Boards oversee; management operates. The ten questions below are built for that altitude, and each comes with what a credible answer contains, the warning sign in a weak one, the executive who should own it, and the evidence a board should ask to see. They are ordered from value to risk, because a board that asks only about risk trains management to treat AI as a threat to be contained rather than a decision to be made well.
Where boards actually stand
AI is now a scheduled agenda item for most public-company boards. In NACD's 2025 public-company survey, more than 62 percent of responding directors said their boards set aside agenda time for full-board AI discussions, which NACD frames as more than double the 2023 level. The sub-questions ran on 163 responses from NACD members, so read it as association members rather than US directors generally.
Capability has not kept pace with attention. Corporate Board Member and Diligent Institute's What Directors Think 2026 found just 8 percent of directors say their board has strong AI expertise, the lowest of any area surveyed. Deloitte's Governance of AI research, covering 695 respondents across 56 countries, found two-thirds saying their boards still have limited to no AI knowledge or experience.
That gap is the argument for questions rather than expertise. The board's job is not to out-expert management. It is to ask questions good enough that weak answers become visible.
Value, ownership and proof
1. Where specifically should AI create enterprise value, and how will we know?
Why the board asks it. Without this, every subsequent answer floats. A board that has not agreed what success looks like cannot judge whether a program is working or whether it should continue.
What a credible answer contains. Named use cases tied to operating or financial metrics, with a stated timeline and a baseline to measure against. Productivity is not a metric.
Warning sign. A list of tools and pilots with no expected effect on the profit and loss account, or value described only as capability.
Who should own the answer. The CEO, with the business owner of each named use case.
Evidence to request. The three largest AI commitments, each with its expected result, its owner and its payback date.
2. Who has individual accountability for the AI decision?
Why the board asks it. Accountability is the line that everything else hangs from, and it is the one most likely to be missing. It is also least visible from where the board sits.
What a credible answer contains. A named executive with both budget and process authority, confirmed independently by finance and by technology. Three people should give the same name in writing.
Warning sign. A committee. Or a name the CEO gives that the CFO or CTO would not. In our September data, reported unowned AI decisions run at 2 percent from the CEO seat, 15 percent at finance and 30 percent at the technology seat, the last on a base of 23 and directional. The seat least likely to see missing ownership is the seat the board hears from.
Who should own the answer. The CEO names it. Finance and technology confirm it.
Evidence to request. The signer of the last three AI purchases above the approval threshold, with the paperwork. If nobody can produce three names within a week, approval is happening below the level the board assumes.
3. How are we distinguishing AI adoption from financial return?
Why the board asks it. Usage metrics are the easiest thing to produce and the least informative. Boards get shown them because they look like progress.
What a credible answer contains. Three separate layers kept separate: usage, operating change, and booked result. Plus an honest statement of which of the three the company can currently evidence.
Warning sign. Adoption metrics standing in for return. In our September finance data, proving ROI was named the main blocker by 65 percent of the August cohort, up from 53 percent earlier in the year, on a base of 290. A rising number is not necessarily bad news: it usually means proof is now being demanded, which is a later and healthier stage than deployment without measurement.
Who should own the answer. The CFO.
Evidence to request. A reconciliation from claimed AI benefit to a line in the management accounts, for at least one program.
Data, concentration and agents
4. Where did the training and input data come from, and do we have the rights to use it that way?
Why the board asks it. Provenance is the exposure that surfaces late and expensively. It reaches contracts, privacy, intellectual property and customer commitments at once.
What a credible answer contains. A mapping of data sources to the permission that covers each, including customer data used for training or fine-tuning, third-party licensed data and scraped content. Plus the contractual position with model providers on what they may retain.
Warning sign. Provenance described as a vendor responsibility. Or an inability to say whether customer data has been used for training.
Who should own the answer. The general counsel, with the chief data or technology officer.
Evidence to request. The data provenance register, and the clauses in the two largest model contracts covering retention and training use.
5. How concentrated are we on a small number of model or infrastructure providers?
Why the board asks it. Concentration risk built quietly over two years is hard to unwind in a quarter, and it moves pricing power to the provider.
What a credible answer contains. A quantified dependency by workflow, the cost of switching, and whether an alternative has actually been tested rather than merely identified.
Warning sign. A single provider underpinning critical workflows with no one having priced the lock-in, or a resilience plan that has never been exercised.
Who should own the answer. The CIO or CTO, with finance on the commercial exposure.
Evidence to request. The share of AI-dependent revenue or critical process running on the largest single provider, and the last date an alternative was tested.
6. How are AI agents authenticated, authorized and monitored?
Why the board asks it. Agents act. That makes identity and privilege a board-level control question rather than an implementation detail, and it is where the gap between what a team is asked to govern and what it is funded to govern shows up.
What a credible answer contains. An inventory of agents in production, what credentials each holds, who owns each one, short-lived rather than standing credentials, fine-grained privilege limits, logging of every agent action rather than only failures, and human approval for high-impact actions. CISA and international partners published joint guidance on agentic AI adoption that sets out this ground.
Warning sign. Shared service-account credentials. An inventory maintained by hand, which is out of date the week it is written. In our September security data, 67 percent of senior security leaders named securing agents and their access as their top AI problem while 37 percent held a dedicated AI security budget line, on a base of 110.
Who should own the answer. The CISO.
Evidence to request. The agent inventory with credential scope and named owner per agent, and confirmation of whether it is system-generated or hand-kept.
Incidents, regulation and people
7. What triggers an AI incident escalation to this board, and has the path been tested?
Why the board asks it. Escalation thresholds agreed after an incident are worth very little. The board needs to know the trigger exists and works before it is needed.
What a credible answer contains. Defined triggers by severity, a named escalation owner, an external reporting decision path, and evidence the path has been exercised. The NIST AI Risk Management Framework and ISO/IEC 42001 both give a structure management can be held to, and 42001 is certifiable, so the question of whether the company has been audited against it has a real answer.
Warning sign. AI incidents folded into general IT incident handling with no distinct trigger, or a policy that exists on paper and has never been run.
Who should own the answer. The CISO for detection and containment, the general counsel for external reporting.
Evidence to request. The AI incident policy, and the date and findings of the last tabletop exercise that included an AI scenario.
8. What is our regulatory and legal exposure, and how is it tracked?
Why the board asks it. The map is moving, and the obligations that bind are not always the ones in the headlines.
What a credible answer contains. A named owner tracking the EU AI Act, where prohibited practices and AI literacy obligations have applied since February 2025 and general-purpose model obligations since August 2025, with high-risk deadlines deferred to December 2027 and August 2028 under the 2026 amending regulation. For US-listed companies, an understanding that the SEC has no AI-specific rule and applies ordinary materiality, while AI-washing enforcement is live. Plus state exposure, including Colorado's replacement law effective January 2027 and California's frontier AI transparency regime.
Warning sign. Treating the EU deferral as a reprieve. It is a deferral of the high-risk tier, not of the prohibitions or the literacy obligation, and it applies extraterritorially.
Who should own the answer. The general counsel.
Evidence to request. The regulatory tracker with named owner per obligation, and the last review date.
9. What is AI doing to our workforce and our organizational design, and is it minuted as a decision?
Why the board asks it. Funding AI from money earmarked for hiring is a workforce decision. It is frequently not recorded as one.
What a credible answer contains. A stated position on where headcount plans have changed, the capability the company needs to build or buy, and who holds the mandate to change process rather than only to buy tools. In our September data, 21 percent across the finance lane reported funding AI from headcount money, rising to 34 percent at the CEO seat, on a base of 290.
Warning sign. An ambitious AI strategy owned by someone with neither budget nor authority to enforce a process change. Or a material shift in hiring plans that appears nowhere in a board minute.
Who should own the answer. The CEO, with the chief people officer.
Evidence to request. The AI spend split by funding source, and the headcount plan as it stood before and after.
And the one most checklists omit
10. What evidence would make management accelerate, change, or kill an AI program?
Why the board asks it. It is the cheapest test of whether AI is being treated as an investment or as an inevitability, and it takes thirty seconds to answer.
What a credible answer contains. Stated kill criteria and a return clock, set before the spend rather than after. Ideally written into the approval itself.
Warning sign. No defined off-ramp. Programs that can only continue are how sunk cost becomes strategy.
Who should own the answer. The CEO and the CFO jointly.
Evidence to request. The approval document for the largest current AI commitment, showing its stated stop condition.
Which board committee should oversee AI?
There is no settled answer, and boards claiming otherwise are describing their own choice rather than a standard. The evidence shows dispersion, and it shows the dispersion persisting.
EY's review of 2025 Fortune 100 proxy disclosures found 40 percent disclosing at least one board committee charged with AI oversight, up from 11 percent a year earlier. Within that, 21 percent named the audit committee and 25 percent a non-audit committee, and the two figures exceed the total because some companies assign AI to more than one. Glass Lewis analysis of the S&P 100 found 54 percent disclosing board-level AI oversight, of which 63 percent assigned it to a specific committee, usually audit or technology, and 37 percent kept it at the full board. EY's 2026 proxy season review found only 17 percent of S&P 500 boards have a technology committee at all, and concluded that most companies expanded an existing committee, typically audit, rather than creating a new one.
Investors are not converging either. Glass Lewis reports 65 percent of investors believe companies should disclose board oversight of AI governance, and 49 percent believe it should be codified in a committee charter, while views on which committee split three ways.
The practical division that works for most boards is by subject rather than by a single owner. Audit takes controls, data integrity and the reliability of AI-influenced reporting. Risk takes model risk, concentration and incident escalation. Technology, where one exists, takes strategy, architecture and deployment. Nominating and governance takes board composition, director education and the oversight structure itself. The full board takes strategy and business-model exposure.
What causes trouble is not picking the wrong committee. It is AI arriving as an update from whoever presented last, with nobody owning it between meetings. More on how this plays out in practice on the AI and board governance page.
A quarterly board checklist
Seven lines in the pack, each with a named reporting seat and a cross-check from a different one.
| Line | Reported by | Cross-check |
|---|---|---|
| Named owner of AI purchasing | CEO or COO | CFO and CIO confirm the same name in writing |
| Signer of the last three AI purchases above threshold | Finance | The purchase paperwork |
| AI spend by funding source | Finance | Reconciled to the general ledger |
| Payback date on the three largest commitments | Business owner | Finance's view of the same three |
| Proving-ROI blocker rate | Finance | Trend across the last four quarters |
| Agent inventory, credentials and owner | Security | Whether the inventory is system-generated or hand-kept |
| AI security funding status | Security | Finance's view of the same budget |
Available on request at any time, rather than quarterly: the agent inventory. The interval between an agent being granted access and a board hearing about it is the exposure.
A fuller version of this dashboard, with what each line reveals, is here. The underlying figures with their response bases sit in the Board Director AI Governance Report.
Public, private and venture-backed
The disclosure work differs; the oversight work does not. A public-company board carries proxy disclosure and an SEC materiality judgment on top. A private-company board carries neither, which removes a layer rather than the substance.
Venture-backed boards have one exposure the others often do not: the company's product may be built on a single model provider, which makes question five a strategic question rather than a procurement one. They also tend to have the fewest independent directors, which makes the counter-seat discipline harder and more necessary.
One caution worth stating plainly. As of September 2026 there is no decided Caremark case specific to AI, so nothing here should be read as describing established liability. The doctrinal direction is clear enough to act on: Marchand established heightened scrutiny where a risk is mission-critical to the business, and once AI reaches that status, board-level monitoring stops being discretionary.
Open Future Forum runs a Public Board Member Dinner Series for directors of public and late-stage companies, alongside its executive forums for each C-suite seat. Discussions are private and off the record. Applications are read individually.
Last reviewed: September 17, 2026. Competitor eligibility, format and pricing details were checked against official sources on this date.
Frequently Asked Questions
Where directors compare AI oversight, off the record
Open Future Forum convenes public-company board directors and C-suite leaders for candid conversations on AI oversight, risk and accountability. Global, founded in Silicon Valley.