Skip to content
Christoph Kassen

Strategic technology advisor / Cloud & AI / Munich

AboutServicesBlogContact
AboutServicesBlogContact
Back to Blog

What Your Board Will Ask About AI — And What Good Answers Look Like

Published on May 13, 20264 min read
AI StrategyTechnology and BusinessEngineering Leadership

Two years ago, when a board asked about AI, they wanted to know if the company was doing it. The answer was almost always yes — or at least, yes-adjacent. Something with a model, something with a pilot, something in the roadmap.

That's no longer the question.

The questions I hear now are about accountability, not capability. Many technology leaders aren't ready for them.

What changed

High-profile incidents changed what boards feel responsible for asking: harmful output, decisions nobody can explain, and shadow AI creating unknown liability.

Regulation is also maturing in Europe and the UK. Investor expectations are rising. The gap between what companies say about AI and what they do is harder to hide. The stakes went up, so the questions got harder.

The four questions

These are the four that catch organisations off guard most often.

"Do you know how AI is being used in this company?"

This covers the whole organisation, not just technology projects. How many employees use AI tools? Which ones? For what work and with what data?

At most companies, the answer is: we don't know exactly. Employees use unsanctioned tools with company data, and the organisation has little visibility. That is the governance gap.

A credible answer doesn't require a solved problem. "We haven't assessed this formally, but we're doing so" is a reasonable start. "We have a complete picture" needs evidence.

"What happens when the model gets it wrong?"

This is about accountability. If a wrong output leads to a bad loan decision, medical recommendation, or customer interaction, who owns the outcome? How do you remediate and disclose it?

The answer needs specific failure scenarios. What is the worst output this system could produce? Who bears the consequences? Which controls detect and address it?

Most technology leaders can answer this for the AI projects they actively own. Fewer can answer it for systems that were deployed twelve months ago and are now running mostly unattended. Even fewer can answer it for AI tools employees are using in their own workflows.

"Are we in compliance?"

The regulatory landscape for AI is still developing, but several frameworks are now law or near-law: the EU AI Act has risk classifications and conformity requirements for high-risk systems that apply from August 2026. Data protection frameworks (GDPR, UK GDPR) have always applied to personal data processed by AI systems; enforcement has become more active.

The board is asking whether someone has looked. Is there a legal or compliance view on the exposure? Are you tracking the relevant obligations?

The answer doesn't have to be "fully compliant with everything." It should be: "We know what applies, where we stand, and how we'll close the gaps."

"What are our competitors doing?"

This sounds easier than it is. A credible answer needs more than the claim that the company is ahead. Which competitors changed customer experience, operations, or the product with AI? Where would falling behind matter, and where wouldn't it?

If the technology leader doesn't know this, the board usually does. That asymmetry is uncomfortable.

What the CTO's job is in these conversations

The CTO doesn't need to evangelise. The board already believes AI matters. It needs honest translation.

What does the technology do? What are the risks? What is reasonable governance for a company of this size? What don't we know?

Emphasising upside and minimising downside is tempting. It also undermines credibility. Boards that feel managed ask harder questions next time.

The leaders handling these conversations well know the regulatory context, have worked through failure scenarios, and say what they don't know. Prepared, concrete, and honest usually lands well.


If you're preparing for this conversation, I'm happy to compare notes on the framing.

If something here was useful or you're thinking through a related problem, feel free to get in touch.

Back to Blog