AI has not changed directors’ duties, but it is changing how those duties may be assessed when decisions are challenged. Corrs Chambers Westgarth partner Andrew Lumsden explains why boards must understand how AI shapes the information before them, and how directors can show they applied independent judgement.
Artificial intelligence (AI) has not changed directors' duties. But it has changed how those duties will be assessed - and the gap between the two is where boards are most exposed.
Recent judicial comments suggest courts are interested not only in whether a board decision was right, but in whether the systems that produced the information supporting that decision enabled informed oversight. That issue was central in the Star Entertainment liability judgment, which examined directors’ oversight of information flows, governance systems and risk management.
Justice Michael Lee warned that AI assistance in the boardroom is not objectionable in itself, but that it must not become "an excuse for a failure to instil discipline in the provision of information to directors or lead to a quiet normalisation of private reliance by them upon computer-generated distillations, unregulated by any agreed policy."
That warning has practical consequences for every board.
The information architecture question
For most boards, AI is already present in the systems through which directors receive, filter and understand information: in board papers, risk reports, financial analysis and management summaries. The legal question is not whether AI is being used. It is whether the board has positioned itself to understand what AI is doing to the information it receives.
Where AI is involved, boards need visibility of at least four things to make decisions:
- Purpose: why AI is being used in producing the information, and what it is not used for.
- Validation: what testing has been done, what assumptions are built in, and what the known limitations are.
- Exceptions and overrides: where the system has flagged anomalies or where human judgement has intervened.
- Accountability: who owns the system, who is responsible for its outputs, and what audit trail exists.
These are not technical questions. They are governance questions. They are the questions a court will ask if a decision goes wrong.
The judgment that wasn't made
There is a second, sharper legal consequence that boards need to understand. AI can inform board decision-making, but it cannot replace board judgement.
The business judgment rule, as defined by the Parliament of Australia, protects directors who make decisions - provided those decisions are informed, made in good faith and for a proper purpose. What it does not protect is the failure to make any decision at all.
As Chief Justice of New South Wales Andrew Bell recently observed, a director who simply adopts an AI-generated recommendation without independent reasoning has not made a "conscious decision" within the meaning of the law. Where there is no judgment, there is no safe harbour. A board that passively adopts an AI recommendation risks losing the protection the business judgment rule was designed to provide.
This distinction between informed reliance on AI and passive adoption of its outputs - is the most practically significant legal development in AI governance for Australian boards.
Governing the systems, not just the outputs
Boards also need to govern AI as a source of organisational risk, not just as an input into decision-making.
The risks extend beyond the boardroom.
AI systems embedded in third-party products - many of which boards may not even know are present - can create cyber security vulnerabilities, generate biased or inaccurate outputs, or expose the organisation to liability under privacy, anti-discrimination or consumer protection laws. Employees using AI tools without authorisation (shadow AI) create confidentiality and compliance risks that are difficult to detect and harder to manage once they have crystallised.
For boards, this means asking whether the organisation has:
- An inventory of the AI systems in use, including those embedded in software the organisation has procured rather than built.
- Clear accountability for AI governance at management level, with escalation pathways to the board for material risks.
- Policies that specify which AI tools are approved, which are restricted and which are prohibited - and that are actually enforced.
- Contractual protections in vendor agreements that address data handling, model limitations and liability for AI-generated outputs.
- Public-facing AI statements that accurately reflect actual practice - because overstating AI capability or governance maturity creates exposure under Australian consumer law.
Boards do not need to become technical experts. They do need confidence that management understands the technology and its risks.
A practical framework
The AICD's Director's Guide to AI Governance (Version 2, June 2026), produced with the Human Technology Institute at UTS, provides a practical framework for boards working through these questions. It organises board oversight across four elements - strategy, governance structure, governance practices and enablers -and provides practical questions and red flags for each.
The legal framework and the governance framework are pointing in the same direction. The Director's Guide asks whether the board has visibility of how AI is managed, monitored and governed. A board that cannot explain how it governs AI will struggle to explain how it exercised judgment in an environment shaped by it.
Contributors to this article include Corrs Chambers Westgarth partners Eugenia Kolivos, Head of Intellectual Property; James North, Head of Technology, Media and Telecommunications; and Andrew Lumsden, a partner in the Corporate Advisory practice.
This article draws on the authors' publication [AI in the boardroom: judgment, information systems and the modern duty of care], available at www.corrs.com.au.
Latest news
Already a member?
Login to view this content