What board-level AI oversight actually requires.
When an AI system causes harm, "we had a policy" is not an answer if no one owned the decision to deploy it, no one tested whether the oversight worked, and no evidence exists either way. Accountability for AI does not sit with the technology — it sits with whoever approved its use, and that cannot be delegated away by delegating the system.
What good oversight looks like.
Not a maturity model — four concrete things a board can ask for and expect a direct answer on.
- A named owner for every AI system in use — not a committee in the abstract, a person who answers for it.
- A policy that says what is and is not acceptable, approved at the top, not drafted and left unsigned.
- Evidence that oversight actually happened — a decision record, not a retrospective claim that it must have.
- A tested escalation route — someone who knows what to do when an AI system does something it should not.
The failure mode is quiet, not dramatic.
Most AI governance failures don't look like a single bad decision — they look like a policy that was never actually approved, an oversight mechanism that exists but nobody tests, or an owner named in a slide deck but not in practice. Each is a named risk in this library, not a hypothetical.
Two questions worth asking directly.
Is there a person who owns this AI system's risk, by name, today? And if its oversight mechanism were tested tomorrow, would it actually catch a problem — or only look like it would?
Next: is there a policy at all.
The first, most basic accountability question — and one of the highest-severity risks in the library.