, pricing, and data handling in ways not currently reflected in enterprise risk registers.
  • ·Organizational risk is elevated for boards and general counsel offices whose AI oversight frameworks were designed around assumptions of internal AI development, as those frameworks may no longer match operational reality and could expose organizations to governance failures if not updated.

Governance controls affected

What to do now

  • Audit which AI capabilities your organization accesses through third-party services rather than owns, and document the results against your current vendor risk inventory.
  • Review existing vendor contracts and liability clauses for AI services to assess whether they address the accountability gaps created by externally hosted models and cloud-based inference services.
  • Examine whether platform intermediaries supplying AI services to your organization hold dual market roles that create conflicts of interest, and update enterprise risk registers to reflect those findings.
  • Assess whether board-level governance charters, audit committee mandates, and third-party risk policies reflect current operational reliance on external AI rather than internally developed systems, and recommend updates where gaps exist.
  • Track legislative developments in the EU and at the U.S. federal level related to AI supply chain accountability, and assign ownership within the compliance function for monitoring how those frameworks will create new affirmative obligations.

What to watch next

Compliance teams should monitor the implementation guidance and enforcement priorities emerging from the EU AI Act, particularly provisions assigning liability along AI supply chains, as these will translate the structural conditions described in the article into concrete legal obligations. The evolution of the EU Digital Services Act and any finalized EU Digital Networks Act framework will also be relevant for organizations that interact with large platforms in a dual-role capacity. At the U.S. federal level, teams should track whether financial regulators expand their existing third-party AI risk guidance into binding requirements that mirror the supply chain accountability logic the article analyzes. Enforcement actions targeting third-party AI arrangements in any of these jurisdictions will serve as early indicators of how regulators are interpreting accountability gaps in practice.

Stay ahead of stories like this

Get every Global AI governance development like this one, plus the rest of the week's developments. Every Thursday.

Powered by Buttondown.

Related Coverage

Research2026-09-01

SR 26-2 Forces Banks to Rethink Model Governance From Inventory to Board Oversight

The OCC and Federal Reserve's revised model risk management guidance, SR 26-2, resets supervisory expectations for U.S. banks by shifting to a materiality-based approach that covers both traditional statistical models and AI systems, replacing the SR 11-7 framework that had governed bank model governance since 2011. Practitioner analysis from CRA identifies four areas banks must redesign: inventory scope, model tiering, validation independence, and governance alignment up to the board. A companion implementation guide from Lumenova AI adds concrete steps, including inventory rationalization and a distinct governance lane for agentic and generative AI, while a proposed academic framework maps a six-layer control architecture for bringing GenAI systems into SR 26-2 scope. Banks that still run AI governance and model risk management as separate programs face the most immediate pressure to harmonize them.

Research2026-09-07

CISO AI Confidence Tracks Governance Readiness, Not Control Effectiveness

An IANS Research survey of 113 CISOs found that optimism about managing AI security risks over the next 24 months correlates more strongly with organizational readiness factors than with verified technical controls. Factors such as leadership understanding of AI risk, defined governance ownership, CISO budget authority, and adequate staffing drive confidence levels. Analysts caution that these signals reflect favorable conditions rather than demonstrated control outcomes, and that third-party AI risk and agent authorization gaps remain broadly unaddressed.

Research2026-09-02

FLI Safety Index Ranks Frontier AI Firms, Creating a Vendor Benchmarking Obligation

The Future of Life Institute published its AI Safety Index Summer 2026 on August 26, 2026, ranking major frontier AI developers on safety practices and transparency. Anthropic leads across most domains in the ranking. The index gives enterprise compliance teams an external benchmark to use in vendor due diligence, procurement risk assessments, and board-level AI risk reporting.