The 9% Problem · What Your Board Actually Wants to See on AI

An empty boardroom conference table seen from directly overhead, shrouded in shadow except for a single sharp cone of spotlight illuminating one empty chair at the head of the table, representing the accountability question every board is now asking about AI oversight.

Somewhere in the next board meeting, or the one after that, someone is going to ask you a version of the same question. Not “what’s your AI strategy.” That question went stale a year ago. The one coming now is sharper: who is accountable for what your AI systems actually do, and how would you prove it. If your company is backed by a private equity sponsor, the person asking is not making conversation. She is the operating partner your fund sent, and she is going to write your answer down.

It is just not an answer to the question that was actually asked, which is not whether AI governance exists on paper but whether it would hold up if someone asked to see it.

Most CEOs give some version of the same answer, and it is the wrong one. They point to a policy document. They mention a committee that meets when something comes up. They say the head of ops “keeps an eye on it.” None of that is a lie, exactly. It is just not an answer to the question that was actually asked, which is not whether AI governance exists on paper but whether it would hold up if someone asked to see it.

 

The question just got sharper

The shift is not subtle if you have been anywhere near a fund this year. LPs have started asking general partners how portfolio companies govern AI, not whether they use it. General partners have started asking operating partners the same thing back down the chain. By the time the question reaches a portfolio company CEO, it has already been asked twice, and the person asking you the third time has a limited patience for a slide with a checkmark on it.

This is not paranoia dressed up as diligence. It tracks a real shift in what boards are being told their job is. A client alert from the law firm WilmerHale earlier this year laid out where board obligation on AI is heading: comprehensive assessment of where AI is actually being used across the organization, a real oversight structure rather than an ad hoc one, risk management aligned to a recognized framework rather than invented on the spot, and clear enough accountability that responsible teams can move fast instead of freezing. The alert’s framing was blunt. AI governance is no longer just good practice. It is becoming a legal and strategic obligation, the kind that shows up in a deposition before it shows up in a press release.

 

The number behind the question

Here is what makes this more than a compliance footnote for a portfolio company specifically. Grant Thornton’s 2026 AI Impact Survey, drawn from 950 business leaders surveyed between late February and mid-March, included a private equity subgroup of 100 respondents, and the private equity numbers were the worst in the entire survey. Just 9 percent of PE respondents said they were confident they could pass an AI governance audit within 90 days, less than half the rate across every other sector surveyed. Only 7 percent had a tested AI incident response plan, meaning a plan somebody had actually run through rather than filed away. Forty-five percent described themselves as still piloting, 11 points above the cross-industry rate, while only 5 percent had fully integrated AI into operations, compared with 14 percent everywhere else.

Put plainly: portfolio companies are moving into AI at a normal pace and governing it at a much slower one, and the gap between those two lines is exactly where an operating partner’s question lands. The same survey noted that organizations with AI fully integrated into operations were four times more likely to report revenue growth from it. Private equity, with nearly half its companies still piloting, is sitting on the wrong side of that line, which means the AI governance conversation and the AI value conversation are the same conversation now, not two separate ones.

None of this is a surprise if you have watched how fast the tooling has moved versus how slowly the accountability structures around it have followed. Most portfolio companies adopted their current AI tools the way they adopted most software: a department found something useful, it spread by word of mouth, and nobody stepped back to ask who owns the risk it now carries. That is a normal way for a capability to enter a company. It is not a normal way for a company to answer for it later.

 

Why the committee answer doesn’t land

A committee is not nothing. It is just not what the question is actually asking for, and the gap between the two is where most CEOs get caught flat.

An oversight structure that only convenes when something goes wrong is not oversight. It is incident response wearing oversight’s clothes. A policy document that was written once, filed, and never revisited against what the company is actually doing with AI eighteen months later is not a governance system. It is an artifact of the month it was written. And a committee that approves everything brought to it, because nobody on it has the standing or the information to say no, is a rubber stamp, not a safeguard. An operating partner who has sat through a few of these conversations can usually tell the difference inside the first two questions.

What she is actually listening for is whether you can map your live AI use cases to a real risk tier, whether the tier with the least oversight is also the one with the least at stake, and whether someone above the working level actually reviews that mapping on a schedule rather than when a headline forces the issue. Most portfolio companies, when asked, discover they have fragments of this. A use case list here, a data policy there, a security review that covered something adjacent last year. What they rarely have is the fragments connected into one system somebody can walk a stranger through in twenty minutes.

 

What a real answer looks like

The fix is not a bigger binder. It is a system built the way Governance is a Freeway, Not a Roadblock describes it: guardrails as the thing that lets a company move faster with confidence, not the thing that slows it down. A freeway with lane markings carries more cars at higher speed than an open field with none, and AI governance done right works the same way. It is not friction added after the fact. It is the structure that makes speed survivable.

That structure starts with a live inventory of where AI actually touches the business, tiered by what happens if it gets something wrong: assistive work a person checks anyway, work that is sensitive enough that someone should see the output before it moves, agentic work where the system takes action on its own, and consequential work where a mistake reaches a customer, a regulator, or a financial statement. It continues with a cadence, not a one-time review, because the tier a use case sits in this quarter is not guaranteed to be the tier it sits in next quarter as the system’s autonomy or scope quietly expands.

An operating partner does not want your confidence. She wants your receipts.

And it ends with something an outside party can actually check, which is the part almost everyone skips. Project Vista exists for exactly this reason: a 90-day method that turns AI investment decisions into something sequenced and governed rather than ad hoc, and its companion, the Vista Score, turns the answer into a number that can be tracked over time instead of a reassurance that has to be taken on faith. That is the same discipline Innovation Vista holds itself to on its own dated and scored predictions; a claim that cannot be checked later is not a claim, it is marketing. An operating partner does not want your confidence. She wants your receipts.

 

If you are buying companies, not just running one

Portfolio companies rarely stay the same shape they started in, and that matters here more than it first appears. An add-on acquisition does not just bring new revenue and a new team. It brings whatever AI governance, or lack of it, the acquired company was carrying, on whatever tools it happened to adopt, reviewed by whoever happened to be paying attention there. Our 2026 AI Dividend Map describes the Rollup shape as the pattern where a market will not consolidate on its own but capital consolidates it by acquisition anyway. That pattern has a governance cost nobody prices into the deal model. Every add-on is a fresh audit-readiness problem stitched onto the last one, and the gap compounds faster than most integration plans account for, because integration plans are usually built around systems and org charts, not around which AI use cases the acquired company never told anyone about.

A governance system built the way described above absorbs an add-on the way a well-built freeway absorbs an on-ramp: the new traffic merges into lanes that already exist, gets tiered the same way everything else is tiered, and shows up in the same score the rest of the portfolio does. A company without that system treats every add-on as a one-off cleanup project, which is exactly the kind of ad hoc pattern that produced a 9 percent readiness number in the first place.

 

The clock predates the diligence call

The mistake is waiting for the question to arrive before building the answer. By the time a diligence team or an LP update forces the issue, you are assembling the governance system and the evidence of it at the same time, under a deadline someone else set, which is the worst possible way to build anything meant to be trusted.

The sequence that works is the same one that works for every other part of the technology stack: stabilize first, so the data and access controls underneath your AI use cases are solid enough to govern honestly; optimize second, so the tiering and cadence actually run rather than existing on a slide; monetize third, once the system is real enough that the AI value story and the AI governance story are the same story instead of a hopeful one and a defensive one. Skip the order and you end up demonstrating maturity you do not have, to the one audience most practiced at telling the difference.

An independent assessment is the fastest way to find out which stage you are actually in before someone else asks. Most CEOs are surprised by the answer, and it is much better to be surprised in a conversation you called than one you did not see coming.

Nine percent of your peers could answer it today.

The next version of the question will not be gentler. Nine percent of your peers could answer it today. The other ninety-one percent are the ones an operating partner is about to spend her afternoon with, and you would rather not be one of them.

More from our blog

The 9% Problem · What Your Board Actually Wants to See on AI

The 9% Problem · What Your Board Actually Wants to See on AI

Somewhere in the next board meeting, or the one after that, someone is going to ask you a version of…
Cheap Tools, Scarce Judgment · Why Outside Expertise Has Never Been More Valuable

Cheap Tools, Scarce Judgment · Why Outside Expertise Has Never Been More Valuable

AI tools get cheaper every quarter. The experience to use them well does not. Why outside expertise is worth the…
If Your Tech Budget Looks Like Last Year's, You Missed the Turn

If Your Tech Budget Looks Like Last Year's, You Missed the Turn

Every fall the same document shows up. Last year’s technology budget, rolled forward, with a percentage on top. For most…