Keeping The Board Focused On The AI-Human Relationship

Direct Source Verification: This story is aggregated from Forbes (forbes.com). Full reporting rights and copyright belong to the primary publisher.
AI moves action into systems that may not have been designed with accountability in mind. Here's what leaders need to know.

By Craig Davies, Chief Information Security Officer, Gathid.

getty​Most board conversations about AI still start in the wrong place, usually too high up in the stack. The questions are typically about productivity, regulatory exposure, ethics, budget, workforce impact or competitive advantage. But CISOs don’t get close enough to the operating issue that decides whether AI becomes a controlled business capability or the next unmanaged risk surface.

The question I want boards to ask, then, is more specific: When a human and an AI system share the work, who holds the authority to act, who owns the decision, and how do we prove what happened?

This is how AI has become an identity management problem. For years, identity governance was built around the fairly stable assumption that a user was a person. That person had an account, a role, a manager, a lifecycle and an access review. Even when governance was imperfect, the model was understandable.

AI has changed the shape of the user. A single employee may now operate with a copilot, a coding assistant, a workflow bot, a service account, a data pipeline and several automated agents acting around them. Increasingly, these systems make decisions that affect production systems, customers, financial workflows or regulated data.

The Board does not need a technical briefing on every AI tool in use. What directors need is a simple way to understand how human judgment, machine action and business accountability fit together.

I would frame it this way: Every AI-enabled workflow creates an authority chain.

A human sets an objective. A system interprets it. An agent or automation acts. Another system records or responds to that action. Somewhere in that chain, data is accessed, changed, moved, summarized or exposed. If the Board can’t see this chain, it can’t govern the risk.

Teams are adopting assistants and agents because the individual use case looks safe. For example, a developer might want help writing code, or a marketer wants clearer campaign analysis. The risk rarely appears in the first use case. It appears when those tools are connected to systems, credentials and workflows that allow them to act.

A practical example from my own work changed how I think about this. In one of my workflows, an alert from a governance platform triggers a bot to collect supporting information, compares it with similar historical tickets, checks the affected identity against patterns and creates a draft incident ticket. By the time I look at it, I’m not starting from an empty screen. It’s a useful workflow that saves me time and removes some of the low-value hunting that security teams do every day.

But that agent is not “me.” It has its own identity and permissions. It can reach specific systems, retrieve information and initiate a workflow step without me clicking a button each time. If it pulls the wrong context, misses a pattern or raises the wrong ticket, the business won’t shrug and say, “The bot did it.” The questions will be very human. Who approved this? Who owned the process? Why did it have that access? Why was it allowed to act?

That is the board conversation CISOs need to encourage. AI moves action into systems that may not have been designed with accountability in mind.

Traditional board reporting often focuses on access metrics, such as how many users, how many privileged accounts, how many reviews completed and how many policy exceptions.

Those numbers still matter, but they’re not enough for an AI-enabled enterprise. Boards need to understand authority, including what an identity can actually do after roles, permissions, credentials, inheritance, delegation and system relationships are considered.

• Who or what can act on behalf of the organization?

• Which AI systems have access to production data or operational workflows?

• Where can an agent read, write, approve, deploy, refund, modify or escalate?

• Can we distinguish between an action taken by a person, a machine assisting that person and a machine acting independently?

• Who owns each non-human identity?

• How quickly can we reduce or remove an agent’s authority if something goes wrong?

These questions move a board away from the abstract and into practical, governable risk. They also make it clear that AI governance can’t sit only with innovation teams, legal teams or data science groups. If an AI system can act inside enterprise systems, identity and security must be involved before deployment, not after the first incident.

In my experience, boards respond to evidence. CISOs should give them metrics that explain the AI-human relationship in terms of authority and accountability. Useful measures include the number of AI agents and automations with access to business-critical systems, the percentage with named business owners, the number with standing authority versus time-limited authority, and the number of workflows where machine actions can change data or trigger operational outcomes.

I would also report authority concentration. If a handful of human or non-human identities can perform a disproportionate number of high-impact actions, the Board needs to know.

Another useful metric is revocation confidence. If an agent’s authority needed to be removed today, could the organization do it cleanly? Would it know which systems, tokens, service accounts and workflows were affected? If the answer is unclear, the organization has delegated authority without control.

The Board should not be left with the impression that AI is either a productivity miracle or an uncontrollable threat. Both framings are lazy. The real work is governance of the relationship between people and the systems now acting around them.

When a human and a machine share the work, who holds the authority, who owns the decision and how do we prove it? That is the AI-human relationship that every CISO needs to help their board understand.

Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?

Original Source
https://www.forbes.com/councils/forbestechcouncil/2026/09/21/keeping-the-board-focused-on-the-ai-human-relationship/
Visit Forbes ↗
SHARE STORY:
𝕏 f in

Related Coverage in Business