AI governance for boards: four questions, one page
Directors don't need a technical briefing. They need to know someone owns this and the answer is written down. Here's the structure, for whoever has to say so.
This page is general information for operators, current as of the date shown. It is not legal advice, and reading it does not create an attorney-client relationship. Specific facts change the answer.
The four questions
A board is doing its job on AI when it can answer four questions without calling a special meeting. Who owns AI risk? That answer should be a person's name, not the name of a committee. What is deployed? That's an inventory covering AI in the product and AI your own staff use to run the company. What have we promised? Those are the material AI commitments already sitting in customer contracts, vendor terms, and public marketing claims. And what happens when it fails? That's the escalation path, from the first incident report through to the notice that reaches the board.
This is oversight, not novelty
The duties here are the ordinary ones directors already carry: informed oversight, good faith, reasonable inquiry, applied to a subject that happens to be new. Nobody expects a director to master model architectures, and no court has asked one to. What gets criticized afterward is having no reporting system at all, so that nobody in the room could have known. Treat AI the way you treat any other enterprise risk with a standing agenda slot: somebody owns it, it's inventoried, and it gets reported on a schedule.
Shadow AI is a governance fact
Employees adopt AI tools faster than any policy can follow. In one large survey, a majority said they were using tools they believed were prohibited, and unsanctioned AI now shows up as a measurable factor in breach costs. Translated for the boardroom: "do we have an AI policy?" is the wrong question, because the answer is almost always yes and it tells the board nothing. "Does the inventory match what people are actually doing, and who checks?" is the question worth the meeting time.
The quarterly page
One page, four sections, each quarter:
- 1.Inventory changes: AI added to or removed from the product and from internal operations.
- 2.Commitments: the material AI terms signed this quarter, in customer addenda and vendor agreements, plus any claims made publicly.
- 3.Map movements: regulatory changes that reach this company, not the industry in general.
- 4.Incidents and near-misses, and whether the escalation path was actually used.
Signed by the named owner. Filed with the minutes.
Against over-building
Most companies at this stage do not need an AI ethics board, a framework subscription, or a thirty-page policy nobody finishes reading. They need a policy people will actually read, an inventory that's true on the day you look at it, and an owner the board can put a question to. Build those three first, then add ceremony later, when scale genuinely calls for it.
If the board asks the four questions and gets four answers, you're governing. If any answer comes back as "we should look into that," you've just found this quarter's work, and a board meeting is a much better place to find it than a deposition.