Six questions your board will ask

Two consumer goods manufacturers deploy the same AI demand planning system. Both pilots succeed. Forecast accuracy improves by more than 30 percent. Both take a scale-up proposal to their executive teams.

One gets board approval in sixty days and runs the system across thirty-five manufacturing sites by spring.

The other has its proposal tabled. Eighteen months later it is still running at two pilot sites. The technology worked. No executive would approve broader deployment without governance the company had not built.

Six questions did that. They are the questions any board will ask before approving AI at scale, and they are worth answering before the meeting rather than during it.

Who owns this system if it makes a costly error?
Not a team and not a function. A named individual whose name appears next to the system in the AI inventory, accountable for what the system does, how it performs, and what happens when it fails. If the answer is IT, the answer is no one.

What data is it accessing, and does that comply with our data governance policies?
An AI assistant connected to ERP can synthesize supplier pricing, margin structures, and strategic planning data across everything its permissions reach, in response to a single query. It amplifies whatever access control gaps already exist. The question is not what the system was built to see. It is what it can reach.

What contractual protections exist if the vendor changes the model without notice?
Most AI vendor agreements do not require notification of model changes. A system validated against one model version is not validated against its successor. This gap rarely matters during a pilot and becomes material at enterprise scale.

What stops the system from acting outside its authorization?
Circuit breakers: pre-programmed thresholds that pause autonomous operation when spend limits, transaction volumes, or error rates are exceeded, and escalate to a human. Enforced through system configuration, not through policy.

How will we know if it is performing as expected?
Monitoring at the granularity where degradation actually shows up, which in consumer goods means SKU, customer, and site level. Aggregate accuracy metrics mask localized failure. Seasonal volatility, reformulations, and portfolio changes make drift a recurring condition rather than a one-time concern.

What happens when it does not?
A documented escalation path, a named first call, and a defined suspension condition that halts the system's autonomous authority pending revalidation. Decided before the incident, because the moment it is needed is the worst time to build it.