Board Regulatory Disclosure: The CEO Credibility Test

PwC's 27th Global CEO Survey finds 64% of CEOs agree the regulatory environment is the number one barrier to reinvention. EY's Responsible AI Pulse (August 2025) finds only 14% of CEOs strongly agree their organization has appropriate AI controls in place. The quarterly board asks what our AI Act, NIS2, and DORA exposure is. "I believe we are compliant" is no longer an acceptable answer.

In brief: PwC 2026, KPMG 2025 (n=1,350), and EY's Responsible AI Pulse (August 2025) converge: regulatory exposure is top-of-mind, and only 14% of CEOs strongly agree their organization has appropriate AI controls in place. The board knows it. A CEO who brings a factual snapshot of governed terminology, approvals, and coverage reopens the credibility the surveys say is eroding. We provide the artifact, not the board deck.

The question the board asks every quarter

Every quarter, the audit or risk committee asks a version of the same question: what is our AI Act, NIS2, and DORA exposure, and how do you know? The quarterly regulatory update is no longer a footnote on the agenda. It sits near the top, alongside financial performance and strategic risk.

Three data points below are the strongest external reads on how boards frame that question in 2025 and 2026.

The PwC 2026 Global CEO Survey reports that nine out of ten executives cite at least one of cyber threats, macroeconomic uncertainty, geopolitical uncertainty, or regulatory complexity as a moderate or serious risk. The PwC 27th Global CEO Survey from the prior year recorded that 64% of CEOs agree the regulatory environment is the number one barrier to reinvention. The twelve-month trend has not softened it.

"Sixty-nine percent say the pace of regulation — its ability to keep up with the technology itself — will be a barrier to success." KPMG 2025 CEO Outlook, n=1,350

EY's Responsible AI Pulse (August 2025) reports that only 14% of CEOs strongly agree their organization has appropriate AI controls in place — against 29% of other C-suite. EY frames it as CEOs being "consistently the least likely to claim their organizations have strong controls in place around AI." Controls are not the same as regulatory compliance, but the gap is what the board hears.

What this costs the CEO personally

The board meeting is the moment the regulatory posture becomes a credibility statement rather than a policy document. In 2025 and 2026, regulatory literacy is explicitly among the competencies boards are evaluating in the CEO. A CEO who says "I believe we are compliant" to the audit committee — without a factual, timestamped snapshot — is speaking from exactly the position the EY survey flags: the least-confident seat at the C-suite table, self-reporting the weakest controls.

Audit committees short of evidence expand internal audit scope, commission external advisors, and schedule more frequent interim briefings. A single quarter of "we are working on it" on AI Act, NIS2, or DORA turns the next four board agendas into follow-up sessions on controls evidence.

The quarterly calendar behind the question

The board's question sits against a dated calendar. Prohibitions under the EU AI Act have applied since 2 February 2025 and GPAI obligations since 2 August 2025. Article 50 transparency remains a 2 August 2026 checkpoint; under the 7 May 2026 AI Omnibus political agreement, high-risk planning moves to 2 December 2027 for stand-alone systems and 2 August 2028 for product-embedded systems, pending final legal text (European Commission AI Act page; Council political agreement). NIS2 enforcement depends on national transposition, with management-body oversight duty under Article 20(1) and a management-function-ban request power under Article 32(5)(b) for essential entities. DORA is in force for in-scope financial entities. "What is our AI Act exposure" is not rhetorical — it is a prompt for the CEO to produce evidence.

How terminology governance helps

We narrow to one control: the definitional record behind policies, disclosures, and technical documentation. We do not write the board deck, generate the AI Act conformity assessment, or replace counsel. We produce an artifact the CEO can cite when the board asks what governance looks like underneath the assurance.

  • Four-eyes approval. Every regulatory term requires a separate reviewer and approver, recorded by Atlassian account ID — a dual-control record the CEO can point to when the audit committee asks who signed off on the definition of a high-risk AI system.
  • Version history. Every change to a regulatory or financial term is retained with the prior version, supporting director inspection of definitional drift across quarters.
  • Audit trail with timestamps. Who, what, when, and why is recorded before each change — the four-eyes approval record supports the NIS2 Article 20(1) management-body approval obligation.
  • Compliance scanner. Reports where deprecated or unapproved terms appear across Confluence spaces, producing a coverage metric for the board rather than a narrative.
  • CSV export with full version history (PDF audit-package export on the 2026 roadmap). Board materials can include a CSV snapshot of the approved glossary dated to the meeting.

For current pricing, see the Atlassian Marketplace.

Frequently asked questions

What are the named surveys behind the CEO regulatory credibility problem?

Three surveys converge. PwC's 2026 Global CEO Survey finds nine in ten executives cite cyber threats, macroeconomic uncertainty, geopolitical uncertainty, or regulatory complexity as moderate or serious risks. KPMG's 2025 CEO Outlook (n=1,350) finds 69% of CEOs say the pace of regulation will be a barrier to success. EY's Responsible AI Pulse (August 2025) finds only 14% of CEOs strongly agree their organization has appropriate AI controls in place, against 29% of other C-suite. (Controls are not the same as regulatory compliance — but the gap is what the board hears.)

Why does the EY 14% figure matter for the boardroom?

The EY Responsible AI Pulse (August 2025) reports CEOs are consistently the least likely among C-suite to strongly agree their organization has appropriate AI controls in place. That self-assessed control gap is what the board will probe. A CEO who tells the audit committee "I believe we are compliant" without a factual snapshot of governed terminology, approvals, and coverage is speaking from the position the EY data flags as weakest.

Is a terminology glossary sufficient evidence of AI Act, NIS2, or DORA compliance?

No. Compliance Glossary is not a legal shield and not a full compliance program. It is one documented governance artifact: time-stamped, four-eyes approved definitions of regulatory terms that the CEO can cite to the board alongside other evidence. It provides the artifact, not the board deck, the legal opinion, or the conformity assessment.

What should a CEO hand the board at the next quarterly update?

Exhibits rather than assurances. A coverage report of governed regulatory terms, the approval chain with named reviewers and approvers, a timestamped audit trail, and a CSV snapshot (with full version history) dated to the meeting. PDF audit-package export is on the 2026 roadmap. Pair that with a written status on Article 50/GPAI AI Act readiness, the 2027/2028 high-risk Omnibus plan, NIS2 transposition, and DORA third-party risk posture.

Install before the next quarterly board meeting

For current pricing, see the Atlassian Marketplace.

Evaluate in Confluence Read the Security Whitepaper

Related reading