Is The Board Asking The Right Questions On AI Use?

By Mack Yusof

A chatbot once helped land an airline in a legal dispute. A law firm once got caught filing court papers full of cases that never existed. Employees at one of the world’s biggest tech companies leaked secret files simply by typing them into a chatbot. In each case, people relied on AI in ways that created consequences for the organisation or individual involved.

That is the real story of artificial intelligence in business today. AI is no longer a back-office tool run by the IT department. It writes reports, drafts board papers, screens job applicants, flags fraud, and much more. It has moved from the server room to the boardroom. The only question left is whether the people in charge are watching closely enough.

When the Robot Gets It Wrong, Who Pays?

In 2022, a Canadian man named Jake Moffatt asked Air Canada’s website chatbot about bereavement fares after his grandmother died. The chatbot told him he could book a ticket first and claim a discount later. That was wrong, however, he believed it, booked his flight, and was then refused the refund. Air Canada’s argued the chatbot was a “separate legal entity” and the company should not be blamed for what it said.

The tribunal was not persuaded. It found Air Canada liable for negligent misrepresentation, holding that the airline had a responsibility to ensure the information provided through its website was accurate, whether it came from a conventional webpage or its chatbot. The lesson for any Board is simple. Accountability cannot be outsourced to a machine. If a company’s AI gives customers incorrect information, the company may still have to answer for it.

A similar story happened in a New York courtroom. In the now-famous Mata v. Avianca case, a lawyer used ChatGPT to help write a legal brief. The AI invented six court cases that sounded completely real, complete with fake quotes and fake citations, and nobody checked before filing. The other side’s lawyers tried to look the cases up and found nothing. As a consequence, the lawyer was sanctioned, and the case became a global cautionary tale for every profession now experimenting with AI.

Neither company set out to be careless. Both simply trusted the machine’s output more than they questioned it, and that is exactly the habit every Board needs to break.

When AI Leaks Your Own Secrets

Confidentiality risk is also an issue. In 2023, engineers at Samsung used ChatGPT to help with tasks involving confidential company information, including source code and internal meeting material. Three separate incidents were reported within a short period, prompting Samsung to restrict the use of generative AI tools on company devices. The incidents highlighted a basic but important governance risk. Once employees enter confidential information into an external AI service, the company may no longer control that information as tightly as it would within its own systems.

Every listed company holds boardroom-level secrets about merger plans, unpublished financial results, executive pay, litigation strategy, and much more. It only takes one well-meaning employee pasting a confidential document into a free AI tool to get a faster summary for that secret to leave the building permanently, and untraceably.

Anyone who has used a chatbot knows that there is a possibility it can produce an answer that sounds completely convincing and is completely wrong. That, more than anything, is the core governance challenge. When a human employee makes a mistake, there is usually a clear trail, however, with AI, that trail gets blurry fast.

An employee may say, “the system recommended it,” while Management can claim that “the team relied on the system.” The technology vendor may justify that “it was only a tool.” And somewhere along that chain, the Board must ask the one question that matters: who made the decision?

The answer can never simply be “the AI.” A machine cannot sit before shareholders, a regulator, or a judge and explain itself. Responsibility always lands back on people, which is exactly why the Board needs to know how much human checking sits behind every AI-assisted decision in the company.

The Numbers Show a Governance Gap

It is a mainstream governance gap, and the data backs it up.

Governance researchers at ISS-Corporate found that among S&P 500 companies, the proportion disclosing some form of board oversight or AI competency rose from 12.3% in 2022 to 31.6% in 2024, more than double in two years. Boards are waking up, but that still means roughly two-thirds of S&P 500 companies did not disclose any form of AI oversight or competency.

Malaysia is asking the same question. The Securities Commission Malaysia’s Corporate Governance Monitor 2025 flagged AI governance, digital transformation and cybersecurity as emerging areas Boards must oversee. In July 2026, the Securities Commission proposed clearer rules on how Boards should govern AI use. The direction is clear. AI governance is increasingly a Board-level issue, not something that can be left solely to IT.

Some directors worry they must become computer scientists or experts to do this job properly, but in fact, they don’t. Nobody expects a director to write software or understand every line behind a cybersecurity system. What a Board needs is the judgement to ask the right questions.

It’s Not Just a Boardroom Problem, It’s Everyone’s

The issue doesn’t happen only in the boardroom; it happens across the whole company. The Samsung leak didn’t happen because of a rogue executive. It happened because ordinary employees, trying to work faster, pasted sensitive material into a free chatbot. The Air Canada case did not involve a director, but it involved a customer-service bot doing exactly what it was built to do, just wrong. Every failure started with an everyday task: writing a summary, answering a customer, drafting a document.

That is precisely why “use AI responsibly” is not, by itself, a real policy. It sounds reassuring, but it tells an employee nothing about what they can and cannot type into an AI tool, or what to do when the AI’s answer looks a little too convenient. Having clear, specific rules and not just a slogan is what protects a company. The Board’s job is to make sure those rules exist, are understood, and are followed.

According to the SC’s Corporate Governance Monitor 2025, which assessed disclosures for financial years ending in 2024, 33 of the 48 MCCG best practices had adoption levels of at least 90%. But the same report stated that some companies still give vague, boilerplate explanations when they don’t follow best practice. That shows that good scores don’t always mean good governance.

The Governance Framework Is Catching Up

The SC’s ongoing corporate governance review is examining Board effectiveness, emerging risks, and technology, areas that reflect how fast the corporate landscape is changing. In July 2026, the Securities Commission proposed clearer expectations for Board oversight of technology and artificial intelligence, including disclosures on AI use and governance. That is a good step, but regulation alone will not fix this.

Every listed company still must ask itself one basic question: do we actually know where AI is being used in our organisation? If the answer is “not really,” the Board may already have a governance problem, with or without new rules.

AI will bring real business benefits through faster analysis, better forecasting, and more productive teams. Boards have no reason to fear it, but there is also no reason to trust it blindly. Corporate governance was never meant to block new technology. It exists to make sure new technology is adopted responsibly and with clear accountability.

AI can process and analyse enormous volumes of information at a speed that would be difficult for a human team to match. But governance was never really about processing information but rather about judgement, accountability, and the courage to say, “I’m not comfortable with this yet.” No algorithm can do that for a Board.

Five Questions Every Director Should Bring to the Next Board Meeting, among others

1.  Where in our company is AI already being used, and does the Board actually know?

2.  Who is accountable when it gets something wrong: a named person, or “the system”?

3.  What confidential information are staff allowed and not allowed to put into AI tools?

4.  Is there human review before AI-assisted output feeds into a major decision?

5.  If a regulator or a court asked us to explain an AI-assisted decision, could we?

If a Board cannot answer the questions comfortably today, that is not a technology gap. It is a governance gap and, as the cases above show, it is one that can cost real money, real trust, and a company’s reputation.

Companies must always remember that AI has already walked into the boardroom, invited or not. The real test isn’t whether companies use it, since they already do. The test is whether corporate governance, and the people responsible for it, have caught up.

Disclaimer: The views and opinions expressed in this article are solely those of the writer, in his personal capacity, and do not reflect the views or positions of his employer(s), any organization he is affiliated or associated with, or any company named or referenced in this article.

Latest News

Must read