> ## Content Index
> Fetch the complete content index at: https://www.nedness.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# The Expert in the Room part 2
- URL: https://www.nedness.com/articles/the-expert-in-the-room-series/
- Published: 2026-09-25T09:02:05.000Z
- Updated: 2026-09-25T14:13:30.000Z
- Description: Does AI need its own chair?
- Author: Julia Warrander
- Tags: #article, AI and Robotics, Board composition, #established, Established, Clarity, Board effectiveness

In [part 1](https://www.nedness.com/articles/the-expert-in-the-room-series-part-1/) of this series, we looked at thirty years of governance failures, from Barings to Silicon Valley Bank, and found that courts and regulators kept asking the same question: had the board put in place a way to stay informed about the risks that mattered most, and had it acted on what it learned? Whether the board contained an expert in the relevant field rarely influenced the outcome.

This article addresses whether artificial intelligence changes that. One could argue that AI is moving faster than any technology a board has dealt with, spans all functions, and is too technical for a generalist director to truly understand. The more useful question may be whether AI genuinely changes what directors are expected to do, or simply changes the information they need in order to do it well.

## Defining AI

Before asking whether a board needs an AI expert, it helps to be clear about what the term covers, since it used to encompass a myriad of activities and solutions. The two words artificial intelligence have been utilised for the credit scoring and fraud detection models that banks have run for decades and for the generative tools (large language models) that arrived with ChatGPT in late 2022\. Today, artificial intelligence describes the tools that sit on most employees' desktops (whether or not the company approved them), and the newer agentic systems that carry out tasks with their own licence to act. However, these are different technologies with different risks, and although they all fall under the name artificial intelligence, each requires a different response from boards.

Regulators have struggled with the same problem and have settled on a useful answer: define AI by what it does, rather than by how it is built. The OECD's definition, adopted with only minor changes in the EU AI Act[1](#fn-1), describes a machine-based system that infers from the input it receives how to generate outputs such as predictions, content, recommendations or decisions, with varying levels of autonomy and the capacity to adapt after deployment.[2](#fn-2) The UK government's 2023 white paper declined to define AI at all, and instead regulated it by reference to the two characteristics that matter: adaptivity, meaning the system learns and its behaviour is hard to explain in advance, and autonomy, meaning it can act without a human deciding each step.[3](#fn-3) For boards, the questions can be framed around where in the business a system is inferring, adapting, or acting; how much of the decision it is making; and who is accountable for the result.

## Technology, strategy or governance?

A second, perhaps more important classification question is whether AI should be framed as a technology issue, a strategy issue, or a governance issue. How an organisation answers this often determines who owns it, which committee mandate it falls under, and what kind of information is shared in the board papers. If defined as simply as a technology, it goes to the chief information officer and is the mandate of the IT committee, focusing on vendors, security, and implementation. As strategy, it generally sits with the chief executive and the full board, and the conversation often focuses on markets, productivity, and what competitors are doing. Categorised as governance, it becomes more a matter of oversight: which decisions are being handed to systems; on what authority, with what checks, and who is answerable when they go wrong.

The issue is that each framing captures part of the picture, but none captures the full picture. A board that treats AI only as technology repeats the Boeing pattern, in which the committee charged with risk saw the financial dimension and not the one that brought the company down.[4](#fn-4) A board that treats it only as strategy tends to hear more about the opportunity and be less focused on the risks.

In my view, AI cannot be confined to any one of these categories, and boards that treat it as a technology issue, a strategy issue or a governance issue alone will receive board papers that omit key information. The consequence for directors is that each of them needs a working knowledge of the technology, sufficient to understand the questions being put to them, and to recognise when a governance matter has been presented as a technical one.

## Does AI change the question?

AI differs from many previous technologies because it is being adopted exceptionally quickly and can spread through an organisation before governance, skills or controls catch up. For boards, that speed matters as traditional annual strategy, risk and investment cycles may be too slow. However, speed shifts the reporting cadence rather than changing a director's duties.

What makes AI particularly different is its breadth. Earlier technologies often transformed a specific process, system or department. AI, however, can affect almost every part of an organisation at once: customer service, marketing, operations, finance, HR, legal, risk, compliance, technology and strategy. It can change both how work is done and what work is needed, while also altering customer expectations and competitive dynamics. The lesson for boards is that AI is an enterprise-wide issue and needs attention that reaches well beyond the traditional IT lens.

The opacity issue is important because, with many AI models, it can be difficult to explain exactly how an output or recommendation was reached. The Bank of England's Prudential Regulation Authority (PRA), which supervises UK banks and insurers, has said it does not expect to build a separate regime for AI, and treats AI models as sitting on a spectrum of increasingly complex quantitative models, with requirements determined by characteristics such as autonomy in decision-making, dynamic learning and transparency.[5](#fn-5) On that basis, opacity raises model risk and, with it, the level of governance, validation, monitoring, and challenge required. In practice, the less transparent and more autonomous a model is, the stronger the board should expect the controls around explainability, human oversight, testing and accountability to be.

These characteristics undoubtedly make oversight more demanding. Boards therefore require enhanced reporting, more frequent updates, and stronger assurance mechanisms than they have relied on in the past. However, this does not fundamentally alter the director's role. The underlying challenge remains the same as in the case studies discussed in Part 1: ensuring the board receives timely and meaningful information about important risks and responds appropriately when concerns emerge.

## The current state of play

Directors themselves recognise the gap. According to WTW’s 2026 global survey of directors and officers, only 51% said their board had the skills and knowledge to oversee AI effectively, the second-lowest score of the fourteen areas assessed, ahead only of climate transition.[6](#fn-6) Although half of respondents were concerned about AI errors and misinformation, fewer than a third worried about weak governance of how AI is used. It seems boards are more aware of the risks AI may create to their organisation, and less focused on whether their own oversight is strong enough.

A similar picture emerges in Australia and across Asia. Research by the Diligent Institute, the Singapore Institute of Directors and the Governance Institute of Australia found that 57% of organisations were already using AI in at least one part of the business, while 70% put digital transformation at the top of the 2026 board agenda. Yet 68% of respondents also identified digital skills as a critical development need for their own boards.[7](#fn-7)(See chart below.)

![Chart for inclusion in Article 2 of Series.png](https://storage.ghost.io/c/7a/6d/7a6d2077-bcbf-4f08-b8dd-5561ff13d53e/content/images/2026/09/Chart-for-inclusion-in-Article-2-of-Series.png)

Evidence suggests boards are starting to respond, but at very different speeds. Glass Lewis found that around seven in ten large European companies disclosed board-level oversight of AI during the 2026 proxy season, a sharp increase on the previous year. More than half of large European companies and over four in ten UK companies have an AI policy, compared with just 21% of the US Russell 1000.[8](#fn-8) The gap probably reflects the regulatory culture: Europe has pushed companies towards explicit AI governance, while US companies have so far been more likely to absorb AI into existing risk frameworks.

In the US, EY reports that just 5% of S&P 500 directors are described in proxy statements as having AI experience, up from 1% in 2022\. Only 17% of S&P 500 boards have created a dedicated technology committee; most have instead added AI and technology oversight to an existing committee, usually audit.[9](#fn-9) The SEC’s Investor Advisory Committee found a similar imbalance in 2025 filings: 60% of S&P 500 companies treated AI as a material risk, but only 15% disclosed any board oversight of it.[10](#fn-10)

What stands out in these surveys is the disconnect between adoption and capability. Organisations are embedding AI across businesses, and formal oversight is developing quickly, yet directors still do not feel fully equipped to oversee it.

## What is required

In the UK, the 2024 Corporate Governance Code makes the board responsible for monitoring risk management and internal controls, and from financial year 2026 for declaring whether material controls were effective. If AI sits within a material control, it is already the board's responsibility, whether or not AI is discussed as a separate topic.[11](#fn-11) For banks, the PRA brings AI and machine-learning models within model risk requirements: management designs and operates the framework, the board sets appetite, approves the policy and remains accountable.[12](#fn-12)

The EU AI Act requires organisations using high-risk AI to ensure proper oversight, monitoring, logging and competent people, but it does not require an AI expert, an AI officer or an AI committee, and the European Commission has confirmed that no particular governance structure is needed to meet its literacy obligation.[13](#fn-13)

The position is similar elsewhere. The SEC dropped a proposed requirement to disclose board cyber expertise in 2023 and asked instead how the board oversees the risk.[14](#fn-14) New York's financial regulator has since extended its requirement that governing bodies understand cybersecurity and be trained on AI-enabled threats and AI-related risk.[15](#fn-15) Singapore's proposed guidelines make boards responsible for AI risk appetite, governance and their own literacy.[16](#fn-16) In Australia, the AICD treats AI oversight as part of directors' existing duties.[17](#fn-17) The courts have not created a new duty either. As we saw in Part 1, the Delaware courts still ask whether the board put a reasonable reporting system in place and acted on what it heard.[18](#fn-18) In the UK, section 174 of the Companies Act 2006 still measures a director against the care, skill and diligence the role demands and the knowledge that director actually has.[19](#fn-19)

Regulators and courts are not demanding specialist AI seats, nor are they insisting on entirely new governance structures. Instead, the direction of travel is towards AI literacy across the whole board.

## The case for an expert

The strongest evidence for AI expertise on boards comes from MIT's Center for Information Systems Research. It found that the 26% of large US company boards it classified as digitally and AI savvy in 2024 (using a threshold of three or more savvy directors) delivered returns on equity 10.9 percentage points above their industry average, while the remainder were 3.8 points below.[20](#fn-20) Shareholders are focused on this too: Glass Lewis, one of the two leading proxy advisers used by large institutional shareholders, now assesses board oversight of AI and may recommend against directors where insufficient oversight or management of AI has resulted in material harm to shareholders and the board's oversight, response or disclosure is inadequate.[21](#fn-21) Technology committees are also becoming more common; 17% of S&P 500 boards now have one, and the National Association of Corporate Directors (NACD), the main US body for board members, has developed guidance to help boards decide whether they need a dedicated committee.[22](#fn-22)

Practitioners make a similar argument, usually in terms of capability rather than board structure. Shelly Palmer, a director of 1-800-Flowers.com, argues that every director now needs to be fluent in AI strategy, data ethics, and digital accountability, as part of their fiduciary responsibility.[23](#fn-23) Francesca Odell of the law firm Cleary Gottlieb makes a similar point: boards cannot contain specialist expertise in every subject they oversee, but directors still need to keep learning to challenge effectively. The law firm Debevoise & Plimpton, while setting out the arguments against appointing a designated AI director, also accepts that such an appointment may make sense where the right candidate brings both relevant experience and the broader qualities required of a good director.[24](#fn-24)

## Why the expert is likely the wrong answer

One issue is largely practical: few people combine deep AI expertise with the requisite experience to serve as a director, and those who do often have conflicts of interest, such as investments in AI companies or relationships with vendors, that need managing. If a board appoints an AI expert, it also invites the question of why there is no equivalent seat for cyber, for example.[25](#fn-25)

More problematic, it can change board dynamics and effectiveness. It increases the risk that other directors defer to the expert rather than stimulating diversity of thought and a willingness to challenge management, while also lessening the incentive for other directors to learn. Enron is an example: its audit committee was chaired by a former dean of Stanford's business school, had the expertise to understand what management put in front of it, yet did not challenge what it saw.[26](#fn-26) Nor is expertise a safe proxy for good oversight; the study cited in Part 1 found that financial expertise on bank boards was associated with greater risk-taking and worse performance in the 2008 Global Financial Crisis.[27](#fn-27) The advantage MIT's earlier work identified for digitally savvy boards in 2019 had disappeared by 2024, once 72% of boards had it, so expertise as a differentiator can decay.[28](#fn-28) Finally, regulators on three continents have declined to require an expert seat, and the SEC withdrew its proposed disclosure of board cyber expertise.[29](#fn-29)

## Literacy across the whole board

In practice, directors need to be comfortable discussing AI without becoming technical specialists. They should understand what a system is being used for, what data it was trained on, how much discretion it has been given, where human oversight sits, and who remains accountable for its decisions. The objective is not to turn board members into technologists; it is to ensure they can engage with AI as a business issue: recognising where it could create value or change strategy; considering how to forecast and track ROI; and identifying where it raises governance, ethical, accountability, or risk-management questions.

Regulators in Singapore and New York already expect board members to have this level of understanding. The EU AI Act also requires organisations to take measures to support AI literacy among staff who use these systems. If boards expect employees to understand the AI they use, they should meet the same standard themselves.

In the final part of this series, we turn to what that means in practice and signpost where our community can go to find the resources needed to support them on their AI-learning journey.

---

\*\* *Use of AI statement*

This article was written by Julia Warrander, its human author. AI was used to research background sources, to check quotations and figures against the original documents, and to compile the footnotes. It did not write the argument, the interpretation or any of the original editorial. The article was reviewed and edited by Peggy Curley, Chief Communications Officer, and approved for publication under the NEDness Editorial Policy.

**Sources**

1 Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act), Official Journal of the European Union, 12 July 2024\. [↩](#fnref-1)

2 OECD (2024) Explanatory memorandum on the updated OECD definition of an AI system, OECD Artificial Intelligence Papers No. 8\. ; Regulation (EU) 2024/1689 (Artificial Intelligence Act), Art 3(1). [↩](#fnref-2)

3 Department for Science, Innovation and Technology (2023) A pro-innovation approach to AI regulation, CP 815, section 3.2.1\. [↩](#fnref-3)

4 In re The Boeing Company Derivative Litigation, C.A. No. 2019-0907-MTZ (Del. Ch. 7 September 2021), discussed in Part 1 of this series. [↩](#fnref-4)

5 Bank of England and Prudential Regulation Authority (2023) Written evidence to the House of Commons Science, Innovation and Technology Committee inquiry into large language models, paras 23 to 24\. ; see also Prudential Regulation Authority (2023) Model risk management principles for banks, Supervisory Statement SS1/23, para 2.8, which states that model risk increases with model complexity and is higher for models that are difficult to understand or explain. [↩](#fnref-5)

6 WTW (2026) Global Directors' and Officers' Survey Report 2026: AI. [↩](#fnref-6)

7 (Diligent Institute, Singapore Institute of Directors and Governance Institute of Australia (2025) APAC Governance Outlook 2026, media release, 24 November. [↩](#fnref-7)

8 Glass Lewis (2026) 2026 Proxy Season Global Trends Part 2: Boards of Directors, August. [↩](#fnref-8)

9 EY Center for Board Matters (2026) 7 questions for boards after the 2026 proxy season. [↩](#fnref-9)

10 SEC Investor Advisory Committee (2025) Recommendation Regarding the Disclosure of Artificial Intelligence's Impact on Operations, approved 4 December. [↩](#fnref-10)

11 Financial Reporting Council (2024) UK Corporate Governance Code 2024, Principle O and Provision 29\. The declaration applies to financial years beginning on or after 1 January 2026\. [↩](#fnref-11)

12 Prudential Regulation Authority (2023) Model risk management principles for banks, Supervisory Statement SS1/23, Principles 1 and 2\. The statement applies to UK banks, building societies and PRA-designated investment firms with internal model approval; it does not apply to insurers. [↩](#fnref-12)

13 Regulation (EU) 2024/1689, Arts 4 and 26, as amended by Regulation (EU) 2026/1744 (Digital Omnibus on AI), in force from 27 July 2026, which defers the deployer obligations for Annex III high-risk systems to 2 December 2027 and rewrites Art 4 as a duty to take measures to support AI literacy. ; . European Commission (2025) AI Literacy: Questions and Answers, which confirms that no specific governance structure is mandated. [↩](#fnref-13)

14 Securities and Exchange Commission (2023) Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure, Release No. 33-11216, discussed in Part 1 of this series. [↩](#fnref-14)

15 New York State Department of Financial Services (2024) Cybersecurity Risks Arising from Artificial Intelligence and Strategies to Combat Related Risks, Industry Letter, 16 October. [↩](#fnref-15)

16 Monetary Authority of Singapore (2025) Consultation Paper on Guidelines on Artificial Intelligence Risk Management, P017-2025, 13 November. The Guidelines were still to be finalised at the time of writing. [↩](#fnref-16)

17 Australian Institute of Company Directors and UTS Human Technology Institute (2026) A Director's Guide to AI Governance, version 2, June. [↩](#fnref-17)

18 In re Caremark International Inc. Derivative Litigation, 698 A.2d 959 (Del. Ch. 1996); Marchand v Barnhill, 212 A.3d 805 (Del. 2019); both discussed in Part 1 of this series. Caremark set the duty: directors must make a good-faith effort to ensure a reporting system exists. Marchand is the Blue Bell case, in which the board of a Texas ice cream maker was alleged never to have heard about listeria in its plants before an outbreak killed three people. The Delaware Supreme Court let the claim proceed, holding that boards must make a good-faith effort to put in place a reasonable system for monitoring and reporting on the company's central compliance risks, and that regulatory inspection is no substitute. [↩](#fnref-18)

19 Companies Act 2006, s.174\. [↩](#fnref-19)

20 Weill, P., Woerner, S.L. and Banner, J. (2025) AI-Savvy Boards Drive Superior Performance, MIT Center for Information Systems Research, 8 December. ; also published in MIT Sloan Management Review. [↩](#fnref-20)

21 Glass Lewis (2025) 2026 Benchmark Policy Guidelines: United States, board oversight of artificial intelligence. The policy was introduced in the 2025 guidelines and carried into 2026\. [↩](#fnref-21)

22 National Association of Corporate Directors (2024) Technology Leadership in the Boardroom: Driving Trust and Value, Report of the NACD Blue Ribbon Commission, 7 October, including the tool Technology Oversight Structures: Is a Technology Committee Right for Your Board?. Available to NACD members. [↩](#fnref-22)

23 Kirsch, N. (2025) Five Technologies Directors Should Prepare to Engage with in 2026, NACD Governance Outlook, 10 December. Palmer and Odell are both quoted in this article. [↩](#fnref-23)

24 Gesser, A., Chandrasekhar, C., Juergens, E., Kaplan, M., Slutzky, S.J. and Regner, W. (2026) Board Oversight of AI: Do Boards Need AI Experts?, Debevoise & Plimpton, republished on the Harvard Law School Forum on Corporate Governance, 27 April. [↩](#fnref-24)

25 The practical objections, the effect on board dynamics and the conflicts point are set out in Gesser et al. (2026), above; the argument is the authors' own rather than a finding of a court or regulator. [↩](#fnref-25)

26 United States Senate, Permanent Subcommittee on Investigations (2002) The Role of the Board of Directors in Enron's Collapse, S. Prt. 107-70, 8 July. [↩](#fnref-26)

27 Minton, B.A., Taillard, J.P. and Williamson, R. (2014) Financial expertise of the board, risk taking, and performance: evidence from bank holding companies, Journal of Financial and Quantitative Analysis, 49(2), pp. 351 to 380, discussed in Part 1 of this series. [↩](#fnref-27)

28 Weill, Woerner and Banner (2025), above: 72% of large-company boards met the 2019 definition of digitally savvy by 2024\. [↩](#fnref-28)

29 Securities and Exchange Commission (2023), above. The proposed rule would have required disclosure of board members' cybersecurity expertise; the final rule did not. [↩](#fnref-29)