TheResolution

AI in the Boardroom: Three Seats and a Chair | Global Directors Council

Written by Dee McGrath | May 6, 2026, 10:45:00 PM

Global Directors Council Roundtable
Global Directors Council Roundtable Co-hosted by Dee McGrath and BoardOutlook.

Insights from Our Co-Host

"When I think about AI from a director's vantage, I find I need a mental model to keep myself honest. My career was largely in technology in financial services, and even with that background I would describe myself as an enthusiastic amateur in this space. The honest position, I think, is that no one is an expert in AI right now in any settled sense — the field is moving too quickly. What we can do, and must do, is keep actively learning, with a very open mind about what the next twelve to eighteen months may demand of us.

The model I have come to use is three seats and a chair. The first seat is AI on the table — AI as the subject of governance. Capital allocation, third-party concentration risk, M&A optionality, the strategic moats AI may erode or build, the consumer harms emerging from rapid deployment. There is little that is exotic in this work; what is new is the velocity at which it moves, and the discipline it demands of us in setting risk appetite, demanding evidence over analogy, and ensuring deployment is matched by controls.

The second seat is AI at the table. This is AI as a tool for the board itself: research synthesis, scenario stress-testing, regulatory horizon scanning, peer benchmarking, real-time challenge in committee meetings. Used well, AI in this seat sharpens independent challenge and helps directors think through scenarios at a fidelity we have not previously been able to achieve. Used badly, it lends a hallucinated confidence to our own deliberation. That is a failure mode we cannot afford.

The third seat is AI beyond the boardroom — AI deployed at scale across the enterprise, in product, operations and customer interactions, and increasingly making decisions every day. The challenge here is a cadence mismatch. Machines decide every day; boards meet, at most, monthly, and always look in the rear-vision mirror. The reporting and controls we have relied on for slower-moving systems will need to compress, both in frequency and in form.

The chair, in this framing, is the director themselves. AI may widen the aperture, but the fiduciary duty, the independence and the consequence stay with the seat. The work for boards now is to embrace the technology without losing sight of what only directors can provide: judgement under uncertainty, ethical clarity, and the willingness to keep asking the question that no model would have generated."

— Dee McGrath

Executive Summary

AI is no longer a peripheral or specialist topic for boards. It is reshaping how organisations compete, how directors prepare, how risk is identified and how decisions are tested. Yet the gap between recognising AI's significance and integrating it meaningfully into board practice remains substantial — and in many cases, is widening rather than closing.

BoardOutlook recently convened a Global Directors Council roundtable in Melbourne, the third in a series following earlier virtual sessions with UK, US, Canadian and Singapore based directors. Held under Chatham House Rule, the session brought together non-executive directors and chairs from listed, private and government organisations across Australia, alongside a senior executive perspective from a globally scaled, AI-native financial services business. Sectors represented spanned financial services, health insurance, critical infrastructure, healthcare, technology and education, with specialist expertise in technology transformation, regulated lending, model risk management and behavioural assessment.

The data points in a clear direction. Across BoardOutlook's benchmarking of approximately 150 boards over the last two years, there has been a meaningful uplift in the proportion of directors self-identifying as advanced on technology and data capability — an approximately seven percentage-point shift toward expertise at the upper end of the band. At the same time, not a single board in that sample listed AI as an explicit skill on its matrix. AI appeared, when at all, as a sub-area under technology, data or digital oversight. The implication is the same one that surfaced in our prior sessions: boards are responding to the AI shift in their personal capability, but have yet to formalise it as a governance competence in its own right. The space between those two facts — recognised by individuals, unaddressed by boards — sat at the heart of this discussion.

Where AI Belongs in the Boardroom

Effective use of AI in the boardroom resists a single definition, but the framing offered by our co-host gave the conversation a useful structure: three seats and a chair. AI on the table is the subject of governance — what the company is doing with it, where the risks lie, where the strategic exposure sits. AI at the table is the tool directors use themselves — for preparation, pattern recognition, challenge and synthesis. AI beyond the boardroom is the technology deployed at scale across the enterprise, making decisions at a velocity that does not naturally synchronise with a monthly board cadence. The chair is the director themselves, the bearer of fiduciary duty and independence.

Most boards spend considerable time on the first conversation, structured time on the second, and very little deliberate time on the third. The appetite for that third conversation was unmistakable in the room. Several participants observed that they regularly use AI in their advisory or executive work but barely use it in their roles as directors — a gap they recognised as significant and largely unaddressed at board level. The framing that resonated most strongly was that AI's value in the boardroom lies in enhancing director judgement, not replacing it. AI can widen the aperture; it cannot relieve directors of the obligation to read, to challenge or to decide.

The Maturity Spectrum and the Sanctioning Question

Participants described very different starting points across their portfolios. At one end, organisations just beginning to set policy and approve tools, where the priority is establishing rules of engagement before unleashing scale. In the middle, organisations with evolving governance and a growing inventory of use cases, working through training, classification of data, and remuneration consequences for misuse. And at the other end, founder-led, AI-native organisations operating across jurisdictions where AI is embedded by design and "transformation" is not part of the internal vocabulary. The governance challenge is materially different at each end of the spectrum, and the assumption that one playbook applies is one of the more common errors in early board conversations.

A consistent and emphatic frustration cut across all three postures: the inadequacy of current board-portal AI capabilities. Directors described the available tools as too generalised, untuned to local regulatory and governance context, and unhelpful for the kind of probing analysis directors actually need. The practical workaround being adopted by some boards is to lift papers out of the portal and into a secure, organisation-controlled environment — for example a SharePoint instance with a sanctioned enterprise model — where management can pre-empt board questions and directors can interrogate the material more deeply. The view in the room was that this gap will close, but until it does, board-level AI use will remain uneven and partly improvised. The risk of inaction was identified clearly: prohibition does not mean absence, it means shadow IT.

Fluency or Expertise? The Skills Question Revisited

The skills-matrix discussion split the room usefully. One view: AI literacy is now baseline, like financial literacy, and the goal is universal director fluency rather than a token AI seat — particularly given that anyone calling themselves an AI expert today is likely overstating it. The counter-view: there is no substitute for the perspective of a director who has actually led technology transformation through prior waves, and that depth of executive experience does materially improve board performance.

The synthesis was both/and. Universal upskilling is non-negotiable and should be reflected explicitly on the skills matrix, not buried under technology or data oversight. But that does not preclude — and may complement — deliberate appointment of directors with substantive technology careers, particularly on boards facing significant transformation or operating in highly regulated sectors. The cybersecurity debate of recent years offers a useful parallel: most boards landed on enough fluency for everyone to ask the right questions, plus deliberate strength in specific seats. The same standard is now applying to AI, and the boards that recognise this earliest will be best positioned.

Trust in Two Forms: Data and Outputs

Trust was usefully unpacked as two distinct concerns: trust in data and trust in outputs. On the first — security, privacy, residency — the strong view was that for organisations already standardised on enterprise platforms, enterprise AI tools are governance-equivalent to the rest of the technology stack. The hype around "we cannot use AI" often misunderstands this; the relevant question is which models, hosted where, with what data, accessible to whom. On the second, the most reliable approach is to constrain AI to executing institutionalised methodology rather than asking open-ended questions. The analogy offered was that an AI is more useful as an analyst applying your framework than as an oracle producing its own. Without that constraint, what comes back tends to be the average of the entire internet — usable, but rarely sharp.

A connected observation was that AI capability rests on data foundations that few organisations have actually built. Several directors noted that organisations are launching into AI without first sorting out data management, with the result that searches return haystacks where no one is sure what is actually inside. The hidden tail of this is environmental and financial: data volumes balloon, storage costs compound, and the compute footprint becomes a board-relevant ESG concern in its own right.

Velocity, Cadence and the Governance–Management Line

A genuinely unresolved question is whether the monthly board rhythm remains fit for purpose in an AI-enabled organisation where decisions are being made every day at machine speed. Directors expressed scepticism toward the obvious answer of "more dashboards" — that pulls directors into management and blurs the line that has historically protected the board's strategic perspective. The view that emerged was that what is actually needed is sharper narrative synthesis from management on a slightly more frequent cadence, with better tooling for directors to interrogate the underlying data themselves between meetings. The line between governance and management may need to be redrawn deliberately rather than allowed to blur by default.

For boards with mature AI deployment, the velocity question becomes operational: at what stage does an AI use case come to the board, and in what form? The pattern shared was a layered model — global product roadmap visibility at every meeting with growing transparency on which initiatives are AI-driven; local regulatory gating before deployment in jurisdictions with specific obligations; and post-decision reporting through risk and credit committee channels. Several directors flagged the value of capturing AI initiatives the organisation has chosen not to pursue. The negative inventory is governance evidence in its own right.

The Agent Command Centre

A distinctive emerging governance practice is the model and agent inventory: a real-time view of which AI agents are deployed across the organisation, what task each is performing, when each was last reviewed by the model risk management function, and how each is performing against its mandate. This was variously described as an "agent command centre" or an "LLM gateway." As agentic tooling proliferates, this kind of inventory looks set to become a standard component of board reporting, in much the same way as a register of material outsourcing arrangements. Several directors observed that the practice resembles people management more than software management — agents have jobs, performance, and a need for periodic review.

Beyond the Board: People, Culture and the Operating Model

Across executive careers, change management is consistently the first casualty of business-case trimming, and the discussion suggested AI is no exception. Two telling anecdotes captured the point. First, software engineering teams that achieved significant productivity uplift through AI tooling — in one example, between forty-five and eighty percent — and then quietly stopped using the tools once they realised the productivity gains might surface uncomfortable questions about role design. Second, engineers who report that the cognitive shape of their week has inverted: Mondays and Fridays used to carry the heaviest cognitive load, with deep production work concentrated between Tuesday and Thursday. But AI has changed the rhythm of work: instead of reducing effort, it has redistributed and intensified it across the entire week. Humans are now spending more time continuously reviewing, validating, integrating and quality-assuring AI-generated outputs. The technology itself is the easy part. The harder challenge is redesigning the operating model, incentives, and cognitive sustainability of work in a world where oversight and judgment are required every day, not just at the edges of the week.

A more speculative but recurring observation was that AI is likely to dissolve the functional silos that have shaped corporate organisational design for decades. The implication for boards is that operating-model conversations may move from the periphery to the centre of strategy discussions over the next few years, and that approving the technology without engaging the structural consequences is increasingly an incomplete answer.

Cyber Risk, Reshaped on Both Sides

AI is changing the cyber threat model in ways that touch board-level risk taxonomies. Phishing sophistication is rising sharply, driven by AI on the attacker side, and the legitimate-looking volume is climbing rapidly enough that some directors described pausing on emails they would previously have actioned without thought. "Harvest now, decrypt later" makes post-quantum cryptography a current rather than future concern, particularly for organisations holding long-lived sensitive data. The calculus on patch cadence is also shifting: as AI accelerates vulnerability discovery, traditional "patch what is priority on a reasonable cycle" postures may no longer be defensible. Several directors flagged that the AI expertise needed to govern these areas is materially different from the expertise needed to govern AI in product or workflow — another argument for fluency over a single named expert.

Practical Applications: What Is Actually Working

A number of specific applications surfaced as immediately useful within the boundaries of considered governance.

  • Drafting and pressure-testing within structured frameworks: directors using AI to draft questions or papers reported the strongest results when they constrained the AI to apply known governance lenses or regulatory frameworks, rather than asking it to opine. The approach was likened to instructing a junior analyst to apply a defined methodology, not asking an oracle for an opinion.
  • Pre-empting board questions on the management side: in one organisation, papers are run through a sanctioned environment before they reach the board, allowing management to anticipate likely director challenges and tighten their material accordingly. The efficiency gain on both sides was described as significant.
  • Broadening perspective beyond local context: directors operating in domestically focused organisations described using AI to bring in global perspective on specific issues — competitor moves in other markets, regulatory direction in comparable jurisdictions, sector trends not yet visible domestically — at a depth that traditional desk research could not match in the time available.
  • Operational AI deployments visible to the board: in one financial services organisation, an AI chatbot has been handling customer service for several years and outperforms human agents on customer satisfaction metrics. AI-driven verification for lending applications has been piloted under detailed regulatory governance. Performance management cycles use AI summarisation of one-on-one transcripts to support quarterly reviews. None of these are speculative; they are in production, governed, and surfacing in board reporting.
  • Succession and skills planning: in a separate case shared in the session, a dual NZX/ASX-listed company used a governance-specific AI tool to model succession sequencing options for a board facing concurrent independence and tenure constraints. The chair of the people committee reported that work that would have taken her a full day of preparation without the tool was completed in two hours, and it produced a draft board paper of sufficient quality to anchor a board meeting discussion.

Practices That Build AI-Capable Boards

Several governance practices distinguished boards making meaningful progress from those treating AI as either a future problem or someone else's responsibility.

  • A clear mental model for AI in the boardroom. Articulating, at a board level, the distinct conversations being held — AI as governed subject, AI as director tool, AI as deployed capability — and ensuring each receives proportionate attention.
  • AI as an explicit skill on the board's capability framework. Naming AI capability directly on the skills matrix, and assessing it candidly, is a low-cost step that surfaces gaps before they surface elsewhere.
  • Sanctioned tooling and clear red lines. Boards moving past the experimentation stage are explicitly approving which tools may be used on board material, where data resides, and which categories of content remain out of scope. Hosting models within trusted infrastructure was viewed as a meaningful additional safeguard.
  • A model and agent inventory in board reporting. As deployed AI scales, a centralised inventory of models and agents in production — with provenance, ownership, last review date and performance against mandate — is becoming a credible expectation of board oversight.
  • Structured prompting over open-ended questions. The strongest results came when directors and management constrained AI to apply known frameworks rather than asking it to opine.
  • Hands-on, applied education. Programs combining governance theory with weekly applied exercises were valued more highly than briefings, and visible continuing education is increasingly expected by external scrutineers of board readiness.
  • Use case sequencing protocols. Establishing in advance which AI initiatives are reportable, which require pre-deployment board approval, and which sit within delegated management authority — and capturing the use cases declined alongside those approved.
  • Investment in change management as a first-order line. Treating people, culture and operating-model implications as a primary budget line, not the residual after technology costs are settled.

How BoardOutlook Supports Boards on AI Readiness

AI readiness in the boardroom needs to be measured and actively managed, not assumed. BoardOutlook's platform supports boards across the full set of processes that make this possible: board, committee and director evaluations; skills matrices that can incorporate AI as an explicit competence; CEO and chair evaluations; and Director 360s that surface how directors are actually showing up alongside the credentials they bring.

Where this becomes particularly powerful is in combination with AI itself. BoardOutlook's AI-powered tool, OutlookIQ, enables boards to interact with their performance, composition and evaluation data dynamically rather than through static, point-in-time reports. Drawing on a board's own underlying data, BoardOutlook's global benchmarking dataset and an institutionalised governance framework, the platform supports thought-partnered analysis across succession planning, capability gap identification, performance oversight, risk and scenario planning, and strategic priority alignment. All of this operates within hosted, audited infrastructure with deletion and retention controls explicitly engineered for the sensitivity of board data.

For boards ready to take AI readiness seriously as a governance priority — both as a domain to oversee and as a capability to build into their own work — BoardOutlook provides the tools, data and structured process to make that commitment concrete and sustained.

This paper was developed by BoardOutlook based on a Global Directors Council roundtable co-hosted with Dee McGrath. Participant contributions are reflected thematically and are not individually attributed, in accordance with Chatham House Rule. BoardOutlook's Global Directors Council brings together chairs and directors from across sectors and geographies to explore governance questions in a confidential peer setting. For information on upcoming sessions or the BoardOutlook platform, please contact the BoardOutlook team at jingqi.wu@boardoutlook.com.