Directors are regularly told they need to understand artificial intelligence. They do not. They need to be able to interrogate the people who do, and to recognise the difference between an answer and a performance. That requires twelve questions, not a technical education.
Why a question set beats a briefing
The standard response to board-level AI anxiety is a briefing: an external speaker, forty slides, a broad sense of change and no change in the company's actual controls. Six months later nobody can say whether the business is better governed than it was.
A question set works differently. It creates a record of what management asserted and when, it exposes the gap between confidence and evidence, and it converts a vague topic into a list of things somebody has to go and find out. Each question below is paired with what a credible answer sounds like — and, where it is instructive, what an evasive one sounds like. The pattern to watch for is the answer that describes intention rather than a document.
Questions 1–4: exposure
What AI is in use across this business today, and how do we know?
A good answer refers to a written register with a named owner and a review date, and states how it was compiled — expense records and a staff survey, not just management interviews. It will usually include an honest note that the register is probably incomplete and by roughly how much.
A weak answer is a confident verbal list. Confidence without a document means nobody has looked properly.
What company or client data has left the building through these tools?
A good answer maps data categories to specific systems, states where the data is processed and stored, and confirms whether provider terms permit retention or use of that content for model training.
A weak answer is "nothing sensitive". That is a conclusion, and the board should ask what was examined to reach it.
Where does AI output reach a client, a patient or a regulator without a human check?
A good answer distinguishes between drafting assistance reviewed before it leaves the business and genuinely automated output, and names every instance of the latter with its reviewer or its justification for having none.
A weak answer claims a human always reviews everything. At any scale that is rarely true, and it is worth asking how the review is evidenced.
What have we told clients, insurers and regulators about how we use AI?
A good answer references specific contractual commitments, privacy notice wording and any questionnaire responses already submitted, and confirms that current practice matches what was said.
A weak answer treats this as a marketing question. The exposure here is a gap between a signed statement and operational reality.
Questions 5–8: control
Who is accountable for AI governance, by name?
A good answer is one name, recorded in the minutes, with a described mandate and the authority to stop a deployment.
A weak answer distributes responsibility across IT, legal and operations. Shared accountability at this stage of maturity reliably produces none.
What does our AI policy permit, and have staff actually read it?
A good answer summarises the permitted, restricted and prohibited tiers in plain language, and cites the proportion of staff who have acknowledged it and when new joiners receive it.
A weak answer is that a policy exists. Existence is not adoption, and a policy staff route around silently is worse than none, because it creates false comfort.
How does a new AI tool get approved, and who has said no recently?
A good answer describes a short assessment applied consistently, applies it to free tools as well as paid ones, and can point to a specific rejection or a condition imposed. A gate that has never refused anything is not a gate.
What happens in the first hour after an AI incident?
A good answer names the reporting route, the timescale, the person who decides on client or regulator notification, and confirms that AI-specific failure modes are written into the incident procedure — not just outages, but confidential data entered into a public tool and materially wrong output acted upon.
A weak answer points at the general IT incident process. It was almost certainly not written with these scenarios in mind.
Questions 9–12: value and direction
What has AI actually saved or earned us, in numbers?
A good answer is narrow and measured: named workflows, hours or error rates before and after, and candour about what was tried and abandoned. Two proven use cases beat a portfolio of pilots.
A weak answer cites industry statistics. The board is asking about this company.
Which parts of our business are most exposed to competitors using AI well?
A good answer is a strategic judgement about where speed, cost or service quality could shift against the firm, with a view on how quickly and what the response would be. It should sound like a competitive analysis, not a technology briefing.
What single AI failure would hurt us most, and how likely is it?
A good answer names one specific scenario grounded in this business — a confidentiality breach with a named client, a wrong figure in a filing, a discriminatory screening outcome — with an honest likelihood and the control that reduces it.
A weak answer lists generic risks. The value of the question is the forced choice of a single worst case.
Could we answer a client's AI due-diligence questionnaire tomorrow?
A good answer is that the material exists — register, policy, data map, incident procedure, training records — and could be assembled within a working day.
A weak answer requires a project. This question is the most commercially predictive of the twelve, because enterprise procurement and investor diligence are, for most UAE mid-market firms, arriving well ahead of any regulator.
If management can answer all twelve from documents rather than from memory, the business is in the top band of governance maturity. The five dimensions scored in the UAE AI Governance Readiness Index 2026 map closely onto this question set.
How often to ask
Quarterly, as a standing agenda item with a two-page written paper. Questions one to eight should be asked every quarter, because exposure and control drift as tools change. Questions nine to twelve suit an annual strategic session, where the discussion is about direction rather than assurance.
Record the answers. The value compounds: a board that can see how the answer to question one has changed across four quarters knows something about the trajectory of its business that no single briefing would have supplied. Where the answers reveal specific gaps, the twenty-eight-point governance checklist converts them into work with owners attached, and the UAE regulatory landscape explains which of those gaps carry legal weight for your entity as opposed to commercial weight.
One caution. A board that asks these questions and receives inadequate answers has created a record of being on notice. That is the correct position to be in, but it comes with an obligation to follow up. The questions are only useful if the minutes of the next meeting show what changed.