AI Academy · Book
Executives & Directors · Module 07 · Chapter 007

AI Governance Committee and AI Governance Office

Many large organizations run AI governance through two structures. A committee decides what is material; an office makes governance run every day; business owners keep the outcome. Each needs written authority, and the work fails when either one starts doing the other's job.

≈ 16 min read

After this chapter you can

  • Distinguish an AI Governance Committee, which decides, from an AI Governance Office, which operates.
  • Assign each kind of matter one verb - decide, recommend or be informed - and a route for disagreement.
  • Explain the mandate the office needs to request, route, record, track and escalate without owning AI systems.
  • Describe the hand-off between the two - written triggers, a decision paper and a decision log.
  • Explain how AI reporting reaches executive leadership and a board committee.

In 2018 Axon, the company best known for the Taser and police body cameras, set up an AI Ethics Board. It recruited serious people: law professors, privacy and civil liberties advocates, and AI researchers. The board was not decoration. In 2019 it advised against putting face recognition on Axon’s body cameras, and the company agreed1.

In the spring of 2022 the board voted 8 to 4 against even a narrow pilot of drones armed with Tasers. On 2 June, nine days after the school shooting in Uvalde, Texas, Axon announced that it was developing such drones to be stationed in schools. On Sunday 5 June, as criticism mounted, Axon’s chief executive announced that the company was pausing work on the project2. The pause came too late to keep the board. On 6 June nine members made their resignations public, writing that the announcement had bypassed the company’s own commitment to consult them3.

Here is the contradiction. Axon had one of the most respected AI ethics bodies in any industry, and at the one moment when its judgment mattered most, it could not stop anything. Its expertise was real. Its authority was not. The board was advisory, so when management disagreed, the only lever left to its members was to walk out.

Axon’s board was an external panel rather than an internal governance committee, but the lesson carries over. What makes a governance body work is not who sits on it. It is what the body is allowed to decide, and what happens when someone disagrees.

The core idea

As The AI Governance Operating Model showed, governance scales when the center keeps what must be consistent and risk decides how far each decision travels. Many organizations run that model through two formal structures with different jobs.

The committee decides, the office operates, and business and product teams keep ownership of outcomes and systems.AI GovernanceCommitteeDirection, material decisions, riskacceptance, escalationsDecidesAI GovernanceOfficeIntake, routing, inventory, standards, evidence, follow-upOperatesBusiness andproduct teamsOwn the outcomes and run the systemsOwns
Figure 7.7.1 The committee decides, the office operates, and the business keeps the outcome. Neither body replaces the owner.

The AI Governance Committee is a cross-functional decision and oversight body. It sets direction, takes the decisions that need several functions with authority in one room, accepts or refuses material risk, and handles what is escalated to it. The AI Governance Office is an operating function. It runs intake, routing, the inventory, standards and training, evidence and follow-up, every working day. Below both sit the business and product teams, who still own outcomes, as AI Roles, Ownership and Accountability established.

Without the committee, hard decisions drift or get made by whoever shouts loudest. Without the office, the committee’s decisions stay on slides. And when the committee becomes the workflow, executives become a queue.

What the committee decides

A committee’s scarcest resource is executive attention. It should spend that attention only where cross-functional or executive judgment is genuinely needed: high-impact AI uses, the acceptance of material risk, enterprise policy, significant exceptions, strategic priorities and serious incidents. It should not see every low-risk request, every model version or every technical detail. That work is real, but it belongs elsewhere.

The Axon board shows the second half of the design. For every type of matter, the charter must say not only whether the committee is involved but how.

A decision-rights table in which the committee decides high-impact uses and incident responses, recommends policy and is only informed of routine use.MatterCommittee roleWho elseHigh-impact AI useDecidesBusiness owner proposes; office preparesMaterial riskacceptanceDecides or escalatesExecutive leadership above its limitEnterprise AI policyRecommendsExecutive committee or board approvesRoutine usewithin standardsIs informedBusiness owner approves; office recordsSerious AI incidentDecides the responseOffice coordinates; owner acts
Figure 7.7.2 Decide, recommend or be informed: the charter assigns one verb to each kind of matter, so nobody discovers it in a crisis.

Three verbs do most of the work. Where the committee decides, its answer stands unless a higher body overrules it. Where it recommends, someone named takes the decision and must record why if they disagree. Where it is informed, it sees the item in a portfolio report and does not debate it. Axon’s board effectively had only the middle verb, and no rule for what happened when its recommendation was rejected. That is the gap to close: write down the verb, and write down the route a disagreement takes.

A useful test for any agenda item is whether it needs several functions, with authority, at the same table. If it does not, it should be decided before the meeting. Material risk acceptance and its conditions are treated in depth in AI Evaluation and Approval Gates; here the point is only that the committee is where the largest of those calls are made.

Who sits at the table

Membership should follow the organization’s AI risks and decisions, not a standard list. Committees typically draw on the business, technology, data and AI, security, privacy, legal, risk and compliance, and product. A logistics company may need operations at the table; a media group may need its editorial standards lead.

A chair with the authority to decide, surrounded by members chosen to match the organization's AI risks.ChairAgenda, decision,escalationBusinessTechnologyData and AISecurityPrivacyLegalRiskOperations
Figure 7.7.3 Members are chosen for the risks the organization actually runs. The chair matters more than the headcount.

The chair matters more than the headcount. A good chair runs the agenda around decisions rather than status updates, insists that each item ends with a recorded outcome, and has enough authority to settle a disagreement or take it higher. Many committees are chaired by an executive who owns enterprise outcomes, such as the chief operating officer, rather than by the head of a single function whose own proposals will come before it.

The committee also needs built-in challenge. Technology wants to ship, risk wants less exposure, the business wants more value. Those pressures are healthy if the committee makes the trade-off explicit and records who accepted it. Internal audit, as the third line in the Institute of Internal Auditors’ model, stays outside the vote so that it can later give independent assurance on the decisions made4.

What the office operates

If the committee is where decisions are made, the office is where governance becomes a routine. It turns policy and decisions into a system that runs on an ordinary Tuesday.

The office runs intake, routing, the inventory, standards and training, decision support for the committee, and follow-up.IntakeOne front door for every AI requestRoutingEach request to the right pathInventoryThe record of what AI existsStandards and trainingOne way of working, taught onceDecision supportPapers and evidence forthe committeeFollow-upConditions tracked to closure
Figure 7.7.4 Six jobs. The last two connect the office to the committee, and they are the easiest to underfund.

A common design failure is an office that can recommend but cannot coordinate. To run the system it needs documented authority to do five things: request information from any team using AI, route a request to the reviews it needs, keep the inventory, track the conditions attached to approvals, and escalate when a team does not respond. An office that has to ask permission to ask questions is an administrative team, however capable its people are.

Two boundaries keep the office honest. First, it is not the owner of AI systems or their risks; the business owns the outcome and the technical owner owns the system. Second, it is not an advocate. When it prepares a decision for the committee, it assembles the evidence, states whether required reviews are complete and records dissent. The business owner makes the case. An office that lobbies for approval, or for rejection, loses the trust that makes routing work.

Many organizations also have an AI center of excellence, which builds capability: platforms, reusable components, engineering practice. The governance office runs risk, policy and the decision process. Small organizations often combine the two, or place the office inside an existing risk or compliance team, and that can work, as long as someone is named to run intake, routing and follow-up, with written authority to do it.

Where the two meet

The committee and the office meet at one point: the escalation. The office decides which requests stay on a delegated path and which cross an escalation trigger and go up. The routing logic itself belongs to the operating model, and the tiers that feed it are the subject of AI Inventory and Risk Classification. What this chapter adds is the hand-off.

An escalated request moves from a written trigger, through a decision paper, to a committee decision, a log entry and follow-up by the office.TriggerWritten condition,not a hunchPaperEvidence anddissentDecisionTaken bythe committeeLogConditions,owner, reviewdateThe office follows up until every condition is closed
Figure 7.7.5 One boundary, four steps and a follow-up. The paper and the follow-up are where hand-offs usually break.

Typical triggers are high impact on customers or employees, material financial exposure, significant autonomy, a regulatory concern, a major policy exception and a serious incident. They must be written precisely enough that two people in the office would route the same request the same way. A trigger that depends on someone’s sense of importance is not a trigger.

The decision paper is where the office earns its keep. A good one fits on two pages: what the system does and for whom, the evidence from reviews, the legal view, the options including a smaller version, the business owner’s recommendation and any dissent. A committee that complains it cannot decide has often been sent forty slides of status instead.

A charter and a decision log for each body

Two structures can overlap badly: both approving, both setting policy, both chasing the same team. A short charter for each one prevents that.

The committee and office charters differ in purpose, authority, cadence, records and measures, so the two bodies do not overlap.Charter itemCommitteeOfficePurposeDirect and decideOperate and enableAuthorityDecide, recommend or be informed, by matterRequest, route, record, track, escalateCadenceMonthly or quarterly, plus at short noticefor incidentsContinuousRecordsDecision logEvidence file and inventoryMeasured byDecisions made and their timelinessTime to decision, inventory coverage
Figure 7.7.6 One page each. If the two columns say the same thing in any row, the structures will collide.

The committee meets when decisions need it, often monthly for portfolio and risk review and quarterly for an enterprise review, with a short-notice route for a serious incident. Meeting more often does not make governance stronger. The office works continuously.

The decision log is the committee’s memory. Each material decision gets an entry: what was decided, the rationale, the risk accepted, the conditions, the accountable owner and a review date. It turns a meeting into a commitment someone can be held to, and it is among the first records an auditor or regulator will ask for. The office keeps the evidence behind each entry.

The standards point the same way. ISO/IEC 42001, the AI management system standard, asks top management to assign and communicate responsibilities and authorities for relevant roles5. The NIST AI Risk Management Framework asks that roles and lines of communication be documented and that executive leadership take responsibility for decisions about AI risk6. A one-page charter for each body is the simplest way to show both.

Up to the board

Above the committee sits executive leadership and, in many companies, the board. Boards are moving quickly to name where AI oversight sits. Among the 80 Fortune 100 companies EY reviewed, the share disclosing that at least one board committee oversees AI rose from 11 percent in 2024 to 40 percent in 2025. The audit committee is the most common single home, named by 21 percent of all filers; other committees, such as technology or governance, are named by 25 percent8. The two add up to more than 40 percent because some companies assign AI oversight to more than one committee, as EY’s own footnote notes.

The share of Fortune 100 companies disclosing board committee oversight of AI rose from 11 percent in 2024 to 40 percent in 2025, most often the audit committee.11%Board committeeoversees AIFortune 100 disclosures in 202440%Board committeeoversees AIFortune 100 disclosures in 202521%Audit committee holds itOf all filers in 2025; othercommittees 25%Source: EY Center for Board Matters, Fortune 100 filings · 2025
Figure 7.7.7 Board-level oversight of AI almost quadrupled in a year. All shares are of the same 80 filers; audit (21%) and other committees (25%) sum above 40% because some companies assign AI to more than one committee.

Naming a board committee is the easy part. A second study measures two different things across the S&P 500. The share of companies disclosing AI as a risk rose from 12 percent in 2023 to 83 percent in 2025. The share of directors with disclosed AI expertise rose only from 1.5 percent in 2021 to 2.7 percent in 20259. Boards will depend on what reaches them. The chain is office, to committee, to executive leadership, to the board or a board committee, and the office is usually the one that consolidates the portfolio, the significant risks, the incidents and the open conditions into a report the board can read. It provides the evidence; it does not take the board’s decisions.

Story: one day in a port operator’s governance office

The following is an illustrative composite, built from patterns common in port and terminal operations rather than from one company. The terminals, people, requests and numbers are invented to show the mechanics.

A container terminal operator runs four terminals and has been using AI for three years. Its AI Governance Committee is chaired by the chief operating officer and meets monthly. Its office has three people, led by a former operations planner, with a written mandate to request information, route reviews, keep the inventory, track conditions and escalate.

In one day the port operator's office triages requests, uses its mandate, prepares a decision paper, supports a committee meeting and logs the outcomes.08:00Four requeststriagedThree stay on thedelegated path10:30Unregisteredfeature foundThe office usesits mandate12:00Decision paperfinishedTwo pages, withHR's dissent14:00CommitteedecidesFive items,five outcomes16:30Log andfollow-upConditions andreview dates set
Figure 7.7.8 One day, two bodies, one boundary between them. (Illustrative composite.)

At eight, the office lead triages four new requests. A tool that extracts data from customs and shipping documents, an updated berth-planning model and a translation aid for customer emails all stay on the delegated path, with a privacy check on the emails and approval by the business owners. The fourth is different. A terminal manager wants a tool that allocates crane shifts using each operator’s productivity score. Because it allocates work using individual performance data, it crosses a written trigger for employee impact, and counsel’s view is that it would probably be high-risk under Annex III of the EU AI Act. It goes to the committee.

At half past ten, the office learns that the gate team has switched on a new AI feature in the truck-appointment system without registering it. The lead does not need to ask anyone’s permission. She asks the gate manager for a description within five days and notes that, if it does not come, the matter goes to the committee chair.

By noon she has finished the decision paper on the crane-shift tool: what it does, who it affects, the vendor’s evaluation, the pilot data, the legal view, three options, the terminal manager’s recommendation and HR’s written dissent. She does not recommend approval or rejection. She states which reviews are complete and which are not.

At two, the committee meets with five items, all material. On the crane-shift tool it chooses the middle option: a pilot at one terminal, scores used only to balance shifts and never in discipline, the works council consulted before the pilot starts, and a review in ninety days. It refers one other item, a model whose potential financial exposure exceeds its delegated limit, to the executive committee.

At half past four, the lead writes five entries in the decision log, each with its rationale, conditions, owner and review date, and adds them to the quarterly report that goes to the board’s audit committee. Just before she leaves, the gate manager sends the description. Registering turned out to be faster than explaining why he had not.

Nothing on that day was heroic. The committee spent its two hours on decisions that needed it. The office did everything else, and had the authority to do it.

What this means for leaders

Four lessons follow for anyone who sits on, chairs or sponsors these structures.

  1. Give each body one verb per matter. Decide, recommend or be informed, written in the charter, with a route for disagreement. An advisory body without that route will be bypassed when it matters most.
  2. Give the office a mandate, not a mailbox. Written authority to request, route, record, track and escalate is what separates an operating function from an administrative one.
  3. Make the hand-off the product. Precise triggers, a two-page decision paper and a decision log with review dates are where the two bodies succeed or fail.
  4. Build the line to the board before the board asks. Decide which committee of the board receives AI reporting and what the office consolidates for it.

Check yourself

  1. The AI governance committee should approve every AI system.
  2. An expert advisory board can protect an organization even if its charter gives it no decision rights.
  3. The governance office owns the risks of the AI systems it tracks.
  4. The office can approve low-risk AI if that authority is delegated explicitly.
  5. The more often the committee meets, the stronger governance is.
  6. Board committee oversight of AI among Fortune 100 companies roughly quadrupled between 2024 and 2025.

Reflection: find the verb

What comes next

The committee decides and the office operates, but the office cannot route what it cannot see. Lifecycle governance starts with two questions: what AI systems do we actually have, and which of them need stronger governance? The next chapter, AI Inventory and Risk Classification, answers both.

Laws referenced

EU AI Act · EU

Regulation (EU) 2024/1689, as amended by Regulation (EU) 2026/1744

Risk-based rules. Prohibited practices include social scoring, untargeted scraping of facial images, and emotion recognition in workplaces and schools (with narrow exceptions). High-risk systems (Annex III: biometrics, safety components of critical infrastructure such as energy, water and traffic, employment and worker management, credit, education, essential services, law enforcement, migration, justice) need risk management, data governance, documentation, logging, human oversight, human oversight that keeps people able to understand the system, notice automation bias (over-reliance on its output), override it or stop it (Art. 14(4)), appropriate accuracy, robustness and cybersecurity (Art. 15), automatic logging of events (Art. 12), a provider quality-management system (Art. 17) and conformity assessment. An Annex III system is not high-risk if it poses no significant risk of harm, for example a narrow procedural or preparatory task that does not replace human assessment; systems that profile people are always high-risk, and a provider relying on this exception must document it and register (Art. 6(3)). Deployers of high-risk AI must use it as instructed, assign competent human oversight, monitor its operation, keep logs for at least six months and report serious incidents (Art. 26); employers must inform workers' representatives (Art. 26(7)). Public bodies, private providers of public services, and deployers of credit-scoring or life and health insurance pricing systems must carry out a fundamental-rights impact assessment before first use (Art. 27). Providers must run post-market monitoring (Art. 72). A deployer that puts its name on a high-risk system, substantially modifies it, or changes its purpose so that it becomes high-risk takes on the provider's obligations (Art. 25(1)). A substantial modification (Art. 3(23)) of a high-risk system needs a new conformity assessment, unless the change was pre-determined and documented at the first assessment, as with planned continuous learning (Art. 43(4)). Providers of general-purpose AI models (from 2 Aug 2025) must keep technical documentation, have a policy to comply with EU copyright law including text-and-data-mining opt-outs, and publish a sufficiently detailed summary of training content (Art. 53). Research, testing and development before a system is placed on the market or put into service is outside the Act, except testing in real-world conditions (Art. 2(8)). Since the 2026 Omnibus, the Art. 4 AI-literacy duty is an obligation of effort (take measures to support literacy), not of result. Fines reach EUR 35 million or 7% of global turnover for prohibited practices.

  • 2024-08-01 — Entered into force
  • 2025-02-02 — Prohibited practices (Art. 5) and the AI-literacy duty (Art. 4) apply
  • 2026-07-27 — Omnibus softens Art. 4: providers and deployers must take measures to support AI literacy; no specific level must be guaranteed
  • 2025-08-02 — General-purpose AI model obligations apply; governance and penalties regime in place
  • 2026-08-02 — Transparency duties (Art. 50) apply: disclose AI interaction, label synthetic and deepfake content (marking for generative systems already on the market: 2 Dec 2026)
  • 2027-12-02 — High-risk obligations for Annex III systems (e.g. hiring, credit, education, essential services) - moved from 2 Aug 2026 by the 2026 Omnibus
  • 2028-08-02 — High-risk obligations for AI in products regulated under Annex I

Last verified 2026-10-06 · official text

Worker consultation on workplace technology · EU member states

AI Act Art. 26(7); national co-determination law, e.g. Germany BetrVG s.87(1) no. 6, Netherlands WOR art. 27

Introducing systems that can monitor or assess employees usually requires informing or obtaining the consent of works councils or employee representatives, depending on the country. Plan this before a pilot, not after.

Last verified 2026-10-06

Directors' duty of oversight (Delaware "Caremark" doctrine) · US - Delaware (case law for most large US companies)

In re Caremark International Inc. Derivative Litigation (Del. Ch. 1996); Marchand v. Barnhill (Del. 2019)

Directors breach their duty of loyalty if they make no good-faith effort to put a reporting system in place for mission-critical compliance risks, or ignore red flags it raises. Where AI is mission-critical, a board that has no way to hear about AI risk is exposed. Liability is hard to establish, but the duty shapes what boards should ask to see.

  • 1996-09-25 — Caremark decision
  • 2019-06-18 — Marchand v. Barnhill: board must make a good-faith effort to oversee mission-critical risks

Last verified 2026-10-08

References

  1. The Policing Project, NYU School of Law. Axon Ethics Board Members Resign Over Company's Plan to Build Taser-Equipped Drones. The Policing Project. 2022.
  2. TechCrunch. Axon's AI ethics board resigns over plan to surveil schools with armed drones. TechCrunch. 2022.
  3. Wael Abd-Almageed, Miles Brundage, Ryan Calo, Danielle Citron, Rebekah Delsol, Barry Friedman, Chris Harris, Jennifer Lynch and Mecole McBride. Statement of Resigning Axon AI Ethics Board Members. The Policing Project, NYU School of Law. 2022.
  4. The Institute of Internal Auditors. The IIA's Three Lines Model: An update of the Three Lines of Defense. The IIA. 2020.
  5. ISO/IEC. ISO/IEC 42001:2023 Information technology - Artificial intelligence - Management system. International Organization for Standardization. 2023.
  6. National Institute of Standards and Technology. Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1. NIST. 2023.
  7. European Parliament and Council of the European Union. Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act). Official Journal of the European Union. 2024.
  8. EY Center for Board Matters. Cyber and AI oversight disclosures: what companies shared in 2025. EY. 2025.
  9. The Conference Board. From Principles to Practice: Governing AI in the Corporation. The Conference Board. 2026.
  10. Supreme Court of Delaware. Marchand v. Barnhill, 212 A.3d 805 (Del. 2019). Justia US Law. 2019.

Further reading

Sources last verified 2026-10-08.