ai governance
Board Oversight of AI: What Directors Actually Need to Ask
Most boards either ignore AI risk entirely or ask questions so generic that management can answer them without saying anything. Here's the middle ground that actually works.
Board-level AI oversight tends to fail in one of two directions. Either AI barely comes up — treated as a technical implementation detail beneath the board's remit — or it comes up in a form so generic ("how are we thinking about AI risk?") that management can answer comfortably without the answer actually meaning anything. Neither produces oversight that changes what the company does.
Why this is a board-level question at all
AI governance failures increasingly show up as the kind of risk boards are already accountable for: regulatory exposure, discrimination liability, reputational damage, and — for public companies — disclosure obligations around material risk. A board that would never accept "we don't really track our credit risk exposure in detail" as an answer shouldn't accept the AI-risk equivalent either, once AI is making or materially influencing consequential decisions.
The questions that actually surface something
Generic questions get generic answers. These get more specific ones:
- "Show me the current systems inventory and how many are classified as high-risk or consequential-decision systems." If management can't produce this promptly, that's the finding — not the AI systems themselves, but the absence of the inventory that should already exist.
- "Who has the authority to stop a deployment, and has that authority ever actually been exercised?" A governance program that has never once said no is either extremely lucky or not actually reviewing anything with real scrutiny.
- "What's our exposure in the jurisdictions where we have enacted AI-specific law?" — forcing a specific answer tied to Colorado, the EU, or wherever the company actually operates, rather than an abstract discussion of "AI regulation" broadly.
- "When did we last update our risk assessment for [a specific consequential system], and what changed?" A single point-in-time assessment that's never revisited is a compliance artifact, not an active risk management practice.
What good board reporting on AI actually looks like
The reporting that holds up isn't a narrative slide about "our AI strategy" — it's the same kind of structured, recurring report the board already expects for other enterprise risk categories: current systems inventory by risk tier, status of pending reviews, any incidents or near-misses since the last report, and regulatory developments in the jurisdictions where the company has real exposure. If AI risk reporting doesn't look structurally similar to how the board already receives other risk reporting, it's a sign the function hasn't been integrated into existing risk governance yet.
Who should own the board relationship
This usually lands with whichever committee already owns enterprise risk oversight — audit or risk committee in most structures — rather than requiring a dedicated AI committee, at least until AI risk reaches a scale that justifies a standalone body. The mistake we see most often is routing AI oversight through a technology or innovation committee instead, which tends to frame the conversation around opportunity rather than risk, and misses the compliance and legal dimensions entirely.
Connecting this to the operating structure
Board oversight is the top of a structure that has to actually function below it — see our governance committee guidance for the operating layer the board should expect to exist beneath its own oversight, and our full governance framework checklist for how the pieces fit together end to end.