Who answers when it is wrong
Boards are being asked to approve AI budgets on the strength of a demonstration. Three questions turn that into a decision a board can actually defend.
A management team brings a demonstration to the board. Something is summarised, something is drafted, a number appears in seconds that used to take a week. The room is impressed, because it is impressive. Then someone asks what it costs, management gives a figure, and the board approves it.
That is not a decision. That is a reaction to a demonstration, and it is how most Danish boards have been approving artificial intelligence for two years.
The problem is not that boards are being careless. It is that a demonstration answers the one question a board does not need answered. Whether the technology works is management's responsibility to establish, and by the time it reaches the boardroom it usually does work, at least on the case that was chosen for the room. The questions a board is actually accountable for are never the ones a demonstration addresses.
There are three of them.
1 · What is it trusted with?
Not what it can do. What it is allowed to do, written down, before it is deployed.
Every system in a company sits somewhere on a line between suggesting and deciding. A spreadsheet suggests. A payment rail decides. Most of what has been bought under the heading of AI in the last two years has been quietly installed nearer the deciding end than anyone at board level was told, because nobody drew the line explicitly and the software defaults to helpfulness.
The board's question is not technical. It is the same question it asks about a signing authority: what is the largest thing this can do without a person agreeing to it first? If management cannot answer that in one sentence per system, the answer is that nobody knows, and that is the finding.
I ask for it as a written boundary, in the language of the business rather than the language of the vendor. It drafts the reply; a named person sends it. It flags the claim; the assessor decides it. It reconciles the ledger; nothing posts without approval. Those are sentences a board can hold management to twelve months later. "We are using AI in customer service" is not.
2 · What stays under human decision, permanently?
The first question is about today's boundary. This one is about the boundary that does not move.
Every automation programme creates pressure to widen its own scope, and the pressure is legitimate: the thing works, the savings are real, and the next case looks like the last one. What a board owes the company is a short list of decisions that will not be automated regardless of how well it performs. Who is hired and who is let go. What a customer is told when something has gone wrong. Anything that ends a relationship. Anything a regulator would expect a named human to have weighed.
Write the list while the programme is small. It costs nothing now and it is nearly impossible to establish later, when the exception you want to protect is the one standing between the company and a number management has already promised.
This is not caution about the technology. I have spent three years working with it, I chaired an AI company, and I have money in two more. It is the ordinary discipline of deciding what a business is before an operating decision decides it for you.
3 · Who answers when it is wrong?
It will be wrong. Not often, if it is built well, and the failure will usually be small. The question is what happens in the fifteen minutes after somebody notices.
A board should be able to name, for each system with any real authority:
- the person accountable for its output — not the vendor, not the platform team, a person
- how a wrong output is detected, and whether that detection is automatic or depends on the customer complaining
- what is reversible, and what is not
- what is logged, well enough to reconstruct what the system was told and what it answered
That last one decides whether the other three are answerable at all. A system that cannot show its sources and cannot show its inputs cannot be investigated, only apologised for. When I build in this space, that is the property I insist on first: it answers with its sources, and it says so when it does not know. Not because it is elegant, but because the alternative is a company that cannot tell a regulator, a customer or its own board what happened.
What this looks like in a board pack
Three questions, one page, per system that has any authority at all. Boundary, permanent exclusions, accountable person. Reviewed when the boundary moves, which it will.
If management cannot produce that page, the finding is not that they are doing AI badly. It is that nobody has yet decided what the company is willing to let it do — and that is a governance gap, not a technology gap. It belongs to the board.
The part that has nothing to do with AI
I have sat on the other side of this. I ran three companies with a board and a chairman above me, and I know exactly what it is like to bring something to a board that I believed in and be asked a question I could not answer. It is uncomfortable, and it is the moment the board earns its fee.
The failure mode I watch for is not a board that says no. It is a board that receives a report which is comfortable rather than true, accepts a figure it cannot interrogate, and discovers eighteen months later that the boundary it thought existed was never written down.
The technology is new. That failure is not.