Corporate governance discussions have largely focused on how directors and officers should manage and monitor AI in their companies. But there is another open question: to what extent may corporate leaders use and rely on AI in discharging their duties? Although AI use by corporate leaders is widespread, specific guidelines and best practices remain rare, and case law is largely non-existent. While retaining human judgment appears to become the guiding principle on where to draw the line between legitimate and illegitimate AI uses, more nuanced approaches will likely emerge. In any event, there is an urgent need for clear and detailed policies.
Directors and Officers are Already Using AI
Directors and officers are beginning to embrace AI for governance purposes. Based on reports and anecdotal evidence, it seems clear that board members and executives utilize AI for a range of tasks, from preparing and synthesizing documents, formulating questions before and during meetings, and leveraging AI to access information to evaluating performance and helping with administration. Additionally, and most consequentially, boards and managers also use AI for oversight and decision-making, including in the form of ‘AI board advisor’ systems.
Studies confirm corporate leaders’ increasing use of artificial intelligence. Although a report by the Australian Institute of Company Directors has found that directors and boards remain cautious in using AI, it also noted that conversations in boardrooms are shifting from ‘how do we govern AI’ to ‘how can AI help us govern’? A recent survey by the Society for Corporate Governance and Nasdaq suggests that uptake of AI tools by governance professional is rapidly growing, while authorized use by directors progresses with slower pace. Yet, the study also highlights the widespread use of unsanctioned ‘shadow’ AI use by board members, which occurs outside the confines of company-approved systems.
When May, and When Must, D&O use AI?
The prevalent view among business and legal commentators is that corporate leadership may legitimately use AI (which excludes clear aberrations such as ‘shadow’ use and other practices that may endanger confidentiality and privacy obligations). Indeed, in some instances directors and officers may arguably even be duty-bound to leverage AI. The difficulties, however, lie in formulating usefully precise boundaries and practices that identify appropriate reliance on AI systems while avoiding excesses. Achieving this balance is challenging and remains almost uncharted legal territory. Regulatory frameworks, codes, standards, and industry practice are beginning to supply tentative answers, but there is still a lack of judicial guidance addressing directors’ and officers’ AI-related fiduciary duties, as I have noted in my corporate governance and AI research.
The use and non-use of AI implicates primarily the duty of care, although it can also be relevant in terms of the duty of loyalty, such as in cases of bad faith and self-dealing. In Delaware, the duty of care of directors and officers entails the obligation to inform themselves prior to making a business decision, of all material information reasonably available to them. Similar requirements apply in Canada and the UK, with statutory provisions requiring directors and officers to use reasonable care, diligence and skill, which includes using appropriate information. Acceptable standards of care evolve based on market expectations and commercial practice, which also means that individuals who fail to utilize AI that is accessible and has proven capabilities may fall short of their obligation to act with care and consider all information reasonably available. An expectation to use AI may begin to apply where its use has become commonplace and leads to significantly improved outcomes and/or tangible efficiencies. An example of this may be the areas of risk management and compliance, where AI use is already common and arguably cost-benefit effective.
Just as the failure to use AI may become a potential breach of directors’ and officers’ duties, over-reliance on AI might lead to personal liability. The AI black box creates three issues for managers: (1) they may not know the specifics of an AI tool’s design and underlying data; (2) they may not be certain whether the AI tool had accurate and complete information when reaching a decision, and whether the output itself is accurate; and (3) they may not be aware of the AI tool’s reasoning, including alternatives that it may have considered. Additionally, AI tools are not within the scope of corporate law provisions that allow directors to rely in good faith on information provided by certain professionals or experts. This combination of factors may cause managers to fall below the required diligence when they use AI. The business judgment rule will also not protect directors if reliance on AI is construed as a failure to be reasonably informed or an indication of a lack of acting in good faith.
At the same time, some of the very issues that may render the use of AI impermissible or ‘careless’ – mainly its opaqueness and complexity, but also accuracy, safety, and confidentiality concerns – are inherent to many AI systems. This raises the question of how directors and officers can use AI safely and responsibly when it comes to their own activities. A central guiding principle is that, as with any other advice or information that they receive, corporate leadership may not passively accept AI outputs. Rather, they must critically examine it, including considering their own knowledge and relevant sources of information. In particular, analogizing from requirements for directors’ reliance on experts, it follows further that boards must: (1) use AI outputs in good faith; (2) ensure that a query is within the relevant AI tool’s competence; and (3) select AI systems with reasonable care.
ASIC v Bekier: Judicial Guidance on Directors and AI
In what might be the first decision commenting directly on the use of AI by corporate directors, albeit in the form of non-binding dicta, the Federal Court of Australia in Australian Securities and Investments Commission v Bekier (2026) has provided useful guidance in a decision on managerial duties. Refering to the use of AI as a governance support tool by boards, the court first observed a “shifting … focus from how companies generally oversee AI in their organisations to how AI might assist the directors themselves in the discharge of their duties.” It acknowledged the informal use of AI by directors as well as its use by management and company secretaries in the creation of board packs – which in turn directors might read and analyzed with the help of AI.
In light of these realities, the court went on to outline a cautious but flexible stance on AI that rests on transparency, clear policies, and rejection of mechanical reliance.
As the court stated:
Ultimately, however, directors must be furnished, by whatever means are adopted, with information in a form that is both comprehensive and capable of proper digestion. It scarcely requires emphasis to observe that the use of AI-generated summaries as a substitute for the careful reading and interrogation of board materials would warrant caution, not least because inadequately deployed or misdirected AI may increase risk and legal exposure rather than mitigate it. That said, there is considerable potential for AI, if appropriately utilised, to assist directors in the discharge of their duties.
But any use of AI should be controlled and transparent. It seems to me prudent that boards should discuss and deliberately govern any AI use by formal adoption of policies, rather than just wink at informal “shadow” use. Chairmen and company secretaries have a critical role in preserving role boundaries with management and promoting proper director engagement. Although ethical reasoning and judgment rests with directors, not machines, AI is already changing the way in which directors receive and analyse material. It is the responsibility of directors to ensure that this occurs in a responsible way, guided by Middleton J’s caution that a board can control the information it receives.
In terms of the limits of AI reliance, the court also observed:
[I]t appears it is necessary to restate plainly that directors cannot rely upon an inability to cope with the volume of information they receive. In short, a director, whether executive or non-executive, is required to take reasonable steps to place themselves in a position to guide and monitor the management of the company, and is expected to take a diligent and intelligent interest in the information available to them, understand that information, and apply an enquiring mind to their responsibilities.
A way of addressing information overload, at least in part, could be through the principled and transparent use of emergent technology. The modalities of reading and examining material in board papers might change, but analysing and understanding information provided by management is a core function of a board; after all, this is the primary way by which directors access the information necessary to make informed, bona fide decisions.
In short, according to Bekier, directors that use AI must still use their own informed judgement.
The Limits of Human Judgment and Oversight of AI
The need to preserve ‘informed judgment’ by corporate directors and officers appears to be the guiding principle at this stage. What exactly that means is not clear, although we could say it entails careful consideration of relevant information, followed by independent analysis and a decision grounded in facts, individual expertise, and good faith efforts to advance business interests.
While human judgment and – more broadly – human oversight of AI appear to be reasonable requirements, there is the question to what extent, and how, this remains helpful and viable in the age of AI. Machines are vastly better than humans when it comes to certain tasks, and asking that individuals always be the final decision-makers and overseers is neither conducive to efficiency gains nor realistic. It is also at odds with the imminent shift to fully autonomous agentic AI systems.
More nuanced approaches and frameworks for human involvement are therefore necessary, both in terms of when to ask for human involvement and what shape it should take. In terms of the former, for instance, questions that entail ethical or moral components appear good candidates for mandatory exercise of human judgment. Regarding the latter, there is a range of potential models for involving humans, some of which are helpfully outlined in the EU’s Guidelines for Trustworthy AI.
Going forward, it is unlikely that requiring directors and officers never to defer to AI will be an optimal, or even workable, solution. Instead, AI corporate governance frameworks that allow AI decisions, hybrid AI-and-human-decisions, and decisions decided solely based on human-judgment may well emerge as the most practical solution. The idea of business leaders as the ultimate decision-makers is further put into doubt in view of a Delaware proposal to trial new AI-only managed entitites. This suggests that a future with agentic AI corporations that conduct business without human judgment and oversight may soon be upon us.
This Insight is based in part on my forthcoming book chapter.