If AI makes the decision, who owns the consequence?
Your board approved that AI decision 18 months ago. It no longer covers what the system actually does.

Why it matters
Authority over AI decisions drifts outward while accountability stays on paper. Boards need to map material decisions, name decision rights, and establish what forces authority back to humans — not audit AI systems.
The key facts
8 to knowFoundry State of CIO 2026: ~75% of leaders say AI is reshaping operations; ~70% expect deeper agentic involvement in 2026
Authority drift pattern: decision-making power moves outward while formal accountability remains static, often unmapped and unrecorded
Most orgs have or plan AI steering groups; only ~50% report formal approval process
Material decisions: those affecting customers, capital, employees, regulatory standing or resilience — typically 15–20 per firm
Four verbs framework: Recommend (system proposes), Decide (system chooses within limits), Execute (system chooses and acts), Accept (person carries consequence)
Evidence threshold: if authority limit is typed into policy rather than built into workflow, it does not hold under pressure
Risk expansion without reauthorization: approval granted for one use case quietly covers expanded scope months later
Reconstruction time: afternoon = evidence of clear decision chain; fortnight = archaeology
Go to the source
CIOcio.com
Publisher excerpt: Twenty-two rows. That was the AI inventory in a board pack I read last year, and it was a good one. Every system named, every owner listed, every risk rating filled in and colour-coded. Somebody had worked hard on it, and the committee approved it in four minutes. I kept looking for a column that…