AI: where it stands, and what trusted adoption requires
Background for an exploratory discussion: the three waves of adoption, the five
governance principles published for boards, the ten dimensions of trusted AI, and where the firm
works across AI and technology.
Purpose: background for an introductory discussion on AI and technology: what is
changing, what boards are being asked to oversee, and where KPMG works Position as at: 12 August 2026 Scope: enterprise AI adoption and its governance. Sector examples are drawn from financial
services. Regulatory references are illustrative and jurisdiction-specific Status: illustrative working material for discussion. Not legal or regulatory advice
Trust is the condition for scale.
The published principles put it directly. Trust is described there as the foundation that allows
AI to be scaled successfully rather than a constraint upon it. Organisations investing in
governance, accountability and transparent practice are held to be best placed to innovate boldly
and earn lasting confidence. Governance read as a brake produces the opposite of what it is for.
1. Where AI stands: three waves
Adoption has moved in three recognisable waves. The waves overlap and organisations sit across
more than one of them at a time, so the question is not which wave an organisation has reached but
where the weight of its investment currently sits.
Wave
What it looks like
What the board was asked to do
One. Personal productivity
Assistants and copilots in the hands of individuals. Research and drafting that took three
or four days compressed into minutes. Value accrues to the person doing the work.
Contain the downside. Keep organisational intellectual property from leaving through the
tool, and limit the consequences if something went wrong.
Two. Process improvement
AI inside a process rather than beside it. Automation in the back office, and prompts that
support a service agent during a live interaction. Still human-led throughout.
Make sure the opportunity is being taken, in a safe and controlled way. The emphasis moves
from containment to capture.
Three. Agentic
Systems that plan and act across other systems, with growing autonomy and several distinct
types of agent. Most organisations are at the beginning of this.
Decide what an agent may do without a person, and evidence that the limit holds.
Most organisations are still substantially in wave one, and that includes large professional
firms. This is worth saying plainly because the gap between wave one spending and wave two or
three language is common rather than exceptional. It is a shared starting position rather than a
finding about any one organisation.
The language of containment from wave one persists, and it is still useful. The question asked
then was how to limit the blast radius if something went wrong. In wave three that question returns
with more force, because a system that acts can affect a record, a customer or a payment rather
than only a draft.
2. What boards are being asked: the five principles
In April 2026 KPMG International and the INSEAD Corporate Governance Centre published a set of AI
governance principles written for boards rather than for technologists. They are principles rather
than rules, chosen deliberately because principles are more useful where situations are unclear and
uncertain, and they are explicitly illustrative rather than mandatory standards or legally
enforceable obligations.
The dilemmas fell into three perspectives. Principles 1 to 3 take the company view, principle 4
the ecosystem view, and principle 5 turns the board on itself.
1Strategic oversight for long-term value creationCompany view
What the principle says
The board oversees the development and execution of the AI strategy, and how it supports
sustainable long-term value creation.
Its five sub-principles
1.1 Sustainable long-term value creation with AI
1.2 Responsible innovation
1.3 Foundational investments
1.4 Organisational flexibility and learning
1.5 Transformation scope
What it means in a discussion
The dilemma named is capital allocation. Benefits require sizeable early investment in
technology and data infrastructure, capability building and change management, at a point when
returns are uncertain, against pressure to show short-term productivity gains. The source states
that long-term value from AI will not derive solely from productivity gains, which is the
sentence that reframes a licence budget as something other than a strategy.
Source: Principle 1 and sub-principles 1.1 to 1.5.
2Active technology and security oversightCompany view
What the principle says
The board actively oversees strategic AI technology choices and expects appropriate
consideration of speed, cost, sovereignty, privacy, safety and security.
Its three sub-principles
2.1 Deliberate AI capability ownership
2.2 Well-managed vendor dependency
2.3 AI safety and security
What it means in a discussion
Technology choices are not always board-level topics, but the source is direct that the setup
of the stack, from data centres and cloud infrastructure to the choice of foundation models and
proprietary or third-party data, has a major impact on cost, speed, quality and above all on the
control an organisation has over its AI systems. Sovereignty is named as increasingly relevant,
including whether an organisation can expect governmental support or restriction. Vendor
dependency covers a vendor failing or being legally prevented from supplying, and several
vendors on one project with no clear structure for liability if the AI fails. Sub-principle 2.3
names agentic misalignment alongside data poisoning, misinformation, privacy breach and cyber
attack, and expects risk-based traceability and auditability including clear audit trails.
Source: Principle 2 and sub-principles 2.1 to 2.3.
3Workforce transformation and human accountabilityCompany view
What the principle says
The board expects management to develop clear guiding principles for AI adoption, and
considers how the adoption strategy affects human capital, including the future role of humans
relative to AI.
Its three sub-principles
3.1 Defined and safeguarded quality of (human) decision-making
3.2 Strategic workforce transformation and upskilling
3.3 Appropriate long-term talent pipeline
What it means in a discussion
Sub-principle 3.1 is a control expectation carrying an HR label. Boards ask management to
define which decisions must always involve meaningful human oversight, involvement or
accountability, consistent with human-in-the-loop and human-on-the-loop concepts. On
high-impact decisions, a higher degree of AI involvement is held to be appropriate only where
outputs are explainable, auditable and aligned with risk appetite. It also expects the board to
remain informed on where tools are being developed bottom up as well as top down. Sub-principle
3.3 reaches further than most expect, asking how entry-level roles and apprenticeships might
evolve and what that means for the future labour market.
Source: Principle 3 and sub-principles 3.1 to 3.3.
4Building trustworthy AIWider stakeholders
What the principle says
The board expects management to proactively adopt standards for trustworthy AI reflecting
the organisation's values and regulatory obligations, and to consider stakeholders and society
at large.
Its five sub-principles
4.1 Fair and inclusive AI solutions, processes and culture
4.2 Safeguarded privacy, data usage and protection in AI solutions
4.3 Impact on the physical environment
4.4 Trustworthy AI
4.5 Legally compliant AI
What it means in a discussion
Sub-principle 4.2 requires that data is legally obtained and its use permissioned and
transparent, extending to suppliers, vendors, partners and regulators. Permissioned is the
operative word, because retrieval tools inherit whatever access already exists. Sub-principle
4.4 asks for values to be translated into practice through technical design together with
monitoring for learning practices, testing, output drift and incident management. Sub-principle
4.1 contemplates involving an objective external party where appropriate. Sub-principle 4.3
covers energy and water use, which matters where sustainability commitments and data centre
decisions sit in the same organisation.
Source: Principle 4 and sub-principles 4.1 to 4.5.
5The work of the boardThe board itself
What the principle says
The board considers how AI affects its own governance practices, defines what effective AI
oversight looks like, and adapts its structures and processes, particularly around oversight of
risk management.
Its five sub-principles
5.1 Appropriate oversight capabilities for AI and other emerging technologies
5.2 Effective AI oversight processes
5.3 AI tailored risk management
5.4 Adherence to a globally diverse regulatory AI landscape
5.5 Transparent and outcome-based reporting
What it means in a discussion
This is the only principle where the board acts rather than instructs, which makes it the
most immediately actionable. The source observes that traditional linear ways of working may
need adjustment, and that boards may revise structures and composition, committee mandates,
review frequency, agenda time and the use of external expertise. Committee charters are named
directly. Sub-principle 5.2 goes further and contemplates the board using AI itself, subject to
clear guidelines on permissible use by directors and, where appropriate, a formal and legally
vetted AI use policy for board members covering confidentiality and legal privilege.
Source: Principle 5 and sub-principles 5.1 to 5.5.
The evidence base. The principles drew on inputs from over 25 board members
across the Americas, Europe and Asia, a steering committee of directors collectively serving on
more than 25 boards, and an advisory council covering a further 22 organisations.
3. Trusted AI: the ten dimensions
The principles describe what a board should oversee. The Trusted AI framework describes the
dimensions along which an AI system is judged trustworthy, and is applied across the KPMG network.
It is the layer where a governance expectation becomes something that can be designed, tested and
evidenced.
Dimension
What it asks of a system
01
Accountability
A person remains answerable for the system at every stage of its life, and human oversight is designed in rather than assumed.
02
Transparency
Those affected are told, appropriately, that AI is in use and what part it plays.
03
Explainability
The reasoning behind an output can be set out in terms the recipient can act on.
04
Fairness
Bias against individuals or groups is looked for, measured and reduced.
05
Privacy
Personal data is used lawfully and no more widely than the purpose requires.
06
Reliability
Performance holds at the accuracy claimed, consistently and over time.
07
Data integrity
The data carries known quality, governance and provenance.
08
Security
The system resists attack, manipulation and misuse.
09
Safety
People and property are protected from harm the system could cause.
10
Sustainability
Environmental cost is understood and contained.
How the two fit together. The principles are what the board asks for. Trusted AI is how
management answers, because each dimension reduces to something that can be specified in a design,
checked in a test and shown to an auditor. Several map directly: accountability and explainability
to sub-principle 3.1, privacy and data integrity to 4.2, security and safety to 2.3, sustainability
to 4.3.
4. What is seen in practice
Observations from adoption work rather than from a study. They are offered as a description of
the common pattern, and no proportion is asserted for any of them.
What comes up repeatedly
Why it happens
Wave one value is real and hard to evidence
Time is released across many people in small amounts rather than removed from one process,
so it does not appear in an operational number. Reported savings frequently turn out to have
converted into prompting and small decisions.
The data foundation decides the outcome
Unstructured, unclassified and inconsistent source material makes a pilot perform well on a
prepared sample and poorly on live material. This is the least visible and most expensive part
of the work, and it survives a change of model or vendor.
Permissions surface before anything else does
Retrieval inherits existing access rights, so over-shared locations become searchable in
plain language. The exposure pre-existed the tool and was simply harder to reach. It is
checkable quickly, which is why it is usually the first thing to look at.
Ownership sits between functions
Adoption falls between technology and the business, and a committee is appointed where an
owner with budget authority is what the work needs.
Success was not defined before the pilot began
Without a criterion set in advance, a pilot can neither fail nor graduate, and it continues
being described as promising.
Agentic deployments are ahead of the controls
Interest in agents is running well ahead of written limits on what an agent may do without
a person, and ahead of the audit trail needed to show the limit held.
5. Where KPMG works
Grouped by the question being answered rather than by service line, and covering technology
delivery as well as governance, since in practice the two arrive together. Nothing below is a
proposal. Any engagement is scoped to the organisation's own position, and independence
requirements are confirmed before scope is discussed where an audit relationship exists.
AKnowing where the organisation standsDiagnostic
What it covers
AI maturity and readiness assessment against a defined baseline; a use case portfolio scored
for value, effort, risk and data readiness; an inventory of the AI systems, models and agents
already in use, with owners and data reach.
Why organisations start here
The inventory is often the point at which the position becomes visible, because assembling it
is more informative than the document that results. It also sets the baseline everything later is
measured against.
Related principles: 1.1, 1.5, 5.5.
BGovernance, policy and riskFramework
What it covers
AI governance frameworks covering policy, standards, roles, risk appetite and approval gates;
risk assessments for AI systems; extension of existing model risk management to generative and
agentic systems; third-party and vendor AI assurance; data protection impact assessment; mapping
to applicable regulatory requirements and, where a group has European exposure, forward mapping
to the EU AI Act.
Why organisations start here
Extending an existing framework is usually faster and better adopted than building a parallel
one, because the ownership and the reporting line already exist.
Related principles: 2.2, 4.5, 5.3, 5.4.
CAssurance over AI systemsEvidence
What it covers
Readiness for and support through ISO/IEC 42001 certification; pre-implementation review of a
specific system before go-live; independent evaluation and adversarial testing of models and
agents; monitoring for output drift and incident management; internal audit support where AI
enters the audit plan.
Why organisations start here
Sub-principle 4.1 contemplates an objective external party where appropriate, and
certification gives an external reference point that internal assurance cannot supply on its own.
Related principles: 4.1, 4.4, 2.3.
DThe foundation, and the peopleDelivery
What it covers
Data readiness: classification, lineage, quality, and remediation of permissions and
over-sharing before retrieval is switched on. Alongside it, target operating model and centre of
excellence design, role-based enablement, and board and executive education.
Why organisations start here
These are the foundational investments sub-principle 1.3 refers to. They are the least
visible part of a programme and the part whose absence stops the rest from working.
Related principles: 1.3, 3.2, 5.1.
EBuilding and running the technologyDelivery
What it covers
Selection of platforms and models against cost, control and sovereignty requirements; design
and delivery of the systems themselves, including agentic workflows; the cloud, data and
integration work underneath them; and the cyber security of the resulting systems, which changes
shape once systems begin acting rather than only answering.
Why it belongs in the same conversation
Sub-principle 2.1 treats the choice of stack as a board-level matter because it determines
cost, speed, quality and the degree of control retained. Governance designed apart from the
build tends to arrive after the decisions that mattered have been taken.
Related principles: 2.1, 2.2, 1.4.
A board session on the principles is the usual starting point. The principles were written
to be worked through by a board rather than read, and a session on them carries no commitment and
no prerequisite: it needs no access to systems, no data, and no prior assessment. Where a board
wants to go further, the same material supports a review of committee mandates and a policy on
directors' own use of AI, both of which sub-principle 5.2 contemplates directly.
6. Questions worth exploring
Openers rather than an agenda, and none of them expects a prepared answer. Each is a question
worth thinking about aloud together, and several have no single right answer.
Question
Why it is worth the time
Position and ambition
Where does the weight of investment currently sit across the three waves, and where should
it sit in twelve months?
Separates the ambition from the spending. A gap between the two is common and is more
useful named than left implicit.
Which single process would be worth taking properly into wave two?
One process carried through produces an operational number. A portfolio of pilots usually
does not.
Trust and control
Which decisions should always involve a person, and where is that written down?
Sub-principle 3.1 asks the board to have this defined. It is a risk appetite question
rather than a technical one.
Of the ten trusted AI dimensions, which two carry most weight in this sector, and how would
they be evidenced today?
Focuses a broad framework on the two that a regulator or customer would actually test.
What would a plain-language search across existing systems return that it should not?
Quick to check, and it establishes whether the data and permissions foundation is sound
before anything is built on it.
The board and its own work
Do committee mandates say who owns AI oversight?
Principle 5 names charter revision directly, and it is a concrete step a board can take
without waiting for anything else.
Is there a policy on directors' own use of AI, covering confidentiality and privilege?
Sub-principle 5.2 contemplates one. Few organisations have it, and board papers are exactly
the material where it matters.
What reporting would let the board see adoption, benefit and risk in one place?
Sub-principle 5.5 expects systematic and transparent reporting, including explanations of
major AI capital allocation decisions.
7. Sources and limitations
Sources
AI Governance Principles for Boards, KPMG International and the INSEAD Corporate
Governance Centre. Publication number 140336-G, published April 2026, 22 pages. Read in full.
Every principle and sub-principle reference in section 2 is drawn from that text.
The KPMG Trusted AI framework, applied across the KPMG network, for the ten dimension names in
section 3. The one-line descriptions in that table are written for this document.
Known limitations
The three-wave description in section 1 reflects how adoption is commonly characterised in
practice. It is not part of the published principles, which contain no wave model, and the two
should not be attributed to one another.
Section 4 is observation from adoption work rather than research. No proportion, percentage or
survey figure is asserted anywhere in this document, deliberately, because none is sourced.
No value or cost figure is given for any service or process. Quantification depends on the
organisation's own volumes and scope (to confirm).
Section 5 describes where support is commonly provided. It is not a proposal, and scope, fees
and timing are not addressed here.
Where an audit relationship exists, some or all of the services described may not be
permissible for audit clients and their affiliates or related entities. This is confirmed before
scope is discussed (to confirm).
Regulatory references are illustrative and jurisdiction-specific. Nothing here is legal or
regulatory advice, and positions should be checked against the issuer's current published text.