Board Expectations on AI Are Rising: What General Counsel Should Do Next

Board Expectations On AI Are Rising
Board Expectations On AI Are Rising

Boards are no longer treating AI as a technology issue. AI, AI agents and automation are now central to discussions about competitive advantage, productivity, cyber risk, customer impact, workforce change and regulatory exposure.

Across many organisations, there is pressure to do more with AI, faster. Boards want to understand how the organisation is responding. Management teams are being asked to identify opportunities, test use cases and show progress. At the same time, many organisations are still building a practical understanding of how AI tools work, where they are already being used, and what risks they create.

For General Counsel, that shift changes the legal team’s role.

The task is not to slow the organisation down. It is to support management teams to move with momentum while ensuring that AI adoption can be explained, governed and defended. Directors want to know where AI is being used, what value it is expected to create, what risks are being accepted, and who is accountable when systems behave unexpectedly.

Recent Australian guidance reinforces the point. The AICD and Human Technology Institute’s updated AI governance resources note that AI tools and systems have become embedded within many Australian organisations, and that the board plays a key role in governing the balance between opportunity and risk. General Counsel are well placed to help turn that expectation into practical oversight.

Why Board Oversight is Becoming More Demanding

AI governance is difficult because it cuts across familiar control areas. A single AI use case can involve privacy, data quality, cybersecurity, procurement, intellectual property, employment, consumer risk, confidentiality and recordkeeping.

AI agents add another layer. Unlike tools that generate content or summarise information, AI agents may act across systems, retrieve data, trigger workflows, make recommendations or initiate steps in a business process. That creates different questions about authority, human oversight, logging, accountability and intervention.

This does not mean every AI use case requires board approval. It does mean the board needs a clear view of the organisation’s risk appetite, the permitted categories of AI use, and the controls that apply as use cases become more consequential.

The Australian Government’s Guidance for AI Adoption is useful here. It sets out six essential practices covering:

  • Accountable ownership
  • Risk management
  • Data governance
  • Testing
  • Human oversight
  • Transparency

These are not abstract governance concepts. They need to show up in how AI use cases are assessed, approved, monitored and reported.

APRA’s open letter to industry on AI also warns boards operating across banking, insurance and superannuation that governance, risk management, assurance and operational resilience practices are not keeping pace with AI adoption. The message to boards is clear: organisations can pursue AI aggressively, but they need to be equally serious about governing and overseeing the risks.

The General Counsel’s Role is to Find ‘Happy Pathways’

The most useful contribution legal can make is a pathway that makes safe AI adoption easier to follow than informal experimentation. This means making it easy for the business and individuals to comply.

That starts with a clear classification of AI use cases. Low-risk internal productivity tools should not be managed in the same way as AI that affects customers, regulated decisions, privileged information or high-impact business processes. The legal team can help define the categories, the approval level for each one, and the minimum evidence required before a use case moves forward.

A practical framework should help the organisation answer five questions.

  1. Risk appetite: What AI risks are we prepared to accept, and where are the red lines?
  2. Approved use cases: Where can AI be used, and under what conditions?
  3. Accountability: Who owns each AI use case, control and decision?
  4. Escalation: What must be escalated to legal, risk, management or the board?
  5. Reporting: What evidence does the board receive to monitor AI adoption and risk?

Risk appetite should be practical enough to guide decisions. For example, internal productivity use may be permitted through approved tools and training. Customer-facing use may require stronger review. Use involving privileged, confidential, personal or regulated data may need tighter controls. Fully automated decisions affecting customers, employees or legal rights may require senior approval, and may sit outside risk appetite altogether.

Escalation also needs to be clear. Use cases should be escalated where they involve sensitive data, regulated decisions, customer or employee impact, third-party AI tools outside approved procurement pathways, or AI agents connected to core business systems. Material errors, hallucinations, bias, cyber incidents or near misses should also be visible through defined escalation routes.

A practical AI governance framework might include:

  • Approved AI use cases and prohibited uses
  • Risk appetite settings for different business functions
  • Review requirements for data, privacy, confidentiality and third-party terms
  • Human review checkpoints for high-impact outputs
  • Escalation routes for exceptions, incidents or unclear use cases
  • Recordkeeping standards so decisions can be reconstructed later.

This is where legal operations become central. Policies alone do not create control. The organisation needs processes, records, audit trails and reporting that show how AI decisions are being made.

What the Board Should be Able to See

Board reporting on AI should avoid two extremes. It should not become a technical inventory that directors cannot use, nor should it be reduced to broad assurances that everything is under control.

The better approach is a concise governance view that answers practical questions:

  • Where is AI being used, by whom and for what purpose?
  • Which use cases are approved, under review, rejected or outside policy?
  • What are the highest-risk use cases and what controls apply?
  • Who owns each use case and who can stop or change it?
  • What incidents, exceptions or near misses have occurred?
  • What training, monitoring and assurance activity is in place?

A useful board report might include:

  • An AI use case register showing approved, under review, rejected and retired use cases
  • A risk profile of high, medium and low-risk use cases
  • Control status across privacy, data, cyber, human oversight and vendor review
  • Exceptions, incidents, near misses and unresolved issues
  • Expected benefits, future benefits and lessons learned
  • Upcoming decisions requiring executive or board attention.

General Counsel does not need to own every answer. However, they do need to help ensure the answers are available, consistent and supported by evidence. That requires coordination with risk, compliance, IT, data governance, procurement, business leaders and the company secretary.

What this Means for the General Counsel

AI governance is becoming a test of legal leadership. Boards want progress, but they also expect accountability, visibility and credible oversight. A General Counsel who can help the organisation create happy pathways for AI adoption will be better placed to support innovation while reducing avoidable risk.

The next step is not to have more policies but to build the operationalise governance including approved pathways, clear escalation, evidence of review and board reporting that reflects real organisational use.

The GCs who will be most valuable to their boards are the ones who can help the organisation move quickly, with enough discipline that decisions can be explained, challenged and defended.

Share

Share