The AI policy has become the corporate governance equivalent of a fire drill memo: filed, approved, and rarely tested. It is a policy that most boards now have. Very few could tell you, on short notice, which AI systems are running inside their organization, who authorized them, and who answers for what happens when a system goes wrong. That gap between the document and the deployment is where Jim Tunnessen, Founder and Chief Executive Officer (CEO) of Governbox AI, says the genuine exposure sits. After more than two decades in federal C-suite technology roles shaping how AI gets used across the United States, his read is unsentimental. A policy is a statement of intent. Risk lives in operations, and boards have been auditing intent while the operations ran unsupervised. His remedy is not a new framework or another committee. It is three questions a director can ask in a meeting and judge management by the quality of the answer.
Start With What You Have
The first question sounds too basic to put to a sophisticated executive team: what AI do we have? Tunnessen means it literally. Every tool, every vendor feature, every model. The emphasis on vendor features matters more than directors usually appreciate, because the bulk of enterprise AI did not arrive through a procurement process anyone voted on. It arrived as an update. A customer relationship management system gained a summarization engine. A support platform switched on automated drafting. Nobody signed a contract for AI; they signed a contract for software, and the AI came later, inside the renewal. The result is an installed base that no single executive has ever seen in full.
What Tunnessen asks management to produce is not a slide. It is a living use case inventory with a named owner for each entry. Both halves of that phrase carry weight. Living, because a snapshot taken last quarter describes a system that has since changed. Named owner, because accountability that attaches to a department attaches to no one. “You’d never approve a budget without seeing the numbers,” he says. “AI deserves the same discipline.” The comparison is sharper than it first appears. Boards accept, as a matter of course, that financial oversight requires line-item visibility before approval. They have tolerated for AI a standard they would reject outright for capital spending: broad assurance that systems are under control, with no underlying detail. A board that cannot name the owner of a given AI use case has not delegated that risk. It has misplaced it.
Evidence Beats Assurance
The second question is where most governance conversations quietly collapse. Can we prove it’s governed? Tunnessen draws the distinction cleanly: “A policy tells people what should happen; evidence shows what did happen.” Those are different artifacts serving different purposes, and boards routinely accept the first as a substitute for the second. A policy is cheap to produce and impossible to falsify in a meeting. Evidence is expensive, specific, and reveals whether the control operated at all.
He points to the National Institute of Standards and Technology (NIST) AI Risk Management Framework and ISO/IEC 42001 as the structures that give this rigor a shape. He is also explicit about the output a board should expect: documented risk assessments, testing results, and a decision record. The test he applies is the one that should concentrate the mind of any director. The record should be something you could hand to a regulator tomorrow. Not reconstruct, not assemble, not explain. Hand over. That standard changes what management has to build, because a decision record that survives external scrutiny cannot be written after the fact. It has to be generated as decisions are made, which means the governance has to be running continuously rather than performed at audit time. Boards that absorb this will stop asking whether a policy exists and start asking what the last documented AI risk assessment concluded, who signed it, and what changed as a result. The first question is answerable with a yes. The second is not.
Someone Has To Watch The Agents
The third question is the one with the shortest runway. AI agents, Tunnessen notes, now act on their own. “They send messages, move data, and trigger transactions.” Each of those verbs describes an action a company would ordinarily require a human to authorize, log, and answer for. Agents perform them at machine speed, in volume, across systems, often without a person reviewing the individual decision. The governance models most organizations built assume a human in the loop at the point of action. That assumption is dissolving, and the controls built on top of it dissolve with it.
Tunnessen’s answer is architectural rather than procedural. “Oversight has to live inside the system itself,” he says, describing what he calls the agentic control plane: clear limits on what an agent can do, a log of what it did, and a person who can step in. Three components, and the ordering is deliberate. Limits constrain the action before it happens. Logs make it reviewable afterward. The human intervention point ensures someone can stop it. Oversight written into a policy document cannot do any of this, because the agent never reads the document. Oversight written into the system can. For directors, this reframes the question entirely. The issue is not whether the company has rules for agents. It is whether those rules are enforceable by the infrastructure or merely aspirational in a binder.
Tunnessen’s larger point is that these three questions are not an annual exercise. “Strong AI governance is an operating system you run every day.” Boards that start asking now, he argues, gain real confidence in how AI is used across their organization. The ones that wait will be asking the same questions under considerably less comfortable circumstances.
Follow Jim Tunnessen on LinkedIn for more insights on AI governance, board oversight, and managing agentic risk.










