Governance and risk

AI governance for boards

Governance is not a policy document. It is the set of decisions that says what AI may do, who approves it, and what happens when it fails. Most boards do not have one yet.

By Zakir Hoosen, Director, Fuzzelogic Solutions. Board-level guidance in plain English.

You do not need to understand how the technology works to govern it. You need to understand what it is allowed to do, who said yes, and what happens when it says the wrong thing. Most boards have a policy. Very few have governance. The difference matters when something goes wrong.

This guide explains what AI governance actually means for a board, what the research says about the state of it today, and the four-step framework to put it in place.

What governance is, and what it is not

A policy says what the company believes. Governance says what the company does. The policy might say we take AI seriously. Governance says who approves each AI system before it goes live, who checks it after, and who has the authority to turn it off.

I have seen boards pass a Responsible AI policy and treat the job as done. The policy sits in a folder. Nobody reads it. Meanwhile, teams are using AI tools that the board has never heard about. That is not governance. It is a letter to itself.

Governance is not a one-time exercise either. It is a set of recurring decisions: what gets reviewed, how often, and by whom. If nothing changes after a board meeting, governance is not happening.

The state of play

The numbers are not encouraging.

"21% of organisations have no AI governance at all, and governance and risk is the fastest growing barrier to adoption."

Source: Deloitte, State of AI in the Enterprise

One in five organisations is running AI with no formal governance in place. That means no one has decided what the technology may or may not do, who approves it, or what happens when it gets it wrong. For a regulated business, that is a problem waiting for a regulator to name it.

The Deloitte finding that governance is the fastest growing barrier tells you something else. It means organisations are starting to notice the gap. The question is whether they are filling it with real decisions or with more paperwork.

Why governance matters more as AI gets more autonomous

The nature of AI is changing. Early AI tools were assistants. They drafted text, summarised documents, suggested next steps. A human always reviewed the output. The risk was low because someone was in the loop.

That is no longer the full picture. New systems act on their own. They book meetings, send emails, make recommendations without waiting for a human to say yes first. When a system acts on its own, governance is not optional. It is the only thing between a mistake and a crisis.

"The most effective safety and security controls for agentic AI are human approval on consequential actions and strong access governance."

Source: Anthropic, CISO Guide to Agentic AI

The Anthropic guide is worth reading closely. The point is not that AI is dangerous. The point is that the controls that matter most are the ones humans built before the technology arrived. Approval gates. Access rules. Limits on what a system may do without someone saying yes.

How to classify risk

Not all AI carries the same risk. A tool that drafts internal meeting notes is not the same as one that approves credit applications. Governance starts with sorting the two apart.

  1. Consequence. What happens if it gets it wrong? Annoying, costly, or damaging.
  2. Reversibility. Can you undo the decision, or is it permanent?
  3. Visibility. Does the output go to a customer, a regulator, or stays internal?
  4. Frequency. How many decisions does it make per day, per hour, per minute?

Palantir's governance framework puts it plainly. An AI agent that fails one percent of the time might be fine for drafting sales emails. It is not fine for processing payments or approving loans. The test is simple. What breaks if it gets it wrong, and can you fix it?

Classify every AI use by these four questions. The ones that score high on consequence and low on reversibility need the tightest governance. The ones that score low on both can move faster.

The four steps of responsible adoption

Fuzzelogic works with a four-step model. It applies to governance as much as it does to adoption.

  1. Find it. You cannot govern what you cannot see. Start with a full inventory of where AI already exists in the business.
  2. Classify it. Sort each use by consequence and reversibility using the four questions above.
  3. Govern it. Apply the right level of oversight to each classification. Not every use needs a board paper. Some need a monthly review.
  4. Train for it. The people who use AI need to know the rules, and the people who supervise them need to know what to look for.

You already have AI in your business. You just do not know where. Every approved tool, every department using a chatbot, every team that has found a faster way to do something. Find it first. Then decide what to do about it.

The regulatory direction

If you are waiting for a regulator to tell you exactly what governance looks like, you will wait a long time. But the direction is clear.

The JFSC issued AI governance guidance in July 2026. The GFSC and the EU AI Act are moving the same way. The pattern is consistent. Regulators expect boards to know what AI is doing in their business, to have classified the risk, and to have someone accountable. The details will differ by sector. The expectation will not.

A board that waits for the final rule before building governance is making a choice. It is choosing to be late. And in a regulatory environment, being late is being exposed.

What a board should actually do

Governance is not complicated. It is four decisions.

First, name the person. Not a committee. A named individual who owns AI governance and reports to the board. Someone who loses sleep over it.

Second, build the inventory. Find every place AI is used or planned. Include the tools no one told the board about. Include the experiments. Include the approved vendor that quietly added AI features to a platform you already pay for.

Third, set the classification. Use the four questions. Consequence, reversibility, visibility, frequency. Every AI use gets a classification. High-risk gets monthly review. Low-risk gets quarterly. New uses get board approval before they go live.

Fourth, set the review cycle. Governance is not a one-off. It is a rhythm. Monthly for high-risk, quarterly for medium, annually for low. Every review asks the same three questions: what is it doing, has anything changed, and who says yes.

The honest version

Fuzzelogic works with boards across banking, insurance, healthcare, retail, manufacturing, and government. In nineteen years, the pattern has not changed. Governance is not the thing that slows you down. It is the thing that lets you move with confidence.

Your systems were built for a world before AI. Most can get there. We tell you which ones cannot.

Start with the assessment. Two to four weeks, fixed price, and you own the verdict and the roadmap whether or not we build any of it. When you are ready to talk AI, call Fuzzelogic Solutions and ask for Zak. www.FuzzelogicSolutions.com | info@FuzzelogicSolutions.com | +44 (0)1624 618950

For the next step, read what happens when AI fails, then shadow AI. The full library is on our index. Our site explains how Fuzzelogic approaches AI for business. You can reach Zak directly via our contact page.

Start with the assessment

Two to four weeks, fixed price, and you own the verdict and the roadmap whether or not we build any of it.

Get in touch

When you are ready to talk AI, call Fuzzelogic Solutions and ask for Zak.

www.FuzzelogicSolutions.com | info@FuzzelogicSolutions.com | +44 (0)1624 618950