Home  /  Advisory  /  Board oversight of AI

Board oversight · AI

Board oversight of AI.

A board does not need a view on whether AI will end the human race. It needs to be able to show, in writing, that the company is in control of the AI it has already deployed. That is a different task, it is answerable, and for a UK listed company it is now closer to a reporting obligation than it was. This page is written for the UK regime first, and says where that regime ends and someone else’s begins.

Rahim Hirji advises chief executives, boards and leadership teams, in person worldwide and online. He is an independent advisor on AI and human judgement, the author of SuperSkills (Kogan Page, 2026), and has run, grown, bought and advised businesses with AI in them. He also speaks, to senior rooms rather than conferences. He founded the skills platform EtonX, later acquired by Eton College, and led Quizlet’s international growth across more than 60 countries.

What changed in January 2026

Provision 29 of the UK Corporate Governance Code 2024 applies to accounting periods beginning on or after 1 January 2026. It asks the board to monitor the risk management and internal control framework, to review its effectiveness at least annually across “all material controls, including financial, operational, reporting and compliance controls”, and to give in the annual report a declaration of effectiveness of those material controls as at the balance sheet date, together with a description of any that have not operated effectively and the action taken or proposed.

Three things about that are routinely misstated, and a chair should know them before anybody sells him a remedy. It is a declaration about effectiveness rather than a warranty that everything worked, and the Code contemplates a negative or qualified one. There is no external assurance or auditor attestation requirement attached to it. And the FRC declines to say what a material control is: “It is not the FRC’s role or intention to prescribe or dictate what a material control is for a company.”

For a 31 December year end, the first declaration under Provision 29 appears in the annual report published in 2027. The work that produces it happens now.

Rahim Hirji speaking from a lectern to a seated audience in a wood-panelled hall
Mid-keynote, to a seated room

Which boards this actually applies to, and what the rest should read instead

Provision 29 reaches companies listed in the commercial companies category or the closed-ended investment funds category, whether incorporated in the UK or elsewhere. The old premium and standard segments went in July 2024, so a briefing that still says “premium listed” was written before the Listing Rules changed and may be stale in other ways too.

If your board is not in scope, the obligation is different and the questions are the same. A private company board, a family business board, a partnership board, a charity board, an academy trust board, a housing association board and an NHS board all answer to a different instrument and none of them answers to a rule that names AI. Several use the Code as a reference point voluntarily, and the Wates Principles apply to large private companies. The five decisions below do not depend on which instrument you sit under.

If you operate in the EU, or your systems’ output is used there, a second regime applies on its own timetable. The EU AI Act’s transparency obligations under Article 50 apply from 2 August 2026. The high-risk obligations moved in 2026 and now apply from 2 December 2027 for stand-alone high-risk systems and 2 August 2028 for those embedded in regulated products. A great deal of board material still quotes the old August 2026 date for high-risk, so check the date on anything you are handed. The AI literacy obligation in Article 4 has been in force since 2 February 2025 and is the one most UK boards have not noticed.

The two regimes ask different questions. The UK one asks whether your controls worked. The EU one asks whether the system is permitted, transparent and overseen. A board with both needs one answer that satisfies each rather than two programmes.

The Code says nothing about AI, and neither does the regulator

This is the part most board briefings skate over. The UK Corporate Governance Code does not mention artificial intelligence anywhere. The FRC has published guidance on AI in audit, for auditors, and research on AI in corporate reporting, and it has published no AI guidance for boards. The FCA has said it does not plan to introduce extra regulations for AI and will rely on existing frameworks. There is no UK AI statute.

So a board looking for the rule that tells it what to do about AI will not find one. What it has instead is a general obligation that now bites: if a material control has AI inside it, the declaration covers it. The question moves from what the regulator requires to what the board can evidence, which is a harder question and a more useful one.

Five decisions a board can answer

These hold whether the technology moves fast or slowly, and none of them requires a view on the frontier.

One. Which decisions machines may make in the company’s name. The outcomes a system may determine without a person deciding: a credit limit, a refund, a hiring shortlist, a public reply. A board that cannot produce that list has let the systems decide it. How AI decision rights should be allocated.

Two. Who can stop each system, and whether they would. Being able to stop a system is a technical fact. Being willing to stop it mid-quarter with revenue attached is a leadership fact, and it should be rehearsed before it is needed. Designing a stop button people will use, and what an AI kill switch is.

Three. What people must remain able to do unaided. Skill the organisation would need if the system stopped, lost without anyone deciding to lose it. Capability debt.

Four. How the board would find out if something went wrong. That requires an incident definition written before there is an incident. What counts as a serious AI incident.

Five. What management’s assurances rest on. An assurance that oversight exists is a claim. A sampling regime, a reviewer disagreement rate, a log of overrides or a rehearsed stop is evidence. How a board knows management’s claims are true.

Human in the loop is not a control

The phrase appears in almost every AI policy written in the last two years, and a board should treat it as a claim to be tested rather than a control to be recorded. A person who approves what a machine proposes, at the speed the machine proposes it, without the time or the standing to disagree, is a signature rather than an oversight mechanism.

Three pages set out what to ask instead: why human in the loop is not a safeguard, whether a human can approve a decision at machine speed, and what meaningful human oversight means.

Where the oversight sits, and who does it

The structural questions have answers worth arguing about rather than obvious ones. Whether AI oversight belongs with the full board or a committee, and which committee, is covered at should AI oversight sit with the full board or a committee. Whether the answer is to recruit a director with AI expertise, which is the reflex and often the wrong move, is at should we appoint a director with AI expertise.

What directors themselves need to be able to do is a separate question from what the company needs to be able to do: what AI literacy means for leaders. And the question nobody asks until it is awkward, whether directors should be putting board papers into an assistant, is at should directors put board papers into AI.

What this is not

It is not compliance work and it does not produce a framework. There are good firms who will build you an AI governance framework, certify a management system against ISO/IEC 42001, or map your obligations under the EU AI Act, and if that is what you need you should use one of them.

This is the half a board cannot outsource: deciding what the machines may decide, who can stop them, and what the organisation must remain able to do. I sell no software, take no vendor’s money and build nothing, so nothing in the view depends on what you decide. Governance files the assurance; leadership asks what it rests on.

Formats and logistics
The room
A board meeting, a board away day, or a session with the audit or risk committee
The output
Written: the decision list, the stop list, the incident definition, and what the board should be shown each meeting
Before the day
A fact-find with the company secretary or the chair, and a read of what management has already produced
Not this
Framework build, ISO 42001 certification, EU AI Act mapping, vendor selection, model risk
Delivery
In person and online, worldwide, in English
Enquiries
A reply within 24 hours
What the first conversation usually sounds like, in composite“We have to declare whether our material controls operated effectively. Some of them have AI in them now. Nobody in this room can tell me who would stop one, or how we would know it had gone wrong.”
Before you book

Questions chairs and company secretaries ask.

Does the UK Corporate Governance Code say anything about AI?

No. The Code does not mention artificial intelligence anywhere. What it does, from accounting periods beginning on or after 1 January 2026, is ask the board to declare the effectiveness of its material controls and to describe any that did not operate effectively. If a material control has AI inside it, the declaration covers it. The obligation is general rather than AI-specific, so a board waiting for a rule that names the technology will wait a long time.

Has the FRC issued AI guidance for boards?

No, and this is worth checking before anyone tells you otherwise. The FRC has published guidance on the use of AI in audit, which is written for auditors, and research on AI in corporate reporting. It has published no AI guidance for boards. The FCA has said it does not plan to introduce extra regulations for AI and will rely on existing frameworks, and there is no UK AI statute.

Does Provision 29 mean we have to certify that our controls worked?

No. It asks for a declaration of effectiveness of the material controls as at the balance sheet date, together with a description of any material controls that have not operated effectively and the action taken or proposed. A qualified or negative declaration is contemplated by the Code. No external assurance or auditor attestation is required, and the FRC declines to define what a material control is.

Should AI oversight sit with the audit committee or the risk committee?

It depends on where the company already puts things that cross every function, and the wrong answer is the one nobody chose. The argument is set out at should AI oversight sit with the full board or a committee.

Do we need to appoint a director with AI expertise?

Usually not, though it is the most common reflex. A single expert director can reduce the rest of the board's engagement rather than raise it, which is the opposite of oversight. The case both ways is at should we appoint a director with AI expertise.

Do we need ISO/IEC 42001?

It is a voluntary management system standard, there is no UK legal obligation to hold it, and it does not discharge Provision 29 or data protection law. Its practical use to a board is that it produces documented, auditable evidence of AI controls, which is the sort of evidence a material controls review needs. It is a reasonable question to ask management, not an answer in itself.

Does the EU AI Act apply to us?

It can apply to a UK company that places AI systems on the EU market or whose system output is used in the EU. The timeline moved in 2026: the transparency obligations in Article 50 apply from 2 August 2026, while the high-risk obligations were deferred, to 2 December 2027 for stand-alone high-risk systems and 2 August 2028 for those embedded in regulated products. A great deal of board material still quotes the old dates, so it is worth checking the date on anything you are handed.

Do you build the framework?

No. Framework build, certification, obligation mapping, vendor selection and model risk are done better by firms that specialise in them, and I will say so and name the type of firm you want. The work here is the half a board cannot delegate: what the machines may decide, who can stop them, and what the organisation must remain able to do.

Board oversight

Tell me what your board has to be able to show.

A reply within 24 hours, and a conversation before anything is proposed.

Enquire or email rahim@thesuperskills.com

The written second opinion on a strategy you have already built is at a second opinion on your AI strategy. The standing board relationship is at board advisory. The wider advisory offer is at AI adviser to CEOs and boards, and the research this page draws on is indexed at the research. The parent page for all of this is AI keynote speaker. Browse every topic, audience and region, or take the speaker pack to whoever is running the day. Every engagement delivered so far, with the dates checkable at each organiser, is at the speaking record.

I have sat on the other side of this. A board member of EtonX, the company I founded, and of TeacherMatic. A non-executive director at Whitefox. A school governor, and a member of the Aga Khan Education Board for the UK. I know what the paper looks like the night before, and I know the difference between a board that has considered something and a board that has received a presentation about it.

Box of Amazing

Rahim’s free weekly letter on AI and human capability

If this was useful and you want a small amount of it each week, that is what the letter is for. Weekly essays on AI, capability and the future of work. Read by 25,000 people, every week since 2017. Free, and one click to stop.

Opens Substack to confirm. No pitch in it, unsubscribe in one click, and nobody follows up because you read something.

Running an event, or responsible for how AI arrives in your organisation? Keynotes  ·  Advisory for CEOs and boards  ·  Enquire