TERBIS
All articlesStrategy

Part 1 of "Styrelse & AI"

Read the full series →

What every board needs to know about AI

August 10, 2026

Most boards have, at some point in the past year, sat through a presentation on AI. Fewer have asked whether they themselves have the knowledge required to judge whether the business is doing the right things with the technology.

That is understandable. AI is developing quickly, the terminology is technical, and it is tempting to rely on management's assurance that “we have it under control.” The problem is that AI amplifies several risks already present in digital investments. These systems can generate content, influence decisions and, in some cases, act at high speed and with broad reach.

At the same time, the technology can create significant competitive advantages. Opportunity and risk often exist within the same project. That makes AI unsuitable for complete delegation.

Why this belongs in the boardroom

Three reasons make AI a board-level matter rather than a purely technical one:

Regulatory accountability. The EU Artificial Intelligence Act places obligations on organisations that develop, provide or use AI systems. The applicable duties depend on factors including the organisation's role, how the system is used and its risk classification. The issue cannot therefore be handled by the IT department in isolation.

Strategic competitiveness. Used well, AI can improve productivity and decision support and create new revenue streams. Used poorly, it can create legal, operational and reputational problems. Avoiding it entirely also creates a risk of being outpaced by competitors that learn earlier.

Risk at scale. AI systems allowed to book, pay, communicate or influence decisions without clear boundaries can cause errors at a speed and scale that traditional controls were not always designed to handle.

The EU AI Act — the short board-level version

Without going into legal detail, the AI Act classifies uses of AI according to risk, with obligations increasing as the potential harm grows.

  • Unacceptable risk — certain uses, including some forms of social scoring, biometric categorisation and manipulation, are prohibited. The first prohibitions began to apply in February 2025.
  • General-purpose AI models — the models behind many AI services have been subject since August 2025 to requirements including transparency, documentation and copyright compliance. Models with systemic risk face additional duties concerning risk assessment, testing and incident reporting.
  • High-risk systems — under the updated timeline, rules for stand-alone systems in areas including employment, education, creditworthiness and critical infrastructure begin to apply on 2 December 2027. The date for high-risk AI embedded in regulated products is 2 August 2028.
  • Penalties — the regulation contains several penalty levels. Breaches of the prohibited AI practices may result in administrative fines of up to €35 million or 7 per cent of an undertaking's worldwide annual turnover. Lower maximum levels apply to other infringements.

The point for a board is not to memorise dates or legal definitions. Management must be able to explain where the organisation stands, while the board needs to ensure that the issue has appropriate ownership, governance and oversight. The exact legal duties depend on the organisation's role and how its systems are used.

Opportunities and challenges belong together

It is easy to fall into either ditch: complete AI optimism — “we simply need to implement faster” — or complete AI scepticism — “we will wait until the rules are settled.” Both are risky board positions.

The opportunities are real: more efficient processes, better decision support and products and services that were not possible a few years ago. But every opportunity has a possible mirror image. The same system that automates customer service can make the wrong decision at scale. The same model that accelerates analysis can amplify biases in its source material or produce incorrect conclusions in convincing language.

A board that only discusses opportunities misses the risk picture. A board that only discusses risks misses the value the organisation is leaving behind.

The right question is rarely “AI or no AI,” but:

Under what conditions, within what limits and with what oversight?

What happens without the right restrictions

AI without clear boundaries on what a system may and may not do creates unpredictability. Problems may develop slowly and invisibly or spread rapidly at scale. In either case, the organisation may not discover them until the consequences have become significant.

Some practical examples:

  • Agents receive overly broad authority — an AI system asked to “optimise customer communication” without clear limits may send inappropriate content to the wrong audience before a person has time to react.
  • Data is used beyond its intended purpose — information collected for one purpose is used by a model for something else, with possible privacy and GDPR consequences.
  • Decisions lack traceability — when an organisation cannot explain why an AI system influenced a loan, recruitment or customer decision, both legal and trust risks arise.
  • Costs grow without visibility — without budget limits, usage principles and ownership, AI can become a growing cost that nobody truly owns.

The absence of restrictions does not create freedom. It creates unpredictability. Unpredictability in systems operating in real time and at scale is a risk the board must ensure the organisation can manage.

Start with a map, not a comprehensive policy

The board's first task does not need to be commissioning a large AI policy. Instead, ask management to create a simple map showing:

  • which AI systems and services the organisation uses
  • the purpose of each use
  • the data the systems process
  • the decisions or actions they may influence
  • the applicable limits
  • who owns value, risk and follow-up

Without this map, the organisation can neither assess its risks nor prioritise its opportunities. The inventory does not need to be perfect at first. Its initial purpose is to make the invisible visible.

Questions the board should be able to ask

A board does not need to know how to build AI systems. It needs to know how to ask the right questions of those who do:

  • Which AI systems do we use today, and who owns the risk assessment and expected business value of each one?
  • Which of our AI uses may fall under high-risk rules or other specific requirements, and what is our plan?
  • Which decisions and actions may our AI systems perform without human involvement — and was that boundary deliberately set, or did it simply emerge?
  • How do we measure and report AI-related outcomes, deviations and incidents to the board?
  • If an AI system harms a customer or breaches a rule tomorrow, do we know who is accountable, and can we reconstruct what happened?

If management does not have clear answers, that is not a sign that everything is under control. It is a sign that the questions need to be asked more often and more systematically.

A board does not need to have every answer about AI. But it must ensure that the organisation knows which systems it uses, what value they should create, what limits apply and who is accountable when something goes wrong.

That is not technical micromanagement. It is modern board work.

Sources: EU Artificial Intelligence Act — Regulation (EU) 2024/1689; AI Omnibus enters into force; European Commission's current AI Act timeline. Checked 10 August 2026.

Share

LinkedInX

Cite this article

Norström, A. (2026). What every board needs to know about AI. Terbis. https://terbis.se/en/articles/vad-en-styrelse-maste-kunna-om-ai