Ask a board how it governs AI and you’ll usually get one of two unsatisfying answers. Either a technical one that belongs three layers down — model cards, eval suites, red-teaming — that no director can meaningfully oversee, or a vague one — “we take it very seriously,” “we have a policy” — that means nothing you could audit. The gap between those two answers is where most AI governance actually lives, which is to say: nowhere useful.

On 29 June 2026, the Australian Institute of Company Directors, working with the University of Technology Sydney’s Human Technology Institute, published version 2 of A Director’s Guide to AI Governance, and it does the genuinely rare thing. It turns “govern AI” into eight concrete elements a board can actually hold itself accountable for — not code to review, not slogans to repeat, but oversight questions with answers you can check. It’s the most usable board-level framing of the problem I’ve seen, and it quietly settles an argument a lot of organisations are still having with themselves: the difference between complying with AI rules and governing AI well.

For the rest of us: what a board actually does

A board doesn’t build the AI, run the models, or write the policies. Its job is oversight — making sure the people who do those things are competent, accountable, and pointed at the right goals, and that someone is answerable when things go wrong. Governance is not operation. It’s the structured act of asking the right questions and refusing to accept hand-waving answers.

That’s exactly why AI has been hard to govern at board level. The technology is unfamiliar and probabilistic, the risks are novel, and directors have understandably worried that governing it requires understanding it the way an engineer does. It doesn’t. It requires knowing which questions oversight is responsible for — and until recently, nobody had written that list down in language a boardroom could use.

The eight elements

The Guide organises board oversight of AI into eight elements. None require a technical background; all require honest answers:

  1. Oversight and accountability — who, specifically, is answerable for AI outcomes, at board and management level?
  2. Strategy and purpose — why are we using AI here, and does it serve the organisation’s actual goals?
  3. Risk management — are AI-specific risks identified, owned, and inside our existing risk framework?
  4. AI system lifecycle management — do we govern these systems from design through retirement, not just at launch?
  5. People and culture — are our people equipped, and is the culture one that surfaces problems rather than hiding them?
  6. Third-party relationships — do we understand and govern the AI we buy and depend on, not just what we build?
  7. Transparency and disclosure — can we explain, to those affected, how and where AI is used?
  8. Continuous improvement — is governance a living process that learns, or a document that was signed once?

The power of the list isn’t any single item — most are unsurprising once stated. It’s that it’s complete and concrete. A board can walk through all eight, ask “can we answer this honestly,” and the gaps that surface are its governance roadmap. That’s a very different exercise from “do we have an AI policy.”

Compliance is the floor. Governance is the building.

Here’s the distinction the framework makes clean, and it matters most for a European audience living under the EU AI Act. Regulation like the Act is fundamentally about obligations — the specific things you must do, document, and prove, or face a fine. It tells you the legal minimum. It is necessary, and it is not the same thing as governing well.

The AICD framework is about oversight — stewardship of a technology your organisation is choosing to use, above and beyond what any regulator requires. The relationship between them is simple: compliance is the floor, governance is the building you put on it. An organisation can be fully compliant with every applicable AI regulation and still govern AI badly — no clear accountability, no lifecycle discipline, a culture that hides failures. Conversely, the eight elements are most of what you’d need to be compliant anywhere, because good oversight produces the documentation and accountability regulators ask for as a byproduct.

For a Swiss or European board, that reframing is useful precisely because the compliance conversation can crowd out the governance one. It’s easy to treat “are we EU AI Act compliant?” as the whole question. It’s the floor. The eight elements are how you decide what to build above it.

What this means

This is the practical, unglamorous heart of the research I keep coming back to: governing probabilistic systems is a real discipline, and it’s a board-level one, not just an engineering one. The AICD guide is valuable because it’s adoptable — non-technical, sourced from a respected directors’ body, and shipped as a suite that includes a plain-language introduction, a snapshot reference, and tailored checklists for smaller organisations and not-for-profits. You don’t need to be Australian to use it; the eight elements travel.

The move worth making is concrete. Take the eight to your next board or leadership meeting and ask, for each, “can we answer this with evidence, or are we hand-waving?” Wherever the honest answer is hand-waving, you’ve found the next piece of governance to build. That exercise costs an hour and tells you more about your real AI maturity than any compliance checklist — because it measures oversight, which is the thing a board is actually for.


References