AI as a board-level imperative: the trajectory accelerates
Each year, Freshfields publishes its Data Law Trends report – a forward-looking guide to the forces reshaping how businesses manage data, AI and digital risk globally. We published the 2026 edition in October 2025 and today we’re providing an update on one of its most widely resonant chapters: AI as a board-level imperative.
Our last report explained how, entering 2026, boards needed to not only manage AI but also be ready to articulate their approach clearly and convincingly to the market. It also outlined how listed companies could take clear and defensible steps to meet rising expectations from investors and regulators. This blog provides a follow-up to our earlier report, and explains why, six months into 2026, the trajectory we identified hasn't just continued – it's accelerated.
The direction of travel is clear: the way a business governs AI is becoming key to managing risks and part of how investors, regulators and the market assess the quality of its wider corporate governance.
The rise of agentic AI
In the first six months of 2026, AI has been shifting from a tool that responds to prompts to an autonomous partner that plans, acts and learns – reshaping workflows, transactions and risk profiles across every sector.
The new wave of “agentic” AI raises the stakes and means businesses must develop governance processes, assign internal accountability and ensure traceability for all agentic AI deployments.
Policymakers continue to raise the bar
US states have continued to enact and roll out a growing patchwork of state AI laws that range from governing frontier models to regulating specific AI use cases in the consumer space and other contexts. These laws impose various requirements regarding public disclosures, regulatory reporting, user safeguards, and other measures that directly impact internal AI governance. And enforcement agencies, particularly the Securities and Exchange Commission (SEC) and the Federal Trade Commission (FTC), remain focused on AI-washing and the accuracy of AI-related disclosures and representations.
The EU has agreed some reforms aimed at reducing the burdens of its AI Act – and delaying some duties coming into force, such as compliance with rules for so-called high-risk AI systems, e.g. in the HR context. This is welcome to business, but the core architecture of the AI Act is not radically changing. High-risk classification, conformity assessments, transparency obligations – these remain.
So boards across the world are under growing pressure to demonstrate structured AI oversight. The EU AI Act, for example, doesn't prescribe a particular governance model, but the expectation – from regulators, investors and the market – is that management and supervisory boards have the competence to scrutinize AI strategy and the frameworks to hold their organizations to account. That expectation is only intensifying.
Businesses are responding, with more to do
Yet many businesses remain unprepared. In recent months ISS STOXX published further research that really puts numbers on this. Out of over 3,000 US companies reviewed, only 8% disclosed board-level AI oversight, and only 9% even acknowledged having AI policies. That's a remarkably low baseline given the scale of AI adoption across corporate America.
Nevertheless, Freshfields’ tracking suggests listed companies are continuing to build momentum in developing new governance processes to help address these challenges. For example, our tracking of the UK FTSE 100 shows a clear trend of more listed companies naming AI as a principal risk, and a steady uptick in dedicated AI committees and teams and directors with AI expertise.
AI governance becomes a key theme for investors and proxies
What ties all of this together – and what we foreshadowed in the original report – is that proxy advisors and institutional investors are now making AI governance a defining theme of this proxy season. Glass Lewis said it plainly in March this year: AI governance and related disclosures will likely be top of mind for issuers and investors, and companies are navigating the challenge of balancing innovation with responsible integration as best practices continue to emerge.
That language matters. It tells boards of listed companies that this isn't a future problem – it's a current expectation. And it's a global one. Whether you're navigating the AI Act in Europe, state-level laws in the US, or investor and regulatory expectations in the UK, the core message is the same.
How boards should respond
Boards need to be able to articulate – clearly and credibly – how they govern AI, what risks they've identified and what they're doing about them. The companies that get ahead of this will build trust with investors and regulators. Those that don't will find themselves playing catch-up in an increasingly unforgiving environment.
So the pace has quickened, but the playbook we set out in our report still holds. If you're advising a board on AI governance, it gives you the strategic grounding – and our team is here to help you put it into practice.
The pace of AI development shows little sign of slowing. Agentic AI, evolving regulatory frameworks and growing investor expectations are all increasing the importance of effective governance. AI will continue to evolve over the coming months and is likely to shape many of the conversations leading into the next edition of our Data Law Trends report later this year.
