Where the Governance Burden Now Sits

The structural shift in AI oversight can be summarized across four dimensions. As prescriptive federal rules recede, the practical responsibility for identifying acceptable AI risk moves inward, from regulators to the enterprises operating the systems, and ultimately to the boards responsible for overseeing enterprise risk.

Dimension What It Means for Boards
Regulatory guardrails recede Prescriptive federal rules give way to enterprise-level interpretation of acceptable AI risk. The interpretive burden relocates to the organizations operating the systems.
Procurement becomes a governance lever Federal contracting policy attaches AI governance conditions to vendor and contractor relationships, including through flow-down provisions that reach subcontractors.
Fiduciary duty fills the gap Existing duty-of-oversight standards apply to AI risk whether or not new AI-specific statute exists. There is no waiting period for the obligation to apply.
Evidence becomes the test Boards are judged on whether reasonable information and reporting systems existed, not on intent alone. Documentation of ongoing oversight matters.

A Shift in Where AI Risk Oversight Sits

Historically, much of the interpretive work around acceptable AI risk was absorbed by regulatory bodies issuing prescriptive rules that enterprises then implemented. As federal deregulatory activity reduces the volume and specificity of that prescriptive guidance, the interpretive burden does not disappear. It relocates to the organizations operating the systems, and ultimately to the boards responsible for overseeing enterprise risk.

Corporate directors should confirm the exact scope and timing of any specific deregulatory action against primary federal sources before treating it as settled. But the structural pattern is consistent across governance frameworks: when external guardrails loosen, internal oversight obligations do not loosen with them.

A common board misconception: that regulatory retreat reduces fiduciary exposure. In practice, reduced external prescription increases the weight placed on a board's own risk oversight process, because there is less regulatory record to point to as a baseline of reasonable conduct.


OMB M-26-04 and the Procurement Link

Procurement-linked federal policy, referenced here as OMB M-26-04, represents a distinct mechanism from direct regulation. Rather than mandating conduct across the economy, procurement memoranda typically condition federal contracting relationships on specific governance, documentation, or risk management requirements.

This means the practical reach of such a memorandum depends heavily on flow-down provisions: whether obligations imposed on a prime federal contractor extend contractually to subcontractors, vendors, and software suppliers further down the chain.

Boards should not assume their organization is unaffected simply because it does not contract with a federal agency directly. Any organization with federal contracting exposure, direct or indirect, should have legal and procurement counsel review the actual text of the memorandum and any related agency guidance to determine applicability before drawing conclusions about scope. This is a legal and contractual analysis, not a general industry assumption, and it should be revisited whenever contracting relationships change.


Fiduciary Duty Does Not Wait for New Statute

Boards do not need AI-specific legislation to have an existing oversight obligation. Established fiduciary concepts, including the duty of care and the duty of oversight, already require directors to establish reasonable information and reporting systems for material enterprise risks and to monitor those systems in good faith. AI risk, where it is material to the business, falls within this existing framework rather than outside it.

What has changed is the salience of the question: as AI systems take on more operational and decision-making functions, and as external regulatory scaffolding around them shifts, the adequacy of a board's information systems for that specific risk category becomes easier to scrutinize.

The practical implication: Directors should treat AI oversight the way they would treat any other risk category with growing materiality, by asking whether the board currently receives information sufficient to know if something is going wrong, rather than waiting for a dedicated AI statute to define the standard.


Governance Artifacts a Board Should Be Able to Request

Demonstrating reasonable oversight requires more than written policy. Directors should be in a position to request and review a defined set of governance artifacts from management. The following items represent a reasonable minimum for any organization where AI systems carry material operational or decisional responsibility:

Inventory and classification

  • A current inventory of AI systems in production, including purpose, data inputs, and operational scope
  • A risk classification for each system, distinguishing high-consequence from lower-stakes uses
  • Documentation of which systems operate autonomously versus with human approval gates

Ongoing monitoring and reporting

  • Periodic management reporting to the board or a designated committee on AI risk status
  • Incident logs covering unintended AI outputs, security events, or policy violations
  • Evidence that controls were operating during the period under review, not only at the time of the last audit

Contractual and procurement coverage

  • A review of federal contracting relationships and applicable flow-down provisions
  • Vendor and subcontractor AI governance requirements, where relevant
  • Counsel's determination of whether OMB M-26-04 or related memoranda apply and how

Where Runtime Governance Fits

Policy documents and periodic audits establish intent and describe controls at a point in time. They do not by themselves demonstrate that those controls were operating continuously between review periods. Runtime governance addresses that gap by monitoring and enforcing policy at the point where AI agents and systems actually execute, rather than only at the point where policy is written.

This includes controlling what tools or data an AI agent can access, enforcing least-privilege permissions, requiring approval workflows for sensitive actions, and maintaining audit logs of what occurred during operation. Trussed AI provides runtime governance, agent identity and permissions controls, tool approval workflows, and audit logging as part of its platform for securing enterprise AI agents.

For a board, the relevant distinction is not any specific vendor, but the general principle: static policy documentation answers what the organization intended, while runtime governance and logging answer what the systems actually did. Both are relevant to demonstrating reasonable oversight, and boards should ask which of the two their current reporting is actually built on.


Practical Next Steps for Boards

Directors seeking to strengthen AI oversight can structure their immediate work around three questions:

  1. What do we currently know? Establish whether management maintains a current AI inventory with risk classifications, and whether the board receives any regular reporting on AI risk status.
  2. What does our contracting exposure require? Engage legal and procurement counsel to determine whether OMB M-26-04 or related procurement memoranda apply to the organization directly or through subcontractor relationships, and what specific documentation or governance requirements follow from that applicability.
  3. Can we demonstrate continuous oversight? Determine whether current controls produce evidence of operation across time, not only at audit moments. If the answer is that the organization relies primarily on written policy and point-in-time audits, that gap is worth addressing before it becomes the subject of scrutiny.

A note on scope: The questions above apply regardless of whether a specific AI statute has been enacted. Existing fiduciary standards already require boards to establish and monitor reasonable information systems for material risks. The task is applying that existing obligation to a risk category that has grown in operational significance.


Frequently Asked Questions

Does deregulation reduce a board's AI oversight obligation?

No. Existing fiduciary standards, including the duty of care and duty of oversight, apply to material enterprise risks independently of whether specific AI regulations exist. When external regulatory prescription decreases, the scrutiny applied to a board's own oversight process often increases, because there is less external rulemaking to cite as a baseline of reasonable conduct.

Our company does not contract with federal agencies. Does OMB M-26-04 apply to us?

It may, depending on whether you supply products or services to a prime federal contractor. Procurement memoranda typically include flow-down provisions that extend obligations to subcontractors and vendors. Whether and how these provisions reach your organization is a legal and contractual question that requires counsel's review of your specific contracting relationships, not a general industry assumption.

What is the difference between a policy document and runtime governance evidence?

A policy document describes what an organization intends its controls to do. Runtime governance evidence demonstrates what the systems actually did during operation, including logs of tool access, permission enforcement, approval workflows, and detected violations. Both matter: policy establishes intent, and runtime evidence demonstrates continuous operation of controls between audit periods.

How often should the board receive AI risk reporting?

There is no universally mandated frequency, but periodic reporting aligned with other enterprise risk reporting cycles is a reasonable baseline. For organizations where AI systems carry significant operational or decisional responsibility, more frequent reporting, or the availability of on-demand status information, may be warranted. The key test is whether the board has sufficient ongoing information to recognize a material problem if one develops.

What constitutes a high-consequence AI system for classification purposes?

High-consequence systems are generally those whose outputs directly affect significant decisions: employment actions, credit or benefits determinations, patient care routing, security decisions, or autonomous actions with financial or legal consequences. Risk classification should reflect both the potential magnitude of harm from an error and the degree of human review in the loop before an output takes effect.