Elemental AI
Elemental AI
Artificial Intelligence. Real Decisions.

Bringing Clarity and Accountability to AI Oversight

Strategic advisory for boards and leadership teams making critical decisions regarding AI strategy, risk, and oversight. Fayeron translates complexity into action โ€” without the jargon.

Subscribe to the Briefing Take the Self Assessment
Fayeron Morrison
Fayeron Morrison, CPA, CFE
Founder & President, Elemental AI
Stanford GSB AI Leadership Program
Co-Chair, PDA AI Governance SIG
What We Do

Where Fayeron Can Help

01
Board & Leadership Education

Your technical team speaks in models and algorithms. Your board speaks in risk and accountability. Fayeron translates between them โ€” so you can ask the right questions, identify the blind spots, and make decisions that actually stick. No jargon, no fluff, just clarity on what matters.

02
Governance & Accountability

Most companies are flying blind on AI governance. Who's accountable when a chatbot makes promises you can't keep? What controls exist today โ€” not planned for Q3? Fayeron helps you build oversight structures that work in practice, not just look good on paper.

03
Risk, Readiness & Responsible Use

97% of organizations have no access controls on their AI tools. That's not a future problem โ€” that's today's problem. Fayeron helps identify what risks you're actually carrying, where your gaps are, and what responsible AI adoption looks like when you're not a tech giant with unlimited resources.

Featured in The Corporate Board

“Noses In, Fingers Out” Meets AI

The old board rule fails when AI makes light-speed corporate decisions.

September / October 2026

Fayeron Morrison examines what informed board oversight requires when AI agents can access data, make decisions, and act before a human sees what happened.

Led by Fayeron Morrison

Fayeron Morrison, CPA, CFE

Stanford GSB AI Leadership Program   |   Co-Chair, Private Directors Association AI Governance SIG   |   Founder & President, Elemental AI

Thought Leadership

Elemental AI Insights

Weekly analysis on AI governance, accountability, cybersecurity, and board oversight.

Elemental AI: The Briefing cuts through the hype to help leadership teams understand what actually matters.

Read the Substack Listen to the Podcast
Featured Insights
๐Ÿ›๏ธ
AI Governance
Why Boards Are Flying Blind on AI Risk
๐Ÿ›ก๏ธ
Cybersecurity
When AI Becomes Infrastructure
โš–๏ธ
Accountability
The Five Questions Every Board Should Ask About AI
๐Ÿ“Š
Governance Maturity
Most Companies Are Less AI-Ready Than They Think
Governance Navigator

Does Your Board Know Where You Actually Stand?

The Elemental AI Governance Navigator is a structured diagnostic โ€” grounded in the WEF AI Governance Alliance framework โ€” that reveals your organization's true AI governance maturity across seven domains on an objective 0โ€“5 scale.

Most organizations overestimate their readiness by one to two levels. The Navigator surfaces that gap before it becomes a board-level failure.

Take the Self-Assessment
๐Ÿ›๏ธ
Governance & Oversight
๐ŸŽฏ
Strategy & Use Case Fit
๐Ÿ›ก๏ธ
Risk, Ethics & Compliance
๐Ÿง 
Decision Intelligence
๐Ÿ‘ฅ
Leadership & Talent
๐Ÿ”„
Culture & Change
๐Ÿ—„๏ธ
Data & Infrastructure Readiness
Get In Touch

Let's Talk About Your AI Governance

Whether you're just starting to think about AI oversight or navigating specific challenges, Fayeron can help you get clear on what matters and what to do next.

Email
Fayeron.ElementalAI@gmail.com
LinkedIn
linkedin.com/in/fayeronmorrison
X / Twitter
@ElementalAIHQ
Substack
Elemental AI: The Briefing
Fayeron Morrison
About

Fayeron Morrison

Helping boards and executive teams govern AI with clarity, accountability, and real-world business rigor.


CPA
Certified Public
Accountant
CFE
Certified Fraud
Examiner
Stanford GSB
AI Leadership
Program
Co-Chair
PDA AI Governance
Special Interest Group

AI governance is a leadership issue โ€” and a boardroom responsibility.


Fayeron Morrison founded Elemental AI to help boards and leadership teams navigate AI oversight with the same rigor applied to financial controls, cybersecurity, and enterprise risk.

She is a graduate of the Stanford Graduate School of Business Executive Program in AI Leadership and the creator of the Elemental AI Governance Navigator โ€” a diagnostic tool designed to bring clarity and accountability to AI oversight at the board and executive level.

From frameworks to real-world implementation, she equips directors and executives with the clarity, tools, and confidence to govern AI in a way that protects value and earns trust.

AI Governance

Designing practical governance frameworks that strengthen oversight, manage risk, and drive responsible innovation.

Financial & Forensic Lens

Bringing a CPA + CFE perspective to accountability, controls, and operational risk in AI systems and business processes.

Boardroom Translation

Turning AI complexity into clear, actionable insights for directors and executives โ€” so better decisions get made.

โ€œ

AI governance is not what the board discussed.
It is what the board can prove.

Fayeron Morrison
Affiliations & Credentials

Professional Background

๐Ÿ›๏ธ

Coopers & Lybrand / PwC

11 Years in Public Accounting

Audit, advisory, fraud, and complex technical accounting experience across diverse industries and business environments.

๐ŸŽ“

Stanford Graduate School of Business

AI Leadership & Governance

Stanford Executive Program graduate and creator of the Elemental AI Governance Navigator โ€” a diagnostic tool for AI oversight at the board and executive level.

๐Ÿ‘ฅ

Private Directors Association

National AI Governance Leadership

Co-Chair of the PDA AI Governance Special Interest Group and contributor to the PDA National AI Task Force developing AI Oversight Governance: The Private Director's Body of Knowledge (2026).

Published & Featured

The Corporate Board, September/October 2026 issue cover
The Corporate Board  ·  September/October 2026

“Noses In, Fingers Out” Meets AI

The old board rule fails when AI makes light-speed corporate decisions.

Fayeron Morrison examines how board oversight must evolve when AI agents can access data, make decisions, and act before a human sees what happened.

Read the Article →
Speaking & Appearances

Speaking &
Appearances

From boardrooms to executive forums, Fayeron is regularly invited to share insights on AI governance, risk, and responsible innovation with board directors and leadership teams.

Topics Include
  • ๐Ÿ›๏ธ AI Governance & Oversight
  • ๐Ÿ›ก๏ธ Risk & Compliance
  • ๐Ÿง  Decision Intelligence
  • ๐Ÿ”’ Cybersecurity & AI
  • โš™๏ธ Responsible AI Use

Interested in having Fayeron speak to your board or leadership team about AI governance, risk, and oversight?

2026 โ€” Upcoming
NOV
02
Noses In. Fingers Out. Eyes on the Agents.
2โ€“3pm PST  ยท  Board Members and Executive Management
PRESENTER LEARN MORE โ†“
2026 โ€” Past
JUL
14
Put Data First Conference
Lido House, Newport Beach  ยท  8amโ€“5pm PST  ยท  Conference Audience
MODERATOR LEARN MORE โ†“
JUN
03
Cybersecurity Leaders Panel: Securing the AI Frontier
Planet Cyber Sec AI AppSec, Santa Monica  ยท  8amโ€“5pm PST  ยท  Conference Audience
PANELIST LEARN MORE โ†“
JUN
01
What a $99 AI-Powered Bear Teaches Executives About Control Layers in AI
2โ€“3pm PST  ยท  Board Members
PRESENTER LEARN MORE โ†“
MAY
18
Choosing the Right AI Model: ChatGPT, Claude, Gemini, and Perplexity Compared
2โ€“3pm PST  ยท  40 board directors and governance leaders
PRESENTER LEARN MORE โ†“
MAR
26
AI Governance in the Age of Digital Disruption
UCLA Anderson  ยท  3โ€“6pm PST  ยท  100+ board directors
MODERATOR LEARN MORE โ†“
MAR
02
The Joonko AI Washing Crisis: What Boards and Executives Missed
2โ€“3pm PST  ยท  32 board directors and governance leaders
PRESENTER LEARN MORE โ†“
JAN
19
AI Voice Technology in Practice: Risks, Opportunities, and Governance Considerations
2โ€“3pm PST  ยท  Executive Roundtable
PRESENTER LEARN MORE โ†“
2025
OCT
06
Deepfakes in the Age of AI: What Executives and Boards Need to Know
2โ€“3pm PST  ยท  Executive Roundtable
PRESENTER LEARN MORE โ†“
Services

What We Do


AI governance advisory for boards and executive teams navigating oversight, accountability, risk, and operational readiness.

โš–๏ธBoard Advisory ๐ŸงญGovernance Navigator ๐ŸŽ™๏ธSpeaking & Education ๐Ÿ”Risk & Compliance
01

Board Advisory & AI Governance


Helping boards move from AI uncertainty to accountable oversight.

Most boards are now being asked to oversee AI strategies they were never equipped to evaluate.

Elemental AI helps boards and audit committees build the literacy, frameworks, and oversight structures they need to govern AI with confidence.

Capabilities Include
  • โš–๏ธ Board education sessions on AI risk and opportunity
  • ๐Ÿ“‹ AI governance policy development and review
  • ๐Ÿ—‚๏ธ Oversight structure design and accountability mapping
  • ๐Ÿ“„ Vendor contract and AI tool accountability review
  • ๐Ÿ“Š Board reporting frameworks
02

AI Governance Navigator Assessment


A structured diagnostic that reveals your true AI governance maturity.

The Navigator is a maturity assessment across seven governance domains on a 0โ€“5 scale โ€” grounded in the WEF AI Governance Alliance framework.

Unlike self-assessment tools, it scores based on observable behaviors because leaders consistently overestimate their own readiness.

Capabilities Include
  • ๐Ÿงญ Seven-domain maturity assessment
  • ๐Ÿ“ˆ Gap analysis and prioritized recommendations
  • ๐Ÿ—บ๏ธ Action roadmap for governance improvement
  • ๐Ÿ“‹ Executive summary for board and leadership review
03

Executive Education & Speaking


Practical education for non-technical leaders who make decisions that matter.

Keynotes, workshops, and executive education designed to cut through complexity and help leaders govern AI with clarity.

Capabilities Include
  • ๐ŸŽ™๏ธ Board and C-suite AI governance workshops
  • ๐Ÿ† Conference keynotes and panel appearances
  • ๐Ÿ“š Custom executive education programs
  • ๐ŸŽ“ AI literacy for directors and leadership teams
04

AI Risk & Compliance Review


A forensic, accountability-first approach to AI risk evaluation and compliance.

With CPA and CFE credentials and deep experience in technical accounting, Fayeron evaluates AI risk, vendor accountability, and regulatory exposure.

Capabilities Include
  • ๐Ÿ” Shadow AI inventory and risk assessment
  • ๐Ÿ“„ AI vendor accountability and contract review
  • โš–๏ธ Regulatory compliance gap analysis
  • ๐Ÿšจ AI washing and misrepresentation risk assessment
"

AI oversight is no longer optional.
It is a board responsibility.
Let's lead it with clarity and confidence.

Insights

Elemental AI: The Briefing

Weekly analysis of AI governance failures, frameworks, and what boards need to know โ€” published every Monday on Substack.

Elemental AI: The Briefing

Every Monday, a new issue lands in subscribers' inboxes โ€” real AI governance case studies, Navigator framework applications, and the analysis boards actually need. No hype. No jargon. Just clarity.

Read on Substack โ†’
Recent Coverage

What We've Been Writing About

Data & Infrastructure Readiness
The PocketOS Incident: When AI Agents Delete Production Databases
Risk, Ethics & Compliance
Nippon Life v. OpenAI: The Unauthorized Practice of Law Problem
Governance & Oversight
Joonko: What AI Washing Fraud Actually Looks Like

Topics We Cover

Shadow AI Board Literacy AI Risk Vendor Accountability Regulatory Compliance AI Washing Governance Frameworks Case Studies Navigator Framework

๐ŸŽ™๏ธ The Elemental AI Podcast

Weekly companion episodes to the Briefing, co-hosted with AI voice Chris via ElevenLabs. New episodes every Wednesday.

Listen Now โ†’
Never Miss an Issue

Subscribe on Substack for Monday delivery directly to your inbox.

Subscribe Free โ†’
The Corporate Board  ·  September/October 2026

“Noses In, Fingers Out” Meets AI

The old board rule fails when AI makes light-speed corporate decisions.

The universal rule of governance oversight has long been that boards monitored operations and controls, knew who was in charge of what, but would then leave managers to do their jobs. What happens, though, when autonomous AI agents increasingly take action on their own for the company? Or, when employees tap “shadow” AI tools independently to perform tasks? New federal policy now means that you—and your board—can face felony charges for AI misuse.

There is a phrase that has governed boardrooms for decades. You have heard it in director training programs, read it in governance textbooks (and probably nodded along to it in your first board orientation). “Noses in, fingers out.”

The idea is elegant in its simplicity. Boards stay informed, keeping their noses in the business, but resist the temptation to meddle in management decisions, keeping their fingers firmly out of day-to-day operations. It was designed to protect the boundary between governance and management. It gives CEOs operational latitude and prevents boards from micromanaging executives.

For most of the twentieth century, it worked well. It does not work anymore, though, and artificial intelligence is the reason why.

“Noses in, fingers out” worked for boards when the most consequential actors inside a company were human—visible, accountable, and replaceable. AI agents break that assumption. They do not just generate text for review. They act, accessing data, triggering workflows, making decisions, and operating at a speed no quarterly oversight can match. When something goes wrong, the governance question is immediate: Who authorized this, what was the agent allowed to do, and where is the evidence?

On June 2, 2026, that question moved into the federal enforcement spotlight. Executive Order 14409 directed attention to existing criminal laws when AI is used to unlawfully access systems or data. If your board is discussing AI but cannot produce an agent inventory, scoped access rights, audit trails, vendor controls, and a shadow AI discovery process, it is not governing AI.

In June 2026, Eric Brandwine, a vice president and distinguished engineer at Amazon Security, argued that human-in-the-loop oversight can fail when repeated exposure causes people to stop responding meaningfully. It is a striking observation from a senior executive at one of the world’s largest technology companies, and it reflects the operational reality underlying the governance argument below.

“Noses in, fingers out” was designed for a world where consequential decisions were made by human beings, executives who could be hired, evaluated, and if necessary, fired. A board could reasonably monitor a CEO’s judgment by reviewing quarterly financials, strategy sessions, and management presentations. The information flow was curated and comprehensible.

Artificial intelligence breaks every one of those assumptions. Today, the most consequential decisions inside many organizations are not made by executives at all. They are made by algorithms—credit models, hiring filters, pricing engines, fraud-detection systems, and increasingly, autonomous AI agents authorized to take actions without human review.

These systems operate continuously, at scale, and at speeds no human overseer can match. They make thousands of decisions per hour that individually look trivial, but collectively define the company’s risk profile, regulatory exposure, and ethical posture. A board that reviews quarterly reports cannot govern this reality. A board that relies on management to characterize AI risk is experiencing, in the words of one governance analyst, a simulation of reality, not reality itself. The curated boardroom presentation and the actual behavior of a deployed AI system are two very different things, and the gap between them is where governance failures live.

“Noses in, fingers out” worked for boards when the most consequential actors inside a company were human—visible, accountable, and replaceable. AI agents break that assumption.

For years, the argument for updating board governance doctrine was philosophical, but now it is legal. On June 2, 2026, President Trump signed Executive Order 14409, titled “Promoting Advanced Artificial Intelligence Innovation and Security.” Coverage primarily focused on the headline—a voluntary framework for AI developers to give the federal government early access to “frontier” models. Buried in Section 4, though, is something more immediately consequential for every board overseeing a company that deploys AI agents.

For the first time, a presidential directive named AI agents as distinct legal actors in a data-access liability framework. This pointed the full force of existing federal criminal statutes directly at AI agent-enabled actions. There is no need to wait for Congress or for a notice-and-comment rulemaking process before the government can enforce existing statutes. The liability clock is already running.

Section 4 directs the Attorney General to prioritize enforcement of three existing federal criminal statutes—identity fraud, unauthorized computer access under the Computer Fraud and Abuse Act, and wire fraud. These apply to anyone who uses AI agents to unlawfully access data for criminal purposes.

Routing through existing statutes rather than creating new law means prosecutions can begin immediately. The EO resolves prior ambiguity by treating an AI agent operating outside its authorized scope as the functional equivalent of an unauthorized human actor—with all the liability that implies.

Until now, a company whose AI agent exceeded its authorized data access faced civil exposure: a lawsuit or regulatory inquiry. After June 2, the same conduct sits in the DOJ’s priority enforcement queue. The prospect of criminal enforcement changes the risk calculation considerably.

The SEC has made its priorities equally clear. Its Fiscal Year 2026 Examination Priorities explicitly direct examiners to assess whether firms have adequate policies to monitor and supervise AI technologies and to review whether AI representations are accurate. Passive, noses-in oversight produces no paper trail and fails that test.

For boards with EU exposure, important requirements governing certain high-risk AI systems are now scheduled to apply beginning in December 2027, with other requirements following different implementation dates. Boards that wait until 2027 to act will find themselves in the same position U.S. boards are today—behind, exposed, and scrambling.

Until now, a company whose AI agent exceeded its authorized access faced civil exposure. Now, the same conduct sits in the DOJ’s priority criminal enforcement queue.

Before unpacking the governance implications, it helps to be precise. An AI “agent” is not an AI chatbot that answers questions. It is an AI system that takes autonomous actions on behalf of a user or organization. Such actions can include browsing the web, executing code, sending emails, querying databases, making API calls, and initiating transactions. The agent does not just generate a response. It does things.

In March 2026, cybersecurity researcher Jeremiah Fowler discovered three completely unprotected databases belonging to Sears Home Services with no passwords, no encryption. Inside were 3.7 million customer chat transcripts, 1.4 million audio recordings, and nearly four terabytes of data collected by Sears’ AI voice agents. The exposed material included names, home addresses, telephone numbers, appliance details, and repair schedules. Some recordings ran up to four hours, capturing background conversations and sounds customers never knew were being recorded.

No hacker or sophisticated attack was involved. The agents had been collecting and storing customer data continuously, at scale, with zero governance controls around what they retained or how it was protected. The systems appear to have collected and stored data as designed, but the surrounding security and governance controls were plainly inadequate.

That is the deployer liability story in its purest form. No attacker, no rogue employee, just an organization that built and deployed AI agents without asking what they were collecting, where it went, or who was watching.

The Sears exposure is a civil and regulatory liability story. Section 4 of the June Executive Order is what happens when that same governance failure moves into criminal territory. In November 2025, Anthropic reported that a threat actor it assessed with high confidence to be a Chinese state-sponsored group had manipulated Claude Code into attempting intrusions against roughly 30 global targets. Security researchers noted that 80 to 90 percent of the attack tactics were carried out by the AI agents themselves, with minimal human involvement.

Diagram: Who answers for AI? A ring of accountability — board, CEO, CISO, legal, vendor, data owner — around a central AI agent, with the question ‘Who authorized the agent?’
Noses in. Fingers out. Eyes on the agents.

This was not a case of a human hacker using AI as a tool. The agents were the primary actors. This is exactly the scenario Section 4 was written to address, and why AI agent-enabled criminal access is now a federal enforcement priority.

When an AI system generates text, a human reads it and decides what to do. When an AI agent acts, the action is already taken. The human may not see it until later (if at all). The decision/action cycle that governance frameworks were built around has collapsed into a single automated step, and the accountability question that used to have a clear human answer is now much murkier.

That murkiness is precisely what Section 4 is designed to resolve. The answer regulators are arriving at, on both sides of the Atlantic, is the same—the organization that deployed the agent is accountable. Proving accountability now requires documentation that most companies do not currently have.

AI agent liability spans three layers: developer, deployer, and user. Most boards sit in the deployer layer, and that is where the most underappreciated exposure lives. Legally, deployers face liability for agent behaviors that harm others even when the underlying model performed exactly as documented. Your configuration choices (permissions, scope definitions, oversight mechanisms) are your liability. The four items below represent the minimum documentation that prudent deployers should be prepared to produce.

When an AI agent acts, the action is already taken. A human may not see it until later (if at all). The decision/action cycle that governance frameworks were built around has collapsed.

The liability standard the new Executive Order creates is not vague. To demonstrate that an AI agent operated within approved boundaries—and to strengthen the company’s position if its practices are questioned—a company should be able to produce four things:

Then there is the “shadow AI” problem. Verizon reported that 45 percent of employees in its dataset regularly used AI tools on corporate devices and that approximately two-thirds accessed those tools through noncorporate accounts. According to a 2026 Verizon report, this shadow AI has become the third most common non-malicious data loss trigger, a fourfold increase year over year.

Such activity may involve no malicious intent and may occur without triggering an immediate breach notification. Just proprietary source code and internal documents quietly moving into systems your board never reviewed and your legal team has never approved.

Shadow AI nevertheless creates a serious governance problem. An employee may connect an unapproved third-party agent to company systems without understanding what information the agent can retrieve, retain, or transmit. Even when the employee’s purpose is benign, the resulting access can violate company policies, contractual obligations, privacy requirements, or data-security controls. If the information is later used unlawfully, the company may also face difficult questions about authorization, monitoring, and accountability.

The governance implication is direct: Passive oversight cannot govern what it cannot see. A quarterly security report may not reveal that an unapproved AI agent has been accessing customer data. Boards therefore need reliable agent-discovery and inventory capabilities. “Noses in, fingers out” was never designed to provide that visibility.

The Harvard Law School Corporate Governance Blog observed that the most urgent AI governance failure is not ignorance—it is inaction. Most boards are discussing AI, but very few have formal oversight mechanisms with teeth.

This is not a criticism of individual directors, but a structural problem. The “noses in, fingers out” model was never designed to produce the verifiable, documented governance evidence that regulators now expect. Board discussions generate minutes. Minutes are not audit trails of AI risk oversight. Regulators now will want evidence: model cards, explainability documentation, incident logs, proof that the board reviewed and challenged outputs.

“We have an AI policy” is not a defense. “Here is our documented board-level review of the model’s performance against its risk thresholds last quarter” is.

None of this is an argument for boards to start running operations. The legitimate concern behind “fingers out”—that board micromanagement undermines executive authority—remains valid. Instead, the answer is to redefine what informed oversight requires in an AI-enabled structure.

“We have an AI policy” is not a defense. “Here is our documented board-level review of the model’s performance against its risk thresholds last quarter” is.

In practice, boards now need documented answers to five AI questions before the next examination cycle:

This governance gap also raises fiduciary concerns. Directors are expected to make informed decisions and, under Delaware oversight doctrine, to make good-faith efforts to establish and monitor systems for reporting material risks. As AI agents assume more consequential responsibilities, boards should consider whether existing reporting systems provide meaningful visibility into those risks.

When an AI agent takes a consequential action—moving money, denying a claim, or accessing sensitive data—and something goes wrong, one of the first questions will be who authorized it. The answer should trace to a human being with documented authority who made a deliberate governance decision to deploy the agent with that scope and permit it to take that category of action.

If you are not sure where your company stands, you should find out. Start with the self-assessment at our company website.

The old doctrine “noses in, fingers out” gave boards a simple rule for a simpler world. It assumed the most consequential actors inside your organization were human, visible, accountable, and replaceable. That world is gone. The agents are acting now, continuously, at scale, in your name.

The new doctrine is simple too: “Noses in, Fingers out, Eyes on the Agents.”

The board that cannot see what its agents are doing cannot govern what they do next. The agent accountability era has a governance infrastructure requirement.

Fayeron Morrison, CPA, CFE, is founder and president of Elemental AI, based in California. linkedin.com/in/fayeronmorrison

Originally published in The Corporate Board, September/October 2026 (Vol. XLVII, No. 280), pages 5–9. © 2026 The Corporate Board.

Contact

Start the Conversation

Whether you're a board member, C-suite executive, or advisory firm looking to build AI governance capacity โ€” let's talk.

Let's Work Together

Elemental AI works with private company boards, executive teams, and leadership groups who are serious about governing AI responsibly. If that's you, she'd like to hear from you.

Connect
Email
Fayeron.ElementalAI@gmail.com
LinkedIn
linkedin.com/in/fayeronmorrison
X / Twitter
@ElementalAIHQ
Substack
Elemental AI: The Briefing

Send a Message