The board conversation on AI governance
← Insights

Leadership

The board conversation on AI governance

VisionRelic·20 May 2026·8 min read

What boards actually need to hear about AI governance, and why most board packs get the framing wrong.

Board packs on AI governance usually contain three things: a technology overview explaining what large language models are; a regulatory summary listing every framework the organisation might be subject to; and a risk heat map with red, amber, and green cells. The pack runs to thirty or forty slides. The directors read it on the train, glaze over by slide eight, and arrive at the meeting with no clearer sense of whether the organisation is in control than they had before they opened it.

This is a wasted opportunity. The board has limited time, real authority, and a genuine appetite for being helpful on AI governance. The reason the conversation tends to be unproductive is not that the board does not care, but that the materials prepared for it are designed to demonstrate effort rather than to enable decision.

What the board is actually trying to learn

Behind every board question about AI governance is a single underlying question: are we in control of this. Not are we compliant, which is a downstream question. Not are we deploying AI strategically, which is a different conversation. The governance question is specifically about whether the organisation has visibility, accountability, and the ability to intervene when things go wrong.

A board pack that answers this question well needs to address four things, in roughly this order. What are we actually running. What obligations apply to it. Who is accountable for what. And what does the plan look like, with dates.

Most packs answer questions one and two at length and skip questions three and four. The first two are reassuring because they look thorough. The second two are uncomfortable because they require concrete commitments. The board, however, needs the second two more than the first two, because the second two are the questions only the executive can answer.

The inventory, in language the board understands

The first slide of any board pack on AI governance should be the inventory, expressed at a level of granularity the board can act on. Not we have one hundred and forty seven AI systems, which is unactionable. Not a list of every system, which is overwhelming. The right level is a small number of categories, with counts, with one example each, and with a clear statement of the consequence if any of them goes wrong.

For example: we run nineteen customer-facing AI systems, the largest of which determines support routing for two million tickets per year; we run thirty-one internal AI systems supporting back-office processes, of which seven feed into credit decisions; we depend on eleven third-party AI services, three of which are material to our operations. With that framing, the board immediately understands the shape of what they are governing, which they cannot do from a hundred-line spreadsheet.

The inventory slide also surfaces the most useful question the board can ask, which is whether the inventory is honest. The right answer to this question is rarely yes, completely. The right answer is we know about most of what we run, here is what we have done to find what we did not know about, and here is our estimate of the remaining gap. A board that hears that answer is being told the truth. A board that hears that the inventory is complete is being told a comfortable fiction.

Obligations and when they apply

The second slide should be obligations, expressed as a small number of dates. Not a list of every framework the organisation might be subject to, which is paralysing. The frameworks that materially apply, the dates on which the obligations bite, and what the organisation needs to have in place by each date.

For most European organisations in 2026, this looks roughly like: the EU AI Act general purpose AI obligations are already in force and we are operating against them; the high risk system obligations now apply from December 2027 and we are using the extra time as planned; ISO 42001 certification is targeted for Q3 2027 and is on track; sector-specific regulatory expectations are evolving, with the most material change being X, and our response is Y.

Three or four dates. A position on each. The board can then ask the question that matters: are these dates the right dates, and are we resourced to meet them. Without the dates, the conversation cannot happen.

The governance architecture on a single page

The third slide is the most important and the most often missing. It is a single page showing the governance architecture: who decides what, who reviews what, who escalates to whom. Boxes and arrows. Names of roles, not names of individuals. The flow from a system being proposed, through risk assessment, to approval, to deployment, to ongoing review, to incident handling.

This slide is the answer to are we in control. The board reads it and sees, in one image, whether there is a coherent structure. They see whether decisions have owners. They see whether there is an escalation path. They see whether the structure has the right level of independence from delivery. They see whether anyone is accountable for the whole thing.

Most organisations do not have this slide, because they do not yet have the architecture. The act of trying to draw it forces a useful conversation internally about who really does decide what, which is often less clear than the org chart suggests. If the slide cannot be drawn, the program is not yet ready for board reporting, and the right next step is to spend a quarter making it drawable.

The milestone plan

The fourth slide is the plan: the next four quarters, with two or three milestones per quarter, named owners, and a clear indication of which milestones are at risk and why. Not a Gantt chart, which boards cannot use. A small table that fits on one page and tells the board what to expect to hear about in subsequent meetings.

The milestones should be specific enough to be verifiable. Not improve AI governance maturity but inventory complete and signed off by audit committee, classification matrix peer reviewed and adopted, governance ritual operating with attendance and minutes published. The board can hold the executive to milestones like these. They cannot hold the executive to vague aspirations.

What boards do not need

Several things that commonly appear in AI governance board packs should be removed.

Technology explanation. The board does not need to understand transformers, retrieval augmented generation, or how a foundation model is trained. If a director wants the education, offer it separately, in a private briefing. Do not use the board meeting for it.

Risk taxonomy. The pack does not need slides categorising the kinds of risk AI poses: bias, hallucination, security, privacy, and so on. The board needs to know that the organisation has classified its actual risks against its actual systems and is managing them. The taxonomy is internal scaffolding, not board material.

Heat maps. Red, amber, green grids are the comfort food of board reporting. They convey nothing actionable because the colours are subjective and the categories are pre-chosen. Replace heat maps with specific facts and specific commitments.

Strategic AI discussion. Whether and how the organisation should be using AI strategically is a vital conversation. It is a different conversation. Do not mix it with governance reporting. If both need to happen in the same meeting, do them as two distinct items, with different materials and different framing.

What changes when the conversation goes well

A board that receives the four-slide pack described above stops asking governance questions in adversarial mode and starts asking them in supportive mode. The questions shift from how do we know any of this is true, which is the question a board asks when it does not trust the material, to how can we help you accelerate this, which is the question a board asks when it does.

The shift is worth a great deal. Boards have authority that the executive does not: they can allocate budget across the year, they can apply pressure to other functions whose cooperation the program needs, they can give the executive air cover when the program requires saying no to a high-profile internal initiative. A board that understands the governance program will use that authority on its behalf. A board that is confused by the governance program will use it elsewhere.

Boards do not need to understand AI to govern it well. They need to understand that someone accountable has mapped the risk, built the controls, and committed to a review cadence. Give them that, clearly and honestly, and the conversation changes from scrutiny to partnership. That is what good governance reporting actually achieves.