Boards in the age of AI
Directors who treat AI as a line item will be out-governed by those who treat it as a strategy question. Three disciplines separate them.
Most boards still discuss AI the way they discussed cloud in 2012: a capex conversation, handed to IT, reviewed quarterly. That framing is already costing them.
Where the pressure is coming from
Regulators are moving faster than usual. Customers are asking pointed questions about training data and auditability. Employees — especially in the middle — are using tools the company has not sanctioned and in many cases has not mapped.
The directors we work with who are getting this right share three habits.
1. They name an accountable owner at the executive level
Not a committee. A single executive with budget, P&L exposure, and the authority to pause deployments.
2. They revisit risk appetite annually, not just policy
The temptation is to write a policy, bolt it onto existing risk documents, and move on. The boards who are ahead treat model risk, data provenance, and third-party AI exposure as first-class risk categories with their own appetite statements.
3. They invest in literacy, not demos
Directors who can ask a useful second question in a briefing outperform directors who have seen the prettiest demo. That literacy has to be built; it does not arrive from vendor decks.
What to do in the next 90 days
Commission an inventory of AI use across the business — sanctioned, unsanctioned, and vendor-embedded. Most boards are surprised by the size of the last category. Once you know the surface area, the strategy discussion becomes concrete.