# Board AI Literacy Curriculum and Self-Assessment Templates

Building enough AI literacy at board level for real oversight. A curriculum outline tied to the company's own AI risks, an annual board briefing template that is context, not operations, a director self-assessment, and criteria for choosing an external educator.

**Who this is for:** The company secretary, general counsel, or chair building the board's AI oversight capacity.

Source playbook: https://aigovernance.com/playbook/director-ai-literacy

---

## Director AI literacy curriculum outline

_Topics, depth, and how each connects to the specific AI risks this company runs._

### Template

| Topic | Depth for directors | Connection to our AI risks |
|---|---|---|
| What AI can and cannot do (capabilities and limits) | conceptual | which of our decisions rely on it |
| How AI systems fail (bias, drift, hallucination, brittleness) | conceptual + examples | our people-affecting and customer-facing systems |
| The regulatory landscape | working knowledge of the regimes we are in | EU AI Act, US state law, sector rules for our sectors |
| Governance and oversight structures | working knowledge | our committee, three-lines model, reporting |
| Reading an AI risk report | practical | our board dashboard and thresholds |
| Escalation and crisis | practical | our escalation register and incident types |

### Worked example

> Tailoring for our board (AI in hiring and fraud decisions, both people-affecting and regulated).

| Topic | How we tailored it |
|---|---|
| How AI fails | leads with a bias case study built from our own adverse-impact history, anonymised |
| Regulatory landscape | covers only the EU AI Act, Colorado SB205, NYC LL144, and fair-lending analogues, not a global survey |
| Reading an AI risk report | uses our actual board dashboard and thresholds |

### Acceptance criteria

- Every topic states the depth expected of a director, not a practitioner.
- Each topic is connected to a specific AI risk the company actually carries.
- The curriculum uses the company's own systems and reports as teaching material.

---

## Board AI briefing template

_An annual context-setting session, deliberately separate from the quarterly operational report._

### Template

> Once a year, 60-90 minutes. Sets context, not status.

- **Where AI sits in the strategy:** what the company is betting on AI for, and the exposure that creates
- **The risk landscape:** how AI risk is evolving for our industry and jurisdictions
- **Our governance model:** how it works, what the board sees and decides, what it does not
- **Two or three deep dives:** a real system, a real incident or near-miss, a real regulatory change, explained fully
- **What good oversight looks like:** the questions directors should be asking management
- **Open discussion**

### Worked example

**2026 annual board AI briefing:**
- Strategy: AI is core to the hiring and fraud products; ~30% of revenue touches an AI-influenced decision.
- Landscape: risk-based regulation spreading from the EU to US states; enforcement focus on hiring and lending.
- Model: committee under Risk; board sees a quarterly dashboard and any Sev-1; board approves risk appetite annually.
- Deep dives: (1) the resume screener end to end; (2) the September support-copilot data near-miss; (3) the EU AI Act high-risk deadline move.
- Questions to ask management: "which systems are High-tier and are they all assessed?", "what is our worst plausible AI incident and are we ready for it?", "where are we behind on a regulatory deadline?"

### Acceptance criteria

- The briefing is context and education, held separately from operational reporting.
- It includes deep dives on real systems, incidents, and regulatory changes.
- It gives directors specific questions to ask management.

---

## Director AI literacy self-assessment

_A short questionnaire to find gaps and track progress, done privately by each director._

### Template

| Statement | Confident / Somewhat / Not |
|---|---|
| I can explain, at a high level, how the company's main AI systems make decisions | |
| I understand the main ways AI systems fail and which of ours are exposed | |
| I know which AI regulations the company is subject to and the key deadlines | |
| I understand how AI risk is governed and what the board decides | |
| I can read our AI risk dashboard and tell whether the picture is good or bad | |
| I know what would trigger an escalation to the board and what we would do | |
| I know the questions to ask management about AI risk | |

### Worked example

> Aggregated and anonymised across 8 directors, 2026.

| Statement | Confident | Somewhat | Not |
|---|---|---|---|
| Explain how our AI makes decisions | 3 | 4 | 1 |
| Ways AI fails and our exposure | 2 | 5 | 1 |
| Regulations and key deadlines | 1 | 4 | 3 |
| Read the risk dashboard | 4 | 3 | 1 |

Gaps to address in the curriculum: regulation, and failure modes. Repeat after the annual briefing.

### Acceptance criteria

- Results are aggregated and anonymised, used to shape the curriculum, not to grade individuals.
- The assessment is repeated to show progress over time.
- Low-confidence areas map to specific curriculum modules.

---

## External educator selection criteria

_How to choose an outside educator, and what a good one looks like._

### Template

| Criterion | What good looks like |
|---|---|
| Board-level experience | has taught directors, not just executives or engineers |
| Independence | no conflict (not selling the company AI tools or audit services) |
| Tailoring | will build the session around our systems and risks, not a stock deck |
| Regulatory currency | current on the regimes we face, with primary-source knowledge |
| Practical framing | teaches the questions to ask, not just concepts |
| References | directors at comparable companies who can speak to impact |

### Worked example

> Shortlist evaluation.

| Candidate | Assessment | Outcome |
|---|---|---|
| A | strong board experience; stock deck only; would not tailor | pass |
| B | tailors; current on EU and US rules; references check out; independent | selected for the 2026 briefing |
| C | excellent, but also pitching us an assurance engagement | conflict; declined |

### Acceptance criteria

- The educator has taught at board level and will tailor to the company's systems.
- There is no conflict of interest (not selling related products or services).
- References from directors at comparable companies were checked.

---

## Governance controls this kit produces evidence for

- **BRD-001**: The curriculum and self-assessment are the director AI literacy and competency assessment.
- **BRD-002**: The briefing reinforces the board's role and decision rights under the committee charter.
- **HOC-007**: Teaching directors to read the risk dashboard strengthens board risk reporting and escalation.
- **BRD-005**: Director literacy is one dimension of the governance maturity assessment.
