AI governance is a subset of technology governance, not a replacement for it. I’ve run technology governance sessions with more than 100 directors across various boards. Here’s a version of what typically comes up. Picture an IT head walking into a board committee meeting, a subset of directors who sit on this ahead of the full board, with a business case for an enterprise data platform: a hypothetical $35 million, four-year rollout, a deck full of dashboards and use cases, the word “AI-ready” on nearly every slide.
The committee digs in the way a smaller group with more time can. Which vendor. What happens to the legacy systems during migration. How many people do we need to run this once it’s live? Someone asks about data quality, because a platform is only as good as what feeds it. It’s a good discussion, specific and unhurried. Five or six people spend ninety minutes on one item instead of just five.
Then it goes to the board.
Same business case, same deck, much shorter conversation. A few directors nod at the AI-readiness language. One asks if this is really necessary this year. Someone says the committee already reviewed it, so it’s probably fine. The board approves.
The AI language signals importance without giving the board anything to hold onto. Once a project gets labeled AI-enabling, it starts to feel like a question only technical people can judge, so directors default to trusting the people who built the deck instead of asking their own questions.
But the questions a board actually needs to ask here have nothing to do with AI.
Is this platform worth $35 million? What happens after the money is spent, how do we increase the odds this actually gets used the way the deck promises? Which milestones tell us it’s on track? Do we have the people to run it, in terms of resources and headcount, or are we building something we can’t staff?
None of that requires knowing how a transformer model works. It requires the discipline to press on a number, the same discipline that works on any $35 million line item, whatever technology sits behind it.
The same pattern shows up in cybersecurity, and it’s arguably worse there because the language is vaguer. Management reports that they’ve “strengthened our monitoring posture.” Boards nod. Nobody asks what strengthened means. Is it more endpoints under watch, a lower threshold for flagging, more SOC headcount, or a new tool? “Strengthened” is not a metric. It’s a word chosen because it sounds like enough.
This is why I think the AI literacy conversation boards are having right now is aimed at the wrong target. The instinct is to send directors to learn AI, sit them through a primer on machine learning, maybe some linear algebra so the concepts don’t feel like magic. That has some value. It solves for the wrong gap though. The real gap is the habit of turning a vague, impressive-sounding claim into a specific, answerable question, whether the claim is about a data platform, a hospital records system, an ERP overhaul, or a cybersecurity upgrade. AI just happens to be the current version of that vague claim.
Training for this can’t be a single program because the need isn’t uniform. There’s a track for directors who just need to be conversant enough to ask good questions, skip the architecture, and get to oversight. There’s a deeper technical track for the rare director who is also a builder or a deployer, someone with real hands-on experience. And there’s a baseline every single director on the board should carry, not delegated to whoever happens to be the “tech person” in the room. Technology governance works the same way financial literacy does on a board. You don’t excuse half the directors from understanding the balance sheet because one member used to be a CFO.
Oversight can’t be one person’s job. A board that treats technology governance that way is building a single point of failure into its own oversight function. The fix is to make sure every director can look at “strengthened monitoring” or “AI-ready platform” and ask what that actually means in numbers before the money moves.
