Transformation/AI: Deterministic controls to govern probabilistic outcomes?

'If AI breaks the law, who wears the handcuffs?’

AI has shifted from a slightly geeky, technical topic that lurked in the shadows, to a defining governance challenge. But now it has been thrust into the spotlight, there are clear concerns about how technological change is accelerating faster than firms can keep up with. But as we enter Q1, should we be setting aside a desire for fluency, and focusing instead on asking better, braver questions?


‘AI isn’t coming for our jobs, but the people who understand it are.’

Sector overview

Across our 2025 forums, one theme rose above all others: the accelerating impact of artificial intelligence and emerging technologies on governance, risk and organisational resilience. What began as a technical conversation has now become a strategic, cultural and, somewhat unexpectedly, ethical one. As we move into 2026, the question is no longer whether boards should engage with AI, but how quickly they can build the fluency required to oversee it responsibly?

Throughout the year, we heard a consistent message from our guests - the concern that the pace of technological change is outstripping the board’s ability to properly question it. One participant noted that 'AI isn’t coming for our jobs, but the people who understand it are.' The threat is not automation itself, but the widening gap between those who can challenge AI‑driven decisions and those who cannot.

This gap matters because AI is no longer confined to innovation teams or digital functions, it is embedded in every move we make - from risk modelling to customer interactions and strategic decision‑making. With the machine firmly risen, Boards must now ensure that technological literacy has a firm seat at the table, and is part of every discussion. One attendee noted that 'AI is not just a tech issue. It’s a risk, culture and strategy issue.'

Yet fluency does not mean expertise. We repeatedly heard that we don't all need to become Silicone Valley-spec technologists overnight, we just need to become more confident at asking questions.

Problem is, the traditional lines of questioning - cost, efficiency, implementation - don't always get to the crux of the issue... firms need to be considering additional issues around AI bias and accountability. One guest noted questioned that 'if AI breaks the law, who wears the handcuffs?' Asking the 'daft' questions isn't being difficult , its being realistic in the face of a still relatively unknown risk.

The frustration of the unknown was a recurring discussion point, with the apparent 'opacity of technology reporting' a real cause for concern. Cyber and AI updates often arrive in highly technical language, leaving Boards struggling to distinguish between genuine risk, and noise. As one participant shared their concerns that 'cyber risk updates land like Greek for most of the board. We need translation, not transformation.'

Firms are increasingly aware that whilst AI bring huge benefits, and is a juggernaut that cannot be stopped, if left to freewheel, poorly governed tech runs the risk of amplifying existing cultural weaknesses. The technology as we know it today may be relatively new, but feedback suggests that the governance principles need to remain firmly entrenched in the traditional: transparency, proportionality and informed oversight still reign supreme.

‘Cyber updates land like Greek for most of the board.

We need translation, not transformation.’

Looking ahead

Looking ahead to 2026, we expect the conversation to shift from experimentation to integration. Boards will need to move beyond high‑level briefings and into structured, scenario‑based discussions about AI’s impact on business models and risk profiles.

We anticipate a far greater emphasis on the interplay between human and machine decision‑making, with firms that embrace curiosity, invest in their own learning, and create space for informed challenge likely to see a more successful output, with less reluctant teams.

Regulators, too, are sharpening their expectations. While formal AI regulation remains in flux, supervisory bodies are signalling that boards must demonstrate understanding, not just compliance. Possibly easier said than done!

This is particularly relevant where AI intersects with areas such as consumer protection and financial crime. The message is clear, ignorance is not a defence.

AI is forcing boards to rethink what good governance looks like in a digital age, quickly. It demands new skills, new conversations, and new forms of collaboration between the Board, NEDs, Executives and technical specialists. Not an easy change for some, but also a huge opportunity to build more resilient, adaptive and forward‑looking organisations, with a more open culture.

As we heard repeatedly throughout the year, the goal is not to master the technology, but to master the questions that shape its use.

The bottom line

AI is now a board‑level strategic issue, not a niche topic.

NEDs feel under -equipped to challenge AI‑related decisions.

Cyber and AI risks are converging.

Boards need fluency, not expertise: translation, not transformation