The signal
The Center’s September paper, Is AI Mission Critical?, examines the oversight question use by use. A system assisting a consequential decision about a person raises different questions from one drafting routine internal material. The technology label alone cannot establish the character of the risk, its relationship to the enterprise, or the consequences of failure.
The paper proposes three determinations in sequence: whether the use presents a compliance risk or a business risk; whether a compliance risk is central to the business or peripheral; and whether it is mission critical. These are the Center’s synthesis of the authorities examined in the paper.
The insight
A classification has value when it carries a reason and an oversight response. The paper argues that a finding of “not mission critical” does not by itself settle what reporting or attention a use requires. The board needs to know what was assessed, which obligations counsel identified, and why the institution chose its response.
The distinction between an operating control and board-level reporting also matters. In Marchand v. Barnhill, the Delaware Supreme Court allowed an oversight claim concerning food safety to proceed based on allegations about the absence of a board-level monitoring and reporting system. That case concerned food safety. The Center’s paper develops its own analysis of the implications for AI.
The action item
Ask management and counsel to bring one completed determination worksheet for a consequential AI use to the next oversight meeting. Review the reason and evidence for each determination, the accountable executive, the reporting the board will receive, and the event that would require reconsideration. Record the conclusion and the oversight response together.
A dated record of that judgment gives The AI Oversight Program something specific to oversee and revisit. The program is the governance.