A board of directors opens the "artificial intelligence" item. An AI risk committee has been formed, a charter adopted, a governance team appointed. Then a simple question: can we answer, with evidence, for each of our AI systems in production? The silence that follows measures readiness more faithfully than the org chart.

The structures have grown faster than the ability to answer for them. According to a survey reported by Fortune in December 2025, 70% of Fortune 500 executives report an AI risk committee and 41% a dedicated governance team, but only 14% say they are fully ready to deploy AI.

A board's AI readiness is measured property by property and system by system, on evidence. A committee attests to an intention; a score attests to the facts. And in 2026, liability is settled on the facts.

In short: A board's AI readiness does not come down to a committee or a charter. It is measured system by system, on six properties and on evidence. In 2026, the AI Act makes part of the high-risk obligations enforceable and liability rises to the deployer, hence to the board. Three questions decide: who validates this use, where the data goes, whether results replay. identifiable's AI readiness report, free, places a board on these questions from the AI Index diagnostic and the iDIA framework, and names the first gap to close.

Why 2026 moves AI risk to the board

Three forces converge this year, and they all point to the boardroom table.

First, the law. From August 2, 2026, part of the obligations of the EU AI Act covering high-risk systems becomes enforceable, with penalties of up to 7% of global annual revenue for the most serious breaches. The regulation assigns liability to the system's deployer, not only to its provider. A Canadian organization that processes data of EU residents is concerned, as our analysis of the AI Act coming into force details.

Second, indirect regulatory pressure. The NIST AI RMF, voluntary in theory, is increasingly invoked by sector regulators as a standard of reasonable care. In February 2026, the US Treasury translated its principles into an AI risk management framework for financial services, some 230 control objectives. What was a best practice is becoming an opposable reference.

Third, governance doctrine. In April 2026, KPMG and INSEAD published global AI governance principles for boards. AI oversight is treated there as a fiduciary duty, on par with financial or cyber risk. AI now belongs to the board; what remains is what a board must be able to produce when the question arrives.

Why a committee does not make a board ready

An AI risk committee attests to an intention: the organization has decided to handle the subject. It does not attest that a given system is traceable, that its data is controlled, that its results replay. Intention and evidence live at two different levels.

That is what the gap between 70% of organizations with a committee and 14% that say they are ready reveals. Between the two sits an illusion of coverage: the structure exists, so the risk is supposedly held. Yet risk is not held by the org chart, it is held by evidence, on each system.

A headline score flatters, too. An organization that judges itself "70% ready" is reassured, while the danger does not hide in the average but in the weakest property of a single critical system. A flattering average masks concentrated risk: exactly what the case of a strong overall Index shows, where a single property below the floor fails the whole.

The board itself is concerned. According to KPMG's AI Pulse survey, only 8% of boards judge themselves to have strong AI expertise; and while a large majority of directors already use AI for board work, few govern that use. The table that oversees AI rarely governs its own.

The three questions that decide liability

When the question arrives from a regulator, a client or an auditor, it almost always comes down to three. Each maps to a measurable property of the iDIA framework:

  • Who validates this use? Traceability of the decision and named accountability: the Accountable and Governed properties.
  • Where does the data go? Residency, dependencies and controls specific to AI risk: the Sovereign and Secure properties.
  • Do the results replay? Documented, replayable configurations and outputs: the Reproducible property.

A board that can answer, on evidence, has played its Move 38, the move that belongs to the human once the machine's capability is acquired. A board that defers to the model's output discovers the gap at the worst moment, when the question is already on the table.

The AI readiness report, free for boards and executives

Measuring this does not require a six-month audit to begin. identifiable brings its evaluation tools together in a new form, readable by a board: the AI readiness report, free of charge.

It starts from the AI Index diagnostic, which situates an organization on the six properties in twelve questions and produces a score from 0 to 100. That diagnostic is then read against the iDIA framework and the four frameworks (ISO/IEC 42001, NIST AI RMF, AI Act, Law 25), then translated into a custom report: where you stand on each property, where the risk concentrates, and the first property to address.

The deliverable fits a board reading: a profile, a verdict per property, a priority. It is free, without commitment, and serves as the entry point to a Move 38 evaluation scoped on your real systems when you decide to go further.

The report does not replace the Responsible AI Practice designation, granted at the threshold after a full evaluation. It answers a more immediate question, the one a board asks before all the rest: where do we really stand, today?

A committee attests to an intention. A score answers for the facts.