7 min readAI Agents · Cybersecurity
The One Slide Your Board Needs on AI Agents
By Michelle Savage, Experience Design Director, PayPal

TL;DR: The board has one real question about AI agents: when one does something wrong, can the company show it had control? Give them four statements backed by four mechanisms. You can see every agent, stop any agent, trace an action back to its owner, and prove all of it after the fact.
Last updated October 6, 2026. This piece was rebuilt from the ground up around the one-slide answer, so the conclusion gets delivered the first time.
A board member asked Josh who's liable when an AI agent does something wrong. He'd just spent 13 slides on the controls, and he hadn't answered that question once. That was August 24, 2026, in front of a credit union board of nine, none of whom had worked in financial services. He'd shown them the roster, the credentials, the checkpoint, the kill switch, the log. All mechanism. Then the hardest question of the night arrived and he built the answer live: liability rests on whether you can show you had control. He'd presented the proof and skipped the conclusion. This piece is the conclusion, delivered first.
What does the board actually want to know about AI agents?
Who's on the hook when an agent does something wrong. That's the question under every other question. They'll ask about strategy and cost first, and those are warm-up. The cold one is liability. So answer it first: an AI agent acted on its own and caused harm, and here's how we'd show a regulator or a court that we had control of it the whole time. If you can say that in one breath, the rest of the briefing is detail. If you can't, the rest of the briefing is decoration.
A Fortune 500 CISO told Josh at the RSAC Conference that three of her teams were piloting agents and she couldn't tell her board who owned any of them. That's the version of this question that arrives too late.
Why do most AI board briefings skip the liability question?
Because the security team builds the deck, and security teams think in controls. The 13 slides walked through the mechanism piece by piece, every piece right, and never said the sentence a director needs: this is why we'd be able to show we had control. Directors don't run the mechanism. They own the outcome, and the distance between those two views is where the question gets cold.
There's a second reason. On a June 22, 2026 call, a large credit union's annual 30-minute board presentation was being built by the reporting team while the CISO presented it with the head of compliance. Two owners, one slot. The liability framing is the one thing both owners agree on, and it usually isn't in the deck at all. The pattern held across three engagements in nine weeks: one board heard about AI spend before it heard about AI control, and one education-only session with no decision ask still got the liability question anyway.
What are the four things a board needs to hear?
Statement | The mechanism behind it |
We can see it | A roster of every agent, what it touches, what it can spend, and its named human owner, with a separate identity per agent so actions don't get logged under a person's name |
We can stop it | A kill switch someone other than the builder can pull, plus a limit that fires an alarm before one agent reaches too far |
We can trace it back | A checkpoint in the path between agent and tools, writing one log line per call with the agent's name on it |
We can prove it | The attribution record itself, kept and unaltered, ready for an examiner or a lawyer |
Then the closing line, out loud: liability rests on whether we can show we had this control, and here's the proof. The owner half of "see it" is covered in who owns your AI agent, and the containment half of "stop it" in AI agent blast radius.
What does this look like when an agent goes wrong?
Kevin's story from the book is the one to use. His procurement agent had been perfect for three months, so his team expanded its permissions to negotiate pricing under $50,000. Within 48 hours it read a 15 percent bulk discount as permission to commit $1.4 million to industrial floor cleaner, roughly 40 years of stock. A routine morning review caught the pending authorization inside the 24-hour confirmation window. Nobody lost $1.4 million.
Walk it through the four statements. They could see the agent: the team knew what it was and what it could spend. They could stop it: the 24-hour window was the stop, and it held. They could trace it: the review found the pending authorization and the discount that triggered it. They could prove it: the pending record existed before anyone went looking. That's what "we had control" looks like to a board. Something bad started, and the chain held. Kevin's team now runs monthly sessions trying to break their own agents, which finds more problems than any audit did.
Where does this fit what the board already owes regulators?
For public companies, inside an obligation that already exists. On July 26, 2023, the SEC adopted rules requiring companies to describe in the annual report how the board oversees cybersecurity risk and what management's role is. An agent with credentials that acts without a human in the loop is a cybersecurity risk, so the board's oversight of it is now a disclosure item. Credit unions and private companies don't file 10-Ks, and their examiners and insurers ask the same question in a different form: show us you had control.
The NIST AI Risk Management Framework, published January 26, 2023, puts governance as the function that runs across everything else and names accountability and clear roles as part of it. The four statements are that governance function, translated for a director with 30 minutes and one question.
What goes on the one slide?
One slide, four rows: see it, stop it, trace it back, prove it. Next to each row, the one mechanism that makes it true and the name of the person who owns that mechanism. At the bottom, in larger type than anything else: liability rests on whether we can show we had this control. Put it early in the deck. If the board remembers one slide, make it the one that answers the question they were going to ask anyway.
Frequently asked questions
Should the CISO present AI agent risk, or the CIO?
Whoever can say "we can stop it" and mean it. In practice that's the CISO, because the kill switch and the log live in security. If the CIO owns the agent program, present together, and the four statements come from the person who owns the controls behind them.
How much technical detail does the board need?
Almost none. Each statement gets one mechanism named in plain words. A roster is a list. A kill switch is a switch. A checkpoint is a gate in the path. Save the diagrams for the appendix. A director who wants depth will ask, and that's a good sign.
What if we can't say yes to all four yet?
Say which ones you can't, with a date. A board would rather hear "we can see and stop every agent, and tracing is 60 days out" than a slide that implies everything is done. A missing piece with a date is a plan. The implied yes is a liability of its own.
Is the board briefing a one-time event?
No. The roster changes monthly. Tell the board the agent count, how many were stopped, how many were traced, and how many changed owner since the last meeting. Four numbers on one line, and it's the update that shows the chain is still holding.
Key takeaways
The board's real question is liability, and it has a yes-or-no answer: can you show you had control?
Four statements carry the answer: see it, stop it, trace it back, prove it. Each maps to one mechanism and one named owner.
Kevin's $1.4 million near-miss is the four statements working: something bad started, and the chain held.
For public companies, board oversight of agent risk is already an SEC disclosure item under the 2023 rules.
One slide, four rows, with the liability line in larger type at the bottom. Deliver the conclusion first.
Before you build the slide, baseline the four answers. The free self assessment takes about ten minutes and shows which statements you can make today.
The board has one question about AI agents, and it's whether you can prove you were in control when one went wrong. Build the deck around that sentence and the other 12 slides take care of themselves.