Most AI governance documents get written once, filed, and never checked against what is actually happening. The board does not need a policy. It needs ten direct questions asked before any AI tool is given access to company data, and again at every renewal.
These are drawn from where the two leading 2026 frameworks, the NIST AI Risk Management Framework and the EU AI Act, actually converge: inventory, classification, contractual guarantees, and an audit trail. Ask them in the boardroom, not just in a policy binder.
- 1. Where is AI actually in use across the business?
Not just the tools IT approved. Internal models, AI features already embedded in SaaS you pay for, and the tools staff have brought in themselves. You cannot govern what you have not inventoried.
- 2. What does 'shadow AI' look like inside this business specifically?
Most leaders have no visibility into how much sensitive data staff paste into public AI tools. Find out before deciding what to do about it.
- 3. Which data classification tiers exist, and are they mapped to AI approvals?
High sensitivity data (contracts, financials, customer records) should only ever reach AI tools that meet a correspondingly high bar. If that mapping does not exist yet, that is the gap.
- 4. Does every AI vendor we use offer a genuine zero retention mode?
Not a marketing claim. A contractual guarantee that our data is never used to train a model outside our control, and that we can prove it.
- 5. Who can see what, and does the AI tool respect it?
An AI layer that ignores existing permission boundaries creates a new exposure path, even if every individual answer looks reasonable.
- 6. Is there an audit trail for every AI action, not just every AI answer?
Who asked what, what was returned, and what the AI did as a result. Without this, an incident review has nothing to review.
- 7. Is there a kill switch, and has it ever been tested?
The ability to immediately cut an AI tool's access when something goes wrong is only real if someone has actually pulled it once, in a drill.
- 8. What happens when an AI tool is wrong?
A defined escalation path, not an assumption that a human will catch it. The Workday 2026 productivity research found that for every ten hours an employee gains from AI, nearly four are lost fixing what it got wrong.
- 9. Which regulatory framework are we actually building against?
The NIST AI Risk Management Framework and the EU AI Act are the two doing the most work in 2026. Know which applies, and where the gaps are against it.
- 10. Who owns this, ongoing, not just for the rollout?
Governance that lives with one project team decays the moment that team moves on. It needs a permanent owner and a recurring review date.
Boards where these questions get asked directly, not delegated to a policy document, show measurably higher control maturity: better inventories, real risk assessments, and audit trails that actually get used when something goes wrong.
Where this connects to the Org Brain
A governed intelligence layer answers most of these questions by construction: it resolves identity and permissions before any data is read, it creates a full audit trail by default, and it never creates a new access path outside what already exists. Good architecture makes good governance the default, not an extra project.