Your Fiduciary Duty in the Age of AI
There is a common misconception that AI introduces entirely new legal obligations for directors. It does not.
What AI does is change the context in which existing obligations apply.
Under the Corporations Act 2001 (Cth), directors have a duty of care and diligence — to exercise the degree of care that a reasonable person in their position would exercise. That duty is not static. It scales with the risks and complexities of the business.
If AI is being used in your organisation, the standard of care required of you now includes understanding and overseeing that use.
The Reasonable Director Standard
The question courts will ask is not whether you understood the technical details of the AI system. The question is whether a reasonable director in your position would have taken steps to understand and oversee AI-related risks.
The factors that inform this standard include:
- The nature of the AI use. Is it customer-facing? Does it make decisions that affect individuals? Does it handle sensitive data?
- The scale of deployment. Is AI used in a single marketing function, or is it embedded across operations, compliance, and risk management?
- The regulatory environment. Are regulators in your sector issuing guidance on AI governance? Are there enforceable obligations?
- What your peers are doing. What are comparable boards doing to govern AI? The standard of care is informed by industry practice.
How This Plays Out in Practice
Consider three scenarios:
Scenario 1: A company uses an AI recruitment tool that systematically disadvantages candidates from particular demographic groups. The board was unaware the tool was in use. A regulator investigates and finds the company in breach of anti-discrimination law.
Questions for the board: Should you have known the tool was being used? Should you have had a policy requiring oversight of AI-enabled hiring decisions?
Scenario 2: A company deploys a customer-facing AI chatbot that provides incorrect financial advice. The company is sued. The board had not discussed AI risk at any meeting in the preceding 12 months.
Questions for the board: Was the board's risk oversight adequate? Was management required to report AI-related risks?
Scenario 3: A company's employees are using public AI tools to process confidential client data. A data breach occurs. The board had no AI usage policy in place.
Questions for the board: Did the board exercise reasonable care in overseeing the company's information security environment?
What Directors Should Do Now
The most practical step you can take is to ensure your board has a structured approach to AI oversight. This does not require a separate AI committee. It does require:
- Management reporting. Ensure management reports on AI usage, risks, and controls at least quarterly.
- Board-level discussion. Schedule a dedicated discussion on AI governance at least once per year.
- Documented oversight. Record the board's consideration of AI risks in meeting minutes.
- External input. Consider engaging independent expertise to review the board's AI governance framework.
The Bottom Line
Your fiduciary duty is not new. But the expectations attached to it are evolving. A director who can demonstrate that they asked questions, sought information, and exercised independent judgment in relation to AI will be in a defensible position.
A director who cannot demonstrate any of those things will not be protected by claiming AI was too complex or too new to understand.
The law does not require you to be an AI expert. It requires you to be a diligent director.