// AI AND THE BOARD

AI and the Board: the questions that show whether AI is working in a B2B software company.

Also known as: board AI oversight, AI governance for boards, AI strategy for NEDs, AI readiness.

Every chair asks the CEO the same question: where are we on AI? Most CEOs answer it in aggregate. Copilots in marketing, a forecasting model in sales, an agent in pilot in customer success. The board nods, and nobody in the room can tell whether any of it is working. This guide sets out the questions that get a board a real answer, and the free Ortent tools that help it check the answer against evidence.

I have held board roles in PE and VC-backed businesses since 2006. I have run commercial teams at a company that built an AI orchestration platform, and at one whose platform was deliberately rules-based with no AI in it at all. In both, the board conversations that mattered were never about which model to buy. They were about who owned the work, what it cost, what it earned and what we could prove.

This guide is for chairs, NEDs, PE operating partners and CEOs of PE and VC-backed B2B software companies, with extra depth for life sciences and healthtech.

// IN SHORT

A board does not need an AI strategy deck. It needs four things. A map of the company's workflows that shows which ones AI can run, which it can help with and which must stay human. A small, separate budget for new AI revenue that is not judged against the same return as cost savings. An inventory and an audit trail for every AI tool in use. And evidence, not a policy document, behind every AI claim the company makes. The public record suggests most companies are not there yet. Of 120 companies Ortent scored from their own filings, 92 report AI revenue that is live. Only 4 say how they fund new AI bets.

Why "where are we on AI?" gets the wrong answer

AI is not adopted by a company. It is adopted inside individual workflows, and each workflow carries its own risk and its own case for AI. An aggregate answer hides exactly the detail the chair needs: which workflows have changed, what that cost, and what it earned.

The aggregate answer also tilts towards cost savings, because savings are easy to count. A process that took ten people now takes six. That is real money, and boards should take it. The problem is that a competitor can buy the same tools next quarter and take the same cost out. The saving tends to get passed on to customers in price rather than kept as margin. The question that tells a board whether AI is changing the company's position is a different one: did it make us any money we could not have made before?

The rest of this guide splits the board's job into four areas. What to ask in the boardroom. How to fund AI as a strategy. How to decide where AI goes in operations. And what the evidence outside the company says.

AI is not adopted by a company. It is adopted inside workflows, one at a time.

AI in the boardroom: nine questions for every quarter

Open board papers on a dark walnut desk, with a burnt-orange pen marking a line of text and a stack of index cards carrying scoring notes in the corner.
// THE BOARD PACKAsk the same nine questions in the same order every quarter, and compare the answers with last quarter's.

These questions come from the essays and tools behind this guide. Ask them in the same order every quarter, the way you would work through a risk map. If an answer comes back as the title of a document, the follow-up is simple: show me the artefact.

  1. Show me the map. Which workflows use AI today, what is the current risk score on each, which are agent-ready, augment or human-only, and which one are we moving this quarter?
  2. Did it make us money we could not have made before? Report new AI revenue separately from AI cost savings, so the board can see both.
  3. How are new AI bets funded, and who owns them? There should be a ring-fenced budget, one named owner and a quarterly review, with a written point at which each bet is stopped.
  4. Can we produce the inventory on demand? Every AI tool in every part of the operating model, with its owner, the data it can see and the date it was last reviewed. The board does not need to audit the stack. It needs to know the audit can be produced quickly.
  5. Can a non-engineer reconstruct any decision the system made in the last twelve months? If not, the company does not yet have an AI product it can defend in front of a regulator or a customer.
  6. Who owns the orchestration layer? If the honest answer is the model vendor, the company's advantage depends on that vendor's roadmap, pricing and licence terms.
  7. Do we own the AI in our own product? Can we evidence our rights to the data it was trained on and the data it uses, today?
  8. Where is the substantiation for every AI claim we make? Every claim on the website, in a proposal or in a pitch deck (autonomous, AI-powered, an accuracy figure) should have a file behind it. In a sale process, a buyer will ask for it.
  9. Do we know which AI rules apply, and which framework we run to? A written view of which rules apply and from when, such as the EU AI Act where the company sells into or operates in the EU, mapped to a recognised framework such as ISO/IEC 42001 or the NIST AI Risk Management Framework, and reviewed whenever the rules change. A board does not need to be the legal expert. It needs to know someone has written this down.

The AI Board Diagnostic scores a board on these nine questions in about ten minutes, on five stages from not discussed to governed, and names the question to fix first.

Track the answers over time, not just the content. The rule I use on a risk map works here too. One quarter without a good answer is a process problem. Two quarters is an ownership problem. Three quarters means the leadership has not taken it on.

Questions 7 and 8 are the ones that surface latest and cost most, usually in diligence at exit. A written AI policy does not answer either of them. The Diligence Radar scores a SaaS or AI company on nine of these quieter domains, including AI governance and claims, on two axes: how exposed the company is and how ready it is to evidence its position. More on this in Ask for proof, not policy.

AI and strategy: fund new revenue, not only savings

The AI value gap is the distance between those two kinds of return. On one axis is the operational efficiency a company has realised from AI. On the other is the new revenue AI has created. A company high on efficiency and low on new revenue is in what I call the Efficiency Trap: the savings are real, but they will not set it apart for long. Companies that score well on both are the Reinventors. (The full argument is in The Efficiency Trap.)

New AI revenue usually comes from one of four patterns, set out in the Reinventors tool.

  1. Productised expertise. A service that was uneconomic to deliver one customer at a time, now delivered at scale.
  2. New product surface. A capability that could not exist before the model, built in as a feature or a product.
  3. New pricing model. Usage or outcome-based pricing that AI makes measurable and defensible.
  4. New reachable segment. A market that was too small or too costly to serve until the cost of serving it fell.

The board should not try to pick the winning bet. It should set up the conditions for the company to find it. That means a small reinvention budget that is ring-fenced from the efficiency budget and not held to the same return, because early bets will not clear that bar. It means running the bets as a portfolio and expecting most early probes to fail. And it means a staged funding ladder: frame the bet in one sentence with the riskiest assumption and a point at which you stop; probe that assumption as cheaply as possible; pilot with real customers and real, small revenue; and only scale once the economics hold and a competitor cannot copy the play by buying the same AI next quarter.

The Reinventors tool scores each candidate bet on six axes: customer pull, adjacency to the core, defensibility, capability to deliver, speed to a real yes or no, and whether the downside is capped. The AI Value Gap diagnostic places a company on the efficiency and new-revenue axes so the board can see where it starts.

AI in operations: decide workflow by workflow

AI needs something to deploy into. An agent cannot run a handoff that nobody has ever drawn, and it cannot triage escalations if there is no record of how they were triaged before. The artefact that solves this is a target operating model: a one-page map of the end-to-end workflows that run the business, with an owner, a process and a risk score behind each one. Building a clean operating model and preparing a company for AI turn out to be the same piece of work.

On top of the map, each workflow gets one of three AI classifications. This is the overlay on the interactive target operating model.

Agent-ready Augment Human-only
What it meansAn AI agent can run the workflow end to end, under audit and replayAI speeds or improves the human work but cannot run the workflow on its ownJudgement, accountability, regulation or context that does not codify
Human roleIn the loop on exceptions onlyIn the loop on every decisionOwns the work
PreconditionsCodified handoffs, clean inputs, outputs that can be inspectedA clear process the AI sits insideNone. AI is the wrong tool here
Where the gain showsCost and capacityCycle time and qualityRisk avoided by not deploying
Board questionAre the controls fixed before the agent goes in?Is the gain measured, and over how long?Is anyone deploying AI here anyway?

The classification is not enough on its own. Read it next to the risk score, and next to a view of where AI would pay back most. An agent-ready workflow with a high cost of friction is the best place to invest. An agent-ready workflow that already runs well is a poor use of the next quarter's budget. The board's job is to argue about that priority on one page, rather than in slides about copilots.

Two more things decide whether operational AI holds up. The first is architecture. In regulated and specialised work, a chain of small components tuned to narrow tasks, under an orchestration layer the company owns, usually does better than one large general model. The second is the audit trail: every call, input, output, model version and prompt version, kept and searchable by the company rather than the vendor. Without both, AI spend tends to spread department by department with no shared record, and the first serious regulator or customer question becomes a board problem. (See Don't build the LLM and The IT stack nobody audits.)

If your board gets an aggregate answer on AI and cannot see which workflows have actually moved, a 30-minute intro call is the quickest way to test where the gap is.

Book a 30-minute intro call

AI market evidence: what the public record shows

An open ledger on a dark desk with a single line lit by a narrow beam of light while the rest of the page sits in shadow.
// WHAT COMPANIES DISCLOSECompanies put AI revenue on the record. They go quiet on cost, capacity and how new AI bets are funded.

A board should know what peers and competitors say about AI in public, because that is what buyers and investors read. Ortent publishes three free sources for this.

What 120 companies disclose. Between 6 and 23 August 2026, Ortent scored 120 public companies from their own filings and statements on the AI Value Gap questions. 92 report AI revenue that is live. 37 say how their AI savings compared with what they expected. 75 say nothing about what happened to the capacity AI freed up. Only 4 say how they fund new AI bets. Of 720 answers in total, 244 were not disclosed, and 241 of those sit on the cost and funding side. Companies are happy to talk about AI revenue. They are much quieter about what it cost and how the next bets get paid for, which are the questions a board should be asking internally. The full table and data are free to download.

Healthcare AI. The Healthcare AI Radar maps seventeen categories of AI in healthcare, eleven clinical and six administrative. Each is scored on evidence, deployment and economics, and its status is set by its weakest score, because one weak leg is what stops a category scaling. Before a board backs a healthcare AI product or acquisition, it should know which of the three legs is the weak one.

NHS boards. The NHS Board Radar reads the published board papers of NHS organisations. In the October 2026 refresh, AI appears in the papers of 134 of 143 organisations, and it is the one priority with real momentum, almost all of it ambient voice moving from trial into routine use. Even so, no organisation scores above 7 on AI delivery, because no board pack yet shows AI producing a measured benefit sustained over more than one period. Any board, NHS or not, can use that as its own test.

One caution when reading these sources. An outside-in score measures what a company has published, not how well it uses AI.

Worked example: one map, three answers

Take a healthtech company with three workflows on the same operating model.

The "acquire customer" workflow is amber on the risk score and agent-ready on the AI overlay. It could be automated end to end, but the risk score says fix the controls first. Invest in the audit trail, then deploy the agent.

The "patient pathway" workflow is red on the risk score and human-only on the AI overlay. AI is the wrong tool here. The workflow needs its operating model fixed before any model is called. A board's instinct may be to put an agent on its most troubled workflow, and in this case that would add risk.

The "regulatory filing" workflow is green on the risk score and augment on the AI overlay. AI can speed up the analyst's work, but a person still signs. The gain shows up in cycle time, not headcount.

Three workflows give three different answers, and none of them is visible if the CEO answers the chair in aggregate.

Two things from my own operating years sit behind this. When I was COO at Lumeon, every part of the operating model had a named owner, a codified process, a risk score and a quarterly review, and the board read the colours on it when it wanted to know where the risks were. Lumeon's platform was rules-based, with no AI in it, and the discipline of the map was what made it work. At Sapio Sciences, SigmaticOS was built as an orchestration platform rather than a single model: over a hundred agents, each tuned to a part of the drug discovery loop, sitting under an orchestrator that chose the right agent and passed it the right context. The value sat in the orchestration and the record of what each agent did, not in any one model.

How Ortent works with boards on AI

Ortent Advisory works with chairs, boards and CEOs of PE and VC-backed B2B software companies, with depth in life sciences and healthtech. AI work runs through the same five services as everything else. Which one fits depends on how many gaps the board can see.

  1. Sprint. One clear AI question, one board-ready answer in two weeks. For example: should we fund this AI product line, or would our AI claims hold up in diligence?
  2. 90-day Diagnostic. For several gaps at once. A full commercial and operating read against evidence, including the operating model, the AI overlay and where new AI revenue could come from.
  3. Advisory. Standing counsel to the CEO or chair on a monthly cadence, including the quarterly AI questions above.
  4. Non-executive director. A board seat with operator experience in growth-stage SaaS, life sciences and AI.
  5. Fractional CGO. When a new AI revenue line needs a senior commercial owner inside the executive team.

Engagements start with a 30-minute intro call to test fit.

FAQs

What questions should a board ask about AI?

Start with nine, asked in the same order every quarter. Which workflows use AI, at what risk, and which one moves this quarter. Whether AI has created revenue the company could not have made before. How new AI bets are funded and who owns them. Whether the AI tool inventory can be produced on demand. Whether a non-engineer can reconstruct any decision the system made. Who owns the orchestration layer. Whether the company can evidence its rights to the data its AI uses. And where the substantiation is for every AI claim the company makes, and whether the board has a written view of which AI rules apply and which framework the company runs its AI work to.

Who should own AI at board level?

The board as a whole owns oversight, through a standing set of questions each quarter. Below the board, each AI bet and each AI workflow needs one named executive owner and a quarterly review. When ownership is spread across departments, AI spend grows function by function with no shared inventory or audit trail.

Is an AI policy enough for AI governance?

No. A written AI policy is not AI governance. A board should ask for the artefacts that show the controls run: the AI tool inventory with owners and data scope, the audit trail of what the systems did, evidence of rights to training and input data, and a substantiation file for each AI claim. If the answer to a board question is a document title, ask to see the artefact.

How should a board measure the return on AI?

Report two numbers separately: the efficiency AI has realised and the new revenue it has created. Savings are easier to count but tend to be competed away once competitors buy the same tools. For any claimed benefit, ask whether it has been measured and whether it has held for more than one period.

What is the AI value gap?

The gap between the operational efficiency a company has realised from AI and the new revenue AI has created for it. A company high on efficiency and low on new revenue is in the Efficiency Trap. A company that scores well on both is a Reinventor. The free AI Value Gap diagnostic on ortent.co places a company on both axes.

What makes a workflow agent-ready?

An agent-ready workflow can be run end to end by an AI agent, under audit and replay, with a person in the loop only on exceptions. That needs codified handoffs, clean inputs and outputs that can be inspected. If the workflow also carries a high risk score, fix the controls and the audit trail before deploying the agent.

Should a company build its own large language model?

Rarely. In regulated and specialised work, a chain of small components tuned to narrow tasks, under an orchestration layer the company owns, usually does better than one large general model and is far easier to audit. The board questions are which tasks a smaller component would handle better, who owns the orchestration layer, and whether any decision can be reconstructed.

Does this apply to healthcare and life sciences companies?

Yes, with extra evidence available. The Healthcare AI Radar scores seventeen categories of healthcare AI on evidence, deployment and economics, with status set by the weakest score. The NHS Board Radar shows how NHS boards report AI: in October 2026 AI appears in the papers of 134 of 143 organisations, but no board pack yet shows a measured benefit sustained over more than one period.

Is there a tool to score a board on these questions?

Yes. The AI Board Diagnostic on ortent.co scores a board on the nine questions, each on five stages: not discussed, discussed, owned, measured and governed. A policy on its own never scores above discussed. It takes about ten minutes, stores nothing, and names the question to fix first. A Claude prompt version scores the same questions from real evidence and ends with a 90-day plan.

// FIELD NOTES BY EMAIL

Not ready to talk? Get the next field note in your inbox.

Delivered via Substack. Unsubscribe any time. See our privacy notice.

// GET IN TOUCH

Clarity when it counts.

If you have a board seat, a fractional mandate or a commercial reset coming up in the next 90 days, email directly. We'll book 30 minutes to see whether Ortent is the right fit.

Book a 30-minute intro call