Board advisory

Your board will be asked what it knew, and when.

Your governance framework designs the control. This work tests whether the human part of it operates. A non-voting board seat, a view on a single decision, or a session built for your agenda.

Most board conversations about AI are about adoption: what has been deployed, how fast, and what it saved. Those are management questions and management is usually answering them well.

The board's question is different and it is rarely on the paper. Can this board tell, afterwards, that a decision was reasoned? Who is able to override a system, and have they ever done it? What can this organisation still do if the tools stop? Those are questions about judgement, and judgement is what a board is actually for.

Two things make them urgent rather than interesting. Under the EU AI Act a person given oversight of a high-risk system must be enabled to interpret its output, to disregard or override it, and to remain aware of the tendency to over-rely on it, with the two-person rule on biometric identification naming competence, training and authority together. Graded entry. And the human-factors literature is clear that inserting a person at the end of a process is not, by itself, a safeguard. Why human in the loop is not a safeguard.

Boards are being handed oversight duties that assume a capability nobody has measured. The longer version of this argument was published by The European Business Review in August 2026.

If you came here looking for AI governance

A fair question, and the answer is no, so it is worth settling in the first paragraph rather than the fifth.

I am not a compliance adviser. I do not write AI risk registers, map controls against the EU AI Act, run conformity assessments, build governance frameworks or draft audit committee papers. Firms that do that work properly exist, several of them are very good, and if that is what you need you should engage one rather than me.

Put in the terms a board already uses: a governance framework designs the control. This work tests whether the human part of it operates.

Every audit committee knows that a control can be properly designed and still fail in operation, and that the way you find out is to test it. Human oversight is a control. It is designed on paper, it is named in the framework, and it is almost never tested. A named overseer who cannot tell a plausible wrong answer from a right one is a control that exists in design and not in operation.

So the framework tells you the control is there. This tells you whether it works, and it is usually asked for the first time during an incident.

Where this sits on a board agenda

Four items that appear on real board and audit committee papers, and the question underneath each that the paper does not answer.

AI risk appetite

The paper sets thresholds. The unanswered question is who is empowered to stop the system when a threshold is crossed, and whether that person has ever done it. An appetite nobody can act on is a number in a document.

Board oversight and director duties

Under the EU AI Act a person given oversight of a high-risk system must be enabled to interpret its output and to disregard or override it. The unanswered question is whether your named overseer can tell a plausible wrong answer from a right one, which is a question about their practice rather than their job title.

Audit committee reporting and assurance

Reporting shows what the system did. The unanswered question is whether the decision could be reconstructed six months later, and by whom. Assurance over a process is not assurance over a judgement.

Resilience and business continuity

Continuity plans assume the work returns to people if the system stops. The unanswered question is whether those people can still do it, because the capability decayed while the system was running. The measured decay rates are here.

If your board already has clear answers to those four, you have the outside view covered and you do not need me. That is rarer than boards expect and it is worth ten minutes finding out.

Three ways this works

An advisory seat

A non-voting seat held over a defined period, usually four to six meetings across a year. I am in the room for the decisions, I read what you read, and I say the thing the room is circling. No vote and no fiduciary duty, which is what keeps the view independent and the accountability where it belongs.

A view on one question

One decision, one engagement. A short fact-find, conversations across the business, then a written view and a discussion. Most often used before a significant commitment, or after one that is not going the way it was supposed to. No ongoing commitment on either side.

A board session

A bespoke session for the board or the top team, built to make people think rather than watch slides. It opens with an argument and a set of provocations, then moves into structured discussion designed to surface where the board actually disagrees. Some people call it a keynote, some a presentation, some a briefing. It is the same thing and it is built for your agenda, not delivered off a shelf.

Where this is the wrong choice

If what you need is a roadmap, an integration partner or somebody to run the build, that is AI consulting and I am not the person for it. I am not going to build your tech stack, and a good implementation partner will do it better and cheaper than a board advisor pretending to.

If you want somebody permanently, with a vote and a duty, you want a non-executive director. That is a different appointment with different obligations and it should be recruited as one.

And if your board already gets a straight answer to what AI has changed about its decisions, who can override a system and what capability the organisation has lost, you do not need an outside view. That is rarer than boards think, and it is worth the ten minutes it takes to find out before spending anything.

The research this rests on

Everything above is argued in public, with the evidence graded and what it does not support stated alongside what it does:

Questions boards ask

Is this AI governance, compliance or risk advisory?

None of the three. I do not write AI risk registers, map controls to the EU AI Act, run conformity assessments or draft audit committee papers, and specialist firms do that work properly.

This is the question those exercises leave open: whether the people named in your governance framework could actually detect a wrong answer, whether anyone has ever overridden the system, and what the organisation could still do if it stopped.

What is the difference between this and an AI consultant?

Most AI consulting is roadmap and execution: tooling, integration, the build. That work matters and I am not the person for it.

This is the other question. Whether the board can tell that a decision was reasoned, who is accountable when the system is wrong, and what the organisation will still be able to do without the tools. Judgement and oversight rather than delivery.

Do you take a formal board seat?

Not a voting one. I sit as an advisor, which means I am in the room for the decisions and I carry no fiduciary duty and no vote. That keeps the independence useful and it keeps the accountability where it belongs, with the directors.

How long does a board advisory arrangement run?

Usually a defined period rather than an open commitment: often four to six meetings across a year, sometimes a single cycle around one decision. If you want somebody permanently, you want a non-executive director, and that is a different appointment.

Can you just come in once?

Yes, and for a lot of boards that is the right amount. One question, one engagement, a view delivered in writing and in the room, and no ongoing commitment on either side.

We have already deployed and it is not going well. Is it too late?

No, and this is a common reason boards call. The work is different after deployment: it starts from what has actually happened rather than from a plan, and the first task is usually establishing what the organisation can still do unaided.

When should we not do this?

If your board already gets a straight answer to what AI has changed about your decisions, who can override a system and what capability you have lost, you do not need an outside view. That is rarer than boards think, and it is worth ten minutes establishing before you spend money.

Start here

Tell me what the board is deciding.

A 30-minute conversation about the decision in front of your board. If I am the right person, we go from there. If not, you will still leave with something useful.

This is selective work. I take on a limited number of private clients at a time, so the attention stays real.

Read by Rahim, not by an assistant. Reply within 24 hours, including if the answer is that this is not the right work for you.

Prefer to talk first? Book a 30-minute call

Prefer email? rahim@thesuperskills.com

Box of Amazing

Rahim’s free weekly letter on AI and human capability

If this was useful and you want a small amount of it each week, that is what the letter is for. Weekly essays on AI, capability and the future of work. Read by 25,000 people, every week since 2017. Free, and one click to stop.

Opens Substack to confirm. No pitch in it, unsubscribe in one click, and nobody follows up because you read something.

Running an event, or responsible for how AI arrives in your organisation? Keynotes  ·  Advisory and coaching  ·  Enquire