Boards and AI: Why AI Competence Belongs in the Boardroom

AI has moved quickly from an emerging technology to a force capable of reshaping how companies operate, compete, and create value. Yet while AI adoption is accelerating across organisations, many boards are still struggling to determine what their role should be.
Is AI primarily an operational matter for management? How much does the board really need to know? And how can directors distinguish genuine strategic opportunities from the latest wave of AI hype?
For Elin Hauge and Magnus Revang, these are no longer theoretical questions. Drawing on decades of experience across technology, AI, business strategy and leadership, they believe a lack of AI competence at board level can create a governance deficit - leaving companies exposed to both missed opportunities and unnecessary risk.
Two perspectives on AI, technology and the boardroom
Hauge and Revang bring complementary expertise to the conversation.
Elin Hauge is a business and data strategist, AI advisor, board director and pragmatic futurist. With more than 25 years of experience connecting data-driven technologies with business value, she brings together a background in physics, mathematics, management science and business strategy. She has also held several non-executive board positions, giving her first-hand experience of the questions boards need to ask around strategy, risk, regulation, and technology.
Magnus Revang brings more than 25 years of experience in UX strategy, design, AI, and market research. A former Gartner analyst and award-winning product leader, he has worked extensively with AI, conversational technologies and digital products, and currently leads product development at Openstream AI. His perspective combines a deep understanding of how technology evolves with practical experience of turning emerging technologies into products and business solutions.
Together, their perspective goes well beyond the question of how boards can use generative AI themselves. Their focus is on the bigger picture: how AI changes strategy, operations, risk, competitiveness and ultimately the responsibilities of the board.
AI competence is about much more than using ChatGPT
One of the most common misconceptions is that personal experience with AI tools equals AI competence.
A board member who knows how to use ChatGPT can certainly benefit from it in their own work. But that does not necessarily mean they can make sound strategic decisions about how AI should be used across a company.
As Hauge and Revang point out, being able to use an AI tool is very different from understanding how AI could affect the company's strategy, operations, and market.
For boards, the question is not whether they can use an AI assistant to prepare for a meeting. It is whether they understand enough about the technology to challenge management, identify opportunities, assess risks and make informed decisions about the company's future.
There are other blind spots, too. Some boards assume AI is firmly within management's domain and therefore do not need to get involved. Others are so focused on the opportunities that they are reluctant to discuss the risks.
Both approaches can be problematic.
The pace of development also makes it increasingly difficult to separate genuine capability from hype. Boards need enough understanding to ask: What can AI actually do today? What is likely to become possible tomorrow? And what does that mean for our business?
Why AI has become a board issue now
AI is not new. The opportunity has been developing for several years. So why has the board's role become more urgent now?
One reason is that the technology itself has matured.
The development of large language models has fundamentally changed how people interact with technology and what machines are capable of doing. The pace is extraordinary. Capabilities that seemed unrealistic just months ago can quickly become commercially viable.
At the same time, the infrastructure, tools and integrations needed to deploy AI effectively are becoming more mature. For businesses, it is increasingly realistic to make meaningful investments in AI to improve innovation and competitiveness.
The challenge is that competence has not necessarily kept pace with opportunity.
Regulation has also moved AI firmly into the governance conversation. The EU AI Act introduces requirements that companies need to understand and prepare for, while rules around data protection, cybersecurity and digital resilience create additional responsibilities for organisations and their leadership.
And then there is the wider security environment. Rapid technological development, combined with an increasingly unstable geopolitical landscape, has changed the scale and nature of information security risks facing businesses. For boards, understanding these risks is becoming part of responsible oversight.
As Hauge has argued in her work on AI and boards, the challenge is no longer simply recognising that AI is here. Boards need to understand how different forms of AI create different opportunities, risks and governance requirements.
AI is strategic, not simply operational
It can be tempting to think of AI as something that belongs in IT or somewhere further down the organisation.
But AI has the potential to influence the fundamental drivers of business performance: revenue, costs and market share.
The most significant impact will often come not from using AI to write emails or summarise meetings, but from applying it to the company's core processes, products, services and systems.
This is where the real opportunity lies, but it is also where things become more complicated.
A strategically relevant AI initiative requires a deep understanding of both the business and the technology. The board needs to understand where AI could change the company's competitive position, how the market might evolve and what capabilities the organisation will need to develop.
That is fundamentally a board-level discussion.
The danger of getting AI adoption wrong
The risks of insufficient AI competence are not limited to missing an opportunity. Poorly governed AI adoption can actively create new risks for a company.
Hauge and Revang highlight a particularly useful example.
Consider a company that introduced AI tools across its workforce and encouraged employees to use them through a strong incentive scheme.
An expert working in a critical business function discovered that AI could categorise new customers according to industry codes. The classification was important because it influenced pricing and risk management.
The AI appeared to work extremely well. It was correct around nine times out of ten.
But the expert had previously performed the task manually, with an error rate of around one per cent. The company's pricing and risk models had been built around that level of accuracy.
A ten per cent error rate was therefore not an improvement. It was a significant risk.
The problem was not the technology itself. The problem was that nobody had properly considered what a seemingly small error rate meant in the context of the business.
This is precisely where board competence matters. Without sufficient understanding, a board can approve initiatives that appear innovative and efficient on the surface while inadvertently increasing the company's exposure to risk.
Don't confuse activity with strategy
Another common trap is the desire to simply be able to say that the company is “doing something with AI”.
This often leads to low-risk, low-impact projects: internal tools, isolated experiments and applications in support functions.
These can be useful. But they are not necessarily strategically important.
The better question is: How can AI change the company's ability to compete?
Boards should look beyond whether an initiative uses AI and ask whether it contributes meaningfully to revenue growth, cost reduction, market share or long-term capability.
The strategic value of AI is often found deeper inside the business. It’s in core processes, proprietary data, products, services and operational systems.
Hauge has described this distinction through a framework that separates personal productivity tools, AI agents, and enterprise-level AI applications. The further organisations move towards applying AI to their own business processes and data, the more important board-level understanding of strategy, data, information security and risk becomes.
Technology moves so quickly that something developed internally today could become an off-the-shelf product tomorrow. Investments therefore need to deliver value, whether through measurable business impact or meaningful competence building.
The goal should not be to win the race to implement AI first. It should be to invest where AI can create lasting value.
Risk cannot be an afterthought
There is sometimes a reluctance to talk about risk when discussing AI. The concern is that too much focus on risk could slow innovation.
But opportunity and risk cannot be separated. Risk assessment is fundamentally about considering what could happen, how likely it is to happen, and what the consequences would be for the company.
For boards, this should be part of the same conversation as strategy.
If AI could fundamentally change the company's market, operating model or competitive position, the board needs to consider both sides of that equation.
And boards should not be afraid to ask for help.
Independent experts can provide an objective perspective, particularly in areas where technology is changing faster than the board's existing expertise. The key is to ensure that external advice helps the board make better decisions rather than simply reinforcing a predetermined technology agenda.
Regulation makes board knowledge even more important
AI does not exist in a regulatory vacuum.
Board members already have responsibilities relating to oversight, control and sound management of the company. Depending on the organisation, these responsibilities intersect with legislation covering areas such as data protection, AI, cybersecurity, and digital resilience.
For companies operating in regulated sectors, additional requirements may apply.
The important point is that board members cannot simply assume that these matters belong to someone else because they are technical or legal.
A lack of knowledge does not remove responsibility. That makes competence development increasingly important, particularly as AI becomes embedded deeper into business processes.
What should boards do next?
The first step is surprisingly straightforward: make AI a regular boardroom topic.
Not as a one-off presentation. Not as a demonstration of the latest AI tool. And not simply as a discussion about how directors themselves can use ChatGPT.
Boards need to develop a shared understanding of how AI could affect the company and its market.
That means asking the right questions:
- Where could AI fundamentally change our business?
- Which of our core processes could be transformed?
- What opportunities could create competitive advantage?
- What new risks could AI introduce?
- How are management measuring the success of AI initiatives?
- What capabilities and competence will we need?
- What should we be monitoring as the technology develops?
It is also worth considering whether the board itself has the necessary expertise.
Hauge and Revang argue that boards should ensure they have more than one person with genuine digital and AI competence. This can come through developing the capabilities of existing directors or bringing in new expertise.
Ultimately, AI competence at board level is not about becoming technical experts.
It is about being able to ask better questions, challenge assumptions and make better decisions.
From AI awareness to AI governance
AI is developing too quickly for boards to treat it as a one-time strategic exercise.
What was considered ambitious two years ago may already be outdated. What seems experimental today could become standard business practice tomorrow.
That makes continuous board-level engagement essential.
The boards that navigate this well will not necessarily be the ones that adopt the most AI tools. They will be the ones that understand where AI genuinely matters to their business, where the risks lie and how the technology could reshape their competitive landscape.
The real question for boards is therefore no longer “Should we be doing something with AI?”
It is: “How will AI change our company, and are we prepared to govern that change?”