A board that has never had to ask "where does this model's training data come from" is about to be asked to oversee a system built on one. Gartner's 2024 survey of 328 non-executive directors found 91 percent view AI primarily as an opportunity for shareholder value, and 80 percent simultaneously admit their board's current practices and structures are inadequate to oversee it. Boards are enthusiastic about a technology they are not yet equipped to govern, which is exactly the setup that produces expensive surprises.
This article is grounded in current advisory work, not retrospective analysis. Mark Lynd is a 5x CEO/CIO/CISO with Thinkers360 Top 10 global rankings across Cybersecurity and Artificial Intelligence and was ranked #1 globally in Cybersecurity in 2023. He is currently Head of Executive Advisory and Strategy at Netsync, advising enterprise C-Suites and boards on the AI and cybersecurity questions moving fastest in 2026. The frameworks and patterns referenced here are from active engagements this quarter.
Risk categories that did not exist five years ago
Traditional cyber oversight asks whether the perimeter holds, whether patching is current, whether incident response works. Those questions still matter, but AI systems introduce risk categories that do not map cleanly onto that vocabulary, and a board using only the old questions will miss them entirely.
Shadow AI is the clearest example. A 2026 report from Optro, titled "The AI Oversight Gap," found that 80 percent of organizations report moderate to pervasive use of AI tools that were never formally approved, with 35 percent describing that use as pervasive or widespread outright. Only 25 percent of organizations have comprehensive visibility into how employees actually use AI day to day, 53 percent have only partial visibility, and 21 percent have limited visibility or none. Employees are pasting customer records into consumer chatbots to draft emails faster, and in three out of four organizations, nobody with governance responsibility can say how often that happens.
The consequences are not hypothetical. The same Optro research found 40 percent of organizations reported inaccurate AI outputs causing problems in the past year, 33 percent reported policy violations, 28 percent reported customer complaints, 27 percent reported data breaches tied to AI use, 26 percent reported regulatory action, and 22 percent reported legal claims. Separately, ISACA's 2026 research found that 25 percent of organizations have no active AI policy at all. A quarter of organizations are running this exposure with no governing document in place.
Vendor risk that hides inside a familiar-looking contract
The second new category is third-party AI risk, and it is easy to miss because it often arrives wrapped in a vendor relationship the organization already trusts. Model risk sits alongside it, and it is subtler still. A traditional software vendor ships a version, the organization tests it, and the behavior is stable until the next release. A vendor's AI model can change behavior between two ordinary Tuesdays because the underlying model was retrained, fine-tuned, or swapped for a newer version behind the same API, with no version number the customer ever sees. A board used to thinking about vendor risk as a point-in-time due diligence question needs to understand that with AI vendors, the thing being assessed keeps moving after the assessment is done. A CRM vendor adds a generative AI feature. A document management platform starts training suggestions on uploaded files. The procurement relationship looks unchanged, but the data flow underneath it has changed completely, often without a new contract review.
Venminder's 2025 State of Third-Party Risk Management survey found 49 percent of organizations experienced a third-party cyber incident in the past 12 months, and among those, 40 percent had added contract language specifically addressing AI risk in response. That is a reactive number, not a proactive one. Most organizations are amending contracts after an incident forces the question, rather than asking it during procurement. A board should want to know whether AI-specific vendor terms, covering what the vendor's model can be trained on, where outputs are logged, and who is liable when the model is wrong, are a standard clause before signature or an afterthought bolted on after the vendor already has the data.
A worked example
A regional healthcare system I advised this year rolled out an AI-assisted scheduling and intake tool from an established software partner. The security review focused on the usual things, network access, data encryption, SOC 2 status, and the vendor passed cleanly. Nobody on the review asked what happened to patient intake notes once the model processed them. It turned out the vendor's AI feature, added after the master agreement was signed, retained a rolling window of interaction data on a shared infrastructure layer used across all of the vendor's customers, for model tuning purposes described only in a separate, updated terms-of-service document that procurement never re-reviewed. Nothing here was a hack. It was a governance gap between the security review process, which was thorough, and the AI feature's data handling, which nobody had assigned to anyone to check. The fix was not more security controls. It was adding one explicit question to every vendor renewal, what does this vendor's AI do with our data now that it did not do when we signed, because vendors add AI features faster than customers re-review contracts. The broader lesson generalizes well beyond healthcare. Any organization that treats vendor security review as a one-time gate at signature, rather than a standing question revisited whenever a vendor announces a new feature, has a governance process built for a world where software changed slowly. AI vendors do not live in that world anymore, and neither should the review cadence built to watch them.
The strongest case against a separate AI governance track
The obvious objection is that creating a distinct "AI risk" oversight lane duplicates existing cyber, data privacy, and vendor risk governance, and that a board already stretched thin on cyber oversight cannot sustain a second, parallel track without diluting attention from both. This argument has real weight. Gartner's data on board time allocation shows directors already believe existing cyber practices are under-resourced, and stapling a new category on top without added expertise or added meeting time just spreads the same attention thinner. The stronger response is not to build a separate AI committee, but to fold these specific questions, shadow AI visibility, vendor AI data terms, and policy coverage, directly into the existing cyber risk reporting cadence, so the board is asking about AI risk inside the same 30 minutes it already has, rather than carving out new time it does not have. Where this argument wins outright is at organizations with no active AI policy at all. There, the honest answer is that oversight cannot be folded into an existing track because there is no track to fold it into, and the first step has to be writing the policy before the reporting cadence can even begin.
Monday questions for leadership and the board
Do we know, with actual data rather than a guess, how many employees are using AI tools we have not approved. Does every vendor contract renewal include a specific question about what that vendor's AI does with our data, and has that question changed since we last signed. Do we have an active, written AI policy at all, and if not, who owns writing one and by what date. When an AI system gives a wrong answer that reaches a customer or a regulator, do we know who is accountable, the vendor, the employee who used it, or the executive who approved the tool. Is AI risk showing up as its own line item in board reporting, or is it still invisible inside a general technology update.
The organizations that get hurt by AI are rarely the ones being reckless. They are the ones assuming their existing governance already covers a technology that changed the questions.