AI
Boards Now Own AI Lineage They Cannot Inspect
Bessemer’s AI governance brief tells boards to prove training-data lineage, but most companies run vendor models whose origin they cannot inspect or reconstruct.
Bessemer operating advisor George DeCesare told CEOs in August 2026 that AI governance is now a board duty, not a CISO add-on. The Atlas brief, written with Christine Deakers, asks directors to prove the lineage of training data the way a court proves physical evidence.
That ask lands on companies that mostly do not train the models they ship. The second effect is a split: firms that own logged data can answer a buyer or a regulator, and API wrappers often cannot.
A Kaiser Risk Officer’s Brief for CEOs
DeCesare joined Bessemer Venture Partners as an operating advisor in February 2026 after serving as senior vice president and chief technology risk officer at Kaiser Permanente. Bessemer said he secured $1 billion in board funding there and built a program covering millions of members and 230,000 employees. He holds a JD, sits on the HITRUST board, and has worked on HIPAA and SEC cyber disclosure rules.
On August 19, 2026, Bessemer published his argument that cybersecurity’s old job, stopping unauthorized access, does not cover AI. A model does not store a dataset. It folds statistical patterns into parameters, so poisoned, biased, or unlawfully obtained data can shape later outputs with no file left to seize.
He names healthcare diagnoses, credit approvals, fraud detection, and financial disclosures as live cases, not thought experiments. When those outputs drive decisions, he writes, they become institutional knowledge assets, and a board’s duty of care and duty of loyalty may be in play.
Without a verifiable chain of custody, AI becomes a source of regulatory and legal exposure rather than competitive advantage.
George DeCesare, operating advisor, Bessemer Venture Partners
The firm posted the same brief from its official account the day it went up.
— Bessemer (@BessemerVP) August 19, 2026
DeCesare’s seven-step board action checklist tells directors to name an accountable AI lead, audit provenance on systems already in use, approve acceptable-use rules, push the CISO past perimeter controls, schedule independent traceability audits, pass an ethics framework, and write chain-of-custody terms into vendor contracts. He also lists 10 questions for the CISO, starting with whether the firm can identify the origin of every dataset that trains or influences its AI.
A model policy memo does not answer those questions. Lineage, the human handoff, and a record that survives a later dispute do.
What the EU AI Act Requires for Training Data
For high-risk systems that train on data, Article 10 of the EU AI Act already states the core demand in law. Providers must apply data-governance practices that cover design choices, the origin of data and collection processes, preparation steps such as labelling and cleaning, the assumptions the data are meant to represent, fitness of the sets, and an exam for bias that could harm health, safety, or fundamental rights.
Sets must be relevant and representative, and as error-free and complete as the intended purpose allows. They also have to fit the geographic, contextual, behavioural, or functional setting of use. That is provenance as a product rule, not a values statement.
The calendar around that rule split in 2026. The Digital Omnibus on AI, Regulation (EU) 2026/1744, was published on 24 July 2026 and entered into force on 27 July 2026. It moved the heavy high-risk duties because harmonised standards, notified bodies, and national watchdogs were not ready, not because Article 10 got lighter.
EU AI ACT DATES AFTER THE DIGITAL OMNIBUS
| Obligation | Original date | Date now in force |
|---|---|---|
| Prohibited practices (Article 5) | 2 February 2025 | 2 February 2025 (already applies) |
| AI literacy (Article 4) | 2 February 2025 | 2 February 2025 (already applies) |
| GPAI model duties, including a training-content summary | 2 August 2025 | 2 August 2025 (already applies) |
| Article 50 transparency and disclosure | 2 August 2026 | 2 August 2026 (already applies) |
| Machine-readable marking for older generative systems (Art. 50(2)) | 2 August 2026 | 2 December 2026 |
| High-risk Annex III standalone systems | 2 August 2026 | 2 December 2027 |
| High-risk Annex I product-embedded systems | 2 August 2027 | 2 August 2028 |
Annex III duties moved 16 months. Annex I duties moved 12 months. GPAI providers still owe a public summary of training content, and deployers have had to disclose AI interactions since 2 August 2026. Bessemer posted the fiduciary warning 17 days after that transparency date, and after high-risk system duties had already been pushed to 2 December 2027.
The delay is runway. Classification still has to happen now, because the systems that will be high-risk in 2027 are largely the ones going into service in 2026.
Most Buyers Cannot Prove a Foundation Model’s Data
DeCesare is blunt that most organisations cannot prove their AI data was lawfully acquired, handled cleanly, and left unaltered in ways that changed model behaviour. He also says you cannot audit your way backward through a trained neural network, so chain of custody has to exist before training starts.
That is the right technical point, and it collides with how companies actually buy AI. Vendor-risk questionnaires in 2026 open by asking the supplier to name the foundation model and version, then to describe any fine-tuning. The working premise is that the product is a wrapper around a model from OpenAI, Anthropic, Google, Meta, or Mistral.
A CEO who asks DeCesare’s first CISO question, the origin of every dataset used to train or influence the system, will get a contract clause and a model card, not a custodian log. The buyer never held the pre-training corpus. Hashing an internal RAG store does not reconstruct the weights that already sit behind the API.
Question five, whether the firm can reproduce a production model from original datasets, configuration, and pipeline, fails the same way. Reproduction is a property of a training run you control. It is not a property of a closed model you rent.
So the checklist’s first six steps read as if the company owns the foundry. Step seven, vendor contracts, is where most of the exposure actually lives. Boards that treat the whole list as equally doable will spend a year hashing data they do own and still fail the RFP question that names the upstream model.
Delaware Oversight Duty Does Not Wait for a Statute
DeCesare frames the legal hook as duty of care and duty of loyalty. Patrick Meson, a corporate counsel at a New York investment bank, put a sharper Delaware reading on the same problem on 25 June 2026. He argues that deciding to deploy or build AI is a Caremark event, a governance choice that attaches before the tool is switched on, because accountability for outputs does not move to the vendor with the purchase order.
Meson walks the oversight chain from Caremark (1996) through Stone v. Ritter (2006), which placed the duty in loyalty, not care. Charter clauses under DGCL § 102(b)(7) can wipe personal care liability. They do not cover a loyalty claim that the board made no good-faith effort to watch a mission-critical risk. Marchand (2019) required board-level monitoring when the risk is core to the business. The McDonald’s derivative case in 2023 extended that oversight duty to officers inside their own functions.
THE OVERSIGHT MATH
- Where it attaches: Meson notes that roughly two-thirds of Fortune 500 companies are incorporated in Delaware, so Caremark is the default corporate law for a large share of U.S. boards.
- What good faith looks like: Directors do not have to explain a transformer. They do have to show a reporting system and a record that they used it.
- When AI qualifies: Credit decisioning, AML monitoring, hiring, insurance underwriting, and large-scale handling of protected data are the examples Meson flags as likely mission-critical.
- The practical yardstick: He treats NIST’s voluntary AI risk management framework, released as AI RMF 1.0 on 26 January 2023, as the process standard counterparties and examiners already use even though it is not a statute.
No Delaware court has yet held that a specific AI system was mission-critical in the Marchand sense. The cyber oversight cases of 2025 already treated digital risk as a board subject for companies that live on consumer data. Meson’s point is procedural: if AI bears on a core compliance risk, waiting for an AI statute is not a defence.
U.S. agencies are not waiting either. The SEC created a Cyber and Emerging Technologies Unit in February 2025. Its Division of Examinations posted fiscal 2026 examination priorities on 17 November 2025 that put AI tools, trading algorithms, and the accuracy of AI-related claims on the exam list, along with policies for monitoring those systems.
Vendor Contracts Leave the Liability With the Buyer
Meson cites a 2026 Jones Walker market analysis that found 88% of AI vendors cap their own liability at the monthly subscription fee, while pushing broad indemnities back onto the customer for discrimination, IP, and regulatory claims. A procurement team that signs the paper as ordinary SaaS boilerplate keeps the downside and still cannot inspect the weights.
That is why the RFP has become the working courtroom. Questionnaires now ask whether any live suit is about how training data was acquired, not only about outputs; whether an EU-market model has published its training-data summary; and whether the no-training promise is an API setting the customer can see, not a sentence in a slide deck. Insurers writing tech E&O and cyber cover are pulling the same file. NAIC examiners have already told insurance buyers that “we trust the vendor” is not an exam-ready answer.
DeCesare wants chain-of-custody clauses in every AI vendor deal: provenance documentation, integrity controls, and notice when datasets change. Those clauses are worth drafting. They will not conjure a pre-training corpus the vendor refuses to disclose. The honest board paper says which systems are in-house trained, which are fine-tunes on owned data, and which are API calls whose lineage stops at a name and a version number.
Hash the Dataset Before Anyone Trains
Where a company does train, fine-tune, or retrieve over its own data, DeCesare’s forensic list still maps onto work engineers can do. He borrows chain of custody from evidence law: origin, possession, tamper signs, integrity checks, access logs, and preservation, all built before the run, because the influence disappears into parameters afterward.
He also wants data classed on three extra axes before it enters a pipeline, the SCC triad of sensitivity, criticality, and compliance, sitting beside the older CIA triad of confidentiality, integrity, and availability. Healthcare training sets and a chatbot that drafts internal email do not get the same controls.
DECESARE’S SIX PROVENANCE CONTROLS
| Control | What the record has to show |
|---|---|
| Identifiable origin | Source organisation, acquisition date, collection method, licence, regulatory class |
| Documented possession | Who touched each version, when, and what they did |
| Tamper evidence | Hashes, signatures, or immutable storage that make silent edits visible |
| Integrity verification | Periodic hash checks, pipeline reproducibility tests, version diffs |
| Access control logs | Every human or machine action on training data and model artifacts, with time and identity |
| Preservation | Kept datasets, configs, training logs, and eval results so a later failure can be rebuilt |
Those six controls are feasible on a labelled clinical set, a claims warehouse, or a fine-tune corpus the company ingested under contract. They are theatre on a public foundation model. Boards should require the full set on first-party training and a different, written residual-risk finding on every system whose weights sit off-premises.
Seven Board Asks That Still Work on a Vendor
The useful residue of DeCesare’s list is the part a director can still demand when the model is rented. It is narrower than a forensic lab, and it is the part that will show up in a procurement file or an exam.
BOARD ASKS THAT STILL WORK ON A VENDOR
- Named owner: One executive with authority over provenance standards and a direct board report, not “the CTO, in addition to everything else.”
- System inventory: Which AI systems already touch clinical, credit, fraud, hiring, or disclosure decisions, and which of those are API wrappers.
- Model identity in writing: Foundation model, version, and any fine-tune, plus the model-card URL, as a contract exhibit.
- No-train proof: The technical control that keeps customer prompts out of someone else’s training run, not only a marketing sentence.
- Training-data categories: Licensed, internal, synthetic, or web-collected, with a representation on rights, even if URLs are not on the table.
- Liability and notice: A cap that is not the monthly fee, plus notice when the vendor changes data, model, or subprocessors.
- Reproduce what you own: For every in-house train or fine-tune, keep the six provenance controls so a later output can be rebuilt from logs.
If management cannot name the upstream model, or cannot show how customer data is kept out of training, that is a risk disclosure in DeCesare’s terms, not a documentation lag. Independent audits then have a defined job: trace the data the company actually held, and confirm the vendor file matches the contract, rather than pretending to walk through weights nobody will open.
Companies that already log origin, licence, and hashes on the data they train on will clear the questionnaires that wrappers fail. That is the advantage DeCesare is selling. It accrues to firms that own their pipelines, and to vendors willing to put model identity and data rights in the contract, not to the board that only filed the checklist.
Disclaimer: This article is news reporting and analysis of public AI-governance guidance, EU legal text, and Delaware oversight doctrine. It is informational only and does not constitute legal, regulatory, insurance, or board-advisory advice. Readers should consult qualified corporate counsel, and where relevant a CISO or compliance officer, before changing governance charters, vendor contracts, or model-deployment practices. Figures, case citations, and regulatory dates reflect the named sources as used in this piece and can change with new filings, guidance, or court decisions.
-
AI3 months agoFable 5 Came Back Under a Commerce On-Off Switch
-
AI4 months agoGoogle’s SpaceX GPU Lease Has a Sept. 30 Deadline
-
CRYPTO4 months agoPlasma One’s XPL Locks Face a 1.81 Billion Cliff
-
APPS4 months agoDGO’s Rs 549 World Cup Pass Cost Fans Sleep and Data
-
AI4 months agoMoonshot AI’s $30 Billion Ask Became a $35 Billion Close
-
NEWS4 months agoColorOS 17 Device List Spans Oppo, OnePlus and Realme
-
GAMING4 months agoXbox Cuts 3,200 Jobs After Five Years of Thin Returns
-
GAMING3 months agoThe RTX 4050 Under Rs 70,000 Hides a Wattage Gap
