Skip to content
MAYFLOWER SPECIALTYMayflower Specialty

Risk

AI and the Board: Oversight Duties, AI-Washing and D&O Exposure

Updated 12 minute readBy Mayflower Specialty

Directors and officers face AI claims in two ways: for overstating what the company's AI does, a practice known as AI-washing, and for failing to oversee AI that later causes harm. Regulators have already brought AI-washing cases, and shareholders filed 15 AI-related securities class actions in the first half of 2026 alone.[1] A D&O policy may respond to both kinds of claim, but some insurers now add AI exclusions, so boards should document how they oversee AI and check at every renewal whether each layer of their D&O program is silent on AI or excludes it.[23]

What Is AI-Washing?

Definition

AI-washing

AI-washing is the practice of overstating what a company's artificial intelligence does or how much the company relies on it. Regulators treat such statements as potentially misleading, and shareholders can bring securities claims over them.

AI-washing ranges from claiming a product uses AI when it does not to exaggerating how well the AI works or how much of the job it does without people. When the SEC announced its first cases, its then-chair said: “Such AI washing hurts investors.”[2] The exposure sits wherever the company describes its AI in public, from filings and earnings calls to fundraising decks and marketing, so it is best to hold AI statements to the same standard of evidence as financial ones.

Which AI-Washing Cases Have Regulators Brought?

The SEC, federal prosecutors and the FTC have all acted against AI-washing since March 2024, and the cases have moved from investment advisers to a public company and then to criminal charges against a startup founder.

DateAuthorityTargetAllegationResult
March 18th 2024SECDelphia and Global Predictions, two investment advisersFalse and misleading statements about their use of AISettled without admitting or denying the findings; civil penalties of $225,000 and $175,000 [2]
January 14th 2025SECPresto Automation, a public restaurant-technology companyFalsely claimed its own AI drive-thru product removed the need for human order-taking, when the vast majority of orders required human interventionSettled; a disclosure controls violation was also found; no civil penalty [3]
April 9th 2025Federal prosecutors in the Southern District of New York, and the SECAlbert Saniger, founder of the shopping app NateRaised roughly $42 million on claims that the app used AI to complete online purchases on its own, when it allegedly relied heavily on contractors in the Philippines and RomaniaCharged; Saniger has pleaded not guilty and the charges are unproven [5][6]

The D&O Diary described the Presto order as what may be the SEC's first AI-washing action against a reporting company,[4] and the Saniger case shows that an AI claim made to raise money can create personal criminal exposure. AI claims have also stayed on the SEC's agenda after the change of administration, since on February 20th 2025 the Commission created a Cyber and Emerging Technologies Unit whose priorities include “fraud committed using emerging technologies, such as artificial intelligence and machine learning”.[7]

The FTC applies the same reasoning to claims made to customers: its Operation AI Comply, announced on September 25th 2024, brought cases against five companies, including DoNotPay over its AI “robot lawyer”, and the then-chair said “there is no AI exemption from the laws on the books”.[8] A proposed policy statement published in the Federal Register on July 7th 2026 goes further, arguing that consumers reasonably expect AI systems to aim for accurate output, so a company that markets an AI system and steers its output away from that expectation without clear disclosure may deceive them; it had not been finalized as of this writing.[9]

Most of these cases began with a claim about what AI could do that the company could not support, so the practical course of action is to require supporting evidence, such as test results or operating data, behind each public claim about what the company's AI does.

How Many Securities Class Actions Involve AI?

Plaintiffs filed 16 AI-related securities class actions in 2025[11] and 15 in the first half of 2026 alone,[1] according to Cornerstone Research and the Stanford Law School Securities Class Action Clearinghouse, and the newest suits challenge what companies left out about AI as well as what they overstated.

PeriodAI-related securities class action filingsChange
20237 [10]n/a
202415 [10]More than double 2023
202516 [11]Slightly above 2024
First half of 202615 [1]“On pace to nearly double the 2025 total”, in Cornerstone's words

The first-half 2026 filings accounted for $385 billion, or 73%, of the $529 billion Disclosure Dollar Loss Index for the period, which measures the fall in defendant companies' market value when the alleged misstatements came to light.[1] The D&O Diary counted 24 AI-related securities suits filed in 2026 by September 23rd, nearly 14% of all new securities class actions, including a suit alleging that AppLovin overstated how consistently it was improving its AI models and failed to disclose development delays to a generative AI video feature.[12]

The claims are also changing shape, as a suit filed on June 25th 2026 shows: ZoomInfo shareholders allege that management promoted the company's evolution into an AI-powered platform while omitting the effect AI was having on its legacy subscription business.[13] The D&O Diary describes this as an emerging category of AI litigation, which asks less whether the AI exists than whether companies adequately disclosed its impact on their business model.

Directors are therefore exposed for saying too much about what AI will do for the business and for saying too little about what it is doing to the business, so the recommended course of action is for the disclosure committee to review AI statements for both errors, including whether known effects of AI on revenue, pricing or customer retention have been disclosed where material.

What Is the Board's Duty to Oversee AI?

Delaware law requires directors to make a good-faith effort to ensure the company has a system for reporting the risks that matter most to the business, and where a company depends on AI, plaintiffs can be expected to argue that AI is one of those risks, although how the courts will treat that argument is not yet clear.

Definition

Oversight duty

The oversight duty is a director's obligation, under Delaware's Caremark doctrine, to make a good-faith effort to ensure that the company has an adequate system for reporting compliance and other critical risks to the board. An utter failure to attempt to put such a system in place is treated as bad faith and a breach of the duty of loyalty, which can expose directors to personal liability.

The doctrine comes from In re Caremark International Inc. Derivative Litigation, decided by the Delaware Court of Chancery on September 25th 1996, in which Chancellor Allen, approving a settlement, wrote that a director's obligation “includes a duty to attempt in good faith to assure that a corporate information and reporting system, which the board concludes is adequate, exists”. The court set a high bar, requiring “a sustained or systematic failure of the board to exercise oversight”, and called the claim “possibly the most difficult theory in corporation law upon which a plaintiff might hope to win a judgment”.[14]

The Delaware Supreme Court showed in Marchand v. Barnhill, decided on June 18th 2019, that the bar can be cleared. It allowed an oversight claim against the directors of Blue Bell Creameries after a listeria outbreak killed three people and forced a full recall, relying on the board having had “no committee overseeing food safety, no full board-level process to address food safety issues” even though food safety was a “compliance issue intrinsically critical to the company's business operation”.[15]

Boeing's directors agreed in November 2021 to settle a Caremark suit alleging that the board failed to monitor safety before the two 737 MAX crashes,[16] and the Delaware Court of Chancery approved the settlement on February 23rd 2022. Under the settlement Boeing was to recover $237.5 million from the directors' insurers, and the New York State Comptroller, a co-lead plaintiff, called it the largest monetary settlement in this type of case in the Delaware courts' history.[17]

None of these cases involved AI, but for a lender whose credit decisions run through models, or a software company whose product is an AI system, a plaintiff could argue with some force that AI is intrinsically critical in the way food safety was at Blue Bell. The Court of Chancery has, however, distinguished oversight of legal compliance from oversight of ordinary business risk, calling Caremark-type duties to monitor business risk “fundamentally different” in In re Citigroup in 2009,[18] so an AI claim framed around legal compliance or safety is likely to be stronger than one about a failed AI strategy. Either way, the board should expect a plaintiff to ask where AI risk was reported, which committee owned it and what the minutes show.

Oversight claims also reach directors personally, because Delaware does not allow a company's charter to eliminate a director's liability for a breach of the duty of loyalty or for acts not in good faith, which is where Caremark claims sit.[19] Delaware law lets a company indemnify, or reimburse, directors for judgments and settlements in suits brought by outsiders, but only for expenses in suits brought by or on behalf of the company, such as Caremark claims, while expressly allowing it to buy insurance for its directors whether or not it could indemnify them.[20] D&O insurance can therefore be the main source of funds for resolving an oversight claim, as it was at Boeing.

What Should a Company Disclose About AI Risk?

SEC rules require public companies, where appropriate, to discuss under “Risk Factors” the “material factors that make an investment in the registrant or offering speculative or risky”, and they discourage generic risks that could apply to any company.[21] According to The Conference Board, 72% of S&P 500 companies flagged AI as a material risk in their 2025 public disclosures, up from 12% in 2023.[22] A risk factor that names AI as material helps show that investors were warned, but a plaintiff may also use it to argue that the board knew AI was critical to the business, so the board's actual oversight should match the importance its disclosures give AI.

Does D&O Insurance Cover AI-Washing and Oversight Claims?

A standard D&O policy may respond to an AI-washing suit or an oversight claim, because both allege wrongful acts by directors and officers, which D&O exists to cover, but three kinds of provision can remove that cover.

AI Exclusions

Some insurers have begun adding AI exclusions to management liability forms. One large US insurer introduced an “absolute” exclusion for D&O, E&O and fiduciary liability that removes cover for loss from any claim “based upon, arising out of, or attributable to” any actual or alleged use, deployment or development of AI by any person or entity, or any insured's “statements, disclosures, or representations concerning or relating to” AI. Coverage lawyers at Hunton Andrews Kurth wrote that “the potential breadth of this exclusion cannot be overstated”.[23]

The second limb of that exclusion reaches claims over what a company has said about its AI, which is where AI-washing suits sit, and the first could reach an oversight claim after an AI failure. Policies that say nothing about AI, known as silent AI, leave the answer to argument after a claim, so every layer's wording is best read before renewal; the guide to silent AI and the new AI exclusions explains what to look for.

Conduct Exclusions

D&O policies commonly exclude deliberate fraud and illegal personal profit, usually once established by a final adjudication, with defense costs typically paid until then. An AI-washing case that ends in a finding of intentional fraud could therefore fall outside cover, and depending on the wording the insurer may seek to recover the defense costs. It is best to confirm that the exclusion applies only to the person whose conduct was adjudicated, so that one executive's fraud does not remove cover for directors who knew nothing of it.

Fines, Penalties and Investigations

Civil penalties such as those paid by Delphia and Global Predictions are often excluded from the definition of loss or covered only where the law allows them to be insured. Cover for regulatory investigations also varies, and some policies limit cover for an investigation of the company itself, so it is a good idea to ask the broker when investigation cover begins and whether it extends to the company as well as to its directors and officers.

Where Affirmative AI Coverage Fits

Mayflower Specialty writes affirmative AI coverage, meaning cover that addresses AI expressly rather than leaving it to argument. Its AI Directors and Officers Liability (AI-D&O) module is written for claims against directors and officers that arise from the company's use of AI, and AI DIC Excess is a difference-in-conditions layer over an existing tower of primary and excess policies, written to respond where those policies are silent on AI or exclude it. Both are written on a claims-made-and-reported form on A- (Excellent) AM Best rated paper backed by global reinsurers, placed through brokers and underwritten on the applicant's AI governance. Whether a particular claim is covered depends on the policy wording, so it is a good idea to ask the broker before each renewal whether any layer of the D&O program has added an AI exclusion and how it defines artificial intelligence.

What Should a Board Ask Management About AI?

A board can test its AI oversight with eight questions, and each answer should be documented well enough to show what the board knew and when.

  1. Where does the company use AI, and which of those uses could cause material harm if they failed?
  2. Which committee or executive owns AI risk, and how often does it report to the board?
  3. What evidence supports each public statement about the company's AI, and who approves those statements?
  4. Do disclosure controls cover AI statements in earnings calls, investor materials and marketing as well as in SEC filings?
  5. How is AI affecting revenue, pricing or customer retention, and has that effect been disclosed where it is material?
  6. How are AI systems tested for accuracy, bias and security, and what did the most recent tests find?
  7. What happens when an AI system causes a serious incident, and how quickly does the board hear about it?
  8. Does any layer of the D&O program exclude AI or say nothing about it?

The first two questions go to the Caremark standard, since an inventory and a named owner are the minimum evidence that a reporting system exists, and the next three go to disclosure, so a board with limited time should start with those five and record the answers in its minutes.

What Steps Should a Board Take on AI Oversight?

The recommended course of action is to put AI oversight on a documented footing before an incident or a lawsuit forces the question, and to align the D&O program with it at the next renewal, in four steps.

  1. Assign ownership: Give AI risk to a specific committee, such as audit, risk or technology, and record it in the committee's charter. Marchand turned on the absence of this kind of structure for food safety.
  2. Set a reporting cadence: Have management report on AI inventory, incidents, test results and regulatory changes on a fixed schedule, quarterly where AI is central to the product, and minute the board's questions.
  3. Bring AI statements into disclosure controls: Treat claims about AI capability like financial metrics, with supporting evidence on file and a named reviewer, and extend the review to marketing and investor materials, since the Presto order shows that the SEC examines disclosure controls as well as the statements themselves.[3]
  4. Review the D&O program at renewal: Ask the broker how each layer treats AI, and where a layer excludes AI or is silent on it, consider affirmative AI coverage or a DIC layer above the program.

Much of this evidence is also what an underwriter asks for, because Mayflower underwrites on the applicant's AI governance; the guide to how underwriters assess AI risk explains that review. The coverage gap check shows where an existing program may fall short, and boards that want to see terms can ask their broker, start an AI-D&O application or talk to the Mayflower team.

Frequently Asked Questions

What is AI-washing?

AI-washing is the practice of overstating what a company's artificial intelligence does or how much the company relies on it. The SEC settled its first AI-washing cases against two investment advisers on March 18th 2024 and settled charges against a public company, Presto Automation, on January 14th 2025. Shareholders can also bring securities class actions over such statements, and the FTC treats misleading AI claims to consumers as deception.

Can directors be personally liable for AI failures?

Directors can be personally liable for AI failures in some circumstances. Under Delaware's Caremark doctrine, as applied in Marchand v. Barnhill in 2019, directors who make no good-faith effort to put a reporting system in place for a risk critical to the business can be liable for the resulting losses. Courts have not yet decided whether AI is such a risk. Because Delaware does not let a charter eliminate this liability, D&O insurance can be the main protection for directors.

Does D&O insurance cover AI-washing claims?

A D&O policy may respond to an AI-washing claim, because such claims usually allege misstatements by directors and officers, which D&O exists to cover. Cover can be removed by an AI exclusion, by a fraud exclusion once intentional misconduct is established, or by limits on fines and penalties. Whether a given claim is covered depends on the wording of each layer of the program, which should be checked before every renewal.

What should a board ask management about AI?

A board should ask where the company uses AI and which uses could cause material harm, who owns AI risk and how often they report, what evidence supports each public AI claim, whether disclosure controls cover AI statements, how AI is affecting the business, how AI systems are tested, how incidents reach the board and whether the D&O program excludes AI or is silent on it. The answers should be recorded in minutes.

Do companies have to disclose AI risks to investors?

Public companies generally must discuss, under the SEC's risk-factor rule, the material factors that make an investment in them speculative or risky, which includes AI where it is a material risk to the business. The Conference Board found that 72% of S&P 500 companies flagged AI as a material risk in 2025, up from 12% in 2023, and recent lawsuits allege that companies failed to disclose how AI was disrupting their business.

Sources

  1. [1]Securities Class Action Filings Surge in the First Half of 2026, Cornerstone Research and Stanford Law School Securities Class Action Clearinghouse, July 29th 2026
  2. [2]SEC Charges Two Investment Advisers with Making False and Misleading Statements About Their Use of Artificial Intelligence (Release 2024-36), U.S. Securities and Exchange Commission, March 18th 2024
  3. [3]In the Matter of Presto Automation Inc. (Release No. 33-11352), U.S. Securities and Exchange Commission, January 14th 2025
  4. [4]SEC Files AI-Washing Enforcement Action Against Restaurant Technology Company, The D&O Diary, January 21st 2025
  5. [5]DOJ and SEC send warning on "AI washing" with charges against technology startup founder, DLA Piper, April 16th 2025
  6. [6]Client Alert: The First Real Test: What Saniger Means For AI-Disclosure Fraud, Quinn Emanuel Urquhart & Sullivan, June 11th 2026
  7. [7]SEC Announces Cyber and Emerging Technologies Unit to Protect Retail Investors (Release 2025-42), U.S. Securities and Exchange Commission, February 20th 2025
  8. [8]FTC Announces Crackdown on Deceptive AI Claims and Schemes (Operation AI Comply), Federal Trade Commission, September 25th 2024
  9. [9]Policy Statement Concerning the Suppression of Accuracy in Artificial Intelligence Systems (proposed), 91 FR 41638, Federal Trade Commission, Federal Register, July 7th 2026
  10. [10]Securities Class Actions Increase Again in 2024; AI-Related Filings Double, Insurance Journal (reporting Cornerstone Research and Stanford data), February 4th 2025
  11. [11]Overall Size of Securities Class Action Filings Reached New Heights in 2025, Cornerstone Research and Stanford Law School Securities Class Action Clearinghouse, January 28th 2026
  12. [12]AI-Related Securities Suit Filings Continue to Surge, The D&O Diary, September 23rd 2026
  13. [13]AI-Related Securities Litigation Continues to Evolve, The D&O Diary, July 13th 2026
  14. [14]In re Caremark International Inc. Derivative Litigation, 698 A.2d 959 (Del. Ch. 1996), Delaware Court of Chancery (opinion text hosted by New York University), September 25th 1996
  15. [15]Delaware Supreme Court Reinforces Directors' Oversight Obligations on Mission-Critical Subjects (Marchand v. Barnhill, June 18th 2019), Jones Day
  16. [16]NYS Comptroller DiNapoli and the Fire and Police Pension Association of Colorado Statements on Proposed Settlement of Boeing Lawsuit, Office of the New York State Comptroller, November 5th 2021
  17. [17]State Comptroller DiNapoli Statement on Boeing Lawsuit Settlement, Office of the New York State Comptroller, February 23rd 2022
  18. [18]In re Citigroup Inc. Shareholder Derivative Litigation, C.A. No. 3338-CC (Del. Ch. Feb. 24, 2009), Potter Anderson & Corroon, February 24th 2009
  19. [19]Delaware General Corporation Law, Section 102(b)(7), State of Delaware
  20. [20]Delaware General Corporation Law, Section 145, State of Delaware
  21. [21]17 CFR 229.105 (Item 105), Risk factors, Legal Information Institute, Cornell Law School
  22. [22]New Study: 7 in 10 Big US Companies Report AI Risks in Public Disclosures, The Conference Board, October 6th 2025
  23. [23]The Continued Proliferation of AI Exclusions, Hunton Andrews Kurth, Hunton Insurance Recovery Blog, May 28th 2025

Next step

Put Affirmative AI Coverage in Front of Your Board

Apply online and underwriting will respond within 48 hours, or send a short note if you would rather talk first.