In February 2025, Deloitte's Global Boardroom Program closed the second edition of its AI governance survey: 695 board directors and executives, across 56 countries. The headline result read like relief — the share of boards with no AI on the agenda dropped from 45% to 31% compared with the prior edition.
But "on the agenda" and "having visibility into what's actually happening" are two different things. A Gartner survey of non-executive directors, released in late 2024, found that 80% of them believe their own board's current structure is inadequate to oversee AI. And the most recent survey from the National Association of Corporate Directors, NACD, shows 62% of boards now setting aside agenda time for the topic — but only 27% have formalized that oversight inside a committee's charter.
The straightforward reading: most boards already talk about AI. Few can actually oversee it. And the reason is rarely lack of interest — it's that no one has brought into the room the numbers that would make oversight possible.
For boards of Brazilian and Latin American companies, the same gap tends to weigh more, not less. Data-protection laws already require retention, access, and decision trails for personal data; when AI enters that flow without an equivalent control, the board inherits an exposure no meeting minutes will resolve on their own. The starting point isn't a new policy — it's the same question already asked of any other material risk: how is this measured, how often, and who is accountable for each number.
AI Talk Is Not AI Oversight
A board oversees credit risk because a quarterly report exists with delinquency, concentration, and coverage figures. It oversees information security because a committee exists with incident indicators. Overseeing AI by discussing... what, exactly?
In practice, the AI item on the agenda is usually a strategy presentation: where the company wants to go, which projects launched, what competitors are doing. That's a worthwhile conversation — and, at most companies, it's the only one. Few of these discussions reach an operational report with a verifiable number: how many people use AI, with what information, under what authorization.
That vacuum helps explain Gartner's 80%. It isn't that directors see the technology as too dangerous; it's that the reporting structure behind every other risk oversight function simply doesn't exist yet for AI at most companies. NACD's data makes the same point from the other side: 62% already talk about the topic regularly, but only 27% tied that conversation to a committee with formal responsibility — the difference between an agenda item and something actually under supervision.
That difference shows up first when something goes wrong. In a credit audit or an information-security investigation, the responsible committee already has the report ready — because the report is routine, not an exception. With AI, at most companies, the question "who authorized this" still depends on reconstructing a conversation nobody saved anywhere.
Why the License Report Fails

The most common answer when a board asks for visibility is an adoption report: how many licenses of a given tool were purchased, how many teams were trained. It's a real number — and it's the wrong one.
It says nothing about the use that happens outside those licenses, in personal accounts, with company information inside them. It says nothing about what is actually being spent per conversation, task, or department. It says nothing about how many risk-bearing decisions passed through some form of human approval before going out. And when something goes wrong, it says nothing about where to reconstruct what happened.
The reason is structural: a license is purchased by a department; AI use happens per person, per system, per piece of information accessed. Those are different units of measurement. However thorough it is, a purchasing report will never turn into a usage report.
There's also a quiet cost to this mismatch: while the board reads adoption numbers, risk and finance teams remain without visibility into that same usage — each one seeing only the slice its own tool happens to capture.
What has to be in place
An AI dashboard a board can actually use depends on mechanisms built into the work environment by design, not on a manual survey put together the night before the meeting.
Corporate identity as the starting point. When AI access comes from the same directory that controls email and internal systems, "who used what" stops being an IT archaeology question and becomes a direct report — because an employee's departure and the loss of access happen at the same moment.
Access by each person's role. Without it, "who could access that piece of information" has no reliable answer — anyone with AI access would, in theory, have access to everything it reaches.
Human approval based on risk. Actions and documents with real impact potential pause before going out, right inside the conversation, with a record of who approved them. It's the number almost no board can cite today: how many risk decisions went through that step this quarter.
An audit trail by area. Creating an agent, approving a piece of content, changing a permission — all logged and searchable. It's the difference between reconstructing an incident in minutes and depending on whoever happened to remember what was in the room.
Visible cost per use. Not a single monthly invoice, but spend tied to conversation, task, and department — the basis for any return-on-investment conversation the board will eventually want to have.
This is how Skyller was designed: identity coming from the company's own directory, with approval and an audit trail as the environment's default, not as a report produced on request.
What Changes When the Number Exists

With those mechanisms in place, the report that today is nearly impossible to produce becomes something read in five minutes: how many people use AI, in which areas, with what information, how many decisions went through human approval in the period, and how much was spent.
That changes the conversation in two directions. For leadership, it's the difference between believing the AI function is under control and showing it with a reproducible number — the kind of evidence regulators and auditors already demand of other risk areas. For the board itself, it's the difference between debating technology, a subject for which, as Gartner's own data shows, most directors don't feel prepared, and debating a risk report, a format every board already knows how to read.
The reverse is also true: without those numbers, any AI policy approved in the minutes becomes a promise with no way to check whether it's being kept.
There's also an effect on the board's own composition. Deloitte's survey shows boards rethinking who sits at the table because of AI — seeking directors with more technology fluency. A dashboard with concrete numbers reduces that pressure: overseeing a risk report doesn't require every director to be a specialist in the technology behind it, any more than overseeing credit risk requires the board to know how to code a scoring model.
Four Questions for the Board Agenda
Before the next meeting where AI is on the agenda, these four questions separate a strategy discussion from real oversight:
- How many people, today, have access to AI at the company — and through which login? If the answer doesn't come from the same directory that controls every other system, the number is incomplete by definition.
- How much was spent on AI last quarter, and at what level of detail? A single invoice per vendor isn't an answer; spend broken down by area or task is.
- How many risk decisions went through human approval before going out? Without a numeric answer to that, there's no way to know whether the policy approved in the minutes is actually in force.
- If an AI-related incident happened today, how long would it take the team to reconstruct what occurred? With an audit trail, minutes. Without one, it depends on who remembers.






