How organisations define and direct AI use
Finding
Large organisations place AI among technology, security and compliance controls while using leadership directions, performance measures and incentives to increase its use. The board guidance examined includes no specific requirement to identify or test the written instruction supplied by the organisation and used to shape AI answers.
Evidence
The Classification Study examined published governance material from fifteen large listed organisations. AI appeared within technology, security, product, risk, conduct or compliance governance in every case, while the mechanisms used for professional advice were absent. The Mandate Study found published evidence of AI use being formalised through leadership instructions, performance assessment, incentives, training, integration into work and board expectations. The Unread Instruction examined nine current board and audit frameworks and applied three tests to each. General duties covering lists of AI uses, ownership, testing and monitoring appeared throughout, yet no framework required anyone to know who wrote the organisation's instruction, when it changed, or how the same important request performed under a different instruction or model version.
Evidential limit
These papers use published corporate material and public guidance. They cannot show every internal rule or board practice, and the Mandate Study does not establish whether requiring AI use improves work. The framework review excludes material behind login or membership barriers and applies only to the versions examined.