Something changed for boards this year, quietly, and the change was in accountability rather than in information.
In February the Central Bank of the UAE issued guidance on the responsible adoption of AI by licensed financial institutions. Governance and accountability sits first among its five principles, and the accountability described attaches to the institution and its board — not to the vendor who built the system.
Delaware’s courts have been moving in the same direction from a different angle. The duty of oversight has been read, case by case, to require that a board maintain a functioning system for surfacing risk in its mission-critical operations. Not that directors get every judgment right — that they not be structurally blind. Practitioner commentary through 2026 has argued, with increasing confidence, that AI is the natural next application. No court has yet decided it.
Both developments assign the board responsibility. Neither changes what the board is shown.
Both developments assign the board responsibility. Neither changes what the board is shown.
A paper in which every number traces back to the party being paid means the board approved a decision using measures the counterparty authored.
Governance Asymmetry
The reporting line that did not move
In most institutions, the AI update reaching the board is prepared by the team deploying AI, using figures supplied by the vendor selling it. This is not a governance failure in any deliberate sense — it is the ordinary flow of information in any organisation, and it works acceptably for most subjects.
It works less well here for a specific reason. In most board reporting, the numbers describe something that already happened and can be independently reconstructed: revenue, headcount, incidents, capital ratios. In AI reporting, the numbers frequently describe a counterfactual — what would have happened without the system — and counterfactuals cannot be reconstructed. They can only be modelled, and the model has an author.
Diagnostic Check 1
A fifteen-minute check requiring no technical knowledge
Take the last board paper that proposed or reported on an AI initiative. For every quantified claim in it — projected saving, efficiency gain, benchmark, payback period, adoption rate — trace where the number came from.
Not whether it is plausible. Where it came from.
Three origins account for nearly all of them:
Vendor's own material, reproduced
A figure from a sales deck or a case study, carried across without re-derivation.
Institution's business case, built on vendor assumptions
One step removed, and considerably harder to see, because the figure now carries your institution's logo and formatting. The assumptions underneath — adoption rate, baseline, attribution — usually came from the vendor.
Something the institution measured itself
Rare. Figures derived independently from internal baselines and validated measurement clauses.
The ratio is the finding. A paper in which every number traces back to the party being paid is not a dishonest paper. It is an ordinary one. But it means the board approved a decision using measures the counterparty authored, which is a materially different act from the one it appeared to be.
Diagnostic Check 2
The adjacent check, ten minutes
The number problem has an ownership counterpart: if nobody on the board is formally responsible for testing these figures, the ratio above will not change on its own. Open your board’s committee charters and search all of them for artificial intelligence.
Four possible results, each meaning something different:
Audit Committee
Risk or Technology
Several Committees
None
Whatever the answer, it is a fact about your governance rather than an opinion about AI.
Synthesis
What follows
Neither check tells a board to stop, and neither requires anyone to understand how a model works.
What they establish is whether the institution possesses an independent view of its own AI programme, or only a well-formatted version of the vendor’s view. Those feel identical in a board meeting. They differ entirely when the numbers are tested.
Diagnostic Closing Test
If nothing in the last paper originates on your side of the table:
The useful question is not whether the figures are correct. It is what it would take to produce your own — and how long that would take, and who would own it.
An institution that cannot author its own metrics has effectively outsourced the definition of success to the party selling the system.