top of page
Search

Governing a New Kind of Employee

Aug 4
7 min read

Updated: Aug 26

How AI Has Compelled the Evolution of Corporate Governance, and Why the Answer Is Already in the Boardroom


A whitepaper by Steven Hill, Managing Partner, OakTruss Group LLC

August 2026


Executive Summary


Artificial intelligence (AI) has moved consequential judgment into software. Systems now approve, flag, prioritize, and decide. These are functions that, until recently, only people performed, and that shift has compelled an evolution in corporate governance. The good news is, this evolution builds on foundations every board and leadership team already have. The bad news is, AI governance is not well understood, and the work of strengthening corporate governance to include AI may move slower than market, technology, and customer drivers demand.


The values a board or c-suite applies to AI are unchanged from the governance it applies to people. What must change is the tooling to measure and the clock speed of enforcement: a human decision-maker is reviewed periodically, while a machine making ten thousand decisions an hour requires continuous oversight. From this follows a compact definition of responsible AI: the discipline of making AI’s behavior observable, its risks proportionately controlled, and its humans accountable.


Delivering that discipline requires nine artifacts. By artifact we mean something concrete you can point to and hand to an auditor: a register, a log, a report, a signed approval. Every one of them is an existing governance structure, built long ago to govern capital allocation, re-instantiated to govern judgment. An AI inventory (a list of every AI system the company uses) is the asset register; a decision log is the general ledger; deployment gates are capital approval; independent assurance is internal and external audit. Boards do not need a new theory of governance; they need to do for judgment what they already did for capital.


1. The Oldest Discipline in the Boardroom


Corporate governance has always been the governance of judgment. Officers commit the company by contract. Managers allocate resources. Underwriters price risk; clinicians authorize care; buyers select suppliers. In every case a person exercises discretion with consequences the enterprise must own.


Over roughly a century, companies built a complete oversight apparatus for this: the general ledger records what happened; the budget bounds what may happen; the delegation-of-authority matrix defines who may decide what; internal controls constrain how decisions are made; and internal and external audit verifies the whole. The apparatus was organized around capital allocation for a practical reason: capital was the medium through which consequential judgment left a durable, countable trail. Governing the ledger was how you governed the judgment behind it.


The apparatus works. It is tested by crisis, well understood by directors, embedded in regulation, and taught in every business school. The question AI poses is not whether this model is sound; it is whether the model can follow judgment to the new place where it can be exercised.


2. A New Kind of Employee


AI systems in production today approve loan applications, flag transactions for review, screen resumes, triage support tickets, set prices, and draft communications. Each of these is an exercise of discretion, the very thing governance was built to oversee. For the first time, that discretion resides in software.


It is useful, and only slightly figurative, to call such a system a new kind of employee, because the analogy captures both why existing governance applies and why it must adapt. Like an employee, an AI system acts on the company’s behalf and creates obligations and exposures the company owns.

Unlike an employee, it:


  • Operates at machine speed with an unlimited duty cycle (if the power stays on). It does not sleep, eat lunch, or slow down when uncertain, unless designed to do so.

  • Scales by replication. A flawed human judgment is one person’s error; a flawed model is every instance’s error, simultaneously.

  • Cannot be deposed, interviewed, or held personally responsible. Accountability cannot terminate in the system itself; it must terminate in a named person.

  • Changes behavior when retrained or when the world drifts. Its “character” is not stable in the way a vetted professional’s is presumed to be. Agents do behave in unexpected ways, and when they do, the behavior is typically noticed only because a human happened to observe it and is rarely measured consistently.


These properties are why AI has compelled governance to evolve rather than merely stretch. A framework calibrated to human tempo is structurally mismatched to an actor that produces a quarter’s worth of decisions before lunch.


3. The Values Carry Over. The Enforcement Cannot.


Much of the public conversation treats AI governance as a new value system to be adopted. This misstates the problem. The values are settled. Fairness and accuracy in consequential decisions, transparency about how they are made, and accountability for their outcomes are already board-level expectations for human conduct. No new principles are required, and framing responsible AI as a novel ethics project may complicate it, confuse leadership, and stall action.


What cannot carry over unchanged is the measurement and enforcement model. Human oversight is periodic because human output is periodic. Machine judgment is continuous, so its oversight must be continuous: telemetry instead of interviews, automated monitoring instead of sampling alone, standing reporting instead of ad hoc updates, and pre-set intervention thresholds instead of after-the-fact review.


This pair of observations, values unchanged and measurement and enforcement transformed, compresses into a working definition: Responsible AI is the discipline of making AI’s behavior observable, its risks proportionately controlled, and its humans accountable.


Each clause is load-bearing. Observable: you can see what the system did and why. Proportionately controlled: oversight is sized to consequence (a chatbot suggesting meeting times does not need the scrutiny of a model denying credit). Humans accountable: every consequence traces to a name, not to “the algorithm.”


4. The Nine Artifacts


The definition becomes operational through nine artifacts, three for each clause of the definition: three that make behavior observable, three that keep risk proportionately controlled, and three that keep humans accountable. None is novel. Each is a structure the enterprise (board, c-suite, and other layers of leadership) already maintains for capital allocation, re-instantiated for AI systems that exercise judgment. Download Whitepaper for Table Diagram


The table rewards a second reading, because the mapping is structural. The reason a general ledger exists is that capital moves through many hands and the enterprise needs one authoritative record of what happened. Decisions now move through many systems, and the enterprise needs the same. The reason capital approval exists is that some commitments are too consequential to make without senior sign-off. Deploying or materially changing a high-consequence model is exactly such a commitment. The logic transfers because the problem transfers.


The mapping tells corporate leadership how to allocate effort. Some organizations can see everything their systems do. Yet they may have tiered nothing, undersized controls, and set no thresholds a system must clear before it goes live. Others gate deployment tightly, yet no system has a named owner and no one outside the operating team ever verifies the result. The proactive board question is not “do we govern AI?” but “which of the nine artifacts do we already have, and which is weakest?”


5. The Regulatory and Policy Direction of Travel


External frameworks are converging on the same architecture:


  • Model risk management came first. U.S. banking supervisors’ guidance on model risk management (Federal Reserve SR 11-7 and OCC Bulletin 2011-12, issued 2011) required model inventories, tiered validation, and review independent of model owners: the nine-artifact pattern in miniature, fifteen years early.

  • NIST generalized it. The NIST AI Risk Management Framework (AI RMF 1.0, 2023) organizes AI governance into Govern, Map, Measure, and Manage functions: accountability structures, inventory and context, measurement, and proportionate response.

  • The EU codified it. The EU AI Act (Regulation (EU) 2024/1689)1 is built on risk tiering, with obligations (logging, documentation, human oversight, conformity assessment) all scaled to consequence.


A leadership team that builds the nine artifacts is not betting on any one regulation. It is building the substrate every current framework presumes.


1Under the Digital Omnibus on AI, the first amendments to the EU AI Act since its 2024 adoption, a provisional agreement reached on May 7, 2026, and approved by the European Parliament on June 16, 2026, defers high-risk obligations: Annex III systems move from August 2, 2026, to December 2, 2027, and Annex I product-regulated systems from August 2, 2027, to August 2, 2028. These changes take legal effect only upon formal adoption and publication in the Official Journal; August 2, 2026, remains an active compliance date until then. The tiered architecture is unchanged.


6. What Boards and Executives Should Do Now


The practical program follows directly from the table:


  • Take the inventory first. Nothing else is possible until every AI system exercising judgment is registered. The inventory effort may surprise you; “shadow AI”, or unauthorized internal use of AI tools, is the shadow IT of this decade. For example, an employee pasting company data into a personal AI assistant, or a colleague quietly leaning on a chatbot to draft part of their work, rarely shows up on any system of record. Personal devices are a common way this slips in, and unintentional AI compounds the problem as vendors push frequent, asynchronous AI features into enterprise systems you already run.

  • Tier before you control. Proportionality is what makes the program affordable. Classify systems by consequence and autonomy, then match the oversight to the tier, so the higher the tier, the more controls the system carries. Tools like the OakTruss Group AI Cube™ bring structure, technical competence, and consistency to this exercise.

  • Assign names, not departments. Every system gets one accountable owner. A committee selects, prioritizes, and coordinates; a person answers.

  • Put AI on the standing board and c-suite agenda. Board and leadership consumable reporting: what the portfolio of systems did, what escaped its bounds, what changed, in the same (or more frequent) cadence and discipline as financial reporting.

  • Commission independent assurance early. Internal audit already knows how to verify controls it did not design. Extend its charter. Solicit competent external auditors and advisors to verify AI systems are being deployed responsibly.


Conclusion


AI has compelled the evolution of corporate governance in the most literal sense: the actor being governed has changed, so the machinery of governance must follow it. But the evolution is a homecoming, not a departure. For a century, boards governed judgment indirectly, through the trail it left in capital. Now that judgment also lives in software, boards must govern it there, with an inventory, a ledger, a tiering scheme, controls, gates, a charter, named owners, standing reporting, and independent assurance.


Capital allocation has a ledger, a budget, an approval matrix, and an auditor. The judgment now exercised in software needs the same. The organizations that internalize this will find responsible AI neither mysterious nor optional. Responsible AI is just governance, doing what governance has always done.


OAKTRUSSGROUP.COM | DALLAS, TX 75201 6 © 2026 OakTruss Group


References

Board of Governors of the Federal Reserve System. Supervisory Guidance on Model Risk Management, SR Letter 11-7 (jointly with OCC Bulletin 2011-12). April 2011.


National Institute of Standards and Technology. Artificial Intelligence Risk Management Framework (AI RMF 1.0). NIST AI 100-1, January 2023.


European Union. Regulation (EU) 2024/1689 (Artificial Intelligence Act). Amendments under the Digital Omnibus on AI (provisional agreement of 7 May 2026; European Parliament approval of 16 June 2026), pending formal adoption and Official Journal publication.



 
 
bottom of page