
Every month, BarnOwl GRC compiles and reviews leading Governance, Risk and Compliance (GRC) articles and thought leadership from around the world.
This article draws on BarnOwl’s August 2026 review of 39 GRC articles and summarises the themes I believe deserve particular attention from risk managers, executives and boards.
Over the past few months, the GRC conversation has progressively shifted—from questioning traditional risk practices, to trust and behavioural governance, and then to decision intelligence.
August takes us somewhere different again.
Governance is becoming operational.
Nowhere is this more evident than in artificial intelligence. The question is moving beyond whether organisations have AI policies, principles or committees. Increasingly, organisations need to demonstrate who is accountable, what authority AI has, how its actions are monitored, and whether it can actually be stopped.
But the August themes extend beyond AI. Business continuity is being challenged to prove resilience rather than recovery. Boards are being warned that too much backward-looking assurance can create strategic blind spots. And the boundaries between risk, resilience, compliance, culture and technology governance are becoming increasingly difficult to defend.
For risk managers and executives, these are important signals.
1. AI Accountability Is Becoming Personal
Perhaps the most significant development in August is the shift from organisational AI accountability to named individual accountability.
The UK regulatory discussion provides an important signal. Rather than creating an entirely new accountability regime for AI, the direction emerging from the FCA and PRA is that existing senior-management responsibilities can already encompass AI risk within the areas those executives oversee.
The implication reaches far beyond UK financial services.
An executive responsible for a business function may increasingly be expected to understand and govern the AI being used within that function—even when that executive is not an AI specialist.
This creates a very practical governance question:
Who, by name, is accountable for each material AI use case in your organisation?
If the answer is “IT”, “the AI committee” or “the vendor”, accountability may not yet be sufficiently clear.
Risk managers should consider mapping every material AI application to a named business owner and confirming that the individual understands the accountability they carry.
2. Where Is Your AI Kill Switch?
One of the most practical questions raised in the August articles is also one of the simplest:
Can you stop your AI?
This becomes increasingly important as organisations move from generative AI that provides information towards agentic AI capable of taking action.
An AI agent might access data, use APIs, change configurations, create credentials, communicate with another system or even initiate transactions.
At that point, governance is no longer only about what AI says.
It is about what AI is authorised to do.
Research referenced in the August review indicates that many organisations still cannot demonstrate a tested mechanism for stopping an AI agent.
Executives should therefore ask:
- What authority has this AI been given?
- What systems and information can it access?
- What actions can it take without human approval?
- Who can override it?
- Have we actually tested our ability to stop it?
A kill switch that exists only in a policy is not a control.
It needs to work.
3. Beware of “Agent Washing”
August also gave us an important new term: agent washing.
Richard Chambers describes this as the practice of presenting conventional chatbots, workflow automation or rules-based technology as autonomous AI agents.
This matters because boards and executives may make investment and risk decisions based on capabilities that the technology does not actually possess.
The opposite risk also exists: an organisation may believe it has purchased a relatively simple AI assistant when the technology has considerably more autonomy than decision-makers understand.
For Internal Audit and Risk Management, this creates a new assurance question:
What does the technology actually do—not what does the vendor call it?
For every material AI tool, organisations should understand its autonomy, permissions, escalation requirements and audit trail.
4. Are Boards Looking Back When They Should Be Looking Forward?
Another significant August theme challenges how boards receive risk information.
Much board risk reporting remains dominated by:
- audit findings
- control effectiveness
- compliance status
- incidents
- remediation progress
All of these are important.
But they predominantly tell boards what has already happened.
The emerging argument is that organisations can be highly assured about yesterday while remaining strategically blind to tomorrow.
Risk managers should therefore examine the balance of information presented to boards.
How much of the board risk discussion concerns historical control performance versus uncertainty surrounding future objectives?
This does not mean reducing assurance.
It means strengthening forward-looking risk intelligence.
Risk functions should increasingly help boards answer:
What could change our assumptions about achieving our objectives—and what decisions should we make now?
5. Business Continuity Is Not the Same as Resilience
One of the strongest arguments in the August review is the distinction between business continuity and resilience.
Traditional Business Continuity Management often focuses on restoration:
How quickly can the system return?
How much data can we afford to lose?
How quickly can operations resume?
Those remain important questions.
But resilience asks something different:
Can we continue achieving our critical objectives even if the capability cannot immediately be restored?
That distinction matters.
An organisation may successfully restore a system within its agreed Recovery Time Objective and still fail its customers, strategy or regulatory obligations.
Executives should therefore challenge resilience reporting that relies predominantly on RTOs, RPOs and completed continuity exercises.
The more important question is:
Can the organisation continue pursuing its most important objectives while under sustained disruption?
That requires a different type of testing.
6. The Risk Register Debate Is Moving to the CRO
The debate over risk registers and risk appetite continued through August—but with an interesting evolution.
The question is increasingly becoming less about whether the register itself is useful and more about the value created by the risk function.
Imagine every individual risk owner has correctly identified and assessed their risks.
Could the organisation still misunderstand its overall exposure?
Absolutely.
Risks interact.
Assumptions overlap.
Dependencies remain hidden.
And individually reasonable decisions can collectively produce an unacceptable enterprise outcome.
This is where the CRO should add unique value.
Not by owning the risk register—but by seeing what individual risk owners cannot see from within their own areas.
Executives should therefore ask their CRO:
“What can you see across the organisation that individual risk owners cannot?”
The answer should be much more valuable than a consolidated list.
7. Risk, Resilience, AI and Culture Are Converging
Perhaps the most important structural signal from August is that traditional GRC boundaries are becoming increasingly artificial.
Risk Management manages uncertainty.
Business Continuity manages disruption.
Compliance manages obligations.
Ethics manages behaviour.
AI governance manages technology.
Internal Audit provides independent assurance.
But major organisational decisions rarely respect these boundaries.
Consider an AI-enabled customer process that fails.
It could simultaneously create:
- operational risk
- regulatory exposure
- reputational damage
- ethical concerns
- customer harm
- technology risk
- third-party risk
- resilience issues
Managing these through separate governance silos may actually make the organisation less capable of understanding the full exposure.
This does not necessarily mean organisations should immediately restructure their GRC functions.
It does mean they should identify the critical decisions where organisational silos prevent leaders from seeing the whole picture.
Integration should begin around decisions, not organisational charts.
8. Internal Audit Faces a New Challenge: Finding the “Whole Truth”
Internal Audit also remains under significant pressure.
AI-generated information, enormous data volumes, increasingly complex technology environments and extended supplier ecosystems make it harder to establish what is actually true.
At the same time, Internal Audit is expected to provide assurance over AI governance, resilience, culture, third parties and emerging technologies.
The risk is that assurance becomes broad but shallow.
“Drive-by audits” that cover a topic without generating meaningful insight may satisfy an audit plan but add little value.
Audit Committees should therefore increasingly consider not only:
“Was this area audited?”
but:
“What did we learn that we did not know before?”
What Risk Managers Should Do Now
The August themes suggest several practical priorities.
Map AI accountability. Identify every material AI use case and assign a named accountable executive—not simply a technology owner.
Test the kill switch. Choose at least one production AI use case and demonstrate that the organisation can stop it safely and quickly.
Add agent washing to the risk radar. Verify what AI-labelled technologies actually do, what authority they possess and what evidence they retain.
Rebalance board reporting. Compare backward-looking assurance with forward-looking risk intelligence. Boards need both.
Move from continuity to resilience. Test whether critical objectives can continue when important capabilities remain unavailable.
Demonstrate the CRO’s enterprise view. Show connections, concentrations and cascading exposures that individual risk owners cannot see.
Integrate around decisions. Identify where separation between risk, compliance, resilience, ethics and AI governance is producing fragmented decision-making.
What Executives and Boards Should Be Asking
The questions arising from August are remarkably practical:
- Which AI risks am I personally accountable for?
- Which decisions can our AI systems make without human approval?
- Can we demonstrate that our AI kill switch actually works?
- Are we receiving enough forward-looking risk intelligence?
- Are we resilient—or simply capable of restoring systems?
- What risks emerge when individually acceptable exposures interact?
- Are governance silos preventing us from seeing the complete picture?
- Is Internal Audit giving us deeper insight or simply broader coverage?
Final Thought
Perhaps the most important message from August is that governance can no longer live primarily on paper.
An AI policy does not govern an AI agent.
A continuity plan does not create resilience.
A risk register does not guarantee better decisions.
An audit report does not automatically provide insight.
Governance becomes real when accountability is clear, controls can be demonstrated, people know when to intervene, and leaders have the information they need to make sound decisions under uncertainty.
For risk managers and executives, the next phase of GRC may therefore be less about creating another framework—and much more about proving that the governance we already have actually works.
August’s challenge is simple: move from governance by intention to governance by evidence.
This article is based on BarnOwl GRCs review and synthesis of 39 Governance, Risk and Compliance articles included in its August 2026 GRC article review, with the themes distilled for risk managers, executives and boards.
April–May: reset → June: trust and behaviour → July: decision intelligence → August: operational accountability and evidence.
iGRECS strive to empower sustainable impact through good governance by connecting expertise, build capacity and fostering inclusive, transparent and integrated GRECS and related practices.