AI Risk: The 10 Things Every Board Should Know (and Most Don’t)
Corporate governance has always lagged behind the risks it is meant to manage. Boards develop oversight frameworks for risks after those risks have become embedded in organisations — sometimes after the first major incident makes the gap impossible to ignore. The pattern with AI is disturbingly familiar: boards are approving AI investments at an accelerating pace and with genuine enthusiasm, while their understanding of the specific, material risks that AI introduces remains in most cases inadequate.
This is not a criticism of board directors as individuals. The AI risk landscape is genuinely complex, rapidly evolving, and technically challenging to understand. But the complexity of a risk does not reduce a director’s fiduciary obligation to understand and oversee it. This article identifies the ten AI risks that every board should understand — and the specific question each risk demands they ask of management.
1. Hallucination and Decision Quality Risk
Generative AI systems produce plausible, authoritative-sounding outputs that can be factually incorrect — a phenomenon known as hallucination. When AI-generated content is used in high-stakes business decisions — investment recommendations, legal analysis, medical guidance, regulatory submissions — undetected errors can have material consequences. The board question: which business processes are using AI-generated outputs in decisions, and what validation mechanisms are in place to catch errors before they cause harm?
2. Algorithmic Bias and Discrimination Liability
AI systems trained on historical data can perpetuate and amplify historic biases — producing systematically disadvantageous outcomes for protected groups in hiring, credit, insurance, and other high-stakes contexts. This is not a theoretical risk: there are already significant regulatory actions and litigation cases involving algorithmic discrimination in each of these domains. The board question: where is AI being used in decisions that affect individuals, and what bias testing and ongoing monitoring is in place?
3. Intellectual Property and Training Data Exposure
The legal landscape around AI-generated content and the training data used to create it remains unsettled but is rapidly developing. Organisations that use Generative AI to produce content may face IP claims from rights holders whose work was used in training. The board question: has the organisation received legal advice on its IP exposure from AI use, and is there a policy governing what data can be used with external AI systems?
4. Data Privacy and Confidentiality Risk
Every interaction with an external AI model carries a risk that confidential information is transmitted to a third party. Employees using consumer AI tools with customer data, financial information, or strategic documents may be inadvertently creating data protection violations. The board question: what controls are in place to prevent confidential data from being processed by AI systems outside the organisation’s data governance framework?
5. EU AI Act and Regulatory Compliance
The EU AI Act — the world’s first comprehensive AI regulatory framework — creates specific compliance obligations for organisations deploying AI in high-risk domains. Other jurisdictions are developing equivalent frameworks. Non-compliance carries significant financial penalties and reputational risk. The board question: has the organisation mapped its AI deployments against relevant regulatory requirements, and is there a compliance programme in place?
6. Cybersecurity and AI-Specific Attack Vectors
AI systems introduce new cybersecurity attack surfaces: prompt injection (manipulating AI systems through crafted inputs), data poisoning (corrupting training data to alter model behaviour), model theft, and AI-powered social engineering attacks. The board question: has the cybersecurity risk framework been updated to address AI-specific vulnerabilities, and are AI systems included in regular security testing?
7. AI Liability: Who Is Responsible When AI Gets It Wrong?
When an AI system makes a consequential mistake — a flawed medical diagnosis, an erroneous financial recommendation, a discriminatory hiring decision — the question of who bears liability is both legally unsettled and organisationally unresolved in most organisations. The board question: for each material AI deployment, is there a clear and documented accountability framework defining who is responsible for AI decisions and their consequences?
8. Vendor Concentration and Technology Dependency
Rapid adoption of AI tools from a small number of major vendors — Microsoft, Google, OpenAI, Salesforce — creates concentration risk: dependency on vendor reliability, pricing decisions, and product strategy that organisations cannot control. The board question: what is the organisation’s AI vendor concentration risk, and what is the contingency plan if a critical AI vendor changes its terms, pricing, or availability?
9. Reputational Risk from AI Errors
AI errors in customer-facing contexts can damage brand and customer trust rapidly and visibly. The board question: which customer-facing processes use AI, what is the quality assurance process for AI outputs in those contexts, and what is the escalation and communication plan when AI-related customer incidents occur?
10. The Governance Vacuum
In many organisations, AI deployment is moving faster than governance frameworks. Individual functions are deploying AI tools without organisation-wide policies, standards, or oversight. This governance vacuum creates risk across all of the dimensions above. The board question: is there an enterprise AI governance framework, and is there board-level visibility of AI deployments and their risk profiles?
What Good Board AI Governance Looks Like
The boards leading the way on AI governance are doing four things. They have received structured education on AI risks — not a single briefing, but an ongoing programme that updates as the landscape evolves. They have approved an enterprise AI governance framework that covers risk categorisation, approval processes, monitoring, and accountability. They have assigned specific board-level oversight of AI risk — typically to the audit and risk committee, with clear reporting requirements from management. And they have moved AI from a ‘technology agenda item’ to a standing strategic and risk topic that receives serious attention in every governance cycle.
The time to build this governance infrastructure is before an incident demands it. Boards that act now will be able to enable AI investment confidently, knowing that adequate safeguards are in place. Boards that wait will find themselves governing in crisis mode — a much more difficult and costly place to operate from.
Related Insights
The CFO’s AI Imperative: From Efficiency Gain to Strategic Transformation
Finance has always been an early adopter of technology — from double-entry bookkeeping to spreadsheets to ERP to cloud-based analytics. And finance has always been…
Read more
Building the AI-Ready Organisation: Why Technology is the Easiest Part
When most organisations begin an AI readiness assessment, they start with technology. Do we have a modern cloud infrastructure? A unified data platform? Access to…
Read more
The AI Workforce Paradox: More Productivity, More Uncertainty, and a Generation of Workers Who Don’t Know Where They Stand
The evidence that AI improves individual productivity is now overwhelming. Across dozens of controlled studies, knowledge workers with AI tools consistently outperform those without —…
Read moreSubscribe to our Monthly Newsletter and other News Updates
Receive our news and valuable perspectives on organizational effectiveness each month.