Boards are approving AI investments they cannot yet fully govern. Most directors understand that AI is strategically significant. Far fewer sit on boards equipped with the structure to oversee it.
The figures measure different things: broad AI adoption across organizations, and AI risk oversight disclosure among the largest U.S. public companies. The direction is still clear.
Taken together, McKinsey's 2025 State of AI survey and EY's review of Fortune 100 proxy filings point to the same issue: this is not a gap in awareness. Most boards know AI matters. What is missing is the architecture behind that awareness: a defined AI posture, a formal policy with real escalation triggers, and reporting that gives directors something they can act on.
Having principles on paper is not the same as having governance.
01Start with posture
McKinsey frames this as an organization's AI posture: is AI primarily a productivity tool, a transformation lever, or a core part of the business model? I find it useful because the answer determines how much board attention the topic warrants, what kind of reporting directors should expect, and where escalation should sit.
Not every board needs the same oversight model. A company using AI to optimize internal operations has different governance requirements than one building AI into its core product strategy. What matters is that the board and management have aligned on which posture applies, and calibrated board engagement accordingly.
02Build the escalation layer
Once posture is settled, the rest of the architecture follows. A policy should name real escalation triggers, not aspirations.
A real escalation trigger is not “use AI responsibly.” It is a rule that certain uses cannot go live without documented approval: AI involving personal information, client data, restricted data, automated decision support, external publication, or integrations into production systems.
Reporting should also be designed for decisions, not reassurance. Not “we are exploring AI,” but which functions are using AI in production, what decisions those systems touch, what could go wrong, what controls sit underneath, and what choices require board or committee input.
That is the difference between knowing AI is on the agenda and being able to govern it.
The organizations that get this right will be the ones where boards stop treating AI as a management execution issue and start treating it as a governance responsibility.