A governance roundtable I attended earlier this year kept returning to the same realization: nobody in the room was struggling with the technology anymore.
What they were stuck on was everything surrounding it, such as who owns the risk, where the data actually lives, and what happens when a system acts before a human signs off.
I have had a version of that conversation on repeat with directors and executive teams over the past few months. AI no longer shows up alone in these discussions. It brings accountability, data readiness, cyber, and exposure to regulators.
That is probably the most important shift in the boardroom. AI is no longer something that can be handed to the CIO, CTO, or the innovation team and treated as a technology investment. When it starts influencing how decisions are made, how work gets done, and how customers are treated, it becomes a governance issue.
The real AI boardroom question is no longer whether AI matters. It is whether the organization knows how to turn AI into value without losing control of the risks.
The following are five questions I believe belong on every board agenda in 2026.
1. Is AI Becoming a Business Capability, Or Are We Just Collecting Experiments?
An organization can have dozens of AI initiatives and still lack an AI strategy. One department may be deploying a generative AI assistant, while another may be using predictive analytics. Similarly, a third department may have purchased an AI-enabled software platform.
Each project may make sense on its own, but that does not always mean the organization is building a coherent capability.
The board should ask whether these initiatives align with a small set of strategic priorities. If AI disappeared tomorrow, which parts of the business would be affected? That question can reveal whether AI has become embedded in the operating model or remains a collection of interesting demonstrations.
McKinsey found that although 88% of organizations reported regular AI use in at least one function, only about one-third said they had begun scaling their AI programs across the enterprise.
Therefore, the AI boardroom should ask management to demonstrate how successful experiments are moving from proof of concept to production and then to enterprise scale.
That requires more than technology. It requires the underlying data to be usable, accessible, governed, and reliable.
For example, a company trying to build an AI-powered forecasting system may discover that its sales data is spread across incompatible systems and that definitions are inconsistent. Plus, it cannot be easily traced back to its sources. The AI model is not necessarily the problem here. It’s actually the organization’s data foundations.
Boards should ask who owns critical data, how data quality is measured, where sensitive information can flow, and which datasets provide genuine strategic value.
The board should also distinguish between AI as a tool and AI as a capability. Buying an AI application can deliver short-term productivity gains, but developing the people, data, processes, governance, and infrastructure to repeatedly deploy AI is what builds organizational capability.
So, the strategic question goes beyond just “Where are we using AI?” It is: “What part of our” business are we rebuilding around AI, and what will it look like when we succeed?”
2. Are We Turning AI Investment Into Measurable Value?
Productivity is usually where the first AI gains show up. For example, employees write and analyze faster and spend less time on repetitive work. This is useful, but none of that automatically means the business is getting a return.
Boards need to push the conversation further. If an AI tool saves 10,000 hours, what happened to those hours? Did they reduce costs, increase capacity, improve customer service, accelerate product development, or enable employees to do more of the same work?
The financial case for AI is also proving harder to make than the productivity case. Deloitte’s 2026 State of AI in the Enterprise research found that only 20% of organizations reported significant revenue increases from AI, while 40% reported cost reductions.
Boards should expect major AI investments to have a clear definition of value. That could include:
Lower operating costs
Faster decisions
Fewer errors
Better customer retention
Greater capacity without a proportional increase in headcount
There is also a longer-term question. AI can speed up an existing process, but its greater value may come from changing how that process works altogether. For example, a customer-service team might start by using AI to summarize conversations and then redesign the entire support model around automated triage and knowledge retrieval.
That is the difference between efficiency and transformation. One improves the existing model, while the other can change the business’s economics.
The board should know which AI investments are delivering value today and which are expected to deliver value later. They should also know which have become expensive experiments with no clear path to return.
So, the deep question is: “Where is the value showing up, and who is accountable for making sure it does?”
3. Can We Trust Our AI, and Can Others Trust Us With It?
Trust usually doesn’t appear as a standalone agenda item in the AI boardroom. It shows up disguised as another question, such as why the model denied that loan, why the chatbot said that to a customer, or why the system flagged this employee and not that one. When a board asks this, something has usually already gone wrong.
The scale of the exposure is larger than most directors assume. IBM found that 87% of organizations believe they have clear AI governance frameworks in place, yet fewer than 25% have implemented the controls needed to manage bias, transparency, and security risk.
McKinsey found that 51% of organizations using AI have already experienced at least one negative consequence, such as inaccurate outputs, biased decisions, security incidents, or similar issues.
That gap between what a company claims and what it can actually demonstrate is where the real risk sits.
Regulators are moving to align with that reality. Under the EU AI Act, a significant wave of obligations for high-risk systems takes effect in August 2026, with penalties of up to €35 million or 7% of a company’s global turnover for the most serious violations. Boards operating anywhere near that regulatory perimeter can no longer treat AI risk as an internal matter.
There’s a second, quieter version of this question: Can the company publicly defend what it says about its AI? There is a wave of companies overstating what their systems do, which has already drawn attention from the FTC and a growing number of shareholder suits.
A board that signs off on AI-related claims in a filing or an investor deck without requesting evidence faces the same exposure as the executive who wrote them.
None of this means governance has to slow AI down. It means the controls need to be in place before the system makes decisions that matter, including human review at the right checkpoints, access restrictions, bias testing, and a clear owner when something goes wrong.
So the board-level version of this isn’t “Do we have an AI policy?” It’s: “If a regulator, a journalist, or a customer asked us to prove our AI is safe and fair right now, could we?”
4. Are Our People and Our Culture Actually Ready for This?
Boards tend to treat this as an HR question, but it isn’t. The three questions above, related to strategy, value, and governance, all depend on people who are willing and able to use the system.
The gap is wider than most leadership teams assume. IBM’s 2026 CEO Study found that 83% of CEOs believe AI success depends more on human adoption than on the technology itself. The same research found that 53% of employees will need upskilling just to do their current job effectively over the next two years, with another 29% needing reskilling into a different role entirely.
Training hasn’t kept pace. Only about 13% of workers report receiving meaningful AI training, despite far more employers saying they plan to reskill their workforce. BCG found a clear threshold effect, i.e., employees who receive at least five hours of structured training show higher confidence and usage, and most companies never get most of their people past that line.
Similarly, Deloitte’s 2026 State of AI in the Enterprise found that 84% of organizations have not redesigned jobs around AI capabilities, despite rising expectations for automation. The research also found that insufficient worker skills are the primary barrier to integrating AI into existing workflows.
That means boards should look beyond whether the company has an AI training program. They should ask which roles are changing, what skills will become more valuable, and whether employees are being given a realistic path to adapt.
There is also a cultural question. Employees need to feel able to speak up when an AI system is producing poor results or creating extra work or risks. If people are afraid to challenge the technology, management may end up seeing polished adoption numbers and miss problems on the ground.
The strongest organizations are treating AI as a catalyst for work redesign. That means combining AI with human judgment, rethinking workflows, reshaping career paths, and deciding where people add the most value.
For the AI boardroom, the question is about readiness: “Are we preparing people to work differently, or simply asking them to use a different tool?”
5. What Happens When AI Fails, and Are We Ready for It?
Every AI conversation assumes the system works. Boards need to spend at least as much time on what happens when it fails.
StackGen’s State of Reliability 2026 analysis of 177,960 public status-page records found that AI-related incidents accounted for 10.7% of disclosed incidents year-to-date in 2026, up from 1.7% in 2023. The same research documented at least nine cases in which autonomous AI agents damaged production systems by deleting data or entire databases.
Third-party dependencies make this worse. More than one in four AI-related incidents in that study originated with a vendor the affected company didn’t control, and those third-party failures took roughly three times as long to resolve.
The cost of not planning for this is real. Signisys research puts downtime costs at ~$8,600 per minute, up 54% since 2022. However, fewer enterprises regularly test failover for AI-dependent systems.
AI failure does not always mean a system crashes. An application can remain available even as its outputs become unreliable or its underlying data changes. This makes AI resilience distinct from traditional IT continuity.
Boards should ask what happens when a critical AI system fails or when it continues running but begins making poor decisions. Can employees switch to a manual process? Are there alternative vendors or models? Can the organization detect degraded performance quickly enough to prevent broader business impact?
The board does not need a perfect prediction of every possible AI failure. It needs confidence that the business can detect, contain, recover from, and continue operating after a failure.
Bottom Line
An AI boardroom does not require the board to become AI experts to answer the five questions above. It requires the discipline to ask before the technology decides the answer for them. The organizations pulling ahead in 2026 will be those whose boards insisted on strategy, value, trust, people, and resilience.
iExchange Ideas • Innovation • Impact
Where Ideas Meet Opportunity.








As a relatively new board member, I really like the perspective this article provides.
There are many articles about AI governance out there, but I find the clarity and explanations in this one to be very insightful.
The five questions are the right questions for an organisation that has already decided it's doing this. None of them ask the one that comes before all of them: why. What is AI actually bringing that wasn't there before, and does the answer hold up, or is FOMO doing the deciding?
Worth being precise about what "bringing" means here. AI isn't doing anything an organisation couldn't already do — it's doing it at more scale and more speed, which is a real difference, but a difference of degree, not of kind. If a business didn't have this problem yesterday, deploying AI doesn't create the need retroactively. The genuinely useful question, before any of the five, is whether there's a business challenge here that technology can actually address, or whether the technology is looking for a justification.
That also explains why so much of what gets badged AI is overkill. Some of what's described here — summarising, retrieving, flagging — already has existing, simpler technology that does it perfectly well. AI earns its place assisting a task someone already does, adding something a process didn't have, or bringing enough context to sharpen a decision a person is still making. Treated as the answer on its own, rather than one capability brought in at the point it's actually needed, it's solving a problem that already had a solution, with a far more expensive one.
And every one of the five questions is still asked from inside the boardroom, measuring the organisation's own exposure. The harder version of the trust question isn't whether the company can defend its AI to a regulator — it's what the system is actually doing to the person on the other end of it, the customer or claimant who never sat in on any of these five conversations but lives with what they decided.