Most boards now use AI, yet almost none govern it. In the BoardPro AI Governance Pulse 2026, 79% of governance professionals reported using AI weekly or more, while only 2% of organisations had a formal governance framework. This article sets out where that gap sits, why it exposes directors personally, and the practical steps that let a board turn AI from a risk to manage into capacity for its mission.
Fewer than one in fifty boards govern AI well. That is the central finding of the BoardPro AI Governance Pulse: a benchmark report – and it carries real consequences for directors, not just as a gap on a maturity model, but as a personal liability exposure.
The survey collected responses from 485 governance professionals, 85% of them from Australia and New Zealand. Two-thirds were directors, board chairs, or governance professionals, and 43% came from the charity and not-for-profit sector. This is a governance-engaged audience that cares about getting things right. If gaps show up here, the broader market is almost certainly further behind.
This article also draws on the BoardPro webinar discussion of the AI Governance Pulse: a benchmark report, led by governance experts Helen van Orton and Alexie O'Brien.
79% of governance professionals use AI weekly or more, but only 9% describe themselves as very confident in how they are using it.
Only 2% of organisations have full AI governance in place with a formal framework with clear accountability and regular reporting.
29% of organisations have no AI governance measures at all — no policy, no training, no oversight.
Three in four boards receive management information on AI risks, workforce impacts, and regulatory changes only on an ad hoc basis or never.
One in four boards has not discussed a single AI-specific risk. Only 52% have discussed data privacy.
The fix does not require a full AI strategy. It starts with visibility: name an owner, set a minimum policy, and get AI onto the board agenda within 30 days. The plan is set out below.
The personal adoption story in the data is strong. 53% of respondents use AI every single day, and 79% use it weekly or more. This is not dabbling. It is embedded behaviour.
Personal adoption of AI for governance work
Source: AI Governance Pulse: A benchmark report
The use cases have moved well beyond basic drafting. 74% use AI for research and information gathering, and 73% for drafting, editing, or summarising content. But 43% now use it to challenge their own thinking and get a second opinion, and 31% apply it to strategic thinking and scenario planning. Nearly half (49%) describe AI as a thinking partner, not just a productivity tool.
These are directors, chairs, and governance specialists actively using AI to inform the work they bring to the board.
In addition, AI use across organisations is widespread; the board knows it's in the building, just not exactly where and without the governance structures to manage it. Four in ten organisations say AI use by individuals within their organisation is informal; three in ten know that AI use is in some teams. Almost 10% are not sure what the AI use is.
AI adoption at the organisational level
Source: AI Governance Pulse: A benchmark report
The governance picture mirrors the adoption one. Only 2% of organisations in the survey have what the research defines as full governance: a formal framework with clear accountability and regular reporting. At the other end, 29% have nothing in place at all – no policy, no training, no oversight. Almost half of boards have no agreed position on AI whatsoever.
At every level, AI activity is outpacing the oversight structures designed to manage it – the challenge for boards in 2026 is not AI adoption; it is AI governance. The result is organisations where daily use of AI, including for drafting advice, summarising data, and informing strategy, happens without a governance framework. If something goes wrong, the board cannot point to a policy, an approval process, or a named person overseeing it. For directors, the question is no longer whether to govern AI. It is whether you can demonstrate that you did.
“There is a lack of insight, or perhaps a blinkered approach, given how widespread AI use is by individuals at board and staff level, but no policy, process or direction.” - CEO / Executive Director, community organisation, New Zealand
Board preparation for AI governance
Source: AI Governance Pulse: A benchmark report
One phrase from the survey responses captures a pattern that shows up again and again around awareness vs enablement.
“The board is AI aware, but not AI enabled,” says Helen van Orton. “Aware is it's sitting in our briefing deck, and we've heard someone talk about it. Enabled is sitting in that conversation that follows on from it.”
The confidence data reinforces this. 79% of respondents use AI weekly, but only 9% feel very confident using it, and just 54% describe themselves as confident at all. Almost half (46%) say they are still figuring out how to use AI effectively. People are regularly using tools they are not fully comfortable with, and that has direct implications for the quality of AI-informed decisions reaching boards.
There is also a visibility problem. 21% of respondents do not know what their staff are using AI for. A further 17% say AI is probably embedded in their tools, but nobody has formally mapped it. Together, that is more than a third of organisations with limited visibility into how AI is being used internally.
The asymmetry compounds the problem. Management has daily, high-volume exposure to AI use across the organisation. The board has the agenda paper. That gap widens every week.
“Due to the profile of our board, very few have a good understanding of AI or are regular users themselves. The staff use it, but the board do not know enough about it.” – CEO / Executive Director, charity / not-for-profit, UK
Asked how often management provides the board with information on AI, across workforce impact, emerging regulation, and AI performance and risks, the pattern was consistent across all three topics. Roughly three in four boards receive that information either on an ad hoc basis or not at all. Around 38% receive nothing at all.
Boards cannot oversee what’s invisible. Even boards that believe they are governing AI are likely doing so in an information vacuum.
The risk-conversation data is equally stark. One in four boards (26%) has not discussed a single one of the AI-specific risks in the survey, and less than a fifth have active oversight of how AI is actually being used in their organisation.
“One in five respondents don't actually know what their staff are even using AI for,” says Alexie O’Brien. ”Seventeen per cent say it's probably embedded in the tools they're using, but nobody's actually mapped it. Put those two numbers together and more than a third have really limited visibility into how AI is being used in their organisation. That's a huge blind spot.”
Data privacy and intellectual property exposure is the only AI risk discussed by a majority of boards (52%). Shadow AI and hallucinations follow at 29% each. The numbers fall sharply from there.
Directors' liability exposure from AI decisions has been discussed by just 17% of boards, and insurance and directors and officers (D&O) coverage gaps related to AI by only 8%. Agentic AI has been discussed by just 10% of boards, and prompt injection by only 5%. Those risks are among the most significant emerging risks, yet barely on the radar.
These risks can hurt directors personally, and they remain largely unexamined.
US research from Grant Thornton's 2026 AI Impact Survey found that 78% of business executives lack strong confidence they could pass an independent AI governance audit within 90 days. Privacy regulators in both Australia and New Zealand have issued explicit guidance against entering sensitive information into publicly available AI tools, which is the current regulatory direction, applicable right now.
Learn more about these risks, with real-world examples, in The AI-Enabled Board whitepaper.
The survey data points to three patterns that explain why organisations have fallen into the gap between adoption and governance.
“Only one in five companies have a named person actually accountable for AI governance," says Alexie. "If you haven't got an owner, governance suddenly is everybody's problem, but at the same time, it's nobody's.”
The fix is straightforward: name someone this week. They do not need to be an AI expert — they need to be accountable for coordinating the response.
41% of respondents say AI is used informally by individuals in their organisation – not sanctioned, not systematic. Alexie notes that this figure is likely conservative, and that shadow AI is a genuine blind spot for many boards.
One respondent described it directly: widespread AI use at board and staff level, but no policy, process or direction. The board is told one thing while the reality on the ground is different.
The AI-Enabled Board whitepaper cites IBM's 2025 Cost of a Data Breach Report: one in five organisations experienced a breach caused by shadow AI, adding an average of USD 670,000 to breach costs.
“Your people are feeding your data into tools nobody's approved, nobody's monitoring, and your board may not even know they exist," says Helen. "If you can't see it, you can't govern it. And as a board, if you can't govern it, you own the consequences.”
Only 31% of respondents use AI for strategic thinking and scenario planning. In many organisations, AI is treated as an administrative efficiency play, parked in the technology team rather than sitting on the strategy agenda.
As Helen and Alexie say in the whitepaper, AI governance is now board work. Boards need visibility, policy, and assurance over how AI is used across the organisation. That is not a technology responsibility. It is a fiduciary one.
“AI is not a technology strategy," notes Helen. "Your organisation's strategy is your strategy, and the question is where can AI help me with this? Not what's our technology strategy about AI? The tech team need to figure out the tools, but your actual AI strategy needs to sit with you as a board. It needs to change your ability to execute on your mission. If you park it in IT, it's not going to go anywhere.”
As a starting point, use the BoardPro free AI policy template.
The survey did not only surface what is going wrong. It also shows what the gap is costing organisations that stay stuck in it, and what the ones getting it right are gaining.
This is the part most easily missed. Governing AI well is not only about protecting directors from a claim. It is what lets an organisation use AI with enough confidence to actually change what it delivers and, through that, the real-world impact it has on the people it serves. Governance is what gives leaders the confidence to invest decisively rather than dabble at the edges. The following three building blocks are shared by organisations doing AI governance well; each is developed in full in The AI-Enabled Board whitepaper.
Informed oversight does not mean directors must become technologists. Boards that have never engaged with AI tools first-hand are governing something they have not experienced.
“It doesn't mean the board has to become the technologists," concedes Alexie. "Directors have to be fluent enough to interrogate management's assurances, not just take them at face value. Can you ask your CEO which agents are operating in our business? What can they access? What can they do without human approval? If you can't ask that with confidence, that's the fluency gap boards need to close.”
Boards that get real value from AI do not treat it as a technology project to manage or a risk to contain. They treat it as a strategic capability on the strategy agenda, not hidden in the risk register. The question is not only “what could go wrong” but “how can AI help us deliver on our mission”.
For a not-for-profit or a smaller organisation, that shift changes the equation. You do not have to hire your way to greater capacity. When AI takes on routine work, it frees people to do the work that moves the dial, such as protecting funding, deepening participant trust, and putting more of the organisation's effort where its mission actually lands.
That link — better governance letting a board execute on its mission — is the chain the rest of our Governing with Impact series follows, step by step, to real-world impact.
Grant Thornton's 2026 AI Impact Survey underlines the cost of inaction: 78% of executives lack confidence they could pass an independent AI governance audit, and organisations with fully integrated AI are nearly four times more likely to report revenue growth than those still piloting. Your mission does not change because of AI. AI changes your ability to execute on it, but only when governance is there to enable it rather than block it.
Ethical leadership means clear boundaries on data, named accountability for AI governance, and a culture where staff feel safe raising concerns about AI rather than hiding it. You will not fix shadow AI with a policy alone. You fix it with a culture where people do not feel the need to hide. Until your board has a policy on approved tools, treat confidential board papers as off-limits for any general-purpose AI tool.
The governance gap will not close in a single board meeting, and you don't need a full AI strategy to act. In the webinar, Helen and Alexie set out a 30-day plan you can start next Monday, not next quarter.
Review the AI tools in use across your organisation, including AI embedded in existing software, and make the results visible to the board. Ask three questions: what tools are staff actually using, what data is going into them, and who approved them? Many boards are governing what they assume is happening rather than what actually is.
Only 20% of organisations have a named individual or team accountable for AI governance, so naming one puts you ahead of most. Assign explicit oversight, ideally at committee level, and have that person report to the board as a standing item, not just when something goes wrong.
An AI policy does not need to be comprehensive to be useful. A one-page acceptable use framework covering data handling, output review, and accountability is better than no framework at all. Just 7% of organisations have a process to review or audit AI outputs, so make output review explicit. Most organisations already have the building blocks in their data policies, privacy frameworks, and employment agreements; start by extending these to cover AI.
Three in four boards receive information on AI risks, and workforce impacts only on an ad hoc basis or never. Ask management to report on AI activity, emerging risks, and regulatory developments as a standing agenda item. It does not need to be comprehensive; visibility is the foundation of governance.
If you take one thing from the 2026 AI Governance Pulse: A benchmark report findings, it's to start the discussions and set action points around these six questions.
Do we know which AI tools are being used in our organisation, and by whom?
What data is going into those tools, and do we have clear rules about what must not?
Who is accountable for AI governance, and are they reporting to the board regularly?
Which AI risks have we explicitly discussed?
Are we treating AI as a technology issue or a strategic governance issue?
Have we discussed our exposure as directors, including personal liability and D&O coverage in the context of AI?
Based on the Pulse 2026 data, most boards would not be able to answer all six. That is not a criticism – it is the point. These are the conversations that need to start.
The AI governance gap is the difference between how widely AI is used inside an organisation and how formally it is governed. In the BoardPro AI Governance Pulse 2026, 79% of governance professionals reported using AI weekly, while only 2% of organisations had a formal governance framework with clear accountability and regular reporting.
The Pulse 2026 survey identified specific AI risks boards should be actively discussing: data privacy and intellectual property exposure, shadow AI (unauthorised use of AI tools by staff), hallucinations and inaccurate outputs, director liability from AI decisions, D&O insurance gaps, vendor and third-party risk, agentic AI, and prompt injection. One in four boards has not discussed any of these.
Shadow AI refers to AI tools used informally within an organisation, by individuals, without sanction, and outside any governance framework. The Pulse 2026 survey found 41% of organisations report this kind of informal use. IBM's 2025 Cost of a Data Breach Report found shadow AI contributed to one in five data breaches, adding an average of USD 670,000 to breach costs.
A minimum viable AI policy covers three things: what data must never be entered into AI tools; which AI tools are approved for use; and what AI outputs require human review before being acted on. Staff need to know the policy exists and what it says. BoardPro's free AI policy template provides a practical starting point.
Under Australian and New Zealand company law, directors must exercise care, diligence, and skill personally. Under the Australian Corporations Act (s180) and the New Zealand Companies Act (s137), directors cannot delegate these duties to technology. The AI-Enabled Board whitepaper notes that on 5 March 2026 the Federal Court of Australia handed down ASIC v Bekier [2026] FCA 196, in which Justice Lee confirmed that technology may assist comprehension but cannot displace judgment; the statutory obligation remains personal.
Attend the Roadshow and learn more! Choose your city and register here
Boards that want to spend less time assembling papers and more time on the decisions that matter can see how BoardPro’s board software supports the shift — start a free, 30-day trial and set up your next board meeting in a few clicks, no credit card required.