← Research
Research

Should AI oversight sit with the full board or a committee?

The machinery can go to a committee. The allocation cannot, because it is the board deciding what the company is. How to split the two, and the one item that must never leave the full agenda.

Last reviewed: 15 September 2026

AI governance, meaning the register, the risk tiers, the audit trail and the incident process, can sit with an audit or risk committee. AI leadership, meaning which decisions the machines may make and what the organisation must stay capable of, is the board deciding what the company is and cannot be delegated. How to split them, and the item that stays on the full agenda. An evidence review by Rahim Hirji; every figure resolves to a graded entry in the evidence base that says what it does not show.

Question this page answersAll 811 questions this research covers

The answer is to split the question, because AI oversight is two different jobs and only one of them can be delegated. The governance machinery, meaning the register of live systems, the risk tiers, the audit trail, the incident process and the regulatory reporting, is the kind of work an audit or risk committee exists to do, and it should go there. The allocation, meaning which consequential decisions the machines may inform, recommend or execute, who owns each, and what the organisation must remain capable of doing unaided, is the board deciding what kind of company this is. That is not committee work. Deloitte's 2025 survey found 31 per cent of boards with AI not on the agenda at all and 66 per cent describing themselves as having limited to no knowledge; the temptation, in that state, is to create a committee and send the subject there. That is the one thing not to do.

The answer, in one line

Split it. The governance machinery, the system register, risk tiers, audit trail, incident process and regulatory reporting, fits an audit or risk committee, which already does that kind of work.

Share as a card

What goes to the committee#

Everything that checks decisions after they are made. The register of live AI systems with a purpose, an owner and a review date. The risk tiers, and the evidence that higher tiers get more human review. The audit trail for consequential decisions, and whether it would let somebody reconstruct one. The incident definition, the playbook, and whether the drill was run. Regulatory reporting under the EU AI Act where it applies. And the assurance question: whether anybody who does not report to the programme has read the documents this year. An audit committee does this for financial controls already and the shape is identical. The distinction between the machinery and the decisions is set out at AI governance versus AI leadership.

What stays with the full board#

Two items, and they are short. Once a year, the allocation: the board reads the list of decisions the organisation has marked as ones a machine may inform, recommend or execute, and the ones it may never own, and confirms that the list still describes the company it wants to be. That is a strategy conversation, not a control conversation, and it belongs to the whole board because the answer shapes what the company does to its customers and its people. Every quarter, the disagreement rate for consequential systems: how often the humans reviewing machine output reached a different answer. A committee can collect it. The full board should see it, because a rate that has fallen to zero means the company is being run by systems nobody is checking, and that is not a control failure, it is a change in what the company is.

Why not a dedicated AI committee#

Because it becomes the place AI is sent so that the board need not think about it. The pattern this site documents at executive level, judgement delegated to whoever understands the tool, reproduces at board level the moment there is a room for it. A standing AI committee also tends to fill with the directors who are most comfortable with the technology, which selects for enthusiasm at exactly the point where the board needs challenge. The exceptions are the companies whose product is the AI, where a technology committee may already exist and the AI work belongs in it, and the regulated sectors where a supervisor expects a named committee. For most boards, extending the audit or risk committee's remit for the machinery and keeping the two short items whole-board does the job without building a new room to lose the subject in.

What the committee chair asks, and what the chair of the board asks#

The committee chair asks whether the register is complete, whether the tiers are applied, whether the log would survive a regulator, and whether the drill was run. The chair of the board asks one question a year of the chief executive: which decisions have we handed to machines since we last looked, and did we mean to? If the answer is a list, the board is doing its job. If the answer is a description of the governance framework, the machinery is being offered in place of the decisions, and the board should say so. The questions in full are at what should a board ask about AI.

What nobody has measured#

No study compares board structures for AI oversight and their outcomes, and the Deloitte figures are self-description by a panel. The split proposed here follows from the distinction between governance and leadership, which is an argument about what each structure can do by construction, and from the audit committee's existing role, which is the nearest working analogy. Whether boards that split it this way do better is untested.

Key sources

On whether the board needs a specialist to do any of this, should we appoint a director with AI expertise. On what the board is entitled to believe, how does a board know management's claims about AI are true. On what an incident is and which reach the board, what counts as a serious AI incident. On the whole picture, what board oversight of AI looks like.

About this research#

Rahim Hirji is the author of SuperSkills (Kogan Page, 2026), keynote speaker on AI and human capability, and founder of The SuperSkills Intelligence Company. He has run, grown, bought and advised businesses with AI in them. Findings are attributed to the studies and statements that produced them and kept separate from the interpretation. This is a living reference, reviewed and updated as significant new evidence appears.

How this research works  ·  Reviewed quarterly  ·  Found an error? Tell me and it is corrected on the page.

Evidence review · SS-2026-249 · Graded against the published rubric

Cite this page

Hirji, R. (2026). Should AI oversight sit with the full board or a committee?. The SuperSkills evidence base, SS-2026-249. https://thesuperskills.com/research/should-ai-oversight-sit-with-the-full-board-or-a-committee. Last reviewed 15 September 2026.

An evidence review by Rahim Hirji, not peer-reviewed research. For a material claim, cite the underlying study as well; every study here carries its own permanent link.

How citations and IDs work
Questions answered on this page

Should AI oversight sit with the full board or a committee?

Split it. The governance machinery, the system register, risk tiers, audit trail, incident process and regulatory reporting, fits an audit or risk committee, which already does that kind of work. The allocation, meaning which consequential decisions the machines may inform, recommend or execute, who owns each, and what the organisation must stay capable of, is the board deciding what the company is, and stays with the full board.

Should we create an AI committee?

Rarely. A standing AI committee tends to become the place AI is sent so the board need not think about it, which reproduces at board level the delegation this site documents at executive level. Extend the remit of the audit or risk committee for the machinery, and keep the allocation whole-board.

What is the one AI item that stays on the full board agenda?

The allocation and the disagreement rate. Once a year the board reads the list of decisions the machines may make and confirms it still describes the company it wants to be; every quarter it sees how often the humans reviewing those systems disagreed with them.

In this hub

Definitions

The terms this field uses, defined against their primary sources.

Ask the evidence
What does the evidence actually show?What should our board be asking about this?Where does Rahim disagree with the consensus?
Bring this into your organisation

If this describes something happening in your teams, say so.

Keynotes, board sessions and advisory work, drawing on research across more than 200 organisations in 30 countries. Tell me the room, the date and the shift you need. A reply within 24 hours.

Start a conversation

Topics and audiences  ·  All research

Two short items stay with the full board. Reading them with the board once a year is the standing advisory seat described on the board page. Board advisory.

This argument is one a board usually meets for the first time in the room. There is the boards and leadership version, and the full range of topics and audiences.

Box of Amazing

Rahim’s free weekly letter on AI and human capability

If this was useful, the weekly letter is where the thinking happens first. Most of what ends up on this site starts there. Weekly essays on AI, capability and the future of work. Read by 25,000 people, every week since 2017. Free, and one click to stop.

Opens Substack to confirm. No pitch in it, unsubscribe in one click, and nobody follows up because you read something.