Fortune 500 companies are rapidly formalising their AI governance structures, with a survey from Deloitte published this week finding that 67% of large enterprises have established or are in the process of establishing a formal AI governance board or committee — up from 31% in the same survey conducted twelve months ago.
The acceleration is driven by two converging pressures. The first is regulatory: the European Union's AI Act compliance deadline for high-risk AI systems falls in August 2026, and companies with EU operations must have documented risk management systems, human oversight mechanisms, and bias monitoring in place for AI systems used in employment, credit, healthcare, and education decisions. For multinational companies that use the same AI systems globally, compliance with EU requirements effectively sets a de facto global standard.
The second pressure is shareholder and board accountability. Following several high-profile incidents in 2025 and early 2026 where AI system failures caused reputational and financial damage to companies — including a major financial institution whose AI-based loan approval system was found to exhibit systematic bias along demographic lines — institutional investors have begun explicitly asking for AI risk reporting in the same framework as cybersecurity and operational risk.
The composition of AI governance boards varies significantly by company. Some have established cross-functional committees drawing from legal, compliance, engineering, and HR with a mandate to review and approve new AI system deployments. Others have created standalone AI ethics offices with dedicated staff. A growing number have added AI governance to the remit of existing board-level risk committees, treating AI risk as a category within enterprise risk management rather than a separate discipline.
External audit of AI systems is emerging as a new professional services category. The Big Four accounting firms have all launched AI audit practices in 2026, and several specialist AI auditing firms have raised significant funding to provide third-party technical assessment of AI systems against regulatory requirements.
The governance structures being built today face a fundamental challenge: AI systems, particularly foundation model-based systems, evolve continuously through prompt changes, model updates, and fine-tuning, unlike traditional software which changes in discrete releases. Governance frameworks designed for static software reviews are ill-suited to AI systems that can behave differently following model provider updates that the deploying organisation does not control or even necessarily notice.