In 2014, a Hong Kong venture capital firm announced it had appointed an algorithm, VITAL, to its board with formal voting rights on investment decisions. The announcement generated global coverage and a durable myth: that a machine had become a legal fiduciary. It had not, and could not have, under Hong Kong corporate law or any other. What actually happened, and what continues to happen in every serious 2026 boardroom AI deployment, is considerably less dramatic and considerably more legally consequential than the headline suggested.
Key Takeaway
Every major corporate law jurisdiction examined in current 2026 scholarship, including the United States, United Kingdom, Canada, Australia, and New Zealand, requires that a director be a natural person, which categorically excludes an AI system from holding a director's seat or the fiduciary duties attached to it. This is settled and not seriously contested. What is genuinely contested, and rapidly evolving, is a different question: what duty of care and duty of oversight require of the human directors who increasingly rely on AI systems for information, analysis, and recommendations that shape board decisions. Recent scholarship frames this as an emerging "AI due care" standard, and the evidentiary bar for demonstrating good-faith oversight of AI-assisted decisions is rising quickly, even though the doctrinal test, the 1996 Caremark standard, has not formally changed.
The Natural Person Rule
The foundational legal fact this entire topic rests on is simple and, per current scholarship, essentially uncontested: corporate statutes across every jurisdiction examined in a 2026 comparative analysis require that a director be a natural person, and this requirement effectively bars AI systems from holding formal director status today[1]. Hong Kong's own Companies Ordinance requires at least one natural person director and specifically restricts corporate directorship for listed groups[2], the same jurisdiction whose VITAL announcement a decade earlier generated the enduring "AI board member" myth. Delaware, the UK, Germany, Canada, and every other jurisdiction surveyed in current comparative corporate governance scholarship impose the same natural-person requirement[2].
This is not a gap regulators are actively working to close in favour of algorithmic directorship. It reflects a structural feature of fiduciary law itself: a fiduciary duty presumes an agent capable of deliberation, judgment, and legal accountability, including the capacity to be sued, sanctioned, or disqualified. An AI system, however sophisticated, has none of these capacities under current law in any jurisdiction, and no serious corporate law reform proposal as of 2026 argues for granting them.
Why "AI Board Member" Headlines Mislead
What is actually happening at the boardroom level in 2026, per current legal and governance commentary, is a staged, deliberate integration of AI as a decision-support tool operating strictly beneath, not alongside, human directors. Recent industry analysis of large multinational board practice describes a near-term emphasis on AI literacy for directors, basic guardrails, and embedding AI tools within existing committee structures, chiefly audit, risk, and technology committees, rather than any movement toward AI holding formal voting authority[3]. Directors are using AI to synthesize board materials and interrogate large document sets; general counsel and corporate secretaries are evaluating its use for transcription and minute preparation[4]. None of this confers fiduciary status on the tool, and current governance guidance explicitly recommends boards adopt charter language affirming the opposite: that only natural person directors exercise fiduciary duties and voting authority, with AI use explicitly framed as a decision-support layer beneath that authority[3].
Duty Of Care And The Duty Of Oversight
The genuinely live legal question is not whether AI can be a fiduciary. It is what fiduciary duty requires of a human director who relies on AI. Director fiduciary duty is generally analyzed as three related obligations: the duty of care (acting with the diligence of a reasonably prudent director), the duty of loyalty (acting in the corporation's interest rather than one's own), and the duty of oversight or supervision, a more recently crystallized derivative of the duty of care[5].
The duty of oversight is the one AI adoption stresses most directly, because it requires a board to ensure the corporation has adequate reporting systems in place to surface material risks, and an AI system whose outputs directors cannot meaningfully interrogate is, by definition, a harder system to build adequate reporting around. Current commentary frames the tension precisely: under the duty of care, to be reasonably informed through AI, directors must first be reasonably informed about it, and reliance on untested AI output is no substitute for the board's own independent judgment[4].
Caremark And The Black-Box Problem
The doctrinal foundation for the duty of oversight in Delaware corporate law, which remains highly influential across common law jurisdictions including Canada, is the 1996 In re Caremark International decision, which established that a sustained or systematic failure to implement or monitor an adequate reporting and information system can expose directors to personal liability[5]. The standard was clarified further in a 2021 Boeing-related decision and extended to executive management in a 2023 McDonald's case[5].
A 2026 analysis frames the AI-specific application of this doctrine precisely: AI does not change the Caremark standard itself, but it changes the evidentiary terrain on which good faith oversight is demonstrated[6]. Directors are not required to understand how a large language model generates an output or what its underlying architecture does; the inquiry is procedural, not technical. What is required is a good-faith effort to design, validate, and supervise the company's reliance on a system in light of its intrinsic opacity, with process and documentation, not personal technical mastery, as the object of scrutiny[6]. A recurring, practically important point in this literature: legal accountability for what an AI system does does not transfer to the vendor when a procurement contract is signed[6].
Business Judgment Rule 2.0
The business judgment rule ordinarily shields directors from liability for decisions made in good faith, on an informed basis, and in the honest belief the decision serves the corporation's best interest, even if the decision turns out badly. Recent scholarship examining the interaction between this protection and the EU AI Act argues the Act, though not formally addressed to corporate boards, creates a de facto governance standard that is reshaping this protection in practice, giving rise to what the authors term two novel fiduciary duties: AI due care and AI loyalty oversight[7]. These proposed duties compel directors to exercise informed, technologically literate, and ethically grounded oversight of algorithmic systems, reconceiving the traditional duty of care to demand what the authors call cognitive adequacy, the capacity to question, understand, and monitor the technological tools shaping corporate choices, rather than simply deferring to a system's output because it arrived with apparent authority[7].
This is a proposed doctrinal evolution rather than settled law in any jurisdiction as of this writing, and should be read as an influential scholarly position rather than a binding legal standard. It is nonetheless a useful signal of where the business judgment rule's practical application is heading: a director who approved a decision based substantially on an AI system's output, without any meaningful process for validating that output, is increasingly unlikely to find the traditional protection applies as cleanly as it once did for an equivalent decision based on a human analyst's report.
The Governance Gap, In Numbers
Current survey data quantifies a real, measured gap between AI adoption and AI governance at the board level. A 2026 survey found 66% of directors report using AI tools personally, while only 22% report their board has a formal AI governance framework in place[1]. A separate 2026 analysis found only 35% of boards have fully incorporated AI into their oversight function, with roughly 38% of directors reporting they do not feel they receive sufficient AI education to fulfil that function[3]. This gap is precisely what the Caremark-based liability exposure discussed above attaches to: a board using AI extensively without a corresponding governance framework is, per current scholarship, accumulating exactly the kind of unmonitored, opaque reliance the duty of oversight exists to prevent.
The Legal Personhood Debate
Serious academic proposals do exist for reforms that would move closer to AI-attributable accountability, though none currently propose AI holding fiduciary duty in the traditional sense. One 2026 paper proposes an "AI Legal Entity" framework under which an AI system would hold its own assets, including intellectual property, and liabilities, backstopped by mandatory indemnity structures and a human director accountable for its operation, using corporate personhood itself as the analogy for how such a structure might work[8]. This proposal explicitly retains a human director as the accountable party; it does not propose the AI itself bearing fiduciary duty, but rather a novel asset-and-liability structure around the AI's outputs, with human accountability preserved throughout. It is worth citing precisely because it illustrates how far current serious scholarship is from proposing algorithmic fiduciaries: even the most AI-forward legal personhood proposals in 2026 retain a human director as the fiduciary of record.
A Securities Regulator Has Already Named The Risk
It is worth noting that this is not purely a matter of academic or corporate-law speculation about a future risk. The U.S. Securities and Exchange Commission's 2026 examination priorities formally designated AI as a systemic market risk[1], a regulatory signal that AI governance failures are now within the scope of active supervisory attention, not merely a private litigation risk boards might face after the fact. The European Union's AI Act, discussed in the Business Judgment Rule 2.0 scholarship above, separately imposes fines of up to €35 million or 7% of global turnover for serious violations, applying to any organization whose AI systems affect EU markets or individuals regardless of where the organization is headquartered[1]. Neither instrument is directly addressed to Canadian corporate boards. Both are, per current scholarship, creating exactly the kind of de facto governance expectation that shapes how a Canadian court would likely assess whether a board's AI oversight met a reasonable standard, since regulatory and market practice norms are a standard input into how fiduciary duty is judicially construed even where no directly binding statute exists.
What This Means Under Canadian Corporate Law
For Canadian businesses specifically, the Canada Business Corporations Act and equivalent provincial statutes require directors to be individuals, with no exception contemplated for algorithmic or automated systems, consistent with the pattern across all jurisdictions examined in the 2026 comparative scholarship discussed above[1]. Combined with the absence of a comprehensive federal AI statute discussed elsewhere in this publication, Canadian directors face the Caremark-style oversight exposure through existing corporate and securities law rather than through any AI-specific Canadian statute, since none currently exists. This means the governance gap described in the survey data above carries real, if currently untested in Canadian courts, exposure: a Canadian director relying substantially on AI-generated analysis for a material decision, without a documented process for validating that analysis, is operating under the same evidentiary logic the Caremark line of cases applies in Delaware and that Canadian courts have historically drawn on when interpreting equivalent Canadian oversight duties.
The Duty Of Loyalty's Quieter AI Problem
Most commentary on AI and fiduciary duty concentrates on the duty of care and oversight, discussed above, and gives comparatively little attention to a subtler exposure under the duty of loyalty, the obligation that a director act in the corporation's interest rather than any conflicting interest of their own. AI systems increasingly embed vendor-specific incentives that are not always visible to the director relying on them: a procurement recommendation engine trained partly on data supplied by, or optimized to favour, a vendor with a commercial relationship to the software provider; an AI-generated market analysis that systematically favours acquisition targets or investment structures the tool's own provider has a downstream financial interest in recommending. None of this requires bad faith on the director's part to become a genuine loyalty problem; it requires only that the director not have asked, and not have been in a position to know, whether the tool's recommendations were shaped by an interest other than the corporation's own.
This is a newer, less litigated corner of the fiduciary duty landscape than the Caremark oversight line discussed above, and current scholarship has not yet produced the same volume of analysis on it. It is nonetheless a foreseeable extension of loyalty doctrine as AI tools become more commercially entangled with the vendors who build them, and boards adopting AI governance frameworks would be well served asking not only "did we validate this output" but "do we know what interests, if any, shaped it before it reached us."
A Worked Case: The Algorithm-Recommended Acquisition
A private company's board is presented with an AI-generated market analysis recommending a specific acquisition target, complete with valuation modelling, competitive positioning, and projected synergies. The board approves the acquisition substantially on the strength of this analysis, with limited independent verification of the underlying assumptions. The acquisition subsequently underperforms significantly relative to the AI-generated projections.
Applying the framework above, the business judgment rule's traditional protection is not automatically forfeited merely because AI was involved, poor outcomes from good-faith, informed decisions are exactly what that protection exists to shield. The exposure arises specifically from the process: could the board demonstrate a good-faith effort to validate the AI system's key assumptions, understand its known limitations, and exercise independent judgment rather than simple deference to a confident-sounding output? A board that can point to a documented validation process, even an imperfect one, sits in a meaningfully different position than one that cannot produce any record of having interrogated the analysis before relying on it. This is precisely the "evidentiary terrain" distinction the 2026 Caremark-AI scholarship describes: the standard for good faith has not changed, but what counts as evidence of it, in an AI-assisted decision, increasingly requires a visible validation process rather than an assumed one.
What Boards Should Actually Do
Drawing directly from the scholarship above, several concrete practices follow. Adopt explicit charter language affirming that only natural person directors hold fiduciary duty and voting authority, with AI explicitly scoped as a decision-support tool, closing off any ambiguity about where accountability sits[3]. Build and document a validation process for any AI output materially informing a board decision, proportionate to the decision's stakes, since the process itself, not technical mastery of the underlying model, is what current doctrine actually scrutinizes[6]. Invest in director AI literacy specifically to close the education gap the 2026 survey data identifies, since a director cannot meaningfully validate what they do not understand at a functional level. Route material AI-assisted decisions through an accountable committee, typically audit or risk, rather than leaving AI governance informally distributed across the full board with no single owner.
Why This Usually Lands On The Audit Committee
It is worth explaining specifically why audit and risk committees, rather than technology or strategy committees, have emerged as the primary home for AI governance in current board practice, per the 2026 industry analysis cited above[3]. The duty of oversight, the specific fiduciary obligation AI reliance stresses most directly, has historically been operationalized through the audit committee's existing mandate over internal controls and risk reporting systems, the same institutional machinery Caremark itself was decided around. Routing AI governance through a technology or innovation committee, by contrast, risks framing AI oversight as a strategic or competitive question rather than a fiduciary compliance one, which is precisely the framing current scholarship argues understates the actual legal stakes. The practical implication for a smaller company without a formally separated committee structure is not that AI governance requires an entirely new body, but that whichever body already carries internal-controls oversight responsibility should explicitly absorb AI governance into that existing mandate, rather than treating it as a separate, lower-priority initiative.
A Note For Students Of Corporate Law
For anyone studying corporate governance, this area is a useful live illustration of a recurring pattern in how legal doctrine absorbs new technology: the substantive standard rarely changes as fast, or as dramatically, as popular commentary suggests, while the practical application of that standard shifts considerably faster, through changes in what counts as adequate evidence of compliance. Caremark, decided in 1996 in the context of a pharmaceutical company's regulatory compliance failures, was not written with AI in mind and has not been rewritten to address it. What has changed is the factual context courts and boards must apply it to, and 2026 scholarship's core contribution has been mapping that application rather than proposing a new doctrine. This is a more common pattern in the evolution of corporate law than the "AI changes everything" framing common in popular technology commentary suggests, and it is worth recognizing as a template for how other emerging-technology fiduciary questions are likely to be resolved as well.
Taken together, the natural-person rule, the Caremark-derived oversight standard, and the emerging AI due care scholarship form a coherent, if still-developing, picture: the law is not waiting for AI to become a fiduciary before holding boards accountable for how they use it.
The Limits Of This Analysis
Several caveats matter. This entire area is genuinely unsettled and evolving rapidly; the specific scholarly proposals cited, "AI due care," "AI loyalty oversight," the AI Legal Entity framework, are influential recent academic positions rather than binding law in any jurisdiction as of this writing, and courts have not yet definitively tested how the Caremark standard applies to a genuinely AI-assisted board decision in a reported Canadian or Delaware decision. The natural-person director requirement is well-established and unlikely to change quickly, but legal personhood scholarship in this area is active and could shift the landscape meaningfully within the useful life of this article. Readers with a live governance decision at stake should treat this article as a framework for the relevant questions, not as a substitute for current legal advice from corporate counsel familiar with their specific jurisdiction and circumstances.
Frequently Asked Questions
Can an AI system legally be a company director in Canada?
What was the 2014 "AI board member" story actually about?
Does using AI for board decisions increase a director's legal liability?
What is the Caremark standard?
What should a smaller, privately held Canadian business actually do about this?
References
- Evi Eni, O. (2026). AI Governance and the Board of Directors: Fiduciary Duty, Regulatory Liability, and the Director's Obligation to Govern Artificial Intelligence in 2026. SSRN Working Paper. papers.ssrn.com/sol3/papers.cfm?abstract_id=6884399
- Telesto Strategy. (2026, February 11). Board Series: Will Your Next Board Member Be An AI Agent? telestostrategy.com/board-series-will-your-next-board-member-be-an-ai-agent
- Fenwick. (2026, May 27). AI in the Boardroom: What Directors Need to Know Now. fenwick.com/insights/publications/ai-in-the-boardroom
- Goodwin. (2026, July). Governing the Board's Own Use of AI: Fiduciary Duties, Risks and Practical Safeguards. goodwinlaw.com/.../governing-boards-ai-fiduciary-duties
- American Bar Association. (2024, March). The Duty of Supervision in the Age of Generative AI. Business Law Today. americanbar.org/.../duty-of-supervision-generative-ai
- The D&O Diary. (2026, June 25). Guest Post: AI Governance Is a Fiduciary Duty, citing Matera, P. (2026). From Red Flags to Black Boxes. CLS Blue Sky Blog; SSRN 6161886. dandodiary.com/.../ai-governance-is-a-fiduciary-duty
- Oxford Law Blogs. (2026, January 29). Fiduciary Duties and the Business Judgment Rule 2.0 in the AI Act Age. blogs.law.ox.ac.uk/.../business-judgment-rule-20-ai-act-age
- Das, S. (2026, April 16). The Director's Duty: AI Personhood Through the Corporate Law Analogy. SSRN Working Paper. papers.ssrn.com/sol3/papers.cfm?abstract_id=6587299
This article discusses current corporate governance scholarship and general legal principles and is provided for general informational purposes. It is not legal advice. Corporate governance and director liability standards are jurisdiction-specific and rapidly evolving in this area; confirm your board's specific obligations with qualified corporate counsel.