AI is running far faster than most boardrooms are equipped to match. Non-technical directors are now being asked to make governance decisions about systems they’ve never touched, risks they don’t yet understand, and intellectual property they didn’t know existed. Here’s a practical guide to helping those conversations go well.

The Boardroom Gap

There’s a recurring pattern in professional services firms right now: the people building and deploying AI tools are not the same people who are ultimately accountable for them. Technical teams move fast. Directors, rightly focused on strategy and fiduciary duty, are often several conversations behind.

This isn’t a failure of leadership – it’s a communication problem. AI governance risks are real, but they arrive dressed in jargon. “Model drift,” “data provenance,” “agentic workflows” – these phrases don’t land in a board meeting. And when the language doesn’t land, the risk doesn’t register.

The good news is that you don’t need to teach your board how to think like engineers. You have to get them thinking about AI, as they already think about any other operational risk: Who is responsible? What could go wrong? What’s the firm’s exposure?

Three Risks Every Director Should Understand

Not all AI risks are equal, and not all of them need to be on the board agenda at the same time. But these three tend to be the most consequential for professional services firms – and the least well understood.

1.
Data You Don’t Control
When staff use public AI tools – even casually – client data, internal financials, or proprietary processes can enter systems outside the firm’s control. Most firms don’t yet have clear policies about which AI tools are approved, which data can be shared with them, and under what conditions.
2.
IP You Haven’t Recognised
Professional services firms have spent decades building proprietary knowledge: workflow maps, advisory frameworks, checklists, diagnostic tools. These are intellectual property, but most firms don’t treat them that way. AI both amplifies and exposes this IP simultaneously.
3.
Accountability With No Owner
If AI governance is everyone’s job, it simply becomes nobody’s. Without a person tasked with overseeing A.I., risks pile up in silence. By the time they come to light, it’s no longer operational – it’s reputational.

Converting Technical Risk Into Board Language

The most effective governance conversations reframe AI risks in terms that directors already have frameworks for. Here’s how to make that translation in practice:

  • Instead of “training data exposure”, ask: “Have we audited the privacy practices of every AI tool our staff are using? Do we know which ones have seen client information?”
  • Instead of “IP leakage”, ask: “If a competitor’s employee could prompt an AI model to reproduce our core advisory process, would we know? Would we have any recourse?”
  • Instead of “hallucination risk”, ask: “What’s our review process before AI-generated content reaches a client? Who signs off, and what are they checking for?”
  • Instead of “agentic AI”, try: “Are we putting any systems into deployment that take actions – sending emails, updating records, filing documents, without a person vetting every step?”
  • Instead of “model governance”, ask: “If an AI tool we use changes its behaviour, is deprecated, or was trained on bad data, what’s our backup plan?”

All of these reframings present the risk in terms that tie directly to fiduciary responsibility. Directors don’t need to understand how the systems work; they need to understand whether adequate controls exist.

Most Firms Don’t Know What IP They Have

One of the less obvious governance challenges is that professional services firms are sitting on intellectual property they’ve never formally recognised. Decades of process refinement – tax workflows, client onboarding sequences, audit checklists, advisory frameworks – represent real, replicable, defensible value. It’s just never been categorised that way.

AI changes the stakes considerably. When a firm’s internal knowledge is embedded into an AI workflow or a client-facing tool, that knowledge becomes scalable. It also becomes more visible, more portable, and more vulnerable. A process that once lived in a partner’s head or a shared drive now has structure – which means it can be copied, replicated, or reverse-engineered far more easily.

Directors should be asking: what does our firm know how to do that others don’t? Where does that knowledge currently live? And what happens to it when we hand it to an AI system?

The companies that do this best are no more casual about their internal processes than they would be with a patent or trade secret – because in practice it’s exactly the same.

In practice, it means that companies should be writing down and cataloging their basic processes, determining which are truly proprietary and building access controls around it.

An AI Governance Framework That Works

There’s no need for a new department or policy document for good AI governance. It takes three things: ownership, visibility and a rhythm.

Ownership means identifying one individual to be responsible for AI governance – not a committee, not “the technology team,” but a person who can bring questions before the board of directors, track AI activity across the whole firm and has the authority to say no when something doesn’t meet the standard. It’s sort of an air traffic control kind of function: somebody who knows what’s in the air, what hasn’t taken off yet and needs to land.

Visibility ensures the board has an up-to-date and accurate picture of how AI is being deployed across the firm. Which tools are approved? Which client-facing outputs involve AI? All that a simple registry, updated quarterly, needs to provide directors is what they require in order to exercise meaningful oversight, without getting into operational detail.

Rhythm means that this isn’t a one-time conversation. AI capabilities – and therefore AI risks – change quickly. No longer is a quarterly review cadence ambitious; it is the bare minimum a well-governed firm should keep. The agenda doesn’t have to be long, but it should be consistent: What’s new, what’s changed, which decisions need to be made at the board level.

  • Appoint an AI governance owner: one individual accountable, with a direct line to the board. 
  • Create a basic AI register: What tools are always used, what data, what processes, what outputs go to customers.
  • Audit your data flows: Know where your client and internal data goes before you understand what risks attach to it.
  • Classify Your Firm’s IP: If no one has yet done it, and someone can do it again. It is valuable enough to protect.
  • Set a cadence for review: Quarterly is quite reasonable; annually is too infrequent, given how quickly the landscape moves.
  • Revisit vendor agreements: Especially with AI-enabled software providers. Data ownership clauses have re-emerged as a point of contention. 

Governance Is a Source of Sustainable Competitive Advantage

There’s a tendency to frame AI governance as the thing that slows firms down – the compliance overhead that more agile competitors will sidestep. That framing is both wrong and dangerous.

Clients are paying more attention to how their advisors use AI than most firms realise. The question of whether a firm’s AI practices are trustworthy is quickly becoming part of the selection and retention decision – particularly for clients in regulated industries, or those with their own governance obligations to meet.

A firm that can articulate its AI governance framework – that can tell a client exactly which tools are used, which data they interact with, and what human oversight exists – is in a genuinely differentiated position. That’s not a compliance story. It’s a trust story. And in professional services, trust is the product.

Getting governance right also enables a firm to be enabled faster, not slower. With visibility into AI activity, the board can fast-track decisions on new tools or expanded use cases. The firms that are genuinely struggling with AI adoption are often the ones where governance is unclear – where every new tool requires a slow, anxious conversation because no one has established the standards yet.

When talking to the non-technical directors, they don’t need a technical conversation. It needs to be frank about what the firm does not yet know, explicit about who is on the hook, and remain rooted in a vernacular of risk and accountability that good directors already understand very well.

WANT TO GO DEEPER?

The Convergence of AI & IP – A Masterclass by Gary Boomer

Gary Boomer’s Masterclass explores how accounting and advisory firms can navigate the intersection of artificial intelligence and intellectual property – from recognising the IP your firm already owns, to building governance structures that protect it as AI scales.

→ Begin mastering AI with Miles Masterclass at MilesMasterclass.com