Artificial intelligence has quickly become part of the governance professional’s toolkit. Company Secretaries are using AI to review Board papers, draft first versions of minutes, summarise lengthy reports, prepare governance research and improve the quality of governance documentation.
Used responsibly, these tools can reduce administrative effort and allow governance professionals to spend more time supporting Boards on strategic governance matters. But one question continues to arise in governance discussions: Can I upload Board papers, minutes or committee documents to an AI platform?
The answer is not simply yes or no. Like any governance decision, it depends on the information being processed, the platform being used, the applicable legal and contractual obligations, and the governance controls in place. The issue is not whether AI should be used. The issue is whether it is being used responsibly.
In conversation: Ralph Hohls on AI and governance
Ralph Hohls, CEO and Founder of RH Connect, says the real governance risk is not AI itself, but the ungoverned use of generic AI tools on sensitive board information. In his view, AI can support better board preparation, stronger questioning and more focused agendas — but only where it is used in secure, approved environments with clear human oversight.
Read Ralph’s full opinion on responsible AI in board practice on the The Hub Briefing.
Ralph Hohls is the CEO and Founder of RH Connect, a people-tech connector supporting boards, public-sector teams and governance professionals with practical technology enablement.
AI Does Not Remove Professional Responsibility
One of the biggest misconceptions surrounding AI is that once a document has been generated or improved by a system, responsibility somehow shifts to the technology. It does not.
Perhaps the best-known cautionary example is Mata v. Avianca, Inc., where United States legal practitioners submitted court papers containing case authorities generated by an AI system. Several cited cases did not exist, and the court sanctioned the lawyers. The lesson is clear: professional responsibility remains with the professional, not the AI platform.
For Company Secretaries, this principle applies directly. If AI assists with Board minutes, resolutions, governance reports, committee papers or governance policies, the responsibility for accuracy, completeness and appropriateness remains with the governance professional. AI can assist your work. It cannot discharge your professional responsibilities.
Confidential Information Deserves Governance
Another widely reported example involved Samsung, where employees uploaded confidential source code and internal meeting information to ChatGPT while seeking assistance with their work. The incident prompted restrictions on the use of generative AI tools within the organisation and highlighted how easily sensitive information can leave an organisation’s controlled environment.
Although the circumstances differ from governance practice, the lesson is highly relevant. Company Secretaries routinely handle information relating to Board deliberations, acquisitions, executive remuneration, litigation, shareholder matters, strategic planning and regulatory investigations.
Before uploading any document, consider whether the information should leave the organisation’s governance environment at all. Sometimes the safest approach is not to upload the original document, but to remove identifying information or create an anonymised extract containing only the text necessary to complete the task.
Which Laws and Standards Should Governance Professionals Consider?
AI governance extends beyond a single piece of legislation. Depending on where your organisation operates, where the AI provider processes information and the nature of the information involved, several legal and governance frameworks may be relevant.
South Africa: Protection of Personal Information Act (POPIA), Companies Act 71 of 2008 and Electronic Communications and Transactions Act (ECTA).
European Union: General Data Protection Regulation (GDPR) and Regulation (EU) 2024/1689, the EU Artificial Intelligence Act.
United Kingdom: UK GDPR and Data Protection Act 2018.
United States: California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA), where applicable.
International standards and frameworks: ISO/IEC 42001, ISO/IEC 27001, ISO/IEC 27701, the NIST AI Risk Management Framework and the OECD AI Principles.
You do not need to become an AI legal specialist. You do, however, need to understand which governance obligations apply to your organisation before introducing AI into governance processes.
Better Prompts Produce Better Governance Outcomes
Many governance professionals are disappointed with AI because they ask questions that are too broad. For example, “Summarise this Board paper” provides almost no direction. Instead, instruct AI as you would brief a governance consultant: define the role, provide context, set boundaries and specify the required output.
Example 1: Reviewing a Board Paper
Role: You are assisting me as an experienced Company Secretary preparing for a Board meeting. Context: This document is a Board paper submitted for approval. Instructions: Base your review only on the information provided. Do not invent facts, assumptions or recommendations that are unsupported by the document. Where information is missing, identify the gap rather than making assumptions. Review the paper under the following headings: strategic issues, governance implications, principal risks, decisions required, missing information and questions the Board should ask before making a decision. At the end of your review, identify any governance concerns that require clarification before the matter proceeds to the Board.
Example 2: Reviewing Draft Board Minutes
Role: You are assisting me as a governance quality reviewer. Review these draft minutes. Do not rewrite the minutes. Instead, assess whether they adequately record declarations of interest, decisions reached, resolutions adopted, action items, responsible persons, reporting deadlines and matters deferred. Identify omissions, governance weaknesses and inconsistencies without creating information that does not appear in the original document.
Example 3: Reviewing a Board Resolution
Review this Board resolution from a governance perspective. Assess whether it clearly identifies the decision being approved, the authority under which the decision is made, implementation responsibility, reporting obligations, accountability mechanisms and review requirements. Where improvements are recommended, explain why they are necessary. Do not rewrite the resolution unless specifically requested.
Example 4: Preparing for a Board Meeting
I am the Company Secretary preparing for tomorrow’s Board meeting. Review the attached Board pack and prepare a governance briefing for the Chair. Identify agenda items requiring significant Board deliberation, matters that appear incomplete, recommendations requiring additional supporting information, recurring governance issues from previous papers where identifiable, and governance questions the Chair may wish to ask management.
The Governance Lens
Before using AI with Board or committee material, Company Secretaries should apply a simple governance test:
Purpose: Is there a clear and legitimate governance purpose for using AI?
Information sensitivity: Does the document contain personal information, confidential strategy, privileged material or market-sensitive information?
Platform control: Is the AI tool approved, secure and governed by appropriate contractual terms?
Data handling: Will the information be retained, used for model training or processed outside approved jurisdictions?
Human review: Has a competent governance professional verified the output before it is used?
Record keeping: Is there an audit trail showing how AI was used and who approved the final output?
Artificial intelligence is rapidly becoming another workplace application. Like email, cloud storage and Board portals before it, it will become part of everyday governance practice. The distinguishing feature of an effective Company Secretary will not be whether they use AI. It will be whether they use it with the same care, professional judgement and governance discipline they apply to every Board meeting.
Technology changes. Governance principles do not.
References
Companies Act 71 of 2008.
Protection of Personal Information Act 4 of 2013 (POPIA).
Regulation (EU) 2016/679 (General Data Protection Regulation – GDPR).
Regulation (EU) 2024/1689 (EU Artificial Intelligence Act).
ISO/IEC 42001:2023 – Artificial Intelligence Management Systems.
ISO/IEC 27001:2022 – Information Security Management Systems.
ISO/IEC 27701:2019 – Privacy Information Management.
National Institute of Standards and Technology (NIST), AI Risk Management Framework 1.0.
OECD Principles on Artificial Intelligence.
Mata v. Avianca, Inc., 678 F. Supp. 3d 443 (S.D.N.Y. 2023).
Samsung Electronics generative AI data exposure incident, 2023, widely reported corporate governance case study.

