BOARD BRIEF / SCALING THE AI STUDIO
Three decisions your board should make before it approves the next round of AI scaling spend
A working governance document. Read it before your next meeting, and take the questions into the room.
THE GOVERNING PROBLEM
The oversight duty moved, and the board did not
The board that approved an AI pilot approved something small enough to govern by exception. The AI Studio now being scaled is enterprise infrastructure that touches hiring, lending, and customer commitments. The duty of oversight attaches the moment a deployment becomes material to the enterprise, and by the standard Delaware courts apply, a board cannot discharge a duty it has not documented. No Delaware court has yet adjudicated an AI-specific Caremark claim. That absence is the reason to build documented oversight now, while it is still the cheapest insurance available, rather than after the first adverse event makes your board the precedent.
DECISION ONE
Will the board own an AI inventory, or accept management’s?
The policy question: Does the board possess, and review, its own inventory of every material AI system, naming for each its owner and whether it makes or shapes decisions about people, money, or safety?
Why it is urgent now: APRA’s 30 April 2026 letter to regulated entities named an inventory of AI tooling and use cases as a baseline expectation, not an aspiration, and told boards that recognizing the framework applies is not the same as operationalizing it. The SEC Investor Advisory Committee recommended in December 2025 that companies disclose how their boards oversee AI deployment. Both presume the board can see what it governs.
The governance architecture that resolves it: A board-owned AI inventory and decision map, reviewed by the designated committee and producible on demand. Not management’s inventory presented to the board, but the board’s, which is the document a regulator asks for first.
The question to ask next session: Can we produce our AI inventory right now, or would we have to ask management to go find out what we have deployed? If it is the latter, that is a governance failure, not an administrative gap.
DECISION TWO
Where is the accountable human, and can they actually override the system?
The policy question: For every AI system that makes or shapes a material decision, is there a named human who owns the outcome and holds real authority to override the system, not merely to review its output?
Why it is urgent now: Regulators have named reliance on unverified vendor assurances a governance failure, because the oversight obligation is non-delegable. A reviewer who cannot in practice stop a decision is a governance decoration, not a control. Accountability assigned to a function rather than a person is accountability assigned to no one.
The governance architecture that resolves it: An explicit accountability assignment for each material AI decision, naming the human, the authority, and the escalation path. This is the Accountability Contract Model applied at the board level: a specific assignment, not a declared value.
The question to ask next session: Name the human accountable for our highest-stakes automated decision, and tell me what authority they hold to stop it. If the answer is a team or a process, the accountability does not yet exist.
DECISION THREE
What would have to go wrong for the board to hear about it, and how fast?
The policy question: Has the board defined the escalation threshold that forces specified categories of AI failure upward to it within a defined time, and does it have a plan for what it does when one arrives?
Why it is urgent now: The duty of oversight is, at its core, a duty to ensure bad news travels upward in time to act on it. A board with no defined escalation trigger has accepted that it will learn of an AI failure when the regulator, the plaintiff, or the press does. The EU AI Act’s high-risk deferral to December 2027 changed a compliance date; it did not change this obligation, which Delaware created and Brussels cannot postpone.
The governance architecture that resolves it: A documented AI incident-response and escalation plan with a defined threshold and a defined board response, integrated into the board’s standing risk reporting.
The question to ask next session: Describe our AI escalation threshold and the last time we tested it. If we cannot describe it, we do not have one.
THE BOARD QUESTION BANK
Take these into the room
Can we produce our own AI inventory today without asking management to assemble it? For our highest-stakes automated decision, who is the named accountable human and what authority do they hold to override it? What is our AI escalation threshold, and when did we last test it? Is the Studio’s value being measured against a workflow case, or are we being shown adoption numbers? Where is the documented reporting line from our AI oversight committee back to the full board? Have we confirmed which of our vendor assurances are independently verified and which are inherited on faith? If a regulator asked tomorrow for our AI oversight record, would we produce a system or a charter amendment?
A board oversight system is not built for the directors who build it. It is built for the ones who inherit the seat. The board that stands up its AI inventory, its named accountable humans, and its tested escalation threshold now hands its successors a system they can operate on day one. The board that waits hands them a charter amendment and an adverse event to explain. One is built before the adverse event arrives. The other is assembled after it does, in response to the litigation rather than in advance of it.
This brief is the board’s portion of a larger body of work. The full Board of Directors white paper, including the four-element minimum viable architecture and the 30/60/90 day governance calendar with named owners, sits alongside function-specific papers for the CFO, COO, CHRO, CRO, and CIO/CTO in the Scaling the AI Studio research package. The board white paper is available without charge. A director who reads this brief and asks what the full architecture contains is asking the right question.