Blog
The Case for Secure AI for Corporate Boards

Generative AI is becoming an increasingly useful tool for corporate directors.
It can help a board member understand an unfamiliar market, synthesize lengthy materials, pressure-test a strategic argument, prepare questions for management, analyze competitors, or work through complex information before a meeting.
Boards are paying attention. More than 62% of directors surveyed by the National Association of Corporate Directors now set aside agenda time for full-board discussions about AI. At the same time, NACD describes governance practices around the technology as still lagging.
KPMG’s 2025 survey of nearly 100 U.S. directors found a similar pattern. Companies are beginning to move from experimentation toward scaled adoption of generative AI, while data security, compliance, talent, and governance remain significant hurdles.
AI is moving quickly into corporate decision-making.
The security infrastructure around how people actually use it has not moved as quickly.
The rise of shadow AI
The risk is already visible across the enterprise.
KPMG found that 44% of U.S. employees were using AI at work in ways their employers had not authorized. More significantly, 46% reported uploading sensitive company information or intellectual property into public AI platforms.
That behavior is increasingly referred to as shadow AI: employees adopting powerful AI tools faster than their organizations can approve, secure, or govern them.
There is little reason to assume senior executives and directors are immune.
For a board member, the workflow can be especially tempting.
A director receives a dense board book before a meeting. They want a second perspective on a proposed acquisition, an explanation of an unfamiliar market, or a concise summary of a lengthy strategic memo.
A general-purpose AI tool can provide an answer in seconds.
The easiest thing to do is also potentially the riskiest: paste the information into a personal AI account.
For most knowledge work, that might involve an internal presentation or ordinary business document.
For a director, it could involve acquisition discussions, forecasts, litigation, cyber incidents, executive succession, strategic alternatives, customer information, or other highly confidential board materials.
A consumer AI account is not a boardroom
The issue is more nuanced than saying that public AI providers simply "train on everything."
They do not.
Major AI platforms now provide privacy controls, and their enterprise products can offer materially stronger protections than their consumer products.
The underlying problem for boards is control.
With an individual consumer account, important questions can depend on the provider, account type, and settings selected by the individual user.
Is model training enabled?
How long is the conversation retained?
Has the director used a temporary or private mode?
Does the conversation remain in their account history?
Was the document uploaded through a corporate account or a personal one?
Can the company enforce its own retention policy?
Can its security team establish what information was shared?
Those are poor questions to leave to individual directors when the underlying information may be among the most sensitive a company possesses.
For board information, the standard should be higher.
AI conversations can become records
There is another emerging issue: an AI interaction can create a new information artifact.
A prompt may reproduce confidential information. An output may contain analysis of that information. The conversation may document how an executive or director was thinking about an issue at a particular moment.
Courts are already beginning to confront what that means.
Reuters reported in July 2026 that courts are grappling with whether generative AI prompts receive privilege or work-product protection, with outcomes depending heavily on who created them, why they were created, and how the resulting output was used.
A month earlier, a federal judge allowed prosecutors to execute a search warrant targeting an executive's AI chatbot communications. The executive had argued that some of the conversations contained material related to his legal defense.
These cases are still developing, and the legal treatment of AI conversations will continue to evolve.
But they expose a basic information-governance question for boards:
Should a casual AI interaction create a persistent external record of confidential board thinking at all?
For many board workflows, it should not.
The answer is secure AI, not less AI
Preventing directors from using AI altogether is unlikely to be an effective long-term strategy.
The technology is too useful.
Directors can use AI to arrive at meetings better informed, interrogate information more deeply, connect ideas across hundreds of pages, understand outside developments, and formulate better questions for management.
The objective should therefore be to bring those capabilities into an environment appropriate for board-level information.
Private by default.
Controlled access.
Clear information boundaries.
Minimal unnecessary persistence.
And security designed around the sensitivity of board work.
AI Analyst, built for the boardroom
That is why BoardRadar built AI Analyst.
AI Analyst brings conversational AI directly into BoardRadar, allowing directors to ask questions, analyze information, and work with their own board context without copying sensitive information into a consumer AI workflow.
It can draw from knowledge already available within BoardRadar to support its answers, creating an AI experience grounded in the information relevant to the director.
More importantly, it is designed around a fundamentally different security model:
Private, isolated processing
No retention of prompts
No retention of outputs
No retention of documents used during an AI session
No use of documents, prompts, or outputs to train AI models
Controlled access within the BoardRadar environment
Directors should be able to use the best capabilities of modern AI without compromising the information standards expected of a board.
AI adoption in the boardroom is already underway.
The next step is making it secure.
The boardroom needs AI built for the boardroom.