An Urgent Call to Directors: Holding the Line in the Age of AI

There’s a growing tension building across organisations right now.

Regulators are struggling to keep pace. Senior leaders and operational teams are under pressure to adopt and implement AI at speed. Staff are being exposed to new tools and capabilities almost daily, often without structured guidance. Shareholders are increasingly expecting improved performance and efficiency as a result.

And sitting in the middle of all of this are company directors.

Directors who remain ultimately accountable for the performance and stability of the organisation, while at the same time being asked to ensure it doesn’t veer off course as AI is introduced at scale.

We’re already starting to see examples of what happens when things go wrong.

This is not a distant risk.


I have no doubt that most directors are well aware of the balance between opportunity and risk when it comes to AI.

The challenge is not awareness.

The challenge is managing the pressure from all sides, while finding a practical and sustainable way to maintain control.

From what I’m seeing, many organisations are already moving in the right direction. Strategies are being formed, frameworks are being considered, and governance discussions are happening.

But there are a few areas that I believe will determine whether organisations truly keep a handle on this.


The first is culture and behaviour.

AI is not a contained system. It is not a single platform that can be deployed, controlled, and monitored in isolation. It is rapidly embedding itself across tools, platforms, and workflows, often without organisations even realising it.

A piece of software used yesterday can be augmented with AI features today. Staff are increasingly expected to operate in a “human in the loop” capacity, reviewing, validating, and guiding outputs. Yet in many cases, they haven’t been trained or equipped to perform that role.

This is why culture becomes foundational.

Organisations that recognise the scale of this shift are starting to invest in awareness and capability. Not just technical training, but practical understanding. What to look for. What good looks like. Where the risks sit. What is expected of them.

In the same way organisations have spent years educating staff on phishing, cyber threats, and basic digital hygiene, we now need a similar level of maturity when it comes to AI.

Without that, the control layer simply doesn’t exist.


The second is data governance.

This is not new, but it has taken on a different level of importance.

Data now underpins both the effectiveness of AI and the risks associated with it. How it is structured, managed, accessed, and maintained directly impacts outcomes.

There are well-established standards that provide strong foundations here. ISO frameworks, ISACA guidance, and other governance models already address many of the core challenges. There is no need to reinvent this.

But these frameworks need to be viewed through an AI lens.

How is data being used? How is it being transformed? Where is it flowing? What is being retained, and what is being exposed?

The old principle of “garbage in, garbage out” has never been more relevant.

I’ve seen AI implementations perform exceptionally well in their early stages, only to degrade over time as data quality declines. Not because of a failure in the technology, but because the discipline around data wasn’t maintained.

There is often a temptation to push more and more data into these systems and assume the AI will sort it out.

It doesn’t.

Without strong governance, the quality and reliability of outputs will deteriorate, and risks will begin to surface.

Directors should be expecting clear visibility and accountability in this area. If data governance is not being prioritised, it will become a point of failure.


The third is the governance layer itself.

Policies, procedures, controls, and supporting technologies still matter. They always will.

But they need to evolve.

AI is not static. It is changing daily. Trying to prescribe every possible use case through detailed documentation is not realistic. By the time those documents are written, they are already out of date.

This means organisations need to shift, at least in part, towards a more principles-based approach. One that provides guidance and boundaries, while still allowing for flexibility and judgement in how AI is used.

That doesn’t reduce the importance of governance. It increases the need for clarity.

Staff need to understand not just the rules, but the intent behind them. They need to be able to apply judgement in situations that haven’t been explicitly documented.

That is a different kind of organisational capability.


Looking ahead, I suspect the next 12 months will be one of those periods we look back on and wonder how so much changed, so quickly.

There will be organisations that navigate this well, adapt, and strengthen their position.

There will also be those that struggle, not because they ignored the risks, but because they weren’t able to translate awareness into effective action.


The common thread in those that succeed will be leadership.

Not just at the executive level, but from the board.

Because ultimately, the responsibility for setting the tone, establishing expectations, and ensuring the organisation remains in control sits there.


So perhaps the more useful questions for directors right now are not:

  • Do we have an AI strategy?
  • Do we have policies in place?

But rather:

  • Do we understand how our organisation is actually using AI today?
  • Are our people equipped to manage it responsibly?
  • And if something went wrong tomorrow, how confident are we that we could respond effectively?

I’ll explore some of the more practical approaches to this in the next piece.

Related posts

Leave the first comment

Talk to a specialist
We’re waiting to hear from you and ready to support.
name@company.com
Please include your country code if located outside of Australia.