There is a fair chance that somewhere in your organisation, right now, someone is using an AI tool on company data without anyone having decided whether that is acceptable.
I have seen versions of this pattern repeatedly – from Big Four clients to the company I later ran. AI adoption did not arrive through a strategy. It arrived through the side door: a productivity tool here, a vendor feature switched on by default there, a pilot that became production because it worked.
Boards tend to respond to this in one of two ways. Either they treat AI as a technology topic and delegate it to IT, or they treat it as a strategic imperative and demand an "AI strategy" without asking what that would actually change. Both responses miss the point.
AI is a governance question before it is a technology question
Strip away the vocabulary, and the board's questions about AI are the same questions it should be asking about any material capability:
Where are we using it, and who decided? What are we relying on it for, and what happens if it is wrong? Who is accountable when it causes harm – to a customer, an employee, or the company's reputation? What data are we feeding it, and did we have the right to?
None of these require the board to understand transformer architectures. All of them require the board to insist that someone in management can answer them.
In my experience the honest answer to the first question – where are we using it – is usually "we don't fully know". That is fine as a starting point. It is not fine as a permanent state.
What I have seen go wrong
A few patterns recur.
Ownership falls into the gap. AI touches data, security, legal, HR, product and operations. When everyone is involved, no one is accountable. The board should ask for one name.
The risk is assessed as if the tool were the risk. The tool is rarely the problem. The problem is the decision the tool is being allowed to make, or influence, without a human who understands its limits. A model that drafts a marketing email and a model that screens job applicants are not the same risk, even if they come from the same vendor.
Compliance arrives last. GDPR, the EU AI Act, sector regulation, contractual obligations to customers: these get discovered after the pilot has gone live. Retrofitting governance is expensive and demoralising. Building it in from the start is neither.
The board hears only the upside. Management presentations on AI tend towards enthusiasm. That is natural. The board's role is to be the room where someone asks "and what would this look like if it went badly?"
Do and don't
Do ask management for an inventory: where AI is in use, what it does, who owns it, what data it touches. Expect it to be incomplete. Ask again in six months.
Do name one executive accountable for AI governance across the company – with a mandate that crosses IT, legal and the business.
Do classify use cases by consequence, not by technology. Anything that affects people's rights, money, health or employment deserves a different level of scrutiny than an internal writing assistant.
Do put AI on the board agenda as a standing item under risk and strategy, not as a one-off "AI briefing".
Do ask about the exit. What happens if the vendor changes terms, raises prices tenfold, or disappears? Lock-in is a business risk, not an IT detail.
Don't ban tools by reflex. A blanket ban does not stop use; it drives it underground where you cannot see it.
Don't approve an "AI strategy" that does not name what the company will not do. Boundaries are the part of a strategy that shows someone has thought about it.
Don't accept "the model is a black box" as a reason not to answer questions about accountability. The model may be opaque. The decision to use it is not.
Don't outsource the judgement. External advisors, including me, can help structure the questions. Only the board can decide what level of risk the company is prepared to accept.
A reminder
The board does not need to become technical. It needs to do what it already does with every other material matter: establish who is accountable, understand the consequences of failure, and decide what the organisation is willing to risk.
AI is new. Good governance is not.
---
Maj Britt Arberg is the founder of House of Moon. She has worked at the intersection of cyber, risk and governance in Big Four advisory and as a CEO, holds board education from DTU and has served on boards and advisory boards. She advises leadership teams on the governance of emerging technology.