Director liability and AI washing: the board-risk side of your mandate

A person sitting at a desk under a lamp in the evening, reading a printed document with a thoughtful expression
TL;DR

When a board update claims AI is delivering, a regulator or a buyer can later ask you to show your working. AI washing, exaggerating AI capability to investors, falls under existing securities-fraud law, and commentators argue directors face growing personal exposure for unproven claims. The defence is an audit trail, a dated record of what the system did, on what input, with what oversight. Never let an AI line into a board paper unless someone can stand behind it.

Key takeaways

- AI washing, exaggerating AI capability to investors, is treated as securities fraud under existing antifraud law in the US, not as harmless marketing puffery, which means a stretched AI line in an investor update sits in the same legal category as any other material misstatement. - Director and officer exposure is now a live boardroom concern rather than a theoretical one, with AI spend surging and an emerging gap in traditional D&O insurance that may not catch AI-related claims. - Legal commentators argue the board cannot delegate AI oversight away, the principle being that when an AI system makes a decision the board is treated as having made it, and "I did not understand the technology" is not a defence, only evidence of appropriate oversight is. - An audit trail for an AI claim is a dated, tamper-evident record of what the system did, on what input, with which version, and what human review sat over it, which is what turns a claim from unprovable into defensible. - In an owner-managed business with no compliance function, the protection is a small discipline, keep lightweight documentation, record which claims rest on which evidence, and never let an AI line into a board paper or investor update unless someone can stand behind it.

Somewhere in the slide deck sits a confident line. AI has cut our response times. AI is driving efficiency across the operation. AI is now embedded in how we work. It reads well, and the board nods, because it is the progress they were hoping to hear. Then the quiet question lands, from a cautious investor, a lawyer reviewing the disclosure, or your own gut at eleven at night. If someone asked us to evidence that, could we? Often the honest answer is no. No one wrote down which decisions the AI actually made, on what data, with what oversight. The claim is real-sounding and unprovable, and that combination is what creates exposure.

You have been handed the AI mandate, often without a compliance department behind you. So the claims made upward, to the board and to investors, end up resting on you. This post is about that slice only, the personal risk in the AI line itself, not the governance system around it. It is not legal advice, and where the exposure is real you should take proper counsel. But the discipline that protects you is small.

What is AI washing, and why do regulators treat it as fraud?

AI washing is exaggerating what your AI actually does to investors, claiming capability you cannot back up. In the United States the SEC has brought enforcement actions for exactly this, treating it as a matter for securities law rather than marketing puffery. The mechanism is existing antifraud provisions, including Rule 10b-5. A stretched AI claim then sits in the same legal category as any other material misstatement.

The regulator has been blunt about the standard it expects. As the SEC’s position is summarised in the Harvard Law analysis, if a public company is using AI, that company has to be honest about the role AI plays in its business and not exaggerate it to the point of AI washing. Around 61% of the SEC’s comments on AI disclosures asked companies to clarify how the AI is used and what risks attend it. The message to anyone signing off an AI claim is to have a reasonable basis for it, and to be ready to show that basis.

This detail is US-anchored, and the specific regulator differs for a UK owner-managed business. The principle does not. Any claim about AI, in any market, should rest on evidence the person making it can produce. A UK firm raising investment, reporting to a board, or pitching to an acquirer faces the same logic, whatever the named law on the page.

Why does this land on directors personally?

Director and officer exposure has moved from theoretical to live, driven by how much money now rides on AI. Spending reached $644 billion in 2025, up 76% on the year before, on Gartner figures cited in legal analysis of D&O risk. When that much spend is justified upward with confident claims, the claims themselves become a risk surface, and the insurance behind a director has not yet caught up.

That insurance gap is real and current. The 2026 D&O market is working through AI-related securities suits and AI-washing exposures, with insurers still deciding where these claims belong. As Holland & Knight partner Thomas Bentz put it, there is a lot of confusion and growth in this area because where these claims fit is still being figured out. For a director in an owner-managed business, the cover you assume protects you may have a hole in it precisely where an AI claim goes wrong. Worth checking your own policy wording.

There is a further, sharper argument forming, worth flagging honestly as direction of travel rather than settled law. Legal commentators argue that when an AI system makes a decision, the board is treated as having made it, and that a director cannot defend themselves by pleading they did not understand the technology. A Harvard Law Review analysis raises the prospect of boards being held accountable where insufficient oversight lets AI cause harm. This is emerging argument, not established UK case law, so calibrate accordingly. The defensible position either way is the same, show that appropriate oversight was in place.

What does an audit trail for an AI claim actually look like?

An audit trail for an AI claim is a dated, tamper-evident record of what the system did, on what input, with which version, and what human review sat over it. One vendor working definition calls it an immutable record of AI decisions, inputs, outputs and changes. Stripped of jargon, it answers the question a regulator or buyer will eventually ask. Show me how this decision was reached and who was watching.

The useful components are concrete. The input that went in, the output the system produced, the timestamp, the model version, and whether a human reviewed or overrode the result. None of this is exotic, it is the kind of logging many AI tools can produce if you turn it on and keep it. The discipline is keeping it deliberately, not assuming it exists somewhere by default.

Retention matters, and varies by sector. The same vendor guidance points to financial services typically keeping records for seven years or more and healthcare for a minimum of six, with the firm caveat to check the rules for your own sector rather than guessing. Recognised frameworks help too. The NIST AI Risk Management Framework, with its four functions of map, measure, manage and govern, gives a board a reference point to align oversight to, which strengthens the case that oversight was real.

What should you put in place if you have no compliance function?

If you carry the mandate without a compliance team, the protection is a small discipline rather than a department. Keep a simple record of which AI claims rest on which evidence, so any line in a board paper traces back to something real. Where the AI is making or shaping decisions that matter, note what it did, on what input, and who reviewed it. A maintained document and a habit go a long way.

The single most useful rule is a gate on what goes upward. No AI claim enters a board paper, an investor update, or an annual report unless someone can stand behind it with evidence to hand. That one habit removes the worst of the exposure, because the dangerous claim is the confident, unprovable one, and this gate stops it at the door. It also sharpens the writing, since a line you can evidence is usually more specific than the vague one it replaces.

The payoff is more than defensive. Firms that keep good audit trails save meaningful time when an audit or dispute arrives, and cut the arguments over what an AI-driven decision actually did, because the record settles it. Precise figures get quoted for this, but they trace to single vendor blogs, so treat the gain qualitatively rather than as a promised number. Good records cost a little discipline now and save a lot of scrambling later.

What is well-evidenced here, and what is still forming?

Some of this is solid and some is still forming, and saying which is which is part of being credible in the room. The securities-fraud angle is well-grounded. The SEC has brought real enforcement actions, AI washing is enforced under existing antifraud law, and the honesty standard is on the record. The audit-trail discipline is equally sound. Present both with confidence.

The personal-liability case against directors is the part to handle carefully. It is an emerging line of analysis, argued by legal commentators and explored in law-review work, not a settled body of UK case law you can point to. Presenting it as established precedent would be the same mistake as AI washing, a confident claim the evidence does not yet support. So frame it as direction of travel. The exposure is plausibly growing, the prudent response is to act as though it is real, and where it bites, take advice.

That calibration is itself the move. Distinguishing the well-evidenced from the still-forming is the discipline that keeps an AI claim defensible, and it is how you earn trust with a board that has heard plenty of confident AI talk already. If you want a second pair of eyes on where your own AI claims and oversight stand before the next board paper, book a conversation.

Sources

- Hunton Andrews Kurth (2025). A Practical Guide to Managing AI-Related Directors and Officers Liability. Cited for AI spending reaching $644 billion in 2025, up 76% on 2024 (attributed to Gartner), and the emerging D&O coverage gap. https://www.hunton.com/assets/htmldocuments/Byline/Practical-Guide-to-Managing-AI-Related-Directors-and-Officers-Liability.pdf - The Regulatory Review (2026). Regulating AI Washing. Cited for the SEC bringing enforcement actions against companies exaggerating AI capabilities to investors. https://www.theregreview.org/2026/03/07/seminar-regulating-ai-washing/ - New York State Bar Association (2025). Regulating AI Deception in Financial Markets: How the SEC Can Combat AI Washing. Cited for AI washing being enforced through antifraud provisions including Rule 10b-5. https://nysba.org/regulating-ai-deception-in-financial-markets-how-the-sec-can-combat-ai-washing-through-aggressive-enforcement/ - Harvard Law School Forum on Corporate Governance (2025). SEC comment-letter trend on AI-related disclosures. Cited for the SEC honesty-about-AI quote and that around 61% of comments asked companies to clarify how AI is used and its attendant risks. https://corpgov.law.harvard.edu/2025/01/16/sec-comment-letter-trend-ai-related-disclosures/ - US Securities and Exchange Commission (2026). FY2025 enforcement results press release. Cited for the 456 enforcement actions filed in fiscal year 2025, the research's framing being that many included AI-related components. https://www.sec.gov/newsroom/press-releases/2026-34 - Hinshaw & Culbertson (2025). D&O Liability and Coverage: 2025 Trends, Developments, and Decisions. Cited for the 2026 D&O market grappling with AI-washing exposures and the Thomas Bentz quote that where these claims fit is still being figured out. https://www.hinshawlaw.com/en/insights/in-the-news/dando-liability-and-coverage-2025-trends-developments-and-decisions - Swept AI (2025). The AI Audit Trail. Cited as a working definition of an immutable record of AI decisions, inputs, outputs and changes, plus retention practice of 7+ years in financial services and a minimum of 6 in healthcare. https://www.swept.ai/ai-audit-trail - National Association of Corporate Directors (2025). Implementing AI Governance. Cited for around 25% of boards having formally incorporated AI oversight into committee charters. https://www.nacdonline.org/all-governance/governance-resources/governance-research/director-faqs-and-essentials/implementing-ai-governance/ - Harvard Law Review (2025). Amoral Drift in AI Corporate Governance. Cited as emerging legal analysis suggesting boards could be held accountable where insufficient AI oversight causes harm. https://harvardlawreview.org/print/vol-138/amoral-drift-in-ai-corporate-governance/ - National Institute of Standards and Technology (2023). AI Risk Management Framework (MAP, MEASURE, MANAGE, GOVERN). Cited as a recognised reference point boards align oversight to. https://www.nist.gov/itl/ai-risk-management-framework

Frequently asked questions

What is AI washing and could it really land me in legal trouble?

AI washing is exaggerating what your AI actually does to investors or the market. In the US the SEC has brought enforcement actions treating it as securities fraud under existing antifraud rules, not as harmless marketing. A confident, unprovable AI claim in an investor update or annual report is the same legal category as any other material misstatement. UK regulators differ in the detail, but the principle holds everywhere, any claim about AI should rest on evidence the person making it can produce.

We are a small owner-managed business with no compliance team. What is the minimum I should actually do?

Keep it lightweight and honest. Maintain a simple record of which AI claims rest on which evidence, so any line in a board paper can be traced back to something real. Where the AI is making or shaping decisions, keep a dated note of what it did, on what input, and who reviewed it. Then hold one discipline, no AI claim goes into a board paper or investor update unless someone can stand behind it. That alone removes the worst of the exposure.

Can I defend myself by saying I am not technical and left the AI to the experts?

Legal commentators argue that defence is weakening. The emerging principle is that when an AI system makes a decision, the board is treated as having made it, and a director cannot rely on not understanding the technology. What protects you is showing appropriate oversight was in place, clear accountability, a record of decisions, and human review where it matters. This is direction of travel rather than settled UK case law, so where real exposure exists, take professional advice.

This post is general information and education only, not legal, regulatory, financial, or other professional advice. Regulations evolve, fee benchmarks shift, and every situation is different, so please take qualified professional advice before acting on anything you read here. See the Terms of Use for the full position.

Ready to talk it through?

Book a free 30 minute conversation. No pitch, no pressure, just a useful chat about where AI fits in your business.

Book a conversation

Related reading

If any of this sounds familiar, let's talk.

The next step is a conversation. No pitch, no pressure. Just an honest discussion about where you are and whether I can help.

Book a conversation