Hit enter to search or ESC to close

Navigating AI Governance: Essential Steps for Boards to Take

In this article, Dr. Orla Lenihan, Assistant Professor in Corporate Governance & MBA Director, University of Galway, discusses how boards can build effective AI governance, balance innovation with oversight, manage emerging risks, and strengthen accountability.

https://www.iodireland.ie/images/uploads/library/Dr_Orla_Lenihan_UG.jpg{/banner_image}

In this article, Dr. Orla Lenihan, Assistant Professor in Corporate Governance & MBA Director, University of Galway, discusses how boards can build effective AI governance, balance innovation with oversight, manage emerging risks, and strengthen accountability. 

Artificial Intelligence (AI) has evolved from an emerging technology to a strategic imperative that boards must actively oversee. While directors widely view AI as a top priority, many boards lack the know-how and frameworks to effectively govern AI in their organisations. This disconnect has become more concerning following the introduction of the EU AI Act. The Act represents the world’s first comprehensive legal framework for AI and, although it came into force in 2024, most of the Act’s obligations become legally enforceable in August 2026. For directors to effectively oversee AI with confidence, boards should take four immediate steps.

1. Invest in AI literacy 

Boards cannot govern what they do not understand. Directors do not need to be technical experts, but they must possess a sufficient level of competence to ask the right questions and challenge management’s assumptions. It is important that the board as a whole has adequate fluency in AI to avoid the common pitfall of authority bias—the tendency for a board to defer to one expert director’s judgement instead of collectively assessing the information. Methods of board upskilling include availing of external advisors for AI briefings and obtaining formal AI certifications from board-education providers. At this point, board committees should also review and update their charters/terms of reference to reflect their specific AI-related responsibilities.

2. Develop regulatory awareness

An AI system is a machine-based system that infers, from the input it receives, how to generate outputs such as predictions, content, recommendations, or decisions. The EU AI Act places obligations on both providers and deployers of AI systems. AI providers are the companies or individuals who create or introduce AI systems or models into the market. AI deployers are organisations or people that use AI systems in their operations. The Act takes a risk-based approach by categorising AI systems into three tiers:

  • Unacceptable risk: Applications that threaten safety or fundamental rights are strictly prohibited (e.g., social scoring, some monitoring, automated weaponry).
  • High risk: This applies when the AI system poses a significant risk to the health, safety, or fundamental rights of individuals. For example, AI used in critical infrastructure, education, employment, or law enforcement is subject to strict compliance obligations. Directors of organisations that provide or deploy high-risk AI systems should ensure that all of the following are in place:adequate risk assessment and mitigation systems
    • use of high quality, bias-free datasets
    • logging of activity to ensure traceability
    • detailed documentation
    • clear and adequate information for users
    • appropriate human oversight
    • high levels of robustness, security, and accuracy.
  • Non-high risk: All other AI systems that have minimal potential to cause harm. Providers and deployers of non-high risk systems are encouraged to adopt voluntarily codes of conduct. These AI tools, such as chatbots for example, must also meet transparency obligations to ensure that users know they are interacting with a machine.

To effectively identify risks, directors should ask the following questions of management:

  • What is the AI system doing? Is it making decisions or interacting with people?
  • Who is affected by its outputs? Could it unintentionally discriminate or exclude?
  • What data is it using? Is the data personal, is there a risk of bias, and how is management identifying and mitigating hallucinations?

3. Ensure responsible use of AI

Complementing the EU AI Act is the Assessment List for Trustworthy AI, which provides a self-assessment framework that boards should ensure management is addressing. The list comprises seven requirements to ensure that AI use is lawful, ethical, and robust: 

  • Human Agency and Oversight: AI systems must uphold fundamental rights and incorporate human oversight mechanisms.
  • Technical Robustness and Safety: Trustworthy AI must be dependable and resilient to adversarial attacks or unexpected environmental changes. 
  • Privacy and Data Governance: AI systems must protect the ethical collection, storage, and usage of personal information, adhering strictly to data protection laws like GDPR. 
  • Transparency: Maintain documentation on how AI systems are developed, explain AI-driven decisions, and clearly notify users when they are interacting with an AI system. 
  • Diversity, Non-discrimination and Fairness: AI systems must enable inclusion and diversity, ensuring equitable outcomes for all users regardless of age, disability, or other characteristics. 
  • Societal and Environmental Well-being: AI systems should positively impact the broader society and be sustainable and environmentally friendly. 
  • Accountability: Audit trails and redress mechanisms should be established to ensure responsibility for AI systems.

Boards should encourage management to actively engage with the questions in this assessment list and take appropriate action where necessary to avoid and minimise the risks that an AI system might generate. 

4. Establish AI policy

Every organisation, whether developing or using AI, should have an AI policy that provides clear accountability, strong risk management, and robust oversight. This is firmly the responsibility of the board and the policy must be led from the top. A comprehensive AI policy should include all of the following:

  • The purpose and scope, so everyone knows how AI will be used to support organisational goals and deliver value.
  • Clear definitions of key terms.
  • Guiding principles like fairness, honesty, accountability, and transparency.
  • Compliance with laws and regulations.
  • Who is responsible for managing and overseeing AI.
  • Robust data governance to ensure reliability and security.
  • Risk management procedures, including human oversight.
  • Reporting and communication channels, particularly with regard to incidents.
  • Ongoing monitoring and auditing of AI usage and maintaining documentation.
  • Non-compliance consequences.

The AI policy should be supported by employee training and education to foster a culture that encourages innovation, while remaining mindful of ethical considerations. Developing AI literacy and skills amongst the workforce is essential to ensure that staff use AI tools appropriately, understand the reasoning behind the decisions or predictions that AI systems make, and know when to critically challenge AI outputs. 

AI is reshaping how organisations operate, compete, and succeed. Boards that actively govern AI will be better positioned to maximise its opportunities while managing the legal, operational, and reputational risks that it presents.

This article is the view of the author(s) and does not necessarily reflect IoD Ireland’s policy or position.

About the Author

Dr. Orla Lenihan is an Assistant Professor in Corporate Governance and the Director of the Executive MBA programme at University of Galway. Orla qualified as a Chartered Accountant with PricewaterhouseCoopers and she holds a PhD in Corporate Governance. She delivers executive education courses in corporate governance and finance and she has previously taught on professional accounting and auditing courses. Orla's research focuses on corporate boards of directors and she is a regular radio and television commentator on corporate governance matters.