We opened our session at the Canadian School Boards Association conference with a show of hands.
How many of you have personally used an AI tool in the last month? Almost every hand in the room went up.
How many of you have had a substantive conversation about cybersecurity at your board table in the last year? Well over half.
How many of you feel clear on what belongs to the board and what belongs to staff in these areas?
Maybe a quarter.
We had not planned to stop there, but that pattern was too interesting to move past. So we gave the tables a couple of minutes to talk about it. A room full of experienced trustees, nearly all of whom were using AI personally, most of whom were discussing cybersecurity at their board tables, and only a fraction of whom felt clear on where their role starts and stops.
That gap, between engagement with the issues and clarity about the governance role, was really the whole point of our session.
The pattern did not surprise me, exactly. A few months ago, a trustee said something to me that has stuck: “I feel like I need to understand this better before I can do anything useful.” I have heard versions of that sentence a lot. When a topic is moving this fast, the natural instinct is to reach for expertise. To want to know more before you act.
But the show of hands at CSBA suggested something worth considering: this was not mainly a familiarity gap. It was a role-clarity gap.
And those are very different problems, with very different solutions.
I wrote about the trustee role in a broader way back in May, in a post for people considering running for school trustee ahead of the October elections here in BC. One of the things I tried to say there is that the role is not what most people think it is. Trustees do not run schools. They do not manage teachers. They do not direct operations. What trustees do is govern a system. They set direction, ask questions, build relationships, and hold the system accountable.
That distinction between governance and management is the foundation of everything else. And AI and cybersecurity have become two of the best stress tests of that distinction I have encountered.
That is what drew Mark Pearmain and me into a ninety-minute session earlier this summer, with the national gathering hosted here in BC. Mark leads Surrey Schools, the largest district in BC. I lead a much smaller one. We come at these questions from genuinely different places, which is part of what made building the session together worthwhile. A risk that registers one way in West Vancouver looks different at Surrey’s scale. An innovation that feels experimental in one place might already be routine somewhere else.
We were clear in the room that we were not there as technical experts. What we tried to bring was something different: the perspective of system leaders trying to connect emerging technology, risk, learning and governance.
Here is what I took away.
The trustees in the room were clearer on their role than the conversation about trustees sometimes suggests. We spent time on the distinction between operational expertise (which belongs to staff) and governance judgment (which belongs to the board). I half expected this to be the hardest part of the session. It was not. Many of the trustees who spoke understood exactly where that line sits, and their questions came from the governance side of it.
That was encouraging, and it deserves to be said, because trustees do not always get credit for this clarity.
The anxiety around AI is real, and it is fair. You could feel it in the room. And rather than trying to talk anyone out of it, we kept coming back to a frame that I think holds up: good governance holds risk and possibility at the same time. A board that only sees risk may slow its system at exactly the wrong moment. A board that only sees possibility may leave students and staff exposed.
The anxiety is not a problem to be solved. It is a signal that the stakes are understood.
The cost of cybersecurity belongs in budget conversations. Some of the best discussion in the session came around what cybersecurity actually costs, in staffing, in systems, in preparedness. This is not a luxury line item, and it is not purely an operational detail. Boards approve budgets, and boards should be asking what their district’s cyber readiness costs, what it would cost to be better prepared, and what the cost of being unprepared looks like.
A board does not need to manage the cybersecurity plan. But it does need to understand the investment, the risk, and the consequences of underpreparing.
As Mark put it: the middle of a crisis is a terrible time to discover the board does not know its role.
Education really does look different in every province. One of the best conversations I had after the session was with a trustee from Alberta, who described how differently cybersecurity responsibility is structured there, particularly around the roles of insurance companies and provincial government. I knew this in the abstract. Hearing it described concretely was a reminder that a national conversation about these topics is not about finding one answer.
It is about understanding how differently the same challenge lands across the country, and learning from that variety.
Which connects to the argument Mark made throughout the session, and made well: this work needs national-level connection. Education is a provincial responsibility, but AI and cybersecurity challenges do not stop at provincial borders.
Mark also brought the OECD’s Education for Human Flourishing work into the session, which gave the whole conversation a global context. That matters for trustees because the governance question is not only, “How do we manage the risk?” It is also, “What kind of education are we trying to protect and strengthen?”
The questions trustees are asking about AI are not just Canadian questions. They connect to what education systems around the world are trying to figure out about what it means to prepare young people for a world where the technology keeps getting more powerful and the human elements keep getting more important.
We put together a set of materials for the session, and I want to share all of it here. There is the slide deck and three handouts, including a question bank with twenty questions organized into four areas: learning and equity, privacy and data, risk and readiness, and networks and shared learning. None of the questions require technical expertise to ask.
Please use these however they are useful. Take them to a board meeting. Pull out the three questions that fit your context and ignore the rest. Remix them, adapt them, improve them. They were built to be circulated, not protected.
If one of them helps start a better conversation in your district, that is the point.
HANDOUT: Table Discussion Questions
HANDOUT: 20 Questions Worth Asking This Year
HANDOUT: The Governance Compass
If there is one thing I hope carries beyond the session, it is the closing idea Mark and I landed on: better questions create better conditions, and stronger connections create shared wisdom. What one district learns should not stay trapped in one district. What one province figures out should not have to be rediscovered in another. The way forward on all of this is to keep networking, keep sharing, and keep learning together.
None of us fully knows where this is going. That is exactly why the connections matter.










