Appendix
The Board's Question Set
Questions for directors overseeing agentic deployment and organisational change
The questions below gather the board-directed prompts that appear across the book, organised by governance domain rather than by chapter, because that is how they arise in practice. Chapter references in brackets point to the fuller treatment of each question. They are intended for use in board and executive sessions, not as a compliance checklist but as a way of forcing the right management conversation about agentic deployment. A question that receives a confident answer with no evidence behind it has done its job as surely as one that exposes a gap.
The First Ten
The conversation that matters first
For a board encountering agentic deployment for the first time, these ten questions, drawn from across the domains below, open the conversation that matters.
- For each system described to us as an 'agent', does it meet the operational definition: pursuing an objective across multiple steps without continuous human direction? (Ch. 1)
- Who is the named human accountable for each agent operating at meaningful scale, and is that person the operational leader who authorised it rather than the engineer who built it? (Ch. 6, 9)
- What is each material agent authorised to do, where is that authorisation documented, and when was it last reviewed? (Ch. 4, 9)
- What reliability profile does management receive for each material agent, and who knows what normal variation, drift, and degradation look like for it? (Ch. 6)
- What could our most critical agents be made to do by someone who wanted to harm us, how would we know, and how bad could it get before we stopped it? (Ch. 10)
- Which of our deployments fall into high-risk categories under the EU AI Act or sector regimes, and what is the plan for the obligations now in force and arriving? (Ch. 9)
- What human capability is being built to replace the developmental work that agents now perform? (Ch. 11)
- Does the performance and capability data this board receives still measure what it was designed to measure, and who has checked? (Ch. 11)
- Is AI deployment making the firm harder to compete against, or merely cheaper to run, and what evidence distinguishes the two? (Ch. 12)
- Does the organisation have deployment capability, or merely model access, and what would demonstrate the difference? (Ch. 14)
Authority and Accountability
Who may act, and who carries the consequence?
- What is each agent instructed to do, and how precise are the instructions that govern its behaviour? (Ch. 1)
- What information can each agent access, and how does that access compare with the sensitivity of the data involved? (Ch. 1, 10)
- What can each agent do to our systems, and how are those permissions kept proportionate to the task? (Ch. 1, 10)
- Who decides what each agent is permitted to do, under what conditions, and with what oversight, and who is the single named owner of that authority calibration for every material agent? (Ch. 4)
- Who is the named human accountable for each agent's outputs, configuration, and ongoing performance, and at what seniority? (Ch. 6, 9)
- For each material agent, who decided it was authorised to take its actions, where is the authorisation architecture documented, and when was it last reviewed against the agent's current scope? (Ch. 9)
- When an agent produces a disputed output, how would management trace the cause through the prompt, context, tools, and workflow design? (Ch. 1)
Reliability, Supervision, and Escalation
How does management know the system is still safe to trust?
- What reliability profile does management receive for each material agent? (Ch. 6)
- Who in the organisation knows what normal variation, drift, and degradation look like for each agent, and what triggers intervention? (Ch. 6)
- What is the supervision ratio for high-consequence agents, and how was oversight capacity sized against the actual escalation load rather than assumed? (Ch. 6)
- Where supervisory agents monitor other agents, how far does the accountable human now sit from operational reality, and who has tested the supervisory layer's own error detection? (Ch. 6)
- How are escalation pathways designed and tested, and are they treated with the same seriousness as the workflows themselves? (Ch. 4, 13)
- What does each agent do when it reaches a situation outside its design, how are errors caught, and what does human oversight mean at the system's actual operating speed? (Ch. 1, 4)
- Who owns agent lifecycle management: recalibration as the environment drifts, and the decision to restrict an agent whose reliability has declined while throughput pressure is high? (Ch. 6)
- At the interfaces where work passes from agent execution to human judgement, what context does the human actually receive, and who has examined whether it is sufficient? (Ch. 4, 15)
Risk, Security, and the Record
Where could the agentic layer fail, spread, or be turned against the firm?
- What tools does the risk function have for assessing the aggregate properties of interacting agents, rather than reviewing deployments one by one, and what evidence supports the answer? (Ch. 9)
- Where do multi-agent dependencies create failure paths that no single component review would reveal, and what system-level monitoring exists to catch them? (Ch. 7, 9)
- How are outcome distributions tested across demographic groups before deployment and monitored in production, given that disparate impact is invisible case by case? (Ch. 9)
- What could each critical agent be made to do by someone who wanted to harm us, how would we know, and how bad could it get before we stopped it? (Ch. 10)
- Where has the organisation granted agents broader permissions, data access, or autonomous reach than their tasks strictly require, and who reviews that continuously? (Ch. 10)
- How are high-stakes actions validated against an independent control before they take effect, and where has speed been allowed to override that discipline? (Ch. 9, 10)
- When were our material agents last subjected to adversarial testing by people whose objective was to make them misbehave, and what did it find? (Ch. 10)
- What is our logging designed to: the standard of accountability, evidence, and consequence tier, or the standard of debugging, and has legal counsel shaped its retention, access, and scope? (Ch. 9)
- Which decisions require full traceability under the consequence-tiered standard, which operate with abbreviated logging, and which have been explicitly retained for humans because they should not be delegated at all? (Ch. 7, 9)
- What does the board understand about the organisation's vendor concentration across foundation models, tools, and orchestration layers? (Ch. 9)
- What formal deployment path exists for teams that want to automate their own work, and is it efficient enough that the shadow route does not appear systematically more attractive? (Ch. 9)
Regulation and Liability
What would the firm produce when scrutiny arrives?
- Which of our deployments fall into high-risk categories under the EU AI Act or applicable sector regimes, and what is the plan for the August 2026 and August 2027 obligations? (Ch. 9)
- What would the organisation produce, today, if a regulator asked for the authorisation document and the complete decision log for any material agent? (Ch. 9, 15)
- Has the legal function assessed our liability exposure in cross-organisational agent workflows, and do our commercial agreements address it? (Ch. 7, 9)
- What is each customer-facing agent permitted to commit the firm to, given that the firm is bound by what its automated systems tell and promise customers? (Ch. 12)
- Has counsel reviewed the intellectual property and confidentiality implications of agent memory, fine-tuning, and retrieval architecture? (Ch. 8)
Memory and Organisational Learning
Is the firm learning from execution, or only completing tasks?
- For each material agentic deployment, what inputs, decisions, and outputs are being captured, and to what standard of fidelity beyond debugging? (Ch. 8)
- Who is accountable, and resourced, for converting the operational record into organisational learning, and what has actually changed as a result of it in the past year? (Ch. 8, 13, 15)
- What happens to embedded procedural knowledge when a significant agent is retired or substantially redesigned? (Ch. 8)
- Who can query the organisational memory system, under what conditions, and how does its access governance compare with the firm's other sensitive data assets? (Ch. 8)
People and Capability
What human capability changes as agents absorb execution?
- What human capability is being built to replace the developmental work that agents now perform, and is the investment at the scale the precedents suggest is required? (Ch. 11)
- Where have status, authority, and learning pathways changed even when job titles have not, and how is that being discussed with the people affected? (Ch. 5, 11)
- Is the organisation removing human capability faster than demonstrated system reliability justifies, and who would catch that sequencing error before it bites? (Ch. 11)
- Does the performance and capability data the board receives still measure what it was designed to measure, and who has actually checked? (Ch. 11)
- How much apparent productivity reflects AI assistance management cannot see, and what happens to committed capacity if the individuals carrying private tooling depart? (Ch. 11)
- How is AI fluency developed, observed, and measured as part of the workforce capability model? (Ch. 11)
- Which career paths, specialist communities, and oversight capabilities need redesign as routine execution migrates to agents, and who owns that redesign? (Ch. 5)
- Does management have a deliberate plan for the departmental reconfiguration that follows lower integration costs, and what would trigger its activation? (Ch. 5)
Economics and Competition
Is deployment changing advantage, or only cost?
- What work becomes economically viable when the marginal cost of cognitive throughput falls to a small fraction of the human equivalent, and which analyses, reviews, and monitoring activities were never done because doing them properly was prohibitive? (Ch. 2)
- Is AI deployment changing the firm's business model and pricing logic, or only reducing the cost of existing work, and where does pricing pass production cost through to the client? (Ch. 2)
- Which coordination costs have been reduced, by how much, and what has been done with the capacity that freed? (Ch. 3)
- Which activities should remain inside the firm because their learning is firm-specific or their accountability cannot be transferred, and which are becoming candidates for externalisation? (Ch. 3)
- Is the firm getting operationally smarter through execution intelligence, or only using the same tools as everyone else, and where does the operational signature actually show? (Ch. 12)
- Which parts of the data advantage are durable, which are eroding, and which depend on activation rather than accumulation? (Ch. 12)
- How much of current margin depends on customers finding it hard to compare the firm, hard to switch from it, or hard to see through its pricing? (Ch. 12)
- How is the firm preparing to be evaluated, transacted with, and chosen by agents as well as by people? (Ch. 12)
- What does the organisation concede to competitors while it delays deployment, and how is that weighed against the risk of deploying? (Ch. 10)
Building, Funding, and Measuring
What must be true before deployment becomes capability?
The five workflow-triage questions below are management's to answer for every proposed deployment; the board's version is to ask for the answers and the evidence behind them. (Ch. 13)
- What percentage of cases in this workflow follow a recognisable pattern?
- How will correctness be verified against an independent standard?
- What does a failure cost, and how reversible is it?
- What is the actual condition of the data the agent will use?
- Who will own the agent after deployment?
And the board's own questions:
- Where do current pilots sit relative to thin-slice production, and which have been designed to succeed rather than to reveal? (Ch. 13)
- Was evaluation infrastructure built before go-live, and was governance resolved at design rather than sequenced after development? (Ch. 13)
- Is the board measuring value, reliability, structural consequence, and exposure rather than deployment counts? (Ch. 14)
- Is the business case funding the J-curve of complementary investment, data, integration, evaluation, governance, human development, or only the visible build? (Ch. 14)
- How does the appraisal treat efficiency gains, capability gains, and option value, and where has option value been set at zero because it resists the spreadsheet? (Ch. 14)
- Is the programme run as a portfolio held to account, with positions stopped when they neither return nor teach? (Ch. 14)
- Are partnerships structured so portable learning is accelerated while firm-specific learning accrues internally? (Ch. 14)
- Does the organisation have deployment capability, or merely model access? (Ch. 14)
The Standing Questions
Questions that belong on the agenda repeatedly
These belong on the agenda not once but repeatedly, because their answers change as the agentic layer grows.
- Which workflows now operate differently, not merely faster? (Ch. 15)
- What has the organisation learned from its deployments in the past year, and what changed as a result? (Ch. 13, 15)
- What failure modes have appeared in production? (Ch. 9)
- Who remains accountable for the firm's consequential decisions, and can those people explain them? (Ch. 15, 16)
- Does the organisation remain directed by human judgement as machine execution expands? (Ch. 16)
- How is leadership creating agency for people and the institution as uncertainty increases, rather than allowing the future to feel like something simply done to them? (Ch. 16)