Menu
Laptop with AI search open

From AI ambition to accountability: five flags for boards and leadership teams

Posted on 2 October 2026

Reading time 5 minutes

How to move fast without losing control

AI is no longer something businesses can afford to treat as a future experiment; it is already changing how large organisations work. For boards, senior leadership teams and in-house counsel, the very real challenge is working out where AI can create real advantage to help the business, where it introduces risk or create problems, and how those risks or problems should be managed. This requires legal, commercial and technical teams to work together to implement a robust governance framework early on. Businesses will not build confidence by adopting AI technology as quickly as possible, but by making clear, informed decisions about its value, how it is governed and who is responsible for it.

From our work with corporates, there are five key flags to watch out for as AI becomes a business-critical resource.

1. Start with the business problem, not the technology

The temptation with AI is to begin with the tool. A more useful question is: what decision, process or customer experience are we trying to improve? Not every AI opportunity merits major investment: some use cases will be transformational, but others will be marginal, duplicative or better solved through changing existing processes.

Once the business problem is clear, leaders can decide whether a general-purpose AI tool is sufficient, or if a bespoke solution is needed, and what level of oversight the use case requires.

2. Be crystal clear about governance

AI exposes the limits of traditional corporate silos: a typical deployment will raise legal, data, technology, procurement, employment, IP, regulatory and potentially reputational issues. If ownership of governance is unclear, the risk will become harder to see and harder to manage. Effective governance should therefore be cross-functional and clear. It should bring lawyers, technologists, data specialists, commercial teams and senior decision-makers into the process early. The objective is not to slow the business down, but to provide a practical route to decisions that are informed, defensible and practical to implement.

Good governance allows organisations to move faster with confidence, knowing where AI is being used, why it is being used, what risks have been accepted and what controls are in place.

3. Pay particular attention to vendor contracts

Businesses may have big strategic ambitions around AI, but AI vendor contracts need careful scrutiny. The contract terms may appear standard, but the practical consequences can be significant if the technology underperforms, produces harmful outputs, infringes third-party rights or exposes sensitive data. The potential risks need to be balanced with a clear understanding of the potential commercial benefit AI may deliver.

Data is a pressure point when it comes to AI contracts, so businesses need to consider what a vendor can do with their information. Can the vendor access customer, employee or confidential business data? Can that data be used to train or improve AI models? Is it ringfenced, retained or shared? These questions should be answered before the tool becomes embedded in day-to-day operations.

The right contractual position depends on the use case: an internal productivity tool, a customer-facing chatbot and an autonomous AI agent all carry very different risk profiles. Legal teams need enough technical and commercial understanding to negotiate terms that reflect how the tool will actually be used. This means taking a hard look at areas such as data use restrictions, IP ownership and indemnities. These are not just standard contract terms; they determine who is responsible, how well the business can respond to problems, and what options it has if the technology does not work. as expected.

4. Treat agentic AI as a different risk category

Agentic AI can plan, decide, transact or trigger actions with less direct human intervention. This changes the risk conversation.

Existing legal frameworks are flexible enough to meet these new risks, but greater autonomy within agentic AI is likely to make questions on causation and accountability harder to assess, and brings evidential challenges. If an AI agent makes or influences a decision, organisations need to understand not just the output, but the process of design, deployment, instruction and oversight that produced it. Legal advice must be closely connected to how the technology works to be useful.

Two risks require particular attention – scope creep and unintended autonomy. A tool approved for a narrow purpose may gradually become part of more material decisions. Meanwhile, an agent designed to operate within guardrails may behave unpredictably if those guardrails are poorly specified, weakly monitored or misunderstood by users.

The answer is not to rule out agentic AI: agents require explicit approval, clear limits, human oversight and ongoing monitoring once deployed.

5. Measure value, not activity

AI activity is easy to showcase but AI value is harder to prove. The gap between the two is where many corporate programmes will succeed or stall. The most effective approach is to manage AI like a portfolio of investments. Each significant use case should have a clear purpose, measurable success criteria and a route to scaling, stopping or redesigning if the expected value does not materialise. This requires attention to the foundations – data quality, workflow design, procurement choices, training, adoption and change management - as well as the model.

The leadership imperative: turn AI risk into commercial discipline

Regulation of AI continues to evolve, and global businesses need to adapt to varying approaches to AI regulation.

The risk is not only that organisations move too quickly in deploying an AI solution, but also that they may move too slowly, leaving employees to adopt shadow AI tools (with significant risks to the business), competitors to gain learning advantages and governance to catch up after the fact. In AI, being passive is both a strategic choice and a risk.

AI demands a leadership response: strategic prioritisation, informed legal judgement, practical governance and a clear view of value. Organisations that get this right do not treat AI as either hype or hazard but ensure that it is manageable, accountable and commercially useful.

For corporate organisations, AI is no longer theoretical. It has strategic, legal and operational aspects, and is evolving fast. Watch our film, Finding your edge: Leading with AI or visit our AI resource centre to explore how businesses can build confidence with AI and create responsible advantage.

How can we help you?
Help

How can we help you?

Subscribe: I'd like to keep in touch

If your enquiry is urgent please call +44 20 3321 7000

I'm a client

I'm looking for advice

Something else