Federal and state regulators are converging on a recognisable AI governance baseline. Boards of public-company and regulated-institution clients should expect the next twelve months to define what "adequate" looks like for the institutions under their oversight. This article distills the questions board members should be asking about AI governance — across model inventory, risk assessment, third-party reliance, and incident-response capacity — and offers a checklist to test the institution against the emerging baseline.

Authors