Oversight requires reliable information
Section 95 AktG requires the supervisory board to oversee management. This includes report requests, inspection and audit rights, and approval requirements for certain transactions. AI governance therefore needs structured supervisory-board information.
AI-relevant matters may include new high-risk systems, material model changes, outsourcing, data and supplier risks, HR AI or systems with significant customer impact. The supervisory board does not need to perform technical detail checks, but it needs a robust situation picture.
Questions a supervisory board should ask
- Is there a complete AI inventory including vendor AI, GPAI and shadow AI?
- Which AI systems are high-risk or relevant for corporate-body oversight?
- Which policies, approvals, controls and escalation routes apply?
- Which incidents, weaknesses, audit findings or regulatory changes have been reported?
- Which AI projects should be subject to approval or prior information?
Audit committee and internal audit
Where an audit committee exists, it is a natural place for control, reporting and evidence topics, especially where AI systems affect financial reporting, sustainability reporting, risk management, internal controls or auditable evidence.
Internal audit can assess whether the AI governance model actually works: inventory updates, clear roles, control activity, samples, incident processes and evidence quality.
Duties and committees depend on structure, size, listing status and the specific legal position of the company. This page describes a governance framework, not individual legal advice.