Boardroom

    The board's AI discipline: governance that works without slowing adoption

    May 3, 2026·13 min read

    70% of Danish companies use AI, 56% of employees use unauthorised tools, and only 36% have formal governance frameworks. The governance gap, the EU AI Act, C-suite accountability, the quarterly adoption dashboard and seven sharpened questions the board should ask the executive team.

    > 📥 The full article is available as a PDF (9 pages, Danish) with models, sources and appendices. Download it at the top of the page.

    Article 3 of 3 in the series "AI for executives". Part 1 set the premise: leadership's own usage decides whether the license creates value. This part is about the board's discipline — governance that works without slowing AI adoption in the company.

    1. The third conversation a board needs to have

    If you've taken the first two articles onboard as a board member or CEO, you now face the hardest question in the whole transformation: how do you govern AI without slowing its uptake?

    It's a hard balance. Too little governance and you end up with shadow AI, data breaches and EU AI Act fines. Too much governance and you kill the experimentation culture that makes AI valuable in the first place. Both mistakes are common. Both are avoidable.

    2. The governance gap we all sit in

    The numbers are sharp and consistent.

    • 70% of Danish companies use AI tools in 2026 (Dansk Erhverv, Feb 2026), up from 44% in 2023.
    • 56% of employees use unauthorised AI tools at work (IDC, 2025).
    • Only 36% of organisations have formal AI governance frameworks in place (IBM, 2025).

    In most organisations adoption is far ahead of governance. Boards can measure the cost financially. 20% of data breaches in 2025 involved shadow AI. Average added cost per shadow-AI incident: $670,000. Full breach involving shadow AI: $4.63M vs $3.96M standard (IBM Cost of Data Breach 2025).

    3. The ticking deadline: EU AI Act

    The EU AI Act came into force 1 August 2024. The pivotal date for most Danish companies is 2 August 2026, when most of the high-risk AI ruleset applies. For high-risk systems embedded in products already under sector-specific EU regulation (medical devices, machinery, toys, cars), the deadline is 2 August 2027.

    Fines are calibrated for board attention: up to €35M or 7% of global annual turnover for the most serious breaches; €15M or 3% for ordinary breaches; €7.5M or 1% for supplying incorrect information to authorities.

    High-risk categories are broader than many assume: hiring, credit scoring, biometrics, critical infrastructure, education assessment, access to essential services. If HR runs AI CV screening, you're in scope. If the bank uses AI in credit decisions, you're in scope. Conformity assessments alone typically take 6–12 months for complex systems.

    4. Who owns what in the C-suite

    The classic Danish failure mode: AI is "everyone's" responsibility. CIO says HR. HR says CIO. The board gets status reports covering up the fact that nobody truly owns the agenda.

    Internationally the Chief AI Officer role has grown from 11% to 26% of organisations in two years (IBM IBV, 2,300+ orgs, Q1 2025). Among FTSE 100, 48%. Organisations with a CAIO report roughly 10% higher ROI on AI investments.

    The point isn't that you must hire a CAIO. The point is that one named person must be accountable. If it's the CIO, then CIO. If COO, then COO. Clarity on accountability is what to fix first.

    5. How the board measures real adoption

    Most boards get AI reports built on vanity metrics: licences, pilots, departments rolled out. Those are deployment numbers, not adoption numbers. A disciplined board asks for four dimensions every quarter.

    Adoption. Daily active users as a share of assigned licences. Target: >60% monthly active use within 90 days. Red flag: <30% after six months.

    Depth. Prompts per active user per week. Heavy user: 20+/week. Light user: 1–5. Predominantly light usage = deployment without implementation.

    Value. Cycle time, hours saved, quality gains in concrete workflows. Baseline before rollout is critical. Without a baseline: no ROI story to the board later.

    Risk. Number of data-policy violations per month. A rising number doesn't mean risk is growing — it means your visibility is.

    6. Shadow AI is a governance problem, not a compliance problem

    The hard reaction to shadow AI is to block it. It doesn't work. Samsung blocked ChatGPT after a source-code leak — within a year they pulled the block. Microsoft research shows 71% of UK employees admit to using non-approved AI tools at work; 51% at least weekly.

    The effective reaction is to give employees a better approved option than the one they use in hiding:

    1. Deliver ChatGPT Enterprise, Claude or M365 Copilot on every desktop — not just pilots.

    2. Make access to approved tools faster than signing up for a personal account.

    3. Use DLP and prompt monitoring to catch specific risks, not to block usage in general.

    7. Royal Unibrew's governance approach

    Royal Unibrew's five AI agents run inside Microsoft Teams behind the corporate security perimeter. Data stays under organisational control. There's explicit ownership: Michala Svane, Director of Marketing, Digitalization & Business Development — mandate, frame and budget. The title isn't CAIO, but the function is equivalent inside the marketing domain.

    Lise Knuppert Hordam, manager at Royal Unibrew, has publicly stated the critical-use principle:

    > "You have to be critical of everything that comes from Kondi Kai, because he's a machine. What he says is based on all the data we gave him. So it's valid, but it needs a human touch and creative thinking."

    Controlled data perimeter. One named owner. Explicit critical use. Governance in practice.

    8. The board's seven questions — sharpened

    Use as an agenda for the next board meeting. Expect the CEO and executive team to answer with numbers, not narratives.

    1. Are the CEO and executive team using the tool daily themselves? Ask for a concrete demo. Show, don't tell.

    2. Who owns the AI agenda in the exec team? A named person with KPIs. "We have a steering group" means no one.

    3. Can you show the four dashboard numbers? Adoption, depth, value, risk. If not — when do you start measuring?

    4. Where are we relative to the EU AI Act on 2 August 2026? Inventory in place? Risk classification done? Conformity assessments underway?

    5. What is our shadow-AI strategy? Are we blocking, or delivering approved alternatives faster than personal-account signup at shadow-AI apps?

    6. Does the board itself have AI competence? PwC's 2025 Corporate Directors Survey and KPMG/INSEAD (April 2026) find the same pattern: three-quarters of boards have only moderate or limited AI expertise.

    7. What is our exposure if we don't accelerate? Competitors 12 months ahead on adoption win on cycle time. Quantify the risk in lost EBIT.

    9. What the series has been about

    Three articles. One thesis. If leadership doesn't open the tool themselves, the licence changes nothing. If leadership opens it without discipline, they also open the door to shadow AI, breaches and compliance exposure. The value sits in the narrow band between the two.

    The AI licence is bought. The question isn't whether the technology works. It's whether your organisation will survive this. Good luck.


    📥 Download the full article as PDF (Danish) at the top of the page.

    🎓 Want the four dashboard numbers implemented in your organisation? Book an AI Readiness Sprint or a strategic advisory engagement. First conversation is free.

    📬 Subscribe to the newsletter "AI, Built Human" on Substack — bi-weekly insights on the judgment behind the machine.


    Stefano Vincenti · AI Advisor & Trainer · aitrainer.dk · External Lecturer, IT University of Copenhagen · Cofounder & CTO BotTellMe · Partner, TryZone