top of page

Board Oversight of Artificial Intelligence Risk and Algorithmic Decision-Making: Directors’ Duties in the Age of the Black Box

2 hours ago
28 min read

Introduction : Artificial intelligence has shifted, in an incredibly short period, from the company`s laboratory to its balance sheet. Algorithmic systems now decide who gets credit, which job applications get forwarded for human consideration, how the price of insurance premiums is calculated, which transactions raise suspicions, how the stock inventory and chain of supply is organized, and increasingly, how the compliance function itself detects and processes any inaccuracies.  What was once an efficiency in operations tool has now turned into a decision-making tool having a direct impact on consumers, employees, counterparties, and shareholders.


The rate of this migration has exceeded the existing governance framework that is meant to monitor it. Companies' boards of directors, previously bound by fiduciary duties for human management, are now entrusted with decisions regarding a probabilistic, opaque (even to those creating it) system that was sourced from a third party with a liability waiver and is capable of making thousands of consequential decisions without human intervention. According to the Reserve Bank of India’s survey of regulated firms, issued along with the FREE-AI Committee Report in August 2025, approximately 20% of firms surveyed have already implemented AI in real-life settings and another 67% are currently working on applications of AI for customer care, sales, risk assessment, and cybersecurity.


This raises the question of law that, at first sight, seems simple, but is, in fact, very complex in terms of legal doctrine. What is a director supposed to do about artificial intelligence, and what happens if she does nothing? In fact, the answer requires one to distinguish the duty of care, the duty of oversight and good faith, mandatory provisions of law regulating risk management under the corporate and securities law, and the duty to continuously disclose information, as well as a newly emerging area of sectoral regulation which clearly requires board-approved policies on AI. This blog provides a critical analysis of this question. It examines the legal and regulatory framework in India as well as in a comparative perspective, outlines the judicial construction of liability for oversight, identifies the cases in which AI malfunction becomes a breach of governance or disclosure violation, evaluates the role of risk committees and internal audit and concludes with a practical board agenda for overseeing AI that directors can implement.


Legal Provisions


A. The Companies Act, 2013 (India)


For the first time in Indian statutory law, companies’ responsibilities were laid down by the Companies Act of 2013. Section 166(3) of the Act mandates the director to carry out her duties with adequate care, skill, and diligence, and to apply her independent judgment. Under Section 166(2), the director is required to act in good faith with a view to promoting the activities of the company, benefiting its members in general, and acting in the best interest of the company, its employees, its shareholders, and society, including environmental protection; this is a definition that is much wider than shareholder primacy in Delaware law and which possibly includes the algorithmic harm of consumers and employees.


Risk management is taken explicitly into consideration. Under Section 134(3)(n), the Board's Report must contain a statement regarding the introduction of the risk management policy for the company, including identification of risk factors that, according to the Board, might jeopardise the company's survival. Section 134(5)(e) prescribes that the directors of a publicly traded company should declare in the Directors’ Responsibility Statement that the company has implemented the internal financial control system. Correspondingly, Section 143(3)(i) has as its goal the requirement for the statutory auditor to give his opinion about the efficiency of internal financial control operations.


According to section 177(4)(vii), the Audit Committee is given the responsibility to assess internal financial control systems and risk management. Section 138 along with Rule 13 of the Companies (Accounts) Rules, 2014 prescribes the need for internal audit for specific companies and gives authority to the audit committee to organise the procedures involved in the audit, including the frequency of audit and the processes used. Schedule IV, along with Section 149(8), gives independent directors the responsibility of satisfaction on the reliability of the financial data and the financial control systems and risk management processes.


B. SEBI (Listing Obligations and Disclosure Requirements) Regulations, 2015


For a listed business, Regulation 4(2)(f)(ii) assigns to the board the duty of overseeing and directing the corporate strategy, risk policy and annual budgets, as well as safeguarding the organization’s accounting system and financial reporting, including an independent auditing system and adequate control methods, especially risk management systems. Regulation 17(9) obliges the board to establish methods for informing its members regarding the procedure of risk assessment and mitigation, and revisiting these methods regularly to make sure that the team of executive managers manages risk in the defined manner.


According to Regulation 21, a Risk Management Committee should be established in the top 1,000 companies on the basis of their market capitalisation. The committee must be able to handle any kind of cybersecurity risk, which is the only type of technology risk mentioned in the provision. This means all algorithmic and model risks will surely fall under the purview of the committee. The committee must hold at least two meetings in one financial year, while the board has to outline the duties and obligations of the committee and may authorise monitoring and verification of the risk management plan by the committee. Regulation 30 in combination with Part A of Schedule III requires disclosure of significant events. In addition, the quantitative and qualitative materiality limitations put forth in the recently introduced changes in the year 2023 incorporate algorithmic failures and any measures brought against any organisation.


C. Sectoral Regulation: RBI, SEBI and the Financial Sector


The FREE-AI Committee was set up by the Reserve Bank of India in December 2024 and published its report on 13 August 2025. This report contains the seven guiding principles elaborated in «Sutras», allowing for such ideas as trust is the basis, people first, innovation prevails over restraint, fairness and equity, accountability, understandable by design, as well as security and sustainability. The report presents 26 recommendations grouped into six pillars, which include Infrastructure, Policy, Capacity, Governance, Protection and Assurance. Among other things, the report recommends that regulated entities devise AI policies approved by their boards and including governance, lifecycle management, risk control, and liability of third parties; AI disclosure rules be introduced in the annual report; AI-related incidents be reported; and capacity building of boards and regulators take place.


SEBI has progressed along a similar path. The SEBI (Intermediaries) (Amendment) Regulations, 2025, enacted on February 10, 2025, include a special component on artificial intelligence stipulating that every regulated entity that uses any AI or ML tools, whether created within or obtained from outside sources, will assume full responsibility for the protection of the privacy, safety, and validity of both the investors’ and the stakeholders’ information and the results produced by utilising these means and equipment. The Guidelines on Responsible Use of AI/ML in Indian Securities Markets Consultation Paper issued on June 20, 2025, contains several propositions comprising accountability of the top management under the established governance policies.


D. National AI Policy and Data Protection


The Government of India (through the Ministry of Electronics and Information Technology) published the India AI Governance Guidelines on 5 November 2025, providing recommendations on six pillars spanning three domains: Enablement (Infrastructure and Capacity Building), Regulation (policy and regulation, risk mitigation) and Oversight (accountability and institutions). The Guidelines are voluntary in nature but provide a normative standard against which the reasonableness of the actions taken by the board can be judged.10 Internationally, the OECD’s Recommendation of the Council on Artificial Intelligence, though non-binding, sets out principles of transparency, robustness and accountability that supply a comparable soft-law benchmark for boards.


The Digital Personal Data Protection Act of 2023 provides a strong framework where AI technologies handle personal information. In this context, Part 8 establishes the duty of Data Fiduciaries to apply the necessary organisational and technical measures for ensuring proper compliance with the Act and making certain that personal information used for decision-making is accurate, complete and consistent. Part 10 places certain additional requirements on Data Fiduciaries, including the appointment of a DPO, independent auditors of data, and carrying out Data Protection Impact Assessments. The DPDP Rules of 2025, which were published on 13 November 2025, set out the sequence of the implementation of those obligations.


E. Comparative Frameworks


Regulation (EU) 2024/1689, also known as the Artificial Intelligence Act, requires firms with operations in Europe to comply with certain requirements that directly affect the activities of their boards. The duty to establish, implement, document, and maintain the risk management system throughout the life cycle of high-risk AI system follows from Article 9. Article 14 sets forth the requirement for effective overseeing by persons who have skills, training, and authority to intervene. Article 17 establishes the obligation to set up a quality management system. Article 26 creates new obligations for deployers, such as the obligation to appoint appropriately qualified people to carry out oversight and monitor the operations of the AI system. The responsibility to conduct bias audits for automated employment decision-making tools is specified in NYC Local Law 144 of 2021 and the new Colorado AI Act (SB 24-205) establishes the obligation to act with reasonable care while using high-risk AI systems.


Legal Analysis


A. From the Duty of Care to the Duty of Oversight


The basis of the concept of board oversight liability can be found in the decision of the Delaware Court of Chancery in the case of In re Caremark International Inc. Derivative Litigation. Chancellor Allen ruled that directors may become liable when they do not introduce any means of reporting and controlling information, or if they put such a means into practice but neglect to oversee its functioning. Such conditions are strict: the only case of proper oversight failure can be deemed good faith absence.


The doctrine was taken from the field of the duty of care and moved to the duty of loyalty in the case of Stone v. Ritter, according to which the lack of good faith is only a minor element of the duty of loyalty. This means that one cannot relinquish liability through the use of a charter provision in accordance with Section 102(b)(7) of the Delaware General Corporation Law.


In regard to artificial intelligence, the Caremark model leads to a proposition which is simple to articulate but fraught with challenges in executing. Caremark does not require directors to have knowledge of backpropagation, transformer models or mathematical principles of gradient descent. It requires a good faith effort to create systems that are suitable, validated and supervised in all their known opacity and limitations. The inquiry is procedural rather than technological. The question of a court is not whether the directors have understood the model but whether an adequate system was put in place to inform the directors when the model starts functioning improperly.


B. Mission-Critical Risk: Is Artificial Intelligence Mission-Critical?


Marchand v. Barnhill has clarified the question. The defendant in the present case is the board of directors of Blue Bell Creameries, the company responsible for an outbreak of listeria that killed three people. In this situation, it was determined that if a company works under strict state regulations and is exposed to the risk that is crucial for its business, like food safety, the company’s board of directors has to make an effort to set up a system of monitoring and reporting at the board level for the identified risk. In the case, it was found out that the directors did not have a food safety committee, did not have a procedure requiring the management to inform them about their food safety issues, and neither planned discussions nor recorded any on the issue, which brings us to conclusion that on the basis of pleadings provided by the plaintiff, the board has done absolutely nothing about it.


In re The Boeing Co. Derivative Litigation, the same reasoning was applied in the matter of aeroplane safety after two 737 MAX crashes took place, upholding the validity of a Caremark claim against the board because there was no dedicated committee responsible for safety measures, no consistent procedure of gathering safety information, and safety was treated merely as part of the operational and audit agenda. In re Clovis Oncology, Inc. Derivative Litigation made it clear that alerts regarding a no-go clinical trial, which were turned a blind eye to, are sufficient to raise the Caremark claim.


The transfer to AI in principle is quite simple but rather difficult in practice. For a digital lending company, whose models make all credit decisions; for an insurance company that has automated its claims handling and underwriting process; for a broker that relies solely on algorithms in routing orders and surveillance; and for a medical institution that uses diagnostic AI, AI risk is embedded within their activities. Thus, the AI risk has vital significance for these kinds of businesses, and having no reporting channel, no committee agenda, and no notes taken on the efficiency of the model exposes the board.


It bears emphasis that, as at the date of writing, no Delaware court has adjudicated a Caremark claim founded on an alleged failure to oversee artificial intelligence risk. The doctrinal building blocks are firmly in place; the first fact pattern has yet to arrive in a reported decision. Prudent boards should not draw comfort from that silence. The Court of Chancery declined to sustain the Caremark claim in Construction Industry Labourers Pension Fund v. Bingle, arising from the SolarWinds cybersecurity breach, observing that the board had not utterly failed and that cybersecurity, however serious, was not pleaded as mission-critical in the relevant sense but the decision turned on the sufficiency of the pleading rather than on any principled exclusion of technology risk from oversight doctrine.


It is important to note that no Delaware court has yet ruled on any Caremark claim based on the failure of the board to do its duty in relation to the risk of artificial intelligence. The ingredients of a valid claim are there; a real case has not yet surfaced. A wise corporate board should not feel reassured by this fact. While the court in Construction Industry Labourers Pension Fund v. Bingle did not grant the plaintiffs’ claim because the board had not been entirely negligent and the court ruled that a technology risk issue is not critical for determining the culpability of the board, the case was decided on the technical issue of allegations rather than the question of whether the board could avoid accountability in cases involving technology risk.


C. Officer-Level Oversight and the Limits of Delegation


In the matter of re McDonald’s Corporation Stockholder Derivative Litigation, the corporate officers’ duty of oversight was broadened to stipulate that the officers have a responsibility corresponding to their domain of operations. This is important for AI governance. The Chief Technology Officer (CTO), the Chief Risk Officer (CRO), the Chief Compliance Officer (CCO), as well as the Chief AI Officer (CAIO) have obligations of oversight in their specific areas. Therefore, the board needs to verify that these areas have been properly defined, the way the model owner reports to the officer, which in its turn reports to the committee that reports to the board.


Reliance is allowed, but is not unlimited. Section 141(e) of the Delaware General Corporation Law protects directors who rely in good faith on documents, reports and expert opinions that were chosen with due diligence. The Indian equivalent can be found in the exception to Section 149(12) and in the rule that an independent director can be held liable only for acts of commission or omission that are done with her knowledge, because of decisions made at the board meetings and done with her consent or collegiality and where she is not diligent in performing her duties. In both cases, the important element is due diligence. In Delaware law, there is provision for bona fide reliance on competent professionals; however, there is no blind reliance allowed.


D. The Indian Judicial Position on Director Accountability


The courts in India have brought out a definitive interpretation of the concept of director’s duty which can very much be applied in the context of algorithms. In the case of N. Narayanan vs. Adjudicating Officer, SEBI, the Supreme Court has determined that directors, particularly independent directors and non-executive directors, assume a fiduciary role, which entails responsibility towards the firm and its shareholders. The Supreme Court stressed that directors cannot simply close their eyes to the developments in the firm and view business as a private affair of a few people working for the firm. The Court said that directors should be informed and raise queries, thereby establishing the fact that the act of allowing misleading accounts to be published would not absolve them from their responsibility.


This is an ancient principle in Indian corporate law. It was held in the case of Official Liquidator v. P.A. Tendolkar by the Supreme Court that a director may be so positioned and have been so intimately and for such a long time involved with the management of the firm that he could be considered not only aware of, but also responsible for the wrongdoing in the conduct of company’s operations, regardless of the fact that no concrete breach of law was committed by him personally.


The case of the Securities and Exchange Board of India v. Kishore R. Ajmera brought the needed clarity regarding the proof standards in relation to market conduct matters. The Supreme Court stated that one may rightfully arrive at a conclusion based on the various circumstances and facts surrounding an issue, whereby the pertinent test would be that of an ordinary prudent person. The inference-based approach brings about a requirement for boards to argue very convincingly in case of presence of any of the signs of systematic failure of a given model, such as clusters of complaints, rejection of data outside the norm, unfounded negative audit results, etc.


E. Algorithmic Decision-Making Before the Courts


The involvement of the judiciary in the process of decision-making through algorithms is enough to provide the necessary content that boards of directors must supervise. In the case of Samir Agrawal v. Competition Commission of India, the Supreme Court undertook an inquiry into the accusation of cab companies fixing prices through pricing algorithms as per Section 3 of the Competition Act, 2002. Eventually, although the Court dismissed the appeal, it broadened the scope of locus standi for complainants under the Act and left open the issue of whether algorithmic collusion would take place a perennial worry for any board whose business relies on dynamic pricing.


Mobley vs. Workday, Inc., is the most important algorithmic liability case proceeding in any court right now, pending in the United States District Court for the Northern District of California. The plaintiff claims that Workday’s AI-based screening tools discriminated against him while considering some characteristics such as race, age and disability. The trial court refused to dismiss the case, stating that the complaint contains sufficient information describing Workday acting as an agent of the client-employer, thus allowing it to be classified as an ‘employer’ under the law. Moreover, the court provided preliminary lawsuit status for the age discrimination case in May 2025, ordered the vendor to disclose the names of the employers using its AI screening solutions, rejected the claims about non-coverage of job seekers by the anti-discrimination law provisions and in May 2026 ruled on the vendor’s liability to present its bias test results.


Comparative jurisprudence allows for the making of more cautionary points. In Bates v. Post Office Ltd (No. 6), the Horizon Issues case heard in the English High Court, it was shown how institutions failed to supervise an automated system correctly. In that case, Fraser J found the Horizon system to have ‘serious bugs, faults and errors’ and noted that the Post Office, for a number of years, claimed its software would work perfectly, taking to trial people who worked in post offices according to results from that faulty system. In the case of R (Bridges) v. Chief Constable of South Wales Police, the Court of Appeal ruled that using automated facial recognition systems was illegal due to the lack of the appropriate legal framework, lack of a sufficient data protection impact assessment and failure to comply with the equality duty. Lastly, in NJCM v. The Netherlands case, The Hague District Court found the SyRI risk indication system to violate Article 8 of the European Convention on Human Rights, noting the incommensurability of the system.


In America, State v. Loomis approved the employment of a proprietary recidivism risk prediction tool in the sentencing process but stipulated that the method used comes along with a formal notification of the restrictions, which include the fact that the method is proprietary and the tool raises concerns regarding possible disparate effects. In Houston Federation of Teachers, Local 2415 v.Houston Independent School District, it was held that the utilisation of the proprietary and unverifiable value-added algorithm to dismiss teachers was the basis for procedural due process.


F. When an AI Failure Becomes a Governance Breach


Not all modelling errors are leaders in governance errors. AI systems, by design, operate under a probabilistic framework, meaning that they have to have a non-zero error rate. The analytical issue is to define when the algorithmic failure turns from being an operational issue into a breach of fiduciary duty. Four indicators may be distinguished.


  • Absence of architecture. The corporation utilises AI in an essential function without an AI policy approved by the board, a model inventory, the authority assigned to a committee, an escalation procedure, or discussions at board meetings. This is the Marchand fact pattern put in algorithmic terms, and is the most dangerous situation for the board.

  • Conscious disregard of red flags. The board or authorised personnel receives warning signals about systemic failures—the negative result of an internal audit on model validation, an observation from a regulatory inspection, many consumer complaints, a visible disparity in results based on the protected characteristic, or an alert from a service provider—and does not act or takes only cosmetic actions and does not follow them up.

  • Knowing non-compliance. The company implements a system in a situation where a requirement of law is not fulfilled no discrimination audit where it is necessary, no human supervision based on the requirement of law, no impact assessment based on data protection laws, and processing of personal information without an appropriate legal basis.

  • Representation of capabilities. The business disclosed public information regarding its AI competencies which are not substantiated by the technology itself. This falls under the ‘AI washing’ category and raises a technology governance issue related to securities law.


G. AI Failures as Disclosure Events


The dimension of disclosure warrants specialized attention because it changes an internal governance issue into an external wrongdoing. The Securities and Exchange Commission began taking action against AI-related inaccuracies in March of 2024, resolving concurrent cases against two advisory firms, Delphia (USA) Inc. and Global Predictions Inc., for false and misleading information related to their involvement with artificial intelligence. This was done with civil fines of $225,000 and $175,000 in accordance with § 206(2) and § 206(4) of Investment Advisers Act of 1940, the Marketing Rule as well as the Compliance Rule. In January of 2025, the Commission took the same position with respect to a public reporting company, namely, Presto Automation Inc., where the misleading statements were about the features of its voice AI tool, including referring to third-party unidentified speech recognisers as its own or disclosing possible automation where significant human involvement is still present.


More important than each specific penalty is the trend. Regulation has shifted from professional advisers to private companies that bear the same criminal risk as any publicly traded reporting company. The SEC's Investor Advisory Committee recommended in December 2025 that firms report on their definitions of artificial intelligence, describe procedures of board oversight for the deployment of AI, and explain the methods of AI use and its impact where this information is important. Proxy advisory firms have followed suit, as Glass Lewis integrated its expectations of AI use, risk, and governance disclosure into its policy guidelines for 2026.


In the context of Indian companies listed on the stock exchange, Regulation 30 of the LODR Regulations and Schedule III create obligations that require disclosure in case of a material algorithmic failure. Material algorithmic failures include such events as systemic mispricing, regulatory order to suspend a model being used, class action seeking damages in connection to alleged algorithmic discrimination, a significant data leak occurring due to an AI pipeline failure, etc. Similarly, statements made in the Board Report, Management Discussion and Analysis, and Business Responsibility and Sustainability Report pertaining to the company's AI may be subject to scrutiny. Indian version of AI washing would also entail violations of the prohibition on fraudulent and unfair trade practices, and accuracy obligations.


H. Risk Committees, Internal Audit and External Assurance


The board's institutional framework comprises a three-lines model, which requires the model to be tailored to algorithmic systems at every level. The first line refers to the business function owner of the model, which must ensure that the model inventory is accurate and comprehensive, including shadow deployments and vendor features that are not visible to the central IT. The model inventory should include the model's purpose, population affected, materiality of the decision, data sources, the design of the human component, date of last validation, and the person in charge.


The second line is responsible for risk and compliance, requiring that independent model validation is performed apart from the development team, covering conceptual soundness, data quality and lineage, outcome analysis in regard to protected characteristics, explainability, resistance to drift and adversarial inputs, and adequacy of fallback strategies. The committee on risk management established under Regulation 21 needs to be provided with a regular report on the models' risk, not just annual tech updates.


The internal audit within the third line of internal auditing, as per Section 138, needs to have the ability to conduct auditing of algorithmic systems, either internally or through hiring trained personnel. This is a significant issue since basic internal auditing skills do not accommodate statistical validation. The FREE-AI Committee also suggests that internal auditing, as well as external auditing, should be strengthened. It further mandates developing a form of auditing specifically for AI technologies. This means that when such competence is not available in-house, the Audit Committee needs to get third-party assurance, rather than conduct the internal audit nominally. External auditing is understood as the way. External auditing exists in three forms: independent auditing of bias in AI systems, which is required by the New York local law; obtaining conformity assessment as well as quality management system certification, which is needed according to the EU legislation; and certification against common quality standards such as the ISO/IEC 42001 standard or the NIST Risk Management Framework. If the board orders an external assessment of its AI system and receives the results of the audits by itself, then the necessary legal documentation will be created for this board.


Relevant Case Laws


In re Caremark International Inc. Derivative Litigation, 698 A.2d 959 (Del. Ch. 1996): The duty of oversight is properly articulated in this case. Chancellor Allen reasoned that directors have a fiduciary duty to act in good faith to set up a system of information and reporting in the corporation. Furthermore, only "sustained or systematic failure" of fulfilling this duty will lead to breach of this requirement. Thus, the decision provides the doctrinal basis for all contemporary claims against boards for failing to oversee an important corporate system, including algorithmic systems.


Stone v. Ritter, 911 A.2d 362 (Del. 2006): The Delaware Supreme Court reaffirmed the Caremark rule and placed it in the realm of loyalty, ruling that "failure to act in good faith is part of loyalty" The consequence is that breaches of duty of oversight can indeed be seen as exculpatory under Section 102(b)(7) of the charter.


In the case of the Boeing Derivative Suit, 2021 WL 4059934, it was found that there were a number of problems with the company’s compliance program related to the 737 MAX crashes, including the fact that the board did not have a committee responsible for safety issues, did not hold committees regularly accountable for safety, and reduced the safety issue to monitoring of routine operations of the company. It is clear from this case that merely identifying high-tech risks in the process of doing business does not remove the need for the board to collect and record any evidence of oversight, which is useful for the boards of modern companies that do not monitor AI risks after incorporating them into overall IT updates.


In the Clovis Oncology Derivative case, 2019 WL 4850188, the court ruled that if the board is presented with issues that could harm the company related to regulatory questions it is aware of, then the second requirement for the Caremark claim has indeed been satisfied. It can be concluded from this case that having in place a monitoring system cannot serve as an excuse for violations of the oversight duties if the board is ignoring data from such systems.


Construction Industry Laborers Pension Fund v. Bingle, 2022 WL 4102492 (Del. Ch. Sept. 6, 2022): In this case related to the SolarWinds cyber attack, the Chancery Court dismissed the Caremark claim because it found that the board did not totally fail in exercising its oversight duties and that the complainants did not sufficiently allege careless disregard. This decision demonstrates the high standards of pleading but the Court's reasoning was based on the adequacy of the evidence presented and not on any questions of the application of the oversight doctrine to technology risks.


N. Narayanan v. Adjudicating Officer, SEBI, (2013) 12 SCC 152 (India): The Supreme Court decided that directors, especially lay and help directors, occupy the fiduciary sector and thus have the duties of care that should be executed accordingly. This ruling is the leading authority in India considering that passive directorship does not become an excuse and also applies to using algorithms without asking questions.


The Supreme Court of India, in Official Liquidator v. P.A. Tendolkar, (1973) 1 SCC 602, held that directors are responsible for what’s happening within the company and that they can be liable for any losses caused to the company due to their inaction. This established the principle of willful blindness in Indian jurisdiction, which is similar to the doctrine of conscious disregard from Caremark.


The Supreme Court of India in Securities and Exchange Board of India v. Kishore R. Ajmera, (2016) 6 SCC 368, ruled that findings in securities matters can be made based on the inferences from all the circumstances faced, with the requirement that the ordinary prudent person would form the same inference from the facts of the case. This inference-based approach renders it virtually impossible for directors to deny knowledge of what was reasonably possible to infer from the pattern of failures of algorithm models.


The Supreme Court in Samir Agrawal v. Competition Commission of India, (2021) 3 SCC 136, dealt with the question of whether the pricing algorithms used by cab aggregators amount to price collusion and was dismissed in appeal. However, the Court broadened the standing of the informers and did not conclude on the main issue regarding algorithmic collusion.


Mobley v. Workday, Inc., No. 3:23-cv-00770-RFL (N.D. Cal.) (United States): A collective and class action suit in progress wherein the use of AI-based applicant screening technologies is claimed to discriminate among job seekers by race, age, and disability. The court allowed the claims to stand based on the finding that the vendors were acting as agents of their employer-clients and thus making them employers in the eyes of Title VII, ADEA, and ADA; certified the collective in May 2025; ordered the disclosure of employer client lists; and discussed the discoverability of the vendor’s bias-testing results. The ground-breaking case clarified that procurement does not absolve from liability and both the vendor and its deploying employer are covered by litigation.


Bates v. Post Office Ltd (No. 6: Horizon Issues) [2019] EWHC 3408 (QB) (United Kingdom): Fraser J found that the Horizon accounting system was plagued by defects, bugs, and errors, and that Post Office Ltd claimed reliability of its system while acting on the outcomes obtained through it against the sub-postmasters. This ruling is considered the most complete judicial account of the institutional failure of control of an automated decision system, and the ultimate warning on the governance.


State v. Loomis, 881 N.W.2d 749 (Wis. 2016): The Wisconsin Supreme Court provided its ruling regarding the use of a proprietary recidivism risk assessment in sentencing, stating that the use of such findings is warranted given that the limitations of the recidivism risk assessment will be disclosed in writing. The trade secret nature of the methodology and that studies question the disparate impact of such systems is mentioned. The decision points to the problem of trade secret secrecy in governance and due process rather than only in the commercial sphere.


Houston Federation of Teachers, Local 2415 v. Houston Independent School District, 251 F. Supp. 3d 1168 (S.D. Tex. 2017): The lower court provided that the claim over using a proprietary and non-auditable value-added algorithm for terminating the employment of teachers amounts to a violation of procedural due process, as the trade secret claim of the vendor deprives the affected persons of the right to verify or contest their results. The case creates the requirement of contestability in algorithmic decision-making.


Practical Implications


The practical burden of the foregoing analysis falls on four constituencies. From the vantage point of board members, there exists an opportunity for them to uplift AI from the greatness of being a part of the occasional management report, to its rightful and available position of being a regulated risk type, with an owner identified, a committee charter in place, an escalation implemented and minutes of meetings recorded. The most important defensive move for any board is to generate evidence of oversight process: board as a body and separate committees should maintain records of the decisions made, questions raised and issues discussed.


From the perspective of corporate officers and executives, there may be an inescapable implication associated with McDonald's commitment to supervision; heads of departments will have to leverage the board in order not to fall into liability. It would be critical to appoint the model owner, validation to be performed independently from the development process and every incident related to the model to be duly reported.


For auditors, provision of algorithmic assurance capability is in demand but less accessible. The Audit Committee has to treat even a nominal AI audit that isn’t statistically competent as worse than the absence of an audit because it still creates false assurance records that can serve warning sign for stakeholders that there was little oversight exercised over the process.

For the regulatory compliance office, it is all about legal framework: vendor contracts must ensure audit rights, disclose tests for bias, notify incidents, indemnify, and allow for obtaining necessary documentation required to fulfill the regulatory requirements of the company. Mobley shows that a vendor’s internal bias-testing can become the main part of litigation and it leaves a company that hasn’t seen it at any point in time at a big loss because of lack of transparency.


A Board AI-Oversight Agenda: A Practical Template


The following agenda is offered as an operational starting point. It is structured to map onto the statutory obligations discussed above and to generate the documentary record that oversight doctrine rewards.


Agenda Item

Board Question

Owner

Frequency / Anchor

AI Policy

Is there a board-approved AI policy covering governance, lifecycle, risk controls, human oversight and vendor liability? When was it last reviewed?

Board / RMC

Annual approval; s. 134(3)(n); FREE-AI

Model Inventory

Do we have a complete inventory of every AI system in use, including embedded vendor features and shadow deployments, classified by materiality of decision and population affected?

CTO / CRO

Quarterly

Mission-Critical Mapping

Which AI systems are intrinsically critical to our regulated business? Does each have a dedicated board-level reporting channel?

Board

Annual; Marchand test

Model Validation

Has each material model been independently validated for conceptual soundness, data lineage, drift, robustness and outcome disparity? Who performed the validation and were they independent of development?

Risk / 2nd line

Quarterly to RMC; Reg. 21

Fairness & Bias

What outcome testing has been conducted across protected characteristics? What disparities were found and what was done? Is a bias audit legally required in any market we serve?

CCO / External auditor

Annual; NYC LL 144; Colorado AIA

Human Oversight

For each consequential decision, who is the human with the competence and the authority to override the system? Is override actually exercised, and is it logged?

Business head

Semi-annual; EU AI Act Arts. 14, 26

Contestability

Can an affected individual obtain an explanation and challenge an adverse algorithmic decision? What is the grievance volume and resolution record?

CCO / Grievance officer

Quarterly; DPDP Act ss. 8, 13

Third-Party Risk

Do vendor contracts secure audit rights, bias-testing disclosure, incident notification and indemnity? Have we actually exercised those rights?

Legal / Procurement

At onboarding and annually

Incident Register

What AI incidents occurred this period, what was their root cause, what remediation followed, and did any cross the materiality threshold for disclosure?

CRO

Every meeting; LODR Reg. 30

Disclosure Integrity

Can every public statement about our AI capabilities be substantiated by the underlying technology? Who verified it?

CFO / Company Secretary

Before each filing; anti-AI-washing

Assurance

Does internal audit possess the competence to audit algorithmic systems? If not, what external assurance has been commissioned, and did the board receive the findings unfiltered?

Audit Committee

Annual; ss. 138, 177(4)(vii)

Board Competence

Does any director possess the capacity to interrogate model risk? What training has been provided this year?

Nomination & Remuneration Committee

Annual; Sch. IV


Conclusion


Artificial intelligence does not change the legal standard for board oversight; rather, it changes the conditions under which that standard must be satisfied. The principles put forth in Caremark and Stone v. Ritter, which were further developed in Marchand and Boeing, and which can be seen in the Indian jurisdiction of Tendolkar and N. Narayanan, are still based on the concept of information: the systems must be built in such a way that they can detect risks, and then take proper action after the warning signals are received. What these algorithmic systems do is to be on both sides of the information process simultaneously: AI increasingly takes the role of monitoring for risks, while at the same time being a source of risks itself. Corporate monitoring is no longer done by humans based on visible red flags, but by algorithms making decisions about which risks to detect.


The response of legal in India is now distributed in various elements rather than brought under one umbrella. The Companies Act, 2013 has the sections 134(3)(n) and 166(3), LODR Regulations 17(9), 21 and 30, AI chapter has been included in SEBI (Intermediaries) Regulations, the recommendations from RBI FREE-AI Committee and MeitY India AI Governance Guidelines and obligations of Digital Personal Data Protection Act, 2023 comprise the effective framework at hand. What is mainly lacking here is a court judgment regarding how the directors' actions are evaluated against an error caused by an algorithm. The absence will not be for longer. The amount of AI implementation across Indian financial services, soon will become a matter of timing instead of possibility, given how the regulators use advisory recommendations made in the sector to impose supervisory norms, plus the legislation flow in countries such as the US.


The three reforms are sure to be valuable in enhancing the state of affairs. At first, the Ministry of Corporate Affairs should issue clarifications on the issue of the risk management policy under Section 134(3)(n) and make it clear that model risk and algorithmic risk are also referenced there. The second reform should be initiated by SEBI, which should implement the chapter on AI accountability that is currently used in transactions between intermediaries in the LODR framework. The third reform is that the Institute of Chartered Accountants of India should formulate a standard for algorithmic assurance, since the presence of this standard is vital in ensuring the execution of the statutory internal audit requirements under Section 138.

Until those changes take shape, the protection a director has is only limited to her own capacity and ability. One can ask questions, record questions, record the answers to the questions, record the outcome of the answers provided by the board, and where there was any negative outcome, record what has been done about it. The idea behind the oversight doctrine is that it does not call for individual directors to get it right, it calls for them to be active in their duty. This still holds today, during the era of the black box when they do have something that allows them to save themselves from suffering the consequences of a system they did not care to understand.


Author: Dhanvi Choubey in case of any queries please contact/write back to us via email to content@khuranaandkhurana.com or at  Khurana & Khurana, Advocates and IP Attorney


Endnotes


  1. Reserve Bank of India, Report of the Committee on Framework for Responsible and Ethical Enablement of Artificial Intelligence (FREE-AI) (13 August 2025), Executive Summary and Recommendations.

  2. Companies Act, 2013, ss. 166(2), 166(3) (India).

  3. Umakanth Varottil, ‘Directors’ Duties and Liabilities under the Companies Act, 2013’ in Corporate Governance in India: Change and Continuity (Oxford University Press, 2017).

  4. Companies Act, 2013, ss. 134(3)(n), 134(5)(e), 143(3)(i) (India).

  5. Companies Act, 2013, ss. 138, 149(8), 177(4)(vii) and Schedule IV, Part II (India); Companies (Accounts) Rules, 2014, r. 13.

  6. SEBI (Listing Obligations and Disclosure Requirements) Regulations, 2015, regs. 4(2)(f)(ii), 17(9) (India).

  7. SEBI (Listing Obligations and Disclosure Requirements) Regulations, 2015, regs. 21, 30 and Schedule III, Part A (India), as amended by the SEBI (LODR) (Second Amendment) Regulations, 2023.

  8. RBI FREE-AI Committee Report (13 August 2025), Seven Sutras; six pillars (Infrastructure, Policy, Capacity, Governance, Protection, Assurance); 26 recommendations, including board-approved AI policies (illustrative outline at Annex V), AI disclosures in annual reports, AI incident reporting and audit frameworks.

  9. SEBI (Intermediaries) (Amendment) Regulations, 2025, notified 10 February 2025, inserting Chapter on Usage of Artificial Intelligence (Regulation 16C); SEBI, Consultation Paper on Guidelines for Responsible Usage of AI/ML in Indian Securities Markets (20 June 2025).

  10. Ministry of Electronics and Information Technology, Government of India, India AI Governance Guidelines: Enabling Safe and Trusted AI Innovation (5 November 2025).

  11.  Organisation for Economic Co-operation and Development, Recommendation of the Council on Artificial Intelligence, OECD/LEGAL/0449 (adopted 22 May 2019, amended 3 May 2024).

  12. Digital Personal Data Protection Act, 2023, ss. 8, 10 (India); Digital Personal Data Protection Rules, 2025, notified 13 November 2025.

  13. Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act), arts. 9, 14, 17, 26; New York City Local Law 144 of 2021 (Automated Employment Decision Tools), effective 5 July 2023; Colorado Artificial Intelligence Act, SB 24-205 (2024).

  14. In re Caremark International Inc. Derivative Litigation, 698 A.2d 959, 971 (Del. Ch. 1996) (United States).

  15. Stone v. Ritter, 911 A.2d 362, 369–70 (Del. 2006) (United States); Delaware General Corporation Law, § 102(b)(7).

  16. Pierluigi Matera, ‘From Red Flags to Black Boxes: Corporate Oversight in the Age of Artificial Intelligence’ (2026) SSRN Working Paper No. 6161886.

  17. Marchand v. Barnhill, 212 A.3d 805, 821–24 (Del. 2019) (United States).

  18. In re The Boeing Co. Derivative Litigation, 2021 WL 4059934 (Del. Ch. Sept. 7, 2021) (United States); In re Clovis Oncology, Inc. Derivative Litigation, 2019 WL 4850188 (Del. Ch. Oct. 1, 2019) (United States).

  19. Construction Industry Laborers Pension Fund v. Bingle, 2022 WL 4102492 (Del. Ch. Sept. 6, 2022) (United States).

  20. In re McDonald’s Corporation Stockholder Derivative Litigation, 289 A.3d 343 (Del. Ch. 2023) (United States).

  21. N. Narayanan v. Adjudicating Officer, SEBI, (2013) 12 SCC 152 (India).

  22. Official Liquidator v. P.A. Tendolkar, (1973) 1 SCC 602 (India).

  23. Securities and Exchange Board of India v. Kishore R. Ajmera, (2016) 6 SCC 368 (India).

  24. Samir Agrawal v. Competition Commission of India, (2021) 3 SCC 136, Civil Appeal No. 3100 of 2020, decided 15 December 2020 (India); Competition Act, 2002, s. 3.

  25. Mobley v. Workday, Inc., No. 3:23-cv-00770-RFL (N.D. Cal.) (United States); preliminary collective certification granted 16 May 2025; order on discovery of bias-testing data, 2026 WL 1510537 (N.D. Cal. May 29, 2026).

  26. Bates v. Post Office Ltd (No. 6: Horizon Issues) [2019] EWHC 3408 (QB) (United Kingdom); R (Bridges) v. Chief Constable of South Wales Police [2020] EWCA Civ 1058 (United Kingdom); NJCM et al. v. The Netherlands (SyRI), ECLI:NL:RBDHA:2020:1878 (Rb. Den Haag, 5 February 2020).

  27. State v. Loomis, 881 N.W.2d 749 (Wis. 2016) (United States); Houston Federation of Teachers, Local 2415 v. Houston Independent School District, 251 F. Supp. 3d 1168 (S.D. Tex. 2017) (United States).

  28. In the Matter of Delphia (USA) Inc., SEC Admin. Proc. File No. 3-21894 (18 March 2024); In the Matter of Global Predictions, Inc., SEC Admin. Proc. File No. 3-21895 (18 March 2024); SEC Press Release 2024-36 (18 March 2024); SEC v. Presto Automation Inc. (14 January 2025); Investment Advisers Act of 1940, ss. 206(2), 206(4) and rr. 206(4)-1, 206(4)-7.

  29. SEC Investor Advisory Committee, Recommendation regarding Artificial Intelligence Disclosure (4 December 2025); Glass Lewis, 2026 Benchmark Policy Guidelines.

  30. RBI FREE-AI Committee Report (13 August 2025), Assurance Pillar; Companies Act, 2013, s. 138 (India); ISO/IEC 42001:2023, Information technology — Artificial intelligence — Management system; National Institute of Standards and Technology, AI Risk Management Framework (AI RMF 1.0), NIST AI 100-1 (January 2023).

Comments


bottom of page