A 90-minute board session on AI risk should spend the first 25 minutes on what the organisation already runs and where the duty sits, the next 55 on the three decisions only the board can make, and the last ten converting those decisions into dated actions. It is a governance session with a decision at the end, not a briefing on how large language models work.
Most board AI sessions fail the same way. An expert explains the technology, directors nod, nothing is minuted, and the register looks the same in six months. The fix is to run it as a board meeting rather than a seminar: a pre-read, an inventory in the room, and named decisions on the way out. What follows is the agenda we use, and the artefacts that have to exist for each segment to work. It sits alongside the questions every UK board should ask about AI and produces the input for an AI risk appetite statement.
Key takeaways
- The session needs one page of pre-read and one artefact in the room: the list of AI systems already running. Without it, the discussion stays hypothetical.
- Ninety minutes is enough for three decisions: what is barred, what needs approval, and who is accountable. It is not enough to review individual tools.
- Directors do not need to understand model architecture. They need to be able to test a claim, which is a different skill and a faster one to teach.
- Every segment should end in something a company secretary can write down. If nothing is minuted, the session did not happen.
- Book the follow-up before the room empties. The value comes from the 90 days after, not the 90 minutes.
Before the session
Two things have to be ready, and both are the executive's job.
The one-page pre-read. Not a policy, not a strategy deck. One page covering: where AI is already in use, what decisions it influences, what data it touches, which suppliers are involved, and what the organisation could produce today if a regulator asked. Circulate it five working days ahead.
The inventory. A short table, printed, of every AI system in use. System, purpose, who owns it, what data it processes, whether it informs a decision about a person, and whether anyone has assessed it. Ten rows is usually enough to change the tone of the meeting. Boards that skip this end up debating AI in the abstract, which is comfortable and useless.
If neither exists, that is itself the finding, and the session becomes a scoping meeting. Say so in the minutes rather than pretending otherwise.
The agenda
| Time | Segment | Purpose | Output |
|---|---|---|---|
| 0 to 10 | What we already run | Replace assumption with the inventory | Agreed list, with gaps named |
| 10 to 25 | Where the duty sits | Connect AI to existing director duties, not a new rulebook | Shared understanding of the accountability route |
| 25 to 45 | What we will not do | Draw the barred-use line | A first barred-use list |
| 45 to 65 | What needs approval | Set the threshold between management and board | An approval threshold, in writing |
| 65 to 80 | Who owns what | Name the accountable executive and the reporting route | Named owner, named committee |
| 80 to 90 | What happens next | Convert discussion into dated actions | Actions with owners and dates |
Three notes on running it. Keep the first segment to ten minutes even when it is uncomfortable, because the discomfort is the point. Do not allow a supplier demonstration inside the 90 minutes; it turns scrutiny into a sales meeting. And have the company secretary in the room drafting the minute live, so the wording is agreed while people are still present.
Segment notes and the questions that work
0 to 10, what we already run. Walk the inventory row by row. The single most useful prompt is: "Which of these influences a decision about a person, and who reviews that decision?" Expect to find at least one system nobody had classified as AI, usually inside a product the organisation already licenses.
10 to 25, where the duty sits. The UK has no single AI act, so the duties are the ones directors already carry. For companies, section 172 of the Companies Act 2006 requires regard to long-term consequences, employees, customers, suppliers, community and reputation. Where the UK Corporate Governance Code applies, the FRC's code guidance frames risk appetite and material controls. Provision 29 of the 2024 Code then asks the board to declare on the effectiveness of its material controls, for financial years beginning on or after 1 January 2026. Our note on FRC AI guidance for boards sets out how AI lands inside that. Where personal data is involved, the ICO's AI accountability guidance is clear that the organisation must be able to show compliance, and that senior management cannot delegate the question to data scientists.
Fifteen minutes is enough because the message is short: nothing new has been invented for AI, and the existing duties already bite.
25 to 45, what we will not do. This is the segment that produces something. Ask directors to complete one sentence: "We will not use AI to ..." Common outcomes include no final decision about a person without a human who can change it, no confidential data in unmanaged public tools, no AI-generated content published without a named human owner, and no AI system live without an assessment. Five clauses is a good session. The list is a draft, and saying so out loud keeps the discussion moving.
45 to 65, what needs approval. Set a threshold rather than a list of tools, because tools change monthly. A workable default: anything that scores, ranks, flags or predicts something about a named person comes to the committee before pilot. Everything else stays with management inside policy. Then ask what evidence the board wants with each approval, which is where the register, the impact assessment and the human review log get named.
65 to 80, who owns what. Name one accountable executive for AI governance and one committee that receives the reporting. Inviting the chief information security officer to a meeting does not transfer the board's duty. If the answer is a new committee, the terms of reference matter more than the name, and for most organisations amended audit and risk committee terms are the better answer.
80 to 90, what happens next. Six actions maximum, each with an owner and a date. Anything without a date will not happen.
What to minute
The minute is the deliverable. A useful one records, in the board's own words:
- The AI systems the board was shown, and the gaps in that list.
- The barred uses agreed in principle, marked as a draft for policy.
- The approval threshold, and who applies it.
- The named accountable executive and the receiving committee.
- The evidence the board expects with the next AI paper.
- The date of the follow-up.
That is roughly half a page. It is also the first piece of evidence that AI oversight exists, which matters more than any slide from the session.
The 90 days after
The session sets direction. The following quarter turns it into governance.
| Timing | Action | Owner |
|---|---|---|
| Within 2 weeks | Complete the AI inventory, including embedded supplier features | Chief operating officer |
| Within 4 weeks | Draft the barred-use clauses into policy and circulate for comment | Company secretary |
| Within 6 weeks | Open the AI risk register with owners, controls and dates | Risk lead |
| Within 8 weeks | Agree the standing report format and the committee that receives it | Committee chair |
| Within 12 weeks | First AI paper to the board against the new threshold | Accountable executive |
Frameworks help here rather than lead. ISO/IEC 42001 gives the shape of a management system, the NIST AI Risk Management Framework gives a voluntary risk process built around govern, map, measure and manage, and the NCSC guidelines for secure AI system development give the security baseline. Pick the reference points before the first paper so management is not guessing at the standard.
Common mistakes
Teaching the technology. Directors govern decisions, evidence and accountability, not models. A session that spends 40 minutes on how transformers work has spent 40 minutes badly.
No inventory in the room. Without it, the board discusses a version of the organisation that does not exist.
Ending without a decision. A session with no minuted output is a briefing, and briefings do not change registers.
Running it once. Induction is a starting point. Boards that treat AI literacy as a single event find the ground has moved by the third quarter, which is the pattern behind the pacing problem.
Letting the supplier run it. A vendor session tells you what a product does. It does not tell you what the board should refuse.
Next steps
Ask the executive for the one-page pre-read and the inventory, and put 90 minutes in the next board diary rather than a future strategy day. If the inventory cannot be produced in two weeks, that answer is the agenda item.
For a baseline before the session, the Board AI Scorecard takes a few minutes and shows where the board stands across accountability, policy, risk, data and literacy. The board AI accountability check does the same for decision rights. Where a board would rather have the session facilitated, with the inventory work done first and the minute drafted properly, that is what our board AI training is for. The wider accountability model sits in our guide to board AI oversight.
Last reviewed: 3 September 2026.
Sources: Companies Act 2006 section 172; FRC Corporate Governance Code Guidance; FRC UK Corporate Governance Code 2024; ICO AI accountability guidance; ISO/IEC 42001; NIST AI Risk Management Framework; NCSC guidelines for secure AI system development.



