The Board Still Decides: Governing Algorithmic Decisions in an AI-Driven Enterprise
- Dr M Maruf Hossain, PhD, GAICD

- Feb 21
- 4 min read
Updated: Mar 1
Artificial intelligence (AI) has not created a new category of ownerless decisions in your business. Every outcome generated by an algorithm remains an act of the company, and therefore falls squarely within the legal and moral accountability of the board and executive.

AI does not dilute board accountability
In corporate law, the company is the decision‑maker, and the board is its collective mind. When a model approves a loan, denies a claim, reallocates staff, or routes complaints, those are company decisions, even if no human clicked the approve button. AI is a tool in the workflow, not an independent actor that can own the decision or absorb liability.
For directors, this has a blunt implication: you cannot point at a black box and say, “it decided”. Complexity of the technology does not reduce the standard of care; it raises the baseline for what a reasonable director must ask.
The non‑delegable stewardship of the board
Directors in Australia remain bound by duties of care, diligence and acting in the best interests of the company under the Corporations Act. While powers can be delegated, stewardship of core matters—strategy, risk appetite, organisational design, culture, and key policies—cannot be handed over to an algorithm.
If AI is used in a non‑delegable domain (for example, pricing in a way that reshapes market conduct, triaging vulnerable customers, or allocating scarce care resources), the law treats that as a board‑level decision. The business judgment rule offers no safe harbour if you have not rationally informed yourself, interrogated assumptions and satisfied yourself that AI‑enabled decisions align with strategy, risk appetite and values.
For executives and boards, the practical test becomes: could we defend this AI‑enabled decision, in this context, as if we had made it ourselves?
Cascading accountability, not “AI made me do it”
Effective AI governance embeds accountability into line management, not just technology forums. Responsibility should cascade from the board to the CEO and into specific executives who can be clearly named as accountable for defined decision classes.
A useful distinction is between:
·The business owner: the executive who owns the workflow, customer impact, P&L and compliance obligations.
The technical custodian: the CIO/CDO or equivalent who is responsible for model build, infrastructure, performance and monitoring.
Once AI is in production—approving refunds, changing credit limits, routing complaints—it stops being an innovation project and becomes operational behaviour. When something goes wrong, the accountable person is the business owner who authorised that workflow, not the data scientist who wrote the code.
This single‑threaded ownership prevents the accountability gap that often emerges when AI is spread across labs, committees and shared services with no clear line of sight to outcomes.
Verifiable human contribution: how human oversight actually works
For material decisions, Human-in-the-Loop (HITL) must mean more than a checkbox. A strong model is a verifiable human contribution (VHC) – showing, for each decision class, what the system recommended, what a human accepted or overrode, and why.
Different patterns imply different accountability settlements:
Human‑in‑the‑loop: a human reviews each decision before action; accountability sits with the individual decision‑maker.
Human‑on‑the‑loop: a supervisor monitors a stream of decisions and intervenes by exception; accountability is shared between operator and system owner.
Human‑in‑command: an executive sets use cases, thresholds, and kill switches; accountability sits at the senior executive or committee level.
Autonomous workflow: no routine human review, only guardrails; accountability rests with the business unit head who authorised that automation.
If there is no meaningful human review over a material decision that can affect customers, financial resilience, safety or reputation, that is not innovation – it is a control failure that can translate into personal exposure for directors.
Regimes that already assume AI
Several regimes have already embedded this logic.
Under the Financial Accountability Regime (FAR), accountable persons must map clear lines of responsibility across the AI lifecycle within their remit and take reasonable steps to prevent harm to the entity’s reputation.
In aged care, new responsible person duties require directors and senior managers to exercise due diligence over systems and processes, including those powered by AI, that underpin the quality and safety of care.
These frameworks are converging on a simple principle: you cannot outsource accountability to software. You must design, document and own it.
Eight board‑level levers for AI governance
A practical way for boards and executives to operationalise this is to use the eight AI governance elements articulated in recent AICD guidance, adapted to your context.
Roles and responsibilities: Formally assign who is accountable for specific AI‑enabled decisions, across both business and technology, and ensure those roles are reflected in position descriptions and performance contracts.
Governance structures: Refresh board and committee charters so AI risk and opportunity are explicitly in scope for the full board, risk, audit and people committees where relevant. Avoid relegating AI to an innovation committee without hard authority over risk.
People and culture: Lift digital and AI literacy for directors and executives so they can ask informed questions and resist automation bias. Enc culture where challenging a model’s output is seen as diligence, not obstruction.
Strategy and policies: Tie AI initiatives to clear strategic objectives and risk appetite, and codify acceptable use, escalation thresholds, and prohibited uses in policy.
Processes and controls: Use AI impact assessments to move from “trust me” to “show me” for high-risk use cases—documenting data sources, model purpose, potential harms, mitigations, and sign‑offs.
Infrastructure and data: Maintain an inventory of AI systems and a robust data governance framework; without trustworthy data, no AI governance framework will succeed.
Stakeholder engagement: Ensure those affected by AI decisions—customers, employees, residents, patients—know how to question, appeal, or seek redress.
Monitoring and audit: Extend assurance beyond model accuracy to outcomes, including bias, distributional impacts, compliance breaches, customer detriment, and alignment with stated values.
What this means for your next board cycle
For a C‑suite or board agenda, the AI conversation now needs to move from “can we use it?” to “who owns the outcomes, and how will we prove it?” Three concrete moves in the next 12 months could be:
Mandate a single accountable executive for each critical AI use case, documented in your accountability maps.
Require VHC‑style evidence for material AI‑assisted decisions in risk‑sensitive domains.
Commission an AI governance review using the eight‑element framework, with explicit board‑level action items.
The organisations that will be trusted to scale AI are not those with the most sophisticated models, but those where accountability for algorithmic decisions is as clear and as non‑delegable as any other act of leadership.


