The Four AI Questions CISOs Will Hear From the Board the Next Time They Meet
SC Media, Friday, September 25th, 2026
A CISO op-ed lists four evidence-based questions boards now expect CISOs to answer about AI risk.
In this SC Media Perspectives column, TrustCloud CEO Sravish Sridhar argues boards now expect CISOs to answer four questions about AI with evidence rather than assurances: whether humans stay in the loop on consequential decisions given new AI-enabled attack paths; whether compliance with the EU AI Act, ISO 42001, and NIST AI RMF is continuously demonstrable rather than reconstructed annually; how AI risk from internal use and vendor supply chains is governed under one program; and whether AI has measurably lowered risk and cost.
It cites Verizon's 2026 DBIR (45% of employees now use AI on corporate devices) and McKinsey data showing only about 37% of firms see measurable EBIT impact from AI.