← Insights
Governance

Governing a company that's half AI

When a meaningful share of a company's work is done by AI agents — writing the code, drafting the analysis, touching the customer — the board's job doesn't disappear. It gets harder, and more important.

Mark Ruddock
Mark Ruddock
Advisory Lead · 6 min read
Governing a company that's half AI

Boards are about to face questions that no governance playbook has answers for yet. When a meaningful share of a company's work is done by AI agents — writing the code, drafting the analysis, touching the customer — the board's job doesn't disappear. It gets harder, and quite a bit more important.

Having spent years in boardrooms and now helping build an agentic firm, I've come to a two-part conclusion: the fundamentals of governance still hold, but some of the questions on top of them are genuinely new, and boards that wait to learn them will learn them the hard way.

The fundamentals don't change

A human is always accountable. An agent can write the code, but it cannot answer for it — to a regulator, a customer, or a court. The CEO still owns the outcome; the board still owns oversight of the CEO. No amount of automation moves the locus of accountability off the people in the room. Any governance conversation that forgets this has already gone wrong.

The questions that are new

  1. Who is accountable when an agent errs — and how do you know it did? The chain from decision to consequence gets longer and less legible. Boards will need to insist on knowing where agents act, and where a human signs off.
  2. What is the audit trail? When work is generated rather than authored, "show me how we got here" becomes a harder question. The companies that treat this as a design requirement now will be very glad later.
  3. How do you govern speed? Agents compress cycles that used to take weeks into hours. Oversight designed around quarterly meetings simply won't keep pace. Governance has to get closer to the work without smothering it.
  4. What are the new concentration risks? Model dependence, data exposure, security surface, reputational blast radius. These belong on the risk register alongside customer concentration and key-person risk — because they are exactly that kind of risk.

What boards should start doing now

Build AI literacy on the board before you need it — the same way good boards built security and data literacy over the last decade, ideally ahead of the crisis rather than during it. Put the topic on the agenda as a standing item. And treat model and data dependence as the concentration risks they are, not as an IT footnote.

The boards that will matter over the next decade are the ones that get literate now, while the stakes are still small — not the ones that wait for a bad quarter or a public failure to start learning. Governance was always about asking the right questions of the people who are accountable. That doesn't change when some of the work is done by machines. The questions just get sharper.

Mark Ruddock
Written by
Mark RuddockAdvisory Lead, AFINEA

An internationally experienced CEO with three exits and over 20 years at the helm of VC-backed technology and fintech startups — as a founder and as a later-stage CEO brought in to scale — and an experienced board member.