Ask three directors on the same board which committee owns AI oversight and you will hear three answers. The audit committee will say it belongs there, because AI touches financial reporting and internal controls. The risk committee will say it belongs there, because model risk is risk. The technology committee, if one exists, will say the same thing about technology. Each is right about part of it. None is right about the whole.
The confusion is not a failure of committee design. It is a symptom of the deeper problem this book keeps returning to: the org chart was drawn for a world where work traveled through people and roles before it reached anyone outside the organization. Board committees were drawn against that same map. They divide oversight by discipline — audit, risk, technology, compensation, nomination — because they were built to oversee organizations where the work fit inside those disciplines.
AI does not fit inside those disciplines. It moves across all of them, sometimes in the same case file.
The committee that owns AI is not the committee that has ‘AI’ in its charter
The mistake most boards make is to look for the committee whose charter contains the word AI or model or algorithm and hand oversight there. The instinct is understandable. It is also wrong, because it treats AI as a technology category rather than as a change in how the organization speaks and decides.
The right question is not “which committee owns the technology.” It is “which committee is answerable when the company acts, at the speed AI enables, in a way it cannot fully explain?” That is not a technology question. It is a governance question about ownership at the point where the company’s output becomes consequential to someone outside it.
Answering that question requires the board to look at three committees at once and decide, deliberately, what each of them owns.
What audit committees actually own
The audit committee owns the integrity of what the company reports — to shareholders, to regulators, to the public. When a variance explanation is generated by a model and adopted into the finance packet, the audit committee is not overseeing a technology. It is overseeing whether the language the company puts its name on is faithful to the underlying facts. That is a classic audit-committee question. It has not changed. What has changed is that some of the language is now formed by systems the committee’s usual controls were not designed to inspect.
A useful audit-committee reset is narrow: extend the definition of “material communication” to include any output that shapes what the board or the market believes. Ask whether the pipeline that produced it — prompt, retrieval, template, review — is subject to the same standard of documentation as any other material control. Do not try to make the audit committee the AI committee. Make it the committee that verifies the sentences.
What risk committees actually own
Risk committees have absorbed model risk for a decade. They know how to inventory models, tier them by materiality, require validation, and expect challenger frameworks. That work is still necessary. It is also insufficient for AI in its current form.
Traditional model risk assumes the model produces a number and a human decides what to do with the number. Generative and agentic AI collapse that boundary. The model produces the recommendation, the language of the recommendation, and often the record of what the reviewer did with it. Risk committees that continue to focus only on model performance will oversee the accuracy of the input while missing the fidelity of the output — the sentence that reaches the customer, the summary that reaches the reviewer, the ranking that reaches the manager.
The risk committee’s new work is not to own AI. It is to expand the frame of model risk to include what the model changes in the humans who receive its output — pace, framing, apparent authority, the difficulty of a slow answer inside a fast queue. That expansion is where the committee’s existing muscles do the most good.
What a technology committee actually owns
Most boards do not have a standing technology committee. Those that do tend to use it as a strategy forum — architecture, roadmap, spend. That is a defensible use. It is not oversight.
If the board decides to formalize a technology committee (or a data-and-technology committee, or an AI committee) for the AI era, the committee’s remit is best defined narrowly: capability, resilience, and the design integrity of the systems the company relies on. It owns whether the platforms can do what management says they can. It does not own whether they should. That distinction is the source of most cross-committee friction.
The one that is often missing
Notice what none of the three committees has been asked to own so far: what the company does to a person once a decision has been made and the language has traveled.
This is the terrain the book calls the Human Point of Consequence — the place, outside the company, where reliance meets an actual life. A denial that arrives cleanly. A ranking that shapes a career. A safety summary that closes a file. Oversight of that terrain does not fit inside audit, risk, or technology as they are usually chartered. It requires a committee — or a designated part of an existing committee — whose job is to look at what the company’s outputs cost the people who receive them, and whether the design of the work protects the human who is asked to review those outputs at speed.
Some boards create a public-responsibility or ethics committee for this. Others assign it to the risk committee as a distinct workstream, so it does not disappear inside model risk. The naming matters less than the assignment. What matters is that the board can point to a committee whose specific work is oversight of consequence, not of the tool.
A workable division
For most boards, a serviceable division of labor looks like this:
- Audit committee: fidelity of company language and reported facts. Any AI output that reaches a material audience is inside scope.
- Risk committee: model risk, expanded to include how AI changes the humans who receive its output — pace, framing, apparent authority, review-time economics.
- Technology or data committee (if it exists): capability, resilience, and design integrity of the underlying systems. Not the decision to use them.
- A named owner of consequence — a distinct committee, a chartered workstream, or a lead director — whose job is oversight of what happens outside the company as a result of what the company’s systems say and do.
- Full board: strategy and speed. Whether the pace of adoption matches the organization’s capacity to remain answerable at the point of consequence.
The reason to make this division explicit is not tidiness. It is that in most companies, oversight of AI today is happening by inference. Three committees each assume one of the others is asking a question none of them is asking. The board learns this only after a letter has gone out in the company’s name and a director has to explain, to a regulator or a reporter, who decided the company should speak that way.
The committee that owns AI is not the one with the newest charter. It is the one the board can point to, in advance and out loud, before the sentence travels.
This essay draws on Interlude I and the governance material in the Executive Field Guide of AI in the Org Chart.