In September 2021, Delaware’s Court of Chancery allowed shareholders to pursue Boeing’s directors for failing to oversee airplane safety, and the case settled for $237.5 million. This August, the same judge dismissed a second set of oversight claims against Boeing over the 2024 door-plug blowout, and the reason sat in the board’s files: The court recognized “the volume and depth of Boeing’s reporting” as a best practice instead of evidence of disloyalty. Same company, same judge, same fiduciary duty. The difference was the documented record of what the board received, what it asked and what it decided.
That record is where directors win or lose a Caremark claim, but it isn’t paperwork for its own sake. Boeing’s board prevailed because it had built a reporting system that worked, and its minutes showed that system at work. Across the board directors, chief audit executives and risk leaders I’ve spoken with this year, AI is where the record is thinnest.
The Laws Are Less Certain, but the Duty Isn’t
The Caremark standard applies to AI without any new legislation. Since 1996, Delaware has held directors responsible for making a good-faith effort to put a reporting system in place and to monitor it, and in 2019 Marchand v. Barnhill sharpened that duty for any compliance risk that is “mission critical” to the business. That matters, because AI-specific rules are stalling. G20 ministers endorsed principles in September that limit new regulation to gaps existing law can’t cover, ahead of the leaders’ summit in December. The EU pushed its high-risk AI obligations to December 2027, Colorado replaced its algorithmic discrimination law before it took effect and bank regulators have deferred the question rather than settled it. Until new rules arrive, your board is held to the standard that already applies, and for AI informing who gets hired, approved for credit, insured or treated for care, “mission critical” isn’t a stretch.
Board Minutes Are Your Evidence
In a shareholder lawsuit, the court starts with your board minutes. Delaware law defines the corporate records a shareholder can demand to include board and committee minutes and any materials provided to directors. With 66.7 percent of the Fortune 500 incorporated in Delaware, its rules set the pattern for most large U.S. boards.
But what the minutes leave out matters as much as what they say. In Marchand, a landmark 2019 case about a deadly listeria outbreak tied to Blue Bell’s ice cream products, the Blue Bell board minutes contained no discussion of food safety in the years before the outbreak, and the court treated that absence as evidence the board had no oversight system at all. And where formal records don’t exist, the statute lets a court order their “functional equivalent,” which the Delaware Supreme Court ruled means ordering email to be produced, because the company hadn’t formally documented key decisions anywhere else.
Thin or nonexistent minutes don’t keep the board’s reasoning private, they send the court into its email instead.
From Briefing to Oversight
Large companies’ own public disclosures show there’s a huge maturity gap in the management system. EY’s review of 2025 proxy statements found that 48 percent of the Fortune 100 cite AI as a focus of board risk oversight, but only 16 percent provide any insight into how management reports to the board on it. For cybersecurity, every one of them does. In those same disclosures only 8 percent name the executive who briefs the board on AI, but 89 percent name one for cyber.
Does the proxy explain how management reports to the board?


Share of Fortune 100 proxy statements that do, 2025. Source: EY Center for Board Matters.
The companies I work with show the same pattern. One manufacturing company’s board hears about AI a few times a year, and its public disclosures name AI as a board-level risk. Its policy prohibits using AI in performance evaluations, but it isn’t clear which safeguards enforce that policy, and the board hasn’t pressed on it. Its minutes would show it was briefed. They wouldn’t show that it ever asked management to demonstrate the controls work. That isn’t carelessness, it’s how most boards are briefed on AI today, and it’s precisely the gap that the record will show.
Why Model Bias and Drift Escape the Briefing
The gap is most pronounced when it comes to bias and drift, the two consequential AI failures a briefing is least likely to surface, because neither shows up in a single decision.
Bias is a property of a population. At an AI governance roundtable I co-hosted, the COO of a specialty lender described their accountability model simply: Users own the AI outputs, no matter how a decision is made. As a control over individual judgment, it’s a sound approach. But an employee reviewing one credit file can only confirm that one decision is reasonable. Disparate impact appears when you compare approval rates across groups over thousands of decisions, a comparison no individual reviewer ever sees. University of Washington researchers showed the same thing in hiring: Across more than 3 million comparisons, AI resume screens favored white-associated names 85 percent of the time and Black-associated names 9 percent. No single rejected resume would have revealed it. Owning each output is necessary, but on its own it puts accountability at a level where bias can’t be detected.
Drift is a property of time. A model approved at deployment can degrade as customers, products and markets move away from the data it learned from. A banking executive at the roundtable put it succinctly: AI relies on historical data and isn’t nearly as good at projecting forward. How common is it? More common than most boards assume. When a team from Harvard Medical School and MIT tested 128 model and dataset combinations, quality degraded over time in 91 percent of them. For boards, the lesson is that if you’re relying on the initial review after any meaningful period of time, you’re overseeing a model that may no longer exist in the company.

The record your board needs comes down to two questions a quarterly briefing deck rarely answers: Was this system tested on our population, and has it been tested since we approved it?
The Trade-off the Board Has to Own
Testing creates its own exposure, which is why the board has to know how it’s done. Test too little, and you carry disparate-impact risk without a defense. However, correct a disparity crudely, and you invite a claim that you treated people differently because of a protected characteristic.
Those two legal pressures act on the same model at the same time. Any change made to close a measured gap, such as a new approval threshold, a reweighted variable or a changed data source, should go through your counsel with a documented analysis of business necessity and the alternatives considered. These are rigid legal doctrines, and the testing design, the privilege decision and the remediation choice all belong with experienced counsel from the start. The committee’s job is to confirm that’s how the work is being done, and to evaluate the results.
Before Your Annual Committee Charter Review
None of this requires an elaborate program. It requires four decisions, each leaving a record. A board that makes them is governing AI well, and its minutes will simply show it.
• Start with an education session. Ask management to walk the board through where AI runs in the company, including AI embedded in platforms nobody procured as AI. The session helps build an independent perspective of the risks, and a documented effort to become informed is exactly what Caremark looks for.
• Ask management to report bias and drift testing on your own population. For each system that makes or materially influences a decision about a person, request dated results run since the system was approved. A vendor’s bias statement tests the vendor’s data, not your customers or job applicants, which is what the Mobley v. Workday case is testing in which a federal court let age-discrimination claims over AI hiring screens proceed, and ordered the vendor to identify the employers using its tools.
• Record a decision in the minutes, every time. When the committee receives an AI report, minute it as noted, approved or directed, with the basis. A deck proves you were briefed, but a minuted decision proves you oversaw.
• Specify AI in your charter. Don’t leave it riding under technology or cyber. The compensation committee should know whether any executive incentives are tied to AI results, measured long enough to catch model drift. The nominating and governance committee should know who on the board has the expertise to read the reports and assess the risk.
When I built IBM’s first AI audit program as deputy chief auditor, the question was never whether a policy or framework existed, or even whether we presented it to the board. It was what we could prove, to whom and how quickly. Delaware asks directors the same question, and AI that produces biased outputs or drifts from its approved performance is now an enterprise risk. The oversight a court will credit is the oversight your record shows.


