Explainer
    Perspective
    Perspective

    Part of The company brain: where your organization's knowledge lives

    AI governance for executive and supervisory boards: value, ethics and stop rules

    AI governance is the agreement on what AI may do, who is accountable and when you stop. A three-question framework for boards and supervisors.

    Max van Genderen7 min read
    Share on
    AI governance for executive and supervisory boards: value, ethics and stop rules

    AI governance is the set of agreements on which AI an organisation uses, who is accountable for each application and when that application stops. It is not an IT topic but a board topic. The European AI Act and the Dutch Cyber Security Act place responsibility explicitly with directors.

    Many organisations are already working with AI. A chatbot runs on internal data, a pilot with documents is under way, or someone has switched on Copilot. That changes the question at the board table. It is no longer "does it run?", but "does it do what we intend, and can we stop if it does not?"

    In this article you will find a framework of three questions that works per AI application. You will also read what it takes in your data and what a supervisory board can ask every quarter.

    Why AI now belongs on the board agenda

    Three regimes meet:

    • The EU AI Act applies in phases. AI must already be recognisable as AI, and people who work with AI must be sufficiently AI literate. The heaviest requirements for high-risk applications follow later.1
    • The Dutch Cyber Security Act, the national implementation of NIS2, imposes a registration duty, a duty of care and a reporting duty. Directors carry final responsibility.2
    • The GDPR continues to apply to every piece of personal data that ends up in data or AI. You may use that data only for the agreed purpose and keep it no longer than necessary. A data breach is reported within 72 hours.3

    Together they mean that oversight of IT projects and budgets is no longer enough. Oversight now also covers how AI is deployed, bounded and stopped.

    First the foundation: trustworthy data

    AI on poor data gives answers that look right but are not. That is more dangerous than no AI. So AI governance does not start with the model, but with the data underneath:

    • One definition per KPI, the same for reports and for AI.
    • Traceability: every number can be traced back to its source and the moment it was retrieved.
    • Quality checks in the pipeline that flag deviations automatically.
    • One identity: whoever leaves loses access everywhere at once, and AI never shows more than the user is allowed to see.
    • A recorded setup that is reproducible and auditable.

    Without this foundation, every governance agreement about AI is an agreement on paper. Also read: Implementing AI: why it almost always breaks on your data.

    The framework: three questions per AI application

    Every AI application must be able to answer three questions before it goes live, and again every quarter after that.

    01ValueWhat it delivers,measured against abaseline02Ethical frameOne owner,transparent, peopledecide03Stop rulesExit criteria agreedbefore go-live04Every quarteragainOwner, board andsupervisory boardreviewValue, ethics and stop rules, recorded before go-live and tested again every quarter.

    1. Value: what does it deliver?

    What does this application deliver, what does it cost, and why is it at the top of the list?

    In practice that means:

    • An AI register recording value, status, owner and risk profile per application.
    • A business case up front, with a baseline. Benefits are measured, not assumed. Think of hours no longer spent checking figures, the number of discussions about which number is right, and the share of AI answers judged correct.
    • Prioritising on value, readiness and risk. Start with low-risk applications on controlled data. Sources with personal data, such as email and chat, only come in after an explicit decision and a privacy impact assessment (DPIA).

    2. Ethical frame: who is accountable, and does a person stay in control?

    Who is accountable, do customers and employees know AI is involved, and does a person stay in control?

    • One owner per application. That is a business owner, not an IT department. Deploying and classifying AI is a decision for the executive board.
    • Transparency. Employees know in advance which data is used. Customers know their data stays in the EU and that no decision about them is made by AI alone. AI answers are always recognisable as AI.
    • Human oversight. Every answer is traceable. Wrong answers are flagged and corrected. Outcomes are tested for bias periodically. The system advises, the person decides.
    • A red line. Communication data is never used to assess or monitor employees. Under the AI Act such an application quickly falls into the high-risk category.

    3. Stop rules: when do we stop?

    How to set stop rules per application is covered in Stop rules for AI: set your exit criteria before go-live.

    When do we stop, who escalates in an incident, and how often do we look again?

    This is the question most often missing. A project then continues simply because it was started. Record stop criteria before go-live:

    CriterionExample thresholdConsequence
    QualityFewer than 90% correct answers over 4 weeksPause, fix, test again
    UsageToo few active users after 3 monthsStop or redesign
    CostMore than 20% over budgetExecutive board decides on continuation
    Privacy or securityAny incident involving personal dataStop immediately and escalate
    BiasDemonstrably skewed or harmful outcomeStop immediately, investigate

    Also record an escalation ladder with fixed deadlines, because the legal clock runs from the moment of discovery. Add a review rhythm as well: monthly by the owner, quarterly by the executive board and the supervisory board, and once a year a review of the framework itself.

    The foundation that never leaves the agenda

    Beneath the three questions sit two topics that apply to every application:

    • Cyber security and NIS2 readiness: registration, risk management, MFA, supply chain security and a tested incident process.
    • European data sovereignty: data stays in the EU, a data processing agreement is in place before the first data flow, the purpose of each connection is recorded and there is an exit strategy.

    Be honest about this. Large cloud providers are often American companies. Storage in the EU limits the risk, but does not fully rule out access under American law. Your own key management and a reproducible setup make moving provably possible.

    Also read: Ownership is proven at the exit.

    Arrange it once, in one place

    Value, ethics and stop rules do not hold if every AI project arranges them again. They do work when there is one layer between your data and every AI, where everything comes together:

    • definitions are recorded there once;
    • access is enforced there per user and per model;
    • every question and every answer is logged there.

    04Every AI and language modelWhichever vendor connects03One gateDefinitions, access per user and model, logging, stopping02Trustworthy dataOne definition, traceable, checked01SourcesWhere the data is createdEverything passes through the same gate, so stopping can happen in one place too.

    Whichever vendor or language model connects, everything passes through the same gate, and stopping can happen in one place too. Also read: Connect once, not per agent and Why a semantic layer is not enough for AI.

    Five questions a supervisory board can ask every quarter

    1. Which AI applications are running, and who owns each one?
    2. What have they delivered compared with the business case?
    3. Has a stop criterion been hit, and what was decided?
    4. Were there incidents, and were they reported within the legal deadlines?
    5. Do our data and our customers' data stay in the EU and under our control?

    None of these questions requires technical knowledge. Each question worked out in full, with a good answer and when to probe further: Five questions a supervisory board asks every quarter. The executive board can answer them with a single one-page dashboard.

    Frequently asked questions

    Is AI governance the same as data governance? No, but it builds on it. Data governance settles who owns which concept and what it means. AI governance settles what AI may do with that data and when it stops. Also read: What is data governance?

    Does our AI application count as high-risk under the AI Act? Usually not, as long as you use AI for insight and support. That changes once AI is used to assess people, for example employees in recruitment, performance reviews or monitoring.

    Who carries final responsibility? The executive board sets the AI policy and decides on new applications. The supervisory board oversees the framework. Under the Dutch Cyber Security Act, directors are explicitly accountable.

    Where do you start? With an AI register and one application on trustworthy data. Record the three questions for it, including stop rules, before you scale up. Request a foundation scan.

    Sources

    Every claim in this article can be checked at the source.

    1. 1
      Verordening (EU) 2024/1689 (AI-verordening)

      EUR-Lex

      Gefaseerde inwerkingtreding, transparantie, AI-geletterdheid en hoog-risico-eisen.

      Back to the text
    2. 2
      Cyberbeveiligingswet (NIS2)

      NCSC

      Registratieplicht, zorgplicht, meldplicht en verantwoordelijkheid van bestuurders.

      Back to the text
    3. 3
      Datalek melden

      Autoriteit Persoonsgegevens

      Meldtermijn van 72 uur onder de AVG.

      Back to the text

    Next step

    Want to see what's already inside your organization?

    Leave your details. We'll reach out and plan a scan. Within thirty days you'll see one concrete result.

    No newsletter, no reselling. Just this conversation.

    Comments

    Comments are reviewed by the editors before they appear.

    Use your Google or Apple account, or your business email address.

    Sign in to comment