AI safety is a board decision -- and they need to start making it

AI poses serious risks to people and the systems they depend on. The executives who build and buy AI hold the controls. Boards and CEOs must use them and accept the cost.

AI poses threats to humanity and to the systems we rely on for power, water, security and trusted information.

And as shown by the rogue agents from OpenAI which attacked infrastructure at Hugging Face, current AI agents can and will continue to make mistakes and act against the interests of those who use them. The companies building and deploying the technology are in the best position to reduce those threats. But their boards and CEOs must lead that work -- even when it costs them growth.

This month, the people who build frontier AI said much the same thing. On Sept. 12, Anthropic CEO Dario Amodei published an essay calling on labs to deliberately slow the pace of capability gains, and OpenAI's Sam Altman and xAI's Elon Musk publicly agreed within a day.

A week later, I put the question to Anthropic's own model. I asked Claude whether AI advancement could be paused now that the underlying models already exist. The answer was candid. A single lab can stop. The broader field is a coordination problem across companies and countries, and model weights already released cannot be recalled. Then it named the soft spot. In agentic products, the approval gates that keep a human in the loop are user settings, and users widen them for convenience.

That answer puts the problem in one line. The safeguards are in the hands of the users, and the desire to move fast works directly against keeping AI safe. The users that matter most are companies. Their CEOs decide what to deploy. Their boards decide what risk is acceptable.

Too many leaders have already conceded

Over the past six months, I asked public CEOs if they thought it was still possible to put effective AI safeguards in place. More than 80% said what they had was good enough or not possible to do without extraordinary lift.

I disagree. These are governance decisions which sit with the board and are highly actionable right now.

Boards and CEOs ultimately decide where AI runs, who has authority over AI, what testing AI must pass and who can shut it off. The trouble is that most boards lack the people to make the decision. Outside the technology sector, no large public company has more than one director with hands-on AI experience, according to Christian & Timbers research. Amazon, Walmart, CVS, Home Depot, Sysco, HSBC and MSCI each have one. A board with one expert must take management's word on everything else.

The talent market shows the same gap. Our FDE Scarcity study found about 2,000 engineers in the U.S. with a proven record of turning enterprise AI into measurable returns, at a time when fewer than one in five companies reports meaningful ROI from AI. The study also found the share of hiring executives planning to hire forward-deployed engineers jumped from 5% to 10% early in 2026 to about 70% by the end of the second quarter. Companies are racing to deploy with a thin bench of people who know how to do it well.

Security hiring tells the story most clearly. According to the same study, from January 2025 to July 2025, nine of the 22 CISO and chief security officer searches that came to our firm named deep agentic AI expertise as the most critical qualification. In the same months of 2026, all 32 did. Companies know the risk has arrived. They are hiring for it after it showed up. That is reactive governance, and it leaves boards one step behind their own technology.

Boards and CEOs must stand up for safety

Human safety and the public interest belong on the board agenda next to revenue and EBITDA. That means reporting on AI risk with the same discipline boards apply to earnings, and saying so publicly. Sometimes it means challenging your own industry or your own business plan.

Critical infrastructure shows what the standard looks like. The National Institute of Standards and Technology is developing an AI risk management profile for critical infrastructure, and its concept note calls for thorough testing and systems designed to fail safely. Boards can require that standard today for any deployment that touches physical systems or human safety.

Boards need to take these six action items today:

  1. Assign an AI oversight mandate to a specific committee -- likely audit or risk -- with a written charter. Unclear shared responsibility leads to failure.
  2. Require an inventory of where the company uses AI, for what decisions and on whose data. Most large companies cannot answer that question today.
  3. Classify deployments by consequence. A customer support chatbot and a credit-scoring model are different governance problems.
  4. Name an accountable person for every consequential decision in hiring, credit, medical care and safety.
  5. Treat agentic systems as their own category, with spend limits, scoped credentials and kill switches tested before an incident.
  6. Seat at least one director who can interrogate technical claims, or retain a standing independent adviser.

Safety carries a financial cost. Testing delays launches. Tighter approval gates slow agents down. Limits on a system's authority leave some efficiency on the table. There is and always will be tension between velocity of product development and safety. Boards and CEOs should clearly demonstrate to shareholders why they are making the decisions that they are as it relates to AI and safety.

What if a competitor keeps going?

This is the objection I hear most. A board slows down. A competitor ships, wins the customer and funds its next release with the revenue. The argument is even sharper at the national level. U.S. President Donald Trump reacted to the demands for an AI Frontier Lab slowdown by stating the U.S. cannot afford to fall behind China. Then the industry faced conflict from its clients. On Sept. 18, four consumers filed an antitrust suit accusing Anthropic, OpenAI, Google and SpaceXAI of agreeing to slow development.

I have three responses to boards who put no restraint on their AI due to concerns of speed.

First, most companies reading this buy AI from a handful of model builders. A competitor's release tells a board nothing about a test of absolute safety of the underlying model for a particular use case.

Second, the company that deploys a system owns its failures. When AI fails inside a hospital, a utility or a bank, the regulators, lawsuits and lost customers land on that company, regardless of who shipped first.

Third, speed compounds risk. When I asked Claude what society should worry about most, it pointed to the erosion of correctability. That is the point at which AI is embedded so deeply in infrastructure, employment and decision-making that undoing a bad deployment costs more than living with it. It added that the people who benefit from moving fast are the same people judging whether it is safe. Boards exist to break that loop. Boards that set limits early keep the ability to correct course.

Act on the evidence we have

While many are worried about future extinction-events relating to AI, the risks we create today are clear and present. The most informed experts estimate vastly different projections. Evan Hubinger, who leads alignment science at Anthropic, recently put his personal estimate of that risk at above 10% over the next 10 years. The International AI Safety Report 2026 describes loss-of-control scenarios and states that their likelihood and timing remain highly uncertain.

Boards manage uncertain risks every day. Cyberattacks, pandemics and supply shocks all get controls sized to their consequences. AI deserves the same treatment. The nearer-term signal I watch is employment. Unemployment is the last lever to move, and by the time it moves, the damage is done.

My ask of every CEO and director reading this is simple. Put AI risk on the next board agenda as a standing item, with the same weight as revenue and EBITDA. Name the committee that owns it. Name the director who can question the technology. Decide now who has the authority to stop a deployment, and what the company will pay to use it.

The builders of AI have asked for oversight. Their boards must now step up to supply it.

Jeff Christian is founder and CEO of Christian & Timbers, where he leads CEO, board and technology executive searches. He led the searches for Steve Jobs's last two board appointments at Apple and the search that placed Carly Fiorina as CEO of Hewlett-Packard. He is the author of The Headhunter's Edge.

Next Steps

OpenAI-Hugging Face incident raises AI liability concerns

Dig Deeper on CIO Strategy