The AI Governance Gap Nobody Is Talking About – And Why It Sits Between Management and the Board

What management teams and boards both get wrong about enterprise AI governance.

Over the past year, I have sat in two rooms that rarely talk to each other. In one, management teams present their AI roadmaps – confident, ambitious, full of deployment milestones. In the other, board and committee members receive those presentations, nod at the progress, and move on to the next agenda item. Both rooms believe they are doing their job. Neither is wrong, exactly. But together, they are creating a governance gap that almost nobody is talking about. A McKinsey and NACD study found that only 17% of boards formally own AI governance. The other 83% have, in effect, delegated it to management – who may not realise they have been handed it.

I have spent three decades as a technology executive – building and deploying AI at scale, leading major digital transformations, overseeing enterprise cybersecurity and compliance programmes. I now serve on both the IT Sub-Committee and the Risk Management Committee of one of India’s leading life insurance companies. That shift in vantage point has been clarifying. What I see from the committee table is very different from what I used to see from the management table – and the distance between the two is where the real risk lives.

“Management treats AI as a technology problem it is solving. Boards treat it as management’s problem. So the governance gap sits in the middle, and nobody owns it.”

What Management Teams Get Wrong

Management teams, on the whole, are genuinely trying. They are moving fast because the competitive pressure to adopt AI is real. But speed creates blind spots, and the most common ones I encounter are these:

– Confusing deployment with governance. Having an AI strategy is not the same as governing AI. I have seen organisations celebrate the rollout of a new model while having no answer to the question: who is accountable if this model causes harm? Deployment is a milestone. Governance is an ongoing discipline. The two are not the same.

– Measuring the wrong things. Management tends to report on AI in the language of efficiency – cost saved, time reduced, throughput improved. These are valid metrics. But they are not governance metrics. The questions that matter for governance are different: Is the model performing the way we intended? Has the underlying data drifted? Can we explain a decision if a customer or regulator asks us to? These questions rarely make it into a management presentation.

– Assuming AI risk is IT risk. It is not. When an AI model influences an underwriting decision, a claims outcome, or a fraud classification, it is making a business decision – with regulatory, ethical, and reputational consequences. Managing that risk sits with the business, not the IT function. Most organisations have not made that accountability transfer.

– Planning to govern later. The most dangerous phrase in AI programme management is ‘we will build the governance framework once we have scaled.’ By then, the exposure is already baked in. Models drift silently. Biases compound. Audit trails become difficult to reconstruct. Governance must be designed in from the start, not retrofitted after the fact.

What Boards Get Wrong

Boards are not passive. Most board and committee members I work with are engaged, intelligent, and genuinely concerned about getting this right. But the nature of governance – receiving information rather than generating it – creates its own failure modes:

– Asking the wrong question. The most common AI question I hear at board level is: ‘Are we using AI?’ It is the wrong question. The right questions are: How are we governing it? Who is accountable for AI decisions? What happens when a model gets it wrong? If management cannot answer those questions clearly, the board should not move on.

– Conflating AI risk with cyber risk. They overlap, but they are not the same. Cyber risk is largely about protecting systems from external threat. AI risk is about what the systems themselves do – the decisions they make, the biases they embed, the regulatory obligations they trigger. A board that ticks the AI governance box inside the cybersecurity agenda has not governed AI. This distinction is now attracting wider attention – HBR and the Insurance Journal both addressed it in early 2026 – but it has yet to land clearly inside most Indian insurance boardrooms.

– Being satisfied with a policy document. ‘We have an AI policy’ is not governance. It is the beginning of governance. The questions that follow are harder: Is the policy being followed? Are there exceptions? Who reviews model performance on an ongoing basis? Is the policy keeping pace with how quickly AI capability is actually evolving inside the organisation?

– Not knowing what to ask – so asking nothing. This is the most understandable failure, and the most costly. AI is technical. Board members are often not technologists. So when a polished management presentation lands, it is easier to accept the framing than to probe it. Independent industry experts on committees exist precisely to bridge this gap – to ask the questions that management has not thought to ask itself, in language the full board can engage with.

The Gap in the Middle

The real structural problem is this: management speaks to boards in a language optimised for reassurance, not for oversight. And boards, without the vocabulary to interrogate AI at a technical level, tend to receive those presentations as reassurance rather than as information requiring scrutiny.

In the insurance sector specifically, this gap has immediate consequences. AI is increasingly used in underwriting, claims processing, fraud detection, and customer segmentation. These are not technology decisions – they are decisions with direct impact on customers, with clear regulatory implications under frameworks that IRDAI is actively developing. The 2023 Information and Cyber Security Guidelines are the beginning of that regulatory journey, not the end. Boards that treat AI governance as an IT committee matter are quietly accumulating exposure they may not discover until it surfaces as a regulatory query or a reputational incident.

The companies that govern AI well will not just avoid problems. They will be more trusted by regulators, more confident in their decisions, and better positioned as oversight tightens across the sector.”

What Good Governance Actually Looks Like

None of this is an argument for slowing down AI adoption. It is an argument for governing it at the right level, from the start. In practice, that means a handful of structural changes that are neither technically complex nor expensive to implement:

– A named accountability owner – not the CIO, not the CTO, but a business leader who owns AI outcomes and is accountable to the board for them.

– A board-level risk framework – not a technical document, but a governance framework the full board can interrogate: what we use AI for, what the risk thresholds are, how we monitor ongoing performance, and what escalation looks like when something goes wrong.

– Regular model oversight at committee level – not just deployment updates, but ongoing review of model performance, data drift, and exception patterns. In insurance, this should include specific oversight of any model touching underwriting, claims, or fraud.

– Explainability as a precondition, not an afterthought – the ability to explain any AI-influenced decision to a customer or regulator should be a design requirement, built in before a model goes live.

The organisations that build these disciplines now – not after the first incident, not after the first regulatory query – will be the ones that earn and keep the trust that the AI era will increasingly demand.

I would be glad to hear from others who are working through these questions – whether from the management side or the board side. The conversation is the governance.

References & Further Reading

McKinsey & NACD Board Survey (2024): Only 17% of boards formally own AI governance. · HBR, April 2026: “AI Is Reshaping Cyber Risk. Boards Need to Manage the Threat.” · Insurance Journal, May 2026: “AI Insurance Is Not Cyber Insurance With Extra Steps.” · IRDAI Information and Cyber Security Guidelines (2023) and IT Governance Framework Circulars.

Author:

Hitesh Kumar Arora,
EVP & Enterprise AI Leader, Intellect Design Arena
Independent Committee Member (IT & Risk), Financial Services Sector

The AI Governance Gap Nobody Is Talking About – And Why It Sits Between Management and the Board