Do you have to tell the board the analysis was AI-assisted?
Disclose that the analysis was AI-assisted, and put your protection in verifiability: a one-page provenance statement, a live source check in the room and a retained record let a skeptical director test every claim, so the recommendation survives the challenge.
The direct answer: no single rule compels you to disclose that part of a board deck was drafted with an AI strategy platform, and disclosure is nonetheless the right default. The reason is practical rather than legal. A board deck is a set of claims, and at some point a director challenges one of them. When that happens, the presenter who has already said which parts of the analysis were machine-drafted and who verified them keeps the room; the presenter who is asked mid-meeting how a figure was produced, and answers vaguely, loses the room. Disclosure is what preserves trust when a figure is challenged, and concealment is the weaker position even where no rule forces disclosure.
- The FRC's guidance to the UK Corporate Governance Code 2024 lists, among the extra steps a board may wish to consider for significant decisions, describing in board papers how the proposals have been developed and challenged prior to presenting them to the board.[1] The guidance is not mandatory, but a paper that is silent on how its analysis was produced sits awkwardly against it.
- The EU AI Act's Article 50 transparency duties, which came into force on 2 August 2026, are narrow: they concern providers and deployers of certain AI systems, including duties to inform people that they are interacting with an AI system, to mark synthetic content in a machine-readable format, and to disclose deep fakes.[2] They are not a mandate to label an internal strategy deck, and reading them that way overstates their scope.
- The OECD AI Principles ask AI actors to commit to transparency and responsible disclosure, providing meaningful information appropriate to the context about AI systems, their capabilities and limitations.[3]
- The direction of travel is visible in boardrooms themselves: in PwC's board effectiveness survey of the C-suite, 99% of executives believe boards should be using AI for oversight, yet only 35% of directors say their boards currently do so.[4]
Put together, these points describe a norm rather than a prohibition. Governance guidance expects papers to explain how proposals were built and challenged, and transparency rules where they exist are targeted at other harms. What the board is testing, then, is not the involvement of a tool but whether the analysis behind the recommendation can be trusted. A presenter who discloses plainly starts from the stronger position.
The provenance statement: one page that makes the deck checkable
The working answer to the skeptical director is not a tone of voice or a well-rehearsed defence. It is an artifact: one slide or appendix page, placed in the deck, that states in plain language how the analysis was produced and who stands behind it. Call it the provenance statement. It carries six lines, and each line exists because a director can do something specific with it.
| Line of the provenance statement | What it is for | What a director can do with it |
|---|---|---|
| Which parts of the analysis were AI-drafted and which the team wrote | Separates machine-generated drafts from human-authored analysis so the board knows where each type of risk sits | Probe the boundary: ask why a section was drafted one way rather than the other |
| The named person who verified each load-bearing claim, and how: each cited source opened and compared to the slide | Attaches accountability to the numbers the recommendation depends on, with a stated method rather than a general assurance | Re-run the check, or ask the named person directly, because responsibility is attached to a name |
| The full source list | Shows what the analysis rests on, source by source | Test the evidence base: check whether a preferred source is missing or a source is weaker than it looks |
| The date of the document set the analysis is based on | Fixes the knowledge cutoff so the board knows what was known when the analysis was run | Ask whether anything has changed since that date that the analysis cannot see |
| What was excluded or could not be verified | States the limits honestly, including items the team could not confirm | Probe the boundary of the analysis rather than discovering the gaps by accident |
| Who signs off on the recommendation | Confirms that a human, not a tool, owns the conclusion | Hold a person accountable for the recommendation, as with any other board paper |
The page also does quiet compliance work. The OECD transparency principle asks for meaningful information, appropriate to the context, about the sources and logic behind an AI system's role; a page that names the tool's contribution, the verifier and the source list is that information, written for the one context that matters here.[3] It is also the most checkable form of the process description that governance guidance already anticipates for significant decisions. For a worked protocol on reviewing AI-drafted analysis before it reaches a committee, see the guide to fact-checking an AI-generated strategy deck.
A live challenge in the room: a worked example
Suppose a slide states that the target segment accounts for a given share of revenue, sourced to an industry report, and a director asks where the number comes from. The exchange that follows is where the provenance statement earns its place. Handled well, it runs beat by beat:
- The presenter opens the cited source on screen or in the appendix, in front of the board, rather than summarising it from memory.
- The presenter confirms the scope of the figure on the record: what population the source covers and what it measures.
- The presenter confirms the bound: whether the figure is a point estimate, a range or a forecast, and which of those the slide claims.
- The presenter confirms the date of the source and the unit of the figure, so the board knows the number is current and expressed in the terms the slide uses.
- If the figure matches the source, it stands, and the director has watched it stand rather than being asked to take it on trust.
- If the figure does not match, for example because the slide rounded past what the source supports or used an older edition, the presenter corrects it on the record and states the corrected figure and its source.
The reason correcting openly protects the recommendation is that it preserves the board's ability to audit the rest of the deck. A director who has seen one figure checked live, and seen the presenter concede and correct a mismatch, has evidence that the other figures were produced under the same discipline. The reason defending an unverifiable number destroys the recommendation is symmetrical: the moment a presenter resists a checkable challenge, every other figure in the deck becomes suspect, because the board has learned that the numbers are defended rather than verified. PwC's guidance for directors makes the underlying point plainly: AI-generated outputs may contain errors or biases that appear credible, which is why the information needs to be verified and human judgement applied before it is relied on.[5] Fluency is not verification, and the open check is how the difference is shown. For why traceable sources are the mechanism that makes such checks possible, see this account of auditable strategy decks.
The questions skeptical directors actually ask
Across boards and investment committees, the questions about AI-assisted analysis reduce to four. What did the tool see? What did it not see? Who checked it? What would change the conclusion? None of these is hostile; each is a director doing the job. The provenance statement is useful precisely because each question maps to a line on the page, so the answer is read out rather than improvised.
| The director's question | What it is really probing | The provenance line that answers it |
|---|---|---|
| What did the tool see? | The evidence base the analysis was run on, and how current it is | The document set and its date |
| What did it not see? | The exclusions, gaps and items that could not be confirmed | The line on exclusions and unverifiable items |
| Who checked it? | Whether a named person stands behind the load-bearing claims, and by what method | The named verifier and the verification method: each cited source opened and compared to the slide |
| What would change the conclusion? | How sensitive the recommendation is to its load-bearing claims | The verifier line together with the source list, which shows which claims the recommendation depends on and how firmly each is evidenced |
Pre-answering these questions on the page beats improvising in the room for a simple reason: an answer composed under challenge sounds like a defence, while the same answer printed in the deck reads as part of the analysis. It also signals that the team anticipated scrutiny, which is itself evidence of rigour. Directors have a standing prompt to ask these questions of their own company: the FRC guidance lists, among the questions boards should ask themselves, whether they are aware of emerging technologies, including responsible artificial intelligence, being used by the company, for example in reporting.[1] A board that asks that question of the company will ask it of the deck in front of it.
After the meeting: keeping the decision revisitable
The provenance statement has a second life after the meeting. The deck, its source list and the provenance statement should be retained together, so that the decision can be revisited months later on honest terms. A later review that has the retained record can test the analysis against what was actually known at the time: the document set and its date fix what information existed, the exclusions line records what could not be verified, and the source list shows which figures the recommendation rested on. Without that record, a review drifts into hindsight, judging the decision by what happened rather than by what was knowable when it was made.
- Test the analysis against the knowledge available at the time, using the dated document set rather than memory.
- Re-check the load-bearing claims against their cited sources, using the named verifier's stated method.
- Locate the boundary of the analysis, using the exclusions line, before assuming a miss was a failure of judgement rather than a known limit.
Retention also fits what governance guidance anticipates. Among the extra steps the FRC guidance suggests a board may consider for significant decisions is ensuring that board minutes document the discussion that led to the decision, including the issues raised and the reasons for the decision.[1] A provenance statement filed with the deck gives the minutes something accurate to reflect. The practical point is that AI use tends to leave a written record of its own, in prompts, drafts and outputs, whether or not anyone plans for it, so retention is better handled as a deliberate policy than left to accident.
What not to do: concealment, over-claiming and fluency
Three failure modes account for most of the ways AI-assisted board presentations go wrong. Each is avoidable, and each is worth naming in advance.
- Hiding AI use. The concealment pattern is well documented elsewhere in the organisation: in ISACA's 2023 generative AI pulse poll of digital trust professionals, only 28% of organisations said their companies expressly permitted the use of generative AI, while over 40% said employees were using it regardless and a further 35% were not sure.[6] Undeclared use inside a strategy team is the same pattern with higher stakes, because the deck reaches the board. Disclosure costs one line; discovery of concealment costs the credibility of every figure in the deck.
- Over-claiming the tool's rigour. Describing the analysis as validated, audited or independently checked when what happened was that a tool drafted it and a person skimmed it invites the one challenge the presenter cannot answer in the room: show me. The provenance statement protects because it claims only what happened, and the named verifier can describe exactly what was done.
- Letting fluency substitute for judgement. NIST's AI Risk Management Framework notes that humans may assume AI systems work, and work well, in all settings, and that, whether correct or not, AI systems are often perceived as being more objective than humans.[7] Polished prose is the most dangerous form of this perception, because a well-written slide reads as a verified slide. It is not. The team's judgement, applied at the point of verification and sign-off, is what the board is being asked to trust.
The common thread is a bad trade: each failure mode avoids a small, manageable discomfort, a line of disclosure, a modest claim, an admission of limits, and pays for it in unmanaged risk.
Where the tooling matters: verifiability by design
One closing note on tooling. Decisity is an AI-native strategy consulting platform whose decks carry every claim, number and recommendation clickable to its source. That single property is what makes the practices in this article mechanically possible rather than aspirational: a provenance statement is only as good as the links behind it, and a live source check in the room takes seconds when the cited source is one click away from the slide. It also supports what the OECD accountability principle asks of AI actors, that they be accountable for the proper functioning of AI systems throughout their lifecycle, in line with their role and context.[3] For a description of the end-to-end workflow, from document ingestion to a board-ready deck with full source traceability, see how the platform works.
The tool does not replace the presenter's obligations; it removes the excuses. When every figure in the deck can be opened to its source on demand, disclosure becomes cheap, verification becomes routine, and the skeptical director's four questions have answers that are on the page and checkable in the room, in the meeting and again months later when the decision is revisited.
Related reading:
Sources
- FRC: Corporate Governance Code Guidance
- EU Artificial Intelligence Act: Article 50, Transparency Obligations for Providers and Deployers of Certain AI Systems
- OECD: Recommendation of the Council on Artificial Intelligence (OECD/LEGAL/0449)
- PwC and The Conference Board: Board Effectiveness: A survey of the C-suite (2026)
- Harvard Law School Forum on Corporate Governance: Using AI in the Boardroom: New Opportunities and Challenges (PwC, 29 November 2025)
- ISACA: Generative AI Training, Formal Policies in Short Supply for Most Organizations (@ISACA 2023, Volume 43)
- NIST AI Resource Center: AI RMF 1.0, Section 1: Framing Risk



