
Whitepaper: 2026 – Board Accountability and Agentic AI
Boards are responsible for agentic AI risk oversight - yet boards are approving agentic AI systems that directors don't fully understand, and that even management and the developers that build them cannot fully explain.
OpenAI's recent autonomous hack of the Australian government's Medicare website, demonstrates how unpredictable and misaligned AI agent behavior can be. Organizations are increasingly exposed to financial, geopolitical, legal and reputational risk twice over: as targets of these agents, and also as deployers.
This demands a new board governance approach, one that treats AI agents not as deterministic software, but as autonomous delegates that can pursue goals and do so in misaligned ways.
This whitepaper sets out the immediate priorities boards must follow to better govern agentic AI systems. It draws on the experience of AIUC-1 Consortium members, AI governance researchers and directors who sit on boards across healthcare, financial services, media and other critical industries.

Three immediate AI governance priorities for boards
- Operationalize AI principles. Fewer than one in four US companies have translated AI principles into board-approved governance frameworks with measurable controls. Boards need to move from principles to practical governance oversight, with clear accountabilities, thresholds, reporting, and escalation protocols.
- Understand agentic AI. Directors and CEOs agree that AI is strategically important, but differ significantly in their assessment of board preparedness. Boards need collective AI fluency in order for directors to challenge management, assess risks, and make informed decisions about AI strategy and delegated authority.
- Own AI governance. Board AI governance has begun shifting from agentic decision review to the pre-authorization of decision boundaries and establishment of protocols for breach escalation. Boards and management need a shared language to discuss governance, who owns which decisions, what authority can be delegated, and when matters require escalation.
In the whitepaper, experienced board members outline how they have seen AI governance rolled out successfully. Their experience points to developing collective AI fluency among directors, demanding enterprise visibility through AI inventory, observability and monitoring, and conducting independent assurance by following defined standards with independent verification.
We include an example of a Board AI Agent Governance Checklist and Agent Classification Model that directors can refer to, and use for future board or risk committee meetings.
Many thanks to Louise McElvogue (Non-Executive Director, With Fluency, Adjunct Professor UTS Business School) for leading authorship and our co-authors:
- Dr. Ali Akbari, Director of AI Practice, Gradient Institute
- Kim Anderson AM, Chair and Non-Executive Director
- Sarah Butler, Non-Executive Director, FAICD, Consilium Strategy, Adjunct Professor UNSW Medicine
- Elaine Farrelly, Non-Executive Director
- Donna Flynn, Former Chief People Officer, Steelcase
- Dr. Keri Pearlson, Principal Research Scientist, MIT Sloan School of Management
- Kevin R. Powers, Faculty Director & Lecturer-in-Law, Master of Legal Studies in Cybersecurity, Risk & Governance, Boston College Law School
- Avril Ussery Sisk, NACD.DC, LPEC, Athena Alliance Governance Council
- Lalitha Suryanarayana, Executive in Residence, Techquity Growth Capital
- Gill Whitehead, Visiting Policy Fellow, Oxford Internet Institute, Non-Executive Director, Advisory Council, Frontier Economics
- SuiLin Yap, Director of Product, Microsoft