# Board Talking Points: AI Risk Governance

## Opening Frame

> "AI represents both opportunity and risk. Our competitors are adopting AI rapidly -- we must do the same, but with guardrails that protect shareholder value and satisfy our fiduciary obligations."

---

## Key Metrics to Report

| Metric | Target | Why It Matters |
|--------|--------|----------------|
| AI Tool Inventory Coverage | 100% sanctioned + known shadow | You can't govern what you can't see |
| Vendor Contract Review | All AI vendors reviewed | Training rights = your liability |
| Employee Training Completion | 100% within 90 days | Policy without training = exposure |
| Data Classification Mapping | Complete | AI use rules depend on data tiers |
| Incident Response Readiness | AI scenarios in playbook | Response time drives breach cost |

---

## Questions the Board Should Ask Management

1. **Visibility**: Do we know which AI tools employees used last month and what data entered those systems?

2. **Policy**: Is our AI Acceptable Use Policy published, communicated to all staff, and enforced?

3. **Vendor Risk**: Have all AI vendor contracts been reviewed for training rights and data residency?

4. **Regulatory Readiness**: Are we prepared for EU AI Act compliance and SEC AI risk disclosure requirements?

5. **Incident Preparedness**: Does our incident response plan address AI-specific breach scenarios?

---

## Liability Considerations for Directors

**Duty of Care:**
- AI governance failures may expose directors to derivative claims
- "We didn't know" is not a defense when visibility tools exist
- Board should receive regular AI risk reporting (quarterly minimum)

**Regulatory Exposure:**
- SEC expects documented board oversight of material AI risks
- EU AI Act imposes direct obligations for high-risk AI systems
- State laws (California, Colorado, Illinois) create patchwork liability

**Insurance Implications:**
- D&O policies may exclude AI-related claims without proper governance
- Review coverage with broker as AI risk landscape evolves
- Document AI governance efforts for claims defense

**Recommended Board Action:**
- Add AI risk to standing board agenda
- Require management to present AI Bill of Materials annually
- Ensure AI governance ownership is clearly assigned (typically CISO + Legal)

---

## Closing Statement

> "We are taking a proactive approach to AI governance -- enabling innovation in low-risk areas while protecting the organization from data exposure, regulatory penalties, and reputational harm. We have clear ownership, defined policies, and measurable progress."

---

*For Board Meetings | AI Security for Leaders | v1.0*
