AI and Fiduciary Duty: What Boards Now Expect
AI has moved from the innovation agenda to the fiduciary one. What oversight now means for directors, and the questions serious boards ask.
By Michael Steve · July 30, 2026 · 4 min read
There was a period, not long ago, when AI appeared in board materials under "innovation": a forward-looking slide, safely down the agenda, owned by whoever ran technology. If your board packet still treats it that way, the packet is out of date in a way that matters.
AI has crossed from the innovation agenda to the fiduciary one. Not because a regulator said so on a particular Tuesday, but because of what fiduciary duty has always meant: directors owe care and diligence on matters material to the organization. AI now touches revenue, cost structure, workforce, customer trust, and risk exposure at once, in most organizations simultaneously, whether or not anyone at the table chose it. Materiality is not a decision the board gets to make. It is a condition the board is expected to notice.
Why the duty attaches now
Three realities moved AI into fiduciary territory, and none of them require a new law to be true.
It is already inside the organization. Employees adopt AI tools faster than organizations govern them, which means the exposure exists today: confidential information moving through unapproved tools, work product of uneven quality shipping under the organization's name, decisions quietly shaped by systems nobody vetted. Ungoverned AI is not a future risk; it is a present condition, and oversight of present conditions is squarely the board's business.
It is material to strategy. When a technology can meaningfully move cost structure and open or close revenue, capital is being allocated around it, by your organization or by whoever competes with it. Directors who cannot engage with those allocation questions cannot discharge the duty to oversee strategy.
Failure now has precedent shape. Boards have watched a generation of technology-driven governance failures: data breaches, algorithmic missteps, model-driven decisions that harmed customers and reputations. Nobody at a board table in 2026 can credibly claim AI risk was unforeseeable. Foreseeability is what converts a surprise into a finding.
What oversight actually means here
Oversight does not mean directors becoming technologists, any more than audit committee service means becoming an accountant. It means the board can honestly answer three questions, and has structures that keep the answers current.
Where does AI touch us today? An inventory: where AI is used in operations and products, where employees use it informally, where vendors and counterparties embed it in what they sell you. Most boards that ask this question for the first time are surprised by the informal column, and the surprise is the point.
Who is accountable, and for what? Not "who is enthusiastic." A named owner for AI standards, a clear line for AI-assisted outcomes (the organization is accountable for what it ships, however it was produced), and a reporting rhythm that brings AI exposure to the board on schedule rather than after an incident.
Are we building capability or borrowing opinions? Diligence is ongoing, because the technology moves. A board that heard one briefing in 2024 has not discharged anything. The standard is a leadership-level working understanding, refreshed, of what these systems do, where they fail, and what they change about the organization's position.
A board does not need to understand AI the way an engineer does. It needs to understand it the way it understands debt: well enough to govern how much, where, and on what terms.
Questions that separate serious boards from decorated ones
Directors who want to test their own oversight can ask these at the next meeting, and notice how the room responds:
- What AI is in use in this organization right now, including informally, and how do we know?
- Which of our material decisions are already AI-assisted, and who is accountable for those outcomes?
- What are our standards for what AI must never be used for here, and who set them?
- What would an AI-driven incident in our industry look like, and would we currently find out about ours before it found us?
- Where is AI moving the economics of our sector, and what position have we taken?
None of these are technical questions. All of them are governance questions. A management team that cannot answer them crisply has told the board something important, and a board that has never asked has told itself something worse.
For the executive in the room: arrive with a position
If you sit on the management side of that table, the shift in the board's posture is not a threat. It is one of the clearest openings this moment offers. Directors are going to get their AI clarity from someone: a consultant's deck, a peer's anecdote, or you.
The executive who arrives with a defensible position, an inventory, named accountability, standards, and a claimed direction, does not just survive the fiduciary turn. They become the person the board relies on for it, and that reliance compounds into authority far beyond the AI agenda. What that position needs to contain is its own subject, covered in the briefing your board expects you to have had.
Building one from scratch is the harder path, and it is buildable: the AI Stakeholder Challenge exists to take a leader from secondhand opinions to an owned position, with the governance dimension treated as what it is, the capstone. However you build it, build it before the next agenda comes around. The fiduciary question is no longer whether AI belongs on it. It is whether you were ready when it arrived.
Michael Steve
Founder of the AI Stakeholder Challenge. Helping leaders move from AI awareness to AI leadership.