Artificial intelligence (AI) presents an important governance challenge for boards. Directors are increasingly required to oversee the adoption and use of AI across their organisations. Whether AI is used to support customer service, assist recruitment, conduct data analysis or inform business decisions, it can create significant opportunities for growth and efficiency while also introducing complex risks.
Directors of UK companies are subject to an established framework of statutory, common law and equitable duties that shape corporate decision-making, oversight and governance. Although AI does not create new duties or alter existing ones, it does meaningfully change the context in which directors exercise those duties and affects how those duties are discharged in practice.
This article considers how the use of AI affects the exercise of directors’ duties and offers practical steps for directors and boards to take when overseeing AI-related risks.
The legal framework
As a brief reminder, directors’ duties derive primarily from the Companies Act 2006. Sections 171 to 177 require executive and non-executive directors to:
- Act in accordance with the company’s constitution and exercise powers for proper purposes (s.171).
- Promote the success of the company (s.172).
- Exercise independent judgment (s.173).
- Exercise reasonable care, skill and diligence (s.174).
- Avoid conflicts of interest (s.175).
- Not accept benefits from third parties arising from the directorship (s.176); and
- Declare interests in proposed and existing transactions or arrangements (s.177).
This statutory framework does not operate in isolation. Directors remain subject to common law and equitable duties, including duties to act in good faith, exercise powers for proper purposes and avoid the misapplication of company property. Directors of listed companies or regulated firms are also subject to specific regulatory regimes and obligations.
Understanding how AI is being used within the company
Effective oversight requires directors to understand how AI is being used within the company. While the duty to exercise reasonable care (s.174) does not require technical expertise, it does require directors to maintain a working understanding of the company’s material AI deployments and the risks they create, regardless of whether AI is being used, for example, to support customer service, review contracts, assist recruitment, or optimise supply chains.
The duty to promote the success of the company (s.172) requires that directors assess both the opportunities and risks arising from the adoption of AI. For most companies, AI is a strategic opportunity that may influence competitiveness, innovation and growth. Directors should consider the ways in which AI may contribute to the company’s long-term success.
Uncritical reliance on AI-generated outputs, without appropriate human understanding or challenge, may raise questions about whether directors have exercised independent judgment (s.173) and reasonable care (s.174). Such concerns may arise not only in relation to the company’s deployment of AI across business functions, but also where directors themselves use AI to support their own decision-making.
The risks associated with AI will vary significantly depending on the technology being used and the role it performs within the business. Machine learning and deep learning may be used to analyse large datasets, identify patterns and make predictions or classifications, while generative AI can produce new content and agentic AI can pursue objectives or implement actions with varying degrees of autonomy. These technologies may overlap or be combined within a single AI system.
Agentic AI’s greater autonomy can make decision-making less transparent, limit effective human oversight, and allow errors to be replicated before they are detected. As discussed in previous articles in this series, the use of AI can engage a range of legal and regulatory considerations.1 For example, the use of generative AI may create risks relating to the preservation of legal professional privilege, compliance with data protection obligations when conducting internal investigations, and potentially increased exposure to liability for failure to prevent fraud.
Directors should recognise that AI-related risks evolve throughout the lifecycle of an AI system, with issues arising during design, deployment, monitoring or modification becoming apparent only at a later stage. Those risks may also spread across different business functions. For example, an error introduced into AI-generated customer terms and conditions may subsequently find its way into customer-facing communications and be relied on by customer service teams. What begins as a drafting error may result in customer complaints, regulatory scrutiny, remediation costs and reputational damage.
Practical steps for directors to take
Ensure clear accountability and governance
Directors should ensure that the company has an appropriate AI governance framework, with clear ownership, reporting lines and escalation procedures. An inventory of material AI uses can help provide visibility into where AI is deployed, for what purpose, who is responsible for it and the level of risk involved. AI risks should be presented to the board in a consistent manner and responsibility for their management clearly allocated. Clear accountability and reporting structures help directors maintain effective oversight of AI use and discharge their duty of reasonable care.
Identify and assess AI risks
Directors should ensure that AI-related risks are integrated into the company’s risk assessment and control frameworks. This should include processes to identify, assess, monitor and escalate material AI risks. These processes should be documented so that the company can evidence how AI-related risks are assessed and managed in practice. This is particularly important for high-impact uses, where documented risk assessments are required to assess output, misuse risks and transparency limitations. Where third-party AI systems are used, appropriate vendor diligence and contract controls should address security, access rights, incident notification and change management.
Monitor, test and audit
Directors should ensure that AI systems and the controls governing their use are subject to ongoing monitoring and testing. Boards should receive management information that identifies incidents and exceptions, as well as relevant indicators such as error rates, model drift and escalations, to support effective oversight and challenge. Directors should also ensure that AI systems are appropriately tested against known failure modes and that related controls are subject to independent review and periodic audit. These measures provide directors with the information needed to scrutinise AI systems and exercise independent judgment and reasonable care.
Maintain effective human oversight
Directors should ensure that clear parameters are established for the use of AI, including when human review, verification or escalation is required. Acceptable-use policies should define permitted and restricted uses and establish appropriate controls over the information that may be entered into AI systems. Employees and directors should also receive appropriate training on the AI systems they use or oversee, including their potential failure modes, risks of error or bias, and when human review or intervention is required. Such training can help directors remain appropriately critical of AI-generated outputs, reducing the risk of overreliance on them.
The authors would like to thank WilmerHale intern Michela Bertello for her significant assistance in preparing this article.