Insights · Leadership
Five questions every board should ask about AI
You don’t need to understand how AI works to oversee it well. You need to ask the right questions, and know what a good answer sounds like.
Boards don’t need to understand how AI models work. They do need to oversee how their organisation uses them, in the same way they oversee money, people and data.
The difficulty is that AI arrived quietly. Much of it came in as a feature inside software you already pay for, or as a free tool someone started using on a Tuesday. There was often no project, no business case and no paper to the board. So the first job is simply to ask.
These five questions work for a charity trustee board, a family business or a growing company. None of them needs technical knowledge to ask. All of them are hard to answer badly without it showing.
Question 1
Where are we using AI today?
You can’t oversee what you can’t see. Ask for everything, not only the official projects: chatbots on the website, AI features switched on in email and office software, transcription tools in meetings, and the assistants staff use on their own to draft, summarise or analyse.
The point isn’t to catch anyone out. People use these tools because they help. The point is to know.
- A good answer sounds like
- A short list: each use, what it does, who owns it and what data it touches. Including the tools staff chose for themselves.
- A warning sign
- “We don’t really use AI.” Almost every organisation does now, whether or not anyone decided to.
Question 2
What data goes into it, and where does it go?
Every time someone pastes a customer email, a contract or a spreadsheet into an AI tool, that information goes somewhere. With some services it is kept, and with some it may be used to improve the supplier’s models. Business and free versions of the same tool can have very different terms.
If personal data is involved, your usual data protection obligations still apply. The ICO publishes guidance on AI and data protection, and it is worth someone reading it.
- A good answer sounds like
- For each tool: what information goes in, whether the supplier keeps it or trains on it, and where it is stored. Personal and confidential data are called out separately.
- A warning sign
- Nobody has read the terms, or the answer changes depending on who you ask.
Question 3
What can it do without a person?
AI that suggests is one thing. AI that acts is another. As tools become “agents” that can send emails, update records and make payments, the question moves from whether the output is good to what happens when it isn’t.
We have written a longer piece on what an AI agent should never be allowed to do alone.
- A good answer sounds like
- A clear line between what AI prepares and what AI does. Anything that moves money, deletes records, contacts customers or decides about people needs a named person to approve it.
- A warning sign
- Nobody is sure, or the limits exist only as instructions written into the AI itself.
Question 4
Who owns it when it goes wrong, and how would we know?
AI rarely fails loudly. It gives a customer a wrong answer politely. It summarises a document and leaves out the part that mattered. It works well for months, and then a supplier updates the model and it behaves slightly differently.
So ownership needs to include looking. Someone should regularly review real outputs, not just check that the system is switched on.
- A good answer sounds like
- A named owner for each important use, a way for staff and customers to flag problems, and someone who checks a sample of what the AI actually produces.
- A warning sign
- Ownership sits with “IT” in general, and problems would only surface through a complaint or a news story.
Question 5
What aren’t we doing because we’re nervous?
This one surprises people. Oversight isn’t only about stopping things. Uncertainty can hold an organisation back as surely as recklessness can let it down, and a vague fear of AI tends to produce either paralysis or quiet workarounds.
A specific worry is usually solvable. “We can’t let it email customers directly” leads to a sensible rule, not a ban. Good safeguards are what let you say yes.
- A good answer sounds like
- A short, honest list of uses the team has held back on, with the specific worry behind each one, and what it would take to resolve it.
- A warning sign
- A blanket ban. It usually means AI gets used anyway, out of sight.
How to use these
Put them on the agenda for the next meeting and ask management for a written answer in advance. A page or two is enough. If the answers take longer than that, it is worth asking why.
Then ask them again in six months. AI use changes quickly, and the most useful thing a board can build here is the habit of looking.