A board should demand three things before AI touches strategy work: that you know where the data physically sits, that every recommendation traces to the sources behind it, and that a human can always choose something else. If a vendor cannot answer all three clearly, the system is not ready for your decisions.
Your job on the board is not to be an AI expert. Your job is to make sure management decisions rest on sound data and sound practice.
Then you are told the new strategy platform uses AI. Automated analysis. Assistants that keep working without asking permission every time.
You have three questions:
- Who has access to our data, and where does it sit?
- Can we see what the AI actually did?
- If the AI recommends A, may we choose B?
Those three questions become three demands. A board should insist all three are in place before letting AI into strategy work. Not because the technology is dangerous, but because the responsibility stays with you regardless of what the system suggests.
Demand 1: Do you know where your data physically sits?
The question: where are your customer data, financials and strategy documents at the moment an AI analyses them?
What most boards assume: in the EU.
What often turns out to be true: "we use ChatGPT" or "it's cloud, we haven't asked."
The difference is not theoretical. If data sits in US data centres it is legally reachable by US authorities, whether or not anyone at your company intended to share it.
But location alone does not settle it, and that is what most people get wrong. A US-owned provider can be subject to US law extraterritorially, including when the server stands in the EU. And GDPR follows the personal data rather than the server, so it applies even when processing happens outside the EU. The question is therefore both where data is processed and who can be compelled to disclose it. The full test is in AI and data security in the EU.
What you can demand, phrased so it can actually be checked:
- A named EU data centre, not "EU region" as a marketing phrase
- A contract clause stating data does not leave the EU without your consent
- An answer on who holds the keys, you or the vendor
- A documented deletion process with a deadline you have agreed to
Say it word for word at the next meeting:
"Where does our strategy data sit when the AI analyses it? I want the data centre named, and the clause in the contract that binds the location."
If the answer is "we're not entirely sure" or "both US and EU", that is not an answer. It is an open item, and it closes before you go further.
Demand 2: Can you see what the AI built its answer on?
The question: when the AI produces a recommendation, can you ask what it read to get there?
What most boards assume: that sources come with it.
What often turns out to be true: a well-written answer with no trace of where it came from.
A recommendation without sources is an assertion. It may well be right, but you cannot verify it, and you cannot defend it afterwards.
Concretely, every analysis should be able to show:
- Which documents went in, not merely that some did
- Why the recommendation beat its closest alternative
- Which version of a dataset was used, so a conclusion drawn on April numbers is not mistaken for one drawn on September numbers
- What the AI was denied access to, and why
That last point gets overlooked and it matters most. If something was withheld because it is classified confidential, that should be visible. Otherwise you cannot tell whether the analysis is incomplete or merely brief. How classification decides what a model gets to see in practice is covered in the four classification levels.
Why this matters, concretely:
You enter a new market on the strength of an analysis. It goes badly. Eighteen months later an investor or an auditor asks what the decision rested on. "The AI recommended it" is not a defence. "Here are the five sources, here is what the model weighed, and here is what we chose instead" is.
Traceability is not distrust of the model. It is evidence that you did the work.
Demand 3: May the human choose otherwise?
The question: if the AI points at A and the board thinks B is right, can you choose B without the system fighting you?
What most boards assume: that it goes without saying.
What often turns out to be true: the system makes it awkward enough that nobody does it.
There are three realistic settings, and they should be chosen deliberately:
Insight only. The AI gathers and presents. Humans make every decision. The model is a statistician, not an adviser.
Proposal with approval. The AI proposes, a human approves before anything happens.
Full automation. The AI decides and acts, humans can roll back afterwards. Defensible for routine work, not for strategy.
Strategy work belongs in the first two. Where the line falls, and how to pick a level per task, is the subject of autonomy levels.
An example that actually costs something:
The analysis proposes dropping the customer segment that accounts for 8% of revenue and 40% of support time. The arithmetic is right. What the model does not know is that the segment exists because your largest customer asked for it, and that the large customer leaves with it.
That is not an error in the analysis. It is a fact that never entered it. Which is why the human needs the last word, and why using it has to be effortless.
Say it word for word at the next meeting:
"If the system recommends A and we choose B, what happens in practice?"
If the answer is about the algorithm becoming less accurate, or the model needing retraining, the arrangement is backwards. The system is built for you to follow it. It should be the other way round.
The checklist: nine questions for the next meeting
Print it and bring it.
Location
- Where does our data sit? The answer should be a named EU data centre.
- Who holds the keys? The answer should be us.
- How do we delete it? The answer should contain a deadline.
Traceability
- Can we see the sources behind a recommendation?
- Can we see why A beat B?
- Can we see what the model was not given?
Control
- Can we choose something other than the recommendation?
- Does doing so cost us anything in the system?
- Can a decision be rolled back?
Nine yeses and the foundation is sound. One no is not a crisis, but it is an agenda item with IT and legal, not an item for next year.
Why we built approval as a gate
A demand with no consequence in the system is a statement of intent. So approval in 360° Sprint is built as a gate rather than a status field.
Gate 1 signs off the layer holding Vision Map, Theme Detail, Goal Canvas and Strategic Response. Gate 2 signs off Road Map Overview and Strategic Portfolio. Approving a gate marks that layer's models complete, so the progress figure reflects a decision that was taken rather than a box that was ticked.
Who may approve is a setting on the organisation, not a matter for the individual. It can be set to administrators only, managers and above, or any member. A role without access that attempts to approve is refused.
That is the same point as demand 3, translated into something you can verify: the decision lives somewhere, it lives with a role you chose, and there is a record that it happened.
What to do now
Take the nine questions to the next meeting and ask them out loud. You do not need to understand the model to ask them, and you can hear from the answer whether the vendor has thought it through.
The three demands do not make the AI weaker. They make it what it should be: a department working for you. How a board moves from recipient to active participant in that work is covered in the board and AI.
Your job is not to be an AI expert. Your job is to make sure the strategy is still yours.
If the board is new, or you are still composing it, the groundwork is in boards in smaller companies.