Key takeaways
- Only 26% of corporate boards discuss AI at every board meeting, according to Protiviti and BoardProspects' third annual Global Board Governance Survey of 772 directors and C-suite executives, fielded in the fourth quarter of 2025.
- The gap tracks directly with results: 63% of boards at high-AI-ROI organizations put AI on every meeting's agenda, versus just 13% at low-ROI organizations.
- Confidence follows the same split. 95% of high-ROI organizations report confidence in their ability to integrate AI into operations, against 33% of low-ROI organizations — and 93% versus 42% on having a responsible AI strategy.
- Most boards were never given a standing reporting cadence or format for AI risk, so irregular discussion is a process gap, not a competence failure.
- The EU AI Act's Article 9 risk-management and Article 14 human-oversight provisions assume competent oversight exists somewhere in the organization; they don't specify where, which means the board has to decide that for itself.
If your board's last substantive AI conversation was months ago, you are not the exception. You are the majority. Only 26% of corporate boards discuss AI at every board meeting. That's the headline finding from Protiviti and BoardProspects' 2026 Global Board Governance Survey, the third annual edition of the study, based on responses from 772 directors and C-suite executives gathered in the fourth quarter of 2025. Three out of four boards, in other words, are treating what regulators, courts, and their own risk registers increasingly describe as a board-level accountability item as something to raise only when someone remembers to.
The number that should worry a director more than the headline, though, is the one sitting next to it: 63% of boards at organizations reporting high AI return on investment discuss AI at every meeting, compared with just 13% at organizations reporting low AI ROI. That's not a minor correlation. It's a nearly five-to-one gap between the boards that treat AI as standing business and the ones that treat it as an occasional update, and it lines up with a matching confidence gap: 95% of high-ROI organizations say they're confident in their ability to integrate AI into operations, versus 33% of low-ROI organizations, and 93% versus 42% on confidence in having a responsible AI strategy at all.
| Metric (2026 Protiviti/BoardProspects survey) | High-ROI organizations | Low-ROI organizations |
|---|---|---|
| AI on every board meeting agenda | 63% | 13% |
| Confident in ability to integrate AI into operations | 95% | 33% |
| Confident in having a responsible AI strategy | 93% | 42% |
What the Protiviti survey actually measured
The methodology matters here because a lot of "boards and AI" commentary in 2026 blends different surveys measuring different things. Protiviti's study, detailed on the company's own survey page, asked 772 board members and C-suite executives globally about how their organizations govern AI at the board level, and it is explicit that the 26% figure refers to boards that include AI on the agenda at every single meeting, not boards that discuss AI at some point during the year. That's a meaningfully higher bar than "has talked about AI," and it's the bar the survey uses throughout: the 63%-versus-13% ROI split and the confidence gaps are all measured against that same every-meeting standard.
It's worth distinguishing this from a separate, frequently cited data point: the National Association of Corporate Directors' 2025 Public Company Board Practices and Oversight Survey, which found that 62% of directors say their boards are setting aside agenda time to discuss AI at all, up from 28% in 2023. That's a different question (any agenda time, at any frequency) answered by a different sample, and the two numbers shouldn't be read as contradicting each other. Read together, they suggest most boards have started talking about AI somewhere in their annual cycle, but only about a quarter have made it a standing item rather than an occasional one, and that gap between occasional and standing is exactly where the ROI and confidence numbers diverge.
Two other independent data sets point at the same underlying gap from different angles. Grant Thornton's 2026 AI Impact Survey of 950 business leaders found that barely 1 in 10 boards, 11%, met its threshold for "strong AI oversight," defined as a board that has participated in AI briefings, established governance expectations, and integrated AI risk into ongoing oversight, all three, not just one. And a disclosure-based analysis from ISS STOXX, reviewing public filings from 3,048 Russell 3000 and S&P 500 companies as of January 2026, found that only 245 companies (8%) disclosed board-level AI oversight at all, and only 481 (16%) disclosed having even one director with specialized AI skills. Three surveys, three different methodologies, one consistent pattern: formal, demonstrable board AI oversight is still the exception rather than the norm.
Why this is a governance design problem, not a board-competence problem
It's tempting to read "only 26%" as evidence that most boards aren't taking AI seriously. That reading doesn't survive contact with how board agendas actually get built. A board discusses what it has a standing mechanism to discuss. Financial performance appears at every meeting because there's a defined reporting package, a designated executive (the CFO) who owns presenting it, and a line item on every agenda template that assumes it will be there. Cybersecurity increasingly gets the same treatment for the same reason: a named owner, a recurring report format, and an expectation baked into the calendar rather than revisited each quarter.
AI, for most boards, has none of that scaffolding yet. There's often no single executive whose job description includes "brief the board on AI risk," no standard report format equivalent to a financial statement or a security posture summary, and no template line item that puts AI on the agenda by default rather than by someone remembering to add it. Directors don't skip discussing AI because they've judged it unimportant; they skip it because nothing in the existing process forces the conversation the way the reporting structure forces a financial or security discussion. That's a process failure, not an indifference failure, and it's the reason the fix looks less like "get better directors" and more like "build the mechanism financial reporting already has."
Jessica L. Lewis, a partner in WilmerHale's securities litigation and enforcement practice, put the strategic stakes plainly: "AI governance isn't just good practice, it has quickly become a legal and strategic imperative." Boards that build the oversight mechanism now, she argues, are the ones positioned to meet evolving fiduciary and disclosure standards; boards that wait for the mechanism to build itself are the ones that end up explaining its absence after something goes wrong.
What a defensible board-reporting structure requires
Four elements separate a board that can demonstrate real AI oversight from one that can only demonstrate good intentions.
A standing AI agenda item, not an ad hoc one. The distinction Protiviti's data draws isn't "boards that discuss AI" versus "boards that don't." It's boards where AI has a reserved slot on every agenda versus boards where it competes for attention alongside whatever else is pressing that quarter. A standing item survives a busy meeting; an ad hoc item is the first thing cut when time runs short.
A designated accountable executive. Someone has to own bringing AI risk and performance information to the board the way a CFO owns financial reporting or a CISO increasingly owns security reporting. Without a named owner, "who's briefing us on AI this quarter" becomes a question asked fresh each cycle, and questions asked fresh each cycle are the ones that quietly stop getting asked.
Board AI-literacy training. A board can't meaningfully interrogate an AI risk report it doesn't have the vocabulary to challenge. Directors don't need to become data scientists, but they do need enough grounding to ask the follow-up question after management's first, confident answer — the same baseline of literacy boards were expected to build for cybersecurity a decade ago, and are now expected to build for AI on a compressed timeline.
Risk register integration. AI risk sitting in a separate deck, reviewed by a separate committee, on a separate schedule from the rest of enterprise risk reporting is a structural way of telling the board that AI is somehow not "real" enterprise risk. Folding AI risk into the same risk register, the same heat-map, and the same audit-committee review cadence as financial, operational, and cybersecurity risk is what makes it visible in the same room, at the same time, as everything else the board is already accountable for.
None of these four is exotic. They're the same structural features that already exist for financial and security reporting, applied to a category of risk that hasn't had them yet.
If your board can't currently name who owns AI reporting, that gap is worth closing before the next meeting, not after a regulator asks the same question.
How this connects to the EU AI Act's oversight expectations
The EU AI Act doesn't name the board. Article 9's risk management system requirements and Article 14's human oversight requirements are written as functional obligations on the "provider" or "deployer" as an organizational entity: establish a continuous, documented risk management process across the AI system's lifecycle, and ensure the system can be effectively overseen by natural persons who can intervene or halt it. Neither article specifies that this oversight has to run through the board, a named executive, or any particular reporting line.
That silence is easy to misread as "the board doesn't need to be involved." It's closer to the opposite: the Act assumes competent oversight exists somewhere in the organization and simply doesn't dictate the org chart that produces it. For a regulated entity, that means the board can't point to Article 9 or 14 for cover if its own oversight structure is informal or ad hoc, because the law's human-oversight requirement has to be satisfied by someone, and "no one in particular, informally, sometimes" doesn't satisfy a requirement that the system be overseen by a person who can act on what they see. A board with a standing AI agenda item, a named accountable executive, and AI risk sitting inside the same register as every other enterprise risk is demonstrating the oversight the Act requires exists; a board without those things is hoping a regulator never asks who, specifically, was watching.
A one-page board AI reporting template
A board-reporting structure doesn't need to be elaborate to be defensible. A single page, reviewed at every meeting, covering five things, does most of the work:
- AI system inventory changes. What's new, decommissioned, or materially changed since the last meeting, and its risk classification under whatever framework applies (EU AI Act tier, internal risk scoring, or both).
- Open high-risk items. Any AI system or use case flagged as high-risk that lacks a completed impact assessment, a named owner, or a documented mitigation plan.
- Incidents and near-misses. Bias findings, model failures, or oversight interventions since the last report, with resolution status.
- Regulatory and audit status. Where the organization stands against applicable AI-specific obligations (EU AI Act deadlines, sector-specific rules) and any open audit findings.
- Confidence check. A short, honest self-assessment from the accountable executive: are we confident in this quarter's AI risk posture, and why or why not. This is the line item most reports skip, and it's the one that actually tells a board something a checklist can't.
Five items, one page, every meeting. It's a smaller lift than most boards assume, and it's the difference between a board that can point to a documented history of oversight and one that can only describe its intentions after the fact. Building that page once is straightforward; keeping it accurate every quarter without someone reconstructing it from scratch is the part that actually requires a system behind it.
Building the mechanism instead of waiting for it
The pattern in Protiviti's data is consistent with what shows up across board-governance research generally: the boards seeing better AI outcomes aren't the ones with more expertise walking in the door, they're the ones that built a process that makes AI oversight happen by default rather than by initiative. That process has to live somewhere outside the boardroom between meetings, which is where governance-maturity tooling does real work rather than decorative work.
Secure Privacy's Governance Maturity module is built around exactly this gap: it scores an organization's privacy, cybersecurity, and AI governance maturity against defined benchmarks, and generates the board-ready executive summaries and maturity reports that give a board something concrete to review at a standing agenda slot, instead of asking a director to synthesize where things stand from memory each quarter. Paired with the platform's AI Governance module, which registers AI systems with risk classifications and owners, maps them against EU AI Act obligations, and produces audit-ready documentation, the inventory-and-classification layer that a board report needs (item one and two on the template above) gets generated from the same system tracking the AI systems in the first place, rather than compiled by hand before each meeting.
That combination doesn't replace the board's job. A platform can't decide that AI deserves a standing agenda slot, and it can't nominate the accountable executive; those are governance decisions the board itself has to make. What it does is make the mechanism sustainable once the board makes that decision; the maturity scoring and AI system registry stay current between meetings instead of requiring someone to rebuild the picture from scratch every quarter, which is usually the real reason a standing item quietly becomes an ad hoc one.
If your organization is still assembling that reporting structure, a Data Protection Management System that folds AI governance into the same framework as the rest of the privacy program is a more durable starting point than a one-off board presentation built for a single meeting and never updated again.
FAQ
What percentage of boards discuss AI at every meeting?
Only 26%, according to Protiviti and BoardProspects' 2026 Global Board Governance Survey, based on 772 directors and C-suite executives surveyed in the fourth quarter of 2025. The survey measured whether AI has a standing spot on every meeting's agenda, not whether a board has discussed AI at any point during the year.
Is there a real link between board AI engagement and AI ROI?
Yes, and it's a large gap. 63% of boards at organizations reporting high AI ROI include AI on every meeting's agenda, versus 13% at organizations reporting low AI ROI. The same survey found a matching confidence gap: 95% of high-ROI organizations report confidence in integrating AI into operations, versus 33% of low-ROI organizations.
Does low board engagement with AI mean the directors aren't competent?
Not according to the underlying pattern. Most boards were never given a standing reporting mechanism for AI the way they have one for financial performance or, increasingly, cybersecurity. Without a named accountable executive and a recurring report format, AI discussion depends on someone remembering to raise it each meeting, which is a process gap rather than evidence that directors don't take AI seriously.
Does the EU AI Act require board-level AI oversight specifically?
Not explicitly. Article 9's risk management system requirements and Article 14's human oversight requirements are written as obligations on the organization as a whole, without naming the board or any specific reporting line. The requirements assume competent human oversight exists somewhere in the organization; they don't dictate the structure that produces it, which leaves the board to decide, and be able to demonstrate, where that oversight actually sits.
What should a board AI reporting template include?
At minimum: AI system inventory changes since the last meeting, open high-risk items lacking a completed assessment or owner, incidents or near-misses since the last report, regulatory and audit status against applicable AI obligations, and a brief confidence self-assessment from the accountable executive. Covering all five in one page, reviewed at every meeting, is enough to demonstrate a documented history of oversight rather than an occasional one.
How is the NACD's AI board-engagement statistic different from Protiviti's?
They measure different things. NACD's 2025 Board Practices and Oversight Survey found 62% of directors say their board sets aside agenda time to discuss AI at all, up from 28% in 2023. Protiviti's survey asked specifically whether AI is on the agenda at every meeting, and found only 26% meet that bar. Read together, they suggest most boards now discuss AI occasionally, but far fewer have made it a standing, every-meeting item.




