The missing cuestion: The Chilean Case

Juan Pablo López, Director of Ciberlegal and contributor at IT Business Solutions DEF

For years, the discussion around digital transformation within companies was dominated by a relatively simple logic: incorporating more technology meant increasing efficiency, competitiveness, and adaptability.

This consensus led many strategic decisions to be made under a silent pressure to move quickly, especially in areas related to artificial intelligence, automation, and predictive analytics.

However, a less visible tension has begun to emerge in boardroom discussions. Projects now arrive accompanied by increasingly sophisticated metrics, projections, and technical recommendations, while conversations about risk remain relegated to a secondary role in the deliberation process. Implementation is presented as a business opportunity, and responsibility enters the conversation only afterward.

This gap matters more than it may seem. The challenge is no longer simply understanding how technology works. The real difficulty lies in determining who on the board is capable of translating that implementation into the language of risk that the company will ultimately have to assume.

In Chile, moreover, the regulatory context is no longer peripheral. The Cybersecurity Framework Law has raised governance requirements for critical infrastructure and incident management. The new personal data regulation has increased the institutional significance of information processing and strengthened corporate responsibility for its protection. In addition, the new economic crimes regime has considerably expanded the exposure of directors and executives to liability arising from supervisory failures.

The combined effect of these regulations is significant because it changes the nature of corporate discussions. Technological adoption can no longer be evaluated solely through expected returns or operational efficiency. It must also be examined through the lens of decision traceability, oversight capacity, and the standard of diligence required of those who cast their votes.

In this context, many companies have responded by strengthening compliance structures, creating specialized committees, or introducing periodic digital risk reports. All of these measures are necessary. The problem arises when the existence of a structure begins to be confused with effective governance.

Corporate experience tells a different story. Several major corporate crises have occurred in organizations that did have protocols, committees, and control systems in place. What was missing was the ability to stop the momentum of approval at the critical moment, record a well-founded objection, or initiate a genuine deliberation before the vote.

This issue is becoming especially sensitive in discussions surrounding artificial intelligence. There is clear pressure to adopt predictive tools, automate processes, and accelerate corporate decision-making. At the same time, boards are operating in an environment where accountability for errors, data breaches, or supervisory failures is becoming increasingly personal.

For that reason, the most important question in a board meeting may no longer be how much value a technology project can generate, but whether the company truly understands the risk it is taking on along with it.

When a crisis occurs, shareholders quickly forget the presentation that convinced the room. What remains is the judgment, or the lack of it, with which the decision was ultimately mad.