In a meeting it emerges that a proposal was largely drafted with AI. Nobody minds, and they are probably right not to. Then someone asks whether the figures in it have been checked. It goes quiet for a moment.
Nobody has done anything wrong. It was simply never agreed who checks the output, because it was never agreed that the tool would be used at all. The use arrived before the decision.
That is the pattern. Many organisations now use AI in several places. Sometimes visibly, through approved tools. Sometimes unnoticed, through employees, suppliers, or features that arrive with existing software. That use can be valuable, but it develops faster than the organisation can oversee at board level.
The risk is not that AI is used. The risk is that it remains unclear what AI is used for, what information goes into it, which outputs are trusted, and who remains responsible.
Why this is a board-level matter
AI does not only touch technology. AI touches decision-making.
As soon as AI is used for analysis, selection, assessment, communication or client contact, a board-level question arises: what does the organisation base its decisions on, and who can explain how they came about?
That applies to supporting use as well. A draft text, a client reply, an analysis or a recommendation influences real choices. If nobody has established where human assessment remains mandatory, false certainty follows.
AI thereby changes the relationship between speed and responsibility. You can work faster, and must at the same time remain able to explain what was used, what was checked, and who owns the decision.
What I typically see
- there is no policy, so there is no breach, so the subject never reaches the agenda
- employees use AI because the work would otherwise not get done, and do not report it, because there is nothing to report it under
- client information goes into a service whose terms nobody has read
- a supplier has added AI to an existing service and announced it in a release note nobody read
- outputs are used as substantiation without anyone having checked them
- there is one enthusiastic employee automating a great deal, and nobody knows precisely what
- an experiment has quietly become structural, without a decision and without an owner
- the organisation cannot tell a client whether, and where, AI sits in its services
- the question only reaches the table when a client raises it during a contract negotiation.
The result is that use runs ahead of decision-making. The organisation uses AI, but cannot explain where, how, with what data and under whose responsibility.
The questions this raises
AI does not first require a policy programme. It first requires clarity about use, responsibility and limits.
- Where is AI actually used, including at your suppliers?
- What information goes into it, and what does the agreement say about that?
- Which outputs influence decisions, communication or service delivery?
- Where is human assessment mandatory, and is that recorded anywhere?
- Who owns the outcome when it turns out to be wrong?
- What can you tell a client about your own use of AI?
- Which applications are acceptable, permitted within limits, or not permitted?
- What is needed to reconstruct how a decision came about?
- Which decisions about AI have not yet been taken explicitly?
These questions bring AI back to governable proportions. Not as hype or experiment, but as a question about decision-making, data, ownership and evidence.
What a Reality Check delivers here
A Reality Check does not examine every AI possibility and gives no advice on tooling. It starts from one concrete board-level question and makes visible where AI use touches risk, responsibility and demonstrability.
On this subject, that typically produces:
- a sharp picture of AI use within the chosen scope, including what arrives through suppliers
- the distinction between permitted, informal and unknown use
- insight into which information leaves the organisation and under what terms
- an established position on where human assessment ought to be mandatory
- identification of decisions not yet taken explicitly
- decision points for the board, sharp enough to make the trade-off yourself
- clear ownership for AI use and the risks attached to it.
What a Reality Check does not deliver is a cost estimate, an implementation plan, or a choice of tooling. Those choices stay yours.
The value does not lie in blocking AI. The value lies in making visible where AI influences decisions, data and responsibility.
In short
AI use is not risky because it is new. It becomes risky when use, permissions and outputs grow faster than decision-making, ownership and evidence.
AI does not take over risk appetite, ownership or accountability.
