Field Guide · Board governance
Boards Need More Than an AI Risk Briefing
Boards need to understand AI as risk, but also as a question of institutional relevance, financial sustainability, academic value, and public trust.
The board got its AI briefing. It was thorough, sobering, and mostly about risk. Which is exactly the problem, and the reason governance does not end in the server room.
The general counsel walked the trustees through it: data privacy, cheating, deepfakes, liability, a slide with a padlock on it. The board asked good questions, thanked the presenter, and moved to the facilities report. Everyone left the room feeling appropriately serious, and the institution’s AI oversight was, in practice, complete for the year.
That briefing was not wrong. Everything in it was true. The problem is what it trained the board to believe: that AI is a threat category, something to be contained, like a cyber incident that has not happened yet. A board that only ever hears about AI as risk learns to be cautious about exactly the wrong things. It will ask whether the institution is protected. It will not ask whether the institution is still going to matter.
The institutional question
What does a board actually need to understand about AI beyond the threat assessment?
Boards exist to hold the long view: mission, solvency, relevance, public trust. AI now touches all four, and only one corner of that gets covered by a risk briefing. The question is not whether trustees can recite how the technology works. It is whether they can govern an institution whose operating environment, competitive position, and academic value proposition are all being reshaped at once, and whether anyone is helping them see that whole picture rather than the scariest slice of it.
What this looks like in practice
Start with what the risk-only frame misses. It misses the enrollment question: what happens to a tuition-dependent institution if faster, cheaper, AI-native alternatives keep improving while the demographic pool keeps shrinking? It misses the financial question: which of the institution’s cost structures assume a world where certain work was expensive because it was slow, and what happens to those assumptions now? It misses the academic one: what does this institution’s degree certify in a world where the tools can do some of what the degree used to prove? And it misses public trust, which is the board’s oldest job: how the institution uses AI on its students, transparently or not, fairly or not, will become part of its reputation whether or not anyone plans for that.
None of those are IT questions. They are fiduciary questions, and a board that never hears them is not being lazy. It is being briefed into a corner.
The literacy gap is real, but it is worth being precise about what kind. Trustees do not need to understand model architectures. They need working fluency in the institutional implications: enough to know that “we bought a tool” is not a strategy, that a pilot without success criteria is an anecdote, and that “our vendor handles that” is the beginning of a question, not the end of one. That fluency is buildable in a few honest sessions. What it requires is an administration willing to brief the board on what it does not know yet, which is harder than presenting the padlock slide.
Then there is the reporting rhythm. On most campuses, AI reaches the board as an occasional special topic: a briefing this year, maybe an update next. Occasional topics produce occasional oversight. The alternative is boringly structural, which is why it works. A standing place on the agenda, a short recurring report with the same handful of measures each time, so trustees can see trajectory instead of snapshots. What the institution is piloting, what it retired, what it spent, what incidents occurred, and one strategic question the administration is actually wrestling with. Fifteen minutes, four times a year, beats ninety minutes once.
Boards also need to know where their line is, because AI tempts them to cross it in both directions. Approving the institution’s risk appetite, its major AI investments, and the ethical boundaries it will not cross: that is board work. Choosing tools, writing policy, running pilots: that is administration. A board that drifts into picking chatbots has abandoned its actual post, which is asking whether the whole portfolio serves the mission. The most useful trustees on this topic will not be the ones who know the most about AI. They will be the ones who keep asking the mission question while everyone else is discussing features.
And a word for the presidents and cabinets who prepare these briefings: the temptation is to manage the board’s anxiety by curating the picture, all padlocks or all promise, depending on the quarter. Resist it. A board that discovers the fuller picture late, from a headline or an accreditor or a budget shortfall, becomes a worse partner at exactly the moment you need a better one. The institutions that will navigate the next decade well are the ones where the board and the administration can have the uncomfortable version of this conversation early, on purpose, together.
This is why the governance stretch of the map ends here. Everything in the last eight issues, decision rights, policy, data, security, fairness, compliance, contracts, eventually needs a place where someone asks: is all of this adding up to an institution that will still matter in fifteen years? That room is the boardroom, or it is nowhere.
The Atlas connection
In Atlas, our AI operating map, this is the board governance domain, and it closes the Foundation group — Decide — deliberately. The domains before it built the machinery of responsible AI decisions. This one asks who oversees the machine builders. Board literacy draws on everything the map has covered so far, the reporting rhythm surfaces what the risk assessments and inventories actually found, and the board’s strategic questions preview the parts of the map still ahead: Educate, Serve, Run, and Equip. If governance and org structure asked who is allowed to decide, board governance asks who makes sure the deciding still serves the mission.
Questions worth putting on the agenda
These are questions a board chair and a president could work through together before the next cycle.
- Has our board ever discussed AI as a strategic and financial matter, or only as a risk topic?
- Could our trustees say what the institution’s three most consequential AI commitments are right now?
- Is there a standing, recurring AI report to the board, or does the topic appear when something prompts it?
- Do we have a shared understanding of which AI decisions are the board’s and which are the administration’s?
- If a trustee asked “what does our degree certify in an AI-shaped world,” who in the room would own the answer?
The bottom line
A board that only hears about AI as risk will govern as if standing still were safe. The real fiduciary duty runs deeper: making sure the institution is not just protected from the technology, but positioned for the world the technology is making.
The padlock slide answers whether the doors are locked. Someone still has to ask whether people will keep walking through them.
Also published on LinkedIn: read this guide on the newsletter .