Leadership1 distinct publisher3 min readPublished
Glass Lewis's 2026 proxy season data has cybersecurity oversight disclosed by more than nine in ten large caps, which turns the AI question from a novelty into a peer comparison directors will be asked to answer.
The Board Room · Leadership desk

Compiled by The Board RoomSomething wrong?How this is made
The two percentages that will end up in a governance deck measure different objects, and the difference decides what a board actually has to do about it. Glass Lewis counts clear attribution of cybersecurity oversight, meaning a disclosed statement of which body owns the topic, at over nine in ten large caps in the UK and Continental Europe [1], and defined board oversight of AI at around seven in ten European large caps [2]. The American figure in the same memorandum, roughly 21% of Russell 1000 companies with meetings through June 2026, counts something narrower, which is having an AI policy in place [6]. A company can name an owner without writing a policy, or write a policy without naming an owner, and only the first appears as a line in a committee charter.
The movement is where the two regions separate. Continental European large caps went from around one in five with an AI policy in 2025 to more than half [3], UK companies reached over four in ten [4], and the Russell 1000 moved from about 15% to 21% [6]. That is roughly 30 points of year-over-year change against six, about five times as much [1]. Inside Europe the catch-up is still unfinished, with about 20 points separating cyber attribution from AI oversight [2].
A skeptic on the audit committee would say none of this has cost a director a seat, and on the 2026 record that is correct. Sixty-three US director nominees failed to win majority support, down from 72 in 2025 [7], and only four of them left their boards while 11 resignations were rejected, a departure rate near 6% with 59 directors still seated [8][3]. Canada recorded two failures, down from ten [9]. Australian dissent reached a ten-year high, with 26 ASX300 directors drawing over 25% opposition, nine more than in 2024 [10][4], and Glass Lewis attributes that to share performance, operational challenges, capital allocation and concerns over board composition [11]. In Europe the share of companies with a director proposal above 20% opposition rose from about 2% to about 5% while no uncontested large-cap election failed [12]. The vote channel this season registered performance, not disclosure practice.
The board-deck version says an AI working group exists and will be formalised later in the year, and it is incomplete in one specific respect: the comparison has moved outside the company. The counting appears in a Glass Lewis memorandum covering multiple markets [13], and the peer set has already answered the question in writing. Naming an owner costs agenda time and creates a duty the board then has to evidence at each meeting, while leaving it unnamed costs nothing this quarter and turns into a question a voter can ask with a peer number attached next year. The decision available now is which existing committee absorbs the topic, because the next cycle's comparison runs against a European baseline near seven in ten rather than against an empty field [2].
Ranked by verification strength, evidence, and original report placement.
In both the UK and Continental Europe, clear attribution of board cybersecurity oversight has become standard practice, disclosed by over nine in ten large cap companies.
Board oversight of AI is less established than cybersecurity oversight but catching up quickly, present at around seven in ten large cap companies in Europe, a significant increase from the previous year.
More than half of Continental European large caps have an AI policy in place, up from around one in five in 2025.
Over four in ten UK companies have an AI policy in place.
In the US, board oversight of cybersecurity is disclosed by nearly nine in ten Russell 1000 companies with AGMs through June 2026, largely consistent with 2025.
Approximately 21% of Russell 1000 companies with AGMs through June 2026 have an AI policy in place, an increase from around 15% in 2025.
Follow any of these and your For You feed starts watching them — no settings page required.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Single-source proprietary dataset, internally consistent but unaudited
Every figure rests on one Glass Lewis memorandum republished on the Harvard corporate governance forum. The dataset is quantitative, multi-market and includes year-over-year comparatives, which is stronger than anecdote, but the supplied text discloses no sample sizes, no methodology, and no definition of 'board oversight of AI' or 'AI policy'. Several headline numbers are rounded to 'nine in ten' or 'seven in ten', and no independent dataset corroborates them.
Oversight attribution widespread; written AI policies uneven by region
Adoption of the practice being described is directly measured in the source: around 70% of European large caps name board AI oversight and more than half of Continental European large caps have an AI policy, against a cybersecurity oversight baseline above 90%. But adoption is regionally lopsided — only about 21% of Russell 1000 companies have an AI policy — and these are disclosure counts, not evidence of operating practice.
Framing tracks the data, with mild overreach on what disclosure implies
The story's headline number matches the source exactly and the derived comparisons are arithmetic on the memo's own figures, so there is little numerical inflation. The modest positive gap reflects framing: 'naming a board owner for AI oversight' is a disclosure event, and neither the source nor the cluster offers evidence that it changes AI practice, risk outcomes or accountability — the memo's own voting data shows disclosure and consequence often diverge, with only four of 63 failed US nominees actually leaving their boards.
Proxy adviser publishing metrics shaped by its own voting policies
The dataset is authored by Glass Lewis, a commercial proxy adviser whose voting guidelines and research subscriptions create a direct interest in companies disclosing board oversight structures and in governance benchmarking being seen as consequential. The republishing venue is an academic governance forum that carries contributed practitioner posts, so the framing is not independently edited. No sponsorship of the underlying claims by AI vendors is evident.
Moderate: figures are clear and attributed, but unreplicated
Confidence is supported by precise attribution, disclosed authorship, consistent year-over-year comparatives across five markets, and derived numbers that are simple arithmetic on stated figures. It is limited by the absence of any second publisher or dataset, missing methodology and definitions, rounded proportions in the European figures, and the interested position of the author.
leadership
A sub-80% say-on-pay vote now buys a year of investor meetings1 distinct publisher
leadership
Boards Prune ESG Pay Labels But Keep the Specifics, Reshaping the Next Incentive Cycle1 distinct publisher
leadership
The SEC's Spring 2026 agenda reads like a planning document. Treat it as one1 distinct publisher
leadership
Kalshi's enforcement chief concedes the equity surveillance playbook does not port over1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 27, 2026