How Should Boards Govern AI?
Boards should govern AI like capital: assign a clear owner, keep a written inventory of systems, define success before spending, and review risk, results, and incidents quarterly. The board doesn't need to become an AI lab. It needs to know who owns the bet.
I've sat on both sides of the boardroom table — as the CEO reporting in and as the director asking questions. Here's what I've learned: AI governance rarely fails because directors are stupid or technologically illiterate. It fails because nobody owns anything.
AI gets forty-five minutes on the agenda. Everybody says intelligent things. Somebody mentions disruption. Somebody else mentions risk. Then everyone leaves without a name, a number, or a decision.
That's not governance. That's a book club.
Who should own AI oversight on the board?
Someone should own AI oversight by name — the full board, the audit committee, or a technology committee. The structure matters far less than the assignment: when AI belongs to everybody on the board, it belongs to nobody, and it becomes the agenda item that slides to next quarter every quarter.
The same rule applies inside the company. Every material AI use case needs a named executive owner. Not an "AI council." Not a cross-functional tiger team. A human being with a name. When the model gets something badly wrong — a customer affected, proprietary data exposed, a promised return that never materializes — the board should already know whose phone rings.
A company can outsource technology. It cannot outsource accountability.
What should management be required to show the board?
Management should maintain a written inventory of every material AI system in production or development: what it does, what data it touches, whether it affects customers or employees, who owns it, which vendor is involved, and what success is supposed to look like. Most boards have never seen this document because most companies have never written it.
The first inventory usually produces the same reaction: "We're using that where?" Good. That is the point of the exercise.
Then require pre-committed metrics. Before an AI initiative gets funded, management writes down what success means, how it will be measured, when it will be measured, and what result would cause the company to stop. Without pre-commitment, every update becomes storytelling. With it, the update becomes scorekeeping.
I spent a meaningful part of my career around assessment and measurement, and the pattern is painfully consistent: define the number before the experiment and people manage toward reality. Define it afterward and people manage the narrative.
What questions should directors actually ask?
Skip "what's our AI strategy?" — you'll get a deck. Ask questions with inspectable answers: Which decisions have we automated, and how does a customer challenge one? What data feeds these systems, and do we have the right to use it that way? Which vendor claims did we independently validate? What happens when an AI-generated answer is wrong, and who gets notified? Which AI initiative did we kill in the last twelve months?
That last question tells you a lot. A company running serious experiments should occasionally discover that something doesn't work. If every pilot is a success, you don't have extraordinary innovation. You have generous grading.
Boards should also ask about the human consequence, not just the technology risk. AI can improve margins. It can also change how people get hired, evaluated, priced, served, or denied. Govern both.
How often should AI be on the board agenda?
Quarterly, with numbers — not annually with a futurist keynote. The packet should be short: what changed in the inventory, how funded initiatives are performing against their original commitments, what incidents occurred, what management stopped, and what requires a board-level decision.
If there is no decision for the board to make, that's fine. Call it reporting. But know the difference. Governance starts when somebody has to choose, somebody has to own the choice, and somebody has to live with the result.
If you want to pressure-test where your board stands today, run the Board AI Governance Checklist — twelve questions, ten minutes. For the operating discipline underneath all of this, read What Is Decision Intelligence?.
Frequently Asked Questions
Does AI governance require a technical director on the board?
Technical expertise helps. It is not a substitute for governance. A board with explicit ownership, good questions, and pre-committed metrics will outperform a board with one AI expert and no operating discipline.
Is quarterly too frequent for a board topic?
Not if the reporting is short: inventory changes, performance, incidents, decisions. If management needs forty slides every quarter, you have a different problem.
Where should a board start if it has nothing in place?
Build the inventory. You cannot govern something you haven't bothered to list.
Dave Saben is an executive advisor to CEOs, boards, and private equity firms. He is CEO of Via TRM, a vertical SaaS platform serving 200+ higher-education institutions, founder of Educated Guess Ventures, and the author of three books, including CLOSER: The Professional Sales Doctrine. He has spent 15+ years building AI products, beginning with IP Street in 2011.
Related Concepts
Subscribe to Insights
Get the latest essays on AI, leadership, and operational scale.