Boards face a visibility gap in AI governance
AI oversight is moving from broad policy statements to proof that systems can be identified, traced, and explained. California’s AI Transparency Act became operative on August 2, and Article 50 transparency duties under the EU AI Act began applying on August 2, 2026. The rules do not require every private company to label every internal AI-assisted document, but they reinforce a growing expectation that AI involvement in content, decisions, and workflows can be surfaced and documented.
The hardest problem for boards is visibility. AI may be embedded in enterprise software, HR screening tools, sales assistants, finance workflows, vendor platforms, or employee use of consumer chatbots. Without an inventory, management cannot assess data exposure, decision risk, vendor terms, operational dependency, or regulatory duties tied to those tools.
California’s employment-discrimination regulations took effect on October 1, 2025 and require covered employers to keep relevant employment records for at least four years, including automated-decision-system data. That can cover resume screening, candidate ranking, skills assessments, video-interview analysis, promotion recommendations, and performance-management scoring when they influence employment outcomes.
Boards are urged to demand a practical inventory and risk map before approving another AI policy. The core questions are where AI is running, which consequential decisions it affects, what data flows through it, whether human review is meaningful and auditable, and what would break if a critical AI-enabled workflow had to be paused.