The October answer
Boards need to look beyond the existence of an AI strategy and examine whether production systems are governable. For each material agent, oversight should cover the owner, credentials, data access, operating cost and measurable outcome.
What changed since the September Preview
September framed three board questions around ownership, demonstrated value and security funding. October adds operator data on agent counts, cost visibility, bottlenecks and access methods. No board-specific instrument has a base above 40, so the Preview label applies.
Five questions for the board
- How many production agents operate today, and which executive owns the register?
- What share of agent operating cost is visible in real time?
- Which agents use shared accounts, and what is the migration plan?
- Which business outcome justifies each material agent deployment?
- Does security funding match the scale of the agent-access problem?
Board evidence dashboard
| Board question | October evidence | Base | Oversight implication |
|---|---|---|---|
| Is buying authority named? | 13% report no single owner | 467 | Require a named executive and operating owner. |
| Is production visible? | 80% run agents; 44% have full real-time cost visibility | 75 and 77 | Ask management to reconcile its agent inventory with workflow cost. |
| How does control funding compare with the stated problem? | 68% name agent access; 34% have a dedicated line | 151 | Review access exceptions and security funding together. |
| Is identity attributable? | 37% of applicable answers use shared service accounts | 49 | Ask how agent actions are traced and revoked. |
| Has AI changed the operating model? | 13% report embedded AI | 91 | Distinguish deployed tools from structural dependence. |


| Respondent seat | Base | CEO | Finance | CIO or CTO | No owner | Business unit |
|---|---|---|---|---|---|---|
| CEO or founder | 118 | 80% | 19% | 15% | 3% | 4% |
| Finance | 67 | 27% | 67% | 9% | 13% | 6% |
| Technology | 25 | 24% | 20% | 52% | 16% | 8% |
| Investor or partner | 55 | 42% | 18% | 13% | 24% | 11% |
Selected title-classified groups shown: 265 of 467 respondents. The other/unclassified group (195) and smaller groups (7) are omitted. Any mention; bases from 10 to 39 are directional.

| Group | Base | Full visibility | Partial visibility | No visibility |
|---|---|---|---|---|
| Exploring | 18 | 22% | 33% | 44% |
| Piloting | 14 | 36% | 43% | 21% |
| Deployed in production | 33 | 61% | 33% | 6% |
| Embedded (removing it would change our cost structure or hiring plan) | 10 | 50% | 50% | 0% |
Matched respondents answering both questions; base 75. Small row bases are directional.
The board-specific instrument has not cleared the publication threshold, so this is a Preview. The dashboard combines separate operator instruments and does not imply that the same people answered every question. It organizes the available evidence around authority, economics, identity, funding and operational dependence.
Tested against the record
The NIST AI Risk Management Framework provides a common structure for governing and managing AI risk. The operator data highlights two practical measures for board oversight: cost visibility and agent credential models. Both belong in an inventory of material production systems.
What this means for directors
Directors should request a quarterly production-control dashboard covering agent count, material workflows, named owners, cost visibility, identity model, incidents, exceptions and measured value. It should distinguish pilots from deployed and embedded systems.
Questions this report answers
What should boards ask about AI in production?
Ask for the agent count, named owners, operating cost, identity model, data access and measured value for every material workflow.
How do production-agent adoption and cost visibility compare?
Production-agent adoption is 80 percent and full real-time cost visibility is 44 percent, a 36-percentage-point difference across two questions from the same event (bases 75 and 77).
What is the leading AI security concern?
Agent access, named by 68 percent of CISO-instrument respondents (base 151, any mention).
Key citable facts
- Eighty percent of AI Leaders respondents report at least one production agent (base 75).
- Production-agent adoption exceeds full real-time cost visibility by 36 percentage points: 80 percent versus 44 percent across two questions from the same event (bases 75 and 77).
- Shared service accounts are used by 37 percent of applicable respondents (base 49).
Methodology and honesty notes
This is a board-oriented synthesis of separate operator instruments, not a survey of directors. Preview status applies until the board instrument clears 40 responses. No claim is presented as a board-seat opinion. The 34-point security comparison describes problem prevalence and funding structure; it does not measure whether security spending is adequate.
Related reading
Citation and editions
Suggested citation: Newlands, M. (2026). Board Director AI Governance Report, Preview Edition. Open Future Forum, October 2026.
Work These Questions with Board Peers
Forum Select convenes board directors and executives through small, off-the-record gatherings. Membership is by application and referral.