Exvoria — A Working Manual
The Question Every Board Should Be Asking About AI
Six real questions. Why each one matters. What a bad answer sounds like, what a good one sounds like, and what to actually do next — built entirely on the real AICD/HTI framework, not invented.
By Michael Szafraniec · Exvoria
Draft manuscript — working copy
Front Matter
How to Use This Book
This isn't a book to read on a plane and put down. It's a manual to open at an actual board meeting, or a subcommittee session, or a planning day — and work through, out loud, with the people around the table.
That changes how it's written. Every chapter is built around one real question, not a topic. Not "AI strategy" as a heading with three paragraphs under it — the actual sentence a director would say out loud: "Do we actually know where AI already touches this organisation?" You can read that sentence to your board today, word for word, and it will do its job.
Why questions, not answers. Twenty-five years of turnaround work taught me the same lesson every time, in every sector: the thing that actually damages an organisation is almost never the thing everyone's already arguing about. It's the thing nobody's mapped, because nobody owns it and nobody's been asked the direct question. Answers age — a specific AI tool, a specific policy template, a specific regulation, all of it will look different in eighteen months. A good question doesn't age, because it's really asking whether your governance is actually keeping pace with how your organisation actually operates. That question is exactly as relevant in five years as it is today.
Why these six questions, specifically. They aren't mine. Four of them come directly from AICD and the Human Technology Institute's own Director's Guide to AI Governance — the closest thing Australia currently has to a real standard for board-level AI oversight, built with an SME/NFP-specific checklist. I haven't invented a proprietary framework and dressed it up as research. Where this book adds something, it's in making the reasoning behind each question explicit, and giving you real follow-ups for when the first answer you get is vague — which, in my experience running these conversations, it usually is at first.
Two more questions sit outside AICD/HTI's formal model but earned their place here anyway: whether external pressure has already landed on you (a funder, a regulator, an insurer, an incident), and an honest self-rating from the board itself. Neither is part of the official framework. Both change how urgently the first four questions need answering.
A word on Shadow AI, before you start. You'll see this term repeatedly. It refers to staff using AI tools the organisation never approved and may not even know about — not malicious, usually just someone trying to get their job done faster. It matters because it's no longer a theoretical risk one consultant is warning you about. In 2026, a Federal Court judgment — ASIC v Bekier, arising from Star Entertainment Group's handling of serious compliance failures — saw Justice Lee address AI's growing role in board decision-making directly, unprompted by the case itself, and say that boards should "formally adopt policies, rather than just wink at informal 'shadow' use." Months earlier, AICD and HTI had independently named the same risk, using the same term, in their own guide. A sitting judge and a directors' institute, working independently, landed on the identical specific problem. That's not a coincidence worth reading past.
How to actually run this with your board. Don't spring it as a test. The chapters are written to be read aloud, question by question, with space in each one for your board to answer honestly before moving to the next. If an answer is vague on the first pass, that's normal — that's what the follow-up questions in each chapter are for. The goal of a session using this book isn't to catch anyone out. It's the same goal as any real diagnosis: find out what's actually true, so you can decide what to do about it, instead of guessing.
One more thing, stated plainly because it matters: nothing in this book is trying to sell you anything. If working through it surfaces a real gap your board wants help closing, that's a separate conversation, on your terms, whenever you're ready to have it — not a condition of reading this.
Chapter 1 · AI Strategy
Do we actually know where AI already touches this organisation?
Not "should we adopt AI" — that question comes later, if at all, and it's often the wrong one to start with. This one is simpler and harder to dodge: right now, today, where is AI already being used inside your organisation, by whom, and does the board actually know, or is everyone assuming someone else has a handle on it?
Why this is the right question
Boards routinely skip straight to policy — "do we have an AI policy" — without first establishing whether they know what that policy would even need to cover. AICD and HTI's own framework puts strategy first for exactly this reason: you cannot govern what you haven't mapped. A policy written without first knowing where AI is actually in use is a document that addresses a guess, not the organisation's real exposure.
This is also the question that exposes the gap between what leadership assumes and what's actually happening. A CEO might confidently say "we don't really use AI" while, three floors down, a case worker is running client notes through a public chatbot to save time, a fundraising team is using an AI tool to draft donor communications, and an admin assistant is using an AI transcription service for board meeting minutes without anyone having decided that was acceptable. None of that is malicious. All of it is real exposure the board doesn't know about, because nobody asked.
What a bad answer sounds like
The most common bad answer isn't a wrong answer — it's a confident one that hasn't actually been checked. Something like: "I don't think we're really using AI in any significant way," delivered by someone who genuinely believes it, because nobody has ever actually surveyed staff on what tools they're using day to day. This is the single most common pattern in organisations that haven't done this work: a leadership team that's technically correct that no official AI initiative exists, and completely wrong about what's actually happening at the operational level.
A second bad-answer pattern goes the other way — a long, technical list of every AI-adjacent tool the organisation has ever trialled, delivered as evidence of thoroughness, but with no accompanying sense of risk. Knowing you use fourteen AI tools isn't the same as knowing which of them touch client data, financial records, or decisions that affect vulnerable people. Breadth without risk-weighting isn't strategy, it's inventory.
What a good answer sounds like
A good answer doesn't claim certainty — it demonstrates that the question has actually been asked properly, recently, and of the right people. Something closer to: "We surveyed program and operations staff last quarter, found six tools in active informal use, three of which touch client-identifiable data, and we've flagged those three as the priority for policy attention." It doesn't need to be exhaustive. It needs to show that someone went and looked, rather than assumed.
A good answer also distinguishes between AI the organisation has deliberately adopted (a CRM's built-in AI features, a chosen transcription tool) and AI that's crept in informally through individual staff choices. Both matter, but they carry different governance weight — the first is a decision the organisation can audit; the second is exactly the Shadow AI problem this book keeps returning to.
If the first answer is vague, ask this next
- When was the last time anyone actually asked staff what AI tools they're using day to day — not IT-approved tools, whatever they're actually using?
- Of what we know about, which of those touch client data, financial data, or decisions affecting vulnerable people?
- If a funder or regulator asked us this exact question tomorrow, in writing, could we answer it accurately within a week?
That last question tends to be the most clarifying one in the room. Most boards discover, answering it honestly, that they couldn't.
Worksheet
Where do we know AI is currently being used in this organisation?
Who did we ask to find this out, and when?
Of what we've found, what touches client data, financial data, or vulnerable people?
What's our honest confidence level in this answer — and what would it take to raise it?
Context
Why the People Building This Disagree With Each Other
This chapter isn't one of the six questions. It's context — read it once, early, and treat it as the reason the rest of this book insists on questions your board actually asks itself, rather than reassurance borrowed from whoever sold you the tool.
Here is a fact worth sitting with: the people building and studying frontier AI do not agree with each other about how dangerous it is. Not in the mild way experts disagree about most things — in a genuinely wide, publicly aired range, from serious people with real credentials on every side of it.
Andrew McAfee, a principal research scientist at MIT and co-director of the MIT Initiative on the Digital Economy, represents something close to the measured-optimist end: real risks worth managing, but not an inevitability of catastrophe. Roman Yampolskiy, a computer scientist working in AI safety and cybersecurity, has spent his career arguing that controlling a system smarter than its creators may be close to impossible in principle. Nate Soares, president of the Machine Intelligence Research Institute and co-author of a book literally titled If Anyone Builds It, Everyone Dies, argues from the far end of that same concern. Ed Zitron, a tech critic, pushes back from a different angle entirely — sceptical less of AI's raw capability and more of the industry's economics and honesty about what it's actually built. In September 2026, all four sat down together for a public debate that ran over two hours, arguing openly about whether the priority should be halting frontier AI research outright, or regulating the compute and market power of the companies building it — two genuinely different problems, often talked about as if they were one.
Separately, Daniel Kokotajlo, a researcher who left OpenAI rather than sign a non-disparagement agreement tied to a reported $2 million payout, has said publicly that he estimates a substantial probability — by his own account, around 70% — that advanced AI leads to human extinction. That is his stated view, not a settled fact, and other credentialed researchers — including people in the debate above — would put a very different number on it, or reject the framing of a single probability altogether.
None of these figures are fringe. All of them have real standing in this field. And they do not agree.
Why this matters for a board that will never build a frontier model
Almost nothing in this book concerns frontier AI systems capable of the scenarios these researchers argue about. Your organisation is very unlikely to be building the kind of system anyone in that debate is actually worried about. So why does it matter that the debate exists at all?
Because it settles, immediately, one question a board might otherwise be tempted to outsource: is this actually a serious issue, or is it hype a consultant is using to sell something? When people this credentialed, this senior, and this close to the technology cannot agree on the scale of the risk, that is itself the answer. This is not a manufactured concern. It is a genuinely open, genuinely serious question, being argued about in public by the people with the most information and the most at stake.
What follows from that, for governance purposes, is simple and practical rather than alarming: if the experts don't agree, a board cannot responsibly wait for consensus before acting, and it cannot outsource its judgment to a vendor's reassurance that everything is fine. A vendor's incentive is to sell you the tool. It is not to give you an honest account of a genuinely contested risk. That is precisely why the six questions in this book ask you to map your own exposure, name your own accountable person, write your own policy, train your own staff, check your own external pressure, and rate your own board honestly — rather than asking you to trust someone else's confidence.
You don't need to resolve the extinction-risk debate to do any of that. You just need to accept that reasonable, expert people disagree about how serious AI risk is in general — which means the burden of judgment about your own organisation's specific exposure sits with you, not with whoever is trying to sell you a system.
Chapter 2 · Governance Structure
Who is actually accountable for AI in this organisation, and are they reporting to us?
Not "is someone responsible" — almost every organisation will say yes to that, because it's a low bar and an easy thing to claim. The real question is sharper: can you name the person, and can you point to the last time they actually reported to the board on it?
Why this is the right question
AICD/HTI's framework treats governance structure as the second element for a reason: strategy tells you where AI is being used, but without clear ownership, that knowledge doesn't go anywhere. It sits with whoever happened to find it, and nothing changes.
This is also where good intentions quietly fail. Plenty of organisations can point to someone informally handling AI questions — often whoever's most comfortable with technology, regardless of whether that's actually their role. That's not governance, it's proximity. Governance means the board has deliberately assigned this, knows who holds it, and receives something back from them on a defined cadence. If none of those three things are true, there is no real structure, whatever the org chart implies.
What a bad answer sounds like
The most common bad answer names a person by default rather than by decision: "That'd probably be our IT manager" or "I think Sarah looks after that, since she set up our CRM." Neither of those is a board decision. They're both examples of a task landing on whoever was nearest when it needed doing, with no actual reporting line back to governance.
A second bad-answer pattern sounds more sophisticated but has the same hole in it: a named executive sponsor, a title, even a line in a strategic plan — but nothing has ever actually been reported to the board. Ownership on paper without reporting in practice is functionally the same as no ownership at all, because the board still doesn't know what it doesn't know.
What a good answer sounds like
A good answer names a specific person or role, states plainly what their mandate actually covers, and can point to when the board last heard from them. Something like: "Our COO holds this as part of her risk portfolio, and it's a standing item in our quarterly risk report — last update was six weeks ago, next one's due at the December meeting." It doesn't need to be a big structure. A small organisation doesn't need an AI committee. It needs one accountable person and a real reporting rhythm, however light.
A good answer also acknowledges scale honestly. A twelve-person NFP doesn't need what a listed company needs. What it needs is proportionate: someone named, a cadence, and confidence that if something went wrong, the board would actually hear about it rather than finding out from a funder or a journalist first.
If the first answer is vague, ask this next
- When this person reports to us, what form does that take — a line in a broader report, or its own agenda item?
- If something concerning came up with AI use tomorrow, what's the actual path from them noticing it to us hearing about it?
- Is this responsibility written down anywhere, or does it exist because everyone's informally agreed that's how it works?
That third question tends to be the one that surfaces the real answer. Informal agreement is not governance — it's a habit that can quietly stop the moment the person involved changes roles or leaves.
Worksheet
Who is the named, accountable person or role for AI governance in this organisation?
When did they last report to the board, and in what form?
Is that reporting line written down, or informal?
If something went wrong with AI use tomorrow, how would we actually find out?
Chapter 3 · Governance Practices
Is there a real policy, and does it specifically address Shadow AI?
Two conditions, both required. A policy that exists but doesn't mention informal, unapproved AI use fails the second half. No policy at all fails both. This question can't be answered "yes" on a technicality.
Why this is the right question
By this point in the book you've already met the term. Shadow AI — staff using AI tools the organisation never approved and may not fully know about — is not a hypothetical risk one consultant is flagging. A Federal Court judge addressed it directly, unprompted, in a 2026 judgment (ASIC v Bekier, arising from Star Entertainment's handling of serious compliance failures), saying boards should "formally adopt policies, rather than just wink at informal 'shadow' use." AICD and HTI's own guide names the identical risk, independently, using the identical term.
Most organisations that already have "an AI policy" wrote it before they'd actually mapped where AI was being used (Chapter 1) or decided who owns it (Chapter 2) — which means it's usually a generic document, adapted from a template, that addresses AI use in the abstract without addressing the specific tools staff are actually reaching for. A policy is only as good as the map and the ownership underneath it.
What a bad answer sounds like
The most common bad answer is a real document that doesn't actually do the job: "Yes, we updated our IT policy to mention AI last year." On inspection, this usually turns out to be a paragraph added to an existing acceptable-use policy, written generically, that says something like "staff should use AI tools responsibly" without defining which tools are approved, what data can and can't go into them, or what happens if someone breaches it. It exists. It doesn't govern anything.
A second bad-answer pattern is confident but backwards: "We haven't written a policy because we don't want to slow people down before we understand the space better." This sounds reasonable and is exactly the logic that produces the widest exposure — because staff aren't waiting for the organisation to "understand the space." They're already using whatever tools help them get through the day, policy or no policy. The absence of a policy doesn't pause AI use. It just means that use is happening entirely outside anyone's view.
What a good answer sounds like
A good answer describes a policy that was written after the organisation actually knew what it was governing — informed by the answers to Chapters 1 and 2, not written in a vacuum. It names specific categories: what data can never go into a public AI tool (client-identifiable information, financial records, anything covered by a duty of confidentiality), which tools are approved for which purposes, and what a staff member should do if they want to use something not yet on the list.
Critically, a good answer treats the policy as a living document, not a one-off compliance exercise: "We reviewed it against what we actually found in our AI use survey, updated it in March, and staff know where to raise a request for a new tool rather than just starting to use it quietly." That last part — a real, known path for staff to ask, rather than default to using something without asking — is often what actually reduces Shadow AI, more than the policy document itself.
If the first answer is vague, ask this next
- Does our policy name specific tools and specific data categories, or does it speak generally about "responsible use"?
- If a staff member wanted to start using a new AI tool tomorrow, do they know who to ask, or would they just start using it?
- When was this policy last actually tested against what staff are doing day to day — not just reviewed on paper?
Worksheet
Do we have a written AI policy? When was it last updated?
Does it name specific tools and data categories, or speak only in general terms?
Do staff know the actual path to request a new tool, rather than just using one quietly?
Has this policy ever been checked against what staff are actually doing — not just reviewed on paper?
Case Law Sidebar
ASIC v Bekier & Ors
This sidebar belongs alongside Chapter 3. It's the full context behind the Shadow AI quote used throughout this book, so you can see exactly where it came from rather than taking it on faith.
What the case was actually about
ASIC v Bekier & Ors is a 2026 Federal Court judgment arising from Star Entertainment Group's handling of serious anti-money-laundering and junket-related compliance failures. ASIC brought proceedings against the company's former CEO, its former Chief Legal and Risk Officer (who also held the Group General Counsel and Company Secretary roles), and its non-executive directors.
The outcome split cleanly along one line. Justice Lee found that the former CEO and the former Chief Legal and Risk Officer had breached their statutory duty of care and diligence under section 180(1) of the Corporations Act 2001 (Cth) — specifically, by failing to properly escalate serious risk information to the board. The non-executive directors were not found liable. ASIC could not establish that they had sufficient notice of the risks management had withheld from them, and ASIC did not appeal that outcome.
The core distinction the judgment draws is worth sitting with on its own terms, separate from anything about AI: a board cannot be held responsible for overseeing risks it was never properly told about. Escalation failure by management and oversight failure by the board are not the same thing, and conflating them lets the real failure — poor escalation — go unexamined.
Where AI enters the judgment
AI wasn't the subject of the case. Justice Lee addressed it directly and, it appears, largely unprompted by the pleadings themselves — because AI's growing role in how board papers get prepared and digested had become impossible to ignore by the time judgment was handed down.
His concern, in substance: directors may already be using AI informally to help prepare for board meetings — summarising papers, digesting large volumes of material — without that use being visible, discussed, or governed by any policy at all. That is the shadow use this book keeps returning to. His judgment states that boards should discuss and deliberately govern any AI use through formally adopted policies, "rather than just wink at informal 'shadow' use."
He was careful not to dismiss AI's usefulness outright. His view, in substance: AI can genuinely help directors deal with the sheer volume of material modern board papers involve, so long as its use is controlled and transparent, not informal and undisclosed. As he put it: technology "may assist comprehension, but it cannot displace… informed human judgment." The obligation on management, in his framing, is to present information "in a form that is both comprehensive and capable of proper digestion" — with AI a legitimate tool toward that end, but not a substitute for the judgment a director is actually there to exercise.
Why this belongs in a governance book, not just a legal one
Put the two halves of the judgment together and the lesson for boards sharpens considerably. The non-executive directors in this case were protected because they could show they hadn't been given the information they needed. That protection depends entirely on a board actually knowing what it doesn't know — which is precisely what Chapter 1 (mapping where AI is actually used) and Chapter 2 (naming who's accountable for telling you) are for. A board that can't answer those two questions isn't just under-governed on AI. It's in a materially worse position to demonstrate, if it ever needed to, that it exercised real oversight rather than simply not being told.
Shadow AI, in other words, isn't only a technology risk. In light of this judgment, it's also a records-and-evidence problem: if AI is quietly involved in preparing the papers a board relies on, and nobody has ever formally addressed that, a board may struggle to show — to a regulator, to a court, to itself — that its judgment was actually its own.
Chapter 4 · Governance Enablers
Has anyone actually been trained, or is everyone guessing?
Not "do staff know about AI" — most people have used a chatbot personally by now, and that's not the same thing as knowing what's appropriate to do with it at work, with organisational or client data on the line.
Why this is the right question
A policy (Chapter 3) only works if the people it applies to actually understand it, and understand why it says what it says. AICD/HTI place enablers last in their framework, but not because it matters least — it's last because it's the thing that makes the first three actually function in practice rather than on paper. A strategy that's been mapped, ownership that's been assigned, and a policy that's been written all still fail if the person using a tool on a Tuesday afternoon doesn't know the policy exists, or doesn't understand why it matters enough to follow it under time pressure.
This is also the element most often skipped, because it's the least glamorous. Writing a policy is a project with a defined endpoint. Training is ongoing, harder to point to, and easy to defer indefinitely in favour of things that feel more urgent. But an untrained staff member with access to a powerful AI tool and a deadline is exactly the scenario Shadow AI comes from — not malice, just a gap nobody filled.
What a bad answer sounds like
The most common bad answer treats general tech-savviness as equivalent to training: "Our staff are pretty tech-literate, I think they'd know what's appropriate." This confuses comfort using a tool with understanding its risks. Someone can be highly capable at prompting a chatbot and still have no idea that pasting a client's case notes into it may breach confidentiality obligations, because nobody has ever told them that specific thing.
A second bad-answer pattern points to something that happened once: "We did a session on this when ChatGPT first came out." AI tools and the risks around them have moved substantially since almost any "we covered this once" training would have occurred. A single historical session is not an enabler still functioning today — it's evidence one used to exist.
What a good answer sounds like
A good answer describes training that's specific, current, and tied to the actual policy from Chapter 3 — not generic AI literacy, but "here is what our policy says, here is why, here is what to do if you're unsure." Something like: "Everyone completes a short module when they're onboarded, and we run a refresher whenever the policy changes — most recently in March, tied to that update."
A good answer also acknowledges that training doesn't need to be expensive or elaborate to be real. The ACNC, for instance, runs a free course on using AI safely and responsibly for people working in the NFP sector — genuinely useful, low-cost, and a reasonable first step for an organisation with no training budget to speak of. What matters isn't the production value. It's whether staff can actually answer, in their own words, what they are and aren't meant to do — and whether that understanding is current, not historical.
If the first answer is vague, ask this next
- If we asked three staff members at random what our AI policy actually says, would they be able to tell us?
- When was the most recent training, and was it tied to our current policy or something more general?
- Do new staff get this as part of onboarding, or does it depend on who happens to mention it to them?
Worksheet
Has anyone in this organisation actually been trained on our AI policy specifically — not AI in general?
When was that training last delivered, and to whom?
Is it part of onboarding for new staff, or dependent on who happens to raise it?
If we asked three staff at random what's expected of them, what would they actually say?
Chapter 5 · External Pressure
Has a funder, regulator, insurer, or incident already raised this for us?
This question sits outside AICD/HTI's formal four-element model, but it changes how urgently the first four matter. A board with real gaps in strategy, structure, practice, and training is in a genuinely different position if a funder has already asked about AI governance in a grant condition than if the topic has never come up externally at all.
Why this is the right question
Governance gaps are common and not, on their own, a crisis — most boards are somewhere on this spectrum, and that's a normal starting point, not a failure. What changes the calculus is whether the outside world has already started asking. A funder adding an AI-governance question to next year's grant conditions, an insurer asking about AI use in a renewal questionnaire, a regulator issuing sector guidance, or an actual incident — a data exposure, a client complaint about an AI-generated communication — all mean the runway to get this right on your own terms is shorter than it might otherwise be, or may have already closed.
This is also the question most boards haven't asked themselves directly, because it requires someone to have been paying attention across several different channels — grants, insurance, regulatory communications, incident reports — and connecting them. It's rarely anyone's single job to notice all of it at once.
What a bad answer sounds like
The most common bad answer is genuinely honest but incomplete: "Nothing's come up that I'm aware of." The qualifier is doing a lot of work. It's frequently true that nothing has been escalated to the board specifically, while something has in fact landed at an operational level — a program manager fielding a funder's question, an admin team member noticing new wording in an insurance renewal — and simply hasn't made its way upward, because nobody thought it was significant enough to flag, or didn't know it was relevant to AI governance at all.
What a good answer sounds like
A good answer reflects an actual check, not just recall: "We reviewed our last three funding agreements and our current insurance policy specifically for this — nothing yet, but we've flagged it as something to watch for in the next renewal cycle." It treats external pressure as something to actively monitor, not just something the board would notice if it happened to be big enough.
If the first answer is vague, ask this next
- Have we actually checked our recent funding agreements and insurance renewals for AI-related wording, or are we assuming we'd have noticed?
- Who in this organisation would be the first to see a funder or regulator raise this — and do they know to tell us?
- Has anything AI-related come up informally — a client question, a staff concern, a near-miss — that never got formally reported?
Worksheet
Has any funder, regulator, insurer, or incident raised AI governance with us, directly or indirectly?
Have we actually checked recent agreements and policies for this, or are we assuming we'd know?
Who would be first to see this coming, and do they know to escalate it?
Chapter 6 · Honest Self-Rating
Where would we actually say we sit — ahead, keeping pace, or behind — and why?
The last question in the sequence, and in some ways the hardest, because it asks the board to state a judgment about itself rather than report a fact.
Why this is the right question
Every question so far has asked for information: what's being used, who owns it, whether a policy exists, whether training has happened, whether pressure has already landed. This one asks the board to synthesise all of that into an honest verdict — and to notice whether that verdict matches how the organisation has been talking about AI internally.
It's common for a board to have several real gaps identified across the previous five chapters and still describe itself, informally, as "doing okay" on AI — not out of dishonesty, but because there's no single moment that forces the synthesis. This question is that moment. It's also the question most likely to produce genuine disagreement around the table, which is a feature, not a problem: if three directors say "ahead," one says "behind," and nobody can point to why they disagree, that gap in shared understanding is itself worth knowing about.
What a bad answer sounds like
The most common bad answer is confident without being checked against the previous five chapters: "I'd say we're in reasonable shape." Asked to justify it against what was actually written down in the worksheets for Chapters 1 through 5, the confidence often doesn't hold — not because the board was lying, but because "reasonable shape" was a general impression, not a conclusion drawn from the specific answers already given.
What a good answer sounds like
A good answer references the previous chapters directly: "Looking back at what we've actually written down — we're solid on strategy, real gaps on structure and training, and we haven't checked external pressure at all. On balance, I'd call that behind, not ahead, and I think we should say that plainly rather than round it up." It treats the self-rating as a conclusion drawn from evidence already gathered, not a separate, softer impression.
If the first answer is vague, ask this next
- Looking back at Chapters 1 through 5, which specific answers support that rating, and which don't?
- Does everyone at this table actually agree with that rating, or are we assuming agreement without saying so?
- If we're honest, is this rating based on what we've established today, or on how we generally feel about the organisation?
Worksheet
Based on everything answered in this book so far, where do we actually sit — ahead, keeping pace, or behind?
Does everyone in this room agree with that rating? If not, where's the disagreement?
What would need to change for that answer to be different in six months?
Global Context
Beyond Australia: How This Compares Internationally
Everything in this book so far is built on Australian sources — AICD, HTI, ACNC, a Federal Court judgment. That's deliberate: it's what's actually governing you right now. But it's worth knowing, briefly and honestly, where Australia sits against what other jurisdictions are doing, because the direction of travel matters even for organisations that will never operate outside Australia.
The European Union has already made this binding
The EU's AI Act is not guidance. It's law, and as of August 2026 its core obligations are fully in force — risk classification, human oversight, documentation, and accountability requirements now apply in full to organisations deploying high-risk AI systems in the EU. Board-level AI oversight there is treated as a legal governance obligation that cannot be delegated away, not an aspirational standard a board can choose to adopt or not. An Australian NFP with no European operations isn't bound by any of it. But it's a real, working example of what "AI governance is compulsory, not optional" looks like once a jurisdiction commits to it — and it's worth noticing that Australia's own regulators (ACNC, AICD/HTI) are still operating in guidance and best-practice territory, not binding law, which is a meaningfully different starting position.
The United States has no single answer — it has fifty potential ones
There's no comprehensive federal AI law in the US. What exists instead is a genuine, fast-moving patchwork at state level. Colorado repealed and replaced its original AI Act in 2026 with a revised law governing "automated decision-making technology" in consequential decisions, with substantive obligations commencing January 2027. California has introduced new regulations under its existing privacy law addressing automated decision-making in "significant decisions" about consumers. Other states, including New York, have moved on oversight structures specifically aimed at the largest AI developers. None of this is settled, and an organisation operating across US states — which is not your situation, but is worth knowing about regardless — faces a genuinely fragmented compliance picture, not one law to check against.
Where that leaves Australia
Squarely in the middle, and moving. As the ACNC's own guidance states plainly: Australia does not currently have a formal regulatory framework for AI. What exists instead — AICD/HTI's Director's Guide, ACNC's sector guidance, the reasoning in ASIC v Bekier — is best practice and case law, not statute. That's precisely why the six questions in this book matter as much as they do: in the EU, a board that fails these questions is failing a legal requirement. In Australia, today, a board that fails them is failing a standard nobody can yet fine you for — but every signal, from a Federal Court judge addressing AI unprompted in a 2026 judgment to a directors' institute publishing a formal framework, points toward that gap closing, not staying open. A board that gets this right now, while it's still a choice rather than a legal obligation, is simply choosing to get ahead of something the EU shows plainly enough is coming.
Part 4, Chapter 1
Running the Session
Who should be in the room
At minimum: whoever chairs the board, whoever holds executive responsibility for operations (a CEO or equivalent), and anyone already informally handling AI questions even without a formal mandate — precisely because Chapter 2 exists to test whether that informal arrangement is real governance or just proximity. A subcommittee can run this instead of the full board, but the six worksheets and the self-rating in Chapter 6 should go back to the full board before anyone treats the answers as final. This isn't a subcommittee's private verdict — it's meant to become the board's shared, honest position.
How long it actually takes
Longer than most boards expect on the first pass, shorter on every pass after that. Budget ninety minutes for a first full run-through if nobody has prepared answers in advance — six questions, a genuine discussion on each, and time to actually fill in the worksheets rather than talk past them. A prepared board, where the accountable person from Chapter 2 has gathered real information beforehand, can do it in under an hour. Don't compress the first session to fit a shorter meeting slot. A rushed first pass produces the "reasonable shape" answer Chapter 6 warns about — confident, unchecked, and wrong.
The one rule that makes this work
Nobody in the room should already know all the answers before the session starts. If the accountable person from Chapter 2 has quietly gathered the real information in advance — good, that's exactly what should happen — but the board still needs to hear it live, discuss it, and write it down together, rather than rubber-stamp a report. The value of this book isn't the six questions on the page. It's the conversation they force a board to actually have, out loud, in the same room, at the same time. A board that reads the questions individually and emails back short answers has skipped the part that actually works.
Sequencing
Run the six chapters in order. Each one is written to build on the last — Chapter 1 tells you what to govern, Chapter 2 tells you who's accountable for it, Chapter 3 tests whether that accountability produced a real policy, Chapter 4 tests whether anyone actually knows what the policy says, Chapter 5 tests how urgent all of this actually is, and Chapter 6 asks the board to say, honestly, where that leaves them. Skipping ahead to Chapter 6 without the first five is exactly the "reasonable shape" trap — a rating with nothing underneath it.
What not to do
Don't turn this into a performance for whoever's chairing. The goal is the most honest answer available in the room, not the most reassuring one. If an answer is genuinely "we don't know" — write that down. "We don't know" is a usable, honest starting point. A confident guess dressed up as an answer is not, and it's worse than not knowing, because it stops anyone from fixing the actual gap.
Don't let one person answer for the room. Chapter 6 exists partly to surface disagreement between directors — if the chair says "ahead" and someone else in the room privately thinks "behind," that gap matters more than either individual answer, and it won't surface if only the most senior voice speaks.
Part 4, Chapter 2
Turning Six Answers Into a Plan
A completed set of worksheets is a diagnosis, not a plan. This chapter turns it into one — a real sequence a board can actually run, with or without outside help.
Score it the same way the free check does
If your board has taken the companion assessment (the free AI governance readiness check built alongside this book), you've already seen this scoring — this chapter uses the same one, deliberately, so the book and the tool stay in sync rather than asking you to learn two systems.
For each of the four core questions (Chapters 1 through 4), score your board's honest answer:
- 0 — Gap. No real answer, or the "bad answer" pattern described in that chapter.
- 1 — Partial. Something exists, but incomplete — a policy that doesn't name Shadow AI, a training session that happened once, an accountable person with no reporting line.
- 2 — In place. The "good answer" pattern from that chapter, genuinely.
Add the four scores together: a number out of 8. That number isn't the point — the breakdown underneath it is. A board scoring 6/8 with two zeros in different chapters has real, specific work to do, exactly as much as a board scoring 2/8. The total just tells you how much; the breakdown tells you what.
Prioritise using External Pressure, not just the lowest score
It's tempting to fix whatever scored lowest first. That's usually right, but not always — Chapter 5 changes the calculus. If external pressure has already landed (a funder, an insurer, a regulator, an incident), whichever of the four core questions is weakest and connects to that pressure jumps to the front of the queue, regardless of how the other scores compare. A board with a real gap in training but no external pressure at all has more runway than a board with the same gap and a funder already asking questions.
A 90-day starting sequence
This isn't the only order that works, but it's a reasonable default, sequenced so each step makes the next one easier rather than harder.
Days 1–30 — Close the ownership gap first. If Chapter 2 scored anything less than a 2, fix that before anything else. It's usually the fastest gap to close — naming an accountable person and setting a reporting cadence doesn't require new expertise, just a decision. Everything else in this list depends on someone actually owning it.
Days 31–60 — Write or update the policy. Using the real map from Chapter 1 — not a generic template — draft or revise the policy so it names actual tools and actual data categories, and specifically addresses Shadow AI. Have the newly accountable person from the previous step own this draft and bring it to the board for approval.
Days 61–90 — Deliver the first real training pass. It doesn't need to be elaborate. The ACNC's free course is a legitimate starting point for an organisation with no training budget. What matters is that it's tied to the actual policy just written, not generic AI literacy, and that it reaches everyone the policy applies to — not just the accountable person.
The twelve-month rhythm after that
Governance isn't a project with an end date — it's a rhythm, the same way a financial audit or a WHS review is. A sensible cadence, mapped across a year:
- Quarter 1 — the ninety-day sequence above.
- Quarter 2 — check External Pressure (Chapter 5) properly: review recent funding agreements and insurance renewals specifically for AI-related wording, rather than assuming you'd have noticed.
- Quarter 3 — refresh training, especially if the policy changed since Quarter 1, and especially for anyone onboarded since the last round.
- Quarter 4 — a full annual reassessment: re-run all six chapters, compare the new scores against where you started in Quarter 1, and report the change to the board honestly, gaps included.
A board that runs this rhythm on its own, with no outside help at all, will be in a materially different position twelve months from now than a board that reads this book once and moves on. That's true whether or not you ever have another conversation with whoever gave you this book.
Part 4, Chapter 3
Making This Recur: Turning a Book Into Board Practice
A book that gets read once and shelved hasn't changed anything. The six questions in this book are only worth what they're worth if they become something your board actually returns to — the same way most boards already treat a financial audit or a WHS review as a fixed part of the year, not a one-off event. This chapter is about making that happen deliberately, rather than hoping it does.
Use it for new-director onboarding
Every board eventually inducts new directors, usually with a folder of governance documents, financial history, and strategic plans. This book — specifically the six worksheets, already completed by the existing board — belongs in that folder. A new director reading the organisation's actual, honest answers to these six questions learns more about the board's real AI governance maturity in twenty minutes than any policy document alone would tell them. It also sets an expectation early: this board treats AI governance as something it actually discusses, not a line item nobody's looked at since it was written.
Run it as an annual development session, not a one-off
Many boards already budget a day or half-day each year for board development — training on financial literacy for non-finance directors, WHS obligations, strategic planning refreshers. AI governance belongs in that same category, on the same footing, not treated as a special, occasional topic that only comes up when something goes wrong. Scheduling a fixed annual slot for this — ideally timed to the Quarter 4 reassessment described in the previous chapter — turns it from "something we did once" into "something this board does," which is the actual goal.
Rotate who leads it
The accountable person named in Chapter 2 should gather the information and keep the policy current, but that doesn't mean they need to facilitate every future session. Rotating facilitation — a different director leading the conversation each year, working from this same book — builds shared literacy across the whole board rather than concentrating it in one person. It also protects the organisation against the accountable person leaving and taking all the institutional knowledge with them.
Why the first session is worth running with someone outside the room
Every chapter in this book works as a self-facilitated exercise, and a board that runs it entirely on its own will still get real value from it — that's the point of the ninety-day and twelve-month blueprints in the previous chapter. But the first time through is worth thinking about carefully. Internal dynamics can make brutally honest answers harder to get to on a first pass — a director is less likely to say "I think we're behind" out loud if the person who'd have to fix that gap is sitting across the table and has a stake in the answer sounding better than it is. An outside facilitator running the first session doesn't change the six questions or the framework behind them. What it changes is whether the room feels safe enough to answer them honestly the first time, before the board has its own practised rhythm for doing that itself.
That's a genuine trade-off to weigh, not a requirement — plenty of boards will get real value running this entirely in-house from day one. It's simply worth being honest that the first pass is usually the hardest one to get an accurate read from, and that's exactly when an outside, no-agenda facilitator is most useful and least necessary after that.
Part 4, Chapter 4
Two Ways Forward
Everything in this book works without another conversation. The ninety-day sequence, the twelve-month rhythm, the annual development session, rotating facilitation — a board with the time and the internal capacity to run all of that itself will get real, lasting value from this book and never need to talk to anyone about it again. That's not a soft version of the offer. It's the actual, complete path, and it's written that way on purpose.
Some boards will read that and know, honestly, that "we'll run this ourselves every quarter" is true in principle and unlikely in practice — not through lack of will, but because the person who'd own it already has a full plate, and a governance rhythm that depends on someone finding spare capacity every quarter tends to quietly stop happening around the second or third quarter, the same way plenty of good intentions do. If that's an honest read of your own board, here's what the supported version of this actually looks like — not a different set of promises, the same six questions and the same rhythm, just carried by someone whose job it is to keep it moving instead of it competing with everything else on someone's desk.
What ongoing support actually looks like
A quarterly written briefing to the board — what's changed in AI regulation, funder conditions, or sector risk that's actually relevant to your organisation specifically. Short. Not a report nobody reads.
An on-call review — any time your organisation is about to adopt a new AI tool, or a vendor pitches you something, it gets looked at before you sign, not after. This is where a lot of real exposure actually gets created — a well-meaning decision made quickly, without anyone applying the Chapter 3 test to it first.
An annual formal reassessment — the same Quarter 4 exercise from the twelve-month rhythm, run with someone outside the room, mirroring the cadence your organisation already uses for a financial audit or a WHS review. Boards already budget for that kind of annual check without blinking. This is the same category of thing.
One board or subcommittee meeting per quarter — to present findings and take real questions, in person or by call.
None of this replaces anything in this book. It's the same six questions, the same worksheets, the same twelve-month rhythm — just held by someone whose only job in the room is to keep it honest and keep it moving, rather than a board's own capacity having to survive four consecutive quarters of everything else that's also on the agenda.
How to actually decide
Don't decide this now, on the last page. Decide it after you've actually run the six questions once, honestly, and looked at what the worksheets say. A board that comes out of that first session with a clean, specific plan and genuine confidence it'll get done doesn't need anything from this chapter. A board that comes out of it with real gaps and a quiet sense that nobody's actually going to chase this every quarter has learned something equally useful — and that's a normal, common place for a board to land, not a failure.
If it's the second one: the conversation is one email away, and it starts the same way every conversation in this book has — with an honest question, not a pitch.
Closing
Closing
Six questions. Not a compliance framework, not a technology briefing, not a warning about the future of artificial intelligence — six specific things a board can ask itself, in an afternoon, and answer honestly.
That's a deliberately small promise, and it's worth restating why. Twenty-five years of turnaround work taught me that the organisations that actually fix things aren't the ones with the most sophisticated frameworks. They're the ones willing to find out what's actually true before deciding what to do about it. Nothing in this book asks your board to become technical experts, adopt a specific tool, or resolve a debate that credentialed AI researchers themselves can't agree on. It asks you to know what you don't know, name who owns finding out, write it down, and check it again next quarter.
If you've worked through all six chapters honestly, you already know more about your organisation's real AI exposure than most boards in this sector currently do. What you do with that is genuinely up to you — the ninety-day blueprint in Part 4 works with or without anyone else's help. If a conversation would be useful, it's one email away, and it starts the same way this book did: with a real question, not a pitch.
↑ Back to the top