Atlas Webinar

92% of Directors Use AI, But Does Your Board Have a Policy?

The following is a recap of a recent webinar, 92% of Directors Use AI, But Does Your Board Have a Policy?, hosted by Robin Fleming, Chief Technology Officer at OnBoard, and Rick Doten, AI and Cybersecurity Advisor at Prescient Cyber Risk.

Key Insights

Key Insights

  • 92% of board directors have used AI for board work in the past six months, but 60% of them sit on boards with no formal AI policy.
  • Most boards can't get useful answers from AI because their underlying data is incomplete, inconsistently defined, or scattered across systems nobody's kept current.
  • Boards with an enforced AI policy rate their overall effectiveness 32 points higher than boards with no policy at all.

The Framework Most Boards Skip

Doten’s framework for what makes AI useful comes down to three layers: clean data (complete, accurate, no duplicates), contextual data (shared definitions so “high risk” means the same thing across the board), and governed workflows (documented processes that live in the system itself, written down where the whole team can find them). Skip any layer, and AI can’t reliably deliver.

Fleming connected this directly to governance. Boards running on email threads and shared drives get a fraction of what AI could otherwise offer, because the underlying data is scattered before AI ever touches it. The boards seeing real value consolidated their materials into a governed record first, then layered AI on top.

What Should Never Go Into a Public AI Tool

Compensation data, M&A materials, legal strategy, and financial projections should never touch a public tool like ChatGPT, Copilot, or Gemini. Once that content enters a public model, the board has lost control of where it lives.

Fleming pointed to what OnBoard calls the AI maturity ladder: no policy, then a written policy, then governance-grade AI that enforces the policy by design, so a board’s data never mixes with another customer’s, stays in its own region, and never reaches a public model in the first place.

The Security Questions Every Board Should Ask a Vendor

Doten’s advice doubled as a checklist: which models does the vendor use, is your data used to train them, are agents involved and how are they secured, and what frameworks verify security on an ongoing basis? Standard certifications like SOC 2 and ISO 27001 are table stakes. They don’t automatically extend to the AI layer sitting on top.

Accountability Doesn't Transfer to AI

Doten’s analogy: if your dog bites someone, that’s on you as the owner. Stewardship carries responsibility whether the action came from a person, an agent, or an AI output. Fleming added that governance platforms should show where every answer came from and admit plainly when they don’t have enough information to answer with confidence.

"You are the steward of the organization, and therefore you have responsibility and accountability."

Where to Start This Week

  • Find out which AI tools your directors are actually using. You can’t govern activity you can’t see.
  • Write down a simple policy, even a basic one. The board or governance committee sets expectations; management and IT handle implementation.

Bringing AI Inside the Governance Perimeter

Every thread here lands on the same foundation: AI only becomes safe to use well once board data lives in one governed record instead of scattered across inboxes and public AI accounts. AI Assist was purpose-built for exactly that. Board data stays contained, every answer is grounded and sourced back to the original document, and permissions travel with every interaction, the same access controls and audit trail that protect every other document in OnBoard.

As Doten put it during the Q&A, giving directors a paved road to do the right thing beats leaving them a bumpy road toward the wrong one.

Want to see governance-grade AI in action? Explore OnBoard AI.