The AI Shortcut

Management wants to roll out an AI tool across the business to improve productivity. Some teams are already using similar tools informally, and the CEO is concerned that waiting too long may leave the company behind.

Risk Management

Management wants to roll out an AI tool across the business to improve productivity. Some teams are already using similar tools informally, and the CEO is concerned that waiting too long may leave the company behind.

However, the company has not yet finalised its approach to data use, confidentiality, human oversight or accountability where the technology produces an incorrect or harmful result.

What position should the board take?

Key Takeaways

The Status Quo Is Already a Risk Position

If employees are using AI informally, postponing an official rollout does not mean the company is not using AI. The board needs visibility into what is already happening.

Govern the Use, Not Just the Tool

The level of control should depend on what AI is being used for and what could happen if it gets the answer wrong. Low-risk productivity uses and high-impact decisions should not be treated the same way.

Put Basic Controls in Place Now

The company does not need to wait for a perfect AI policy before restricting access to sensitive data, approving tools, defining human accountability, and stopping unacceptable uses.

The Board Sets the Boundaries, Management Executes

The board should establish risk appetite, test strategic value and demand evidence that the company can manage the risks. It should not become the management team for AI implementation.

The board is not really deciding whether the company should start using AI. That decision has already been made in part. Employees are using AI tools informally, meaning the company already has exposure, even though it has not yet decided how to manage it. Simply delaying an official rollout does not return the business to a risk-free position.

The first task is to understand what is already happening. Which tools are being used? By whom, and for what? What information is being entered into them? Are employees using AI simply to draft or summarise, or are outputs influencing customer decisions, recruitment, financial analysis or other consequential work? These distinctions matter. Good AI governance is increasingly based on the context and risk of the use case, rather than treating every AI use as equally dangerous or benign. NIST’s AI Risk Management Framework, for example, calls for organisations to inventory AI systems, understand their intended uses, define risk tolerance and apply different levels of oversight according to context.

That is also why a company-wide rollout, as described in the dilemma, is probably too blunt. The board should first ask management what problem the tool is intended to solve and where it will be used. Using AI to produce a first draft of an internal document is very different from using it to screen job applicants, recommend credit decisions or analyse confidential client information. The board should be much more interested in the use and consequences of the technology.

The absence of a finished governance framework is not, however, a good reason to do nothing. Some protections can and should be introduced immediately. The company can specify which tools are approved, restrict the use of confidential information and personal data, clarify where human verification is required, identify uses that are currently prohibited, and establish a process for employees to report errors or unintended consequences. A full policy can follow. Waiting to resolve every policy question before setting any rules leaves the organisation exposed in the meantime.

A blanket prohibition is unlikely to solve the problem either. Where employees already see AI as useful, an outright ban may simply drive its use further out of sight. The better response is to bring existing use into the open, stop the activities that create unacceptable exposure, and give employees a legitimate route to experiment within defined limits. The OECD’s AI Principles similarly emphasise human oversight, transparency, security and continuing risk management throughout the life of an AI system, rather than treating governance as a one-off approval before deployment.

This suggests a phased approach. Low-risk uses can be tested first. Management can establish what benefits are actually being delivered, where errors occur, how employees use the technology in practice and whether the controls work. Wider deployment can then follow evidence rather than enthusiasm. More sensitive applications should face a higher threshold before they are introduced.

Human oversight also needs more thought than simply saying that “a human remains in the loop”. Someone should be clearly responsible for the work product. If an employee uses AI to prepare an analysis, make a recommendation or communicate externally, they cannot pass responsibility to the tool if the output is wrong. For higher-impact uses, the board should expect management to explain who can override the system, what that person is expected to check and whether they actually have the knowledge and authority to do so. Accountability has to remain identifiable.

There is also an important distinction between the board’s role and management’s. The board should not design the AI policy, select individual tools or run an AI task force. Its job is to determine the level of risk the company is prepared to accept, to assess whether AI adoption supports the business strategy, and to require management to demonstrate that appropriate controls, skills, and accountability are in place. Management can then determine the operating structure, whether that is an AI committee, a cross-functional working group or named executives with clear responsibility.

The board should also resist the argument that the company must adopt AI simply because competitors are doing so. “We cannot afford to be left behind” may be commercially important, but it is not yet a business case. Directors should ask what measurable benefit the company expects, which processes AI can materially improve, what it will cost, what new dependencies it creates and what happens if the technology does not perform as expected. AI should have to earn its place in the strategy like any other significant investment.

At the same time, directors need enough understanding of AI to ask those questions intelligently. They do not all need to become technologists, but a board that cannot distinguish between the capabilities, limitations and risks of the tools it oversees will struggle to challenge management. Access to external expertise can help when the board lacks sufficient knowledge, but it does not remove the need for directors to build a working level of understanding themselves. The direction of regulation is also moving this way. In the EU, for example, AI literacy requirements already apply to organisations deploying AI systems within scope.

Finally, this is as much a people question as a technology question. Productivity gains change how work is done, which skills become valuable and where judgement still matters. If employees are already experimenting with AI, management needs to understand why. Some of those employees may be the best source of information about useful applications and practical risks. Bringing them into the governance process can be more effective than designing rules without understanding how the technology is actually being used.

The defensible position, then, is to move forward, but not with an unrestricted company-wide rollout. The board should require management to establish what is already in use, address the most serious exposures immediately, define which uses can proceed and under what conditions, and expand adoption as the company learns what works. The governance framework does not need to be perfect before the company

Director Perspectives

A selection of perspectives on the dilemma.

“Take a phased approach with clear safety controls. Audit what employees are already using, create an interim policy, keep humans accountable for outputs and bring the right experts together to guide implementation.” Prof. Cikü Mathenge

“The teams already using AI may be some of the best people to involve. Understand which tools are in use, evaluate them and draw on those employees’ experience as the company develops its approach.” Vako Ferguson

“AI adoption should support the organisation’s business strategy rather than become a tool adoption for its own sake. Clear ownership, due diligence, training, governance and defined milestones should guide implementation.” Sandra Oyewole

“The board should support AI adoption, but not an unrestricted rollout simply because the company does not want to be left behind. The better approach is controlled and phased, with clear rules on data, human oversight and accountability.” Samira Nwaturuocha

“The board should push management to complete the analysis quickly. Look at different adoption scenarios and their consequences, involve the relevant decision-makers and experts, then communicate and implement the agreed approach across the organisation.” Olajobi Makinwa

“Treat AI output with the same critical scrutiny applied to any other tool or third-party input. Deal with the most serious risks immediately, accelerate the longer-term strategy, and ensure the board has enough fluency to challenge management rather than simply receive assurances.” Dr. Marjorie Ngwenya da Silva