In Q2, I sat in a board committee where the general counsel put one slide on the screen: three proposed fines, two shareholder derivative actions, and one executive named personally. Not for fraud. For signing off on an AI model the company could not explain. That slide reset the room.

The shift: liability is moving from the company to the person

The EU AI Act’s high-risk provisions are now live, and several US states have followed with their own rules. But the regulatory text is not the real story. The mechanism is: regulators and plaintiffs’ lawyers are increasingly asking not “does the company have an AI policy?” but “which executive certified this system was safe?” A policy is a corporate artifact. A signature is personal exposure.

Where this is heading

Within 18 months, I expect AI oversight to look like SOX did for financial controls: individual certifications, documented testing, and personal sign-off. That kills the “we have a governance framework” defense. A framework is a document. A certification is a decision. The leaders who thrive will treat AI sign-off the way CFOs learned to treat 404 certifications — as a personal risk decision, not a compliance checkbox.

What separates leaders who adapt

Documented decision provenance. Not another dashboard. When the model changes — and it will — the executive who survives is the one who can show the board what she knew, when she knew it, and what she escalated. That is a leadership discipline, not a data science skill. In 25 years running enterprise technology, I have never seen a single dashboard save anyone in a deposition.

Start now. Pick the one AI system in production with the highest downside. Ask the owner for a two-page sign-off memo: assumptions, failure modes, rollback triggers. If they cannot produce it, that is your liability. Read it. Sign it. Or kill the system.