In addition to directors’ and officers’ own use of AI tools, an important AI governance question concerns board and management decisions on AI development and AI deployment within their enterprise. Furthermore, insofar as AI is already deployed, directors and officers are tasked with monitoring corporate use of AI. These functions are tied to performance and efficiency, but also exposure to external liability of the entity and individuals for AI harms, with its potentially enormous impacts. While the details of fiduciary duties pertaining to AI remain unsettled, external corporate liability for algorithmic harms may already help give them shape.
It is nearly impossible to discuss directors’ and officers’ fiduciary duties in relation to AI without at least mentioning corporate AI governance and its relationship to fiduciary obligations. Fiduciary duties of care and loyalty demand that directors and officers implement adequate AI governance systems that are tailored to their respective corporations, while those systems, in turn, allow them to properly discharge their fiduciary duties. Proper AI governance provides the basis for minimizing AI-related impacts and harms to third parties, and as such also the basis for minimizing corporate and personal liability.
Businesses and other organizations can now look to numerous guides and soft law when it comes to designing AI governance frameworks. Nevertheless, there is no settled legal guidance – whether in the form of binding legislation, regulations, or specific case law – on how fiduciary duties apply to AI development, deployment, and oversight. That said, we can use case law on corporate liability for AI and algorithmic harms based on tort law, products liability, consumer protection law, etc. to distill insights on what directors and officers should focus on when it comes to AI-related fiduciary duties, and how courts might assess them. In practice, the question of fiduciary duty breaches becomes relevant when corporations suffer a financial loss due to actions or inactions of its directors or officers. Liability resulting in forced payments to third parties, including damages for tort victims or regulatory fines and penalties – are examples of such losses. They raise the question whether losses have been caused by the board’s or executives’ careless or inadequate actions or inactions.
AI Decision-Making
AI’s tendency to generate incorrect outputs or fabricate ‘hallucinated’ information is well known. Case law such as Moffat v. Air Canada, in which the airline was held responsible for incorrect information provided by its chatbot, suggests that businesses may not disown accountability for erroneous outputs by AI or algorithmic systems. For boards and management, it is therefore essential to prioritize minimizing such errors as courts tend to treat them as errors of the organization rather than mistakes that can be blamed on an algorithm or AI system as some sort of ‘third-party entity’ (as Air Canada attempted to do in the Moffat case). In California, the law even expressly precludes defendants from asserting a defense that AI autonomously caused harm.
However, there is also judicial recognition that some AI errors are inevitable and that there is no strict liability (without the requirement of fault) for AI harms. This recognition, insofar as courts subscribe to it, should direct corporate leadership’s focus to risk mitigation in the form of disclosures, warnings, and disclaimers.
Notably, litigation involving algorithmic harms linked to social media, chatbots, and autonomous vehicles further illustrates that corporate boards and managers should from the outset consider and adequately address the potential for a broad range of economic, mental, and physical harm when making decisions concerning the development, design, sale, distribution, and deployment of AI tools and systems. This includes carefully evaluating technical reliability, safeguards, and stakeholder impacts. It also involves implementation of appropriate and proportionate risk and harm mitigation measures.
AI Oversight Standards
Once AI is in use, it is the responsibility of directors and officers to engage in thorough oversight to ensure ongoing compliance and risk management. A complication is that foreseeability problems – which arise due to AI’s complexity and opaque nature – may affect internal oversight. When AI harms are difficult to anticipate for individuals, it becomes harder to establish that they were in breach of their duties – which benefits boards and executives, while being a burden on plaintiffs. Conversely, AI also creates heightened risks for boards and managers. Although AI is capable of vastly improving risk management and monitoring, the downside is that AI’s opaque and at times error-prone nature may also make it more difficult for management to identify and respond to warning signs before harm materializes, contrary to their fiduciary duties related to monitoring and oversight.
Delaware provides arguably the most developed legal framework for oversight. Yet, its application to AI has not yet been tested. The basic principles are well established: Caremark, as refined by Stone v. Ritter and subsequent case law, demands that directors and officers implement and maintain an appropriate internal control system. Although the hurdles for holding managers liable for undue oversight remain high, essentially insulating them as long as they did not “utterly” fail to implement controls or “consciously” failed to monitor them, newer developments signal a potential tightening. Marchand v. Barnhill and other decisions have shown that Delaware is more open to oversight claims when they touch upon business risks that are central to a business or ‘mission critical.’ This expansion may sharpen oversight duties and facilitate claims relating to AI whose development or deployment goes to the heart of a corporation’s business or may be considered high-risk.
Case law on corporate AI liability underscores that oversight must not only address technical errors, but also concerns such as bias, discrimination, privacy, and the full range of physical, mental, and economic harm mentioned above. It also serves as an important warning for managers, revealing risks that may affect oversight duties. A fundamental principle of Delaware’s oversight jurisprudence is that boards presented with evidence or information about harms that emanate from their companies may not simply turn away. Instead, Delaware law provides that when red flags are “waved in one’s face or displayed so that they are visible to the careful observer,” they cannot be ignored. While AI induced harms that have not yet materialized may be difficult to foresee, harms that are already the subject of litigation, especially with successful claims, should put boards and managers on notice. Failure to take steps toward stopping and mitigating these and similar harms would become difficult to defend in light of their fiduciary obligations.
Conclusion
Directors’ and officers’ fiduciary duties pertaining to AI-related decision-making and oversight are a nascent and evolving area of the law. While we are waiting for specific case law and judicial guidance – which will no doubt emerge in due course – we can already distill useful initial insights by studying corporate liability to external parties. Corporations’ exposure to external claims, risks, and harms may inform the contours of directors’ and officers’ internal fiduciary duties of care and loyalty. Courts have thus far shown themselves to be open to holding corporations responsible for a broad range of negative impacts linked to algorithms and AI. Boards and managers are therefore on notice that they must anticipate and address the potential consequences of their corporations’ AI activities to avoid the risk of fiduciary duty breaches.
This Insight is based in part on my forthcoming book chapter.