Why Executives Need AI Literacy
Specialists can tell you what AI can do. Only leaders can decide what the organization should do with it, and they stay accountable for that decision. Executive AI literacy is the judgment, the questions and the ownership that let you decide well, without becoming technical.
After this chapter you can
- Explain why AI decisions about opportunity, investment, risk, people and strategy now reach the executive table.
- Define executive AI literacy as judgment, questions and accountability, and distinguish it from technical expertise.
- Replace common questions about AI proposals with questions that expose value, limits, full cost and ownership.
- Recognize the three costs of low literacy at the top - abdication, overreach and over-trust.
- Describe what can and cannot be delegated, including the board's oversight duty.
Before reading on, make a guess. Think of the knowledge workers in your organization. What share of them, would you say, already use generative AI for at least 30 percent of their daily work?
In late 2024 McKinsey asked that question twice. It asked 238 C-level executives to estimate the share, and it asked 3,613 employees what they actually did. The executives estimated 4 percent. The employees reported 13 percent, more than three times as many1. The two numbers measure different things: the first is leaders guessing about other people, the second is employees reporting on themselves.
If your guess was low, you are in good company, and that is the problem. The people who set the budget, the risk appetite and the strategy had the least accurate picture of how the work beneath them was already changing. McKinsey’s own conclusion was blunt: employees were ready, and the biggest barrier to scaling was leadership1. Read that with some care. The data come from one online survey, 81 percent of it in the United States, run by a firm that sells AI transformation work, and a finding that leadership is the bottleneck suits that business. Treat 4 against 13 percent as indicative of a direction rather than a precise measure; the direction is what matters here.
The previous chapter asked why a program like this deserves an executive’s time when specialists understand AI far better than any leader needs to. This chapter answers it. Specialists can tell you what AI can do. They cannot decide what your organization should do with it, and they will not be the ones held accountable when the decision goes wrong.
The decisions have left the technology department
For most of the history of corporate computing, leaders could delegate technology with a clear conscience. Few chief executives needed to understand how a database stores its records. They needed to know what it cost, whether it worked and who was responsible for it, and the specialists handled the rest.
AI does not stay in that box. It drafts what customers read, shapes what employees do all day, touches confidential data and makes or informs decisions that used to belong to people. The consequences of an AI choice therefore land in places that no technology team owns: the product, the brand, the workforce, the risk register and the competitive position. The choices that matter most are business choices with a technical component, not the other way round.
Each of these decisions arrives at the executive table whether or not the people around it understand AI. A proposal for an AI platform is an investment decision. A request to let staff use a public chatbot is a risk decision. A plan to automate part of a function is a people decision. The decision will be made either way. Literacy decides whether it is made well.
What literacy means for a leader
AI literacy is easily misheard as a technical skill, so it helps to be exact. The researchers Duri Long and Brian Magerko, in a widely cited definition, describe it as a set of competencies that let a person critically evaluate AI technologies, communicate and collaborate effectively with AI, and use it as a tool2. Notice what is missing from that list: building models, writing code and memorizing architectures.
For an executive, those competencies reduce to three capacities. Each depends on the one before it.
Judgment is a working sense of what today’s AI does well and where it fails. Its most important lesson is that capability and reliability are different things. A system can produce a fluent, confident and plausible answer that is simply wrong. As AI Is Changing Everything showed, AI’s competence is jagged: excellent at some tasks and poor at neighboring ones that look just as hard. A leader who assumes that a system that writes well must also know what it is writing about will approve the wrong things.
Questions are where judgment becomes useful. The literate executive does not know more answers than the specialists in the room. The difference is the questions: the ones that turn an impressive demonstration into a decision that can be defended.
Accountability is the part that cannot be handed to anyone else, and the reason the first two matter.
Better questions, not more answers
The fastest way to see literacy at work is to compare the questions that typically reach an AI proposal with the questions a literate leader asks instead.
None of the questions on the right requires technical training to ask. Each requires knowing that the answer matters. “What happens when it is wrong?” only occurs to someone who knows that it will sometimes be wrong. “Including the people who check it” only occurs to someone who knows that AI output often needs checking. That is the practical shape of literacy: a short list of questions that a leader knows to ask, and knows how to judge the answers to. Later modules supply the detail behind each one, from evaluation to economics.
The cost of not having it
AI Is Changing Everything described the two stances that waste the AI years, complacency and panic. Low literacy is the usual reason leaders fall into one or the other, and it adds a third failure that is easier to miss.
Abdication looks like caution. Leadership calls AI a technology matter and waits. But the work does not wait, as the gap between 4 and 13 percent shows. Employees adopt tools on their own, and the important choices, which data goes where and which outputs are trusted, get made one person at a time, without anyone deciding.
Overreach looks like ambition. Leadership declares that AI must be everywhere, and every function launches its own pilots. The pattern is now measurable. In S&P Global Market Intelligence’s 2025 survey of more than 1,000 organizations in North America and Europe, 42 percent had abandoned the majority of their AI initiatives that year, up from 17 percent in 2024. The average organization scrapped 46 percent of its proofs of concept before production3. The first figure counts companies that gave up on most of their initiatives; the second is the share of early prototypes a typical company dropped. Some of that is healthy experimentation. Much of it is money spent before anyone asked what the initiative was for.
Over-trust looks like confidence, and it is arguably the most dangerous, because it feels like progress. A leader who has seen AI produce brilliant work comes to believe its output, and approves it into places where a wrong answer is expensive. The story later in this chapter shows how quickly that cost can arrive.
Accountability does not delegate
A common objection to executive AI literacy is that the organization already has a chief technology officer, a data team and consultants. It does, and they matter. They can design, build, test and run AI systems. What they cannot do is take over the leadership team’s accountability for the decision to use them.
Two leading management standards say so directly. The US National Institute of Standards and Technology’s AI Risk Management Framework, a widely used voluntary framework, lists among its governance outcomes that executive leadership takes responsibility for decisions about the risks of developing and deploying AI4. ISO/IEC 42001, the international standard for AI management systems, requires top management to demonstrate leadership and commitment to the AI management system5. Neither asks executives to become engineers. Both assume that executives understand enough to own the decisions.
In practice, the line falls between how and whether. How a system is built, tested and run can be delegated. Whether to use AI for a purpose, why, how much risk is acceptable and who answers for the result cannot. AI Decision Rights and Accountability, in Module 04, works through where that line sits in an organization. The point here is simpler: an executive who cannot follow the argument for an AI decision cannot really own it, and an executive who cannot own it should not sign it.
The board’s share
The same logic reaches the boardroom, where literacy is often thin. In a 2026 study by The Conference Board, only 23 percent of executives described their board as highly fluent in AI, and disclosed AI expertise among S&P 500 directors stood at 2.7 percent in 20256. The first figure is how executives judge their board; the second counts directors whose AI expertise their company discloses.
Directors do not need to be AI experts, and boards rarely should be. But oversight has a legal edge. In the United States, the Delaware Caremark doctrine holds that directors can breach their duty if they make no good-faith effort to put a reporting system in place for mission-critical compliance risks, or ignore the red flags it raises. In Marchand v. Barnhill (2019), the Delaware Supreme Court let such a claim proceed against the directors of an ice cream maker whose board had no regular reporting on food safety, although food safety was central to the business7. Where AI becomes mission-critical, a board that cannot ask about AI risk, or would not understand the answer, is exposed. AI Governance Committee and AI Governance Office, in Module 07, sets out the reporting that boards should expect.
Literacy is also not the same at every level. The foundation, the vocabulary and the core judgments should be shared across the organization. The depth changes with the role.
Story: a fluent answer at launch
This story is real, and it is told as a decision. Put yourself in the leadership of a technology company in February 2023.
A rival’s chatbot has become the most talked-about product in the industry, and another rival is about to put a chatbot into its search engine. Your company has one of the deepest AI research teams in the world and a capable conversational model of its own. The plan is to announce it now, with a short demonstration of the model answering a question, and to open it first to a group of outside testers before a wider launch. The demonstration is ready.
You have two options. Announce this week, with the demo, and show the market you are not behind. Or hold the demo until every answer it shows has been checked by someone outside the team that built it, and accept a week of headlines saying you are slow.
On 6 February 2023 Google announced Bard, “an experimental conversational AI service”, and said it would open first to trusted testers8. The promotional demonstration showed Bard answering a question about new discoveries from the James Webb Space Telescope that a parent could share with a nine-year-old. One of its answers said the telescope had taken the very first pictures of a planet outside our solar system. It had not. That image was taken in 2004 by the European Southern Observatory’s Very Large Telescope9.
Reuters reported the error on 8 February. Alphabet’s shares fell 7.7 percent that day, about 100 billion dollars of market value. A company event the same day also failed to impress investors, so the error was not the only cause, but it was the one that defined the coverage9. Google’s response was that the episode highlighted the importance of a rigorous testing process, which it was beginning that week with its trusted testers10.
The lesson is not that Google lacked expertise. Few organizations had more. It is that the failure happened at the point where expertise ends and leadership begins: the decision about what a fluent answer must pass through before it speaks in the company’s name, in public, under competitive pressure. That is a judgment about reliability, a question anyone in the room could have asked (“who checked these answers?”) and an accountability that sat with the people who approved the launch. All three are literacy, and none is technical.
What this means for leaders
Executive AI literacy is not a credential. It is a habit of mind applied to real decisions. Four practices follow from this chapter.
- Close your own perception gap. Find out how AI is already being used in your part of the organization before you decide anything about it. Ask the people doing the work, not only the people reporting on it.
- Bring the questions, not the answers. Take a short list of literate questions into every AI decision: the problem, the quality needed, what happens when it is wrong, the full cost and who owns the result.
- Keep the “whether” with you. Delegate how systems are built and run. Keep whether, why and how much risk.
- Make the board able to oversee. Ask what the board would need to see to know whether AI risk is under control, and make sure someone is building that report.
Check yourself
- AI literacy for executives means learning to code or to build models.
- Leaders tend to underestimate how much their employees already use generative AI.
- Once a chief technology officer is in place, AI risk can be left to the technology team.
- A fluent, confident AI answer can usually be treated as a reliable one.
- To meet their oversight duty, directors must themselves be AI experts.
- Under the amended EU AI Act, organizations must guarantee a specific level of AI literacy among their staff.
Reflection: your last AI decision
What comes next
Literacy lets a leader understand AI decisions. It does not yet make that leader the person the organization follows through them. Knowing the right questions is awareness; acting on the answers, consistently and in public, is leadership. The next chapter, From AI Awareness to AI Leadership, describes the behaviors that make that difference.
Laws referenced
Not legal advice. Laws change; verify before relying on this, and consult counsel for decisions.
Directors' duty of oversight (Delaware "Caremark" doctrine) · US - Delaware (case law for most large US companies)
In re Caremark International Inc. Derivative Litigation (Del. Ch. 1996); Marchand v. Barnhill (Del. 2019)
Directors breach their duty of loyalty if they make no good-faith effort to put a reporting system in place for mission-critical compliance risks, or ignore red flags it raises. Where AI is mission-critical, a board that has no way to hear about AI risk is exposed. Liability is hard to establish, but the duty shapes what boards should ask to see.
- 1996-09-25 — Caremark decision
- 2019-06-18 — Marchand v. Barnhill: board must make a good-faith effort to oversee mission-critical risks
Last verified 2026-10-08
EU AI Act · EU
Regulation (EU) 2024/1689, as amended by Regulation (EU) 2026/1744
Risk-based rules. Prohibited practices include social scoring, untargeted scraping of facial images, and emotion recognition in workplaces and schools (with narrow exceptions). High-risk systems (Annex III: biometrics, safety components of critical infrastructure such as energy, water and traffic, employment and worker management, credit, education, essential services, law enforcement, migration, justice) need risk management, data governance, documentation, logging, human oversight, human oversight that keeps people able to understand the system, notice automation bias (over-reliance on its output), override it or stop it (Art. 14(4)), appropriate accuracy, robustness and cybersecurity (Art. 15), automatic logging of events (Art. 12), a provider quality-management system (Art. 17) and conformity assessment. An Annex III system is not high-risk if it poses no significant risk of harm, for example a narrow procedural or preparatory task that does not replace human assessment; systems that profile people are always high-risk, and a provider relying on this exception must document it and register (Art. 6(3)). Deployers of high-risk AI must use it as instructed, assign competent human oversight, monitor its operation, keep logs for at least six months and report serious incidents (Art. 26); employers must inform workers' representatives (Art. 26(7)). Public bodies, private providers of public services, and deployers of credit-scoring or life and health insurance pricing systems must carry out a fundamental-rights impact assessment before first use (Art. 27). Providers must run post-market monitoring (Art. 72). A deployer that puts its name on a high-risk system, substantially modifies it, or changes its purpose so that it becomes high-risk takes on the provider's obligations (Art. 25(1)). A substantial modification (Art. 3(23)) of a high-risk system needs a new conformity assessment, unless the change was pre-determined and documented at the first assessment, as with planned continuous learning (Art. 43(4)). Providers of general-purpose AI models (from 2 Aug 2025) must keep technical documentation, have a policy to comply with EU copyright law including text-and-data-mining opt-outs, and publish a sufficiently detailed summary of training content (Art. 53). Research, testing and development before a system is placed on the market or put into service is outside the Act, except testing in real-world conditions (Art. 2(8)). Since the 2026 Omnibus, the Art. 4 AI-literacy duty is an obligation of effort (take measures to support literacy), not of result. Fines reach EUR 35 million or 7% of global turnover for prohibited practices.
- 2024-08-01 — Entered into force
- 2025-02-02 — Prohibited practices (Art. 5) and the AI-literacy duty (Art. 4) apply
- 2026-07-27 — Omnibus softens Art. 4: providers and deployers must take measures to support AI literacy; no specific level must be guaranteed
- 2025-08-02 — General-purpose AI model obligations apply; governance and penalties regime in place
- 2026-08-02 — Transparency duties (Art. 50) apply: disclose AI interaction, label synthetic and deepfake content (marking for generative systems already on the market: 2 Dec 2026)
- 2027-12-02 — High-risk obligations for Annex III systems (e.g. hiring, credit, education, essential services) - moved from 2 Aug 2026 by the 2026 Omnibus
- 2028-08-02 — High-risk obligations for AI in products regulated under Annex I
Last verified 2026-10-06 · official text
EU Digital Omnibus on AI · EU
Regulation (EU) 2026/1744
First amendment to the AI Act. Defers high-risk obligations (Annex III to 2 Dec 2027, Annex I to 2 Aug 2028), adds two prohibited categories, softens the Art. 4 AI-literacy duty to "take measures to support", and simplifies some compliance duties. Art. 50 transparency duties still apply from 2 Aug 2026, with one transition (new Art. 111(4)): providers of generative AI systems placed on the market before 2 Aug 2026 must meet the Art. 50(2) marking duty by 2 Dec 2026.
- 2026-07-24 — Published in the Official Journal
- 2026-07-27 — Entered into force
- 2026-12-02 — Grace period ends for safeguards against two new prohibited uses (non-consensual intimate imagery, child sexual abuse material)
- 2026-12-02 — Art. 50(2) marking duty applies to generative AI systems placed on the market before 2 Aug 2026 (Art. 111(4))
Last verified 2026-10-10 · official text
References
- Hannah Mayer, Lareina Yee, Michael Chui and Roger Roberts. Superagency in the workplace: Empowering people to unlock AI's full potential. McKinsey & Company. 2025.
- Duri Long and Brian Magerko. What is AI Literacy? Competencies and Design Considerations. Proceedings of the 2020 CHI Conference on Human Factors in Computing Systems (ACM). 2020.
- S&P Global Market Intelligence. AI experiences rapid adoption, but with mixed outcomes: Highlights from VotE: AI & Machine Learning. S&P Global Market Intelligence, 451 Research. 2025.
- National Institute of Standards and Technology. Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1. NIST. 2023.
- ISO/IEC. ISO/IEC 42001:2023 Information technology - Artificial intelligence - Management system. International Organization for Standardization. 2023.
- The Conference Board. From Principles to Practice: Governing AI in the Corporation. The Conference Board. 2026.
- Supreme Court of Delaware. Marchand v. Barnhill, 212 A.3d 805 (Del. 2019). Justia US Law. 2019.
- Sundar Pichai. An important next step on our AI journey. Google (The Keyword blog). 2023.
- NPR. Google shares drop $100 billion after its new AI chatbot makes a mistake. NPR. 2023.
- Fortune. Google sheds market value after Bard chatbot inaccuracy. Fortune. 2023.
Further reading
- Hannah Mayer, Lareina Yee, Michael Chui and Roger Roberts. Superagency in the workplace: Empowering people to unlock AI's full potential. McKinsey & Company. 2025.
- Duri Long and Brian Magerko. What is AI Literacy? Competencies and Design Considerations. Proceedings of the 2020 CHI Conference on Human Factors in Computing Systems (ACM). 2020.
Sources last verified 2026-10-08.