Most boards are already using AI, just not officially. A director pastes part of a board report into a chatbot to “summarize it quickly.” A meeting assistant quietly transcribes a discussion that used to stay in the room. Nobody decided any of this; it just started happening. An AI policy gives your board the parameters: what is allowed, what is off limits, and who is accountable.
What should your AI policy cover?
Tick the areas your board needs. The core policy is always included.
Want your policy emailed (in Word)? 📄
How to build your board’s AI policy
- Pick the areas to cover. The core policy (purpose, scope, permitted and prohibited uses, confidentiality, oversight, and review) is always included. Add or drop the modules: meeting transcription, tool approvals, disclosure, vendors, incidents, training, the quick reference, and the jurisdiction notes.
- Review it on screen. The full policy renders below the builder, numbered and ready to read, free.
- Get the Word version. Share your email and we send the editable document, built with your sections, ready to adapt.
- Adopt it properly. Name the policy owner, list the tools your organization already uses, have counsel or your privacy lead look it over if you have one, then adopt it by resolution and calendar the annual review.
What you get
- A board-level AI policy built from the sections you pick, previewed in full on screen.
- The meeting recording and transcription rules most boards are missing, including the in-camera line that AI notetakers keep crossing.
- Clear permitted-use and prohibited-use lists your directors can actually follow, plus a one-page Do / Don’t quick reference.
- An editable Word version with an approved-tools register, a version-history block, and signature lines, sent to your inbox.
Where the policy meets your board materials
The riskiest AI moment for a board is not a headline scenario. It is a director, short on time, with a 90-page package and a free chatbot. The policy’s answer is a rule; the practical answer is keeping board materials somewhere directors never need to take them out of. That is what a secure portal is for: encrypted materials, role-based access, document controls that restrict downloading and sharing, and an audit trail of key actions. The policy and the platform do the same job from two sides.
Make your AI policy easy to follow
Aprio keeps board materials in one secure place, access-controlled and audited, so there is no reason to paste them anywhere else.
What a board AI policy needs to cover
A defensible policy is more than a pledge to “use AI responsibly.” Here is what each part of the template does, and why governance bodies on both sides of the border now expect it in writing.
Purpose, scope, and who it binds
The policy states plainly that it applies even if the organization has not adopted any AI, because directors, staff, and vendors are using it anyway. Scope covers the people (directors, officers, committee members, staff who handle board materials, third parties with access to board information) and the tools: public chatbots, meeting assistants, the AI features embedded in office software, and AI a vendor runs on your information. A definitions section keeps arguments short, including one for shadow AI: tools used in board work without approval or oversight.
Guiding principles that survive tool churn
Tools change monthly; principles do not. The template anchors on five: accountability stays with people, human review before reliance, confidentiality first, transparency, and controls proportional to risk. These align with the OECD AI Principles, the NIST AI Risk Management Framework, and ISO/IEC 42001, so the policy stands on recognized ground rather than one vendor’s opinion.
Permitted and prohibited uses
Directors need a list they can follow without calling a lawyer. Permitted: research on public information, drafting help on non-confidential material, and anything an approved tool was approved for. Prohibited: putting confidential board information into public tools, letting AI touch the record of closed proceedings, presenting unverified AI output as analysis, and treating an AI summary as a substitute for reading the board package. That last one matters more than it looks; a summary can orient a director, but it does not discharge the duty to review the materials.
Meeting recording and AI transcription
This is the section boards ask about first, and the one with the sharpest edges. The template’s rules: recording and transcription are off by default and run only with the chair’s advance authorization; attendees are told at the start, with consent where the law requires it; and recording stops for every in-camera or closed session, no exceptions, including the assistants built into meeting software. Transcripts are treated as confidential records: they can be requested in legal proceedings, they are kept or deleted under the retention schedule rather than by default, and scheduled deletion pauses automatically under a legal hold. The approved minutes stay the single official record, because keeping a fuller second record alongside them invites the argument that the minutes are incomplete.
Tool approvals and vendor AI
An approved-tools register turns “is this allowed?” into a lookup: the tool, its approved uses, the data permitted in it, an owner, and a review date. Approval criteria cover where data is stored, whether inputs train the vendor’s models (require a no-training commitment for anything confidential), retention terms, and security posture. The vendor section extends the same discipline outward: advisors and suppliers who handle board information disclose their AI use, and contracts address confidentiality, data use, and retention.
Disclosure, incidents, and training
When AI helped draft or analyze something the board will rely on, the board is told. When something slips, a director pastes confidential material into a public tool, say, there is a named person to tell promptly, and the incident is treated as a potential privacy or security event with whatever notification duties apply. And everyone covered by the policy gets a short orientation, because a policy nobody has read protects nobody.
Oversight and the annual review
The board (or a named committee) owns the policy, receives regular reporting on AI use and incidents, periodically confirms that D&O insurance addresses AI-related claims, and reviews the policy at least annually, or sooner when the law or the tools move. A version-history table keeps the record of what changed and when.
Why your board needs an AI policy now
Three things changed in the last two years. First, AI stopped being a tool you choose and became a feature that is simply on: transcription in meeting software, assistants in office suites, chatbots on every director’s phone. Second, the material at stake is the most sensitive an organization has. Board packages hold strategy, financials, legal advice, and personnel matters, and a public AI tool may retain whatever is pasted into it. Third, the record-keeping ground shifted. A meeting that transcribes itself creates a document that outlives the meeting and can surface in legal discovery.
Governance bodies have moved from “watch this space” to written expectations. The NIST AI Risk Management Framework and ISO/IEC 42001 give organizations a recognized structure for governing AI use, and director institutes on both sides of the border now publish board-level AI oversight guidance. Regulators are following: US states have begun legislating AI accountability, Canadian privacy law already applies to personal information in AI tools, and financial regulators expect governed model risk. None of it requires your board to use AI. All of it assumes your board has decided how AI may be used around its own work. That decision, written down, is this policy.
The rules are not the same in the US and Canada
The core of a board AI policy is jurisdiction-neutral: confidentiality, human review, and meeting-recording discipline protect a board anywhere. The legal backdrop differs, and the template flags where. US boards deal with a growing patchwork of state AI and privacy laws, and some states require every participant’s consent before a meeting is recorded. Canadian boards work under PIPEDA and provincial privacy law, with Quebec’s private-sector privacy law the strictest of the set, and federally regulated financial institutions carry their regulator’s expectations for model risk. The template’s jurisdiction notes tell you which lines to check with counsel, without burying the policy in statute citations.
Make the safe way, the easy way
Aprio gives your board one secure home for meeting materials: encrypted, access-controlled, and ready wherever your directors sign in. See what that looks like for a board like yours.
Frequently asked questions
Is the AI board policy template free?
Yes. Build it above and read the whole policy on screen, free. Enter your email and the editable Word version, built with the sections you picked, is sent to your inbox.
Can I customize the template for my board?
Yes, twice over. The builder lets you choose which areas the policy covers before it is generated, and the Word version is fully editable, so you can rename the policy owner, adjust the reporting cadence, and add anything specific to your organization.
Does our board need an AI policy if we do not use AI?
Yes. Directors and staff use AI tools on their own, vendors use AI on your information, and meeting software ships with transcription built in. The policy sets parameters for all of that, whether or not the organization ever formally adopts an AI tool.
Can we let AI transcribe our board meetings?
The template’s rule: only with the chair’s advance authorization, with attendees told at the start, and never during in-camera or closed sessions. Transcripts are treated as confidential records under your retention schedule, because they can be requested in legal proceedings.
Does the template work for both Canadian and US boards?
Yes. The core policy is jurisdiction-neutral, and jurisdiction notes flag where US state law and Canadian privacy law differ, so you know which lines to check with counsel for your jurisdiction.
Is this template legal advice?
No. It is a governance starting point built from recognized frameworks. Adapt it to your organization, and have counsel or your privacy lead review it before adoption if you have one.