Skip to content
Governance

The board cannot delegate what it does not understand

Accountability for AI reaches the board of directors: what the UK and European frameworks expect, and why oversight cannot be outsourced.

Antropic · 2026 · 6 min read

AI governance has become a responsibility of the board of directors. Not of the technical department, not of a vendor, not of an ad hoc committee created to sign documents. The thesis of this article is simple: a board may delegate execution, but it cannot delegate understanding. And today the distance between what boards sign and what boards understand is the first unmanaged risk in British organisations.

Accountability is already in force

A UK board answers to two frameworks at once, and neither waits. At home, there is no horizontal AI statute: the government’s white paper set out a pro-innovation approach built on five cross-sectoral principles, applied by existing regulators rather than a dedicated one (GOV.UK, 2023; House of Commons Library). The absence of a single statute does not dilute the duty — it distributes it. The FRC’s guidance on the 2024 Corporate Governance Code asks boards to monitor all material controls and to consider emerging technologies, AI included (FRC, 2024).

Across the Channel, the EU AI Act reaches further than many boards assume: it applies to providers and deployers located in third countries where the system’s output is used in the Union — UK organisations serving the European market fall within its reach (EU AI Act, Article 2). Prohibitions and AI literacy duties have applied since 2025. Article 50 transparency obligations apply from August 2026. The simplification package approved by the Council of the European Union in June 2026 postponed the Annex III high-risk obligations to December 2027, leaving the rest of the structure intact (Council of the EU, 2026).

The point for the board is not to memorise deadlines. It is to grasp that responsibility is assigned by role: provider and deployer — those who develop and those who use — carry distinct obligations, and most companies are deployers without knowing it. Every system adopted, even under licence, activates oversight duties that sit with the organisation. And the organisation’s responsibility, under any serious reading of governance, rises to the top.

The gap between use and governance

The data show a gap that should trouble any chair. According to the Institute of Directors’ business paper on AI in the boardroom, two thirds of directors use AI tools personally and around half of organisations deploy them, yet a quarter have no AI policy or governance structure at all (IoD, 2025). Adoption sprints; governance strolls.

The same picture emerges from McKinsey’s global State of AI survey (2025): only 28% of organisations using AI place governance oversight with the CEO, yet that choice is among the factors most correlated with positive economic impact (McKinsey, 2025). Translated: where the top presides, AI produces value; where the top signs blank cheques, it produces experiments.

The right question in the boardroom is not “are we using AI?”. It is “who answers for the decisions AI is already influencing?”.

Three questions a board must know how to ask

Where does AI enter our decisions? Not the inventory of systems: the map of decisions. Pricing, credit, hiring, appraisals, investment priorities. If a model contributes to a decision, that decision has a new link in its chain of accountability. The boundary to be guarded is the subject of our analysis of algorithmic delegation.

Who answers, by name? AI governance fails when it belongs to everyone, which is to say no one. It needs a function with an explicit mandate: roles, escalation thresholds, review criteria. Generic frameworks downloaded from the internet do not survive the first serious examination — by a regulator, an enterprise client or a court.

What do we actually know, as a board? The literacy duty in Article 4 of the EU regulation covers those who govern, not only those who operate — and the IoD reaches the same conclusion for UK directors without any statute. A board that approves an AI strategy it cannot interrogate is signing a blank cheque. The subject deserves its own treatment, which we give it in AI literacy as a boardroom duty.

The context makes delay more expensive

Some object that the matter is premature. The data say otherwise. According to the Office for National Statistics, a quarter of UK businesses reported using some form of AI technology in late December 2025 — up 15 percentage points since the question was first asked in September 2023. Among businesses with 250 or more employees, the figure is 44% (ONS, 2026).

Adoption on that trajectory means the perimeter to be governed grows faster than any planning cycle. A board that defers the question to the next strategic review is accepting, in effect, that for a full year the organisation adopts systems without oversight. For those who sit on the boards of larger companies, where adoption is approaching half the population, the subject is not prospective in any sense of the word.

Nor is delay competitively neutral. Organisations that build governance after adoption pay twice: once to repair choices made without criteria, and again for the time lost against rivals who could scale quickly precisely because their rules were clear. Well-made governance does not slow adoption: it makes adoption defensible, and therefore repeatable.

The instruments of oversight

How is supervision organised in practice? Structures vary with size, but four elements recur in organisations that work.

A home. The AI question needs a place in the board calendar: within the audit committee, within the risk committee, or — in the most exposed businesses — a dedicated committee with at least one competent member. What has no home has no cadence; what has no cadence lives on emergencies.

A designed information flow. The board cannot oversee what reaches it filtered through project enthusiasm. It needs periodic reporting whose structure is set by the board, not by management: systems in use and the decisions they touch, incidents and near misses, deviations from policy, vendor assessments. Few indicators, but chosen by those who supervise.

A dialogue with those who know. Internal competence should be complemented, not replaced, by qualified external voices — with one caveat that leads to the next point: the provenance of those voices determines the quality of the oversight.

A written record. Deliberations on AI should be minuted with the same care as financial ones: what information the board received, what questions it asked, on what basis it decided. This is not formality — it is the difference, the day something goes wrong, between a board that exercised oversight and a board that merely put it on the agenda. Documenting diligence is itself diligence.

Independence as a structural requirement

There is an obstacle boards underestimate: almost everything they know about AI reaches them from those who sell AI. Technology vendors, integrators, consultancies with commercial partnerships to protect. This is not bad faith: it is a structural conflict of interest. Those who profit from adoption tend to recommend adoption.

That is why the oversight function needs at least one voice with nothing to sell. The role of an independent adviser is not to slow adoption: it is to ensure that every “yes” and every “no” from the board rests on analysis no commercial incentive has bent. It is the principle on which our institute’s method is built, and the perimeter of the AI Governance work we do with boards of directors.

What this means for the board

Accountability for AI is not coming: it has arrived. Anyone who sits on a board should leave the next meeting with three commitments made.

First: a map of the business decisions AI already enters, with a named owner for each. Second: a literacy plan for the board itself, with verification, not certificates of attendance. Third: a source of analysis independent of vendors, reporting to the board and not to procurement.

The two frameworks — Britain’s principles and Europe’s regulation — have made explicit what sound governance already implied: direction cannot be automated. It is exercised — with more instruments, more data and more accountability than before.

Research becomes decision in the advisory work.

Executive Advisory