Skip to content

AI for boards · Literacy

Board AI literacy library

Board AI literacy: Prepared primers on LLMs, agents, AI risk, questions for management, an oversight checklist, and a glossary — plus a curated reading list of verified public resources (NIST AI RMF, EU AI Act, OECD AI Principles, NACD). Not legal advice.

Signed-in boards can enable a literacy tracker at /app/ai-literacy (counts who marked primers read — in-app read marks only. counts of who marked a primer — no scores, grades, rankings, or quizzes. marking a primer read is not proof of competence.). Guest speakers: /ai-for-boards/speakers.

Prepared primers

What directors need to know about LLMs

~6 min read

Large language models predict likely next tokens from training data. They can draft, summarize, and brainstorm — and they can invent confident falsehoods (hallucinations). Treat outputs as drafts that a human owns.

  • An LLM is not a database lookup and not a truth engine. It generates fluent text from patterns in training data and your prompt.
  • Useful board uses: summarize a long memo you already trust, draft questions to ask management, compare two policy options you supply. Risky uses: asking for undisclosed financials, legal conclusions, or “what should we vote.”
  • Always keep a human author. If a director pastes agent output into Prepared, they remain the author — see Outside agent input and Pre-meeting Q&A agent-assisted paste.
  • Ask management: which LLMs are approved, what data leaves the company, and who reviews high-stakes outputs.

Agents in the enterprise — and who is accountable

~5 min read

“Agents” chain tools and steps. Accountability stays with people and the board’s oversight process — never with an unnamed model.

  • An agent that can browse, write tickets, or call APIs multiplies both productivity and blast radius. Privilege, retention, and audit still apply.
  • Prepared calls no AI model. Directors can paste context into their own assistant or, when the chair allows it, connect it to a read-only MCP server with a personal access token — it sees exactly what the director sees, can only save private question drafts, and every call is audit-logged.
  • Board question: who may authorize an agent to act (vs. draft), what systems it can touch, and how incidents are escalated to the board.

AI risk categories boards should inventory

~7 min read

Map AI risk the way you map other enterprise risks: strategy, operations, cyber, privacy, bias/fairness, third parties, model drift, and misuse — without inventing a single “AI score.”

  • Strategy risk: competitors use AI and you do not — or you overspend on tools that never reach customers.
  • Model / product risk: wrong outputs, brittle performance outside training conditions, opaque failure modes.
  • Data risk: training or prompt data that includes secrets, personal data, or IP without controls.
  • Third-party risk: vendors embed models; terms, subprocessors, and exit plans matter.
  • People risk: shadow AI, skill gaps, over-trust. Oversight risk: no owner, no inventory, no incident path to the board.
  • Prepared’s board risk register can hold chair-declared AI risks — it does not compute residual risk scores.

Questions to ask management about AI

~5 min read

A practical ask-list for strategy, risk, vendors, workforce, and regulation — not a script and not legal advice.

  • Inventory: Where do we use AI today (build vs. buy)? Who owns the inventory?
  • Value: Which use cases are material to strategy or revenue? What is the capital plan?
  • Controls: What is prohibited? How do we detect shadow AI? What is the human-review rule for high-stakes decisions?
  • Data: What customer or employee data enters prompts or training? Retention? Cross-border?
  • Vendors: Top AI vendors by spend and criticality; contractual audit and exit rights.
  • Incidents: Last AI-related incident or near miss; how would the board hear within 24–72 hours?
  • Regulation: Which regimes apply to us (e.g. EU AI Act roles, sector rules)? Who tracks changes?

Board AI oversight checklist

~6 min read

A process checklist for chairs — assign owners, set cadence, and record education — not a certification.

  • Assign full-board AI oversight with clear committee support (risk, audit, tech) — avoid a single “AI director” as the only literacy.
  • Require an AI use inventory and risk map at least annually (and after material product launches).
  • Put AI on the calendar: strategy deep-dive and risk deep-dive, not only a one-line update.
  • Confirm management has an escalation path for AI incidents into existing cyber / privacy / product risk channels.
  • Log board education (guest speakers, primers read) as a process record — counts, not scores.
  • Review vendor concentration and open-source / foundation-model dependencies when material.
  • Do not treat a checklist complete as “compliant” with the EU AI Act, NIST AI RMF, or any statute.

Board AI glossary (short)

~4 min read

Shared vocabulary so directors and management talk about the same things.

  • Model — learned parameters that produce predictions or content from inputs.
  • Foundation / frontier model — large general-purpose model often adapted for many tasks.
  • Fine-tuning — further training on organization- or task-specific data.
  • Prompt / context window — the text (and tools) the model sees for one run.
  • Hallucination — fluent output that is factually wrong or invented.
  • RAG — retrieval-augmented generation: fetch documents, then generate with them in context.
  • Agent — system that plans steps and may call tools; still needs human accountability.
  • GPAI — general-purpose AI (EU AI Act vocabulary for broadly capable models).
  • High-risk AI system (EU) — uses listed in the Act that trigger stricter obligations — legal classification is for counsel, not this primer.

Curated public reading list

External links verified to resolve. Prepared is not affiliated with these publishers. Access to full NACD downloads may require membership.

Educational material only — not legal advice, not a compliance determination, not a certification, and not a substitute for counsel. Prepared Board does not determine whether your board meets any AI regulation.