Boards Are Governing the Firm's AI and Ignoring Their Own
Edition 19 - A roundtable at King's College London on the AI directors are already using — and the standard boards keep deferring.
Most boards can now describe how they oversee the company’s use of AI. There is a committee that owns it, an inventory of its deployments, a stated risk appetite, and a policy that specifies what is permitted and what isn’t. Far fewer boards can describe how the board itself uses AI, which is a curious omission, because the directors drafting those policies are increasingly using the technology in their own work. The oversight has been built looking outward, at management and the enterprise, while the desk closest to home has gone unexamined.
On 19 June, I had the pleasure of attending a roundtable on AI in the boardroom at the Dickson Poon School of Law, part of King’s College London. Early in the event, several people said the same thing: their boards were not yet using AI in the boardroom, though they expected it was coming. I suggested that their directors were almost certainly already using it. Individual directors are using AI now, and many are doing so with no governance at all, reaching for whatever tool is nearest to hand, on real board business, with no policy setting out what is acceptable. That ungoverned use is where the risks to accuracy, confidentiality and ethics actually collect, and it is common enough to have a name: shadow AI. The figures bear this out. In Diligent’s What Directors Think 2026, 66% of directors reported using AI for board work, while only 22% sat under any policy governing its use; half used it to prepare for meetings, and 46% reached for a general tool such as ChatGPT.
The typical position, then, is a board that has written careful rules for everyone else’s use of AI and none for its own, while most of its members quietly use public tools on board business. The rest of the roundtable turned on what to do about that, and the discussion is worth reporting because it shows both why the gap persists and what it would take to close it. The room could not agree on how far AI should reach into a director’s work. It agreed, without dissent, on the point that settles the matter in practice: the director remains accountable for every decision and contribution, whatever sat behind them.
The room accepted AI in board work and split over how far it should go
The use cases discussed were unremarkable, which is rather the point — this is already ordinary work. Directors and governance teams described using AI to generate board materials, take minutes, summarise discussions, and condense long board papers into something a busy director can absorb. Most in the room were comfortable with this administrative band of tasks, provided a human checked the output before it was relied upon. That proviso matters more than it sounds, because it is the first of the principles a sensible standard would set down: AI augments a director’s judgement; it does not replace it. The cautious majority had, in effect, already adopted that principle informally; they simply had not written it down or asked whether everyone around the table was applying it.
Above the administrative band, the comfort thinned. Several argued that AI cannot reproduce the judgement that comes with years of experience, and that letting it do the thinking and reach the decision is an abdication of the responsibility a director is appointed to exercise. Others worried about a slower harm: that habitual reliance on the machine would erode directors’ own capacity to think, so that the muscle atrophies precisely as it is needed most. One boundary held across every view in the room. No one wanted to see AI making decisions autonomously. The real disagreement sat higher up, over how far from administration towards judgement the technology should be allowed to climb.
The comparison that matters is director-with-AI against director-alone
Much of the debate circled a question that cannot be answered as posed: whether humans or AI are smarter. I think that framing is the source of most of the confusion. The comparison that matters to a working director is the one that puts the director with AI against the same director without it; human against machine was never the right test. My position in the room was straightforward: me plus the strategic use of AI is considerably smarter than me without it. Set up that way, the abdication worry loses much of its force, because augmentation was never a contest the director was at risk of losing. What remains is a question of order. If a director forms a view first and then uses AI to test it — to find the gap, the blind spot, the counter-argument they had not considered — then AI is checking judgement rather than supplying it. Reverse the order, let the machine think first, and you produce exactly what the room feared: experience displaced, and the director’s own faculty quietly wasting.
Order is not the only thing that separates useful augmentation from theatre. The quality of the input decides whether any of this is worth doing. Generic, context-free prompting produces generic output, which is most of what the 46% reaching for a public tool are getting back. AI grounded in the organisation’s strategy, its history, its commercial position and its board materials is a materially different proposition, and far closer to genuine augmentation than a cold query to a consumer chatbot. Usefulness and exposure rise together, though, and that is the catch. The context that makes the tool genuinely useful is the same confidential, often price-sensitive material a director would have to feed into it, which is why two further principles become mandatory at exactly this point. Outputs must be treated with professional scepticism and verified before they are relied upon, and the tools that hold the organisation’s context must be approved, enterprise-grade systems rather than whatever public model is nearest to hand.
Whatever a board decides about use, the liability does not move
This is the point that turns the question from a philosophical one into a commercial one. A director’s accountability is fixed by law and regulation, and none of it shifts because a model helped prepare the analysis. Under the Companies Act, a director must exercise reasonable care, skill and diligence, judged partly against what may reasonably be expected of someone in the role and partly against that director’s own knowledge and experience. In regulated financial firms, the obligation is sharper still, with individual accountability allocated under the Senior Managers and Certification Regime and good-outcome obligations imposed by the Consumer Duty. An AI-assisted decision is, for these purposes, simply a decision; the assistance is invisible to the standard and to the regulator. That is the third principle, and the one the rest of the argument has been demonstrating: accountability stays with the director.
The practical exposures follow directly. A confidential board pack — or worse, inside information — pasted into a public model is a disclosure the director may struggle to explain afterwards. A decision resting on an AI summary that no one verified, which then proves wrong on a material fact, is the director’s to answer for, not the tool’s. A hallucinated figure or a quietly biased analysis carried into the boardroom unchallenged becomes part of a decision the board owns in full. And the exposure exists today, at the level of the individual director, whatever the board eventually decides about where to draw its line on use. That is precisely why the line-drawing can wait and the standard cannot. A board does not need to resolve the philosophical question of judgement before it protects its members from liabilities that are already live.
The cheapest governance available is a standard for the board’s own desk
The eight principles I brought to King’s are an attempt to write that standard down for directors’ own use, rather than another framework for governing the enterprise’s AI. They run as a set. AI should augment judgement, not replace it, and should be used only where it genuinely improves the board’s effectiveness, not for its own sake. Confidential and privileged material must be protected, and approved tools used in place of public ones. Outputs must meet professional scepticism and be verified. The director remains accountable throughout. Above these sit the conditions that make the rest workable: a board-level policy that makes clear what is and is not acceptable, sufficient AI literacy among directors to challenge an output rather than defer to it, and the discipline of using the technology ethically and in line with the organisation’s values. None of this is exotic. It is the ordinary governance reflex — decide, document, assign ownership, review — applied to a surface the board has so far exempted from it.
The decision this points to is modest and overdue. The shadow use that some in the room doubted was even happening is the clearest argument for not waiting: a board can adopt a policy for directors’ own use of AI now, name who owns it — usually the board together with the company secretary, who is often already the person experimenting — and set a cadence to revisit it as the tools change. The board has found a way to govern almost everything about AI except how it itself works. The standard it can apply to its own desk is the cheapest governance available to it, and the one place it has not yet thought to look.
If this is the kind of board-level analysis you want more of, subscribe to AI in the Boardroom. I write for directors, executives, and advisers who would rather understand what responsible AI adoption asks of them than be sold the technology or warned off it. The eight principles discussed here are available for download below, and future editions will continue to focus on the strategic, governance, and accountability questions that boards cannot delegate — including those that begin at their own table.



