re-ai-gov Join the waiting list

Kennisbank

AI risk at board level: what you can demonstrate and what you cannot

The question you are asking yourself is not technical

As a director, you do not personally check which AI model produces which output. You ask a different question: if this goes wrong, can I show that we knew about it, that we looked into it, and that we did something. That question is governance-related, not technical. And the answer you do not accept is a list of applications approved by IT. Not because that list is incorrect, but because it is incomplete. It describes what was requested, not what is being used.

What you stand to lose

The risk for a director is not that an employee uses a language AI to write a draft. The risk is that you cannot say anything about it at the moment it matters: during an incident, a supervisory question, a liability issue. Demonstrability is then the only thing that counts. Not whether you could have known it at the time, but whether you can show that there was a structure in place to know it. A director who says "we had no visibility into that" is in a different position than a director who says "that fell into a category that we deliberately handled in that way." The difference between those two sentences is what this scan delivers.

What you stand to gain

The intention is not to ban or slow down every use of AI. Most of what employees have started using on their own is functional and delivers something. The gain for a director does not lie in curbing that, but in being able to distinguish: this is low risk and can continue, this touches personal data or decision-making about people and must be handled differently, this is unclear and needs to be investigated. Without that distinction, you treat everything the same — and that is usually too strict for the majority and too lenient for the exception that matters.

Why the IT list is not sufficient

Shadow AI does not arise from unwillingness. It arises because an employee had a problem and found a tool that solved it, without there being a request process that was faster than the tool itself. Those tools do not appear on a procurement list. They only appear once someone asks about them — and only if asking does not immediately lead to a sanction. An organization that wants to see shadow AI must first make clear that reporting is not a risk. That is a governance choice, not a technical one.

What the scan concretely does

The Responsible AI Scan starts with an inventory of what is actually being used, independent of what was ever approved. Each use is then classified by role — who uses it, for what — and by risk level. That classification leads to a governance set: a way of dealing with each category that aligns with the risk structure your organization already has, instead of a new framework alongside it. The content of the rules themselves — which obligations exactly apply, within which deadlines — is addressed elsewhere; that is not what this scan focuses on. This scan focuses on the mechanism: knowing what is running, being able to categorize it, and being able to show that you have done so.

What you can do with this at governance level

With a classification by role and risk level, you can show a supervisory authority, an auditor, or a supervisory board a structure instead of a promise. You can indicate which categories need attention and which do not. You can report on this without having to explain each time anew why you did not know something. That is a different position than reactively explaining why a tool entered unnoticed.

Other roles, other perspectives

The question of AI risk looks different depending on the function. What a CIO needs to know about AI risk concerns systems and infrastructure; what a General Counsel needs to know about AI risk concerns liability and evidence; what a risk manager needs to know about AI risk concerns how AI risk fits into the existing risk taxonomy. As a director, you deal with all three, but you are not the one who carries out the classification — you are the one who must be able to see that it has been done.

The current state of affairs

The Responsible AI Scan is under construction. There is currently no tool you can start and that immediately produces a report. Anyone interested in this can join the waiting list; nothing is being offered that does not yet exist, and nothing is promised about when or with what result.

The question that precedes this

Before you can determine whether AI use is risky, it is often more useful to know what AI means for the work itself: which part of a task can be taken over and which part cannot. That question is close to the risk question, but is not identical to it — a task that can largely be taken over by AI is not automatically risky, and a task that cannot is not automatically safe. The work scan from FTE TO AI calculates per task which part of the work can be taken over by AI, thereby providing a basis on which to pose the risk question more sharply than on the basis of a list of approved applications alone.

Andrewde assistent van de Responsible AI Scan

Vraag maar. Governance begint bij weten wat er draait — ook wat niemand heeft goedgekeurd.

Answers come from this site’s knowledge base. Not tailored advice, and not a scan of your company.