BEYOND AI POLICY: THE BOARD’S ROLE IN DECIDING WHAT TO TRUST
When boards take up artificial intelligence (AI) and crisis risk, the conversation typically starts with a question that has served governance well for years: what is our AI policy? That question remains a sound starting point. What is developing alongside it is a complementary question, one that builds directly on the same governance instinct and extends it to match how crisis information actually moves today.
This is not a call to replace established governance, regulatory, safety, privacy or compliance processes. In highly regulated sectors, this judgment must sit alongside and never substitute for established scientific, medical, safety, legal, regulatory, privacy and compliance review processes. It is an argument for making one additional layer of crisis decision making more explicit: how confidence in information is assessed, decision rights are assigned and escalation is handled under pressure.
Extending established risk taxonomies
Most board risk taxonomies organise crisis exposure by source: internal systems, external reporting, media, regulators and now AI. This made excellent sense for a long time, because source type used to be a reliable predictor of reliability. Internal data was generally more trustworthy than an unverified external claim, and a board could reasonably ask its executives to manage each source category with a fitting set of controls.
AI adds a new dimension to what that organising principle can capture. The change is not only that organisations may use AI tools internally, but that the information environment around them is increasingly shaped by AI-generated content, synthetic media, automated amplification and model-supported analysis. Internal insights may now be AI-supported or probabilistic.
