AI governance continues to evolve in 2025 for both boards and senior management teams. Recent studies suggest many companies are not achieving the desired return on investment from AI projects, and many boards are devoting time to AI governance without achieving desired outcomes. Effective board members and leaders understand their role in safeguarding data, governing new technologies and ensuring the necessary skills in the boardroom and across the organization.
A widely circulated MIT study, The GenAI Divide: State of AI in Business in 2025, reports that despite $30 to $40 billion in enterprise investment in AI, 95% of organizations are getting zero return. Gartner reports that even with an average spend of $1.9 million on generative AI (GenAI) initiatives last year, less than 30% of AI leaders report their CEOs are happy with AI investment returns.
OpenAI’s Sam Altman sees an AI bubble forming as industry spending surges without commensurate gains in performance. Studies from Harvard and Stamford show significant workforce implications.
According to the National Association of Corporate Directors (NACD) 2025 Trends and Priorities Survey, three of the 10 top director trends for 2025 involve technology governance. Cybersecurity threats and AI remain at the center of directors’ technology concerns. In WTW’s most recent Emerging and Interconnected Risks Survey, executives worldwide listed AI and cyber risk as the top two out of 752 emerging risks. Additionally, WTW’s 2025 Directors’ & Officers’ Risk Survey reports data loss and cyberattacks are both within the top three risks.
As we covered in How board-level AI governance is changing, research from professor and corporate director Dr. Helmuth Ludwig and professor Dr. Benjamin van Giffen includes a four-category AI governance model. They recently updated their report with guidance and practices for boards on AI oversight using four pillars under an array of different scenarios, with input from NACD program manager for digital and cybersecurity governance content Dylan Sandlin, board members Rima Qureshi and Samantha Kappagoda, and staff from the Data & Trust Alliance.
Strategic oversight: According to NACD’s 2025 Public Company Board Practices and Oversight Survey, more than 62% of directors set aside agenda time to discuss AI. Yet while many directors note the potential for AI disruption to their company’s strategy and long-term viability, only 23% of boards have assessed how it might happen. Effective boards recognize AI as a material strategic enabler and differentiator that influences an organization’s competitive position and business model.
They adopt three practices:
Capital allocation: Many boards identify proper allocation of capital resources as one of the challenges their organizations faces in adopting AI technologies. Yet only 11% of boards have approved an annual budget for AI projects. Effective boards recognize AI has broad implications for business strategy and operations.
They adopt two practices:
AI risks: Effective boards treat risk oversight not only as a board’s core fiduciary responsibility but also as central to the responsible use of AI systems and maintaining trust among key stakeholders. They recognize that AI may help protect competitive advantage and can play a role in a company’s potential for value creation or destruction.
They adopt two practices:
AI technology competence: Effective technology governance, including AI and data oversight, requires full board engagement with all directors maintaining at least a foundational knowledge of AI and its influence on the organization’s particular needs. These boards also ensure the CEO, management team and workforce have the technological competence to execute the company’s AI agenda.
They adopt four practices:
Effective leaders have shifted from traditional risk management protocols to more dynamic and responsible governance models for managing AI’s growth across industries and applications while adhering to their values. These leaders adopt principle-based governance practices that allow their organizations to benefit from AI technologies while reducing risks and increasing trust and accountability.
A version of this article originally appeared on Forbes on September 19, 2025.