| Board has never formally discussed AI | AI absent from agenda, no policy, ad hoc use by staff | AI added as a standing agenda item with a clear oversight map and policy | Directors move from "we should look at this" to a documented, repeatable oversight cycle that maps to existing duties. |
| Management proposes a significant AI investment | Board relies on the vendor pitch to assess it | Independent, plain-English read on benefits, risks, and assumptions | Directors can interrogate the business case, the controls, and the vendor claims with informed questions rather than taking the pitch at face value. |
| Staff are already using AI tools informally | Unknown, unmanaged, undocumented exposure | Visibility of shadow AI plus a usable policy and guardrails | The board gains line of sight and the organisation gains rules people can follow, reducing privacy, accuracy, and confidentiality risk. |
| Audit and risk committee wants AI in the risk framework | No AI-specific risks recorded or owned | AI risks captured in the existing register with owners and controls | AI risk is treated like any other material risk: identified, owned, controlled, and reviewed, not left as a vague worry. |
| Board literacy on AI is uneven | A few directors engaged, the rest unsure | Short briefings bring the whole board to a shared baseline | Every director can engage in the discussion and ask sensible questions, so oversight does not rest on one or two people. |
| Regulator or stakeholder asks how the board governs AI | Little evidence the board engaged with the topic | A documented oversight trail: policy, register, minutes, questions asked | The board can show it engaged properly with AI risk, which is what informed stewardship looks like in practice. |