The AI Governance Playbook Series
Book 2 — EU AI Act Playbook for Boards ← You are here
Book 2 · The AI Governance Playbook Series

The EU AI Act
Playbook for Boards.

What every board director needs to know, ask, decide and evidence — before the regulator, auditor, insurer or investor asks first.

18Chapters
5Board Questions
Dec 2027CBI Deadline
Book 2of the Series
The EU AI Act Playbook for Boards — Shane Brett PhD

Written for the boardroom,
not the compliance team.

The first Playbook told compliance officers and COOs what to build. This one tells boards what to look for, what to ask, and what to do when the answers coming back from management are not good enough.

Non-Executive Directors

You know what you know. You have a reasonable sense of what you do not know. This book maps the unknown unknowns — where the real board exposure sits — and tells you what to do about it.

Audit & Risk Committee Chairs

The most common failure in AI governance is not that firms have no oversight. It is that they have no evidence of oversight. This book gives you the tools to tell the difference.

Senior Independent Directors

Under Ireland's Individual Accountability Framework, you need documented, genuine, good-faith exercise of governance responsibilities. This book tells you exactly what that requires.

Board Chairs

Competing priorities — DORA, CSRD, MiFID II, GDPR — have pushed AI governance down the agenda. This book gives you the framework to move it to the top, and the minutes language to prove you did.

Five questions that will produce
uncomfortable silences.

Ask these five questions at your next board or risk committee meeting. Note the answers in the minutes. If management cannot answer them clearly today, you now know exactly what needs to be fixed.

01

Can you show me the AI register — every system we use, classified by risk tier?

If the document does not exist, the inventory has not been done. That is the first gap to close.

02

Who is the named accountable person for each high-risk AI system?

Accountability that is not named is not accountability. Under the IAF, the board needs a person, not a team or a department.

03

Can you show me the oversight logs — not describe the process, show me the logs?

The Central Bank will not accept a description of what your oversight process looks like. It will ask to see the logs. Your board should ask the same thing first.

04

Have our AI vendors confirmed in writing that they meet their EU AI Act obligations?

As a Deployer, you cannot outsource compliance to the vendor. If the vendor is non-compliant, your firm is still exposed.

05

When did our AI oversight function last find something that required a change?

If it has never found anything, why not? An oversight function that finds nothing is either not looking, or not empowered to act.

Short by design.
Built for the boardroom.

Each chapter ends with a Board Decision Required section. Information does not protect a board. Decisions, minutes, evidence and follow-through do.

IntroWhy This Book Exists — What Boards Actually Need
Ch 1The EU AI Act in Plain English — What Boards Need to Know
Ch 2The December 2027 Deadline — Why the Wait Is Over
Ch 3Your Firm's Role — Provider, Deployer, or Importer?
Ch 4High-Risk AI — Is Your Firm Already Running It?
Ch 5What the Board Is Actually Responsible For
Ch 6Ireland — Why This Matters More Here
Ch 7The Gap Between Management Reports and Reality
Ch 8What Good AI Governance Looks Like in Practice
Ch 9Vendor Risk — What the Board Needs to Demand
Ch 10D&O Insurance, Audit & the IAF — The Personal Exposure
Ch 11Non-EU Boards — You Are Not Off the Hook
Ch 12The Five Questions — And What to Do With the Answers
Ch 13Board Minutes — Wording That Actually Evidences Governance
Ch 14The AI Governance Dashboard — What to Ask For
Ch 15The Board Resolution That Protects Individual Directors
Ch 16What Happens After You Close This Book
Ch 17–18Working With Us — The External Adviser Model

Appendices included: Board minutes templates · AI governance dashboard template · Director challenge prompts · Vendor due diligence checklist · Example board resolution wording · Key Irish regulatory contacts

Two ways to get the
Boards Playbook.

Also Available

Amazon — Print & Kindle

Amazon

Print and Kindle editions · Ships worldwide

  • Print edition — ships worldwide
  • Kindle edition available
  • Complete book content
  • Quarterly updates not included
Buy on Amazon →

Also in the series

Book 1 — EU AI Act Playbook for Funds & Financial Services

The operational guide for compliance teams and COOs — €42

View Book 1 →

Written by a practitioner,
not a lawyer.

Dr Shane Brett has over twenty-five years of experience in the global investment funds and financial technology industry. He founded GECKO Governance — a RegTech company that built compliance management software for the global investment management industry, backed by institutional investors in the US and Europe.

"Within weeks of publishing the first Playbook, the requests started arriving — not from compliance teams, but from boards. This book is the answer to that question. It is a different book for a different audience with a different job to do."
PhD

Peer-reviewed research on AI governance & fund regulation

GECKO Governance

Founded VC-backed RegTech — scaled globally

UCD Advanced Diploma

Professional Diploma in Advanced Artificial Intelligence

25 Years

Global funds, FinTech & regulatory compliance

Dr Shane Brett

Dr Shane Brett

AI Governance · Global Perspectives · Dublin

Book a Call with Shane →

Also author of Zero to $10 Million: How to Build an 8-Figure Technology Business, Business Expert Press.

globalperspectives.io →

Can your board answer
the five questions?

A 20-minute conversation. No obligation. We will tell you honestly where your board's AI governance gaps are, what the personal exposure is under the IAF, and what needs to happen before December 2027.