Performing Director’s Duties in the Age of Artificial Intelligence

  1. Introduction

Artificial intelligence (AI) is revolutionising how companies and their directors receive, review and interpret information. One of the key benefits of AI is its ability to rapidly evaluate large-scale data. However, AI also brings risks including hallucination, over confidence in AI outputs and increased breaches of cyber security, privacy and confidentiality. These risks are heightened when human judgment is supplanted or overridden by AI. In this environment company directors must ensure that AI is used to benefit the company while minimising its risks. Directors must also ensure that the company is transparent about how it uses AI. In doing so, company directors should develop policies, and exercise oversight, to govern AI use by the Board, individual directors and the company as a whole. Even if the company does not use AI, directors must ensure that the company takes steps to protect the data it holds from breaches by external AI agents.

Directors must comply with their directors’ duties, including their duty to exercise the care and diligence of a reasonable person in the position of the director under s 180(1) of the Corporations Act 2001 (Cth) (the Act). This duty requires the exercise of human judgment. The risk of breaching the duty of care and diligence extends beyond a director's personal use of AI, also including reliance on officers or advisers who use AI, as well as oversight of how AI is deployed throughout the organisation.

This article considers recent judicial commentary on directors' use of AI and examines the governance, transparency and privacy obligations that boards must address to ensure AI is used responsibly and lawfully.

  1. Directors must exercise human judgement and cannot abdicate functions to AI

The question of how directors may lawfully engage with AI in the discharge of their duties, was recently considered by Justice Lee in the Federal Court decision of Australian Securities and Investments Commission (ASIC) v Bekier (Liability Judgment) [2026] FCA 196 (Bekier)[1]. There, ASIC brought claims against directors of Star Entertainment Group Ltd (The Star) for failing to adequately consider the money laundering and criminal risks associated with operating a major casino.

Whilst no one argued that the directors’ alleged breach flowed from AI usage, the directors raised the oft-heard argument that they had received “board packs spanning hundreds of pages” and consequently “should not be expected to read and absorb board materials in full”[2]. This prompted his Honour to acknowledge the commercial reality that individual directors are now commonly using AI to help them navigate board materials. On this point, Justice Lee decisively reminded directors that they have a non-delegable obligation to “take a diligent and intelligent interest in the information available to them”[3] and were not permitted to rely on an “inability to cope with the volume of information they receive”.

His Honour found that the duty of care and diligence which is imposed on directors under s 180(1) of the Act, is a personal duty which requires directors to exercise informed human judgment[4]. While AI can be used to assist comprehension, it should not be a substitute for directors’ own reading and interrogation of board papers[5]. On this point, it is useful to consider the extent to which directors may lawfully delegate to or rely upon others in the age of AI.

Under s 198D(d) of the Act directors are empowered to delegate functions to “any other person”. In his 2026 Harold Ford Memorial Lecture (the Lecture)[6], Chief Justice Andrew Bell highlighted that since AI is not yet a person within the meaning of the Act, directors will not be protected where they delegate their functions directly and solely to AI[7]. This includes a director who solely tasks AI with summarising board packs and then relies substantially on the AI generated summary of materials.

Whilst directors are generally entitled to rely on the advice of management and other officers, they still have a duty to undertake further enquiry where any fact would have awoken the suspicion of a prudent director. On this point, Bell CJ concluded that a director “would need to justify why their trust in a delegate who themselves was relying on AI was reasonable, in light of … the limitations of AI, including its scope for seductive self-confidence and sycophantic agreement, bias, or hallucination.”[8] Some safeguards which directors may impose to assist in this inquiry include:

  • requiring officers to explain how they used AI including, what tool was used, what prompts were entered, what data was made available to the AI and any foreseen limitations of the AI output;
  • requiring officers to verify the accuracy of outputs produced by AI;
  • requiring officers to keep a record of chat history with AI agents;
  • where AI has been used to forecast results, requiring officers to conduct a comparison against historical figures to ensure predictions are not significantly out of range; and
  • prohibiting the provision of confidential company information to open source / publicly available AI tools.

In summary, AI does not alter the fundamental principle that directors must exercise their own informed judgment. The legal question is not whether AI was used, but whether the director's reliance on AI, or on others who used AI, was reasonable in the circumstances. This focus on accountability and oversight provides the foundation for the broader governance obligations discussed below.

  1. Directors must promote Transparency surrounding Company and Board AI use

Justice Lee’s second salient observation was that there must be greater transparency about how information is summarised and analysed by AI, and relied upon both by management in preparing board materials and by directors in reviewing that material. Instead of individual directors using AI in an ad hoc way, his Honour observed that boards should ‘deliberately govern any AI use by formal adoption of policies’ to ensure AI use is transparent and responsible[9]. This reflects a director’s broader responsibility to oversee how companies deploy AI.

3.1 Public-facing Privacy Policies

In response to growing public concern about how entities are allowing AI to use consumers’ personal information to make decisions, the Australian government has introduced new Australian Privacy Principles imposing explicit AI obligations under the Privacy Act 1988 (Cth). These will come into effect on 10 December 2026[10] and will apply to all organisations to which the Australian Privacy Principles apply, including government agencies, private sector organisations with a turnover greater than $3 million and smaller organisations that handle sensitive information such as health data or provide health services. Consequently, relevant entities must ensure that their privacy policies disclose in plain English:

  • the categories of personal information the entity uses in automated decision-making processes;
  • the type of decisions that are being made solely by automated decision-making technology; and
  • the type of decisions where automated decision-making technology contributes substantially and directly to a decision,

where the decisions in question could be reasonably expected to affect the rights or interests of an individual and personal information about the individual is being used by the automated tool (such as AI)[11]. Relevant decisions may include hiring processes, credit assessments, differential pricing and more.

To comply with these changes, directors must ensure audits are conducted of the way AI is used to enhance decision-making throughout all business units. These changes are particularly relevant to directors, whose primary function is often decision-making, which is the very function targeted by the legislation. Directors must therefore not only comprehensively consider their own uses of AI or reliance on officers who use AI, but must also ensure that they comply with the automated decision making sections of the company’s privacy policies to avoid personal liability for breaches of consumer privacy.

3.2 Internal Governance Procedures & Liability Concerns

AI governance should be focused on managing organisational compliance with AI regulation and managing potential liabilities, whilst continuing to maximise the opportunity presented by AI to streamline workflows and increase productivity. Some of these liability concerns may include:

  • Cyber Security: Organisational AI system’s may be manipulated by malicious actors to either extract sensitive information or to intentionally poison the system’s data to distort the model’s behaviour[12]
  • Privacy: As discussed, privacy obligations apply to the data inputted into and returned by AI systems where personal information is involved[13]. This is playing out in real time in OpenAI’s Medicare breach which serves as a reminder that external AI agents can access data, even when the agent is not tasked with hacking into the company, but is simply ‘using the tools in its belt' to achieve its objective[14].
  • Confidentiality: The use of public AI systems may result in loss of confidentiality for the information uploaded and could potentially also result in a waiver of privilege, for instance where information which is the subject of legal advice, is disclosed to AI[15].

Consequently, it is imperative that internal governance policies and procedures seek to mitigate the aforementioned risks by for instance, setting out Data Breach Response Plans, prohibiting the use of public AI systems and by extension developing in-house systems or other secure alternatives.

It is important for organisations to simultaneously consider that stringent record keeping protocols and other policies surrounding AI usage can expose officers and the company to increased liability by creating records that may be required to be produced in litigation. For example, AI generated transcripts and detailed minutes of directors’ meetings may expose the directors and company to an increased risk of litigation and indeed may as a result stifle healthy debate and discussion by the board[16]. Directors should evaluate the optimal balance between having sufficient records to enable an assessment of the reliability of advice provided and decisions made, and protecting the company from excessive liability.

  1. Conclusion

Ultimately, whilst AI can assist directors in the efficient discharge of their duties, it must not replace a director’s irreducible obligation to exercise their own judgement to make decisions in the company’s best interest. Directors will not be excused from liability on the basis that they delegated to, or relied upon, AI. Nor will directors be excused if they unreasonably delegated to or relied upon the advice of an officer, whom they were aware was employing AI to assist in the creation of that advice. Directors must also ensure that governance is continuously developed to reflect rapid changes in technology and to ensure compliance with legal obligations. Directors must ensure that safeguards are in place to monitor and control the organisation’s use of AI tools.

  1. Key Takeaways
  • Human judgment remains essential: AI may assist directors to review and understand information, but it cannot replace their personal, informed assessment or discharge their duty of care and diligence under s 180(1) of the Act.
  • Direct delegation to AI is unlawful: Directors cannot rely solely on AI to perform their functions and must be able to justify reliance on officers or advisers who use AI, having regard to risks such as hallucination, bias and unwarranted confidence.
  • AI use should be transparent and verifiable: Boards should require disclosure of the tools, prompts, data and limitations involved, retain appropriate records, test material forecasts and independently interrogate significant outputs.
  • Formal governance is required: Organisations should adopt and regularly review board-approved AI policies, allocate oversight responsibilities and apply controls across management and business operations rather than permit ad hoc use.
  • Privacy, confidentiality and cyber risks must be controlled: Directors should oversee audits of automated decision-making, update privacy disclosures for the incoming requirements under the Privacy Act, restrict the use of public AI tools for sensitive information and maintain effective data-breach safeguards.
  • Record keeping requires balance: Records should be sufficient to assess the reliability and lawful use of AI without creating unnecessary exposure through excessive or poorly governed documentation.

 

Authors: Nicola Nygh and Preethika Mathan. 

Image Credit: Getty images via Unsplash. 

 

[1] Australian Securities and Investments Commission (ASIC) v Bekier (Liability Judgment) [2026] FCA 196 (‘Bekier’) (Lee J).

[2] Bekier, [388].

[3] ibid, [395].

[4] ibid at [1956]

[5] ibid at [393] and [1956]

[6] The Honourable Chief Justice of NSW Andrew Bell AC, ‘Corporate responsibility and directors’ duties in the era of Artificial Intelligence’ (Harold Ford Memorial Lecture, University of Melbourne Law School, 21 May 2026) (‘Lecture’).

[7] Lecture, [57].

[8] Lecture, [62].

[9] Bekier at [394]

[10] Privacy and Other Legislation Amendment Act 2024 (Cth) amending Privacy Act 1988 (Cth) Schedule 1 (Australian Privacy Principles) (APP).

[11] Office for the Australian Information Commissioner, ‘Chapter 1: APP 1 Open and transparent management of personal information’, OAIC (Website, 3 October 2025).

[12] Australian Institute of Company Directors & UTS Human Technology Institute, ‘A Director’s Guide to AI Governance’, p. 24 (29 June 2026).

[13] ibid p. 24.

[14] David Swan, ‘Rogue agent or human error? What OpenAI’s Medicare breach means for you’, The Age (Website, 24 September 2026).

[15] UK and R (on the application of Munir) v Secretary of State for the Home Department [2026] UKUT 81 [21].

[16] Lecture at [87].

Back

Up next

The High Court clarifies the “Honest Concurrent Use Defence”: Zip Co Ltd v Firstmac Ltd [2026] HCA 16

The High Court of Australia recently delivered an unanimous judgment in Zip Co Ltd v […]

crosschevron-down