Adapted and expanded from an interview originally published by Odgers Berndtson, May 2024.
A lot of directors are carrying the same quiet concern right now: everyone expects me to have a view on artificial intelligence, and I do not fully understand it.
That concern is understandable, but it starts from the wrong premise. Directors do not have to master a technology in order to govern it. Few boards master every technical detail of derivatives, cloud migration, cybersecurity architecture, or global supply chains, yet boards are still accountable for overseeing the risks, choices, and tradeoffs those areas create. Governance is not technical mastery. It is the discipline of asking the right questions, insisting on rigorous answers, and holding management accountable for both. AI does not change that job. It raises the stakes of doing it well.
Given how quickly AI is moving, it is unrealistic for any director to track every advance and immediately know what it means for the business. The pace will beat you if your plan is personal expertise alone. The goal is not to keep up with every model release. The goal is to make sure the governance process is strong enough, and refreshed often enough, to absorb change without the board or management defaulting to panic.
I established and chaired the AI Governance Committee of a board overseeing several billion dollars in assets, and when we created it, we had to answer one foundational question before any other: is AI a standalone concern that requires its own permanent structure, or is it an extension of the enterprise risk management framework we already had? We concluded that AI is a powerful tool, but still a tool, and that governing it should be embedded in enterprise risk management rather than treated as a separate discipline.
A blanket prohibition on AI is usually not caution. It is often an unenforceable policy that management is already working around.
The starting point is uncomfortable for most boards. AI is almost certainly already inside the organization, usually through partners, vendors, suppliers, and software platforms the enterprise relies on every day. That means a blanket prohibition is not the safe, conservative choice it appears to be. It is often an unenforceable one that creates the illusion of control while leaving the actual risk unmanaged.
The defensible move is less exciting and more useful: take inventory. Catalogue where AI is actually in use, internally and through third parties. Assess each application through an enterprise risk lens. Then shape policy to fit what you found rather than what you imagined.
That should also lead to a more serious vendor review process. Boards should understand how key tools are evolving, what data they touch, how models are trained or configured, and whether the contracts require the disclosures, audit rights, security commitments, and oversight the organization needs to manage risk.
When I am asked what worries me that boards may not yet see, I usually point to two things.
The first is operational: bias and privacy. Imagine a hospital using a model to inform admission decisions that later turns out to have a biased effect, or a lender whose credit model creates fair-lending risk. These are not science-fiction scenarios. They are familiar operational and compliance failures now expressed through more advanced tools. Boards should understand them in advance and insist that management build governance frameworks that properly contemplate bias, privacy, explainability, security, and accountability.
The second is human: resistance to change. Complex technology that people do not understand breeds quiet refusal. Top-down mandates tend to fail when the people most affected were never brought into the process. The antidote is continuous education that explains how a system works, why it helps the organization, how it will be governed, and how it is meant to enhance roles rather than simply threaten them. Directors should also remember that the status quo carries risk. An organization that refuses to learn is making a decision too.
Directors worry, reasonably, about regulation that is still uneven and evolving. My practical guidance is simple to state and demanding to practice: do not let AI do anything a human would not be permitted to do. The enterprise risk framework already defines many boundaries of acceptable action, and AI should operate inside those same lines.
Beyond that, the board should ensure management runs appropriate impact assessments and builds transparency into any AI-involved process. That is what keeps experimentation honest without smothering it. There is also an opportunity for thoughtful organizations to engage regulators and industry groups early, share what they are learning, and help shape policy that is workable. It is better to participate in the rulemaking conversation than to spend years reacting to it.
These ideas are easy to agree with and harder to put in place. The work comes down to a few concrete practices:
Define the framework. Name the roles, responsibilities, and accountabilities for AI decisions so that ownership is clear before something goes wrong.
Train regularly. Make education on AI impact, ethics, privacy, security, and business use a standing rhythm, not a one-time seminar. Include the board itself.
Borrow expertise. Bring in people who live in AI governance, ethics, security, and regulatory risk. Ongoing guidance beats a single audit.
Name the downside honestly. Weak governance can invite compliance failures, regulatory scrutiny, operational breakdowns, and reputational harm. The financial cost may be recoverable. The loss of trust may not be.
Be quick, but do not hurry. That old adage holds the posture. Move, because standing still carries its own danger, but move deliberately, with assessment and transparency underneath you, so that speed never becomes recklessness. The boards that look wise in ten years will not be the ones that understood AI first. They will be the ones that governed it well while everyone else was still waiting to feel ready.