INSIGHTS
Different in Kind: AI, Accountability and the Board
Silvan Schriber · October 2026
A model-prepared recommendation and a board decision may read identically. They are different in kind, not in quality, and only one of them carries accountability. That is the governance lesson in Pope Leo XIV's recent statements on artificial intelligence.
A distinction of kind
In a recent post in Latin, the Pope wrote that human art and what a machine generates statistically from countless images made by others "differ ontologically, even before they differ aesthetically". Algorithms, he added, lack the human spark.

The statement concerns art, but its logic travels. It places the difference between human and machine output in what something is, not in how good it looks. As model output becomes indistinguishable from human analysis, that is the only test a board can still apply.
The Pope has been explicit about the stakes. In an encyclical issued in May, he described AI as not morally neutral. On 29.09.2026 he told reporters that the concerns of AI specialists "should be taken seriously", while adding that he was not in "panic mode" (Financial Times, 29.09.2026). Neither alarm nor dismissal: that is the posture of a functioning audit and risk committee.
Classify by kind, not by quality
Most AI oversight still asks whether the output is good enough. That question loses its value as quality converges. The question that holds is what kind of system produced the output, and what it is allowed to do with it.
The industry is arriving at the same line from the architecture side. Bain's blueprint for an AI-native bank (22.07.2026) treats one design decision as central: where deterministic systems end and probabilistic ones begin. Ledger, payments execution, entitlements and regulatory controls sit on one side. Agentic client interfaces, fraud intelligence and orchestration sit on the other. That boundary is a distinction of kind in the Pope's sense, and it belongs on the board agenda rather than in the architecture review.
The second line runs between preparing, deciding and executing. A model that drafts a credit memo is a different kind of thing from an agent that releases a payment. A&M describes the shift in agentic payments as software moving money autonomously, not merely deciding ("Rewiring Finance for 2026", 13.01.2026). The moment a system crosses from preparing to executing, its governance class changes, whatever its accuracy.

FINMA Guidance 08/2024 already provides the instrument. It expects a central AI inventory, risk classification, clear responsibilities, data quality, testing and monitoring, explainability and independent review. Used well, the inventory is where the distinction of kind becomes visible to the board.
Vendor guardrails are not assurance
The Pope's second point is less philosophical. Asked about new safety tools for AI agents launched by Nvidia, he noted that the same company argues against limits and government regulation (FT, 29.09.2026). Whatever one's view of that debate, the governance principle is familiar to any audit committee. A control designed, operated and attested by the party that sells the system is not independent assurance.
The point is no longer theoretical. The FT reports a series of incidents in 2026 in which AI agents accessed systems beyond their intended scope, including during routine training runs. Tooling to monitor agent behaviour is welcome. It does not replace the institution's own testing, nor the independent review that FINMA Guidance 08/2024 expects.
Concentration is the second exposure. A small number of model and cloud providers now sit beneath much of the industry's AI use. FINMA Circular 2023/1 on operational risks and resilience already covers third-party dependencies, ICT risk and critical functions. For AI, the practical questions are who besides the vendor has tested the control, and whether exit from a model provider has been tested rather than assumed.
For Swiss financial institutions, the regulation debate is settled
In the United States, the argument over whether AI needs new rules or whether market forces suffice remains open. Frontier labs have called for coordination; parts of industry and government reject new regulation (FT, 29.09.2026). For a FINMA-supervised institution, that debate is largely academic. The expectations already exist, and they are anchored in company law before any AI-specific text.
-
Art. 716a OR. The board's core duties are non-transferable. They cannot be delegated to management, and by the same logic not to a system.
-
FINMA Guidance 08/2024. Technology-neutral expectations on governance and risk management of AI, as set out above. FINMA's survey of around 400 institutions (published 24.04.2025) found that about half use AI. FINMA asks institutions to approach it early when AI is used in critical processes or for regulatory parameters.
-
FINMA Circular 2023/1. Operational resilience, third-party and ICT risk, critical functions.
-
EU AI Act, Regulation (EU) 2024/1689, as amended by the Digital Omnibus, Regulation (EU) 2026/1744 (in force since 27.07.2026). Transparency obligations under Art. 50 apply since 02.08.2026. Annex III high-risk obligations, including creditworthiness assessment, apply from 02.12.2027. Art. 14 requires effective human oversight of high-risk systems. Relevant to Swiss groups with EU entities or EU clients.
None of these texts asks whether a model's output is good. All of them ask who is responsible for it.
Where the human stays
The Pope closes with a commitment to "safeguard what is human". Industry targets point the other way, at least on the surface. Bain's AI-native bank aims for 80–90% autonomous process execution and a tenfold productivity gain. These are aspirations, not observed results.
The two positions are less opposed than they look. The evidence so far suggests that value comes from redesigning work around people, not from removing them:
-
BCG works with a 10-20-70 rule: 10% of the effort in algorithms, 20% in technology and data, 70% in people and processes.
-
McKinsey's State of AI 2026 (n=1,719, self-reported) finds that only around 6% of companies attribute 5% or more of EBIT to AI. These high performers are about three times as likely to have fundamentally redesigned workflows.
-
Bain's AI in Financial Services summit (04.06.2026) describes weeks to build and a year of organisational wiring. Domain experts become the verification bottleneck in regulated work. Firms that involve risk teams early move fastest.
If 80–90% of execution becomes autonomous, the remaining 10–20% is not residual. It is where judgement, verification and accountability sit, and it is the scarcest capacity in the institution. The board's task is to decide explicitly which decisions stay human, and why.
There is also a commercial argument. McKinsey estimates that AI could reduce net banking costs by around 15–20%, but that competition will pass much of this to customers (Global Banking Annual Review, 23.10.2025). Efficiency gains that every institution can buy will not differentiate. Trust and accountability, which cannot be bought from a vendor, may.
Five questions for the board
-
Does our AI inventory classify each use by kind (preparing, deciding, executing), and does the audit and risk committee review it at least annually?
-
For each critical process, which decisions remain with a named person, and is that written into mandates, policies and minutes?
-
Which controls on our AI systems have been tested by someone other than the vendor?
-
How concentrated are we on individual model and cloud providers, and has exit been tested under FINMA Circular 2023/1?
-
Is verification capacity, the domain experts who check model output, budgeted and staffed as a control, or simply assumed?
None of this argues against using AI. It argues for precision about where the machine's contribution ends and the board's ownership begins, and for keeping that line visible.
The output may look the same. The responsibility never is.
Sources
-
Pope Leo XIV, post on X (Latin), October 2026
-
Financial Times, "Pope Leo criticises Nvidia's Jensen Huang over AI safety", 29.09.2026
-
Bain & Company, "What It Takes to Build the AI-Native Modern Bank", 22.07.2026
-
Bain & Company, "What Financial Services Leaders Are Wrestling with on AI and Organizational Transformation", 04.06.2026
-
Alvarez & Marsal, "Rewiring Finance for 2026", 13.01.2026
-
McKinsey & Company, Global Banking Annual Review 2025, 23.10.2025; The State of AI in 2026, 25.08.2026
-
BCG, 10-20-70 framework, as stated publicly by the firm
-
FINMA, Guidance 08/2024 on governance and risk management when using AI; AI survey media release, 24.04.2025; Circular 2023/1 Operational risks and resilience – banks
-
Swiss Code of Obligations, Art. 716a
-
Regulation (EU) 2024/1689 (AI Act); Regulation (EU) 2026/1744 (Digital Omnibus on AI)