
BICG 2026: AI risk through the board's eyes
Slides, sources and tools from the talk on 09/09/2026. Not a study.
On the morning of 09/09/2026 I spoke at the BICG members' breakfast in Vilnius. The room was board members and executives, and the talk covered three things: what already applies under the AI Act, which AI risks are already inside the company, and what a board can do this month. This page is for the people who were in the room and want the slides, the sources and the printed handout in one place.
The law gave you fifteen months. The risks did not. The board's work starts now.
- Date
- 09/09/2026
- Venue
- BICG members' breakfast, Vilnius
- Length
- 30 min plus 15 min of questions
- Slides
- 27, in Lithuanian
- What was checked
- Every number on a slide has a row in the sources table below. Last checked 08/09/2026.
Slides
Download the slides (PDF, 2.3 MB), slides in Lithuanian
Three things a board can do this month
- A one-page list of which AI tools the company already uses, including the ones employees picked up themselves. The policy comes after that.
- Two sentences on confirming money transfers through a second channel. No exceptions for urgency.
- One name against AI, in writing, and one line in the terms of reference of the audit or risk committee.
The deadline moved. The risks did not.
Ten questions for management
The same text that was on the printed handout. One line under each question on what a good answer sounds like.
- Do we have a list of every AI tool the company uses, including the ones employees picked up themselves?
A good answer shows a table rather than telling a story. A bad answer starts with the words “broadly speaking”. - Who exactly, by name, answers for AI risk, the way someone answers for financial risk?
A good answer names one person and one committee, and it is written into the committee's terms of reference. - What is our AI risk appetite, and did the board actually set it, or did it simply happen?
A good answer points at the minutes of a meeting. If the appetite is written down nowhere, it does not exist. - Where does AI take part in a decision that touches a customer or an employee, and who is the responsible human there?
A good answer names a person who can stop the system and who will face nothing for doing it. - Could we trace one specific AI decision back to a human decision?
A good answer: yes, and here is the log. If we cannot trace it, the system should not be running. - What have we said publicly about our use of AI to customers, investors or the market, and can we back up every one of those words?
A good answer: the marketing text and the real product match. The gap between them is already punished in the US. - Which data is forbidden in AI tools, and how do we know that rule is kept?
A good answer rests on measurement rather than on policy: logs, blocking, checks. - What rights do our AI agents have in production systems, and who approves a destructive action?
A good answer: the default right is read only, writing needs a human approval. - How do we verify that a request to move money really comes from the person we can see and hear?
A good answer: there is a second, independent channel, and it is mandatory above a set amount. - Does the board itself understand AI well enough to ask the second question after the first one, and when are we fixing that?
A good answer has a date. A bad answer is “we trust management”.
A minimal AI policy, one page
- Scope. Who it applies to (every employee and contractor) and what counts as an AI tool in this policy.
- Allowed tools. A short list by name. Anything not on the list is agreed before it is used.
- Forbidden data. Personal data of customers and employees, financial records, credentials, unreleased commercial information. A simple test: if you would not email it to a stranger, do not paste it into a chatbot.
- Human review. Any AI output going to a customer, into finance, into legal or into a people decision is reviewed by a named person. AI does not sign off its own work.
- Disclosure. Where AI substantially shapes a product, a decision or a conversation, that is said in plain words.
- Logs. Write down which tool was used for what, and keep it somewhere findable.
- Incidents. One channel and one name for the report “AI got it wrong, leaked something or made a bad decision”.
- Owner. One person or role accountable for the content of this policy and for it being followed.
- Review. At least once a year. That is the floor, not the goal.
Who is accountable for AI
- A mid-size Lithuanian company does not need a separate chief AI officer role. It needs a written decision on which of the existing executives owns AI: usually the IT lead, the risk lead or the lawyer.
- Oversight is attached to the audit or risk committee and written into its terms of reference. If the board has a technology committee, that one takes architecture, vendor dependency and opportunity, and the audit committee takes control and assurance.
- The work is cross-functional (legal, IT, people, compliance), but the accountability is single and has a name. “Everyone is accountable” means nobody is.
Tools for the board
This list is for a board that wants to review and monitor the risks from the talk, and it leans towards what a 50 to 500 person Lithuanian or Baltic company can actually put in place.
Where to start
- AI Act implementation timeline. One page that settles the argument about dates: transparency and enforcement since 02/08/2026, Annex III high-risk AI systems from 02/12/2027. Free. Fits any company.
- VDAI FAQ “where to start”. The Lithuanian-language questionnaire behind the one-page inventory: who provides the system, what data it touches, whether personal data is involved. Free. Fits any Lithuanian company.
- The NCSC second-channel rule and the FBI IC3 code-word advice. The two sentences of the payment rule are already written; the company only has to adopt them. Free. Fits the finance team.
- The admin report you already pay for: the Google Workspace third-party app report or Microsoft Defender for Cloud Apps shadow IT discovery. Turns “we think we have about ten tools” into a list. Free (with an existing licence). Fits a company already on one of those suites.
- Nudge Security free shadow AI inventory. A read-only connection to the mail system, five minutes, an inventory on day one including accounts created years ago. Freemium. Fits a 50 to 300 person company with no security team.
- NIST AI RMF and its Playbook. Where the named owner and the committee charter line come from, plus a free Excel to start the risk register. Free. Fits any company.
- The Future of Life Institute EU AI Act compliance checker or the Commission's own checker in the Service Desk. Answers “are we high-risk” in about ten minutes. Free, and explicitly not legal advice. Fits any company.
- The Article 50 guidelines and Content Credentials. The labelling duty and the standard that carries it. Free. Fits marketing and communications.
- AI Incident Database and OECD AIM. Fifteen minutes before a risk committee meeting, filtered to your own sector. Free. Fits the risk committee.
- The Lithuanian escalation path: RRT operator guidance and the AI regulatory sandbox. Who supervises, and the free sandbox an SME can apply to. Free. Fits Lithuanian SMEs.
Deliberately not in this shortlist: the AI governance platforms and ISO/IEC 42001 certification. They are the right answer for a company whose customers demand certification, and an expensive distraction for everyone else this year.
Frameworks and checklists
| Tool | For | Price | Note |
|---|---|---|---|
| EU AI Act Service Desk | any company looking for an official answer | free | The answers are guidance, not a binding legal opinion. |
| AI Act implementation timeline | a board arguing about dates | free | 02/12/2027 is the post-Omnibus date. Older decks and articles still print 02/08/2026. |
| Regulation (EU) 2024/1689 on EUR-Lex | a lawyer or a compliance lead | free | Read the consolidated version: the original 2024 text no longer matches the current dates. |
| Commission guidelines on classifying high-risk AI systems | a company working out its own risk category | free | Still in draft and not binding, but it shows how the Commission intends to read the rules. |
| Commission guidelines on the Article 50 transparency obligations, C(2026) 5054 | marketing, communications and the product team | free | 51 pages of heavy reading. For a board the summary plus the deployer obligations is enough. |
| Code of Practice on transparency of AI-generated content | a company that generates or publishes AI content | free | The code is voluntary. Take the “about 190” figure from this page itself. |
| Enforcement framework of the AI Act | a board asking about fines | free | National penalty regimes sit on top of this. In Lithuania the address is RRT. |
| NIST AI Risk Management Framework 1.0 and the Generative AI Profile | a risk committee that lacks shared vocabulary | free | American, and written for practitioners rather than directors. The board value is the Govern function. |
| NIST AI RMF Playbook | whoever is starting the risk register | free | NIST itself says it is neither a checklist nor a set of steps. It needs trimming before a 50-person company can use it. |
| ISO/IEC 42001:2023, AI management system | a company whose customers already ask about certification | paid | The standard costs CHF 225 and certification costs a great deal more. For most Baltic companies this is a decision for later. |
| OECD AI Policy Observatory | whoever follows policy and incidents | free | Policy-oriented. Useful to a board mostly through the incidents monitor. |
| ICO AI and data protection risk toolkit | a data protection officer | free | The page says the guidance is under review after the UK Data (Use and Access) Act, and it is UK rather than EU GDPR. The structure transfers, the legal references do not. |
| CNIL self-assessment guide for AI systems | a team scoring one AI system against the GDPR | free | The English version is a courtesy translation; the French one prevails. |
| Deloitte, “Governance of AI: A critical imperative for today's boards” | a board comparing itself with others | free | Survey data, self-reported, global rather than European. Good for one slide, not for a claim about Lithuania. |
| NACD AI governance resources | a director looking for a list of questions | freemium | Much of it is member-only and the legal framing is American. Borrow the questions, not the legal framing. |
| IoD New Zealand, “AI in the boardroom: a guide for directors” | a director who wants a short guide | free | New Zealand company law. The transferable part is that a director's duty of care is personal and non-delegable. |
| RRT, information for AI operators | any Lithuanian company | free | No dedicated FAQ or deadline list on that page. General contact: rrt@rrt.lt, +370 800 20030. |
| VDAI FAQ “You want to start using an AI system: where to start?” | a company starting its AI inventory | free | It covers the GDPR, not the AI Act. |
| Lithuanian AI regulatory sandbox | a Lithuanian SME building or deploying AI | free | Places are selected, not open to everyone. A board can ask management whether the company applied. |
| Inovacijų agentūra, AI news and calls | a company looking for funding and national guidelines | free | Publication dates are not shown on the tag page, so cite individual articles rather than the index. |
AI inventory and shadow AI
| Tool | For | Price | Note |
|---|---|---|---|
| Nudge Security | a 50 to 300 person company with no security team | freemium | Pricing is not published and neither is the trial length. It finds only what a provider emailed to a company address, so an account created with a personal mailbox stays invisible. |
| Microsoft Purview, DSPM for AI | a company on Microsoft 365 E5-class licensing | paid | This is the enterprise-stack answer: it assumes Purview licensing, onboarded endpoints and someone to run it. |
| Microsoft Defender for Cloud Apps, shadow IT discovery | a company with Microsoft security licensing | paid | By default it cannot discover apps that are not in its catalogue. |
| Cloudflare, shadow IT and AI discovery | a company with Cloudflare Zero Trust or SASE | paid | No free plan is mentioned for this use case, and it presumes Cloudflare already sits in front of employee traffic. |
| Google Workspace, security report on third-party connected apps | any company on Workspace | free (with an existing licence) | It counts OAuth grants, so it catches a tool that connected to Drive or Gmail and misses one an employee simply pastes text into. |
| NIST AI RMF Playbook ir VDAI FAQ | a company that will not buy anything this quarter | free | A questionnaire only finds what people admit to. Pair it with the admin report the company already pays for. |
AI governance platforms
| Tool | For | Price | Note |
|---|---|---|---|
| Credo AI | large organisations | paid | Pricing is not public; it is sold through a conversation with a sales expert. |
| Holistic AI | large organisations | paid | No pricing is shown. |
| OneTrust AI Governance | a company already using the OneTrust privacy platform | paid | Pricing requires a sales conversation. |
| IBM watsonx.governance | large organisations | paid | There is a free 14-day trial, but no per-unit prices appear on the page. |
| Vanta, ISO 42001 | an SME already doing SOC 2 or ISO 27001 | paid | It aims at certification rather than at governing AI risk in general. Pricing is behind a demo request. |
| Drata, ISO 42001 | a company that already runs an ISO 27001 programme | paid | It cross-maps ISO 42001 controls into an existing ISO 27001 programme. Pricing is also not public. |
| Trustible | regulated enterprises | paid | Pricing is behind a demo request. |
Incident registers
| Tool | For | Price | Note |
|---|---|---|---|
| AI Incident Database | a risk committee before a meeting | free | Incidents are press-sourced, so severity and verification vary. |
| OECD AI Incidents Monitor (AIM) | finding examples from your own sector | free | It counts media reports, not confirmed incidents. Useful for direction of travel, not for a statistic on a slide. |
| AIAAIC repository | looking up an individual case | free | An honest limit: the pages do not state who maintains it, the entry count or the licence. Cite individual cases, not the repository itself. |
| Enforcement framework of the AI Act | a board asking who can fine whom, and how much | free | This is a framework page, not a tracker. There is no official EU register of AI Act enforcement actions yet. |
Deepfakes and payment confirmation
| Tool | For | Price | Note |
|---|---|---|---|
| UK NCSC, “Phishing attacks: defending your organisation” | the finance and admin team | free | Written before the deepfake wave, so it says nothing about voice. The rule survives anyway: a call is not a second channel if the attacker chose it. |
| FBI IC3 public service announcement on impersonation of senior officials | a CFO and a treasurer | free | Written for individuals and officials rather than finance teams. The transferable parts are the code word and calling back on a number you found yourself. |
| NSA, FBI and CISA, “Contextualizing Deepfake Threats to Organizations” | a security or risk lead | free | The CISA page is marked as archived content and the PDF itself refused an automated fetch. Open it by hand before quoting from it. |
| NKSC recommendations library | a Lithuanian company writing its own rules | free | There is no dedicated NKSC deepfake document in that list. These are email security and social engineering recommendations. |
| Reality Defender | banks and contact centres | freemium | The site publishes no accuracy figures at all. Detection is a signal, never the control. The control is the callback. |
| Hive, AI-generated and deepfake content detection | platforms and media companies | paid | The accuracy claim is the vendor's own summary of a study, and text detection is not offered. |
Content labelling and provenance
| Tool | For | Price | Note |
|---|---|---|---|
| C2PA and Content Credentials | marketing and the content team | free | Credentials survive only if every tool in the chain preserves them. A screenshot, a re-upload or a careless CMS strips them. |
| Commission guidelines on Article 50, C(2026) 5054 | whoever decides what gets labelled | free | The retroactivity rule matters for marketing. Confirm it in the PDF before relying on it. |
| Code of Practice on transparency of AI-generated content | a company publishing AI content | free | The voluntary route to showing Article 50 compliance. It has a separate section for deployers. |
| Anthropic, “How Claude's text watermarking works” | anyone using AI-written text | free | This is one provider. Do not generalise it to all AI text. |
| OpenAI, “New AI classifier for indicating AI-written text” | a board being sold an AI-text detector | free | OpenAI itself withdrew the classifier on 20/07/2023 for low accuracy: it identified 26% of AI-written text and labelled 9% of human writing as AI. |
| Liang et al., “GPT detectors are biased against non-native English writers” | a company where English is written by non-native speakers | free | 2023 models and 2023 detectors. The direction of the finding has not been overturned, and no detector vendor has published evidence that it has. |
| Dutch Algorithm Register | anyone who wants to see a public inventory | free | It is a government transparency register, not a template. Its value is as the picture of what a one-page inventory could grow into. |
Agent permissions
| Tool | For | Price | Note |
|---|---|---|---|
| Anthropic, Claude Code security and permission model | a company running coding or agentic tools | free | This documents one product. For a board the point is the shape of the question: what may the agent write to, who approves it, and where is the log. |
| Microsoft 365 Copilot setup and admin controls | a company on Microsoft 365 | paid | The oversharing work is the real project, and it is bigger than the Copilot rollout itself. |
| Google Workspace, Gemini admin controls | any company on Workspace | free (with an existing licence) | The training commitment is about Workspace content. It says nothing about what an employee pastes into a consumer Gemini account in a browser. |
| OpenAI, enterprise privacy and data controls | a company using ChatGPT Business or Enterprise | paid | “By default” and “opt-in” are doing real work in that sentence. The board question is whether anyone opted in, and on consumer accounts the answer is different again. |
| Anthropic, API data retention and training | a company using Claude via the API | free | For paid API customers there is no ad hoc deletion. Check that against your own GDPR commitments. |
| GitHub Copilot organisation policies | a company with in-house development | paid | The public-code-matching filter and the retention settings are not on this page; they live on adjacent ones. |
List checked on 10/09/2026; tools change and links go stale.
Sources by slide
Every number on a slide has a row here. The slide number is a link to the slide itself.
| Slide | Claim | Source | Checked | Confidence |
|---|---|---|---|---|
| 2 What applies now | Regulation (EU) 2026/1744 adopted 08/07/2026, in force from 27/07/2026; the high-risk package from 02/12/2027; embedded AI 02/08/2028; prohibited practices and AI literacy from 02/02/2025; transparency from 02/08/2026 | EUR-Lex, Reglamentas (ES) 2026/1744 (Digital Omnibus) | 05/09/2026 | High |
| 2 What applies now | Definitions of deployer and provider; the Annex III areas | DI aktas, Reglamentas (ES) 2024/1689, 3 str., III priedas | 05/09/2026 | High |
| 3 Fines | 15 million EUR or 3%; 35 million EUR or 7%; 7.5 million EUR or 1%High. The AI literacy duty (Article 4) is not on the list of finable breaches | DI aktas, 99 str. 3-5 d. | 05/09/2026 | High |
| 4 My assessment | The headline “breaches may end in more than fines”Headline. The four lines on the slide are the author's own assessment | Verslo žinios, 03/08/2026 (tik antraštė, straipsnis mokamas) | 23/08/2026 | Headline |
| 5 AI in recruitment | Mobley v. Workday (US), case pending; on 22/06/2026 the court let part of the claims standHigh on the status; say “pending” | Duane Morris apžvalga, 24/06/2026; CourtListener byla 3:23-cv-00770 | 08/09/2026 | High |
| 5 AI in recruitment | Emotion recognition in the workplace prohibited from 02/02/2025 | DI aktas, 5 str. 1 d. f p. | 05/09/2026 | High |
| 6 The accidental provider | A deployer becomes a provider under Article 25(1) | DI aktas, 25 str. 1 d. | 05/09/2026 | High |
| 6 The accidental provider | In an Irish survey 25% of companies did not know whether they were providers or deployersMedium. A single country business survey, quoted only with that named | Arthur Cox apklausa, Airija, per mondaq.com | 29/08/2026 | Medium |
| 7 When to label | The Article 50 labelling duties; the rule for agents | DI aktas, 50 str.; Europos Komisijos gairės C(2026) 5054, 20/07/2026 | 05/09/2026 | High |
| 7 When to label | RRT guidance 19/08/2026: deepfakes and public AI text that no human reviewed are labelled; prevention and advice first | Ryšių reguliavimo tarnyba | 29/08/2026 | High |
| 8 The blind spot | 80% of boards have no process to check their own AI useMedium. A UK members' survey, 2022 | Institute of Directors, „AI in the Boardroom: the essential questions for your next board meeting“, 2023, aut. Pauline Norstrom; IoD narių apklausa 2022 | 05/09/2026 | Medium |
| 9 How AI enters a company | In 2025, 21.3% of Lithuanian companies (10+ employees) used AI, in 2024 it was 8.8%; the EU average is 20%High, checked through the API | Eurostat, duomenų rinkinys isoc_eb_ai | 29/08/2026 | High |
| 9 How AI enters a company | From 02/08/2026 a chatbot has to say what it is | DI aktas, 50 str. 1 d. | 05/09/2026 | High |
| 10 Examples | Screenshots: an AI assistant in an online shop; a search for “ChatGPT” in the App Store; an AI mail assistantIllustration, not a study. The mail window is blacked out in the public version | Autoriaus ekrano nuotraukos, 09/2026 | 08/09/2026 | Illustration |
| 11 Examples | Add-in permissions (Microsoft Entra); one real receipt and three generated by AI; the ChatGPT setting “Improve the model for everyone” | Autoriaus ekrano nuotraukos, 09/2026 | 08/09/2026 | Illustration |
| 12 Shadow AI | 66% used AI tools believing the policy forbade it; 88% of them shared work information (43% emails, 34% customer data, 31% financial documents)High on the source; not Lithuanian data | PagerDuty ir Wakefield Research, 1 250 biuro darbuotojų, JAV, JK, Australija, Japonija, apklausa 09-20/04/2026, paskelbta 11/06/2026 | 05/09/2026 | High |
| 13 Operational risk | On 18/07/2025 a Replit agent deleted a live database holding 1,200+ executive records, then fabricated data | AI Incident Database, incidentas 1152 | 05/09/2026 | High |
| 14 Agents | AI agents switched on for free inside a Hostinger hosting account (OpenClaw, Hermes Agent, n8n) | Autoriaus ekrano nuotraukos, 09/2026 | 08/09/2026 | Illustration |
| 15 On your own computer | Permissions for add-ins, browser agents and appsStatement, not a number | Autoriaus tekstas | Statement | |
| 16 Legal risk | About 26,000 families; more than 2,000 children (CBS 2022: 2,090); the government resigned on 15/01/2021; a self-learning risk algorithm (AP fine of 2.75 million EUR)High. Do not use 3,532: that is the Museum of Failure figure | Wikipedia; CBS (Nyderlandų statistika) 2022; Autoriteit Persoonsgegevens, 2021 | 08/09/2026 | High |
| 17 Cyber security risk | Arup: 25.6 million USD (200 million HKD), 15 transfers, one video call, 01/2024 | CNN, 16/05/2024 | 05/09/2026 | High |
| 17 Cyber security risk | Ferrari 2024: the attack stopped by a question about a recently recommended book | MIT Sloan Management Review | 05/09/2026 | High |
| 17 Cyber security risk | Lithuania, 06/2025: a deepfake campaign imitating Lithuanian TV news | LRT English | 05/09/2026 | High |
| 18 You become a provider | Comms Center and Executive Operating Dashboard, the author's own local appsIllustration, the data is invented | Autoriaus programos, demonstraciniai duomenys | 08/09/2026 | Illustration |
| 19 You become a provider | A team system and a sales CRM with an AI assistant | Autoriaus programos, demonstraciniai duomenys | 08/09/2026 | Illustration |
| 20 Reputational risk | Readers picked the AI-written text as the most human, 04/12/2024The author's own experiment; the number of participants is not on the slide | tv3.lt, 04/12/2024; bernardinai.lt, 06/12/2024 | 23/08/2026 | |
| 21 Reputational risk | Anthropic text watermarks under the Article 50(2) code of practice of the AI Act, from 02/08/2026High on the fact; one vendor's decision only | Forbes, 13/08/2026; The New Stack | 08/09/2026 | High |
| 22 The board's side | 66% (79% a year earlier); 31% (45% a year earlier); 5% | Deloitte, „Governance of AI: a critical imperative for today's boards“, 2 leid., 695 direktorių, 56 šalys, 01-02/2025 | 05/09/2026 | High |
| 23 Who answers for what | 11% → 40% of companies assigned AI oversight to a board committee within a year, most often auditMedium. US disclosure data | Harvard Law School Forum on Corporate Governance, 28/10/2025 | 05/09/2026 | Medium |
| 24 A chief AI officer role | IBM survey: 76% have such a role, across 2,000+ large, mostly US organisationsMedium. Only with the sample named | CIO.com apie IBM apklausą, 2026 | 05/09/2026 | Medium |
| 25 ISO/IEC 42001 | The first certifiable AI management system standardHigh. There is no data on Baltic certificates | ISO; DNV | 05/09/2026 | High |
| 26 Three things | The author's recommendationsRecommendation, not a source | (none) | Recommendation |
What the slides deliberately leave out
- “The AI Act applies in full from 2 August 2026.” Wrong since 27/07/2026.
- “A breach of the AI literacy duty carries a 15 million EUR fine.” Article 4 is not on the Article 99 list.
- “Companies are already being fined under the AI Act.” Not one fine has been published anywhere in the EU (checked 05/09/2026).
- “Lithuania has an AI law.” Draft XVP-1564 is in the Seimas, the autumn session starts on 10/09/2026.
- “3,532 children.” That is the Museum of Failure figure; the official CBS number is 2,090.
- “86% of companies use AI without the board knowing.” Quoted in the IoD document with no source; taken off the slide.
Martynas Kairys, head of Zedge Lithuania, AI practitioner and speaker. He gives talks and workshops in his free time from that job.
New posts by email
When a new post goes up, I send it to you. Nothing else, no offers.
By subscribing you agree to receive new intelektas.ai posts. Unsubscribe in any email. How I handle data: privacy.