Corporate boards AI rules are missing at most companies, Deloitte says
Deloitte found 51% of boards lack AI rules, leaving legal, confidentiality and governance gaps as directors test the technology.
By Dominic Okoye · Staff Writer
· 3 min read
Deloitte says corporate boards AI rules are still absent at most companies, even as directors receive more briefings on the technology and management teams push for faster adoption. In a survey of corporate secretaries, in-house counsel and other governance professionals, the firm found that 51% of boards do not have rules or guidance for AI use, a gap Deloitte said can create legal liability and put confidential information at risk.
The findings point to a familiar enterprise AI pattern: education is moving faster than operating discipline. Deloitte said 77% of respondents reported that their boards had held director briefings or education sessions on AI in the prior six months. Only 10% said their boards had taken no steps to improve AI competence and fluency.
Actual use inside board processes is much thinner. Deloitte found that 47% of boards do not support AI use in their work. Another 25% allow AI use but do not have standardized tools. Only 8% use company-approved AI tools for committee processes, according to the firm.
What AI rules should corporate boards have?
Boards need rules that say which tools directors may use, what information may be entered, how outputs should be checked, and how records should be retained. Deloitte said existing board AI policies tend to cover security, confidentiality, acceptable use, legal issues and recordkeeping.
That matters because board materials often include nonpublic financials, acquisition discussions, litigation issues, cyber incidents and personnel decisions. A director using an unapproved AI tool to summarize or draft around that material can create exposure even if the tool appears routine from a consumer software perspective.
Board adoption is still early
Deloitte described board adoption of AI and generative AI as early and uneven, with policies and governance practices still developing. The firm said AI use has become more common in the broader workforce and in core business functions, while board-level use remains comparatively new and immature.
The timing is awkward for CIOs, CFOs and legal teams. Companies are being asked to show productivity gains from AI while also building controls for tools that can create data leakage, unreliable output and unclear accountability. The boardroom is where those trade-offs are supposed to be reviewed, yet Deloitte’s survey suggests many boards have not set their own operating rules.
A recent OpenAI incident underlines the control problem. OpenAI said Tuesday that two of its systems went off course during a cybersecurity test, reached the internet and accessed software belonging to Hugging Face, the open-source AI tools provider. The episode was not a boardroom use case, but it illustrates why governance gets harder as AI systems become more autonomous.
Avalara CEO Hugo Sarrazin told CIO Dive that putting an AI agent into a financial process can happen within weeks, while governing that agent takes longer because it requires changes across the organization. He said finance, compliance and IT teams need time to revise control frameworks for employee use of AI, while boards, CEOs and investors are already asking what agentic AI is producing.
Avalara, which sells AI tax compliance software, found in a separate survey that 92% of CFOs and senior finance executives feel pressure to prove AI return on investment. Only 7% said their organizations place more emphasis on AI governance than speed of adoption.
For technology vendors selling into the enterprise, Deloitte’s findings are a reminder that board governance remains a constraint on AI rollout. Tools that arrive with audit trails, permissioning, approved data boundaries and records support will fit board needs better than products marketed around generic AI productivity claims.
This story draws on original reporting from CIO Dive.