Executive Leadership

An AI Risk Appetite Statement a Board Can Actually Measure

Most boards approve a risk appetite statement once a year. A few have added a paragraph about AI. Almost all of those paragraphs are written so that nobody could ever be found in breach of them.

October 9, 20266 min read

A risk appetite statement is one of the oldest tools a board has. It says, in writing, how much of a given kind of risk the company will accept in pursuit of its plan. Banks have had them for decades because regulators insisted. Most technology companies keep a lighter version, usually a page inside the enterprise risk framework that the audit committee reviews each spring and nobody opens again until the next spring.

AI belongs in that document. I hold this view from both sides of the table. As CEO of Visiting Media I would be the one drafting the AI section, and as a director at ACT | The App Association I am the kind of person who votes on it. I also run a fleet of specialized agents across my own operating work, so I know what it feels like to be held to a line I wrote myself, and how fast I start negotiating with it.

What the current guidance says

The pages that rank for this topic agree with each other more than they disagree. The Institute of Directors in New Zealand suggests starting with a stocktake of where AI already runs, then rewriting the statement around the company’s ethics (privacy and data sovereignty get the most room, with accuracy, attribution and even climate impact further down), then revisiting it with management on a schedule. A longer guide from a board-portal vendor puts the approved statement at the top of every AI risk report, next to a line on whether current use stays inside it. A compliance-focused piece walks through decision significance, acceptable error and human review, dependence on third-party models, and when an incident gets escalated.

All sound. I would sign most of it.

What none of them spend much time on is the part that decides whether the statement is worth the paper, which is how a board actually finds out that a line has been crossed.

Most AI appetite statements cannot be breached

I have read some version of this sentence in more than one draft: “The company has a low appetite for AI-related reputational risk and a moderate appetite for AI-enabled innovation.”

Try to picture the board meeting where management reports a breach of that sentence. You can’t. There is no number in it, and nothing in any system would show the line moving. A statement like that stays in compliance forever, and a statement that stays in compliance forever governs nothing.

Human risk appetite has the same weakness, but people move slowly enough that a quarterly review catches most drift. Agents are faster. An agent can make the same small mistake nine hundred times before lunch (I wrote that line about delegation of authority for agents, and I keep repeating it because it keeps being true). A tolerance written in adjectives gets blown through weeks before anyone convenes to debate whether “moderate” was exceeded.

Give every line a meter

My rule for the AI section is short. Every line names a number, and the system where that number already lives. If the number does not exist yet, the line is a project, and projects go on a different list.

That turns the AI section into something closer to a small table than a paragraph. When I draft it for my own operation and translate it into board language, it looks roughly like this:

  • Customer-facing claims published without a signature: zero. Every public claim gets signed by a human or a dedicated checker agent against a source-of-truth document, and the publish log records who signed. I adopted this after an agent of mine published a fabricated claim at 2:14 one morning. The rule has since caught two fabrications before they shipped.
  • Agents allowed to commit the company with no human approval: a small count the CEO can recite, read straight off the delegation matrix, with any increase signed by the CEO personally.
  • Agents running on personal credentials: zero, checked each quarter against expense reports.
  • Aggregate weekly spend per agent, capped in the system itself so the ceiling is enforced before the money moves rather than reported after.

The first line carries most of the weight, and it is the only one I would refuse to bend for a quarter. The last one is boring plumbing. Both belong in the same table because a director should be able to read the whole thing in under a minute.

Notice what is missing. There is no line about appetite for innovation. I would leave the upside to the strategy, where it can be argued with real numbers, and keep the appetite statement for limits, because mixing the two is how you end up with the sentence I quoted above.

Set tolerance by reversibility

Classic risk appetite tends to sort by money. For agents, whether a mistake can be undone matters more than its size, which is why my delegation matrix uses four tiers ranked by reversibility. The appetite statement is where the board decides how crowded the top tier may get, and which classes of action are never allowed into it at all.

The exclusion list I argued for in what boards should ask about AI (termination decisions, regulated disclosures, material customer commitments, data the company has contractually promised to handle a particular way) is really a set of zero-tolerance lines in the appetite statement. Writing it there gives it the weight of a board vote instead of a policy someone in IT maintains.

Who reads the meter

If the only person who can tell the board a line was crossed is the person who crossed it, the line is decoration.

Expect to breach it

A statement that never gets breached is either set too loose or not being checked. My own delegation matrix was wrong within six weeks of writing it, when an agent picked up a vendor integration nobody thought to log. Your AI appetite statement will be wrong too, probably sooner than you would like.

The healthy pattern looks like this: management reports the breach, explains it, and then either fixes the operation or asks the board to move the line. Either outcome is fine. The unhealthy pattern is a line that drifts because someone quietly reworded it between annual reviews, and the only defense is version history the board can see.

Put appetite breaches on the AI page in the board pack as a fixed row. Keep it there even after it reads zero for a year. A long run of zeros is itself worth a question from a director, usually the question of whether anyone is still looking.

Getting it onto the agenda

Don’t form a new committee for this. The AI lines belong in the existing risk appetite statement, reviewed by whichever committee already owns that document and approved by the full board in the same vote.

The CEO should write the first draft with the people who actually own the agents. Legal can tighten the language afterward, and should, but a statement drafted from the legal side alone tends to describe the risks the company can be sued over and skip the ones that quietly damage the business on a Thursday night. The first attempt to attach a meter to every line will fail in places. Keep the list of lines you could not measure. It is the most useful thing the exercise produces, because it tells you exactly where you are flying blind, and it overlaps heavily with the places shadow agents tend to hide.

One test before the vote. Hand the AI section to a technology board advisor with no other context and ask them to describe a single event next quarter that would count as a breach. If they can do it in a sentence, the statement is ready. If they start with “well, it depends,” send it back.

This article is part of the Executive Leadership cluster, focused on board governance and the operating discipline required to run AI systems responsibly at the executive level.

Related Reading