AI’s Risk-Reward Reckoning Hits the Boardroom


The number of firms citing AI risk as a board issue has tripled. How directors can go beyond mere “oversight.”
Key Takeaways:
- Investors are pressing firms for greater transparency into AI risks and the returns expected from investments.
- Nearly 50% of Fortune 100 firms now treat AI as part of board-risk oversight, triple the number it was a year ago.
- Directors should be looking for a disciplined process for reassessing assumptions when the risk-reward equation shifts.
AI Oversight Isn’t Just About Minimizing AI Risk
The board packet on AI looked upbeat: productivity gains, new vendor partnerships, and promising early results. But as directors dug in, the questions got tougher. What risks was the company taking to produce those gains? Were the risks increasing? And was AI creating enough value to make them worthwhile?
Are the risks management is taking justified by the value AI is creating—and do leaders have a sound process for knowing when that equation changes?”
That risk-reward calculation is becoming a bigger part of board oversight. Forty-eight percent of Fortune 100 companies now explicitly identify AI as part of board-risk oversight, triple the share of a year ago, while 40% assign AI oversight to a specific board committee, up from 11% in 2024. In a separate 2026 survey, 45% of board members said their audit committees had already changed their charters to add AI oversight. Investors are pushing in the same direction: Institutional investors representing $55 trillion in assets said in a recent survey that they want greater insight into both AI risks and the returns companies expect from their AI investments. All this leaves directors with a pressing question: Are the risks management is taking justified by the value AI is creating—and do leaders have a sound process for knowing when that equation changes?
Vinay Menon, senior client partner for IT services and global lead in Korn Ferry’s AI practice, says value has become a central issue in board discussions at many non-tech firms. AI is already improving customer experience and efficiency, he says. “But now the conversation has shifted to one question: When will AI show up in the P&L?” Bryan Ackermann, Korn Ferry’s head of AI strategy and transformation, sees this push for greater financial discipline being driven in part by unstable AI costs. CEOs, he says, are asking, “Wait a minute, I see the bill—but where’s the value?” Ackermann wonders “whether cost will cure FOMO”—the fear of missing out that has fueled some AI spending.
The bigger problem, experts say, is unpredictability. A company can make a deliberate decision to accept a high cost or a known risk, but the greater challenge is to oversee something that keeps changing. “The shelf life of an AI decision is only a few months,” Menon says. That makes learning itself an important measure for boards: What did management learn from its last round of AI projects? How did those lessons change in the next round? Directors should be looking for a disciplined process for reassessing assumptions when the risk-reward equation shifts.
Some of AI’s risks can actually grow with its success. As companies find increasing uses for AI systems, more sensitive data may flow through them, and employees may rely on them for more important work. That raises the stakes for oversight. Menon points to proprietary data as one example: “Boards have a duty to ask whether it’s being protected appropriately.” For directors, the issue is not only whether safeguards exist, but also whether management is tracking the company’s exposure as AI is woven more tightly into its operations.

Greater reliance can create another kind of exposure: loss of control. A company may depend on AI to perform a critical function without controlling the model, the vendor that provides it, or even the rules governing access to it. “The more critical AI becomes to the business,” Ackermann says, “the more boards have to ask who ultimately controls it.” That question has become especially important for multinationals, he says, as governments place new limits on who can use certain AI technologies and where. In other words, a successful AI deployment can also create a new point of vulnerability.
Experts say that’s what makes the risk-reward calculation so important for boards. Directors, they say, need to test whether management understands what new exposures the company is accepting in exchange for AI’s returns—and whether that trade-off still makes sense as the technology becomes more valuable and potentially riskier. As Ackermann says, “Governing AI is like managing quicksand beneath your feet.”
Learn more about Korn Ferry’s Business Transformation capabilities.
