Skip to main content
Laminin Perspectives

6 min read

Boards and AI Governance After the SEC Cybersecurity Rule

The SEC's cybersecurity disclosure rule set a precedent audit committees are quietly extending to AI. Directors should read carefully.

The SEC's July 2023 rule requiring public companies to disclose material cybersecurity incidents on Form 8-K within four business days, and to describe their board oversight of cybersecurity risk in annual filings, has had a quieter second-order effect than the compliance conversation captured. Audit committees, who had to design and evidence oversight processes for cybersecurity, are now applying the same posture to AI. The relevant Commission rulemaking on predictive data analytics remains in flux, and the AI-specific disclosure regime is not yet where the cybersecurity regime already is. But the direction of travel is clear, and boards that wait for the specific rule will be late.

What the cybersecurity precedent established, and what is quietly being extended to AI, is a set of expectations about board-level oversight that are not satisfied by a single quarterly briefing. Directors are expected to be able to describe, in a filing and in a deposition, how the board is informed of material risks, who owns them, and how the board tests the adequacy of the controls. In practice, that means a named committee, a documented cadence, a defined set of metrics reviewed at each meeting, and a paper trail sufficient to demonstrate that oversight was exercised, not merely nominal.

For AI, the specific questions a diligent audit committee should now be asking are narrow and answerable. Which AI systems are in production against customer-facing or financially material decisions? Who owns each one? What is the incident-response process when one of them produces a materially wrong output? What is the evaluation harness that would detect quality drift before an incident? None of these questions require a technical background to ask, but each of them requires a defensible answer that a director can sign a letter behind.

The uncomfortable observation, which we make on the basis of board-level conversations with mid- and large-cap US companies through 2025 and 2026, is that most audit committees cannot answer these questions today. AI risk sits somewhere between the CIO and the CISO in most operating models, and neither role has a natural obligation to bring it to the board at the level of granularity a director now needs. Firms that have started to close this gap have generally done so by asking the general counsel, not the CIO, to own the reporting line, which changes both the vocabulary and the seriousness of the conversation.

For a director on a US public company board, the specific action to take in the next meeting is short: request a written inventory of production AI systems, with owners, decision domains, and last evaluation date. If the inventory does not exist, that is the first finding. If it does exist but has gaps, those gaps are the next quarter's agenda. And if the general counsel is not in the room for that conversation, the conversation is not yet at the level the current regulatory posture expects.

  • Board Governance
  • SEC
  • Audit Committee
  • AI Risk
  • General Counsel

Bring us a decision, not a brief.

If this piece maps to something on your plate, we'd like to hear it.

Talk to Laminin