AI Is Now the Audit Committee's Problem
AI Is Now the Audit Committee's Problem
This article reflects BoardSight's analysis and is not legal advice. Regulatory facts were verified against primary sources on 2026-07-22.
The Uncomfortable Opening
Here's a question for your audit committee chair: What's on the AI risk register?
If the answer is "We don't have one," or "We're not sure," or "AI is an operational issue, not an audit issue" — you have a governance gap worth closing.
Audit committees can no longer treat AI as someone else's problem. Three forces converged in 2025-2026 that put AI on the fiduciary plate.
The Three Converging Pressures
1. EU AI Act Enforcement
The EU AI Act's prohibitions took effect 2 February 2025 and its general-purpose AI obligations on 2 August 2025. Obligations for stand-alone high-risk systems (Annex III — employment, biometrics, critical infrastructure, education, migration, and more) now apply from 2 December 2027, moved back from the originally cited August 2026 date by the 2025 Digital Omnibus; product-embedded high-risk systems follow on 2 August 2028. These duties fall chiefly on deployers under Article 26 (human oversight, monitoring, logging, worker notice) — the Act does not mandate a single named "governance body," but meeting Article 26 in practice requires an accountable internal oversight function. This is not optional for companies with EU exposure.
The enforcement mechanism is real, and tiered under Article 99: up to €35 million or 7% of worldwide turnover for prohibited-practice breaches, and up to €15 million or 3% for breaching high-risk and other obligations. (The single "6% of global revenue" figure sometimes quoted is not accurate.) At that scale, a serious breach is a capital event.
Audit committees are a natural home for this oversight. They own governance, audit, and internal controls — this is their wheelhouse.
2. SEC Disclosure
There is no dedicated SEC AI-disclosure rule — neither adopted nor formally proposed. What exists today: the SEC's existing materiality-based disclosure obligations already apply to AI-related risks, the agency has brought "AI-washing" enforcement actions against misleading AI claims, and a rulemaking petition (File No. 4-882) requests a dedicated AI-governance disclosure rule. Treat AI disclosure as an application of current materiality rules — not as a new mandate that has already been adopted.
"Material" means anything that could affect a reasonable investor's decision. For many companies deploying AI at scale, AI risk is capable of being material — and the audit committee owns disclosure controls.
3. Caremark Duty — the Argument, and Its Limits
Delaware's Caremark line (Marchand, 2019; Boeing, 2021) holds that directors can face liability for failing to establish systems to monitor "mission-critical" risks. A credible argument — and it is BoardSight's analytical view, not a settled Delaware holding specific to AI — is that a material AI deployment can rise to "mission-critical" for a given company, such that directors should maintain a monitoring system:
- Revenue-critical: AI that drives pricing, recommendations, or customer decisions.
- Compliance-critical: AI that makes regulated decisions (hiring, lending, benefits).
- Safety-critical: AI that affects physical safety.
Whether AI is "mission-critical" is a fact-specific question decided case by case; no court has declared AI categorically mission-critical for all companies. The defensible posture is process: establish a monitoring system and act on red flags.
Why Audit Committees Have Been Slow on AI
Fuzzy boundaries (business risk or audit issue?), technical unfamiliarity, and a lack of concrete governance tools compared with financial controls (COSO ERM). Understandable — but no longer a defensible reason for inaction where AI is material.
Where AI is material, inaction on AI governance is hard to defend.
What "AI Is an Audit Committee Problem" Actually Means
Not that members must understand neural networks — but that the committee should: own the governance inventory of material AI systems; ensure second-line assurance (compliance, fairness, regulatory-alignment review) over first-line operations; escalate red flags to the full board; and confirm governance adequacy — "do we have the systems, reporting lines, and escalation protocols for a material AI deployment?", backed by a risk register.
What to Change (In Your Next Meeting)
- Do we have a complete inventory of material AI systems — those affecting revenue, compliance, or safety?
- Is someone explicitly accountable for second-line AI governance — a named person and title?
- Do we have a risk register that exists, is maintained, and is reviewed?
- Have we documented our oversight process (charter language or a board resolution)?
- Have we mapped AI deployment to the EU AI Act — which systems are high-risk under Annex III, and are they governed?
If the answer to any of these is "no," you have a documented governance gap worth closing before it becomes a liability question.
The Inaction Trap
If the committee does nothing and an AI incident later occurs, that inaction can become evidence of a monitoring failure. If the committee establishes governance systems (imperfect as they may be) and responds to red flags, the board has a process defense. Caremark is about process, not perfect outcomes.
Three Concrete Steps
Step 1: Request an AI Systems Inventory (30 days) — name, business unit, function, decision impact (advisory vs consequential), regulatory exposure. Step 2: Confirm Second-Line Accountability — get a name, prepared to present quarterly. Step 3: Schedule a Risk Register Presentation — even a draft forces a concrete governance conversation.
The Bottom Line
AI touches all three lines — operational (first), compliance and fairness (second), and assurance (third). Where it is material, the audit committee has a real role. The question is how deliberately the committee acts.
Sources: Regulation (EU) 2024/1689, Articles 26 & 99 and the 2025 Digital Omnibus timeline (European Commission); Marchand v. Barnhill, 212 A.3d 805 (Del. 2019); SEC rulemaking petition File No. 4-882. Verified 2026-07-22. Not legal advice.