September 29, 2026 in Artificial Intelligence
The Governance Illusion
Why Boards Mistake Compliance for Cyber and AI Readiness
SHARE: PRINT ARTICLE:
https://doi.org/10.1287/LYTX.2026.03.14
Boards are asking more cybersecurity and AI governance questions than ever. But without a clear grasp of what genuine readiness to deal with risk requires, those questions often elicit reassuring answers rather than a true picture of governance underneath – an illusion of readiness that only breaks under real pressure. Post-incident reviews repeatedly surface the same finding: the board had confirmed that policies existed and audits had been passed, but it never confirmed that the organization could actually detect, contain, and recover from a real cyber incident or AI failure. Overseeing the paperwork of governance is not the same as overseeing the capability itself.
The Compliance Theater Problem
“Compliance theater” is the practice of satisfying the appearance of oversight without building the capability that oversight is meant to produce. It is rarely a failure of intent; most directors take fiduciary duty seriously. It emerges instead from how cyber and AI risk information gets packaged and consumed at the board level.
In April 2025, a ransomware attack halted online operations at the British retailer Marks & Spencer for weeks; the company estimated the hit to its operating profit to be around £300 million. The entry point was not a zero-day exploit, but a single contractor’s socially engineered credential. By every formal measure, the organization was compliant.
Richa Kaul, founder and CEO of the GRC platform Complyance, sees this pattern constantly when organizations pass compliance tests but still suffer catastrophic breaches. “I hope you’re never looking at a green dashboard,” Kaul says, “because it’s almost always going to be nonsense if that’s what you’re really seeing.”1 The gap between being compliant and being secure is where attackers operate.
The same theater plays out in AI governance, often faster. Several major tech companies have dissolved or gutted responsible AI functions to accelerate product development and deployment. Three patterns recur among boards that discover, only after an incident, that their oversight was symbolic rather than substantive:
- Annual cadence, continuous risk: Cyber and AI systems change continuously as new models, new data feeds, and new vendors are added, whereas board review remains quarterly or annual at best.
- Maturity scores without stress tests: Framework scores and AI checklists measure whether controls exist on paper, not whether they’ve been tested under simulated pressure or checked against an actual deployed model.
- Metrics that reassure rather than inform: Patch percentages and training-completion rates rarely answer the question a director actually needs answered: how long would it take us to detect, contain, and recover from a real attack or AI failure?
Diagnosis without follow-through, that is, noting a gap without setting a remediation deadline or naming an owner, is simply a more sophisticated version of the same theater.
Why This Gap Persists
Three structural factors keep this pattern in place even at engaged, well-intentioned boards.
- Information asymmetry that runs almost entirely in one direction and widens further on AI, since directors depend on a single CISO or AI leader briefing with few independent channels to validate what they’re told.
- Technical language discourages the probing questions directors instinctively ask about financial risk, so a vague assurance like “aligned with industry best practices” goes unchallenged in a way an unexplained revenue variance never would.
- Incentives on both sides that favor reassurance over rigor.
Where Cyber and AI Governance Converge — and Where They Differ
It is tempting to assume that mature cyber oversight extends naturally to AI. It does not. Yet many boards fold AI into the same committee and briefing cycle built for cybersecurity, expecting the same questions to surface the same risks. The two domains rest on a shared governance foundation, but they differ in what can go wrong, how settled their standards are, and what counts as evidence of readiness. Table 1 compares them across seven dimensions that matter for board oversight.

The last row of Table 1 captures the essential difference. A board fluent only in cybersecurity governance keeps asking whether it can detect an attacker. For AI systems, the more urgent question is whether an organization knows when its own system is wrong, even when no adversary is involved. A penetration test says nothing about model bias, and a bias audit says nothing about lateral movement on the network. Oversight built for one domain will not automatically catch failures in the other.
What the two domains share matters as much as where they differ. Both require executive ownership that doesn’t run solely through the function being evaluated, that tests rather than merely documents capability, and that has continuous rather than periodic reviews.
Both domains also tend to fail for the same reason. As cyber governance attorney Rois Ni Thuama, head of cyber governance at Red Sift, has argued, the underlying cause of most major breaches is rarely the technology itself. “It is never the widget that’s the problem,” says Ni Thuama. “It is always weak leadership, weak governance, lack of accountability.”²
The same holds true for AI, and the overlap is growing. AI adoption is expanding the very attack surface that AI systems sit inside through prompt injection, training-data poisoning, and compromised model supply chains. Governing AI well is therefore one of the more effective levers a board has for reducing cyber risk directly – not a second, unrelated risk to manage.
Because the two domains share a governance foundation, a board does not need two separate oversight playbooks. It needs one approach that demands the same thing in both: evidence of tested capability rather than assurance of documented compliance.
Applying the CPD Framework to Board Oversight
The Commitment-Preparedness-Discipline (CPD) framework provides that approach, giving boards a single lens for overseeing both domains. Commitment means treating cyber and AI risk with the same rigor applied to financial risk, including independent verification that doesn’t run solely through the executive being evaluated. Preparedness means shifting review from documentation to demonstration; a plan that has never been rehearsed is a hypothesis, not a capability. Discipline means resisting the pull back toward annual cadence once engagement fades, with metrics that measure response capability rather than control existence.
Figure 1 illustrates what happens when those pillars are weak. It scores six oversight practices twice, once as boards perceive their own readiness and once against what independent testing confirms. The pattern is illustrative, but it reflects what board-readiness reviews tend to find: perceived readiness outruns tested readiness on nearly every practice, and tested readiness is lowest on independent verification, vendor visibility, and risk-trend tracking, precisely what separates genuine preparedness from compliance theater in either domain.

Applied specifically to AI, each pillar calls for a specific practice. Commitment means classifying AI use cases by risk level and building explainability into high-risk systems from the outset rather than retrofitting it after deployment. Preparedness means scaling human oversight to each use case’s risk and testing whether that oversight actually works. Discipline means monitoring deployed models continuously for drift, misuse, and attack rather than reviewing them once at approval. Because AI systems now sit inside the organization’s attack surface, these practices strengthen cyber defenses and AI governance at the same time.
Questions Boards Should Be Asking
Directors don’t need to become technologists to close this gap. They need questions that shift the conversation from reassurance to evidence:
- When was our incident response plan last tested under realistic conditions, including a scenario where an AI system is the source of the failure, and what did the test reveal?
- What is our current detection-to-containment time, and how has it changed over the past year?
- Which critical vendors and AI providers have we independently verified, rather than merely asked to attest, on their own posture?
- Have we classified our AI use cases by risk level, with human oversight scaled to match, or are we applying the same governance to a chatbot and a credit-decisioning model?
These questions cannot be answered convincingly with a maturity score or a checklist. They require management to demonstrate tested capability and the board to keep asking until that evidence is current.
From Oversight to Ownership
Genuine readiness is not a heavier compliance burden bolted onto existing governance. It is a shift in what the board treats as sufficient evidence: an independent verification channel, tested outcomes rather than documented plans, and a review cadence that matches how fast risk changes.
The stakes are operational and personal. Operationally, recovery speed varies enormously. In Sophos’s 2025 Annual Threat Report, just over half of ransomware victims said they fully recovered within a week, whereas nearly one in five took more than a month.³ Personally, directors face legal exposure. Under Delaware’s Caremark doctrine, shareholders can pursue claims against boards that fail to oversee mission-critical risks such as cybersecurity. That exposure now extends to AI. Directors of Delaware companies can face potential Caremark claims for inadequate oversight of generative AI deployment, and regulators are signaling growing willingness to hold individual directors accountable.
The organizations most exposed to catastrophic cyber and AI governance failures are rarely the ones with disengaged boards. They are more often the ones engaged with the appearance of readiness rather than its substance. Closing that gap does not require more board time or technical fluency; it requires boards to demand evidence of tested capability in place of assurance of documented compliance.
References
- Kaul, R., 2026, “Compliant but Exposed: Rethinking GRC for Real Security,” The Cybersecurity Readiness Podcast Series, episode 107, https://www.cybersecurityreadinesspodcast.com/.
- Ni Thuama, R., 2021, “What Does Good Cyber Governance Look Like? A Legal Perspective,” The Cybersecurity Readiness Podcast Series, episode 8, https://www.cybersecurityreadinesspodcast.com/.
- Sophos, 2025, “Sophos 2025 Annual Threat Report,” https://www.sophos.com/en-us/content/security-threat-report.
Dave Chatterjee, PhD, is an adjunct associate professor at Duke University whose research and advisory work focus on cyber resilience and AI governance. He created the Commitment-Preparedness-Discipline (CPD) framework, the subject of his forthcoming book, Governing Cybersecurity and AI: The CPD Framework (late 2026). He is also the author of Cybersecurity Readiness: A Holistic and High-Performance Approach and the thriller The DeepFake Conspiracy, and he hosts the Cybersecurity Readiness Podcast Series.