One question drives everything we publish: How do we preserve legitimate human governance in an age where machines increasingly shape, recommend and influence decisions?
For centuries, governance assumed a chain of human action: people gather information, people analyse it, people recommend, people decide. AI is changing every one of those stages. That is not a technology development. That is a constitutional shift for organisations.
We investigate what AI does to governance — to the integrity of institutional decisions, to the chain of human accountability, and to the evidence a board would need to defend itself if its oversight were ever questioned.
Filtered by governance problem, not by source. Regulations change. These problems don't.
When AI causes harm, the question courts and regulators will ask is not whether the board knew about the AI system. It is whether the board exercised reasonable oversight of the decisions made using it. Awareness is not oversight. Most boards cannot demonstrate the difference — because the evidence does not exist.
When AI recommends and a human approves, the attribution of that decision is not automatic. Courts are beginning to ask a more precise question: was the human approval genuine deliberation, or was it ratification? The distinction carries legal weight. In Mobley v. Workday, 1.1 billion job applications were rejected by an AI system. The organisations that deployed it approved the system. Whether that approval constitutes a decision is now a federal question.
Governance is not governance unless it is documented. The ICO has confirmed that nominal human involvement in AI decisions — without real authority to change outcomes — does not satisfy UK GDPR Article 22. If your board's AI oversight were scrutinised tomorrow: what minutes would you produce? What policies? What risk assessments? What audit trail? The answer to this question is your actual governance position — not the one on paper.
Boards delegate AI governance routinely — to technology committees, to executive teams, to external providers. What they cannot delegate is accountability. When an AI system causes harm, accountability does not follow the delegation. It stays with the board. Zillow's board delegated pricing decisions to an algorithm. The $881M loss, and the subsequent SEC investigation, did not stay with the algorithm team.
The black box problem is not a technical limitation. It is a constitutional one. If a board cannot understand how a consequential decision was made, it cannot exercise the oversight its legal duties require. "The algorithm decided" is not an explanation — it is an admission. The FRC has confirmed that audit firms remain fully accountable for audit quality regardless of AI tool use. The same principle applies to boards: deploying an unexplainable system does not excuse the board from explaining its outputs.
AI-generated board papers are already in use. The governance paradox is this: a board's ability to scrutinise depends entirely on the quality of the information it receives. When AI generates that information, the board is scrutinising an output it cannot interrogate, produced by a system it may not understand, based on data whose provenance it cannot verify. This is not a future problem. It is arriving. And most governance frameworks have no answer to it.
Agentic AI systems — those that take actions autonomously, including communicating and negotiating with other parties — are moving from experiment to deployment. When an AI agent agrees terms, places orders, or commits resources on behalf of an organisation, the question of authority arises immediately: was this authorised? By whom? Under what governance framework? This is not hypothetical. The legal infrastructure for answering these questions does not yet exist. The governance infrastructure is even further behind.
Shadow AI — the use of AI tools outside sanctioned channels — is the fastest-growing governance gap in most organisations. The Microsoft/LinkedIn Work Trend Index found that 75% of knowledge workers use AI at work, with half using tools their organisations have not approved. The board cannot oversee what it cannot see. And most boards are not seeing most of the AI in their organisations. The question is not whether this is happening. It is whether the board has created the conditions to discover it.
Accountability for AI harm does not disappear because the decision was made by an algorithm. It transfers — to the organisation that deployed the system, the board that authorised it, and those who failed to exercise adequate oversight.— CruX AI Accountability Board Briefing, June 2026
Ten questions. Five minutes. A diagnostic of your organisation's current governance position — and what to prioritise next.
Every question in this assessment is one a court, regulator, or public inquiry might ask of your board. The results will indicate where your governance is sound — and where it is not.
Designed for board directors, company secretaries, and governance professionals. No technical knowledge required.
The CruX Briefing is a monthly publication for boards and company secretaries. It does not report what happened. It investigates what it means — for governance, for accountability, and for the decisions boards will face next.
Written to pass the three tests: true, useful, and still relevant in ten years.
Financial services boards must now confirm their AI systems are classified, documented, and supervised. Non-compliance: fines of up to €15 million or 3% of global annual turnover (whichever is higher). Most boards have outsourced this classification to their technology teams. The question is whether the board has formed its own view.
Ask your executive team. If the answer takes more than a week to produce, that is your governance gap.
Written for board directors, company secretaries, risk and compliance officers, and legal counsel. Free, monthly, and board-ready.
Monthly. No spam. Unsubscribe in one click.
Each engagement is built around the same question: what does your board need to understand, and what evidence does it need to demonstrate that it does?
Direct advisory support for boards navigating AI governance. AI risk briefings, accountability reviews, and board-ready assessments for audit committees and full boards.
Building the governance structures organisations need to manage AI responsibly — from policy and acceptable-use frameworks to shadow AI discovery and risk register integration.
Practical, non-technical education for boards and senior leadership. AI literacy, director duties, accountability masterclasses. No technical background required.
Evidence-based keynotes for governance conferences, company secretary institutes, board leadership forums, and in-house leadership days.
Most AI governance commentary comes from technologists who don't understand governance — or generalist consultants who don't understand law. CruX was founded by a dual-qualified solicitor, chartered company secretary, and corporate governance expert.
We understand the legal duties directors face and the governance mechanics of how boards actually work. That combination is rare. In AI governance, it is the only combination that produces thinking that is both true and useful.
We believe that in ten years, the question of how institutions preserve legitimate governance when technology changes how decisions are made will be recognised as one of the defining governance questions of our time. CruX intends to be the place that consistently explores it with rigour, evidence, and practical insight.
Start a conversationWe don't advise on AI. We advise on what AI does to governance — to the integrity of decisions, to the chain of accountability, and to the evidence a board would need if its oversight were ever challenged.
Our vocabulary
Whether you need a one-off board briefing, a full governance programme, or a keynote for your next event — we'd like to hear from you.
All initial conversations are confidential and without obligation.