Technology is moving faster than the structures designed to govern it. That is not a prediction. It is already the documented reality inside large organisations worldwide. And according to Kailash Sadangi, senior finance and governance professional with over three decades of experience across the GCC, Asia-Pacific, Europe, and Australia, it is the most consequential and least honestly addressed challenge in corporate governance today.
The Numbers Confirm the Gap is Real
The evidence is unambiguous. A 2025 IBM Cost of Data Breach Report found that 63% of organisations lack AI governance policies to manage AI or prevent the proliferation of unsanctioned AI tools (IBM Cost of Data Breach Report 2025). Shadow AI, the unauthorised use of AI by employees, was a contributing factor in 20% of all data breaches, adding an average of $670,000 to breach costs per incident. The average global cost of a data breach in 2024 was $4.88 million, with US figures surging to $9.36 million (IBM/Hinckley Allen, 2024). These are not technology failures. They are governance failures dressed in technical clothing.
The boardroom data reinforces this. As of 2025, only 40% of companies had assigned AI oversight to at least one board-level committee, despite AI being the number one area directors say they need to spend more time on (EY / Harvard Law School Forum on Corporate Governance, 2025). Only 15% of boards currently receive AI-related risk metrics from management (NACD, Directors and Boards, 2026). Meanwhile, just 13% of S&P 500 companies had a dedicated technology committee in 2024, despite technology now constituting the substrate of virtually every business decision (OECD Corporate Governance Factbook 2025). And in PwC’s 2025 Annual Corporate Directors Survey, 55% of directors believed at least one board colleague should be replaced, the highest proportion ever recorded, citing skills gaps and oversight inadequacies as primary concerns (Diligent, Corporate Governance Trends 2026).
Why Accountability Structures Were Not Built for This
Sadangi’s 2025 academic paper, ‘From Boardroom to Blockchain: Reconfiguring Agency, Accountability, and Governance in a Digitally Mediated Economy’, published in December 2025, examines this structural problem with rigour (Medium, Dec 2025). Drawing on agency theory, transaction cost economics, and platform governance scholarship, Sadangi argues that traditional corporate governance was designed to address one central problem: the separation of ownership and control under conditions of imperfect information. Boards, audits, and disclosure regimes were built to constrain managerial opportunism and align human incentives. They were not built to govern algorithms, automated systems, smart contracts, or AI models operating at machine speed.
The result is what Sadangi identifies as an accountability relocation problem. When Distributed Ledger Technology executes rules automatically, when AI makes decisions faster than any committee can review, and when platform infrastructure determines outcomes through code rather than human judgment, accountability does not disappear. It moves. It shifts the burden to protocol designers, core developers, and dominant technology holders who were never subject to the fiduciary obligations, audit requirements, or regulatory scrutiny that traditional corporate governance imposes on directors and executives. As Sadangi writes, the critical governance question is not whether ‘companies without managers’ will emerge, but how boards and regulators will design and supervise digital infrastructures so that efficiency gains do not come at the cost of accountability, fairness, or resilience.
The Structural Consequences Are Already Materialising
The consequences of this structural lag are not hypothetical. Generative AI has increased organisational attack surfaces by an estimated 67%, with cybersecurity breach costs projected to rise from $9.22 trillion in 2024 to $13.82 trillion by 2028 (Diligent, Corporate Governance Trends 2026). Data breach class action settlements in the US exceeded $550 million in 2024 as scrutiny of automated decision-making without sufficient human oversight intensified (Hinckley Allen, 2024). And yet only 23% of boards currently make even moderate use of AI-powered dashboards for risk oversight, despite the quarterly meeting model being fundamentally ill-suited to the pace at which technology risk now moves (Diligent, 2026).
Sadangi observes that the problem is compounded by a deeper organisational dynamic: governance functions were historically rewarded for reliability and caution, while technology functions were rewarded for speed and innovation. These two incentive structures have never been formally reconciled within most large organisations. The result is a permanent tension where technology outpaces oversight, not because oversight is absent, but because the two operate on entirely different timescales, with different risk tolerances, different reporting languages, and different definitions of success.
What Needs to Change
Sadangi’s framework points toward a reconstitution rather than a replacement of governance. The most viable future, he argues, is a hybrid: algorithmic enforcement and immutable audit trails for routine controls, combined with human-led boards and regulators providing judgment, ethical accountability, and adaptive oversight where complexity and trade-offs persist. Code can execute rules. It cannot determine whether the right rules were designed in the first place.
In practice, this means boards must develop genuine technology fluency rather than delegating it entirely to management. It means audit committees must evolve from retrospective verifiers into prospective system governors. It means incentive structures across the organisation must explicitly reward governance velocity, not just technical velocity. And it means the CFO, as the executive who sits at the intersection of risk, reporting, capital, and institutional accountability, is increasingly the person who must hold this tension together.
Kailash Sadangi’s work on this subject is not an academic abstraction. It is a practitioner’s diagnosis of a structural problem that is already costing organisations billions, eroding board credibility, and quietly redistributing accountability to actors who were never designed to hold it. The organisations that address this gap deliberately, with governance architecture that genuinely keeps pace with the systems it is meant to oversee, will be the ones that make technology a durable competitive advantage rather than an expanding liability.
****
About Kailash Sadangi
Kailash Sadangi is a senior finance and governance professional with over three decades of international experience across the GCC, Asia-Pacific, Europe, and Australia. He served as Group CFO at Al-Othman Holding, Saudi Arabia, and holds a MBA degree and DBA researcher from Warwick Business School. His academic work on corporate governance, agency theory, and distributed ledger technology is available via Medium. Professional profile: The Org | ZoomInfo
Sources
IBM Cost of Data Breach Report 2025 — AI governance gap, shadow AI, breach costs
Hinckley Allen — 2024 Year in Review: Cybersecurity, AI, and Privacy Developments
NACD / Directors and Boards — Navigating AI Adoption and Cybersecurity Oversight (2026)
OECD Corporate Governance Factbook 2025 — Technology committee prevalence, board composition
Diligent — Corporate Governance Trends 2026: AI, Cyber, ESG
PwC — 2025 Annual Corporate Directors Survey (55% directors board replacement)
IBM / Cybersecurity Dive — Shadow AI and data breach statistics 2025
Harvard Law School — Cybersecurity and AI: An Increasingly Critical Interdependency (2024)
Kailash Sadangi — From Boardroom to Blockchain (Medium, Dec 2025)
Kailash Sadangi — The Org (Group CFO, Al-Othman Holding)
