Back to Articles AI Governance

AI Governance Without Board Accountability Is Just a Document

By Asaf Levy · · 9 min read

Last reviewed: July 2026

Executive Answer

The EU AI Act begins enforcing high-risk AI obligations on August 2, 2026, with fines up to 35M EUR or 7% of global revenue - yet most organizations cannot name which of their AI systems qualify or who is accountable when one causes harm. A governance policy without individual accountability is not a program. CISOs who build the inventory, the Annex III classification, and the board reporting cadence now will face regulators in a fundamentally stronger position than those treating this as a checkbox.

Key Numbers
  • August 2, 2026 - the date EU AI Act high-risk AI system obligations take effect (Regulation EU 2024/1689, Chapters III and IV).
  • 35M EUR or 7% of global annual turnover - maximum fine for deploying a prohibited AI system under Article 5 of the EU AI Act (whichever is higher).
  • 15M EUR or 3% of global annual turnover - fine for failing to meet high-risk AI system obligations, including governance and oversight requirements.
  • 8.5 million Windows devices crashed in the CrowdStrike incident of July 2024. The CEO was summoned to testify before the US Senate Commerce Committee in October 2024. Board oversight of vendor AI and software dependencies became a regulatory conversation.
  • 4 business days - maximum time US public companies have to disclose a material cybersecurity incident under SEC rules adopted in July 2023. The same disclosure framework is being extended to include material AI system failures by several regulators.
Executive Summary

The EU AI Act begins enforcing high-risk AI system obligations on August 2, 2026, yet most boards cannot name which of their AI systems qualify or who is accountable when one causes harm. A governance policy filed without individual accountability is not a program - it is a document waiting to fail under regulatory scrutiny. CISOs and executives who build the inventory, the classification, and the board reporting cadence now will be in a fundamentally different position than those who treat this as a compliance checkbox.

On August 2, 2026, the EU AI Act starts enforcing obligations for deployers of high-risk AI systems. Most boards I speak with do not know which of their AI systems qualify as high-risk under the regulation. Some do not have a complete inventory of the AI systems their organization is running at all.

Most large organizations have an AI governance policy. It was written by the security or legal team, approved somewhere in the IT hierarchy, and filed. What it almost certainly does not have is a named executive accountable when an AI system causes harm, a board-level reporting cadence, or any process connecting AI deployment decisions to the people ultimately responsible for the organization's risk profile.

The EU AI Act, SEC disclosure rules, and emerging AI liability frameworks are all targeting exactly that gap. Regulators are not asking whether you have a policy. They are asking who is accountable, and whether you can prove it.

What the EU AI Act Actually Requires

The EU AI Act (Regulation EU 2024/1689) has been in force since August 2024. Prohibitions on the most dangerous AI applications took effect in February 2025. The rules that most enterprises need to focus on now are the high-risk AI system obligations, which apply from August 2, 2026.

High-risk AI systems under the regulation include AI used in: critical infrastructure management, employment and worker management decisions, access to education or vocational training, essential private and public services, law enforcement, border control, and the administration of justice. The definition is broader than most organizations assume. An AI tool that helps rank job applicants, assess creditworthiness, or determine access to public benefits likely qualifies.

For deployers - meaning organizations that use these systems in their operations - the obligations include: conducting a fundamental rights impact assessment before deployment, designating a person or team responsible for human oversight, maintaining logs of system use, and ensuring employees who interact with high-risk AI systems receive adequate training. None of these are purely technical tasks. All of them require organizational decisions and accountable humans.

The penalty structure reflects the seriousness of the regulation. Using a prohibited AI system: up to 35 million EUR or 7% of global annual turnover. Failing to meet high-risk AI obligations: up to 15 million EUR or 3% of global turnover. For a mid-market company with 500 million EUR in revenue, a 3% fine is 15 million EUR. For a large enterprise, percentage-of-turnover penalties can be significantly larger than fixed caps.

Why Most AI Governance Policies Will Not Hold Up

I have reviewed a significant number of AI governance policies over the past two years. The structure is usually similar: a definition of what counts as AI, a list of approved tools, a data classification section, and some language about employee responsibilities. Occasionally there is a section on vendor assessment.

What is almost always missing is accountability. Who specifically is responsible for ensuring the organization's AI systems comply with the EU AI Act? Who signs off on the fundamental rights impact assessment? Who gets notified when an AI system behaves unexpectedly? Who is accountable to the board?

Governance documents without individual accountability assignments are not governance programs. They are documents. They create the appearance of a program while ensuring nobody can be held responsible when something goes wrong.

Regulators understand this distinction. The EU AI Act's requirements for designated persons, documented processes, and human oversight mechanisms are specifically designed to prevent organizations from pointing at a filed policy when an AI system causes harm. An auditor will not stop at "do you have a policy?" They will ask who is named, what the process looks like in practice, and whether there are logs showing the oversight actually happened.

The CrowdStrike Lesson for AI Governance

The CrowdStrike incident of July 2024 was not an AI failure, but it produced one of the clearest recent examples of what happens when a board lacks visibility into technical risk. A single software update crashed 8.5 million Windows devices across hospitals, airlines, banks, and emergency services globally. The CEO was called before the US Senate Commerce Committee. Congressional questioning focused specifically on board oversight of software deployment processes and vendor risk.

What transferred to AI governance discussions was a simple point: boards that cannot explain how they oversee the technical systems running their operations face regulatory scrutiny, not just reputational risk.

AI systems make this harder than software deployments. A software update either works or it does not. An AI system makes decisions continuously, may degrade in accuracy over time, can produce unexpected outputs in edge cases not anticipated during testing, and can cause harm in ways that do not appear in system logs until long after the fact. The oversight requirements are more demanding, and the board needs someone inside the organization to build the briefing capability to support meaningful governance.

What Board-Level AI Governance Actually Looks Like

Board members do not need to be technical. They need to be able to ask the right questions and hold management accountable for the answers. That requires someone inside the organization to build the reporting structure that makes that conversation possible.

The first thing that structure needs is an inventory. Before anything else, the organization needs to know what AI systems it is running, who owns them, what decisions they make, and what data they process. This sounds basic. In most organizations it does not exist in a usable form. AI systems arrive through vendor software, SaaS feature updates, internal builds, and individual business unit purchases, usually without any central registry. Building the inventory is often where the first uncomfortable discoveries happen - senior leadership becomes aware of AI deployments they did not know about.

From the inventory, you can run the classification. Which systems fall under the EU AI Act's high-risk definition? Which are making consequential decisions about people - hiring, lending, insurance pricing, access to services? Which operate autonomously with limited human review? The classification exercise shapes the compliance workload.

For each high-risk system, the regulation requires a named person responsible for oversight, a documented human review process, and a clear escalation path when the system produces unexpected outputs. This is where the difference between a policy and a program becomes concrete. A policy says AI systems should have human oversight. A program names who, defines how, specifies the review frequency, and documents what happens when the human reviewer overrides the AI output.

AI risk then needs to appear on the board's agenda on the same cadence as cyber risk - not as a technical briefing, but as a risk report. Which AI systems are in scope, what obligations apply, what the compliance posture is, and what the open risks are. Most boards currently receive no AI risk reporting at all.

The CISO's Role in This Conversation

In many organizations, the CISO is the person best positioned to build board-level AI governance, because they already have the relationship with the board on cyber risk and the organizational standing to drive cross-functional processes. But AI governance is broader than cybersecurity, and the CISO cannot own it alone.

The accountability for AI governance needs to sit with someone who has authority over the full range of AI use cases: hiring decisions, product features, customer-facing automation, financial models, operational systems. In large organizations, this is increasingly a Chief AI Officer role. In mid-market organizations, it typically falls to the CTO or COO, with the CISO responsible for the security and compliance dimensions.

In every organization, the CISO can push for the inventory, the classification, and the board reporting cadence. Those three things alone close most of the gap between a policy document sitting in a folder and a program that holds up under regulatory scrutiny.

The conversation to have with the board is straightforward: the EU AI Act starts enforcing high-risk AI obligations in August 2026. We have done an inventory. Here are the systems that are in scope. Here is what we are doing about it. Here is who is accountable. The board's job is to ask follow-up questions and hold management to the answers.

The Bottom Line

AI governance without board accountability is a document waiting to fail under pressure. Regulators know this, which is why the EU AI Act and SEC cybersecurity rules both build toward the same place: named accountability, documented processes, and board-level visibility into organizational AI risk.

August 2026 is not a distant deadline. For most organizations, the work of building that accountability structure, completing the AI inventory, and getting the first board briefing on AI risk needs to start now. The companies that treat this as a compliance checkbox to complete before the deadline will be in a different position than the ones that build it as a functioning governance program.

This is the third article in a five-part series on AI and enterprise security. Next: how AI is changing the economics of the attack surface, and why your exposure management program needs to catch up.

Asaf's Take

I have sat in rooms where boards approved AI governance policies without a single named person responsible for implementation. The policy felt like progress - it was not. The EU AI Act is asking the exact question those rooms avoided: who is accountable, and can you prove it? Until a real person's name is on the document and on the board's quarterly agenda, you have not done governance. You have done paperwork.

Sources & Further Reading

Frequently Asked Questions

When does the EU AI Act start enforcing high-risk AI system rules?

High-risk AI system obligations apply from August 2, 2026. This covers AI deployed in critical infrastructure, employment decisions, access to essential services, education, law enforcement, and border control. Deployers must conduct fundamental rights impact assessments, designate human oversight, and maintain system logs.

What are the fines for non-compliance with the EU AI Act?

Using a prohibited AI system: up to 35 million EUR or 7% of global annual turnover. Failing to meet high-risk AI obligations: up to 15 million EUR or 3% of global turnover. For large organizations, the percentage-of-turnover calculation will typically exceed fixed caps.

What should a board-level AI governance structure include?

An inventory of all AI systems in use, a classification of which are high-risk under applicable regulations, a named executive accountable for AI risk, a documented approval process for new AI deployments, fundamental rights impact assessments for high-risk systems, and a board reporting cadence for AI risk alongside cyber risk.

How is AI governance different from cybersecurity governance?

Cybersecurity governance focuses on protecting systems from unauthorized access. AI governance addresses what decisions AI systems make, who is accountable for those decisions, whether outputs are accurate and fair, and what happens when an AI system causes harm. It extends into employment law, consumer protection, and product liability in ways that cybersecurity frameworks alone do not cover.

Is your AI governance ready for August 2026?

I help organizations build AI governance programs with real board-level accountability - not just policy documents. Inventory, classification, compliance, and board reporting.

Let's Talk