For the executive who has to present it
The board has asked for an AI plan
Last updated
Justas Butkus is a fractional AI officer based in Vilnius, Lithuania, working with mid-market companies and scale-ups across the UK, EU and US. He writes board-ready AI plans and then owns their delivery, at two to four days a month.
Short answer
A board asking for an AI plan is rarely asking what AI can do. It is asking whether management has a defensible position on opportunity, risk and spend. A good paper names what you will not do, states who is accountable, and is honest about what is not yet known.
What is the board actually asking?
Almost never "what can AI do". They can read that anywhere, and several of them already have.
The question underneath is whether management has thought about this properly. Directors carry personal responsibility for oversight, and AI has arrived as a topic they are expected to have a view on, with very little to anchor that view to. The request for a plan is a request for something they can be satisfied by.
- Are we missing something our competitors are doing?
- Are we exposed – data, regulatory, reputational?
- Is money being spent, and is anyone accounting for it?
- Who is responsible for this?
What should go in the paper?
- Where we are now, honestlyIncluding the tools already in use that were never approved. Disclosing this yourself is far better than a director discovering it.
- What we are going to do, rankedA short list, in order, each tied to a specific business process rather than a technology.
- What we are deliberately not doingThe most credible section in the paper. It shows selection happened rather than enthusiasm.
- What could go wrong and what we have done about itRegulatory exposure, data handling, dependency, failure modes, and the oversight that addresses each.
- Who is accountableA name. Not a committee, not a function. Boards are reassured by names.
- What we will report and how oftenDefine the reporting line yourself before someone defines it for you.
Which questions should you be ready for?
| Question | Weak answer | What they are testing |
|---|---|---|
| What are competitors doing? | A list of press announcements | Whether you can distinguish activity from results |
| What is this costing us? | A software licence figure | Whether staff time and rework are counted |
| What is our exposure? | "We are compliant" | Whether you know which obligations apply to you |
| What happens if it gets something wrong? | "There is a human in the loop" | Whether the oversight is real or nominal |
| Why not do more, faster? | Enthusiastic agreement | Whether you have a considered pace |
Does the reason the board asked change what belongs in the paper?
It changes the emphasis, though the structure holds either way.
| What triggered the request | What to lead with |
|---|---|
| A general "what is our AI position" question | The ranked list and the exclusions, since there is no specific incident to address |
| A competitor announcement | A direct, unemotional assessment of whether it matters to you, before the roadmap |
| An incident, near miss or a customer complaint | What happened, what has already changed, then the roadmap |
| A diligence or insurance question raised externally | The governance inventory first, since that is what is actually being tested |
Reactive papers, written after something specific happened, are judged mainly on whether the immediate cause has genuinely been addressed. A strong roadmap does not compensate for a vague answer to what went wrong.
Does this differ for a private-equity-backed or investor board?
The structure is the same; the audience reads it differently. An investor board is more likely to ask about AI as a value-creation lever across the portfolio, not just as risk to manage, and it is more likely to compare your paper against what other portfolio companies have produced.
Naming what you are deliberately not doing matters even more here, since investor boards have usually seen several AI papers already and can tell the difference between a considered exclusion and an unexamined one. See AI leadership for private equity for the sector-specific version of this position.
What does "tools already in use that were never approved" actually mean?
This is the part management usually wants to soften, and it is the part that most improves the credibility of the paper if handled directly.
- Free consumer AI tools staff use for drafting, summarising or research. Almost every company has this, usually undocumented and usually not malicious.
- Departmental tools bought on a card without a central review. A team solved its own problem and nobody above them knows the data implications.
- Features quietly switched on inside existing software. A CRM or support platform ships an AI feature in an update, and it starts processing customer data with nobody having decided that it should.
None of these are usually catastrophic on their own. What damages credibility with a board is discovering them from a director's own team rather than from the paper you wrote.
What if the honest answer to something is "we do not know yet"?
Say so, specifically, rather than filling the gap with confidence the paper cannot support.
A line such as "we do not yet know what this would cost to run at scale, and we will have a defensible estimate after the ninety-day pilot" is a stronger answer than a number invented to avoid an awkward silence. Boards containing people who have run technology programmes before will recognise a manufactured number faster than they will penalise an honest gap, and a manufactured number that turns out wrong costs far more credibility later.
How does this change once there is already an AI committee or a named owner?
The first version of this paper is usually written from a standing start, with no existing structure to reference. Once a board has already approved a plan once, the second and third versions are shorter and more specific: less framing, more reporting against what was said last time.
The section that should always reappear is "what we are deliberately not doing." It is tempting to drop it once the organisation has some AI credibility, and that is exactly when a board most wants to see that the discipline has not slipped as ambition has grown.
What happens after the board approves it?
The paper is the easy part. What determines whether it was worth writing is whether anyone checks progress against it afterwards.
- Put the review date in the paper itself, not in a separate calendar invite that gets moved.
- Report against the ranked list specifically: what shipped, what did not, and why, rather than a general update on "AI progress."
- Revisit the exclusions list explicitly. If something you said you would not do has since become worth doing, say so and explain what changed.
A plan that is never referenced again after the meeting where it was approved has the same effect as not having written one, at the cost of having written one.
Should this be a slide deck or a written paper?
A written paper, circulated before the meeting, with slides used only to walk through it live. A deck built to be presented rather than read tends to compress the exclusions and the risk section into a single reassuring bullet each, which is exactly the part that should not be compressed.
Circulating the paper in advance also changes the meeting itself: directors arrive having formed questions rather than reactions, which produces a better discussion and makes the "why not do more, faster" question far less likely to derail the room.
What is the most common mistake in these papers?
Presenting a list of possibilities instead of a position.
A paper that describes ten things AI could do for the business, without ranking them or committing to any, reads as research rather than management. It invites the board to do the prioritising, which is not their job and will not go the way you want.
The second most common mistake is overclaiming certainty about return. Boards contain people who have watched technology programmes miss their projections for decades. A plan that says "we believe this process is expensive, here is what we will learn in ninety days, and here is the point at which we will stop if it is not working" is far more credible than one promising a number nobody can support yet.
Frequently asked questions
What should an AI plan for the board contain?
An honest picture of current usage including unapproved tools, a short ranked list of what you will do, an explicit statement of what you will not do, the risks and the oversight addressing them, a named accountable person, and a defined reporting cadence.
What does a board actually want to hear about AI?
That management has a defensible position on opportunity, risk and spend, and that someone is accountable. Boards are rarely asking to be impressed by the technology; they are asking to be satisfied that it has been thought about.
Should the plan promise a return on investment?
Be careful. Boards have watched technology programmes miss projections for decades. A stated hypothesis, what you will learn within a defined period, and the point at which you would stop is more credible than a figure nobody can yet support.
Who should present the AI plan?
Whoever will be accountable for delivering it. A plan presented by someone who will not own the outcome invites the obvious question of who will, and it is better to answer that in the paper than from the floor.
How long should the paper be?
Short enough to be read in full before the meeting. The ranked list and the exclusions matter more than the background, and the background is usually the part that gets padded.
Should we disclose AI tools staff are already using without approval?
Yes, in the paper itself. Free consumer tools, departmental purchases and AI features quietly switched on inside existing software are common and rarely catastrophic on their own. What damages credibility is a director finding out from their own team instead of from you.
What if we do not know the answer to something the board will ask?
Say so specifically, with a date by which you will know. A manufactured number that turns out wrong costs more credibility later than an honest gap costs now.
What should happen after the board approves the plan?
Put a review date in the paper itself, report against the ranked list specifically rather than generally, and revisit the exclusions list explicitly. A plan nobody references again is equivalent to not having written one.
If you have a board date and no paper
This is a well-defined piece of work with a hard deadline attached, which makes it one of the easier things to scope quickly.