According to McKinsey's State of AI survey, only 28% of companies say the chief executive takes direct responsibility for AI oversight — and just 17% put that responsibility on the board. That's a gap of more than two out of three companies with no clear owner for the most basic governance question: who answers for this internally?

A Deloitte survey of 700 directors and senior executives across 56 countries, run between January and February 2025, shows both sides of that gap. Two-thirds of directors (66%) say they have limited or no knowledge of AI. And nearly a third (31%) say the topic simply isn't on the board's agenda — an improvement from 45% in the same survey's prior round, but still a high number for a technology already present in nearly every company.

For decision-makers, the interesting question is no longer "does an AI policy exist here." It's a different one: when the committee meets, what does it actually have to review? A report written by whoever did the work is opinion. A record that any outside party can check is evidence. That difference decides whether AI oversight is real or theater.

A committee with nothing to review

The governance-structure numbers are climbing. The 2026 AI Index, from Stanford University's human-centered AI institute, measured that dedicated AI governance roles grew 17% in 2025, and that the share of companies with no AI policy at all fell from roughly a quarter to 11% of surveyed organizations. The same report found that 36% of companies already cite the ISO/IEC 42001 standard as a reference for their own responsible AI practice, and 33% cite the NIST risk-management framework, from the US technology agency.

Those numbers describe paperwork, not verification. NIST's framework for AI risk management has an entire function dedicated to this, called GOVERN, and it doesn't just ask for a signed policy. It asks that roles and lines of communication be documented and clear to every team, that mechanisms separate whoever builds an AI system from whoever tests it, and that the people responsible hold real authority and resources to act — not just a title on an org chart.

That's where most companies stop. Writing the policy answers the question "does a policy exist" — and Stanford's index shows that number climbing fast. Documenting the separation of duties, building the record that lets someone check later, and giving real authority to whoever sits on the committee: none of that shows up in any survey as a rising number, because most companies haven't gotten there yet.

In Brazil and Latin America, the same pattern repeats at a smaller scale. AI committees emerged over the past two years inside compliance, information-security, or legal teams — usually with no dedicated budget and no authority to demand more than a verbal account from whoever used the tool. The gap surfaces the moment an outsider — an auditor, a regulator, a large client — asks how that policy was verified. That's when the committee finds it has no answer, because it never had anything to consult.

Why a policy alone isn't enough

Why a policy alone isn't enough

Two international standards reach the same conclusion by different routes. NIST's framework separates whoever builds and uses an AI system from whoever audits and tests it, so review doesn't depend on the word of whoever did the work. ISO/IEC 42001, published in 2023 as the first international standard specific to AI management systems, requires top leadership to sign an AI policy and, beyond that, formally record who is accountable for each governance role — not as a formality, but as a document any audit can check.

The problem isn't the absence of these requirements. It's that most companies treat the policy as the finished product, when it's only the starting point. The committee meets, reads a summary prepared by the same team that did the work, approves it, and moves on. No one asks whether that summary reflects what actually happened, because there's no other source to compare it against.

That's the blind spot McKinsey and Deloitte describe from two angles: one says no one took formal responsibility; the other, that whoever should be supervising has neither the knowledge nor the dedicated time. Both get worse when the only material available for review is a report written by someone with an interest in it looking good.

What has to be in place

An AI committee that reviews evidence, not reports, rests on verifiable mechanisms — not a document signed once a year.

Corporate identity for people and agents. Access to AI comes from the same directory that controls the rest of the company — someone let go loses access the same instant, without depending on anyone remembering to revoke a standalone account.

Access according to each person's role. Each person and each agent see only what their function authorizes, including inside a connected tool with dozens of functions — not the whole tool because separating access was more work.

Human approval at defined points, based on risk. Documents on their way to becoming the AI's official knowledge can require review and approval in two steps, with whoever writes it separate from whoever approves it — the same separation of duties NIST's framework recommends across an AI system's whole lifecycle.

An audit trail by area of the system. Creating an agent, approving a document, changing a permission, running a sensitive action: all of it gets recorded. The committee checks the record instead of asking someone to reconstruct events from memory.

Approved knowledge with sources. What the AI uses as reference has an owner, a current version, and a review date — not a loose file someone uploaded once and no one revisited.

This is how Skyller was designed: identity coming from the company's directory, two-step approval for critical documents, and an audit trail by system area, so the committee has something to review — not just something to approve.

What the committee gains from it

What the committee gains from it

The most immediate gain is speed during audits and incident investigations. When every approval, every permission change, and every sensitive action gets recorded by system area, reconstructing what happened stops being a days-long project and becomes a minutes-long lookup — the difference between an investigation and a good-faith guess.

There's also a gain in external credibility. With 36% of companies already citing ISO/IEC 42001 and 33% citing NIST's framework as a reference, according to Stanford's index, the market is moving toward treating these standards as a baseline expectation, not a differentiator. A committee that can show directory-based identity, two-step approval, and an audit trail by system area already answers most of what those standards ask for, without building the mechanism from scratch the moment an auditor asks.

And there's the gain that closes the loop with the problem this article opened with: a committee with this evidence stops depending on the good word of whoever did the work. The question "who answers for this internally" — the same one only 28% of companies can answer for their chief executive, and 17% for their board, according to McKinsey — gets a verifiable answer instead of an org-chart one.

Questions for the committee's next meeting

Before drafting another policy, it's worth bringing these questions to whoever sits at the table:

  1. Who on the committee can pull the audit trail for a specific agent right now, without waiting for a report? If the answer is "we'd have to ask IT to pull it," the committee is reviewing reports, not evidence.
  2. Is there a separation between whoever writes a document and whoever approves it as the AI's official knowledge? Without that separation, a typo can become an official answer before anyone notices.
  3. If someone is let go today, does their AI access drop at the same time, or does it depend on someone remembering to revoke an account? The answer decides whether the control is identity-based or goodwill-based.
  4. Has the committee ever tested asking for evidence of a specific decision, instead of only receiving a summary prepared by whoever executed it? The difference between those two things is the difference between oversight and theater.
  5. Does the company reference an external standard, like NIST or ISO/IEC 42001, for the committee itself to follow, or does every meeting reinvent what to check? An external standard hands the committee a ready-made playbook, instead of a criterion that changes every meeting.

Discover Skyller