What changed
For five years the conversation about enterprise AI was about capability — what it could do, how fast, how cheaply. In the last twelve months the conversation in the boardroom changed. The question is no longer "what can it do?" but "can you prove it did the right thing, and that you would have caught it if it had not?"
That shift moves AI out of the IT risk register and onto the board’s agenda. An unprovable model is now treated the way an unauditable financial control would be: not as a technical gap, but as a governance failure with a name attached.
Where the exposure actually sits
It sits in the decisions you have already automated without an evidence chain — the credit calls, the eligibility checks, the prioritizations that now run on models nobody can fully reconstruct. Each one is fine until it is questioned. The exposure is the aggregate of all the decisions you cannot currently defend.
- Which consequential decisions do we let AI make or shape today?
- For any one of them, can we reconstruct how and why — in full — on demand?
- If the answer is no, what is our plan and timeline to close that gap?