Boards have stopped asking whether the company has an AI strategy and started asking how management knows it is working. NACD's advice to directors for 2026 is explicit: ask "what key performance indicators should we request from management to assess the efficacy of our AI initiatives?" The trouble is that most security and governance teams have never been asked for AI metrics before, and the first attempt tends to produce either a vanity dashboard (tools approved, policies published) or a technical one the audit committee cannot read.
This is a pack of twelve metrics that survive both tests. Each has a definition a director can repeat, a 2026 benchmark from a named source, and the framework clause it evidences — because the same number that answers the board's question is usually the one a regulator or auditor will ask for next.
Why the board is asking now
- Agenda time without governance. NACD's 2025 survey found 62% of public-company directors allocating full-board agenda time to AI. Deloitte's second global boardroom study found 66% of boards still describe their AI knowledge as limited or none, and 31% say AI is not on the agenda at all. Protiviti's Q4 2025 survey of 772 directors and executives found only 26% of boards discuss AI at every meeting — but 63% of the organisations reporting high AI returns do, against 13% of the low performers.
- Directors use it themselves, unsupervised. Corporate Board Member and Diligent found in June 2026 that 82% of US public-company directors had used generative AI for board work in the past six months; 6% of boards have a policy for that.
- Disclosure is catching up with oversight. EY's review of Fortune 100 filings found 48% now disclose AI in board risk oversight (16% a year earlier), 40% name a committee responsible, and 16% disclose that management reports to the board on AI. ISS-Corporate found 22% of the S&P 500 disclosing board AI oversight in May 2026 — and 58% of investors saying companies with significant AI use should apply a recognised risk framework now.
- Accountability has teeth. Glass Lewis's 2026 US guidelines state that where inadequate AI oversight results in material harm to shareholders, it will identify the directors charged with AI risk oversight and may recommend against them. NYDFS's October 2024 letter requires a regulated entity's senior governing body to "regularly receive and review management reports about cybersecurity matters (including reports related to AI)." Under the EU AI Act, deployers of high-risk systems must assign human oversight to people with "the necessary competence, training and authority" and report serious incidents within fifteen days — two for widespread infringement.
Add the benchmark every board has now seen: IBM's 2026 Cost of a Data Breach report found shadow AI involved in 43% of incidents, up from 20%, at an average $5.39M against a $4.99M global average — and 92% of organisations with AI-related breaches lacked proper AI access controls. Directors who have read that want to know the company's number.
The twelve metrics
| # | Metric | Definition | 2026 benchmark | Framework hook |
|---|---|---|---|---|
| 1 | AI inventory coverage | AI apps, agents and MCP servers discovered ÷ those registered and owned. Target: discovered = registered. | Average organisation adopts ~10 AI apps a month, many unapproved (Check Point, Jul 2026); cautious enterprises use under 15 GenAI tools, the top 1% over 300 (Cyberhaven, Feb 2026). | NIST AI RMF MEASURE 2.4; CIS AI Security Guidance Workbook (Jul 2026) "asset visibility and governance" |
| 2 | Sanctioned-usage ratio | Share of AI sessions on enterprise accounts behind SSO. Target: rising quarter on quarter. | 47% of GenAI users still on personal accounts (Netskope, Jan 2026); 67% of AI users on corporate devices use non-corporate accounts (Verizon DBIR 2026). | NYDFS AI letter (access controls); ISO 42001 A.9 |
| 3 | Sensitive-data prompt rate | Prompts containing a classified data type ÷ total prompts. State the definition — vendors measure differently. | 4% of prompts high-risk, one in 25 (Check Point, Jul 2026); 2.6% of 22.4M prompts sensitive (Harmonic, Jan 2026). | NIST MEASURE 2.10 (privacy); EU AI Act Art. 26 |
| 4 | Policy violations per 1,000 users per month | Inline policy events (redact, warn, block) normalised to headcount. | Average organisation: 223 GenAI data-policy violations a month, doubled year on year; top quartile 2,100 (Netskope, Jan 2026). | ISO 42001 clause 9.1 monitoring and measurement |
| 5 | AI access-control coverage | AI systems behind SSO, least privilege and inspection ÷ all AI systems in the inventory. | 92% of AI-breached organisations lacked proper AI access controls; only four in ten limit access to their AI systems (IBM, Jul 2026). | NYDFS Part 500; NIST GOVERN 1 |
| 6 | Agent identity coverage | Agents with a unique identity and a named owner ÷ agents discovered. | 10% of organisations have a strategy for governing non-human identities (Okta, Apr 2026); 33% of IT and security staff do not know how many agents exist (1Password, Jul 2026). | OWASP ASI03; CSA Agentic AI IAM (Aug 2025) |
| 7 | Over-privilege ratio | Data and tools an agent can reach ÷ what its approval covered. | Agents access roughly twice what was approved; 41% of organisations have agents reaching unapproved data (1Password, Jul 2026). | OWASP ASI02; NSA MCP guidance "grant only the minimum access necessary" |
| 8 | Secrets hygiene in AI tooling | Secrets found in coding-assistant context and MCP configurations per 1,000 repositories; leak rate of AI-assisted commits vs baseline. | AI-assisted commits leak secrets at 3.2% against a 1.5% baseline; 24,008 unique secrets found in public MCP configuration files (GitGuardian, Mar 2026 — single source). | CIS Controls 3, 16; OWASP ASI04 |
| 9 | Human-approval coverage | Consequential agent actions (delete, send, pay, push, credential use) that pass through an approval gate ÷ all such actions. | No industry benchmark yet; the NSA's guidance is to treat all automated actions as high-risk and require human approval. | EU AI Act Art. 26(2); OWASP ASI09; NSA MCP CSI (May 2026) |
| 10 | AI incidents and time to detect | Count of AI-related incidents and near misses; mean time from first event to detection. | 88.4% of organisations had at least one agent-related incident in the past year (AvePoint, Jun 2026); the AI Incident Database logged 362 incidents in 2025, from 233 (Stanford AI Index 2026). | EU AI Act Art. 73 (15/10/2-day clocks); NIST MANAGE 4 |
| 11 | Policy-to-enforcement gap | AI policy statements with a technical control behind them ÷ all policy statements. | 68% of breached organisations lacked AI governance — 35% no policy, 33% still drafting (IBM, Jul 2026); 37% of employees follow AI policy only "most of the time" (1Password, Oct 2025). | ISO 42001 A.2; NIST GOVERN 1.2 |
| 12 | Board reporting cadence | Frequency and completeness of AI risk reporting to the board or its committee; whether it is disclosed. | 26% of boards discuss AI every meeting (Protiviti, Mar 2026); 16% of the Fortune 100 disclose management AI reporting to the board (EY, Oct 2025). | NYDFS letter; Glass Lewis 2026; SEC Item 106 for cyber oversight |
How to present it
One page, four rows of three. Metrics 1–3 answer "what AI do we have and how is it used"; 4–6 answer "is it controlled"; 7–9 answer "what can the agents do"; 10–12 answer "how do we know and who is accountable." Each tile carries the number, the direction since last quarter, the benchmark, and one sentence on what changed. Resist adding a thirteenth. The point of a KPI pack is that the same twelve numbers appear every quarter so the board learns to read them.
Three editorial rules make the pack credible. Report definitions with numbers — the sensitive-prompt rate is 2.6% or 4% or 39.7% depending on whether you count prompts, high-risk prompts or data movements, and a director who catches the inconsistency will doubt the rest. Use a named external benchmark for every metric, and say when it is single-source. And show the denominator moving: an inventory that doubles in a quarter is not bad news, it is the first metric working.
Where the numbers come from
Eight of the twelve can be produced only from instrumentation that sees AI usage itself — the inventory, the sanctioned ratio, the prompt rate, the violations, the agent identities, the over-privilege ratio, the approval coverage and the incident clock. Policy documents and surveys cannot produce them. AccuroAI's discovery, attribution and inline inspection generate those eight continuously, with evidence mapped to eight frameworks, and the executive reporting view is built around exactly this cadence: the same metrics, every quarter, with the benchmark beside them. The other four come from the programme itself — access-control coverage from your IdP, secrets hygiene from your code scanning, the policy gap from a control-mapping exercise, and the reporting cadence from the board calendar.
FAQ
Which of these should go to the full board versus the audit committee?
Deloitte's data shows oversight split between full board (46%), risk committee (25%) and audit committee (22%). A common pattern: the full board sees metrics 1, 2, 10 and 12 quarterly; the responsible committee sees all twelve.
What is a realistic target for the sanctioned-usage ratio?
The market moved from 22% to 53% on enterprise accounts in a year (Netskope: personal-account use fell from 78% to 47%). Organisations that deploy inline redaction rather than blocking typically move faster, because employees stop needing the personal account.
Do we need all twelve before the first board report?
No. Report the ones you can measure, mark the rest "not yet instrumented" with a date, and explain why. A board that sees an honest gap list trusts the numbers that are there.
How does this relate to EU AI Act and ISO 42001 evidence?
Directly. ISO 42001 clause 9 requires monitored, measured evidence reviewed by top management; the EU AI Act's deployer duties assume logs, oversight and incident clocks exist. The twelve metrics are that evidence in board form.
Sources: NACD, 2025 Public Company Board Practices and Oversight Survey (28 Jul 2025) · NACD Directorship, technologies for 2026 (10 Dec 2025) · Deloitte Global Boardroom Program, Governance of AI, 2nd edition (2025) · Protiviti global board survey (18 Mar 2026) · Corporate Board Member / Diligent Institute (17 Jun 2026) · EY Center for Board Matters, cyber and AI oversight disclosures (14 Oct 2025) · ISS-Corporate, AI and Governance (20 May 2026) · Cooley on Glass Lewis 2026 US guidelines (11 Dec 2025) · NYDFS industry letter on AI cyber risks (16 Oct 2024) · EU AI Act Art. 26 · EU AI Act Art. 73 · NIST AI RMF Playbook, MEASURE · CIS AI Security Guidance Workbook (27 Jul 2026) · IBM Cost of a Data Breach 2026, via Cybersecurity Dive (29 Jul 2026) · Netskope Cloud and Threat Report 2026, via Infosecurity Magazine (7 Jan 2026) · Check Point Research, AI Security Report 2026 (14 Jul 2026) · Harmonic Security (15 Jan 2026) · Cyberhaven 2026 AI Adoption and Risk Report (5 Feb 2026) · Okta, Businesses at Work 2026 · 1Password agent survey (28 Jul 2026) · 1Password, the enterprise AI crisis (30 Oct 2025) · AvePoint State of AI 2026 (29 Jun 2026) · Stanford HAI AI Index 2026 · GitGuardian State of Secrets Sprawl 2026 (17 Mar 2026) · Verizon DBIR 2026, via National Law Review (28 May 2026).
Related: 7 Questions Your Board Will Ask About AI Risk in 2026 · Why AI Governance Just Became a Board-Level Job · Executive Reporting · ISO 42001 compliance.