AI
CIOs Hold the Records That Keep AI Failures Off Directors
Reed Smith partners warn AI hallucinations and breaches reach boards via weak reporting; CIOs must build records and stress-test D&O cyber E&O policies now.
An artificial intelligence hallucination, data breach or overstated system claim becomes a boardroom problem the moment it dents financial results, draws regulators or lights up customers and the press. Reed Smith partners Carolyn H. Rosenberg and Andy Moss told BankInfoSecurity that CIOs sit at the center of the fix: they build the reporting chains, keep the governance records and push the insurance reviews that keep directors inside the business judgment rule.
Boards already feel the twin pressures to deploy AI fast and still show they stayed reasonably informed. The second-order consequence is clear. Weak escalation and untested cover turn ordinary tech glitches into personal liability questions for directors.
That pressure lands first on information flow. Directors cannot exercise judgment they never receive. CIOs who design how incidents move upward therefore shape whether the board’s protection holds when results, regulators or customers force the issue into the open.
When an AI incident reaches the board
Moss noted that directors must stay reasonably informed and maintain reporting systems that surface significant risks. The business judgment rule still protects reasonable decisions that later fail. It does not protect the absence of reliable information or escalation paths.
“I don’t think you can silo this, and I think that’s where you get into some trouble,” Rosenberg said. AI risk crosses technology, legal, compliance, audit, customer relations and corporate communications. Companies need routine board updates on peer practices and operation-specific risks. Committees can dig into details and hand directors a clean summary of open issues and options.
Triggers that can lift an AI problem to D&O exposure include material financial impact, regulatory scrutiny and public or customer backlash. CIOs need systems that let employees flag problems quickly and let executives carry material issues upward without delay.
- Hallucinations or unreliable outputs that feed public statements or financial models
- Data breaches or privacy failures tied to AI training or inference pipelines
- Misleading performance claims that later look like AI washing to investors
- Model drift or bias that produces discriminatory or non-compliant decisions
Those same patterns already appear in other AI tools. AI meeting notetakers already triggered privacy liability once recordings and summaries left company control.
The common thread is not the model type. It is whether the company already had a path from front-line detection to board-level awareness before outsiders forced the issue. Without that path, each trigger above becomes harder to defend as an informed business judgment.
Survey numbers show insurers expect board ownership
A August 2026 survey by The D&O Diary and Allianz Commercial drew 250 responses from insurers, brokers and insured companies across more than 20 countries. The governance results left little room for debate.
| Survey finding | Agreement level |
|---|---|
| Poor AI governance increases likelihood of D&O-related claims | 94% |
| Boards should approve internal policies governing AI usage | 94% |
| AI governance should form part of overall corporate governance | 95.8%-100% |
| AI-related claims will significantly affect the D&O claims experience | 85.6% |
| Underwriters will request more AI risk information | ~80% |
Respondents ranked capital expenditure, AI washing, data privacy, regulatory proceedings, algorithmic discrimination and intellectual property as clustered top concerns. 94 percent linked poor AI governance to higher D&O claims. Dan Holloway of Allianz Commercial put it plainly: AI is a governance issue as much as a technology issue, and documented policies plus board oversight will become key underwriting signals.
About 55 percent thought existing D&O wording needs amendment for AI; nearly half disagreed. Written comments mostly treated AI as another operational risk that current policies already cover, provided insureds keep accurate disclosures.
The split on wording does not soften the governance message. Even respondents who saw no need for formal amendments still expected boards to own policy approval and to fold AI into ordinary corporate governance. Underwriters asking for more AI risk information will look for that ownership trail, not for perfect technical outcomes.
The SOX control lag that raises officer risk
AI tools now help identify journal entries, analyze revenue trends, support estimates and even draft MD&A sections. Traditional SOX controls assumed fixed-rule systems and human judgment. Probabilistic models create an AI governance gap in SOX financial reporting controls.
Three lag points stand out:
- Control design often trails deployment
- Explainability can block auditors from seeing why a model produced a result
- Data quality and model drift can quietly degrade accuracy
Officers signing Sections 302 and 404 certifications need a reasonable basis that internal controls work. Boards must ask basic questions about reliability, data quality, documentation and handling of unexpected outputs.
Derivative suits can allege boards failed to set basic AI governance or ignored red flags. So far most AI securities cases are AI-washing claims over overstated capabilities; those typically sit inside D&O cover. Deeper use in financial reporting may test that pattern.
When a model feeds journal entry work or MD&A drafting, the certification question is no longer abstract. Officers need evidence that someone tested the control design against the model’s behavior, not only against the older fixed-rule systems the SOX framework once assumed.
How CIOs build the records directors need
Rosenberg and Moss stressed that CIOs create the reliable reporting and governance records that let boards stay informed. Escalation cannot wait for a crisis. Employees need clear paths to raise problems. Executives need channels that reach the board with material issues.
Practical steps that survive later scrutiny include:
- Routine board briefings that cover peer practices, internal incidents and residual risks
- Committee-level deep dives that produce short decision summaries for the full board
- Documented ownership for each material AI system, including testing and monitoring results
- Minutes that record alternatives considered, risks escalated and reasons for decisions
- Clear hand-offs between technology, legal, compliance and communications when an issue surfaces
A parallel Reed Smith podcast from the same Insurance Recovery Group made the same point: directors and officers liability turns on how boards authorize, oversee and document AI use, not on the AI mistake alone. Meeting minutes and governance records become the evidence that defeats hindsight claims.
Crowd conversation on X has already moved past model failure. Observers note that fragmented authority, missing cost transparency and unclear stop rights create the real exposure. Treating AI as an IT line item rather than a fiduciary topic is itself a governance failure.
Records that show ownership, testing results and reasoned choices give directors something concrete to point to. Records that show only deployment dates and vendor names leave the board arguing from memory after the fact.
Stress-testing the three cover lines that matter
Moss and Rosenberg urged companies to stress-test D&O cyber and technology E&O coverage before an incident. AI claims often mix board oversight, product performance, cyber elements, discrimination or IP issues. Insurers may try to push a claim into the line that offers the least cover or the tightest exclusion.
A misleading disclosure claim often looks like classic D&O. A customer claim over defective output may head toward technology E&O. An algorithmic discrimination investigation can sit between them. Cyber exclusions written years ago can sweep up AI-enabled attacks if the wording is broad. AI-specific exclusions remain uncommon on public-company D&O but have appeared on some private-company policies.
| Claim pattern | Cover line often in play |
|---|---|
| Misleading disclosure or AI washing | Classic D&O |
| Customer claim over defective output | Technology E&O |
| Algorithmic discrimination investigation | Between D&O and tech E&O |
| AI-enabled attack caught by broad cyber wording | Cyber, with exclusion risk |
What we know
- Most AI-washing securities suits fall within standard D&O subject to policy terms
- Underwriters increasingly ask about AI maturity and governance at renewal
- Investigation costs can mount quickly; defense-cost advancement timing matters
What remains contested
- Whether existing D&O wordings need formal AI amendments
- How cyber or professional-services exclusions interact with AI governance failures
- Priority among D&O, cyber and tech E&O when multiple policies could respond
Policyholders should map AI risk across the full insurance program at every renewal, update proposal forms so they match current AI use, and push for clarity or sublimits rather than silence. Side A protection for individual directors deserves special attention if corporate indemnity or Side B becomes unavailable.
AI washing filings already set the pattern
Securities class actions tied to AI disclosures rose from 7 in 2023 to 14 in 2024, with a steady flow into 2025 and 2026. Plaintiffs allege companies overstated AI capabilities, revenue contribution or technical sophistication. When short-seller reports or later disclosures undercut the claims, share prices drop and suits follow. AppLovin, Tempus AI and others have faced versions of the charge.
- 2023 – 7 securities class actions tied to AI disclosures
- 2024 – 14 such actions, double the prior year
- 2025 and 2026 – steady flow of new filings continues
The same dynamic appears in marketing. AI-powered marketing claims that became brand liabilities show how quickly a promotional label can turn into a compliance and reputational problem once performance lags the hype.
Boards that approved aggressive AI messaging without documented diligence now face the second-order question: did they have adequate information systems in place, or did they simply rely on management optimism?
Filing volume alone does not prove every claim has merit. It does show plaintiffs already know how to plead overstated capabilities and then tie the drop in share price to those statements. Boards that signed off on the messaging need a paper trail of what they asked and what they were told.
How Fragmented Authority Widens Personal Exposure
The X conversation that moved past model failure pointed at structure, not software. Fragmented authority, missing cost transparency and unclear stop rights leave no single owner when an output goes wrong. That gap is what turns a tech incident into a director-level story.
Rosenberg’s warning against siloing AI risk maps directly onto that problem. When technology, legal, compliance, audit, customer relations and corporate communications each hold a piece of the system, escalation slows. Material issues reach the board late, if at all.
CIOs who document ownership for each material AI system, including testing and monitoring results, close part of that gap. Clear hand-offs when an issue surfaces close more of it. Without those steps, directors face the charge that they never built the reporting systems Moss said the business judgment rule requires.
Why Renewal Season Now Tests Oversight Evidence
Underwriters will request more AI risk information, according to roughly four in five survey respondents. Holloway’s framing makes the ask concrete: documented policies and board oversight become underwriting signals, not optional extras.
That demand meets the contested ground over policy wording. About 55 percent of respondents wanted formal AI amendments; nearly half did not. Companies that update proposal forms to match current AI use, and that map risk across D&O, cyber and technology E&O, enter that debate with fewer surprises.
Side A protection for individual directors deserves a hard look in the same cycle. If corporate indemnity or Side B is unavailable after a serious incident, the personal stake for directors rises fast. Stress-testing cover before the claim arrives is the practical answer Moss and Rosenberg urged.
Directors who wait for a perfect model lose the shield
The business judgment rule still works when the record shows directors asked questions, received briefings and recorded their reasoning. It frays when the first material AI incident reveals no escalation path, no board-approved policy and no insurance mapping.
CIOs who treat reporting, records and coverage reviews as core duties give boards the evidence they need. Those who leave AI ownership fragmented leave directors exposed to the claim that they never really governed the risk. The next renewal cycle and the next unexpected model failure will test which approach companies chose.
-
AI2 months agoFable 5 and Mythos 5 Return as US Lifts Anthropic Export Controls
-
AI2 months agoOracle Cuts 21,000 Jobs in a Year, Cites AI in 10-K Filing
-
AI2 months agoSpaceX’s Google Deal Turns a Rocket Company Into a Cloud Landlord
-
GAMING2 months agoCD Projekt Red Co-CEO: Redemption Arc Isn’t Done, Witcher 4 in 2027
-
CRYPTO2 months agoXPL Rallies 30% Ahead of Plasma One Card Tier Launch
-
NEWS2 months agoGoogle Search Profiles Build a Follow Graph Inside Discover
-
APPS2 months agoDGO App Brings Rs 549 Mobile Pass for FIFA World Cup 2026 in Nepal
-
AI2 months agoMoonshot AI Targets $30 Billion in China’s Fastest AI Funding Sprint
