Governance as Enabler
The AI Governance Questions Boards Should Ask
Directors do not need to be AI experts. They need to know what to ask, and how to tell a credible answer from theatre.
6 min read
By Larry Ockene · Technology & Product LeadBoards already oversee areas where no director is an expert. Their job is to make sure that management understands the issues, has the processes and controls, and can show that those controls work. AI is no different, but it is unfamiliar, it spreads through a company without a coordinated initiative, and the EU AI Act now reaches it. Six “How do we know?” question areas give directors a practical framework: where AI is used, which uses carry consequential risk, what controls exist, whether they work, what the Act requires, and how the board keeps up.
Visibility first
You cannot assess risk or obligations without an inventory of where AI is actually in use, including shadow AI and AI embedded in licensed products.
Sort by consequence
Most AI use is low-stakes. Governance effort belongs on the smaller set of uses that affect customers, employees, or decisions.
Evidence, not policy
A control on paper is not a control. Ask for incident history, testing, and who owns the fix when something fails.
The Act still applies
SME and small mid-cap simplifications reduce the burden but do not remove it. AI literacy and transparency obligations apply at every size.
Revisit on triggers
Set a baseline, agree the metrics the board sees, and define what escalates immediately rather than waiting for the next review.
Boards are accustomed to overseeing areas in which individual directors aren’t necessarily experts. Their role is to satisfy themselves that management understands the issues, has appropriate processes and controls in place, and can demonstrate that those controls are working.
AI governance should be no different. Yet many boards feel less confident overseeing AI because the technology is unfamiliar and changing rapidly. The challenge is particularly acute for SMEs and small mid-caps, which may have neither AI expertise on the board nor dedicated legal, risk, or compliance teams responsible for AI governance.
Meanwhile, AI adoption grows as business teams use it to analyse data and create documents, developers adopt coding assistants, and customer service teams deploy chatbots. At the same time, software vendors are adding AI capabilities to CRM, HR, finance, and other systems companies already use. AI can therefore spread throughout an organisation without ever being part of a coordinated corporate initiative.
While adding AI expertise to the board may be valuable, the more immediate need is for directors to know what to ask. They need confidence that management knows where and how AI is being used, understands the risks and regulatory obligations it creates, and has appropriate safeguards and mitigations in place. The following six “How do we know?” question areas provide a practical framework for that oversight.
How do we know where AI is being used?
Visibility is the starting point for effective AI governance. Companies can’t assess risks, controls, and regulatory obligations without knowing what is actually in use. This can be difficult to establish, as traditional IT and procurement processes won’t always recognise new AI capabilities added to an existing licensed product or an employee using a public AI service. Treating this as an IT ticketing problem is how companies end up with governance on paper and shadow AI everywhere else.
For the board, this means gaining confidence that management has mechanisms to identify significant AI uses, and keep that information current as those uses evolve.
- How do we identify where AI is used in each company department or function?
- How confident are we that this inventory is complete?
- Who is responsible for keeping it current as new tools are adopted?
- How do we identify AI embedded in products and services we license from others?
- How are AI uses outside of approved systems (i.e. “shadow AI”) identified as they emerge?
How do we know which AI uses create consequential risk?
Most AI use in a company is low-stakes: summarising documents, drafting emails, formatting presentations, or tidying up code. The purpose of a risk assessment isn’t to scrutinise all of it equally, but to identify the smaller number of uses that aren’t low-stakes so they get handled in a way that reflects the risk they actually carry.
An AI system can work exactly as designed and still expose confidential information, introduce bias into decisions, infringe intellectual property, mislead customers, or damage the company’s reputation. An organisation needs to distinguish consequential uses of AI (customer-facing, employee-affecting, decision-driving) from the low-stakes majority, and stay alert to risks that emerge gradually as tools adopted for one purpose expand into something more consequential.
- Which AI uses could materially affect customers, employees, or the company’s reputation, including through bias, inaccuracy, misleading output, or exposure of intellectual property?
- How do we know what customer or company data is entering AI systems?
- Where are people making important decisions based on AI-generated recommendations or output?
- How do we recognise when a seemingly low-risk AI use evolves into something more consequential?
How do we know that appropriate controls are in place?
Once management understands the risks, the question becomes whether the company has the controls to manage them. These can include acceptable use policies, approval processes, training, and human oversight. Boards should seek assurance that their company’s controls are specific and enforceable, rather than purely aspirational:
- Do we have acceptable use policies, including rules on what data employees may share with AI systems?
- Who can approve new AI tools or uses, and are AI governance responsibilities clearly assigned across corporate functions?
- Where is human oversight required and how is it designed?
- Have employees received AI training and guidance appropriate to their role and responsibilities?
- Are our controls proportionate to the risk, or are we imposing the same process on low-risk productivity uses as on consequential applications?
How do we know those controls are actually working?
Having controls on paper is different from knowing they work. Boards should look for evidence, such as incident history, testing, reporting, and accountability for remediation. Otherwise governance risks becoming theatre, with policies and inventories that create reassurance without reducing risk.
- What evidence tells us our most important AI controls are actually working?
- How do we test whether human oversight is effective in practice?
- What AI-related incidents or control failures have we seen, and what did we learn from them?
- How would an employee report an AI concern, and how would significant issues reach senior management or the board?
- When a control isn’t working, who is responsible for fixing it and verifying the fix?
How do we know what the EU AI Act requires of us?
What the AI Act requires depends mainly on what an AI system does, how the company uses it, and the role the company plays (e.g. whether it is a provider or deployer). Company size matters too, but mostly in how some obligations are applied. The SME and small mid-cap simplifications can reduce the compliance burden, but they do not remove the underlying requirements; transparency obligations, for instance, apply regardless of company size. Boards should therefore ask whether management has mapped the Act’s requirements to the AI systems the company uses.
- Have we assessed our AI uses against the Act’s categories, confirming none are prohibited, and identifying which trigger high-risk or transparency obligations?
- For regulated uses, do we understand whether we’re acting as a provider, deployer, importer, or distributor?
- Do we know which obligations apply to us, whether we qualify for SME or small mid-cap simplifications, and how that status would change as we grow?
- Do we meet the Act’s AI literacy requirement to train staff to a level appropriate to their role (which applies to every company, regardless of size)?
- Who is responsible for monitoring changes in the AI Act, and where our interpretation is uncertain, whose advice are we relying on?
How do we know we’re keeping up?
AI use, risk, and regulation keep changing, so boards should use the questions above to establish a baseline, and revisit them periodically. The goal isn’t to make AI a permanent board agenda item regardless of whether anything has changed, but to establish regular reporting and clear triggers for escalation when something material does change.
- What has materially changed since our last review?
- What metrics or indicators should the board see regularly?
- What developments require immediate escalation rather than waiting for the next scheduled review?
- Who determines when an AI use or risk needs to be reassessed?
- How do we know when the governance framework itself needs to change?
Good governance starts with the right questions
Good AI governance does not require every director to become an AI expert, nor does it require smaller companies to recreate the compliance machinery of a multinational. Management should own the inventory, risk assessment, controls, and regulatory compliance. The board’s role is to test whether that work is credible, or just theatre.
That means asking management to show how it knows where AI is being used, which uses create consequential risk, what controls apply, and whether those controls are actually working. The answers will change as the technology, the business, and the regulation change. The board’s most useful question might be the simplest one: How do we know?
The answers to these questions can help companies move quickly and confidently with AI without tipping into either paralysis or recklessness.
Author note
Larry Ockene leads technology and product at Foremost. He has built and run enterprise AI platforms as a CTO, and writes about what survives contact with production.
Citation
Cite this essay as:
Ockene, Larry (2026). “The AI Governance Questions Boards Should Ask”. Foremost Thinking, 8 Sept 2026. https://foremost.ai/foremost-thinking/ai-governance-questions-boards-should-ask
More Foremost Thinking

