Investor votes force boards to face AI oversight gaps
The gist
Investor pressure is forcing corporate boards to confront their glaring gaps in AI oversight, as AI adoption races ahead of governance safeguards.
What to know
- Despite a five-year low in shareholder proposals, governance measures drew the highest support at 31.4% in the 2026 proxy season, pushing AI oversight onto board agendas.
- Boards have quadrupled AI risk monitoring, yet still struggle with data access, explainability, and oversight of third-party models, with only 8% disclosing board-level AI oversight.
- While 88% of organizations use AI in at least one function, just 8% have a comprehensive AI governance framework—leaving most companies unprepared for the next wave of autonomous agents.
Shareholders Demand AI Accountability
Investor governance votes are forcing boards to confront their lack of AI expertise, with oversight disclosures and director AI skills still lagging far behind rising risk exposure.
The 2026 proxy season was the catalyst because investor governance proposals stayed strong even as overall proposal volume fell, and that renewed voting pressure is pushing AI oversight onto board agendas. The D&O Diary, using ISS-Corporate data, said overall shareholder proposal volume fell to a five-year low, but governance proposals remained resilient and received the highest average shareholder support at 31.4%, showing that oversight pressure did not fade.
That pressure increasingly attached to AI as investors used governance votes to press boards on a visible oversight gap. One speaker said that over the last three years, the only thing anybody wants to talk about is AI, and The D&O Diary said investors increasingly view governance as the mechanism through which boards should oversee emerging risks; an ISS STOXX study of more than 3,000 Russell 3000 and S&P 500 companies found only 8% disclosed board-level AI oversight, 9% formal AI governance policies, and 16% at least one director with AI expertise, while The Conference Board found AI risk disclosure rose from 12% in 2023 to 83% in 2025 even as disclosed director AI expertise increased from 1.5% to 2.7%.
Oversight Efforts Still Miss Key Risks
Despite quadrupled board monitoring, directors struggle to track AI data flows and third-party risks, leaving ethical and operational blind spots that threaten disciplined governance.
Boards are doing more than adding AI to meeting agendas. As Law360 reported in the headline “Boards Boost AI Risk Oversight Fourfold, But Gaps Remain,” monitoring activity has risen sharply, and CFO Dive shows what that looks like in practice: KPMG’s Matt Johnson and John Rodi say directors are being pushed to understand core AI mechanics, including where systems are deployed, what data they use, whether models are deterministic or probabilistic, and whether tools are assistive, workflow-automating, or agentic.
But the same evidence suggests that more oversight has not yet closed the hardest governance gaps. Law360’s framing that gaps remain is echoed by CFO Dive’s reporting that boards still need clearer visibility into data access, explainability, sensitive-data exposure, and AI embedded in third-party models, while Rodi says smart boards are asking management to “entirely restack” risk views and avoid “unending (and undue) AI activities” — a sign that ethical guardrails and disciplined execution are still uneven.
AI Use Surges, Controls Lag
As AI adoption outpaces governance, companies face mounting incidents and regulatory gaps, with most lacking even basic inventories of deployed AI agents or controls for security and compliance.
This may prove durable because AI deployment is becoming an operating reality faster than companies can build the machinery to govern it. PR Newswire, citing Deloitte, says only 5% of organizations consider their business processes highly prepared for AI agents even as 61% of executives expect most agents they use to become generally autonomous within four years; Capgemini likewise says organisations are rapidly shifting from experimentation to operationalisation, with 38% already having scaled Gen AI use cases, turning governance from a project into a standing board problem. That urgency is reinforced by Gartner’s prediction that by 2027, 40% of enterprises will demote or decommission autonomous AI agents because of governance gaps identified after production incidents.
The pressure also persists because the governance gap is structural, not temporary: The SaaS Sentinel says 88% of organizations use AI in at least one business function, but only 8% maintain a comprehensive AI governance framework, while SAP CTO Philipp Herzig warns, “You can’t manage what you can’t see” and, more specifically, “If I can’t automatically discover and maintain a working inventory of AI assets or AI agents, I don’t know what I’m governing.” That mismatch shows up in practice, from a lender case cited by Chrisman Commentary where a tool that automated borrower pre-approval updates lifted production 25% in week one before anyone had verified logging, storage, or shutdown authority, to IBM’s 2025 Cost of a Data Breach research, which found that 97% of organizations reporting an AI-related security incident lacked proper AI access controls and that one in five organizations also reported a breach connected to AI, and to Capgemini’s finding that 53% see stronger governance frameworks as one of the most effective ways to accelerate adoption.




