In this episode, KB sits down with Mark Thomas, IT governance and risk veteran, ISACA Hall of Famer and president of Escoute Consulting, to pull apart a problem a lot of boards haven’t clocked yet – the gap between owning an AI policy and being able to prove it controls anything. They get into the Air Canada chatbot case and what it says about accountability, why the honest board test is “would anyone notice if this was violated,” and how the risk changes once agents move from recommending to executing. Mark makes the case that human in the loop only counts when the human has the expertise, the authority and the time to say no. He also explains why only a small fraction of organisations have ever tested their ability to shut a system down, and why accountability never transfers to the vendor. A practical, occasionally uncomfortable conversation for anyone putting AI into production. —— About Mark: Mark Thomas is a globally recognised expert in governance, risk management, and digital trust, with more than two decades of experience advising organisations operating in complex, regulated, and rapidly evolving environments. His work sits at a critical intersection where strategy, governance, and execution meet. He works directly with boards and executive leadership to: Strengthen oversight and accountability Improve confidence in decision-making Navigate emerging technologies and digital risk Align governance with real-world execution Mark is known for his ability to translate complex issues into clear, practical insight, helping leaders move from uncertainty to informed, defensible decisions. Keywords: AI governance, AI risk, board accountability, agentic AI, human in the loop, kill switch, digital trust, AI policy, ISACA, Mark Thomas, Escoute Consulting, KBKast, enterprise AI, AI compliance, EU AI Act, shadow AI, Air Canada chatbot