Articles

Exploring the board’s role in governance of AI and emerging technology (Blog)

LinkedIn
Image of a keyboard

Exploring the Board’s Role in Governance of AI and Emerging Technologies

 

In a recent Halex Consulting CoSec Forum, a group of 25+ leading company secretaries, GCs and governance professionals came together to explore the board’s role in governance of AI and emerging technologies.

Given the topic under discussion was AI, we decided to ask ChatGPT to write this blog based on a transcript of the discussion.

The result?  In our view, a solid B minus… but a ton of time saved.

We hope you enjoy the blog and do join us for our next CoSec Forum roundtable at 9am on Wednesday 11th September.  You can register for the event here or go to our Articles & Insights page.

Introduction

Artificial Intelligence (AI) has recently surged to the forefront of technological and corporate discussions, becoming a pivotal element in organizational strategies and operations. This blog summarizes the key points from a recent roundtable discussion that delved into the board’s role in governing AI and other emerging technologies.

The Explosive Growth of AI

Christopher Burt initiated the discussion by highlighting AI’s rapid emergence and its complex nature. Unlike traditional computing, AI systems are characterized by their adaptivity and autonomy, making them difficult to control and predict. Burt emphasized that AI’s ability to learn and make decisions independently sets it apart from conventional IT systems. This dual nature of adaptivity and autonomy means AI can produce different outputs from the same inputs, complicating its management and oversight.

Benefits and Risks of AI

The benefits of AI are vast, from improving breast cancer screening accuracy to discovering new medicinal uses for existing drugs. However, AI also poses significant risks, including potential abuses of human rights, such as deepfake technology and cybersecurity threats. Burt mentioned the example of UK Foreign Secretary David Cameron being scammed via a deepfake video conference, illustrating the real-world dangers AI can pose.

The UK’s Approach to AI Regulation

Burt outlined the UK Government’s stance on AI regulation, which currently does not include new legislation but places oversight responsibilities on existing regulators. These regulators will supervise AI based on five key principles:

  1. Safety, security, and robustness
  2. Appropriate transparency and explainability
  3. Fairness
  4. Accountability and governance
  5. Contestability and redress

Boards are expected to align their AI strategies with these principles to ensure ethical and effective use of AI technologies.

[Note: ChatGPT got this wrong.  It would be sensible for boards to incorporate these five supervisory objectives into their organisation’s AI policy.]

The Board’s Role in AI Governance

A central question of the roundtable was the board’s role in AI governance. Burt suggested several steps boards can take:

  • Blue Sky Discussions – Allocate time for open-ended discussions about AI and emerging technologies without the pressure of making immediate decisions. This allows for comprehensive understanding and strategic planning.
  • Develop an AI Strategy – Boards should develop a formal AI strategy that outlines the organization’s approach to AI, including risk appetite and ethical considerations. This strategy should be revisited regularly due to the rapid pace of technological advancements.
  • Assign Oversight Responsibilities – Designate a specific board committee, such as the audit, risk, or technology committee, to oversee AI initiatives. This ensures focused and informed oversight.
  • Inventory AI Systems – Create and maintain an inventory of all AI systems used within the organization. Understanding where and how AI is being used is crucial for effective governance and risk management.
  • Establish a Skunk Works or Innovation Lab – Implement a sandbox environment where AI can be safely experimented with. This allows the organization to explore AI applications without exposing core operations to undue risk.
[Note: Not bad but ChatGPT missed out a crucial step between (2) and (3).  The board should develop an AI policy based on the board’s AI strategy and risk appetite discussions.  The policy should incorporate the five supervisory principles, call out the principle risks associated with how the organisation plans to use AI and document the material controls over these risks.  The policy should also allocate clear accountabilities to executive management.  This policy should be revisited more frequently than other policies due to the pace of change in this area.]

Expertise and Education

A participant highlighted the necessity for boards to possess or acquire the requisite technological expertise. Many boards lack members with deep technical knowledge, which is essential for meaningful discussions and informed decision-making regarding AI. Options include recruiting new board members with technical expertise or engaging external advisors.

Another participant added that while having tech-savvy directors is beneficial, it can sometimes lead to over-reliance on those individuals, underscoring the need for a balanced approach where all board members are adequately educated about AI.

[Note: We are talking with several boards at the moment about AI governance and risk management and what practical steps their organisations should be taking.  Please feel free to get in touch if you would like to have a quick chat about what steps your board/organisation should be taking.  You can schedule a quick call here. ]

Practical Applications and Concerns

The roundtable also touched on practical applications of AI in board operations, such as using AI to draft board minutes. While AI can assist in summarizing discussions, it currently lacks the nuance required for producing comprehensive and accurate minutes. A participant shared an example where AI tools like Copilot could reduce the workload but emphasized that final minutes would still need human review to ensure accuracy.

Ethical and Legal Considerations

Ethical considerations are paramount in AI governance. The Chartered Institute for Securities & Investment (CISI) offers certifications in ethical AI, reflecting the growing importance of ethics in AI deployment. Boards must also navigate legal complexities, such as data privacy and the implications of recording meetings, as highlighted by discussions around AI-generated minutes and data security concerns.

Conclusion

The roundtable concluded with a consensus on the critical role boards play in AI governance. By fostering informed discussions, developing robust strategies, ensuring ethical use, and continuously educating themselves, boards can navigate the complexities of AI and leverage its potential while mitigating risks. As AI continues to evolve, so too must the governance frameworks that oversee its integration into organizational operations.

 

Chris Burt,

Principal of Halex Consulting

Co-founder, Principal Author and Chair of the Risk Coalition

Chris is a CGI Accredited board reviewer and Principal at Halex Consulting, a leading boutique governance consultancy specialising in independent board evaluations and risk management advisory services.  He is also a co-founder and Chair of the Risk Coalitiona not-for-profit, risk management think tank that aims to improve the effectiveness of risk management practice in the UK and globally. 

Chris is the principal author of the Risk Coalition’s internationally acclaimed, ‘Raising the Bar’ leading practice guidance for board risk committees.  He also Chairs the Risk Coalition’s Risk Committee Chairs and CROs forums, joint Risk Coalition/ISACA Tech Risk SIG and Halex Consulting’s own CoSec Forum for company secretaries and governance professionals. 

Chris speaks regularly on risk and governance-related topics.

Other posts you might like…

Speak with a member of our team. We’re always happy to talk.