Your AI Talks to Customers. Your Board Answers for It.
Directors’ institutes in the US, the UK and Australia have all put AI oversight on the board agenda. Customer-facing AI has been flagged as an area of risk.
When boards think about technology risk, they usually think of the classics: the ERP project that blows its budget, or the outage that hits operations and customers. The cautionary tales are everywhere.
If your CX stack includes AI that talks to customers, the risk is more visible. This isn’t back-office software that fails internally. It is a system that speaks with the company’s voice, thousands of times a day, to customers, the people who pay for everything. When it goes wrong, it can go wrong publicly.
Which is why CX needs to be on the board agenda.
Three institutes, one instinct
The US’s NACD, UK’s IoD and Australia’s AICD have all refreshed their AI governance guidance in the past year. Different markets, same instinct: boards need to govern AI by asking management to show the evidence, not just describe the controls.
NACD asks it most bluntly: how is the system tested, certified, and continuously monitored? How do we know?
The AICD has also published a practical companion for tech investment generally: Five questions boards should ask before investing in major tech projects asks what precise business problem will be solved; whether the company is ready for the change; what processes keep reassessing what could go wrong; whether the partnership models are flexible to allow adoption of a better solution if it comes along, and for a walkthrough of the new system before pressing go. All 5 apply to a CX deployment. The difference is that with AI, the answers keep changing after go-live.
None of this guidance is specifically about CX, yet CX is in the crosshairs, because the customer conversation is where an AI failure meets the outside world. NACD’s guide names CX first when it lists where boards should assess their AI risk.
You can hand the work to a vendor, but the accountability will stay in the boardroom.
US considerations
In the US, regulation is beginning to reach customer-facing conversational AI, though its scope varies considerably. California’s SB 243, in force since 1 January 2026, and Colorado’s Chatbot Safety Act (HB 26-1263), signed in May 2026 and effective 1 January 2027, focus primarily on conversational and companion AI services, with particular attention to disclosure, minors, emotional dependency, self-harm, and any suggestion that the AI offers licensed professional care. They are not universal rules for every customer-service bot. What they signal is the direction of travel: organisations will increasingly be expected to demonstrate how their conversational AI behaves, and whether the required safeguards work in practice.
Where these laws apply, the obligations sit with the company deploying the bot, and not only with the vendor that built it. Colorado’s Act will require operators to file an annual report with the Attorney General on how the safeguards perform. Around all of this sit the FTC’s deception baseline, private rights of action, and a plaintiffs’ bar that has made chatbot claims one of the fastest-growing corners of AI litigation.
The map is still being drawn. Colorado’s separate AI Act has since been amended and its enforcement deferred pending rulemaking, so directors should treat the state picture as one that is still moving.
Where a customer-facing AI falls within one of these laws, approving it is approving a regulated activity with real penalty exposure. Under SB 243, damages run to the greater of actual damages or $1,000 per violation, plus fees, and every instance of non-disclosure can count separately. The question boards need to put to management is the same either way: if a state Attorney General asked tomorrow, what evidence of the bot’s actual behaviour could we hand over?
Australian considerations
In Australia the governance response is arriving through the courts and the prudential rulebook. In ASIC v Bekier [2026] FCA 196, the Federal Court used a directors’ duties case to caution boards that AI can help manage the volume of information but cannot displace human judgement. APRA’s CPS 230 makes operational resilience, including the third-party platforms behind customer channels, a board-owned obligation for regulated entities.
The Australian question is simpler: if customer-facing AI failed this afternoon, who could show evidence of what it was doing this morning, and would that evidence satisfy a regulator, not just a project team?
UK considerations
The UK runs the same logic through the customer outcome. The FCA’s Consumer Duty requires firms to evidence good customer outcomes, and the requirement doesn’t pause because the interaction was automated. The IoD frames AI governance as the questions to ask at your next board meeting. And Britain’s regulatory direction, with sandboxes and real-world testing, makes “show us the test results” a natural sentence for a UK director.
Who answers when the board asks?
The practical problem with most of these questions is that in a lot of organisations, nobody owns the answer. The customer outcome usually sits with a chief customer officer, COO or VP of customer operations. The system sits with the CTO or CIO who bought it. The model sits with a vendor. Ask “how do we know it’s working” and the CX lead points to the platform dashboard, the CTO points to the vendor’s assurances, and the vendor points to its own testing. Everyone is partly responsible, so no one is accountable for the evidence.
So these aren’t CTO questions, and boards shouldn’t let them be answered as if they were. The technology chief can answer for the stack but not the customer outcome; the CX lead can answer for the journey but not the system. The question belongs to management as a whole, and the honest answer needs a record that none of them individually produces.
The question that survives all three
Strip out the jurisdictions and one question remains: how do we know what it is doing, and could we prove that to someone outside this room?
A supplier’s assurance about its own part of the stack may not be enough to satisfy a regulator, or a board seeking confidence across the complete customer journey. Platform dashboards tell you what the system believes about itself. What survives scrutiny is a dated, independent record: scheduled outside-in tests that follow the journeys customers take, capturing transcripts, call recordings and quality metrics as they happen.
Accountability that stays in the boardroom cannot rest on reassurance alone. It has to be evidenced. Building that record is part of what PumpCX does: independent, scheduled, outside-in testing of customer-facing AI, with evidence a board can table.
CRM decisions are about managing customers. AI now speaks for the company every time it communicates. Boards need to treat that as a serious governance issue, and make sure they have the evidence when someone asks.
