Article · May 18, 2026 · 5 min read

Who on the Board Should Own AI?

A view from ten years as an audit committee chair, and twenty years before that at a Big Four firm.

AI oversight belongs to the full board, not to the audit committee alone. The audit committee owns one part of it, risk and controls. Strategy is full board work, because AI is reshaping business models, competitive positioning, capital allocation, and the long-term sustainability of the workforce. Talent, culture, and compensation belong with the compensation and HR committees. Transactions, M&A diligence, and litigation exposure belong with the full board and its legal counsel. Governance day to day needs a named accountable executive rather than a committee. For most companies a dedicated AI committee is not necessary, and defaulting the whole subject to audit is the mistake worth slowing down to avoid.

Most board agendas now include the letters AI somewhere. The question directors are actually wrestling with is simpler. Who on the board should own it?

For the last decade, I have served as Audit Committee Chairman of a privately held software and services business dual headquartered in Hong Kong and Singapore, with operating units across Asia-Pacific. Before that, I spent twenty years at PwC, including as the managing partner of their mid-Atlantic Technology Assurance practice. From those roles (and others), I want to offer a practical answer to a question that seems to be settled too quickly in too many boardrooms.

The default answer I hear most often is, the audit committee will take it. On the surface, that is logical. The audit committee charter already covers risk oversight, internal controls, financial reporting, and in many cases, cybersecurity. AI looks like another item to slide into the same responsibility slot. After ten years of chairing an audit committee and other board roles, I would urge boards to slow down before defaulting there.

The audit committee owns part of this. Not all of it.

AI's place in an enterprise has at least four dimensions that matter at the board level. Strategy. Risk and controls. Talent and culture. Transactions. Each dimension requires a different level of responsibility and oversight.

Strategy is full-board work. AI is reshaping business models, competitive positioning, capital allocation, and the long-term sustainability of the workforce. Those are conversations the full board should be having every quarter and not delegated to a committee. The CEO and the full board need to align on whether the company is using AI to defend its current position, evaluate new ones, or simply keeping pace.

Risk and controls are audit committee work. The audit committee should be briefed on current AI applications, AI governance, third-party AI vendor risk, financial reporting implications, and incident response. The frameworks for these already exist. None of these require audit committee members to write code. However, it does require the audit committee to apply the same discipline and scrutiny they apply to financial reporting and cybersecurity.

Talent, culture, and compensation belong with the compensation and HR committees. AI is changing what people do, how they are evaluated, and how they are paid. Those committees need to be in the conversation.

Transactions, M&A diligence, and litigation exposure belong with the full board, with their legal counsel, and with whichever committee has charter authority over deal review.

Should a board require the formation of an AI committee?

Given the growing importance of AI to an organization, I believe it should be a full board level responsibility, with a clear role for the audit committee on risk and controls, and a clear role for management on adoption and execution. If a company's entire commercial model is being rebuilt around AI, that is a different conversation, and a dedicated committee may make sense. For most companies, it does not.

Three questions every board chairman should be asking now

1. What is our current AI inventory?

If management cannot produce a current list of AI tools in operation, tools in pilot, tools being planned, and tools embedded in third-party software the company already uses, that should be a concern.

2. Who owns AI governance?

There needs to be a named accountable executive, not a committee. There should be documentation the audit committee or the full board can actually review. If the answer is, we have not gotten to that yet, that should be another concern.

3. When was the last time the board received a briefing on AI regulatory developments?

Rules are moving across federal, state, and international jurisdictions at a rapid pace. A board that has not been briefed in the last three to six months is behind.

A closing observation

The boards that get this right will not be the ones with the most AI expertise around the table. They will be the ones that apply the same governance and discipline they are applying to financial reporting, internal controls, and cybersecurity. It requires structure, prioritization, and a willingness to put AI on the agenda as a recurring item rather than a special project.

If you are a member of the board of directors or an audit committee chair working through these questions on your own board, I welcome a conversation. AcumenX advises boards, CEOs, and general counsels on the structure, oversight, and governance discipline that AI now requires. Our engagements are led by a senior partner team rather than a leveraged consulting model.

Keep Reading

Ready for the next phase of growth?

Contact us to discuss how we can address your business needs.