AI Governance · cruxlaw.ai

We don't report
what AI is doing.
We investigate what AI
is doing to governance.

One question drives everything we publish: How do we preserve legitimate human governance in an age where machines increasingly shape, recommend and influence decisions?

For centuries, governance assumed a chain of human action: people gather information, people analyse it, people recommend, people decide. AI is changing every one of those stages. That is not a technology development. That is a constitutional shift for organisations.

We investigate what AI does to governance — to the integrity of institutional decisions, to the chain of human accountability, and to the evidence a board would need to defend itself if its oversight were ever questioned.

The Questions Nobody Is Asking

The board questions that matter — and that most boards are not yet asking

Filtered by governance problem, not by source. Regulations change. These problems don't.

Oversight

Can your board prove it exercised reasonable oversight of AI?

When AI causes harm, the question courts and regulators will ask is not whether the board knew about the AI system. It is whether the board exercised reasonable oversight of the decisions made using it. Awareness is not oversight. Most boards cannot demonstrate the difference — because the evidence does not exist.

Oversight
Decision-Making

Who actually made the decision — the director or the algorithm?

When AI recommends and a human approves, the attribution of that decision is not automatic. Courts are beginning to ask a more precise question: was the human approval genuine deliberation, or was it ratification? The distinction carries legal weight. In Mobley v. Workday, 1.1 billion job applications were rejected by an AI system. The organisations that deployed it approved the system. Whether that approval constitutes a decision is now a federal question.

Decision-Making
Evidence

What evidence would exist if your AI governance were challenged in court?

Governance is not governance unless it is documented. The ICO has confirmed that nominal human involvement in AI decisions — without real authority to change outcomes — does not satisfy UK GDPR Article 22. If your board's AI oversight were scrutinised tomorrow: what minutes would you produce? What policies? What risk assessments? What audit trail? The answer to this question is your actual governance position — not the one on paper.

Evidence
Accountability

Has your board delegated responsibility without retaining accountability?

Boards delegate AI governance routinely — to technology committees, to executive teams, to external providers. What they cannot delegate is accountability. When an AI system causes harm, accountability does not follow the delegation. It stays with the board. Zillow's board delegated pricing decisions to an algorithm. The $881M loss, and the subsequent SEC investigation, did not stay with the algorithm team.

Accountability
Human Judgement

How do you govern a decision that no one can explain?

The black box problem is not a technical limitation. It is a constitutional one. If a board cannot understand how a consequential decision was made, it cannot exercise the oversight its legal duties require. "The algorithm decided" is not an explanation — it is an admission. The FRC has confirmed that audit firms remain fully accountable for audit quality regardless of AI tool use. The same principle applies to boards: deploying an unexplainable system does not excuse the board from explaining its outputs.

Human Judgement
The Next Problem

What happens when AI writes the board paper the board is supposed to scrutinise?

AI-generated board papers are already in use. The governance paradox is this: a board's ability to scrutinise depends entirely on the quality of the information it receives. When AI generates that information, the board is scrutinising an output it cannot interrogate, produced by a system it may not understand, based on data whose provenance it cannot verify. This is not a future problem. It is arriving. And most governance frameworks have no answer to it.

The Next Problem
The Next Problem

When AI negotiates on behalf of your organisation, who authorised those terms?

Agentic AI systems — those that take actions autonomously, including communicating and negotiating with other parties — are moving from experiment to deployment. When an AI agent agrees terms, places orders, or commits resources on behalf of an organisation, the question of authority arises immediately: was this authorised? By whom? Under what governance framework? This is not hypothetical. The legal infrastructure for answering these questions does not yet exist. The governance infrastructure is even further behind.

The Next Problem
Oversight

Does your board know what it doesn't know about AI in your organisation?

Shadow AI — the use of AI tools outside sanctioned channels — is the fastest-growing governance gap in most organisations. The Microsoft/LinkedIn Work Trend Index found that 75% of knowledge workers use AI at work, with half using tools their organisations have not approved. The board cannot oversee what it cannot see. And most boards are not seeing most of the AI in their organisations. The question is not whether this is happening. It is whether the board has created the conditions to discover it.

Oversight
Accountability for AI harm does not disappear because the decision was made by an algorithm. It transfers — to the organisation that deployed the system, the board that authorised it, and those who failed to exercise adequate oversight.
— CruX AI Accountability Board Briefing, June 2026
Self-Assessment

The Questions You Should Be Able to Answer

Ten questions. Five minutes. A diagnostic of your organisation's current governance position — and what to prioritise next.

Every question in this assessment is one a court, regulator, or public inquiry might ask of your board. The results will indicate where your governance is sound — and where it is not.

No data stored or transmitted

Designed for board directors, company secretaries, and governance professionals. No technical knowledge required.

Question 1 of 10
Loading...
0
/ 10
Talk to CruX
The CruX Briefing

Every month. One investigation. One question. One framework.

The CruX Briefing is a monthly publication for boards and company secretaries. It does not report what happened. It investigates what it means — for governance, for accountability, and for the decisions boards will face next.

Written to pass the three tests: true, useful, and still relevant in ten years.

  • One regulatory development — investigated from a governance perspective, not just reported
  • One AI incident dissected — the governance failure inside it, not just the technology failure
  • One board question — something concrete to take to your next meeting
  • Written in plain English. Board-ready. Free to share.
  • Free, forever. No upsell.
Sample — The CruX Briefing June 2026
The investigation

EU AI Act high-risk obligations are live — but the real question is whether boards know what "high-risk" means

Financial services boards must now confirm their AI systems are classified, documented, and supervised. Non-compliance: fines of up to €15 million or 3% of global annual turnover (whichever is higher). Most boards have outsourced this classification to their technology teams. The question is whether the board has formed its own view.

The board question

Which AI systems are making consequential decisions about people — and who is accountable for each one?

Ask your executive team. If the answer takes more than a week to produce, that is your governance gap.

Work With Us

If this thinking is useful to your board, here is how we can help

Each engagement is built around the same question: what does your board need to understand, and what evidence does it need to demonstrate that it does?

01

Board Briefings & Advisory

Direct advisory support for boards navigating AI governance. AI risk briefings, accountability reviews, and board-ready assessments for audit committees and full boards.

02

Governance Frameworks

Building the governance structures organisations need to manage AI responsibly — from policy and acceptable-use frameworks to shadow AI discovery and risk register integration.

03

Training & Workshops

Practical, non-technical education for boards and senior leadership. AI literacy, director duties, accountability masterclasses. No technical background required.

04

Speaking & Keynotes

Evidence-based keynotes for governance conferences, company secretary institutes, board leadership forums, and in-house leadership days.

Why CruX

Why CruX?

Most AI governance commentary comes from technologists who don't understand governance — or generalist consultants who don't understand law. CruX was founded by a dual-qualified solicitor, chartered company secretary, and corporate governance expert.

We understand the legal duties directors face and the governance mechanics of how boards actually work. That combination is rare. In AI governance, it is the only combination that produces thinking that is both true and useful.

We believe that in ten years, the question of how institutions preserve legitimate governance when technology changes how decisions are made will be recognised as one of the defining governance questions of our time. CruX intends to be the place that consistently explores it with rigour, evidence, and practical insight.

Start a conversation

We don't advise on AI. We advise on what AI does to governance — to the integrity of decisions, to the chain of accountability, and to the evidence a board would need if its oversight were ever challenged.

Our vocabulary

Institutional Judgement
The capacity of an institution to reach decisions that are genuinely reasoned, defensible, and human.
Decision Integrity
Whether the process by which a consequential decision was made can withstand scrutiny.
Governance Evidence
The documented proof that a board exercised the oversight its legal duties require.
Accountability Chain
The traceable line of human responsibility from decision to consequence — which AI can break.
Get in touch

Start a conversation

Whether you need a one-off board briefing, a full governance programme, or a keynote for your next event — we'd like to hear from you.

All initial conversations are confidential and without obligation.

hello@cruxlaw.ai
📍
United Kingdom

We respond within one business day. All enquiries are confidential.