By NACD's 2026 governance research, more than 62% of directors now set aside full-board time for AI, up sharply in a year. But scheduling the conversation is not the same as governing the risk: only about a third of directors are strongly confident their board has the skillset to oversee it, and Deloitte's board research finds AI governance is simultaneously a top priority and a recurring gap. The board's job is not to out-expert management. It is to ask questions good enough that weak answers become visible.
Boards oversee; management operates. The ten questions below are built for that altitude. Each is paired with what a strong answer contains and the warning sign in a weak one. They are ordered from value to risk, because a board that only asks about risk trains management to treat AI as a threat to be contained rather than a decision to be made well.
Questions 1–3: value and accountability
- 01Where specifically should AI create enterprise value, and how will we know? A good answer names use cases tied to operating and financial metrics, not “productivity.” Warning sign: the answer is a list of tools and pilots with no expected P&L effect.
- 02Who has individual accountability for delivering that value? A good answer is a named executive with budget and process authority. Warning sign: a committee, or a name the CEO gives that the CTO would not — Open Future Forum's data shows “no single owner yet” rising to 14% even as deployment accelerates.
- 03How are we distinguishing AI adoption from financial return? A good answer separates usage from operating change from booked results. Warning sign: adoption metrics standing in for ROI — the same confusion that leaves proving ROI the top blocker at 51% across finance rooms.
Questions 4–6: disruption, delegation and shadow AI
- 01Which part of our business model is most exposed to AI disruption? A good answer identifies a specific revenue line or moat and what would erode it. Warning sign: management treats AI purely as internal efficiency and has not asked what it does to the offering.
- 02Which decisions or actions are we now delegating to AI systems, and with what human oversight? A good answer names the consequential decisions, the human-in-the-loop thresholds and who set them. Warning sign: no one can list what the systems are allowed to do on their own.
- 03What AI activity is running outside approved systems? A good answer includes a real inventory and a shadow-AI estimate. Warning sign: confident denial — the absence of shadow AI is usually the absence of measurement.
Questions 7–8: concentration and agent control
- 01How concentrated are we on a small number of model or infrastructure providers? A good answer quantifies dependency and has a switching plan. Warning sign: a single provider underpins critical workflows and no one has priced the lock-in.
- 02How are AI agents authenticated, authorized and monitored? A good answer maps to a named security owner and real controls. Warning sign: the gap Open Future Forum measures directly — securing agents is the top CISO concern at 62%, yet 69% of security teams have no dedicated AI-security budget.
Questions 9–10: talent and the kill decision
- 01Do we have the talent and organizational authority to execute the AI strategy? A good answer is honest about capability gaps and who has the mandate to change process. Warning sign: an ambitious strategy owned by someone with neither budget nor authority to enforce it.
- 02What evidence would make management accelerate, change, or kill an AI program? A good answer states kill criteria and a return clock in advance. Warning sign: no defined off-ramp — programs that can only continue are how sunk cost becomes strategy.
The tenth question is the one most board-AI checklists omit, and it is the most revealing. A management team that can tell the board, before spending, what result would make it stop has thought about AI as an investment. A team that cannot has thought about it as an inevitability.
Last updated: August 19, 2026
Frequently Asked Questions
Where directors compare AI oversight, off the record
Open Future Forum convenes public-company board directors and C-suite leaders for candid conversations on AI oversight, risk and accountability. Global, founded in Silicon Valley.