If AI makes the decision, who owns the consequence?

Twenty-two rows. That was the AI inventory in a board pack I read last year, and it was a good one. Every system named, every owner listed, every risk rating filled in and colour-coded. Somebody had worked hard on it, and the committee approved it in four minutes.

I kept looking for a column that wasn’t there. The pack could tell you who owned each system. It could not tell you who was allowed to say no to one.

Those sound like the same thing right up until the morning they aren’t.

1. Signal. AI has moved inside the operating model

When a director asked me last spring what our AI risk was, I gave her the honest answer. Which was that I no longer knew, because the question had changed shape while everybody was still busy answering the old one.

Twelve months earlier I could have told her precisely. We had a model inventory, a review process and a register entry saying the right things about bias and data quality. All of it was true, and all of it had quietly stopped being the point, because the systems had moved inside the work. They chose which cases went to which queue, which prices moved and which alerts a human ever saw.

Foundry’s State of the CIO 2026 report puts the shift plainly. Roughly three-quarters of leaders say AI is already reshaping how their operations run, and the number climbs higher in financial services. Around seven in 10 expect deeper involvement in agentic systems this year.

Don’t let those figures become the story. Adoption numbers are the easiest thing to produce and the least useful thing to govern from. Your board can watch that percentage climb for three years and learn nothing it can act on. The signal underneath is simpler. AI has stopped helping people finish tasks and started shaping how work gets allocated, how rules get applied and what the company does next.

Which means your board needs a better question than how much AI do we have. It needs to know which decisions have changed hands.

2. Consequence. Authority travels faster than accountability

Accountability used to be visible. Person, role, authority, decision. You could follow it with a finger, and when something went wrong you could find the finger.

That chain now reads: human, model, agent, system, supplier, outcome. Every link has an owner and a budget line. The decision itself often has neither.

Watch it happen. A team buys a tool to help underwriters. It starts recommending, and it’s good, so people gradually stop disagreeing. Six months later somebody switches on auto-approval below a threshold, because the review queue is a bottleneck and the numbers support it. Nothing in that story needed a bad actor. Authority moved three times, and nobody recorded any of it.

That’s board risk, not model risk. Call it authority drift. Real decision-making power moves outward while formal accountability sits exactly where somebody wrote it down in 2023.

The same study found most organisations have or plan an AI steering group, with IT sitting on the great majority of them. Only about half report a formal approval process. Structures arrive fast, because they’re easy to announce and cost nothing but a recurring meeting. Decision rights arrive slowly, because somebody has to accept them.

I once watched a company stand up three AI committees inside a year and still be unable to name one person who could stop a model.

3. Decision. Who gave the machine permission?

Your board can’t govern every AI action and shouldn’t try. Trying to do so creates a register nobody reads and a comfortable sense that the ground is covered. Insist instead that management names the material decisions.

Material means it moves customers, capital, employees, regulatory standing or resilience. The tool that writes meeting notes doesn’t qualify, no matter what the vendor promised. A system shaping credit, pricing, workforce reductions, claims handling or cyber response does. Most firms land on 15 or 20. If management returns with two, they haven’t looked. If they return with three hundred, they’ve listed systems rather than decisions.

Then, for each one, four verbs.

  • Recommend. The system proposes, and a person chooses.
  • Decide. The system chooses, inside limits somebody set in advance.
  • Execute. The system chooses and acts, with no human in the transaction.
  • Accept. Somebody carries the consequence when it goes wrong.

That last verb is where rooms go quiet, and it’s the only one that can’t be handed to a machine.

Put them together, and you’ve drawn the authority envelope. What may this system recommend, decide and execute? Where does a person pick the thread back up? Whose name sits on the outcome? It’s a dull artefact, half a page per decision, and it’s what your board should ask to see instead of the AI policy, which everyone has, and nobody reads.

4. Evidence. Show me where the authority stops

An envelope on paper is a claim. Then you ask what proves it.

Start with the system itself. If AI may approve up to fifty thousand, is fifty thousand built into the workflow or typed into a policy? Only one of those holds at three in the morning, when the queue is long, and somebody is under pressure.

Ask which exceptions have been granted. Who approved each, who accepted the risk left behind and when it expires. An exception without an expiry date quietly becomes the operating model, and eighteen months later somebody calls it legacy and asks for budget to remove it. Read the 10 oldest entries in that register, and you’ll learn more than the policy will ever tell you.

Ask how many important decisions ride on the same model, the same cloud, the same supplier. Firms with 20 AI applications regularly discover they have two real dependencies, because separate teams bought separate products built on the same substrate. Procurement records won’t show it. The architecture diagrams and the person who pays the bills will.

Ask whether the business can still decide if the service vanishes. Not whether IT can restore it, which is a different and easier question. Who does that work by hand, how long can you last without it and has anybody currently employed ever done it?

Ask what returns authority to a person: confidence dropping below tolerance, customer harm, a breach of appetite. Then look for one more that most firms lack, because their triggers came from incident management, where failures announce themselves. A drifting model doesn’t crash. It carries on answering plausibly, wrong by small margins, at volume, logging cleanly.

Finally, ask how long it takes to reconstruct one decision from end to end. An afternoon is evidence. A fortnight is archaeology.

5. Challenge. Follow the decision, not the inventory

Five questions. Directors don’t need to become engineers to ask them, and management can’t deflect them with architecture diagrams.

Which material decisions now depend on AI? A vague answer means nobody has drawn the list, which is itself the finding.

Who owns the authority for each one? Not the model owner, not the committee chair. If the answer names a team, you’ve been told who keeps the system running, not who let it decide.

How far has that authority travelled: recommend, decide or execute? Firms are usually one step further along than their paperwork claims.

What brings it back to a person? If the answer is human oversight, ask what forces the human to look while everything still appears fine.

What evidence shows the system stayed inside its limits, and how quickly can you produce it?

Answer all five for the top 10 decisions, and you’re in decent shape. Answer four and go quiet on the fifth, and you’ve found where the work is. The quiet is the useful part.

6. Horizon. Today’s approval expires quietly

The risk worth watching is expansion without reauthorisation, not a dramatic failure.

A provider swaps the underlying model in a routine release. An agent picks up new permissions because somebody connected it to another system. The business points the same tool at a bigger question, since it worked on the small one. More sensitive data joins the workflow. Reliance grows, so the review that was thorough in month one becomes a glance by month nine.

Nothing breaks. Nothing gets announced. The approval granted a year and a half ago now covers something it was never asked about.

Agentic systems will sharpen all of this, because their entire value lies in doing more without being asked each time. That’s their point, and it is also the governance problem stated in one sentence.

So the question I’d put on the agenda isn’t whether you’re monitoring continuously. It’s this. What change would make today’s approval no longer good enough? Write that answer down while everyone is calm, and you have a trigger instead of a hope.

Risk doesn’t only rise when the model changes. It rises when you quietly ask the same model to decide something that matters more.

7. Action. Map the decisions before they map themselves

One deliverable, not a framework. Most firms already have a framework, and it hasn’t helped.

Ask management for a map of the top 10–20 material AI-supported decisions. One row each. The business owner. What the AI actually does, in the four verbs. The authority limit, as a number. Who approved any exception and when it expires. The main dependency. The fallback, and who performs it. What forces escalation. Where the evidence lives.

Nine columns, two pages. It will take longer to produce than anybody expects. That delay tells you something before you read a word, because a company that fills it in a fortnight is already governing this and one that needs a quarter is still discovering it.

What comes back will show you orphaned decisions, ambiguous authority, stale approvals, exceptions nobody closed, concentration hiding behind a healthy supplier count, and a fallback that exists only on paper.

Boards don’t need to own AI. They do need to know who owns the decisions AI is now allowed to make.

AI can inherit authority. It cannot inherit accountability.