AI Governance for Boards:

From Experimentation to Accountability

Recordings

About this event

AI has moved rapidly from experimentation into enterprise-wide implementation. For boards, this creates a new governance challenge: how to support innovation while ensuring appropriate oversight, accountability, transparency, and risk management.

This webinar will examine the board’s role in governing AI amid a complex global environment shaped by regulatory fragmentation, geopolitical competition, cybersecurity threats, misinformation, digital sovereignty concerns, and rapidly evolving stakeholder expectations.

With a particular focus on the GCC and global governance landscape, the session will explore how boards can strengthen AI oversight frameworks, assess emerging risks, and prepare for the strategic implications of AI-assisted decision-making — including the future possibility of AI-generated advisory roles in governance.

Key questions answered

The New Frontier of Corporate Oversight

The strategic landscape has shifted fundamentally, Artificial Intelligence (AI) has evolved from an experimental IT elective to a non-negotiable fiduciary mandate. As organizations transition from a “Wild West” of isolated experimentation toward a structured enterprise reality, boards must recognize that AI governance is no longer a peripheral concern but a central pillar of modern corporate oversight.

 

An analysis by McKinsey & Company reveals an “AI-savvy” performance gap that is already reconfiguring the global competitive landscape: boards proficient in AI oversight currently enjoy an 11% performance premium, while those failing to govern the technology face a staggering 15% performance swing in the opposite direction. This data underscores that a board’s ability to drive an “AI-first” mindset, while maintaining rigorous accountability, is the primary determinant of long-term value creation. To maintain a competitive edge, directors must now balance the rapid adoption of transformative tools with a robust framework that prevents the abdication of directorial duty.
From a governance perspective, there is a profound legal distinction between delegating tasks to an AI system and abdicating directorial responsibility. While AI can process vast amounts of data and propose complex strategies, the board remains the ultimate guardian of the company’s assets and business affairs.
 
If AI-assisted decisions lead to corporate harm, who is held legally accountable, and how does the Business Judgment Rule apply?
As emphasized by Professor Mervyn King and Rohan Sharma, the core of legal protection rests on the “original application of mind.”
 
To be shielded by the Business Judgment Rule, directors must satisfy three stringent criteria:

  1. No Financial Interest: The director must have no personal stake in the decision.

  2. Possession of All Facts: The board must have objectively sought and interrogated all relevant information, including the underlying logic of AI outputs.

  3. Rational Decision-Making: The decision must be a rational business judgment made in the long-term interest of the company.
 
Crucially, Professor King warns that liability is temporal; boards must be able to account for their decisions even four years later, tracing back to the specific version of the algorithms in place at the time the choice was made. Failing to interrogate an AI output is, by definition, a failure of the “rationality” requirement under the Rule. Reliance on a “black box” without intellectual skepticism constitutes an abdication of duty, not a delegation of task.
 
There is a significant Accountability Gap in the operating chain. When we move from software-as-a-service to AI-driven intelligence, the boundary of who to point the finger at blurs. If an enterprise delegates a decision to a model, they often find no clarity on how to find accountability when that model causes harm.” — Rohan Sharma
 
As organizations enter the “Second Wave” of AI—moving from human assistance to autonomous execution—the structure of board oversight must evolve to eliminate information silos.
 
Should boards establish a dedicated AI subcommittee, and what specific roles are needed to oversee AI value creation?
Strategic oversight requires a confluence point for technical and financial data.
 
Professor King mandates the prominence of the Chief Value Officer (CVO) as this critical junction. In a modern governance hierarchy, the Chief Information Officer (CIO) and Chief Financial Officer (CFO) must report to the CVO, who then synthesizes how AI impacts value creation, preservation, or erosion for the board.
 
Whether oversight is housed within the Audit Committee, a Technology Committee, or a dedicated AI Risk subcommittee, the board must mandate that management provides clear answers to the following:

  • Inventory of Shadow AI: Do we have a complete registry of all AI tools used across small business units without official IT approval?

  • Temporal Audit Trails: Is there a documented path showing which human approved a decision generated by an AI agent?

  • D&O Insurance Alignment: Is our current Directors and Officers (D&O) insurance policy being revamped to specifically include personal liability for AI-driven algorithmic harm?

  • Kill-Switch Protocols: Does the organization have the technical ability to “pause” a system immediately if it generates biased or harmful outputs?

 

A critical strategic risk is the failure to differentiate between “Everyday AI,” which boosts individual tasks, and “Enterprise AI,” which fundamentally alters the corporate DNA.
 
What is the difference between ‘Everyday AI’ and ‘Enterprise AI,’ and why must boards mandate this distinction?
Sana Kaleem emphasizes that an “AI-first mindset” requires moving beyond using AI to write better emails.
 
Boards must focus on systemic workflow redesign. For example, using AI to read a contract is a minor productivity gain; redesigning the end-to-end procurement process so AI agents manage vendor selection is a deep enterprise transformation.
 
Feature
Individual Productivity (Everyday AI)
Workflow Redesign (Enterprise AI)
Primary Use
Writing emails, data summaries, and personal task management.
Systemic redesign of hiring, procurement, and credit lending.
Example
Using a chatbot to polish a report or read a single contract.
Redesigning end-to-end procurement so AI agents manage vendor selection.
ROI Metric
Hard to quantify; often results in “well-versed emails” but no systemic change.
Quantifiable; e.g., reducing procurement cycles from 30 days to 15 days.
Strategic Impact
Incremental efficiency at the desk level.
Systemic transformation of margins and competitive speed.
AI strategy is inseparable from ESG (Environmental, Social, and Governance) mandates.
The extreme resource consumption of large-scale AI models creates operational risks that can no longer be ignored.
 
What are the second-order ethical implications of AI, particularly regarding environmental resources and social bias?
 
The “hidden costs” of AI are staggering. A single ChatGPT query consumes as much electricity as 100 Google searches. A mid-sized data center can consume as much water as a town of 10,000 people. This is a visceral concern for regions facing water scarcity, such as Cape Town, which narrowly avoided a “Day Zero” total water depletion.
 
Strategic oversight requires that boards look beyond the “CAPEX-phase” promise of jobs, which Rohan Sharma notes often fails to provide long-term community value.
 
Instead, boards should evaluate the “Should we?” framework.
Specifically, boards must consider mandating that AI vendors and data center partners utilize “off-grid” solutions, such as dedicated solar farms and private water sources, to ensure that the enterprise’s AI demand does not destabilize local utility grids or community resources.
Ethical failure is a governance failure. To fulfill the duty of care, directors must maintain intellectual honesty and a willingness to interrogate “Agentic AI”—systems that do not just suggest, but execute.
 
How can directors fulfill their duty of care when AI algorithms are inherently complex or biased?
AI compounds small initial biases through self-learning, leading to systemic discrepancies in hiring or credit lending.
 
Directors cannot hide behind the complexity of the “black box.” You must be able to “trace back” a decision to a human oversight point.
To ensure the board is protected from future litigation and regulatory scrutiny, every Director’s Evidence Pack must include:
  1. Temporal Algorithmic Auditing
    A documented archive of the specific versions of “agentic” or self-evolving models used at the time a corporate decision was made, allowing for retrospective interrogation.

  2. Intellectual Honesty (Human-in-the-Loop)
    Verified evidence that a human director applied an “original application of mind” to the AI’s output before it was adopted as policy.

  3. D&O Insurance Alignment
    Verification that the scale of the board’s personal liability coverage is in direct alignment with the scale of the AI’s decision-making autonomy.

Asking questions before an incident is governance; asking after is testimony.
 

Summaries

Explainer Video

Podcast-style summary

Hosted By

carolynn chalmers, ceo of the gga

Carolynn Chalmers is the Chief Executive Officer of the Good Governance Academy and a respected voice in governance, sustainability, and responsible leadership. Through her work with global standards and education initiatives, she helps advance practical, purpose-driven governance that supports accountability, long-term value creation, and sustainable organisational performance.

Guest speakers

Professor Mervyn King

Professor Mervyn King is the Founding Patron of the Good Governance Academy and one of the world’s leading voices on corporate governance and integrated reporting. A Senior Counsel and former Judge of the Supreme Court of South Africa, he is widely recognised for his leadership of the King Committee on Corporate Governance and his contribution to advancing ethical, effective, and sustainable governance globally.

Sana Kaleem

Sana Kaleem is a Senior Engagement Manager at McKinsey & Company, specializing in AI-driven transformations that improve operational performance and accelerate growth. She has led large, cross-functional AI programs across government and private-sector institutions in the Middle East, spanning strategy, capability building, and end-to-end implementation.  Sana leads McKinsey’s tech and AI projects in the region and helps shape firm perspectives on AI operating models, workforce transformation, and large-scale adoption. She brings over 15 years of experience working with national government entities, financial institutions, technology partners and is a frequent speaker at AI forums and leadership programs.

Rohan Sharma

Rohan Sharma is an award-winning technology executive who has led AI products and digital transformations at Apple, Disney, and Fortune 100s. Rohan advises Boards and Executives on capital allocation & regulatory risk implication. He is a Stanford Seed strategy consultant and advisory board member at Frost & Sullivan.

Glossary of terms

Term

Definition

Agentic AI
AI technology that does not just provide information but has the capability to execute decisions and drive outcomes autonomously.
Business Judgment Rule
A legal principle providing that directors are not liable for business decisions that result in harm, provided they acted with care, skill, diligence, and without financial interest.
Chief Value Officer (CVO)
A specialized executive role focused on the integration of financial and non-financial information to oversee value creation and preservation.
CPD Requirements
Continuing Professional Development; participation requirements (often tracked via polls or attendance) for professionals to maintain their certifications.
D&O Insurance
Directors and Officers liability insurance, which is currently being revamped to address personal liability risks associated with AI-driven failures.
Enterprise AI
High-level AI integration focused on changing organizational workflows and optimizing entire processes, as opposed to “everyday AI” used for individual tasks like writing emails.
Frontier AI
Highly advanced AI models that possess a broad range of capabilities and can outperform existing tools, often associated with higher levels of systemic risk.
GCC BDI
The Gulf Cooperation Council Board Directors Institute, an organization supporting board effectiveness across Saudi Arabia, UAE, Oman, Qatar, Bahrain, and Kuwait.
Good Governance Academy (GGA)
A global organization dedicated to the promotion of effective corporate governance and sustainability.
Original Application of Mind
The legal requirement for directors to use their own intellectual reasoning and interrogation rather than blindly following a report or an AI output.
Second-Order Effects
The indirect, often unintended consequences of a technology’s adoption (e.g., a tool meant for efficiency causing a class-action lawsuit for hiring bias).
Token Maxing
A situation where an organization exceeds its estimated AI budget due to the high volume of data processed (“tokens”) by employees.

Terms and Conditions

  • The Good Governance Academy nor any of its agents or representatives shall be liable for any damage, loss or liability arising from the use or inability to use this web site or the services or content provided from and through this web site.
  • This web site is supplied on an “as is” basis and has not been compiled or supplied to meet the user’s individual requirements. It is the sole responsibility of the user to satisfy itself prior to entering into this agreement with The Good Governance Academy that the service available from and through this web site will meet the user’s individual requirements and be compatible with the user’s hardware and/or software.
  • Information, ideas and opinions expressed on this site should not be regarded as professional advice or the official opinion of The Good Governance Academy and users are encouraged to consult professional advice before taking any course of action related to information, ideas or opinions expressed on this site.
  • When this site collects private information from users, such information shall not be disclosed to any third party unless agreed upon between the user and The Good Governance Academy.
  • The Good Governance Academy may, in its sole discretion, change this agreement or any part thereof at any time without notice.

Privacy Policy

Link to the policy: GGA Privacy Policy 2021

The Good Governance Academy (“GGA”) strives for transparency and trust when it comes to protecting your privacy and we aim to clearly explain how we collect and process your information.

It’s important to us that you should enjoy using our products, services and website(s) without compromising your privacy in any way. The policy outlines how we collect and use different types of personal and behavioural information, and the reasons for doing so. You have the right to access, change or delete your personal information at any time and you can find out more about this and your rights by contacting the GGA, clicking on the “CONTACT” menu item or using the details at the bottom of the page.

The policy applies to “users” (or “you”) of the GGA website(s) or any GGA product or service; that is anyone attending, registering or interacting with any product or service from the GGA. This includes event attendees, participants, registrants, website users, app users and the like.

Our policies are updated from time-to-time. Please refer back regularly to keep yourself updated.