In its 2025 study of more than 1,250 companies, BCG classified only 5 percent as ‘future-built’ organisations creating AI value at scale. Another 35 percent were beginning to generate value, while 60 percent reported little material return despite substantial investment. BCG’s distinction is instructive for boards: access to AI does not, by itself, create the organisational capability to benefit from it.
Yet boardroom conversations often separate the elements on which that capability depends. An AI strategy discussion presents opportunities for growth and efficiency. A risk discussion considers potential harm. Questions about whether the organisation can implement and sustain the proposed use may arrive later. By then, enthusiasm for the opportunity may have hardened into an investment expectation.
Boards need to consider these questions together. AI value is created when organisational readiness is sufficient to convert opportunity into results, govern the accompanying exposure and produce evidence that the trade-off remains defensible.
Opportunity identifies what AI could deliver. Readiness determines whether the organisation can convert that potential into results. Exposure indicates where and to what extent the organisation may become vulnerable in pursuing that value. It is not the whole of risk but one dimension of the board’s wider risk judgement. Defensibility connects all three by requiring the organisation to explain its choices, justify its assumptions, demonstrate control and respond when conditions change.
This begins with a more demanding account of value. A successful pilot, faster processing or widespread employee use may indicate progress. The board still needs to understand whether the benefit persists once the organisation accounts for integration, human review, errors, remediation, vendor dependence and the consequences for customers or employees. An AI system can save time in one function while transferring cost, uncertainty or diminished decision quality elsewhere.
Readiness is equally specific. An organisation may be well equipped to use AI to help staff find internal information but less prepared to rely on it in lending, healthcare or decisions affecting access to essential services. Each use places different demands on data, expertise, accountability and oversight. The board should therefore resist broad assurances that the enterprise is ‘AI-ready.’ The relevant question is whether it is ready for this use, at this scale, with these consequences.
Exposure should be considered with the same precision. Pursuing value may increase reliance on a vendor, alter how employees exercise judgement or affect people who cannot easily challenge a decision. Such exposure does not automatically make an opportunity unacceptable. It does require management to show what the organisation is accepting, why the expected benefit warrants it and how that judgement fits its wider risk appetite.
This is why governance belongs inside the value discussion. Clear accountability, credible evidence, independent challenge and continuing oversight help management identify which uses deserve investment and which can be scaled responsibly. They also protect the organisation’s ability to justify continued use. A valuable system whose outcomes cannot be adequately examined or challenged may ultimately become a system the organisation cannot confidently rely on.
Readiness must also include the institutional capacity to revisit enterprise judgement. Support for an AI investment should not harden into an irreversible strategic commitment simply because capital, reputation or executive sponsorship has already been invested. The board should expect management to articulate the conditions under which the organisation would scale, constrain, redesign or discontinue a material AI use and to provide evidence that the assumptions supporting continued investment remain valid. An initiative that was defensible when introduced may cease to be so as its scale, strategic importance, stakeholder impact or operating environment changes.
Management owns the work of selecting use cases, developing capability, operating controls and measuring results. The board owns the quality of the enterprise judgement brought to bear on material commitments. It should expect opportunity, readiness and exposure to be presented as one decision, with evidence strong enough to support both investment and reconsideration.
AI’s promise is substantial. Capturing it will depend less on how many opportunities an organisation identifies than on its capacity to realise value, understand what it is exposed to and change course when the evidence demands it. That is the organisational capability at the heart of Defensible AI.
Amaka Ibeji is a Boardroom Certified Qualified Technology Expert and a Digital Trust Visionary. She is the founder of PALS Hub, a digital trust and assurance company, Amaka coaches and consults with individuals and companies navigating careers or practices in privacy and AI governance. Connect with her on linkedin: amakai or email amaka@palshub.net