What Your Board Actually Needs to See in an AI Risk Report
Harvard Law School research of 50+ board directors found most boards rarely or never use AI to fulfil board responsibilities. AI governance needs to be a standing agenda item, not an occasional briefing.
What the Harvard Research Found About Boards and AI
Harvard Law School Forum on Corporate Governance published research in February 2026 drawing on focus groups with more than 50 board directors. The finding that should concern every company secretary and risk executive: most boards rarely or never use AI themselves to help fulfil board responsibilities. This is not primarily a technology adoption problem. It is a structural governance problem: boards have not been given the right information, in the right format, at the right frequency to exercise meaningful AI oversight. The occasional AI briefing from the CTO is not board-level AI governance. It is a technology update.
Why AI Should Be in Every Board Discussion
The Harvard research argues AI's impact on strategy, talent, and risk means it should surface in every board discussion — not only as a stand-alone agenda item. This reframes AI oversight from a specialist topic to a mainstream governance obligation. The risk committee needs to see AI-related operational risk alongside traditional operational risk categories. The audit committee needs evidence that AI controls are being tested. The remuneration committee needs to understand whether AI-driven decisions affect compensation outcomes. The nomination committee needs to consider whether the board itself has adequate AI literacy. Each committee should have its AI oversight responsibilities clearly defined in its charter.
What a Useful AI Risk Report Contains
Based on the Harvard research and comparable governance frameworks, a board-level AI risk report should contain six elements. First, a live AI estate summary: how many AI systems are in operation, how many are in development, how many are unclassified. Second, risk appetite status: which AI risks are currently within appetite, which are beyond appetite, and who owns the acceptance of each beyond-appetite risk. Third, obligation status: how many compliance obligations are open, in progress, evidenced, and met across all applicable frameworks. Fourth, control health: how many controls are rated effective, impaired, or untested. Fifth, incident summary: AI-related incidents and near misses in the period, with root-cause status. Sixth, maturity movement: governance maturity scores across key domains, with movement since the last report.
From Occasional Briefing to Standing Evidence
The structural change the Harvard research recommends is moving from occasional AI briefings to standing, evidenced agenda items. This requires two things that most boards currently lack: a governance program that produces continuous evidence (not point-in-time documentation prepared for the meeting) and a reporting format that presents AI governance status in the same language the board uses for other enterprise risk categories — appetite, exposure, control, and assurance. Leading boards are already using governance data for scenario generation, reviewing AI-related competitor disclosures, and benchmarking their own governance maturity against industry standards.
Wahid AI's Maturity Assessment & Steering module gives boards the structured, recurring visibility the Harvard research says most currently lack. Six live executive lenses cover appetite status, risk exposure, obligation evidence, control health, and maturity movement — exportable as board-ready audit packs. AI governance becomes a standing, evidenced agenda item rather than an occasional technology briefing.
RELATED TOPICS
Ready to operationalise these governance frameworks?
Wahid AI integrates ISO 42001, EU AI Act, NIST AI RMF, and APRA CPS 230 into one governed workflow. See it in a 30-minute demo.