The AI Questions Boards Should Ask in 2026
Last updated:
Why the board conversation about AI has changed
Two years ago the board question was whether the company was doing enough with AI. The honest answer was usually no, and management came back with a pilot.
Now most growing businesses have AI in several places: bought tools, features switched on inside existing software, an internal build or two, and staff using assistants on their own initiative. The question has shifted from adoption to oversight. Is the money producing anything? Is anything dangerous happening? Would we know?
Directors do not need to understand how the models work. They need to ask questions that separate a management team in control from one that is enthusiastic. These are the questions we would want asked if we were sitting on your board.
Questions about where AI is used
- Can you give us a complete list of where AI is used in the business, including inside software we already buy? A good answer is a list with owners. A worrying one is a description of the two projects management is proud of.
- How did you find the uses you did not start? If the answer is 'we asked around', ask what checks exist on expense claims and software invoices.
- Which uses touch customers directly or make decisions about people? These deserve separate attention and the answer should come quickly.
Questions about money
- What is our total AI spend this year, including staff time? Licences are the visible part. Integration, data work, review time and vendor usage charges are often larger.
- Which projects have measurably paid back, and how was that measured? Look for a baseline taken before the change. Our view on measuring AI ROI honestly is that without a baseline, the number is a guess wearing a suit.
- What have we stopped? This may be the most useful question on the list. A management team that has never killed an AI project is either very lucky or not looking.
- Where would the next pound of AI spend go, and why there? A good answer names the business problem first and the technology second.
If every AI project is reported as a success, the reporting is the problem.
Questions about risk and control
- What are the three AI-related failures that would hurt us most, and what stops each one? Ask to see the controls rather than hear them described. An AI risk register makes this a five-minute conversation.
- Where does AI output reach a customer, a payment or a decision without a person checking it? Not all such places are wrong, but each should be a deliberate choice.
- What customer or employee data goes to third-party AI providers, and under what terms? Specifically, whether data is retained or used for training.
- If our main AI vendor changed its pricing or withdrew a product next quarter, what would happen? Probing dependency, not expecting a disaster plan.
Questions about regulation and exposure
- Do any of our AI uses fall under the EU AI Act's high-risk categories, and what is our plan? Relevant for anyone with EU customers, staff or operations. Hiring, credit and insurance uses are the common ones. Dates have been moving, so the answer should reference legal advice rather than a remembered deadline.
- Have we checked our insurance cover for AI-related claims? Professional indemnity and cyber policies are being reworded, and exclusions can appear at renewal without much fanfare.
- Who in management is accountable for AI, and how often do they report to us? One name. If it is a committee, ask who chairs it and what it has decided.
What good answers sound like
Across all fourteen questions, the pattern of a strong answer is consistent.
| Good sign | Warning sign |
|---|---|
| Specific numbers with the method explained | Percentages with no baseline |
| Named owners for each use | 'The team is across it' |
| Projects stopped or scaled back | Everything described as promising |
| Risks described in business terms | Risks described only as 'hallucinations' |
| Honest 'we do not know yet, here is when we will' | Confident answers that change between meetings |
| Costs including people's time | Licence costs only |
Directors should also watch for the opposite failure. A management team so worried about risk that it has banned everything is not in control either. Staff are using AI anyway, just on personal accounts where nobody can see it.
How often boards should discuss AI
For most growing businesses, a short written AI update each quarter and one longer discussion a year is proportionate. The quarterly note should cover spend against budget, results on active projects, anything stopped, incidents and near misses, and changes to regulatory exposure. Two pages is plenty. If you already produce a regular board pack, add it as a section rather than creating a separate document.
The annual discussion is where strategy belongs: which bets to continue, which capabilities to build internally and which to buy. When boards ask SpiderHunts to contribute to that discussion, we usually find the most valuable thing we can offer is a plain account of what is technically realistic in the next twelve months, and what is being oversold.
Where the answers reveal gaps in data, integration or measurement, those are fixable engineering problems. Our enterprise AI service exists largely to close them.
Frequently asked questions
Should a board have an AI expert on it?
What AI metrics should a board see?
Is AI a board-level risk for a small company?
Who should be accountable for AI in management?
Preparing an AI update for your board?
We can help you pull together an honest picture of where AI is used, what it costs and what it has delivered, in a form a board can actually interrogate.
Related services
What we build for problems like this one