P.K. SHARMA

Cyber security intelligence, AI governance, practitioner analysis

Knowledge transfer

Board AI Risk Briefing

A two-hour session that shows a board the architecture beneath the AI risk they are being asked to accept, with live demonstrations rather than slides about slides.

Most boards are briefed on AI risk without ever seeing the thing being described. They are shown a heat map and a list of regulations, asked to accept a risk appetite, and left with no way to judge whether the advice was any good. Directors are not short of AI opinions. They are short of a working mental model, and no amount of governance language substitutes for one.

2 hrs

One session

Structured for people who will not read a technical paper.

4

Live demonstrations

Shown running, not described on a slide.

0

Prerequisites

No technical background assumed of any attendee.

1

Written record

Short enough to reach the minutes.

What gets covered

How a model actually answers

Shown running, not described. Ten minutes here changes every conversation that follows, because the board stops treating the system as an oracle.

Where it breaks

Prompt injection demonstrated against a system holding credentials. This is the moment the risk becomes concrete rather than abstract.

Your regulatory position

Which obligations already apply, which have moved, and which are contractual rather than statutory. Stated plainly, with dates.

The questions to ask

What a director should be asking the executive, and what a good answer sounds like as distinct from a confident one.

How the two hours run

  1. 1

    Before: establish what you actually use

    A short discovery so the session is about your estate rather than a generic deck. Usually reveals more AI in use than the board expects.

  2. 2

    First thirty minutes: the mechanism

    How a model produces an answer, demonstrated live. No mathematics, no jargon, and no slides describing slides.

  3. 3

    Next thirty: where it fails

    Hallucination as a structural property rather than a bug, and a live prompt injection against a system with real permissions.

  4. 4

    Third thirty: your exposure

    Your regulatory position and your actual deployments, including the ones nobody approved.

  5. 5

    Final thirty: what to do

    The decisions in front of the board, and the questions to put to the executive.

  6. 6

    After: the written record

    A short summary so the discussion survives into the minutes rather than into memory.

What you walk away with

  • A two-hour session built around your estate rather than a generic deck
  • Live demonstrations rather than descriptions of demonstrations
  • A plain statement of your regulatory position with dates
  • A question set for directors to put to the executive
  • A written record suitable for the minutes
  • A recommendation on what, if anything, warrants programme work

How this plays out

Example scenario

A board that had already approved an AI policy.

The work: Briefing including a live prompt injection demonstration.

The policy was sound and the board had approved it without understanding what it was mitigating. They asked materially better questions afterwards, which is the entire point.

Example scenario

Directors told AI risk was under control.

The work: Short discovery before the session.

Meeting transcription tools were in use across the executive team, unapproved, recording confidential discussions. The risk that mattered was not the one on the register.

Example scenario

A board weighing an AI investment.

The work: Session focused on the mechanism rather than the market.

The proposal proceeded with a narrower scope and an owner, having previously been a budget line with an ambition attached.

Start the conversation

A short call to understand your situation; a clear scope if the engagement fits, and a straight answer if it does not.

Book a board briefing

Share this

Send it to whoever owns the budget or the risk.

← All services

The problem

Most boards are briefed on AI risk without ever seeing the thing being described. They are shown a heat map and a list of regulations, asked to accept a risk appetite, and left without any way to judge whether the advice they received was good.

Directors are not short of AI opinions. They are short of a working mental model, and no amount of governance language substitutes for one.

What you get

  • Two hours, structured for people who will not read a technical paper and should not have to
  • Live demonstration rather than description: how a model actually produces an answer, and what a prompt injection does to a system that holds credentials
  • Your regulatory position stated plainly, including which obligations already apply and which have moved
  • The questions a director should be asking their executive, and what a good answer sounds like
  • A short written record afterwards, so the discussion survives into the minutes

Proof point

Delivered by a practitioner who builds and audits these systems, using the same interactive explainers published free on this site. Engagements frequently begin here and continue into programme work once the board has decided what it is actually worried about.