Celebrate 9 Years with EIMF
EIMF Has Assisted 6,000+ Professionals Get Certified
Ready for your next professional certification? Choose from 9 self-paced eLearning courses and enjoy a 30% discount!
*complete your purchase before 21 April 2024
AI Has Reached the Boardroom
Artificial intelligence (AI) has escaped the innovation lab and entered everyday banking. The European Banking Authority (EBA) reported in 2025 that 92% of EU banks were already deploying AI, including for customer profiling, fraud detection and creditworthiness assessment. That changes the question for directors. It is no longer simply “What can AI do?” but “Do we know where it is being used, what could go wrong and who is accountable?” The EU AI Act reinforces this shift, making governance and AI literacy increasingly important organisational responsibilities. For boards, AI is therefore becoming a governance issue and seeking out training to help professionals like you to understand the knowledge needed to oversee it responsibly is vitally important.
When an AI system produces impressive results, it is tempting to leave the difficult questions to the technologists. Boards cannot afford that luxury. Directors need to know who owns each system, who approved it, how performance and risks are reported, and who intervenes when something goes wrong. Buying the technology from a third party does not make these questions disappear.
The EU AI Act reinforces this accountability mindset. Its risk-based framework imposes obligations according to how AI is developed and used, while deployers of high-risk systems face specific organisational and oversight duties. Crucially, Article 4 requires providers and deployers to support AI literacy among relevant staff.
For a bank, imagine an externally supplied AI credit tool systematically producing unfair outcomes. “The vendor built it” would be a poor boardroom defence. Directors need evidence that responsibilities, escalation routes, human oversight and challenge are working before customers or regulators discover otherwise.
This does not mean directors must understand the mathematics behind every model. They do, however, need enough AI literacy to ask awkward questions, recognise inadequate answers and establish clear accountability. Effective AI governance starts when somebody can confidently answer, “Who owns this risk?”
AI can fail quietly. A credit model may disadvantage particular customers because historical data contains hidden bias. A GenAI assistant may confidently invent financial information, while an employee might paste confidential client data into an unauthorised tool. Meanwhile, model drift can gradually make yesterday’s reliable system tomorrow’s liability.
These are not hypothetical categories. The EBA warns that AI can create risks involving bias, poor data quality, operational failure, cyberattacks and third-party dependence. The European Central Bank (ECB) similarly highlights hallucination, algorithmic bias and the difficulty of explaining increasingly complex models. It also reports that some banks still lack full transparency over how particular AI models reach their results.
For boards, squeezing these problems into conventional model, technology or operational-risk boxes may therefore miss the bigger picture. An AI risk taxonomy can provide a clearer map, identifying risks across areas such as fairness, reliability, explainability, data, security and human oversight. It can also expose how several risks interact.
That is why AI ethics and trustworthy AI matter beyond abstract principles. Boards need to understand how apparently technical weaknesses can become customer harm, regulatory breaches and reputational damage. Effective governance begins by recognising the risks before an algorithm makes them visible the hard way.
For financial institutions, the EU AI Act changes the boardroom question from “Can we use AI?” to “Can we govern its use?” Its risk-based framework means that obligations depend on what an AI system does and the risks it creates. That matters in banking, where AI used to evaluate a person’s creditworthiness can fall within the high-risk category.
For high-risk systems, the Act brings expectations around risk management, documentation, record-keeping, transparency, accuracy and human oversight. Deployers must also monitor systems and assign people to oversee them. AI literacy obligations require organisations to support staff who operate or use AI systems.
Consider a bank proposing an AI-driven lending tool. A board should ask more than whether it improves approval speed. How is the system classified? Can its decisions be explained and challenged? What evidence demonstrates compliance? Who intervenes if outcomes discriminate?
These are strategic questions as much as compliance questions. Regulatory requirements can influence what technology a bank buys, how quickly it deploys AI and what governance infrastructure it needs. The Act therefore pushes AI governance beyond the compliance department. Boards need to understand not only what their AI can do, but what the organisation must prove about how it does it.
Before a board can govern AI, it needs to know where AI lives. That sounds obvious, yet ECB workshops in 2025 found banks were still building system inventories and that some lacked transparency over how particular models produced results.
A credible inventory should capture developed models and AI embedded in cloud services, vendor platforms and other third-party products. Governance then has to follow each system from planning and procurement through development, testing and deployment to monitoring, modification and retirement. Performance, reliability, data quality and explainability need continuing evaluation, not a ceremonial sign-off before launch.
The challenge becomes sharper when technology is outsourced. The EBA warns that growing AI use brings third-party dependence alongside operational, cyber and legal risks. A supplier may provide the algorithm, but the bank still needs to understand its exposure, monitor performance and maintain controls.
For boards, this makes management information crucial. A dashboard full of green indicators is reassuring only if directors know what has been tested, against which standards, how frequently and with what results. Useful reporting should expose model drift, incidents, third-party weaknesses and unresolved remediation. The board needs evidence that controls work, not simply evidence that controls exist.
An impressive AI policy means little if nobody knows how to apply it. Effective governance requires practical machinery behind the promises. That starts with an AI inventory and risk taxonomy, supported by clear ownership, lifecycle controls, model oversight, evaluation processes and robust scrutiny of third-party providers. A Generative AI Acceptable Use Policy can also establish where employees may use GenAI, what information they can enter and when human review is essential.
This is already becoming supervisory reality. ECB workshops found banks conducting AI system inventories and compliance self-assessments, while around half of the participating institutions had introduced dedicated AI policies or committees. Yet supervisors also identified continuing gaps in data governance and transparency.
The EIMF course brings these building blocks together through practical application and case studies. Its value lies in helping professionals move from knowing the terminology to constructing governance arrangements, assessing AI risks and communicating those risks convincingly to senior management and boards.
Boards do not need to understand every line of code, but they must understand what the technology can do, where it can fail and who is accountable. ECB Banking Supervision is clear that banks cannot outsource accountability to an algorithm and that innovation must accompany strong governance. For directors, that means challenging assumptions, demanding evidence and recognising when intervention is necessary. The winners in AI will not simply be the fastest adopters. They will be institutions whose boards can demonstrate that innovation, responsibility and control advance together.
– Would specialist training, such as EIMF’s Elements of AI Governance in Banking & Finance, help your board and senior professionals ask better questions, challenge AI decisions more confidently and turn regulatory responsibilities into effective governance practice?
Resources
– AI Act
The European Commission (2026)
https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai
– AI Literacy – Questions & Answers
The European Commission (2026)
https://digital-strategy.ec.europa.eu/en/faqs/ai-literacy-questions-answers
– AI talent, skills and literacy
The European Commission (2026)
https://digital-strategy.ec.europa.eu/en/policies/ai-talent-skills-and-literacy
– The rise of artificial intelligence: benefits and risks for financial stability
Banque Centrale Europeenne (2024)
Contact the EIMF Team
Phone: +357 2227 4470
Email: [email protected]
This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the opinion to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
The MAP S.Platis Group uses cookies in order to deliver a better user experience on its websites. For further information regarding cookies please see the MAP S.Platis Cookies Policy at https://eimf.eu/cookies-policy
Necessary cookies are absolutely essential for the website to function properly. This category only includes cookies that ensures basic functionalities and security features of the website. These cookies do not store any personal information.
These cookies track your online activity to help advertisers deliver more relevant advertising or to limit how many times you see an ad. These cookies can share that information with other organizations or advertisers. These are persistent cookies and almost always of third-party provenance.
Also known as “functionality cookies,” these cookies allow a website to remember choices you have made in the past, like what language you prefer, what region you would like weather reports for, or what your user name and password are so you can automatically log in.
Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
Join us to gain insights from Alana Hill, learn practical strategies for turning conflict into opportunity, and discover how challenges can drive growth and stronger team performance.
On All Self-Paced eLearning CPD Courses in Financial Regulation
Hosted by the EIMF and the Chartered Governance Institute
Engage with 20+ leading experts and earn 6 CPD units in Financial Regulation.
Not sure if it’s right for you? Let’s talk.
Discount Coupon: NYNY10
Valid until 31 Jan 2025 23:59
Register now to receive a valuable educational resource each day and be automatically entered into our Grand Christmas Draw on 24th December – Don’t miss out!
On Self-Paced eLearning Courses
*complete your purchase before 21 April 2024