92% of Directors Use AI, But Does Your Board Have a Policy?
The following is a recap of a recent webinar, 92% of Directors Use AI, But Does Your Board Have a Policy?, hosted by Robin Fleming, Chief Technology Officer at OnBoard, and Rick Doten, AI and Cybersecurity Advisor at Prescient Cyber Risk.
Key Insights
Doten’s framework for what makes AI useful comes down to three layers: clean data (complete, accurate, no duplicates), contextual data (shared definitions so “high risk” means the same thing across the board), and governed workflows (documented processes that live in the system itself, written down where the whole team can find them). Skip any layer, and AI can’t reliably deliver.
Fleming connected this directly to governance. Boards running on email threads and shared drives get a fraction of what AI could otherwise offer, because the underlying data is scattered before AI ever touches it. The boards seeing real value consolidated their materials into a governed record first, then layered AI on top.
Compensation data, M&A materials, legal strategy, and financial projections should never touch a public tool like ChatGPT, Copilot, or Gemini. Once that content enters a public model, the board has lost control of where it lives.
Fleming pointed to what OnBoard calls the AI maturity ladder: no policy, then a written policy, then governance-grade AI that enforces the policy by design, so a board’s data never mixes with another customer’s, stays in its own region, and never reaches a public model in the first place.
Doten’s advice doubled as a checklist: which models does the vendor use, is your data used to train them, are agents involved and how are they secured, and what frameworks verify security on an ongoing basis? Standard certifications like SOC 2 and ISO 27001 are table stakes. They don’t automatically extend to the AI layer sitting on top.
Doten’s analogy: if your dog bites someone, that’s on you as the owner. Stewardship carries responsibility whether the action came from a person, an agent, or an AI output. Fleming added that governance platforms should show where every answer came from and admit plainly when they don’t have enough information to answer with confidence.
"You are the steward of the organization, and therefore you have responsibility and accountability."
Rick Doten — AI and Cybersecurity Advisor, Prescient Cyber Risk
Every thread here lands on the same foundation: AI only becomes safe to use well once board data lives in one governed record instead of scattered across inboxes and public AI accounts. AI Assist was purpose-built for exactly that. Board data stays contained, every answer is grounded and sourced back to the original document, and permissions travel with every interaction, the same access controls and audit trail that protect every other document in OnBoard.
As Doten put it during the Q&A, giving directors a paved road to do the right thing beats leaving them a bumpy road toward the wrong one.
Want to see governance-grade AI in action? Explore OnBoard AI.