RSS Amplifier

Her Executive Ascent™ · Jul 22, 2026

Five Questions Every Executive Should Be Asking About AI Before Their Board Does

0
Sign in to vote or save

Her Executive Ascent™, Lori Lalonde · Her Executive Ascent™

Executives face five pressing questions on AI governance before any board meeting forces the issue. Are we set up properly inside the organization? Who is responsible for AI governance? Who is accountable when something goes wrong? How are risks being assessed? Could anyone describe this to the board clearly? Most teams cannot. Grant Thornton's 2026 AI Impact Survey showed 78% of executives lacked strong confidence they could pass an independent AI governance audit within 90 days.

Most executive teams can tell you how many people in their organization have used a generative AI tool this month such as Claude, Copilot or ChatGPT. But only few know who is accountable in the event one of those people entered confidential client data into it.

And that is where the problem lies.

AI adoption has out-paced AI governance almost everywhere. IBM asked 2,000 technology executives about this in June. Seventy-seven percent of executives acknowledged that AI adoption is outpacing current governance capabilities.

Tools spread quickly because everyone wants to measure efficiency & productivity gains. The hype is real. Governance was considered to be something that would slow things down, so oversight was delayed.

The boards are catching up and they want answers. Deloitte's Global Boardroom Program polled nearly 700 board members and executives across 56 countries. The share of boards where AI isn't on the agenda at all dropped to 31%, down from 45%. But two-thirds still describe their own AI knowledge as limited or non-existent. So the questions are coming from people who can't evaluate the answers yet. So how will they know what good looks like?

Here are the five questions I think every executive should be prepared to provide their board a real answer to.

The Executive AI Governance Readiness Check

  1. Readiness. Is the data, the policy, and the shared understanding actually there?

  2. Ownership. Who holds this, by name, with a budget?

  3. Accountability. Who answers when it goes wrong?

  4. Risk. Are we looking past data privacy?

  5. Board readiness. Could we explain any of this today, specifically?

This isn’t a question about tools, but about organizational maturity.

What does AI readiness look like? Your data is clean enough to trust, your policies exist somewhere other than a wiki page nobody reads, and your people know the difference between being allowed to use AI and what specific scenarios they are allowed to use AI for. Most companies have none of that in place. They rollout the AI tool and maybe hold a prompt hackathon to create hype in the hopes that will result in an AI-ready team.

The further a company is from real deployment, the worse this gets. In Grant Thornton’s survey, only 7% of organizations still piloting AI were very confident they could pass an independent governance audit within 90 days. In organizations where AI was fully integrated, 74% expressed confidence. Only a fifth of companies had a tested plan for what to do when AI fails. This is astounding for a technology now sitting inside client deliverables and hiring decisions.

The honest test: pull ten employees from different departments and ask them what they’re allowed to put into an AI tool. If you get ten different answers, then your organization is not ready. You’ve just adopted another tool that will serve as a very expensive email writer.

Ask this question in most companies and you’ll get silence, looks of confusion, a random guess, or all of the above.

IT will say it’s a legal issue. Legal will say it’s a business issue. The business unit says someone above them must be handling it. The reality is that there is no real owner. And governance without an owner is a recipe for disaster.

So here’s my answer. One named executive, sitting at C-suite level, chairing a cross-functional council that includes legal, IT, risk, and the business units actually deploying the tools. The council builds consensus. The named executive carries the decision. Title matters less than authority: this works with a Chief AI Officer, a COO, or a General Counsel.

Most companies currently show oversight without an owner. Thomson Reuters Institute data indicated 44% of firms publicly claim an AI strategy and 40% report board or committee oversight, yet fewer than a third maintain a dedicated team or resources beneath it. IBM found that two-thirds of technology leaders say they’re being held accountable for AI systems they don’t fully control.

That is not proper governance, and it exposes one person to bearing the full responsibility on their shoulders.

Ownership and accountability sound like the same question. They are not.

Ownership is about who runs the governance program. Accountability is about who answers for what happens when AI gets something wrong, whether through biased hiring suggestions, fabricated figures in client reports or unchecked decisions.

None of these are hypothetical cases anymore. Organizations in IBM’s 2026 study reported an average of 54 AI agent incidents over a single year, each requiring human intervention. Seventeen percent were high severity and took more than 4 hours to contain. Of those, 37% led to data exposure or a security breach, and 17% raised compliance problems.

Fifty four incidents yearly equals roughly one per week. Someone needs to answer for each incident, or no one does.

If an AI system produces a bad outcome tomorrow, can you point to the person who signed off on the process that let it happen? If the honest answer is "it depends" or "we'd have to look into it", that's your answer right there.

Most risk conversations about AI are really just conversations about data privacy. That’s one risk among several, and treating it as the whole picture is how the other ones go unnoticed.

The fuller list includes:

  • Model risk. Is the output actually reliable?

  • Operational risk. What happens when the system fails silently instead of loudly?

  • Reputational risk. What does this look like publicly if it goes wrong?

  • Regulatory risk. Are you positioned for rules that don’t exist yet but are clearly coming?

If you’re building this from scratch, the NIST AI Risk Management Framework and ISO/IEC 42001 are where most people begin, and the EU AI Act sets the outer boundary of what regulators will eventually want to see.

This is the question that actually matters, because it’s the one that gets asked whether you’re ready or not.

When a board member inquires specifically how AI risk is managed, replies such as “we have encouraged teams to experiment” fall short.

Here’s our governance structure, here’s who owns it, here’s how we assess risk, here’s what we’ve caught and fixed” is the answer that keeps a board comfortable and keeps a leadership team credible.

And the exposure behind the question is now financial. Article 99 of the EU AI Act sets fines of up to €35 million or 7% of worldwide annual turnover for prohibited AI practices, and up to €15 million or 3% for breaches of most other obligations, including the high-risk system requirements. Those have been enforceable since August 2025. Your board has read those numbers too, or someone has read them to your board.

If you can’t say that with confidence right now, that tells you exactly where the work is.

Organizations that settle these questions early will govern AI more effectively than they adopt it. And governance is turning into one of the central leadership skills of the decade.

Read the original on herexecutiveascent.substack.com

Comments

Nothing yet. Say the first thing.

    Sign in to join the conversation.