IT Governance

AI Governance

How the Business Judgment Rule Applies to AI-Related Decisions and Failures

September 2026 - Directors' duties, Caremark oversight, and comparative safe harbours

The business judgment rule still applies to artificial intelligence the same way it applies to any other corporate decision: it protects informed human judgment, not outcomes and not the machine. What AI changes is how hard it is to show that judgment was actually exercised.

1. What the Rule Actually Protects

In Delaware and most common-law systems, the business judgment rule (BJR) is a presumption that directors and officers acted in good faith, on an informed basis, without a disabling conflict, and with a rational belief that the decision was in the company's interest. Courts will not second-guess a decision that later fails if those conditions are met.

Three limits matter more with AI than with ordinary strategy calls:

  • There must be a judgment. Rubber-stamping a model is not a judgment.
  • The decision-maker must be appropriately informed. Opacity, unverified outputs, and unused available tools can defeat that.
  • The rule does not cover oversight failures. Ignoring known legal, safety, discrimination, or cybersecurity risks from AI is analyzed under Caremark (duty of loyalty / bad faith), not under the BJR.

The practical distinction is this: "the AI was wrong" is not, by itself, a breach. "Nobody owned the decision, nobody tested the system, and red flags were ignored" can be.

2. Three Different AI Problems, Three Different Analyses

2.1 Decisions about AI - adopt, buy, scope, or pause

Choosing to deploy an AI hiring tool, an agentic workflow, or a model in underwriting is a classic business judgment. Cost, speed, competitive risk, and residual error rates are the kind of trade-offs courts leave to boards.

That protection holds if the board:

  • identified material uses and risks (bias, privacy, intellectual property, hallucination, security, and regulatory exposure);
  • asked who owns the system and what human review exists; and
  • recorded why the residual risk was acceptable.

It fails if the board approved a mission-critical system with no reporting line, no risk classification, and no follow-up. That starts to look like abdication, not judgment. Texas's 2025 statutory business judgment rule (Business Organizations Code s 21.419) makes "the model underperformed" even harder to plead, but still leaves room for fraud, knowing illegality, or conscious disregard of red flags.

2.2 Decisions made with AI - the board or management uses the tool

This is where the rule is most strained. Commentators and judges in several jurisdictions now say the same thing: AI can inform a decision; it cannot be the decision.

  • Australia. Chief Justice Bell has said it is "extremely doubtful" that a director who simply adopts an AI bot's recommendation can rely on the statutory business judgment defence in s 180(2) of the Corporations Act. The rationality has to be the director's, and the decision has to be consciously made. A black box can defeat both.
  • Germany. Under s 93 AktG, people are liable, not the machine. An AI error is not treated like a qualified expert report. Unchecked reliance can take the board outside the safe harbour; poor documentation can too, because the board cannot prove it was informed.
  • Delaware. Reliance statutes assume persons - officers, committees, outside experts. A model is not a person. Reliance has to run through humans who validated the output.

Recent Australian examples show how this plays out in practice. In Lanmar (NSWSC 2026), majority directors used ChatGPT for corporate-law strategy against a minority shareholder; the court called it an imprudent adviser and tied that reliance to oppression and duty findings. In ASIC v Bekier (FCA 2026), the court said boards should formally govern AI use rather than "wink at informal shadow use."

The practical test is simple: could the director explain, without pointing at the model, why the company should do this? If the answer is only "the system said so," the BJR likely does not attach.

2.3 AI failures - harm after deployment

When an AI system discriminates in hiring, hallucinates in a customer process, leaks data, or causes operational loss, two layers of liability separate.

The company can be liable in tort, employment, consumer, privacy, or product law whether or not any director was careless. Courts have shown little appetite for "the AI did it." The firm put the system in place. Cases such as the Workday discrimination litigation are about entity responsibility for tools used at scale, not about the business judgment rule.

Directors personally are rarely liable just because the system failed. Personal exposure usually requires either no board-level information system for a mission-critical AI risk (Caremark prong one), or a system that existed plus conscious ignoring of red flags - bias complaints, audit failures, regulator warnings, unexplained drift, or safety incidents (Caremark prong two).

Delaware commentary is consistent that AI does not lower Caremark from bad faith to negligence. A bad outcome, even a large one, is not enough. What does change is the evidence: if the monitoring system is itself a black box, plaintiffs will argue the board never had a real reporting system at all.

A 2026 Boeing Caremark dismissal is a reminder of the other side. Once a board has a monitoring system and is looking at the risk, how it responds is again a business judgment. Courts will not retry the technical call.

3. The Squeeze from Both Sides

The emerging consensus is a paradox, not a one-way "use AI and you are safer" rule.

Over-reliance can destroy the defence: no human reasoning, no conscious decision, no independent assessment.

Under-use can also undermine the "informed" prong. German courts already require boards to exhaust available sources of information. Commentators in Australia, Germany, Korea, and US scholarship argue that as AI becomes a normal analytical tool, deliberately ignoring it - especially when the company already uses it operationally - may look uninformed. Some academic work even floats an "AI judgment rule": in data-heavy decisions, not using available AI support could eventually fail the reasonably-informed test. That is not settled law. It is the direction of travel.

The path boards are being told to take is AI as an aide, not a substitute: use it, interrogate it, and document the human reasons for accepting or rejecting it.

4. What "Informed" Looks Like in an AI Setting

Boards do not need to understand every weight in a model. They do need a process a court can reconstruct:

  • An inventory of material AI uses - hiring, credit, safety, pricing, compliance, and customer-facing agents.
  • A risk class and owner for each material system.
  • Human review where the decision affects legal rights, safety, or significant money.
  • Testing for bias, drift, security, and hallucination before and after go-live.
  • Escalation of incidents and third-party or vendor failures to the board or a committee.
  • Minutes that show the board asked about limits, not just benefits.
  • Prompt and output records when AI is used in a board-level decision. Undocumented use makes the "informed" showing almost impossible, and chatbot logs have already been used as adverse evidence in Delaware litigation.

Without that paper trail, the BJR is hard to invoke even if the directors acted in good faith. With it, a later failure is usually just a bad business outcome.

5. Comparative Snapshot

The doctrine is not identical across jurisdictions, but the pattern is consistent: protection for process, not for abdication.

Jurisdiction Safe harbour AI implication
Delaware, US Common-law BJR; Caremark for oversight (Stone v. Ritter). Adoption decisions protected if informed. Blind reliance and ignored red flags are not. AI does not lower Caremark to negligence.
Texas, US Statutory presumption of good faith (s 21.419, 2025). Ordinary "AI went badly" claims are hard. Conscious disregard, knowing illegality, or abdication can still survive.
Australia Corporations Act s 180(2) BJR; ss 189-190 reliance and delegation. AI is not a "person." Blind adoption is unlikely to be a rational, conscious judgment. Formal AI policies expected (Bekier).
Germany s 93(1) sentence 2 AktG; BGH duty to exhaust available information. People are liable, not the machine. Unchecked AI output is not expert advice. Deliberate non-use of available AI may be uninformed.
EU overlay AI Act risk classification, human oversight, and impact assessment. Does not rewrite fiduciary law, but supplies the governance standard courts may treat as evidence of (un)informed process.

6. Bottom Line

Situation Typical treatment
Board chooses to adopt or reject an AI system after a real process BJR applies.
Director copies an AI recommendation and cannot explain why Often no "judgment" was exercised; BJR does not apply.
Company harmed because a model was wrong Company may be liable. Directors usually are not, absent bad-faith oversight.
Board had no system for a core AI legal or safety risk, or ignored clear red flags Caremark / loyalty analysis, not the BJR.
Board refused to use available AI and made a worse call Growing argument that the decision was uninformed; still fact-specific.

The rule has not been rewritten for AI. What has changed is the proof. Courts will keep deferring to boards that can show they understood the tool's limits and still made the call. They will not defer to boards that outsourced the call to a system no one could explain, or that treated a known AI risk as someone else's problem.

7. Sources and Further Reading

This briefing synthesises commentary and recent authority current as of September 2026. It is not a complete survey of every jurisdiction.

  • KPMG Law, "Business Judgement Rule in the use of AI: how governing bodies are liable for decisions" (19 March 2026) - German s 93 AktG analysis.
  • Hon. Andrew Bell AC, Chief Justice of New South Wales, Harold Ford Memorial Lecture, "Corporate responsibility and directors' duties in the era of Artificial Intelligence" (2026), discussed in Better Boards.
  • Corrs Chambers Westgarth, "AI in the boardroom: judgment, information systems and the modern duty of care" (2026).
  • Hall & Wilcox, "AI governance and directors' duties" (discussing ASIC v Bekier [2026] FCA 196 and Lanmar Pty Ltd (No 2) [2026] NSWSC 800).
  • Hicks Johnson / JD Supra, "AI Oversight and the New Texas Business Judgment Rule" (2026).
  • Harvard Journal of Law & Technology Digest, "AI Comes to the Board Room in a Black Box" (2023).
  • Columbia CLS Blue Sky Blog, "Corporate Oversight in the Age of Artificial Intelligence" (10 March 2026).
  • Oxford Business Law Blog pieces on a "Business Judgment Rule 2.0" and algorithmic Caremark oversight (2026).
  • Helleringer & Moslein, work toward an "AI Judgment Rule," University of Chicago Law Review Online.
  • In re Caremark Int'l Inc. Derivative Litig., 698 A.2d 959 (Del. Ch. 1996); Stone v. Ritter, 911 A.2d 362 (Del. 2006).

This document is a general briefing on how courts and commentators are applying existing fiduciary doctrines to AI. It is not legal advice and should not be relied on as such. Application depends on the governing law of the company, the facts of the decision, and the quality of the board's process and record.

Back to AI Governance