Back to InsightsResearch

The Board AI Competency Gap: A Diagnostic Framework for Director Capability

By James WaddellApril 16, 202611 min

The Board AI Competency Gap: A Diagnostic Framework for Director Capability

BoardSight Research Brief · Reading time: 11 minutes Category: Research · Published: April 16, 2026 · Author: James Waddell, Cognitive Corp


Abstract

Every board in 2026 has an AI competency gap. The question is not whether the gap exists — it does — but whether the board can locate it, measure it, and close it at a credible pace. This brief proposes a diagnostic framework for board AI competency that combines the BAGI (Building AI Governance Index) dimensions with the AIRS (AI Readiness Scoring) instrument from Cognitive Corp's research corpus, applied not to the organization but to the governing body itself. The output is a director-level readiness map that answers the Caremark competence question (ISO 42001 Clause 7.2) with evidence rather than impression. The thesis: board AI competency is not a checkbox, it is a portfolio problem, and it is measurable.


1. Why the question is arriving now

Three regulatory and doctrinal pressures have converged on the board as a body of people, not as an abstract institution:

ISO 42001 Clause 7.2 (Competence). The standard requires that persons whose work affects the AI management system have demonstrated competence. "Top management" is defined to reach the governing body. The board is inside the competence scope.

EU AI Act Article 26 (Deployer obligations). For high-risk systems, deployers — which for large organizations includes those signing off at the board level — must ensure that natural persons assigned to oversee the system have "the necessary competence, training and authority."

Caremark and the reasonable-director standard. Marchand v. Barnhill and In re Boeing established that boards must make a good-faith effort to monitor mission-critical risks. Courts are increasingly willing to look at board composition and agenda time as evidence of whether that effort was reasonable. A board with no identifiable AI-competent director, no AI-oriented education program, and no recurring AI agenda time is giving plaintiff counsel an easy argument.

The shift is subtle but structural. For a decade, boards could satisfy oversight expectations by appointing a single "cyber director" and delegating technology risk to an audit committee. AI breaks that pattern: it touches strategy, risk, compensation, audit, and nominating committee work simultaneously. A single specialist seat is no longer sufficient.

2. What "AI competent" actually means at the board level

Board AI competence is distinct from practitioner AI competence. A director does not need to build models. A director needs to ask the right questions, read the right documents, challenge the right claims, and recognize the red flags. The competencies cluster into five domains:

Domain 1: Strategic framing. Can the director articulate where AI creates competitive advantage or existential risk for the specific organization? Can the director distinguish productivity AI (efficiency gains, limited strategic consequence) from capability AI (reshapes the business model) from infrastructure AI (embedded in operations and requires ongoing governance)?

Domain 2: Risk literacy. Can the director name the specific AI risks that are material to the organization's sector, and distinguish between bias risk, safety risk, security risk, disclosure risk, and vendor risk? Can the director read a risk register and spot concentration, correlation, and missing categories?

Domain 3: Governance architecture. Can the director read an ISO 42001 conformance summary, a NIST AI RMF profile, or a Statement of Applicability and identify what is present, what is missing, and what the organization is choosing not to do? Can the director distinguish management review records from incident logs from impact assessments?

Domain 4: Vendor and third-party AI. Can the director recognize when a material business dependency is mediated by a third-party AI system and ask whether the contract, the audit rights, and the termination terms match that dependency?

Domain 5: Disclosure and communication. Can the director evaluate whether public disclosures — risk factors, earnings commentary, proxy statements — accurately describe the organization's AI posture without triggering securities exposure?

These five domains map cleanly to the BAGI dimensions Cognitive Corp publishes for organizational assessment, repurposed for director-level diagnostic use. The same scoring logic that grades an organization's governance posture (Explainability, Bias Mitigation, Human-in-the-Loop, Trust, Auditability) can be inverted to grade whether directors can read that posture when it is placed in front of them.

3. The AIRS-for-Directors instrument

The AIRS (AI Readiness Scoring) instrument from the Cognitive Corp research corpus was originally built for organizations. In 2025 we adapted it for director-level diagnostic use. The instrument scores each director on the five domains above across four levels:

Level 0 — Absent. The director cannot articulate the domain or recognize its relevance to the organization. A director at Level 0 on Risk Literacy cannot name three specific AI risks material to the business.

Level 1 — Aware. The director recognizes the domain but relies on briefings for substance. A Level 1 director can follow an AI discussion but cannot lead one, cannot challenge management's framing, and cannot recognize when a briefing is non-responsive.

Level 2 — Engaged. The director can challenge, question, and direct work in the domain. A Level 2 director can read a governance document critically, ask for specific missing evidence, and connect the domain to the organization's strategy.

Level 3 — Expert. The director can mentor other directors and set standards for the domain. A Level 3 director is the board's reference point when a novel situation arises.

A healthy board does not need every director at Level 3. It needs a portfolio: for each domain, at least one director at Level 2 or 3, and the full board at Level 1 or above. A board that is all Level 0 on any one domain has a Caremark documentation problem — the board cannot credibly claim it was monitoring what it cannot read.

4. What the data shows

Cognitive Corp's AIRS-for-Directors diagnostic has been run across several boards in 2025 and the first quarter of 2026. The patterns are consistent enough to report:

Strategic framing is the strongest domain — directors with business backgrounds extrapolate well here, and the domain does not require technical literacy.

Risk literacy and governance architecture are the weakest domains. Directors consistently score Level 0 or Level 1 on these, including directors with deep cyber or tech backgrounds, because AI risk categories and governance frameworks are new enough that prior experience does not transfer cleanly.

Vendor and third-party AI is bimodal. Directors who have served on audit or procurement committees score higher; directors whose recent experience is general strategic oversight score lower.

Disclosure competence is underweighted. Most boards assume disclosure is a legal and audit-committee problem. In AI, disclosure is a board problem because the materiality judgment — is this AI material to the business narrative? — cannot be delegated.

The composite picture: most boards have two or three Level 2+ directors on Strategic Framing, one on Vendor risk, and are at Level 0 or 1 across the board on Risk Literacy, Governance Architecture, and Disclosure. The gap is not evenly distributed, and it is not closed by adding a single "AI director."

5. What closes the gap at the portfolio level

There is no quick fix, but there is a credible 12-month program:

Baseline diagnostic. Run the AIRS-for-Directors instrument with each director individually. Aggregate to a board-level portfolio view. This produces the evidentiary record that Clause 7.2 competence was considered.

Education mapped to gaps, not to calendar. Generic "AI for directors" programs do not move competence scores. Programs mapped to specific domain gaps — a tabletop on risk literacy, a walk-through of the organization's own Statement of Applicability, a deep dive on the vendor portfolio — produce measurable level shifts.

Recurring agenda time. Boards that allocate dedicated AI time each meeting (not just within audit) move composite scores faster than boards that treat AI as an ad-hoc topic. 30-45 minutes per meeting is the observed threshold where competence builds.

Nominating committee sequence. The next director search should have AI competence as an explicit criterion — specifically on the weakest domains, not a generic "AI" label. Replacement sequencing over 2-3 cycles closes the portfolio gap within the normal refresh rate without a forced rotation.

External review. An annual external competency review by qualified counsel or advisor creates the third-party evidentiary record that supports the Caremark defense and the D&O underwriting narrative.

6. The competency register

A practical artifact that boards in 2026 should maintain — separate from the skills matrix — is an AI competency register. It records for each director, on each domain, the current level and the remediation plan. It is updated annually as part of the board effectiveness review. It is available to counsel in the event of litigation and to the D&O underwriter at renewal.

The register is not a report card. It is a governance artifact that closes the Clause 7.2 loop the same way the AI system inventory closes the Annex A 6.2 loop. The organization can show it has considered competence, measured it, and is closing identified gaps.

Boards that resist the register on dignity grounds ("we will not score directors") should consider the alternative: a plaintiff's deposition in which each director is asked in sequence to define five AI risk categories and explain their last management review. The register is the less painful path to the same conclusion.

7. Implication for BoardSight clients

BoardSight's Board AI Oversight Audit includes an AIRS-for-Directors diagnostic as a standard deliverable. The output is a competency register, a remediation plan mapped to specific domains, and an education program costed and scheduled over 12 months. The diagnostic is confidential to the board and the nominating committee; the register is a board-owned artifact.

Boards that want to close the competency gap before a regulatory or litigation event forces the question have a roughly 18-month window. The 2026-2027 EU AI Act enforcement timeline, the NIST AI RMF profile adoption in US sectors, and the continuing rise of AI-related derivative filings will make this question harder to leave open.

The gap is not shameful. The absence of a plan to close it is.


Further reading inside the BoardSight library: ISO 42001 for Boards: The Operational Companion to Caremark · The D&O Pricing Shift: How AI Failures Are Being Underwritten in 2026 · From Caremark to AI: The Evolution of Board Monitoring Duty · Three Lines Model for AI Governance

Sources referenced: ISO/IEC 42001:2023 Clause 7.2; EU AI Act Article 26 (Deployer obligations); Marchand v. Barnhill, 212 A.3d 805 (Del. 2019); In re Boeing Co. Derivative Litigation (Del. Ch. 2021); NIST AI Risk Management Framework 1.0; Cognitive Corp BAGI and AIRS instruments (Research Corpus, 2024-2025); NACD Blue Ribbon Commission on AI (2024); PwC Annual Corporate Directors Survey (2025).

B
BoardSight

The AI Oversight Practice from Cognitive Corp.

Standards

NIST AI RMF 1.0ISO/IEC 42001:2023EU AI ActCOSO ERM

BoardSight provides independent, board-ready oversight evidence and advisory support. It does not provide legal opinions, regulatory certification, statutory audit assurance, or a guarantee that an AI system is safe or compliant.

© 2026 Cognitive Corp. All rights reserved.

BoardSight · AI Governance · Three Lines for AI