What the Minutes Show: Boards and the Governance of AI
Over the past several years, artificial intelligence has moved steadily from the margins of organizational life toward the centre of ordinary operations. It now appears throughout the systems organizations rely upon and the work their people perform, frequently arriving without any deliberate decision to adopt it. For a growing number of organizations, the question is no longer whether artificial intelligence will appear in some form. It has already arrived, and that development carries real implications for boards of directors.
I have spent a fair amount of my career in and around boardrooms, working on questions of corporate governance, non-profit governance, and the oversight of various adjudicative and institutional bodies. One lesson that experience has reinforced is that boards tend to function best when they are able to engage an issue at the right level. They are not well suited to performing operational work, and they add little by descending into technical detail. Their contribution lies in the exercise of judgment, the framing of risk, and the assurance that the organization has addressed a problem with the diligence it deserves.
Artificial intelligence is unusually easy to place at the wrong level. Because the underlying tools are technical, it can be mistaken for a matter best left to information technology. Because management and staff are closest to its day to day use, it can appear to be a purely operational concern. And because it raises questions of privacy, confidentiality, and regulatory exposure, it is sometimes treated as a discrete legal problem to be resolved by counsel. In practice it tends to engage all of these dimensions at once, which is precisely why it belongs, at the appropriate threshold, within the board’s field of view.
None of this means that every use of artificial intelligence requires the board’s attention. Most will not, and a board that tried to supervise each new application would quickly exhaust itself to no purpose. The more important discipline is to recognize the threshold at which a particular use ceases to be a mere convenience and becomes a material risk to the organization. By the same token, the complexity of the subject is no reason for directors to hold back. The temptation to regard artificial intelligence as too novel or too technical for the boardroom is understandable, but it should be resisted. Boards routinely oversee matters in which they hold no personal expertise, and artificial intelligence is, in the end, another complex governance question of that familiar kind.
For Canadian directors, the relevant legal framework will be familiar. Directors are responsible for managing, or supervising the management of, the business and affairs of the organization. They owe fiduciary duties, and they are required to exercise the care, diligence, and skill of a reasonably prudent person in comparable circumstances. These obligations do not amount to a manual for the governance of artificial intelligence, but they are more than adequate as a starting point. When a new technology becomes significant to an organization’s operations, its risk profile, or its relationship with the people it serves, directors should expect to receive enough information to exercise genuine oversight rather than nominal awareness.
In my view, three considerations follow. The first is that artificial intelligence is best understood as a category of enterprise risk rather than as a matter of technical implementation. The second is that directors require a practical form of literacy, sufficient to ask informed questions of management and advisors, though well short of the technical fluency of a specialist. The third is that, should an incident occur, the governance record may prove central to how the organization is able to account for its conduct.
AI as Enterprise Risk
The first point concerns where artificial intelligence belongs within the organization’s overall assessment of risk. This may seem obvious, yet it is rarely how the technology actually enters an organization. More often it arrives quietly, and from several directions at once. An employee begins using a publicly available generative tool to summarize documents or prepare a first draft. A vendor introduces an AI feature into a platform the organization already uses. A manager, seeing an opportunity to improve productivity, encourages a team to experiment. Each of these steps is unremarkable in isolation, and each reflects the ordinary, incremental way in which most technologies make their way into institutional life. The difficulty peculiar to artificial intelligence is that uses which appear modest at the point of adoption can carry legal and institutional consequences that are anything but modest.
A single tool may quietly come to process personal information, confidential records, or privileged material. It may begin to influence consequential decisions, such as who is hired or how an internal complaint is handled. It may also create a dependence on external vendors whose data practices and contractual terms lie largely beyond the organization’s control. In each case the salient question extends past whether the tool produces a useful result, reaching the more demanding question of whether the organization genuinely understands the consequences of relying upon it.
None of this is foreign to the work boards already do. Financial reporting, cybersecurity, and major procurement all demand expertise that individual directors may not personally possess, and in each instance the board’s function is one of oversight rather than execution. Its task is to satisfy itself that management has identified the risk, assigned responsibility for it, established appropriate controls, and arranged for reporting proportionate to the significance of the matter. Understood in this way, artificial intelligence sits comfortably within an established governance tradition rather than outside it.
A board should be in a position to receive a clear account of how artificial intelligence is being used within the organization, the purposes it serves, the information it draws upon, and the persons responsible for its approval and ongoing supervision. Where the use is low in risk, that account may be brief. Where it is more consequential, it should be correspondingly fuller. The governing principle is proportionality, in that the depth of oversight ought to reflect both the nature of the use and the potential for harm.
For many organizations, a sensible first step will be a straightforward inventory of how and where artificial intelligence is actually in use. The exercise is unglamorous, but it is frequently indispensable, for it is impossible to govern a risk that has not first been identified. That task becomes considerably harder when the risk is dispersed across the organization through ordinary software, informal staff practices, and vendor-driven upgrades that no one specifically chose.
AI Literacy and Director Oversight
The second point concerns the kind of literacy directors actually require, a term that should be handled with some care. Literacy in this context does not mean technical mastery. No one should expect a director to understand model architecture, the composition of training data, or the underlying mathematics of machine learning. What directors require instead is a sufficient grasp of the categories of risk to ask intelligent questions, to recognize when an answer is reassuring in tone but empty in substance, and to sense when an organization is relying on assumption where it ought to be relying on control.
This becomes especially important precisely when a risk is novel, fast-moving, and potentially significant, which is to say in the very circumstances that most tempt a board to keep its distance. The proper response to such a moment is to lean in rather than to withdraw, to press far enough to understand what management knows, what it does not yet know, and how it proposes to proceed. None of this converts directors into operational managers. It does, however, require them to treat novelty and complexity as reasons for closer attention rather than as occasions for deference.
The questions a board should be willing to ask are not, for the most part, technical ones. They are questions of the plainest kind. Is artificial intelligence in use within the organization, and if so, by whom and with what information? Has management drawn any distinction between routine, low-risk uses and those carrying greater consequence? Are there applications that ought to require approval before they proceed, and is it clear what would prompt a matter to be escalated to senior management or to the board itself? Questions of this sort are simply the ordinary instruments of governance, applied to an unfamiliar subject.
They also guard against one of the more persistent difficulties in this area, namely the diffusion of responsibility. A new tool may be examined in turn by information technology, by legal, by procurement, and by those responsible for privacy or compliance, with each function considering the portion of the problem nearest to it and quietly assuming that the remainder is being attended to elsewhere. In the absence of a deliberate structure, responsibility becomes diffuse, and ownership of the risk comes to rest nowhere in particular.
It falls to the board to resist that drift. It can ask management to identify, by name or by role, who owns the risk associated with artificial intelligence; to fold that risk into the enterprise risk processes the organization already maintains; and to report on the uses that genuinely matter. Most usefully of all, it can ask the two questions that tend to be the most revealing, which are whether the organization has a policy that corresponds to what its people are in fact doing, and whether that policy is in fact being followed.
None of this should be read as an argument for excessive caution. There are many genuinely valuable applications of artificial intelligence, and organizations ought to feel free to pursue them. Sound governance does not impede innovation. More often it enables innovation, by making plain what acceptable use looks like and where accountability resides. Experimentation in itself is healthy and should be encouraged. What ought to concern a board is the particular kind of experimentation that proceeds without visibility, without structure, and without any clear point of accountability.
The Governance Record
The third point concerns the record itself, and the part it may come to play if something goes wrong. At the outset of an initiative the conversation is naturally dominated by the promise of the technology, by the prospect of faster work, better service, or reduced cost, and a board is right to remain open to the genuine possibility that artificial intelligence will improve how the organization performs. After an incident, however, the character of the questions changes entirely. Who authorized the use? What did the organization understand at the time, and what risks had it identified? Was there a policy in place, and was it observed? Was anyone charged with monitoring the system, and did any of this ever come before the board?
In that altered light, the documentary record acquires real importance. Board minutes, committee materials, management reports, and the risk register may demonstrate that the risk was identified, considered, assigned, and monitored, that the board asked reasonable questions, and that it relied appropriately on management and its advisors. They may establish that the organization took a measured and proportionate approach to a developing problem. They may also, of course, show very little at all.
A sparse record does not, in itself, signify poor governance. Minutes are not transcripts, and there are sound reasons not to commit every discussion to exhaustive detail. Where artificial intelligence is being used in ways capable of materially affecting the people an organization serves, however, whether its clients, its employees, or the public at large, some visible evidence of governance attention will be important. This is particularly so where the technology bears upon significant decisions or sensitive information. A system used merely to assist with the formatting of documents does not raise the concerns presented by one used to screen applicants for employment, to determine eligibility for a service, or to inform advice that affects a person’s legal rights. The graver the potential consequence, the more a board will wish to see that the matter received attention commensurate with its importance.
No board can reasonably be expected to prevent every possible failure. Even well-governed systems err, and the legal and technical terrain continues to shift. The pertinent question is therefore a narrower one, namely whether the board conducted itself with care, diligence, and skill in the circumstances as they actually were. Did it seek out sufficient information? Did it understand the nature of the risk? Did it satisfy itself that management had a process, and did it return to the matter as the organization’s use of the technology expanded? A coherent record assists in answering precisely these questions. It may show that the board asked management to map the organization’s existing uses of artificial intelligence, to separate the routine from the consequential, to put a workable policy in place, and to specify the circumstances in which a use or an incident must be escalated. No single one of these steps is dramatic. Taken together, they describe a board attending seriously to a real and developing risk.
Conclusion
Artificial intelligence has entered the boardroom because it has entered the organization, and it has done so in ways that touch operations, legal obligation, reputation, and institutional trust. This is not a concern confined to those organizations that build such systems. It applies with equal force to those that purchase such tools, that permit their staff to experiment with them, or that depend upon vendors who have quietly embedded artificial intelligence within familiar products.
For Canadian directors, the existing framework of duties is sufficient to begin. The obligation to manage or supervise the management of the organization, the fiduciary duties, and the requirement of care, diligence, and skill together point toward informed oversight whenever a new and material risk takes shape. Artificial intelligence does not ask directors to become technologists. It asks boards to understand enough to put useful questions, and to ensure that responsibility for the risk rests somewhere identifiable rather than nowhere at all.
For most boards the early steps are modest enough. They involve asking where artificial intelligence is in use and what information it touches, asking who is accountable for it and what circumstances would warrant escalation, and asking, in the end, the question that draws the others together. Were the organization’s use of artificial intelligence to be questioned at some later date, would its records reveal a considered and proportionate approach, or would they reveal a board that had simply looked away?
In my experience, directors grow markedly more comfortable with artificial intelligence once the subject is restored to the familiar language of governance. A board need not chase every technical development or react to every passing headline. It does need to recognize the moment at which a developing technology has become significant enough to warrant structured oversight, and for a great many organizations that moment has already arrived. The boardroom need not become a technical forum. It does, however, need to ensure that the risks associated with artificial intelligence are no longer invisible within it.
Should an artificial intelligence system one day fail, the inquiry will concern itself not merely with the conduct of the system but with the conduct of the organization, and in particular with the manner in which its board governed the technology’s use. Such an inquiry tends to begin where the present discussion ends, with a careful reading of the record and a single, unavoidable question: what would the minutes show?




Start the discussion!