The Questions Your Board Should Be Asking About AI Security (But Isn't)
March 25, 2026 · 5 min read
Most board conversations about AI security fall into one of two failure modes: they are either so technical that non-technical directors disengage, or so vague that nothing actionable results. Here is what a useful one actually looks like.
I have been in a lot of board rooms. And in the past 18 months, I have watched the AI security conversation go from a future-state topic to a present-tense urgency. Every board is now expected to have a view on AI risk. Very few of them have been given the right tools to form one.
The problem is not that boards lack intelligence or curiosity. It is that the briefings they receive are often designed to demonstrate the CISO's technical knowledge rather than to equip the board to govern. Slides full of threat actor TTPs, attack chain diagrams, and vendor comparison matrices are interesting to practitioners. They are not useful to a board director whose job is to ask the right questions, not answer the technical ones.
So what are the right questions? Here are the ones I would want answered if I were sitting on a board today.
1. What AI are we actually using — including what our employees adopted on their own?
Every organization I work with has a gap between sanctioned AI use and actual AI use. Employees are using consumer AI tools to draft emails, summarize documents, analyze data, and write code. Some of that is happening with organizational data. Most of it is not tracked. None of it is governed. Before a board can assess AI risk, it needs an honest answer to this question. Not just what IT has approved, but what people are actually doing. A proper AI use inventory is the starting point for everything else.
2. What data are we feeding into AI systems, and where does it go?
The most immediate AI security risk for most organizations is not a sophisticated attack. It is an employee pasting sensitive client data into a consumer AI tool because it was faster than using the approved alternative.
The board should understand what categories of data are flowing into AI systems — and whether those systems retain that data, use it for model training, or share it with third parties. This is both a security question and a privacy and legal question. The answer is often "we don't fully know," which itself is important information.
3. How are we governing AI-assisted decisions?
As AI moves from productivity tool to decision-support system — in hiring, in credit, in risk assessment — the governance question becomes more complex. Who is accountable when an AI-assisted decision causes harm? What audit trail exists? How do we detect bias or drift?
This is not a hypothetical for most organizations. If you are using AI-assisted screening in hiring, AI-assisted fraud detection, or AI-assisted underwriting, these questions have legal implications that a board needs to understand.
4. What are our AI-specific incident response scenarios?
Most incident response plans were written before generative AI existed. They do not account for AI-enabled attacks, AI-generated deepfakes targeting executives, or compromise of AI systems that underpin operational processes. Ask whether yours does. AI is changing the attack surface in both directions: organizations are adopting AI, and attackers are using AI. The board should be asking whether incident response planning has kept up. Voice cloning, AI-generated phishing that defeats traditional detection, and manipulation of AI-assisted systems are not future threats. They are current ones.
5. What is our AI security investment thesis?
Security investment in the AI era requires a different conversation than traditional cybersecurity investment. The question is not just "do we have the right defenses" but "do we have the right governance, training, and technical controls to adopt AI safely while managing the expanded attack surface it creates?" This is a strategic question, not just a technical one. A board that is only asking about tools and budgets is missing the more important question about organizational readiness.
What Good Board Governance of AI Security Looks Like
The boards I see handling this best share a few characteristics. They have a standing AI risk item on the agenda — not a quarterly briefing, but a recurring conversation that evolves as the landscape does. They have a clear escalation path for AI-related incidents that reaches the board quickly. And they have invested in director-level education so that questions like the ones above can be asked intelligently, not just read from a prepared list.
The goal is not for board directors to become AI security experts. It is for them to be rigorous governors. That starts with asking better questions.
Next Step
Ready to strengthen your organization's resilience?
A 30-minute discovery call to discuss your cybersecurity posture, incident readiness, and whether advisory support is the right fit.