AI governance for investors: what to ask before and after you invest
· By Daniel Molloy
Every board and every investment committee now hears about AI in every meeting. The pressure to act is real. The information quality is usually poor.
I review AI systems and AI claims for a living. Most of what I see is one of three things: a genuine capability, a useful automation described as more than it is, or a thin layer over someone else's model. All three can be worth money. They are not worth the same money, and they do not carry the same risk.
Governance is how you tell them apart — before you commit, and after.
Before you invest
You do not need to be technical to ask these questions. You need to insist on evidence in the answers.
- What does the AI actually do today? Not the roadmap. The thing running in production, used by real customers, this month.
- Whose model is it? If the product depends on a third-party model, ask what happens when that provider changes prices, terms, or behaviour. Dependence is not a flaw. Unpriced dependence is.
- Whose data is it? Ask what data the system was built on, who owns it, and whether customers agreed to that use. Data problems surface late and cost a lot.
- What does it cost to run? AI features carry a running cost per use. Ask how that cost moves as usage grows, and whether the pricing covers it.
- What is defensible? If a competitor with the same public models could rebuild the product in a quarter, the value sits somewhere else — the data, the distribution, the workflow. Name where.
- What proves it works? Usage figures, error rates, retention on the AI features. Claims are easy. Telemetry is evidence.
A seller who cannot answer these is not necessarily hiding something. But the gap between the deck and the answers is where your risk lives.
After you invest
Adoption without governance is how AI loses you money quietly. The work after the investment is smaller than people fear, but it has to exist.
- A written policy. What staff may use AI for, what data may go into which tools, and who approves exceptions. One page is enough to start.
- Data protection alignment. Where personal data flows, AI use has to fit the company's regulatory obligations. This is a legal question with a technical input, and it needs both.
- Vendor and model review. Someone should own the list of AI suppliers, what each one sees, and what the contracts allow.
- Monitoring. AI systems change behaviour over time — models get updated, costs move, quality drifts. Decide what gets measured and who looks at it.
- Board reporting. AI risk belongs in the same reporting as any other operating risk. Plain numbers, plain language, no demos.
What a defensible position looks like
The output of governance is not a document. It is a position the board can state and defend: what we have adopted and why, what we declined and why, and what we are watching.
That position also protects the valuation story. When the next buyer or the next round runs diligence on the company, the difference between "we use AI" and "here is what it does, what it costs, what it depends on, and how we control it" is worth real money.
If your board or portfolio needs help getting there, that is the work I do — AI governance and strategy, grounded in how the technology actually behaves.