The paper examines the oversight question use by use. It distinguishes an AI-related business risk from a compliance risk, asks whether that compliance risk is central to the enterprise, and then examines whether it is mission critical.
Its central argument is that a board should record those determinations in sequence. A finding that a use is not mission critical does not, on the paper's analysis, settle whether the board needs a reporting system for the risk.
Three determinations
Compliance risk or business risk?
Identify the character of the risk arising from the particular use, including the legal or regulatory requirement at issue.
Central to the business or peripheral?
Examine the relationship between that compliance risk and the enterprise's product, service, or purpose.
Mission critical?
Consider the centrality of the regulated activity and the consequences of a failure for the people the enterprise serves.
The research contribution
The paper develops five questions from its comparison of oversight cases, then applies them to AI uses. It distinguishes the legal floor described in those cases from the more developed program the Center recommends. The five questions and three determinations are the Center's synthesis of the authorities discussed in the paper.
The reference materials include a chronological case comparison, a determination worksheet, and a model board resolution. These allow the reader to move from the argument to the decisions and records it proposes.
Companion materials
The following downloads reproduce the relevant pages of the full paper. The worksheet is Appendix A, pages 30 and 31. The model resolution is Appendix B, pages 32 and 33.
The underlying authorities
The Authorities Register brings together the oversight cases, statutes, regulations, and standards discussed in the Center's work. Search the register or browse its chronological case list.
Relationship to earlier work
This paper refines the Center's Caremark AI Liability Roadmap through a use-by-use analysis. It should be read alongside that earlier work and The AI Oversight Governance Layer.