What Your Board Is Going to Ask About AI

There’s a deck open on your second monitor. It’s titled something like “AI Strategy,” it has a roadmap on slide four with three horizons and a lot of arrows, and you’ve been building it because someone said the board wants to hear about AI. A roadmap is what you present when a board wants to hear about something.

Close it. The board is not going to ask for your AI strategy. Boards don’t govern strategies. They govern spend, results, exposure, and whether the people running the company are competent. When AI comes up at the meeting, and it will, it shows up as four questions wearing business clothes. You already know how to answer all four. The deck is getting in the way.

The board isn’t chasing a trend. It’s doing its job

A board member who raises AI is not asking you to be visionary. They’re asking the same thing they ask about a new distribution center, a currency exposure, or a key-person risk. Money in. Value out. What could sink us. Who owns it. AI feels like a special category because the vendors and the trade press have spent three years insisting it’s a wave, a transformation, a thing happening to your industry. It isn’t. It’s a set of products on a line item, and the board is going to treat it like every other material line item. So should you. That posture is the whole executive mental model for AI: five operating decisions you already know how to make, not a religion you have to adopt.

Here are the four questions, in the order they’ll come, with the answer you walk in holding.

”How much are we spending on this?”

This is first because it’s the easiest for a board member to ask and the one that most often gets a bad answer. The bad answer is a range, a shrug, or worse, a vendor’s productivity claim used as a stand-in for cost. Don’t walk in with “AI is delivering a 3.7x multiplier.” That’s a number someone sold you, and the first person to poke it will win.

Walk in with the bill. Total annual AI spend. Divide it by headcount so it’s legible next to your other per-employee costs. Then split it into the two shapes it actually takes: flat per-seat licenses, and metered usage. That split matters because the two behave differently, and a board that understands the split will trust the rest of what you say. The flat seats are the ones to watch, because an idle flat seat is pure waste. The metered usage is the healthy part of the bill, because you pay in proportion to what your heavy users produce. If you can say “we spend X, it’s Y per employee, most of the growth is metered usage from the teams producing the most, and here’s the one flat SKU I’m auditing,” you’ve answered the spend question better than most public companies can. The five-minute spend audit is where that number comes from.

”And what are we getting for it?”

This is the question that ends careers when it’s answered with theater. The temptation is a single productivity percentage on a slide. Resist it. Six months later the same board member will ask why headcount and contractor spend haven’t moved, and you’ll be defending a number you can’t source.

Answer with people and workflows, not a multiplier. Name two or three workflows AI measurably compressed, the before and after, and the people producing the compression. Contract markup that went from two days to two hours. A support queue where first-response drafts now come out of the model and a human approves them. The named analyst whose output doubled. This is what recognizing leverage looks like on the ground, and it’s more defensible than any index because a board member can go talk to the person.

Be honest about the denominator, too. MIT’s review of three hundred enterprise deployments found ninety-five percent of generative AI pilots delivered no measurable impact on the bottom line.1 That statistic is your friend in this meeting, not your enemy. It’s the reason you report production workflows, not pilots. If your answer is a running pilot, your honest answer is “nothing yet.” Report the two things that are actually in production and owned by a P&L, and let the pilots stay off the slide until they cross over. The full decision loop is in measuring returns.

”What’s our AI policy?”

The board isn’t asking to read the policy. They’re checking that one exists, that it’s short enough to be real, and that a named person owns it. The wrong answer, the one that quietly costs you credibility, is “it’s in committee.” A board hears “in committee” as “we don’t have one,” and they’re right.

The answer they want fits on a page. Approved tools. Off-limits data. A named owner. Shipped. A one-page AI policy ships in two weeks; the forty-page version that’s been in legal review since spring protects no one, because the workforce already picked its own tools while the committee met. If you don’t have the page yet, the correct thing to tell the board is “you’ll have it before the next meeting,” and then actually ship it, because this is the one answer of the four you can fully close before they ask again.

”What happens when this goes wrong?”

The board’s real fear here is a headline. A leaked customer list, a discriminatory automated decision, a regulator letter. Your job is to make the answer boring, because boring is what governance looks like when it’s working.

There are five failure modes that actually land in enterprises, and each has a small set of dull controls that catch it. The one already happening in your company is data leakage through tools you didn’t approve. One in five breaches now involves shadow AI, adding roughly $670,000 to the average breach cost, and most of the companies it happens to had no AI governance policy at all.2 The one arriving next is ungoverned automation: scheduled agents running on a clock nobody in IT approved. Gartner projects AI-related legal claims will pass two thousand by the end of 2026, and the recurring cause isn’t rogue intelligence, it’s missing audit trails for automated actions.3 Name the owner, name the controls, and if you’ve already caught and closed one incident, say so, because nothing reassures a board like evidence the tripwires work. The five modes and their controls are laid out in managing risk.

The four paragraphs that end the meeting

Here is the whole meeting, pre-answered, in four paragraphs you can adapt and put in the pre-read so the questions never have to be asked out loud.

Spend. “We spend roughly $[X] a year on AI, about $[Y] per employee. Most of the growth is metered usage concentrated in the teams producing the most, which is the pattern we want. We audit the flat licenses quarterly and cut the idle ones.”

Returns. “Three workflows are measurably faster in production, owned by named leaders: [workflow], [workflow], [workflow]. We report those, not pilots, because ninety-five percent of industry AI pilots produce nothing measurable and we don’t intend to be in that number.”

Policy. “We have a one-page policy: approved tools, off-limits data, a named owner. It shipped in [month]. It’s short on purpose, because the forty-page version is the one people ignore.”

Risk. “Our biggest live exposure is staff using unapproved tools with company data, and we’re closing it by making the approved tool the better one. Automated agents run only under [owner]‘s sign-off with logging. We caught and closed one incident this quarter, which is how we know the controls hold.”

Read those back. There’s no strategy in them, no roadmap, no horizon three. There’s a number, some named people, a document, and a plan for the bad day. That’s what the board came for. Give them the four paragraphs and the meeting is a status update instead of an interrogation, which is exactly where you want AI to sit on the agenda.

Footnotes

  1. MIT NANDA, “The GenAI Divide: State of AI in Business 2025.” Review of 300 public deployments plus interviews and surveys; 95% of enterprise generative AI pilots delivered no measurable P&L impact. Reported by Fortune, August 2025.

  2. IBM, “Cost of a Data Breach Report,” 2025. One in five studied breaches involved shadow AI, adding roughly $670,000 to average breach cost; 63% of organizations studied had no AI governance policies in place.

  3. Gartner projection that AI-related legal claims will exceed 2,000 by the end of 2026, with recurring causes including missing audit trails for automated actions and inability to explain automated decisions in regulated contexts.