Governing AI in the agentic era: AICD resource update

Monday, 10 August 2026

Elise Shaw photo
Elise Shaw
Content Specialist
    Current

    The Director’s Guide to AI Governance is one of the AICD’s most downloaded governance resources. But two years is a long time in AI. 


    The technology has moved from chatbots to autonomous agents, boards have become more AI-literate, and new risks around cybersecurity and data governance have moved to the top of the agenda. 

    More than 2000 directors joined the webinar to launch the Second Edition of this resource, updated in partnership with the Human Technology Institute (HTI) at the University of Technology Sydney (UTS). 

    The interconnection between AI systems and other business tools is now driving transformational change, said Simon Burns, partner at Gilbert + Tobin. Where AI once meant a smart assistant answering questions, it can now be instructed to act inside an organisation's systems, and the risks scale accordingly. 

    AI tools in action 

    Several panellists pointed to a widening gap between how boards think about AI and how it is actually being deployed. 

    Professor Nicholas Davis GAICD, co-director of HTI, said individual, consumer-style use of AI is now a misleading guide to enterprise AI in the agentic era. Boards, he said, need to rethink literacy, moving from knowing how to prompt a chatbot to genuinely understand autonomy, delegation and decision rights. That gap shows up starkly in HTI’s research: 90 per cent of organisations report they are experimenting with AI, but only 20 per cent say they have anything resembling a strategy, and most of those are really procurement plans rather than strategic frameworks tied to core business objectives. 

    “There’s around 15 per cent of Australian organisations that, from our survey, are really at the frontier of both adoption and good governance,” said Davis. “They pay attention to the human impact.” 

    This means thinking less about AI as an individual tool for a single person or set of individuals. It means digging into the impact on teams, on workflow and on the underlying infrastructure of the organisation that makes it work together and enables people to deliver the value, explained Davis. 

    “As a board, make sure you’re setting the standard in terms of really thinking about and listening to employees and how they experience it, because if this is to be as transformative as the capabilities promise, it is going to have an impact on employees,” said Davis. 

    Non-executive director Louise McElvogue FAICD pointed to a related dynamic inside boardrooms themselves, citing Boston Consulting Group research – 75 per cent of board members believe they know as much or more about AI as their fellow directors, yet 40 per cent of CEOs say their boards don’t pragmatically understand how AI will drive growth. 

    “We’ve all seen that tension play out in boardrooms,” said McElvogue. “That alignment of when you should be pushing for opportunities and when you need to manage the risk is something you need to really work closely with management around governing.” 

    Navigating rising costs and economic uncertainty

    Organisations are struggling to forecast and manage costs that scale with usage. “Boards are trying to figure out how they’re going to project the costs and how they’re going to manage them going forward,” said McElvogue. “It’s incredibly tricky to get ROI [return on investment] around every single place you use AI. So understanding when to pull back and when not to is a tricky decision.” Davis offered a useful reframe for boards assessing return on investment. In a typical AI transformation, only around 20 per cent of the cost is the technology itself, with the remaining 80 per cent going to people, training and supporting infrastructure. 

    “Being able, at board level, to understand that from a strategic perspective – the true costs as well as the risks – is essential,” said Davis. 

    Burns suggested being selective with a broader strategy in mind. “Think about what is actually going to be transformative for the business. It’s an investment in change

    management, and it’s a long six-month or one-year program to actually develop the opportunities out of it. Be targeted and look at a handful of bigger use cases, not a scattergun of little use cases that may or may not deliver anything.” 

    The AI governance challenge 

    Agentic AI – systems that can act autonomously rather than simply respond – were described by the panelists as “like employing a brilliant sociopath in the business”, or “like a capable nine-year-old, highly able, but not always controllable”. Burns said good governance might pair upfront instructions with hard technical controls limiting what agents can actually access or change. “Assume that those controls will fail and start thinking about how to detect and remediate the fallout rather than just prevent it.” 

    Cyber risk was flagged as urgent and shifting. As the cost of mounting an attack falls, panellists warned the greatest exposure might shift toward mid-sized organisations – large enough to be worthwhile targets, but without the resources of top-tier organisations to patch quickly. 

    ASIC and APRA have been sending increasingly strident directives to organisations in regulated sectors around the threat posed by frontier AI models, or indeed non frontier AI models, said Louise Petschler GAICD, General Manager, Education & Policy Leadership at the AICD. 

    “What used to be the province of perhaps bad actors at a nation-state level, or well organised criminal cartels leveraging deep digital expertise, is now much more accessible and at a much faster pace,” she said. 

    The AICD is partnering with the Australian Signals Directorate on a forthcoming set of board-level cyber questions to assist directors in this area, which should be released in August 2026. 

    People, not just technology 

    The panel returned repeatedly to workforce impact. Small errors or biases in automated systems can be far more correlated – and therefore more consequential at scale – than the more randomly distributed errors humans make, a point with particular relevance for not-for-profits serving vulnerable communities. A live poll of attendees found more than half reported increased productivity, while around 30 per cent reported increased errors from over-reliance on AI; role redesign was also common, although reported burnout remained comparatively low. Panellists cautioned that workforce effects often take years to surface and urged boards to have direct, transparent conversations with staff now. 

    The framework at the guide’s core 

    To help boards cut through the volume of AI-related issues, the updated guide

    organises governance into four areas: strategy, structures, policies and practices, and enablers, covering everything from investment decisions and risk appetite through to accountability structures, vendor oversight and building genuine AI literacy at board level. 

    The Director’s Guide to AI Governance (Second Edition) is freely available on the AICD website, alongside related resources on AI use by directors, board minutes in the AI era, and an online AI Fluency Sprint for Directors

    Latest news

    This is of of your complimentary pieces of content

    This is exclusive content.

    You have reached your limit for guest contents. The content you are trying to access is exclusive for AICD members. Please become a member for unlimited access.