RatedWithAI

RatedWithAI

Accessibility scanner

Corporate GovernanceAugust 24, 2026

The Board Minutes Are the Evidence

Oversight liability does not require directors to have understood the model. It requires that they established a system for hearing about it and did not ignore what came back. In most companies deploying AI at consequence, that system was never built — and the proof of its absence is a document the company produces itself.

Two prongs
No monitoring system at all, or conscious disregard of what it reported
Charter
Assignment must be written, not assumed under 'technology risk'
Cadence
A standing agenda item makes a missing report visible

Why the Standard Bites Differently Here

Oversight claims have historically been among the hardest to sustain, because they require bad faith rather than mere carelessness. That difficulty has eroded in a specific direction: where the risk was central to the business and governed by a regulatory regime, and where the board record shows no dedicated attention to it at all, claims have survived dismissal often enough to change how counsel advise.

AI fits that pattern with unusual precision for three structural reasons. It is being deployed into exactly the regulated decisions — hiring, lending, pricing, insurance, clinical support, benefits — where a governing regime exists and harm is legible. It fails in a way that is systematic rather than random, so a single design flaw produces a class of affected people rather than an incident. And it is adopted from the bottom upward, so the governance layer is frequently the last to learn what is running.

There is also a reflexive problem. Boards have spent two years hearing about AI as opportunity — competitive threat, efficiency, product roadmap. Those sessions are in the minutes. What is often absent from the same minutes is any report on incidents, validation results, complaint patterns or regulatory exposure from the same systems. The asymmetry is what a plaintiff's lawyer means when they say the board treated it as strategy and not as risk.

What a Monitoring System Has to Produce

An inventory the board has seen

A current list of AI systems in production, classified by consequence: who is affected, whether a decision about a person follows, which regulatory regime applies, and whether it was built, bought or embedded in a purchased product.

Why it matters: Everything else is downstream of this. A board that cannot say how many consequential systems the company runs has not established a reporting system in any meaningful sense, and the inventory is the first document requested in discovery.

Pre-defined escalation thresholds

Written criteria stating what management must bring to the board: incidents above a severity, adverse validation findings, regulator contact, complaint volumes crossing a threshold, and material changes such as a new model provider or a decision becoming fully automated.

Why it matters: Thresholds set in advance protect directors twice: they generate a record of governance design, and they remove the discretion by which management decides in the moment that something is not board-level news.

Independent assurance, not self-reporting

Internal audit coverage, independent model validation, or third-party testing that reports to the committee rather than through the function that owns the system, with findings tracked to closure.

Why it matters: A monitoring system entirely dependent on the builders of the system reporting on themselves is the structure that failed in every classic oversight case. Independence is the feature, not the rigour of the report.

A response record

Minutes that show what was escalated, what the board asked, what management committed to, and when it was verified — including decisions that no further action was needed, with the reasoning.

Why it matters: The second prong of an oversight claim is conscious disregard of known problems. The only durable answer is a record of engagement. 'We discussed it' without an outcome reads as awareness without action, which is worse than silence.

Three Governance Gaps That Recur

  • Ownership by assumption. Ask three directors which committee owns AI risk and you frequently get three answers. Nobody objects to the ambiguity because everyone believes someone else has it. Amending a charter to name AI risk explicitly costs one meeting and closes the single most avoidable gap in the whole area.
  • Reporting that only carries good news. The AI item on the agenda is owned by whoever is building the AI, and it is a progress update. Risk reporting requires a different reporter and a different template: incidents, near-misses, validation outcomes, complaints, open findings and their age. If the last four board packs contain no adverse AI information at all, that is a finding in itself.
  • Embedded systems nobody inventoried. The consequential model is often not one the company built or even bought directly — it arrived inside a purchased platform, switched on by default, making or shaping decisions under a vendor's brand. These are absent from most inventories, and they carry the same liability as anything built in-house because the deploying company is the one facing the affected person.

One boundary is worth drawing clearly, because the two are routinely conflated. This is a fiduciary question — whether directors built and used a monitoring system — enforced by the company or those standing in its shoes. It is distinct from the securities question of whether what you said about your AI was accurate, which is a disclosure regime with its own rules and its own enforcement history; that side is covered separately in AI risk disclosure in filings. A company can describe its AI impeccably and still have no oversight system, and the reverse is equally possible.

The Insurance Question Directors Should Ask

Directors' and officers' cover responds to claims against individuals for wrongful acts in their capacity as directors, which is the right shape for an oversight claim. What has changed is the underwriting conversation around it: applications increasingly ask about AI governance, and answers given on those forms become part of the contract. Overstating maturity on a proposal form is a rescission risk at exactly the moment cover matters.

Two further mechanics are worth confirming rather than assuming. Whether any AI-specific or technology-related exclusion has been introduced at renewal, since exclusion language in this area has been drafted broadly enough in some markets to reach ordinary deployment. And how the tower responds to a regulatory investigation before any claim is filed, since investigation costs frequently exceed defence costs in enforcement-led matters, and cover for pre-claim inquiry costs varies far more than boards expect.

The Board Agenda Checklist

Take this to the next meeting. It is designed to be answered from the board pack; where it cannot be, that is the finding.

1. Structure
  • Name the committee that owns AI risk and confirm the charter says so in writing
  • Confirm a named executive owner reports on it, distinct from the executive who builds it
  • Establish a standing agenda item with a defined cadence, so a missing report is visible
  • Identify which director has enough fluency to ask a second question, and close the gap by education or appointment
  • Define the interaction between this and existing privacy, security and compliance reporting
2. Information
  • Obtain a current inventory of consequential AI systems, including embedded vendor features
  • Set written escalation thresholds for incidents, findings, complaints and regulator contact
  • Require reporting on adverse outcomes, not only adoption metrics and roadmap progress
  • Ask for validation and testing results directly, including performance differences across groups
  • Confirm internal audit has AI systems in its coverage plan with a date
3. Response and Record
  • Minute escalations with the question asked, the commitment made and the verification date
  • Record decisions that no action is required, with the reasoning stated
  • Track open findings and their age, and challenge anything that has aged without movement
  • Confirm previously reported mitigations were actually implemented, rather than accepting the original commitment as closure
  • Review the minutes annually against the risk classification — strategy and risk framing must not contradict
4. Disclosure and Cover
  • Route AI capability claims in filings, calls and marketing through disclosure controls with technical sign-off
  • Review risk factors for specificity — boilerplate is a liability, not a shield
  • Answer insurance proposal questions on AI governance accurately and keep the supporting evidence
  • Check for newly introduced AI or technology exclusions at each renewal
  • Confirm how the policy responds to pre-claim regulatory investigation costs

Frequently Asked Questions

We are a private company with no public shareholders. Does any of this apply?

The oversight duty is a fiduciary duty owed to the company and enforced through derivative litigation, so it exists regardless of whether shares are publicly traded — what changes is who is realistically positioned to bring a claim. In private companies the pressure typically arrives through different doors: a minority investor in a dispute, an acquirer's diligence process, an investor with contractual information rights, or a founder disagreement where governance conduct becomes the battleground. Sponsor-backed boards face an additional dynamic, since designated directors carry the reputational exposure of the fund alongside their own. The practical position is that the volume of governance appropriate to a private company is lower, but the categories are the same, and the cheapest time to build the record is before an acquirer's counsel asks how AI risk is governed.

None of our directors understand machine learning. Is that itself a breach?

No. Directors are entitled to rely in good faith on officers and on experts selected with reasonable care, and the duty has never required personal technical mastery — audit committees oversee accounting without every member being an accountant. What the reliance defence requires is that it be genuine: that the person relied on is competent and appropriately independent, that the board asked questions rather than accepting a conclusion, and that reliance was not maintained in the face of contrary indications. The realistic weakness is not ignorance but the inability to interrogate. A board where nobody can ask why a validation set was chosen, or what the error rate looks like for the smallest affected group, will accept a reassuring answer that a single informed question would have opened. The remedy is one fluent director, a standing external adviser, or a management reporting template that forces the uncomfortable numbers onto the page.

Management says AI governance is handled by a working group. Is that sufficient?

It is a good sign at the management layer and it does not discharge the board's duty, because the two operate at different levels. A working group implements; the board oversees. The question to put to management is not whether a group exists but what reaches the board and by what rule. Ask for the group's charter, its membership, its escalation criteria, the minutes of its last three meetings, and specifically what it decided not to escalate. That last request is the informative one. A working group that has escalated nothing in a year is either operating a genuinely clean estate or is functioning as a filter, and reading its own record of near-misses distinguishes the two quickly.

Where do the AI-specific regulatory regimes fit into board responsibility?

They give the oversight duty its content. Emerging AI legislation and sector regulator expectations increasingly name governance obligations directly — risk management systems, human oversight design, documentation, incident reporting, and in some regimes a designated accountable person. Where a regime expects a named governance body, the board's failure to designate one is a discrete finding independent of any harm. More broadly, the existence of an applicable regime is one of the factors that pushes a risk toward mission-critical in an oversight analysis, because it evidences that the harm was foreseeable and that a standard of care was publicly available. Boards do not need to track every jurisdiction, but they should require management to maintain and present a map of which regimes apply to which systems, and to flag when a new one attaches.

What is the single most useful thing a board can do this quarter?

Request the inventory of consequential AI systems and read it in the meeting. It takes management a week to assemble the first time and it produces more governance value than any policy document, because it converts an abstract topic into a list with names, owners, affected populations and applicable regimes. In practice the exercise surfaces two things almost every time: a system that makes decisions about people that no director knew existed, usually embedded in a purchased platform, and a system whose owner cannot state which regulatory regime applies to it. Both are actionable immediately. Then set the escalation thresholds and put the item on the standing agenda — with the inventory, the thresholds and the cadence in place, the structural half of the exposure is closed.

Read the Last Four Board Packs

Search them for AI. Count how many mentions are opportunity, roadmap or competitive positioning, and how many are incidents, validation findings, complaints or regulatory exposure. In most companies the second number is zero.

That ratio is the oversight record as a plaintiff would first encounter it. Changing it requires no new committee and no new policy — only a different reporter and a template that has room for bad news.