Nickeled & Dimed

Penny for your thoughts?

We are accepting articles on our new email: cnes.ju@gmail.com

Redefining  Director Liability in AI driven Board Decisions under the EU AI Act 2024

By – Ananyaa Verma

Abstract

AI integration in corporate decision making is a widespread contemporary phenomenon. However, out of the integration emerge an unprecedented set of challenges regarding fiduciary responsibility and liability. This article examines the European Union AI Act 2024 which reshaped the legal obligations of directors by imposing enhanced standards of transparency, and data governance. It contends that the Act addresses longstanding accountability gaps in algorithmic decision-making. By analysing Articles 4, 10, and 14 of the EU AI Act alongside the broader European regulatory framework, this article demonstrates that the emerging legal regime recalibrates the standard of care expected of directors and reinforces the imperativeness of human management in lawful corporate governance.

Introduction

AI and its integration in the corporate governance framework has garnered a great deal of attention in recent years. A lot is yet to be realized in terms of its potential, but its transition into the areas of corporate governance and law means that we are at the beginning of the age of artificial intelligence. It is used as a tool to govern companies by automating business processes, analysing data ,and getting insights on recent market trends and, it has started replacing humans in corporate managerial positions and boardrooms. We are now transitioning from a Human Decision-Making regime to an Algorithmic Decision Making one. These advance models are now equipped to screen M&A targets for firms and strengthen their due diligence process. This transition raises a fundamental question, that if Directors and Corporations rely on Black Box algorithms that are opaque in their decision making then have they neglected their fiduciary duty and breached their Duty of Care and the limits of their liability after a decision turns out to be catastrophic. This article proceeds to evaluate the aforementioned concern by first focusing on the governance challenges arising from AI-assisted corporate decision-making followed by an analysis of the obligations imposed under Articles 10 and 14 of the European Union AI Act 2024. The conclusion then assesses the implications of this regulatory framework with respect to directors’ fiduciary duties and liability.

The Tripartite Governance Crisis- Rubber Stamp Risk, Complexity Defence, and the Expertise Trap

When a company employs AI systems to oversee its operations, it has to bear in mind the risks associated with this integration. Members of the board are expected to exhibit vigilance and exercise the standard of care that any prudent manager would. It is ultimately the fiduciary duty of the directors to act in the best interest of the company. Corporate law, at its core, is made of two central concerns. The first, referred to as the Rubber Stamp Risk challenges the directors’ complete reliance on decisions made by AI which means a dereliction on their past. Second, the Complexity Defence means that directors can take the defence of technology being too complex for them to comprehend the actions and repercussions for them to understand or control. This creates a vacuum because if the law requires directors who understand shrink the pool of directors who can take up managerial roles, and if the law does not require sound understanding of AI, then it negates the principle of Duty of Care. This is what legal scholars refer to as the Expertise Trap.

Article 10 of the EU AI Act and Data Governance Framework

The European Union has adopted an ex-ante approach to address this accountability vacuum by implementing the EU AI Act 2024[SM5] . It categorises AI systems based on risks, for corporate boards and directors, it is considered a high-risk AI system. Article 10 of the Act [SM6] mandates that companies must ensure training, validating and testing of data sets to ensure that the outputs reflect real world diversity and are aligned with the specific purpose and intended use. It reduces informational opacity thereby limiting directors’ ability to rely on uncertainty as a defence against liability. It regulates data governance by way of rigorous obligations like documented design choices and advanced proactive mitigation of bias. For directors this translates into a shield from breaching the duty of care since the presence of statutory assurance of data quality and is auditable data completely negates the Complexity Defences and allows meaningful human oversight under Article 14. Compliance with Article 10 strengthens directors’ ability to satisfy the duty of care by ensuring that AI outputs are capable of meaningful scrutiny, thus forth enabling them to make informed decisions and demonstrate reasonable oversight. In sum, Article 10 does not [SM7] merely add to a set of technical standards but gives directors demonstrable and well-reasoned grounds to innovate new technologies while fulfilling their fiduciary duties.

The Primacy of Human Agency- Article 14 of the EU AI Act

 The European Union’s unwavering stance for a human centric governance system influences the liability of directors in AI driven boardrooms. Under both the Global Data Protection Rules (GDPR) and the EU AI Act, fully autonomous directors are impermissible under Article 22(1) of GDPR ,which demonstrates that no individual may be subject to a solely automated decision that produce detrimental legal consequences. Article 14(1) of the EU AI Act emphasises human oversight. The oversight is meant to minimise risks to health, safety, and fundamental rights through output correction, while also pursuing broader objectives of preserving human agency and building trust in AI systems.  Through this Article, the Act aims to ensure that the person supervising has adequate knowledge to comprehend the system’s operation and its limitations. It gives the power to interpret and then intervene whenever necessary. Deployers are required to possess AI literacy as outlined in Article 4. These obligations reinforce the standard of care by requiring directors to exercise informed, active, and independent oversight, preventing the delegation of fiduciary judgment to AI systems operating without meaningful human supervision.

The 2024 Regulatory Convergence

The AI Act does not create a new cause of action; instead, it raises the bar for what qualifies as a reasonable standard of care. Directors now bear an active obligation to substantiate that boardroom AI systems offer full transparency, produce interpretable reports, and clearly convey their limitations. Failing to maintain this awareness exposes directors to personal liability. Though in 2024, the stakes were much higher. Three legal instruments converged simultaneously to make director liability for AI personal: the AI Act. The NIS2 Directive, creating personal-management-body accountability from October 2024, the AI Act with its seven percent of turnover fines and the proposed AI liability directive reversing the burden of proof if harm was caused by AI. Prior to 2024, algorithmic decision-making occupied a regulatory grey area. On 13 March 2024, the architecture collapsed when the AI Act passed in Parliament by a vote of 523 to 46. With an express provision that management bodies are personally liable for the operationalisation of cybersecurity and risk-management measures, NIS2 made its way to national transposition. The practical consequence is that companies and boards cannot outsource AI governance to technical teams and escape liability by claiming a lack of knowledge or ignorance for when systems collapse. The standard of due diligence has transitioned from passive oversight to active, documented supervision, and evidentiary expectations are now codified in black-letter law rather than left to judicial discretion. In amalgamation, these instruments transform fiduciary liability by intertwining demonstrable AI governance and documented oversight with the standard of care. Directors are hence personally liable for lacking oversight than merely deficient technical compliance. The next wave of European regulatory enforcement is not about technologies but boards, and directors who do not build the requisite governance infrastructure today will find that once this reverse burden of proof alights upon them it is almost impossible to claim back.

Conclusion

The algorithmic age requires a complete reconstitution of fiduciary responsibility. This article has shown that the EU’s regulatory architecture, the AI Act, the cybersecurity framework that imports personal management-body responsibility, and the new liability rules flipping the burden of proof for harm caused by AI, doesn’t just amount to increased oversight. This will inevitably destroy the defences that directors have relied upon. Finally, the Rubber Stamp Risk and Complexity Defence that previously allowed boards to treat AI as a technical discipline outside their understanding is now no longer legally viable. More fundamentally, this regulatory convergence recasts AI governance as an element of fiduciary responsibility itself, collapsing the distinction between technical compliance and corporate governance, and signalling a broader doctrinal shift in directors’ standard of care itself. It’s time for directors to flip the script and ask the right questions. It’s no longer about what the algorithm decided but rather how it came to a particular conclusion, on what basis and under whose supervision.

Author’s Bio

Ananyaa Verma is a third-year law student currently pursuing B.COM LL. B from Jindal Global Law School, Sonipat. Her interests lie in corporate law, insolvency law, and contemporary developments in corporate governance.

Image Source: CC-BY-4.0: © European Union 2026– Source: EP

Leave a Reply


Discover more from NICKELED AND DIMED

Subscribe now to keep reading and get access to the full archive.

Continue reading