How to explain AI risk to the board: What directors need to hear

WorkAI.TV Editorial Desk
4 Min Read

Share with your CISO

Most board presentations on AI risk fail before they start because they hand directors a threat catalog instead of a decision framework. Security consultant Ed Moyle lays out a more defensible approach in this guide to AI risk communication: map actual usage first (sanctioned, shadow, and third-party), convert that into a directional risk vector showing both magnitude and trajectory, then build a board narrative around movement rather than inventory. The argument is less about new frameworks and more about reframing what the board actually needs to govern AI.

What this means for your business

The organizations most exposed here are not necessarily the ones running the most AI. They’re the ones where security leadership is still presenting AI risk as a static list of threats while the business deploys AI faster than the list updates. If your board deck looks like a threat taxonomy rather than a trend line, you’re giving directors the information they need to worry, not the information they need to act. The gap between those two things is where AI governance breaks down quietly.

Moyle’s core claim, that AI risk is directional rather than categorical, is correct and underappreciated. A customer service chatbot that hallucinates answers introduces new reputational exposure, but it may simultaneously reduce the operational risk of undertrained human agents giving wrong answers after a 40-minute hold. Neither framing is complete alone. The CISO who presents only the new threat surface is technically accurate and strategically useless, because the board cannot weigh a one-sided ledger. What Moyle calls a “risk vector” is just the acknowledgment that risk has both a direction and a magnitude, and boards can only govern what moves, not what merely exists.

The harder problem is shadow adoption, and Moyle treats it too gently. Periodic informal check-ins with business teams will not surface the developer who has been piping customer data into an unapproved LLM for six months to hit a sprint deadline. The instrumentation gap between what security knows and what the business is actually running is where real AI liability accumulates. A CISO who waits for structured interviews to discover shadow AI use is already behind. I’d revise this assessment if enterprise AI observability tooling matures enough to make real-time usage visibility routine rather than exceptional, but that’s not where most organizations sit today.

The board framing Moyle closes with is the right one to internalize. Directors don’t need a verdict on whether AI is safe or dangerous. They need a read on which direction the needle is moving in their specific organization, over what time horizon, and by how much. That is a harder story to construct than a threat list, and it requires the CISO to have genuine visibility into business adoption rather than just the security stack. The budget question this reframes is not “what do we spend on AI security tools” but “do we have the instrumentation to know what we’re actually defending against.”

Based on reporting from How to explain AI risk to the board: What directors need to hear, originally published 2026-09-17 13:24:00.

TAGGED:
Share This Article