Tag: Decision Rights

  • Governance by AI: The Next Corporate Governance Challenge

    Governance by AI: The Next Corporate Governance Challenge

    Corporate governance has always been built around one core assumption: companies are run by people.

    Shareholders appoint directors. Directors oversee executives. Executives manage teams. Teams deliver the work. Governance systems, board papers, delegated authority, audit trails, risk registers and accountability frameworks all assume that human beings make the important decisions.

    Artificial intelligence is beginning to challenge that assumption.

    Most current discussion focuses on AI governance: how organisations should use AI responsibly, safely and ethically. That is important, but it is not the whole issue. A deeper challenge is now emerging: what happens when AI does not simply support management, but becomes part of the management system itself?

    This is the shift from governance of AI to governance by AI.

    AI systems can already analyse markets, generate forecasts, assess risks, screen customers, monitor cyber threats, recommend suppliers, automate workflows and support strategic decisions. As autonomous agents develop, they will increasingly be able to initiate actions, make recommendations, execute decisions and adapt processes with limited human involvement.

    That creates a new governance problem.

    The question is no longer only:

    How do we make sure AI is safe and responsible?

    It is also:

    How do we govern an organisation when AI is making or influencing material business decisions?

    This is where the concept of delegated machine authority becomes important. Delegated machine authority occurs when a business gives AI systems decision rights that would previously have belonged to people. This could include approving transactions, reallocating resources, changing prices, prioritising customers, flagging risks or triggering operational actions.

    The risk is not that AI suddenly becomes a legal director. It does not. Human directors and officers remain accountable. The risk is that practical decision-making moves into AI systems while formal accountability remains with humans who may not fully understand, monitor or control those systems.

    This creates what can be called the Autonomous Governance Gap: the gap between governance systems designed for human managers and organisations increasingly managed through autonomous AI systems.

    To close that gap, boards will need a new governance framework. This should include seven core elements.

    First, companies need an AI decision-rights architecture. Boards must define what AI may analyse, recommend, decide or execute, and which decisions must remain human-only.

    Second, there must be a clear human accountability chain. Every AI system with material influence should have a named human owner, executive sponsor and board oversight route.

    Third, organisations need decision provenance: a corporate “black box” recording what the AI decided, what evidence it used, what alternatives were considered, who approved it and what happened afterwards.

    Fourth, AI-managed activity requires continuous assurance, not just annual review. Boards need live visibility of performance, drift, risk, compliance, cyber exposure and unintended consequences.

    Fifth, AI decisions must remain aligned with corporate purpose, stakeholder duties and risk appetite. Optimisation is not the same as judgement.

    Sixth, there must be meaningful human intervention rights: pause, override, escalation and shutdown mechanisms.

    Finally, AI governance must adapt as models, data, agents and business processes change.

    The next generation of corporate governance will not be about replacing boards with AI. It will be about ensuring that boards remain capable of governing companies where AI has become part of management.

    That is the real governance challenge ahead.