OnBoard’s sixth annual survey finds a 32-point effectiveness gap between boards that govern director AI use and boards that don’t.
Ninety-two percent of board directors used AI for board work in the past six months, according to the sixth annual OnBoard Board Effectiveness Survey of 531 governance professionals—up from 69% a year earlier.
Three days before the board meeting, a director opens a 300-page board book, weighs the limited time to prepare, and uploads the file to their preferred large language model. They ask about what they should push back on. And when the meeting starts, the director walks in prepared. No one approved the tool. No one knows it was used. The organization’s most sensitive material sits in a consumer chat log.

The survey recorded the other side of that Sunday night: Confidence in board security fell 15 points year over year, the steepest decline in the study, and data privacy now tops the list of AI’s negative impacts. Boards can feel the practice running ahead of the rules—mostly because there are none. Sixty-three percent have no formal AI policy. Only 6% have an enforced one, with signatures and reviews.
That gap carries a measurable cost. The survey maps boards onto a five-stage AI maturity curve, from nothing in place to an enforced policy, and self-rated effectiveness climbs at every stage: Boards at the enforced end rate themselves effective at 88%—boards with nothing, 55%.

Boards spent 20 years building walls around the board book, and AI carried it out through a chat window in 18 months. An AI for directors has to live inside the rules of the room—the board’s permissions, the board’s record, no training on board data. Directors should never have to choose between being prepared and keeping confidence—Marc Huffman, CEO, OnBoard
The data argues for three changes:
1. Write the policy down. The single largest effectiveness lift in the dataset happens when a board moves from discussing AI to producing a written document—even basic guidelines. The document determines what a fiduciary may do with confidential board material. It belongs alongside directors and officers coverage and audit oversight on a governance committee agenda.
2. Assume every consumer chat is discoverable. Summarizing board books is the survey’s most common director use case—54% of AI-using directors do it, mostly in consumer tools. The past year established what that means. In the New York Times copyright litigation, a federal court ordered OpenAI to preserve user chats that would otherwise be deleted, then ordered 20 million de-identified consumer conversations produced to the plaintiffs. OpenAI’s chief executive has acknowledged that ChatGPT conversations carry no legal privilege. This February, a federal judge ruled that strategy documents drafted with a consumer chatbot were not protected by attorney-client privilege—law firms now warn that sharing privileged material with a chatbot may waive the privilege. A board book summarized in a personal account is a record outside the board’s control: retained, discoverable, and on consumer tiers used for model training by default.
3. Enforce the policy, don’t just write it. The gains concentrate at enforcement, not at the point a board writes a policy down. Security confidence holds steady through the middle stages, then rises 24 points when boards enforce. Enforcement takes more than a document. A written policy cannot follow a board book into a consumer chatbot. It requires AI grounded in the board’s actual record, bound by the permissions the board already set, and barred from training on board material. With those guardrails in place, the highest-judgment work comes into scope. Directors using AI to anticipate board questions rise from 12% on no-policy boards to 67% under enforcement.
The rules are not complicated. Ground every answer in the board’s actual record, respect the permissions the board already defined, never train on board material—and leave the judgment to the people in the seats. —Tim Adair, Chief Product Officer, OnBoard
In a keynote broadcast on July 15, OnBoard’s leaders Huffman, Adair, and chief customer officer Anusha Srijeyanathan will present where AI in the boardroom is going: shared institutional memory rather than a consumer chatbot—secure AI inside the board’s system, assisting proactively instead of waiting to be asked. They will show briefings tuned to each director’s expertise, action items that land on the next agenda with owners attached, and new directors who arrive caught up on years of board history, all built to amplify the directors already at the table.

The pattern across this data is a board that adopted AI faster than it governed it. Ungoverned use now shows up as evidence in court, and governed boards score measurably higher on effectiveness. Putting one agenda item before the governance committee is where the fix begins.
The Future of OnBoard AI streams live July 15 at 1:00 p.m. ET. Register to attend.
Note: This content was created by OnBoard.

