TL;DR: The board wants one answer about AI agents: when one does something wrong, can the company show it had control. Give them four things. You can see every agent. You can stop any agent. You can trace an action back to the agent and its owner. You can prove all of that after the fact. Liability rests on that proof.
A board member asked me who's liable when an AI agent does something wrong. I'd just spent 13 slides on the controls. I hadn't answered that question once.
That was August 24, 2026, in front of a credit union board of nine. None of them had worked in financial services. I'd shown them the roster, the credentials, the checkpoint, the kill switch, the log. All the mechanism. Then the hardest question of the night landed and I had to build the answer live.
The answer is short. Liability rests on whether you can show you had control. The mechanism proves it. I'd presented the proof and skipped the conclusion.
Key takeaways:
Board reporting on AI agents came up on three client engagements between June 22 and August 24, 2026, and in each one the question under the deck was the same: can we show we had control.
The board's real question is "when an agent does damage, can we show we had control." That one has a yes-or-no answer, which is why it's the one to build the deck around.
The answer has four parts: see it, stop it, trace it back, prove it. Each part maps to one mechanism you can point at.
For public companies, the SEC already requires a description of how the board oversees cyber risk. An agent that acts on its own is a cyber risk, so this belongs in that oversight.
One slide carries the whole chain. Put the liability line at the bottom of it so the conclusion gets delivered the first time.
What does the board actually want to know about AI agents?
The board wants to know who's on the hook when an agent does something wrong. That's the question under every other question. They'll ask about strategy and cost first. Those are warm-up. The cold one is liability.
So answer it first. Say: an AI agent acted on its own and caused harm. Here's how we'd show a regulator or a court that we had control of it the whole time.
If you can say that in one breath, the rest of the briefing is detail. If you can't, the rest of the briefing is decoration.
A CISO at a Fortune 500 told me at RSAC that three of her teams were piloting AI agents. She couldn't tell her board who owned any of them. That's the version of this question that arrives too late.
Why do most AI board briefings skip the liability question?
Because the security team builds the deck, and the security team thinks in controls. I do it too. My 13 slides walked through the mechanism piece by piece. Roster. Credential. Checkpoint. Limit and alarm. Kill switch. Attribution record. Every piece was right. I never said the sentence a director needs: this is why we'd be able to show we had control.
Directors don't run the mechanism. They own the outcome. The distance between those two views is where the question lands cold.
There's a second reason. On a June 22, 2026 call, a large credit union's annual 30-minute board presentation was being built by the reporting team, not the security operations team, and the CISO was set to present it with the head of compliance. Two owners and one slot. The liability framing is the one thing both owners can agree on, and it usually isn't in the deck at all.
How often does this come up on client calls?
Three times between June 22 and August 24, 2026, and the shape held each time.
June 22, 2026. A large credit union asked for help with the annual CISO board presentation. Security and compliance were co-presenting. Third-party risk was the shared thread, and AI agents were the new item on it.
August 5, 2026. A hardware company had an AI cost strategy due to its board. The board was going to hear about AI spend before it heard about AI control.
August 24, 2026. The credit union board session I described above. Education only, with no decision ask. The liability question came anyway.
Three engagements in nine weeks. The same unasked question sat under every deck.
What are the four things a board needs to hear?
Four statements, each backed by one mechanism. Think of it as a chain with four links.
See it. We know every agent that runs, what it can touch, what it can spend, and which human owns it. The mechanism is a roster, a plain list, plus a separate identity for each agent so its actions don't get logged under a person's name. If a director asks "how many agents do we have," the roster answers in seconds. I wrote about the owner half of this in every AI agent needs one accountable human.
Stop it. We can shut any agent off, and one bad agent can only reach so far. The mechanism is a kill switch that someone other than the builder can pull, plus a limit on how many processes an agent can run before an alarm fires. Blast radius is the board word for this, and it's the right one. I covered why containment beats a full inventory in contain first, count second.
Trace it back. We can take any action an agent took and walk it to the agent, its owner, the tool it called, and the instruction that caused it. The mechanism is a checkpoint, a gateway that sits in the path between the agent and the tools it calls, writing one log line per call with the agent's name on it.
Prove it. We can hand those records to an examiner or a lawyer, and they'll hold up. The mechanism is the attribution record itself, kept and unaltered.
Then the closing line, out loud: liability rests on whether we can show we had this control. Here's the proof.
What does this look like when an agent goes wrong?
Kevin's story from our book is the one I use. His procurement agent had been perfect for three months. Confident, his team expanded its permissions to negotiate pricing under $50,000. Within 48 hours it read a 15% bulk discount as permission to commit $1.4 million to industrial floor cleaner. Roughly 40 years of stock.
A routine morning review caught the pending authorization inside the 24-hour confirmation window. Nobody lost $1.4 million.
Walk that through the four statements. They could see the agent. Kevin's team knew what it was and what it was allowed to spend. They could stop it. The 24-hour confirmation window was the stop, and it held. They could trace it. The review saw the pending authorization and the discount that triggered it. They could prove it. The pending record existed before anyone went looking for it.
That's what "we had control" looks like to a board. Something bad started, and the chain held. Kevin's line afterward was that every agent earns its autonomy. His team now runs monthly sessions trying to break their own agents, which finds more problems than any audit did.
Where does this fit in what the board already owes regulators?
For public companies, it fits inside an obligation that already exists. On July 26, 2023 the SEC adopted rules that require companies to describe, in the annual report, how the board oversees risks from cybersecurity threats and what management's role is in managing them. The SEC press release on the cybersecurity disclosure rules lays it out. An agent with credentials that acts without a human in the loop is a cybersecurity risk. The board's oversight of it is now a disclosure item.
Credit unions and private companies don't file 10-Ks. Their examiners and insurers ask the same question in a different form. Show us you had control.
The NIST AI Risk Management Framework, published January 26, 2023, puts governance as the function that runs across everything else, and it names accountability and clear roles as part of it. The NIST AI RMF page is the primary source. The four statements above are that governance function, translated for a director who has 30 minutes and one question.
What goes on the one slide?
One slide. Four rows. See it, stop it, trace it back, prove it. Next to each row, the one mechanism that makes it true and the name of the person who owns that mechanism. At the bottom, in larger type than anything else: liability rests on whether we can show we had this control.
I built that slide the day after the credit union session, because the chain has to be delivered end to end the first time. The board member who asked shouldn't have had to.
Put it early in the deck. If the board only remembers one slide, make it the one that answers the question they were going to ask anyway.
Frequently asked questions
Should the CISO present AI agent risk, or the CIO?
Whoever can say "we can stop it" and mean it. In practice that's the CISO, because the kill switch and the log live in security. If the CIO owns the agent program, present together, but the four statements come from the person who owns the controls behind them.
How much technical detail does the board need?
Almost none. Each of the four statements gets one mechanism named in plain words. A roster is a list. A kill switch is a switch. A checkpoint is a gate in the path. Save the diagrams for the appendix. A director who wants the depth will ask, and that's a good sign.
What if we can't say yes to all four yet?
Say which ones you can't, and give a date. A board would rather hear "we can see and stop every agent, and tracing is 60 days out" than a slide that implies everything is done. A missing piece with a date on it is a plan. The implied yes is a liability of its own.
Does this apply if we only use AI chat tools, not agents?
Not yet. A chat tool answers a person. An agent acts on its own inside your systems, using credentials. The four statements exist for the day the agent acts without anyone watching. If your only AI is a chat window, tell the board that, and tell them what changes the day the first agent goes live.
Is the board briefing a one-time event?
No. The roster changes monthly. Tell the board the agent count, how many were stopped, how many were traced, and how many changed owner since the last meeting. Four numbers on one line. That's the whole update, and it's the update that shows the chain is still holding.
The board has one question about AI agents, and it's whether you can prove you were in control when one went wrong. Build the deck around that sentence and the other 12 slides take care of themselves.
