AI Governance, Risk & Red Teaming
Capable · M3 · lesson 3 of 22 · queued
Preview — browse every lesson free. Enroll to mark lessons complete, open partner links and save your progress. Login & enroll →
AI Literacy for the Board - A 90-Minute Briefing Pack
📖
now learning

AI Literacy for the Board - A 90-Minute Briefing Pack

15 min

Ninety minutes. Six slides. Twelve directors who collectively carry oversight responsibility for everything the company does with AI. The board pack is the single most-scrutinized AI deliverable an AI Officer produces, and most AI Officers produce it poorly. They make it too technical, too long, missing the Article 99 quantification, missing the peer benchmark, missing the anticipated Q&A, missing the refresh schedule. They forget that directors are generalists, that the audit committee chair often co-presents, that the questions are sharp, and that the time is fixed. This lesson is the 90-minute board pack template that an AI Officer can adapt for a real board on a real meeting day, with the six-slide structure, the anticipated-Q&A bank, the D&O insurance overlay, the personal-accountability framing for the Article 47 signing officer, and the annual + on-event refresh schedule. The lesson is L2.Ch5.L3, the Tier 1 (executives and board) literacy artifact in the four-tier curriculum.

Why the Board Pack Is Its Own Deliverable

Directors carry oversight responsibility for AI risk. That obligation is increasingly explicit, the EU AI Act's compliance posture maps to a board-governance pattern that most large enterprises already operate under ISO 42001 clause 5 leadership commitment, NIST AI RMF Govern 1.6 (resources) and Govern 4 (culture, risk tolerance), and the broader corporate-governance framework (UK Corporate Governance Code, German AktG, French AFEP-MEDEF, OECD Corporate Governance Principles). When a regulator opens an Article 99 enforcement action, the first question after "what happened" is "what did the board know and when did they know it." The board pack is the evidence that answers that question.

The AI Officer is the primary briefer. The audit committee chair often co-presents, particularly where the audit committee meets monthly on AI risk (typical in financial services and life sciences) rather than quarterly with the full board (typical in industrials and consumer goods). The general counsel is in the room. The CFO is in the room. The CEO is in the room. The questions are sharp, because directors have personal exposure under D&O insurance terms that increasingly exclude reckless or grossly negligent AI governance failures, and because the Article 47 declaration signer for each Annex III high-risk system carries individual accountability.

Time is 90 minutes. Not 120. Not 60. Directors block 90 minutes for major risk topics and they enforce the clock. The pack must land the message, leave time for substantive Q&A, and leave the directors equipped to answer their own peers and shareholders. A 60-minute pack feels incomplete. A 120-minute pack runs over and gets cut short on the most important slide. The 90-minute structure is six slides plus 10 minutes of Q&A, and the discipline of fitting the message into six slides is what makes the pack land.

The Six-Slide Board Pack Structure (Plus Q&A)

The 90-minute board pack template that an AI Officer ships in 2026:

Slide 1 (10 min) - AI Portfolio Summary by Risk Tier

The opening slide answers the director's first question: "what do we have?" The summary has four columns by tier:

  • Article 5 prohibited. Count of systems reviewed; negative-assurance attestation status ("no prohibited systems in scope"); date of last review; the workplace emotion-recognition / social-scoring / predictive-policing / untargeted-scraping / real-time biometric ID-in-public-space coverage. The negative-assurance attestation is the deliverable; the board sees the signed attestation date and the next review cycle.
  • Annex III high-risk. Count of systems by category (§1 biometrics, §2 critical infrastructure, §3 education, §4 employment, §5 essential services, §6 law enforcement, §7 migration, §8 administration of justice). Aug 2, 2026 vs. Dec 2, 2027 timeline track per system (post-Omnibus VII Annex III §5(b) credit and §5(c) life/health insurance on Aug 2, 2026 stand-alone track; rest of Annex III on Dec 2, 2027). Conformity-assessment status per system.
  • Article 51 GPAI dependency. Foundation-model exposure map (GPT, Claude, Gemini, Llama, Mistral, etc.); Code-of-Practice signatory status per provider; Aug 2, 2026 enforcement readiness on the GPAI side; downstream-deployer information flow (Annex XII).
  • Minimal-risk and Article 50 limited. Count of minimal-risk systems (still subject to Article 4 literacy); Article 50 limited-risk systems with sub-article coverage (50(1) chatbot, 50(2) marking accelerated to Dec 2, 2026, 50(3) emotion-recognition notice, 50(4) deepfake).

The slide includes the post-Omnibus VII timeline visual: Feb 2, 2025 (Articles 4 + 5); Aug 2, 2025 (GPAI obligations except enforcement); Aug 2, 2026 (GPAI enforcement + Annex III §5(b)/§5(c) and public-body stand-alone track); Dec 2, 2026 (Article 50(2) accelerated); Dec 2, 2027 (rest of Annex III). The board needs to see the timeline anchored to portfolio items.

Slide 2 (15 min), Article 5 Prohibitions + Annex III High-Risk Walk-Through

The second slide answers the director's second question: "are we exposed?" The Article 5 walk covers the eight prohibition categories with explicit negative-assurance attestation for each (workplace/education emotion-recognition; biometric categorization inferring sensitive attributes; social scoring; behavioural manipulation; exploitation of vulnerability; real-time remote biometric ID in publicly accessible spaces for law enforcement except narrow carve-outs; predictive policing solely on profiling; untargeted scraping of facial images). The negative-assurance attestation is signed by the AI Officer and the Article 47 declaration signer for each Annex III system. The Article 5 worst-case under Article 99(2) is €35M or 7% of worldwide turnover.

The Annex III walk covers the portfolio-level count by §1-§8 with the deployer-vs-provider split, the conformity-assessment status per system, the Article 27 FRIA status for deployer systems, the Article 26 deployer obligation coverage, and the Article 73 incident-reporting connectivity. The Annex III worst-case under Article 99(3) is €15M or 3% per provider/deployer failure. The slide ends with the aggregate Article 99 worst-case from the portfolio (typically €1-2 billion for a €10B-turnover enterprise) and the realistic-case after mitigation (typically 5-15% of worst-case).

Slide 3 (15 min), Article 51 GPAI Thresholds and Foundation-Model Exposure

The third slide answers the director's third question: "what are we dependent on for our AI capability, and is that dependency safe?" The Article 51 walk covers the GPAI thresholds, Article 51(1)(a) presumed-systemic-risk threshold at 10^25 FLOPs training compute; Article 51(1)(b) Commission designation; Article 51(2) self-notification obligation. The foundation-model exposure map shows the company's stack: which foundation-model providers are in production use; the Article 53 baseline GPAI obligations (Annex XI/XII documentation, copyright policy, training-data summary); the Article 55 systemic-risk obligations on the systemic-risk subset (model evaluations, incident reporting, cybersecurity).

The Code-of-Practice signatory status per provider matters because the General-Purpose AI Code of Practice (published July 2025 with adjustments through 2026) is the presumption-of-compliance route for Article 53, a non-signatory provider raises the deployer's diligence cost. The Aug 2, 2026 GPAI enforcement-readiness item is the actionable element: is the foundation-model stack ready for the Aug 2, 2026 enforcement go-live (which Omnibus VII did not move)?

Slide 4 (15 min), Article 27 FRIA, Fundamental-Rights Impact Assessment

The fourth slide answers the director's fourth question: "is the FRIA work on track?" Article 27 requires deployers of certain high-risk AI systems to conduct a fundamental-rights impact assessment before first use. The applicability tracks the deployer category: public bodies and private entities providing public services; deployers of Annex III §5(b) creditworthiness systems (excluding fraud detection); deployers of Annex III §5(c) life and health insurance risk-assessment and pricing systems. The Omnibus VII Aug 2, 2026 stand-alone track applies to these three deployer categories ahead of the rest of Annex III.

The slide shows: the FRIA backlog by deployer category; the FRIA-completion target per system; the FRIA-capability readiness (team size, methodology maturity, AI Office template adoption); the FRIA outputs (risk-mitigation measures, monitoring plan, complaint mechanism); the Article 27(5) AI Office notification obligation; the integration with GDPR Article 35 DPIA (the same risk-assessment process can satisfy both, with care). The Article 27 failure exposure under Article 99(3) is €15M or 3% per failed system.

Slide 5 (15 min), Article 73 Incident-Response Runbook and Reporting Clocks

The fifth slide answers the director's fifth question: "if a serious incident happens, are we ready?" Article 73 requires providers of high-risk AI systems to report serious incidents to national market-surveillance authorities. The three reporting clocks:

  • 10 days for the general serious-incident category.
  • 2 days for serious incidents involving widespread infringement of fundamental rights or serious harm to critical infrastructure.
  • 15 days for serious incidents involving the death of a person, where the report must follow as soon as the causal link is established or reasonably likely.

The slide shows: the incident-response runbook status (template, escalation chain, regulator-contact directory, evidence-preservation procedure); the tabletop-exercise status (last exercise date, gaps identified, remediation status, next exercise date); the cross-coordination with Article 26(4) deployer-side cooperation and Article 55(1)(c) GPAI provider-side incident reporting; the Article 73 failure exposure under Article 99(3) at €15M or 3%. The board needs to see that the runbook has been exercised, not just drafted.

Slide 6 (10 min), Article 47 Personal Accountability + Article 99 Worst-Case + Risk Appetite + Asks

The sixth slide answers the director's sixth question, and the most personally relevant one: "who is on the hook, and what is the worst case?" Article 47 requires the EU declaration of conformity for each high-risk AI system to be drawn up and signed by the provider's authorized representative. The signing officer carries individual accountability for the declaration's accuracy. The slide identifies the signing officer per system (typically the AI Officer or the relevant business unit head), the declaration-renewal cadence, the documented sign-off process, and the D&O insurance coverage status for the signing officer.

The Article 99 worst-case quantification across the portfolio: Article 99(2) at €35M or 7% for any Article 5 exposure; Article 99(3) at €15M or 3% per Article 16 / 26 / 27 / 53 / 4 / 73 failure; Article 99(4) at €15M or 3% per specific operator / notified-body obligation; Article 99(5) at €7.5M or 1% for misleading information. The aggregate worst-case for a €10B-turnover enterprise with 20 high-risk Annex III systems and 6 GPAI relationships and 10 Article 50(2) generative systems can reach €1-2 billion. The realistic-case after mitigation is typically 5-15% of worst-case.

The AI risk appetite statement is the board-approved sentence: "The company accepts AI risk to the level required to deliver business value, with realistic-case Article 99 exposure not exceeding €X across the portfolio at any time, with quarterly board reporting and annual independent assurance." The asks: budget allocation for the FY (typically 0.1-0.3% of revenue for a mature program); headcount approval; specific governance-committee charter approvals; specific risk-appetite-statement amendments.

Q&A (10 min) - Anticipated Questions With Sample Answers

The Q&A is not improvised. The AI Officer pre-builds a question bank with sample answers for the seven questions directors actually ask:

  • "Are we exposed under Article 5?" Sample answer: "No, our annual negative-assurance review covering the eight prohibition categories was last signed [date] by [name]; the next review is scheduled for [date]. The Article 99(2) €35M / 7% worst-case is therefore zero on Article 5."
  • "What changed under Omnibus VII?" Sample answer: "Three things material to us: Annex III §5(b) credit and §5(c) life/health insurance now have an Aug 2, 2026 stand-alone track ahead of the broader Annex III Dec 2, 2027 date; Article 50(2) machine-readable marking was accelerated to Dec 2, 2026 with the grace period cut; the rest of Annex III shifted to Dec 2, 2027. Our portfolio impact: [N] credit/insurance systems on the accelerated track; [M] generative-content systems on the Dec 2, 2026 marking track."
  • "Who signs the Article 47 declaration?" Sample answer: "Per system, the named signing officer is in slide 6 appendix. For our largest exposure system, the signing officer is [name]; their personal accountability is documented in the sign-off process; D&O insurance coverage is confirmed."
  • "Have we tested the Article 73 runbook?" Sample answer: "Yes, last tabletop exercise was [date]. The exercise covered a synthetic-incident scenario across the 10/2/15-day clocks. Gaps identified: [list]. Remediation status: [status]. Next exercise: [date]."
  • "What's our Article 99 worst-case?" Sample answer: "Aggregate worst-case across the portfolio is €[X]M. Realistic-case after mitigation is €[Y]M. Per-row mapping is in the appendix. The quarterly trend is [up/down/flat]; the budget allocation in the asks supports holding or reducing realistic-case."
  • "How do we compare to peers?" Sample answer: "Peer benchmark from [source: published ESG / governance reports, industry surveys, professional services benchmarks] shows our coverage rate at [X]th percentile on AI inventory completeness, [Y]th percentile on FRIA capability, [Z]th percentile on Article 50(2) procurement readiness. The competitive position is [strong/middling/weak]."
  • "Is our literacy program covering the board?" Sample answer: "Yes. This briefing is the Tier 1 quarterly cadence. The full four-tier curriculum (board, deployers, users, affected workers) is operational with completion tracking and assessment evidence. The Article 4 horizontal obligation is covered."

Director-Specific Framing and Audit-Committee Co-Presenter Pattern

The board pack speaks to directors as generalists, not as AI engineers. Directors carry fiduciary-duty obligations under their corporate-law jurisdiction; the AI Officer's job is to translate AI risk into language that maps to the directors' existing oversight responsibility. The framing pillars:

  • Oversight responsibility. Directors are not expected to be AI experts; they are expected to ensure the company has AI experts, processes, and controls. The pack shows that the company has those.
  • Fiduciary-duty implications. Failing to oversee AI risk where the exposure is in the hundreds of millions or billions is a fiduciary-duty exposure. The pack shows that the exposure is quantified and managed.
  • D&O insurance coverage. D&O policies increasingly include AI-governance carve-outs or exclusions. The pack shows the coverage status and any limitations.
  • Board committee accountability. The audit committee, the risk committee, or a dedicated AI / technology committee typically owns AI risk at the committee level. The pack shows the committee charter and the reporting cadence.

The audit-committee chair often co-presents because the audit committee typically owns the Article 99 quantification, the FRIA backlog, and the Article 73 readiness as a quarterly standing item, while the full board sees the summary annually plus on-event. The co-presentation pattern: audit committee chair opens with the committee's oversight perspective; AI Officer walks the six slides; CFO or general counsel chimes in on specific risk areas; CEO closes with the strategic framing. Where the audit committee meets monthly (financial services, life sciences), the co-presentation is tighter; where it meets quarterly (industrials, consumer goods), the audit committee chair's role is more of a sponsor.

Annual Briefing Plus On-Event Refresh Cadence

The board pack is not a one-time deliverable. The refresh schedule:

  • Annual, full 90-minute briefing. Calendar-anchored to the board's annual risk-review cycle (typically Q1 or Q4). The full six-slide pack updated for the current portfolio, the current Article 99 quantification, the current peer benchmark, the current asks.
  • Quarterly, audit-committee briefing. Shorter (30-45 min) deep-dive on a rotating focus (Q1 Article 99 quantification; Q2 FRIA backlog; Q3 Article 73 readiness; Q4 Article 4 literacy coverage). Audit committee sees the full standing items; the rotating focus deepens one area.
  • On-event, special briefings. Omnibus VII (May 7, 2026 political agreement triggered an immediate Tier 1 refresh); major regulatory developments (e.g., Commission Article 50 guidelines, Commission AI Office GPAI Code-of-Practice updates); major incidents (Article 73 serious incident or near-miss in the company or a high-visibility peer event); M&A integration (acquired AI portfolio integration into the literacy and inventory).

On-event refresh evidence is part of the Article 4 audit-defensibility package. A regulator inquiring about Tier 1 literacy in mid-2026 expects to see the Omnibus VII briefing date and attendance log. A regulator inquiring in early 2027 expects to see the first-incident or first-enforcement-action briefing date and the lessons-learned communication.

Cross-Walks: ISO 42001, NIST AI RMF, D&O Overlay

The board pack maps to the broader governance frameworks the company already operates under:

  • ISO 42001 clause 5, leadership commitment. The board's review of the AI Management System (AIMS) is the evidence of top-management commitment. The Tier 1 quarterly board briefing satisfies the audit-evidence expectation. The Stage 2 audit on the AIMS will sample the board-pack attendance log and the audit-committee minutes.
  • NIST AI RMF Govern 1.6 (resources). The board approval of the AI compliance budget is the evidence of resource allocation. The asks slide is the explicit budget request.
  • NIST AI RMF Govern 4 (culture, risk tolerance). The AI risk appetite statement is the evidence of risk tolerance. The board approval and the quarterly trend are the evidence of culture.
  • EU AI Act board-level governance pattern. The AI Act does not explicitly require board-level oversight, but the Article 26 deployer obligations, the Article 27 FRIA accountability, the Article 47 declaration signing, and the Article 99 exposure quantification all aggregate to a level of risk that requires board attention under any reasonable corporate-governance framework.
  • D&O insurance overlay. D&O policies in 2026 increasingly include AI-governance specific terms. Common patterns: exclusion for losses arising from Article 5 prohibited-practice violations; carve-outs for reckless or grossly negligent AI governance failures; coverage triggers for Article 47 personal accountability under specific conditions; coordination with cyber-liability policies. The general counsel reviews the D&O policy annually for AI-governance fit; the board sees the coverage summary in the annual pack.

Six Common Board-Pack Mistakes

Mistake 1 - Too Technical

Directors are generalists. They don't need to see the transformer architecture, the fine-tuning compute budget, the dataset shard size, or the RAG retrieval pipeline. They need to see the risk tier, the regulatory exposure, the mitigation status, and the asks. A board pack that opens with a technical architecture diagram loses the room in the first three minutes. The architecture belongs in the appendix or in the Tier 2 deployer training.

Mistake 2 - Too Long

Twelve slides for 90 minutes is too many. Six is the right number. Directors retain the first slide and the last slide; the middle slides blur. The six-slide structure forces the AI Officer to choose what matters most, and choosing forces clarity. A long pack signals an unfocused program.

Mistake 3 - Missing Article 99 Quantification

The pack must quantify the worst-case in euros (or local currency equivalent). A pack that says "we have penalty exposure under Article 99" without quantifying it leaves the directors unable to weigh AI risk against other risks. The audit committee chair will push back: "what's the number?" The number must be in the pack.

Mistake 4 - Missing Peer Benchmark

Directors sit on multiple boards. They want to know where the company sits relative to peers: better, worse, average. The peer benchmark can be drawn from published ESG / governance reports, industry surveys (e.g., the IAPP AI Governance Profession Survey, the OECD AI Policy Observatory data), professional services benchmarks (e.g., Deloitte / PwC / EY / KPMG AI governance reports), or a curated competitor analysis. Without it, the pack feels self-referential.

Mistake 5 - No Anticipated Q&A Bank

The Q&A is half the value of the briefing. An AI Officer who improvises Q&A answers comes across as unprepared. The anticipated-Q&A bank with sample answers (the seven-question framework in this lesson) is a standing artifact that gets refreshed for each briefing.

Mistake 6 - No Refresh Schedule

A one-time board briefing in 2025 does not satisfy 2026 Article 4 obligations. The annual + quarterly + on-event refresh schedule must be documented and operational. The Tier 1 LMS-equivalent tracking (board-meeting attendance logs and minutes) is the audit-defensibility evidence.

L2 Artifact - The Six-Slide Board Pack Template + Q&A Bank + Refresh Schedule

The L2.Ch5.L3 deliverable that an AI Governance Lead ships is a three-part package: the six-slide board pack template (PowerPoint or equivalent, with the slide layouts, the data tables, the timeline visual, the worst-case quantification math, and the asks placeholder); the anticipated-Q&A bank (the seven-question framework with sample answers, refreshed quarterly); and the refresh schedule (annual full briefing, quarterly audit-committee briefing, on-event special briefings, with the calendar artifacts and the attendance-log template).

The package is the Tier 1 evidence in the four-tier Article 4 literacy curriculum. It integrates with the Tier 2 deployer training (slide 4 FRIA content reused), the Tier 3 user training (slide 5 incident-response runbook reused for operators), and the Tier 4 affected-worker notice (the Article 26(9) right-to-information communication grounded in the same regulatory framework). The audit-defensibility evidence for Tier 1 includes: the board-pack file (with versioning); the board-meeting minutes confirming the briefing was delivered; the attendance log; the Q&A captured in the minutes; the action-items follow-up; the audit-committee chair's signed acknowledgement of the standing item.

Key Takeaways

  • The board pack is the most-scrutinized AI deliverable an AI Officer produces. Directors carry oversight responsibility; the regulator's first question after an Article 99 enforcement action is "what did the board know."
  • 90 minutes. Six slides. Plus 10 minutes of Q&A. The discipline of the six-slide structure forces clarity. Twelve slides loses the room.
  • Slide 1 - Portfolio summary by risk tier. Article 5 negative-assurance; Annex III high-risk count; Article 51 GPAI dependency; Article 50 limited-risk and minimal-risk count; post-Omnibus VII timeline visual.
  • Slide 2 - Article 5 prohibitions + Annex III walk. Eight prohibition categories with negative-assurance attestation; Annex III §1-§8 portfolio count; Article 99(2) €35M/7% worst-case for Article 5; aggregate Article 99 worst-case typically €1-2B for a €10B-turnover enterprise.
  • Slide 3 - Article 51 GPAI thresholds and foundation-model exposure map. 10^25 FLOPs presumed-systemic-risk threshold; Code-of-Practice signatory status; Aug 2, 2026 GPAI enforcement-readiness (unchanged by Omnibus VII).
  • Slide 4 - Article 27 FRIA. Aug 2, 2026 stand-alone track for public bodies, §5(b) credit, §5(c) life/health insurance; backlog status; capacity readiness; integration with GDPR Article 35 DPIA.
  • Slide 5 - Article 73 incident-response runbook. 10/2/15-day reporting clocks; tabletop-exercise status; cross-coordination with Article 26(4) deployer and Article 55(1)(c) GPAI provider.
  • Slide 6 - Article 47 personal accountability + Article 99 worst-case + risk appetite + asks. Signing officer per system; aggregate worst-case quantification; AI risk appetite statement; budget and headcount asks.
  • Anticipated-Q&A bank covers the seven questions directors actually ask. Article 5 exposure; Omnibus VII changes; Article 47 signer; Article 73 tabletop; Article 99 worst-case; peer benchmark; literacy coverage.
  • Annual + quarterly audit-committee + on-event refresh cadence. Omnibus VII triggered an immediate on-event refresh; future on-events include major regulatory developments, M&A, major incidents.
  • D&O insurance overlay matters. Coverage status for the Article 47 signing officer; AI-governance carve-outs and exclusions; annual general-counsel policy review.
  • Cross-walks anchor the pack in the broader governance framework. ISO 42001 clause 5 leadership commitment; NIST AI RMF Govern 1.6 resources + Govern 4 culture/risk tolerance.
  • Six common mistakes to avoid. Too technical; too long; missing Article 99 quantification; missing peer benchmark; no anticipated Q&A; no refresh schedule.
  • The L2 artifact is a three-part package. Six-slide board pack template + anticipated-Q&A bank + annual-briefing schedule. Integrates with Tier 2, Tier 3, Tier 4 literacy.