The duty of care requires directors to act with the level of knowledge and diligence that a reasonably prudent person in a similar position would exercise. For decades, this standard has been applied to financial literacy: directors are expected to understand financial statements, capital structure, and the financial risks facing the company. Those who cannot are considered unfit for the role.
In 2026, the same standard is beginning to apply to AI. As AI becomes material to corporate strategy, operations, and risk — and as regulatory frameworks create explicit governance obligations — directors who cannot demonstrate basic AI literacy are increasingly exposed to personal liability for the governance failures that result from their ignorance.
The Literacy Gap in Numbers
The scale of the problem is significant:
- 66% of board directors report having limited to no knowledge or experience with AI
- 34% of boards have at least one director with substantive AI expertise
- Only 12% of boards have conducted formal AI literacy training for all directors
- 71% of directors say they rely entirely on management's assessment of AI risk without independent evaluation
- 58% of boards have not discussed AI governance at a board meeting in the past six months
These numbers describe a governance structure that is systematically unable to fulfil its oversight responsibilities with respect to one of the most significant risk categories facing modern enterprises.
What the Duty of Care Now Requires
The duty of care is a legal standard, not a best practice. It requires directors to be informed. In the context of AI, being informed means being able to:
Evaluate Management's AI Strategy
Directors cannot challenge what they do not understand. A board that approves an AI deployment strategy without being able to evaluate its risks — technical, regulatory, reputational — has not exercised the duty of care. It has rubber-stamped a management decision without independent scrutiny.
Assess Regulatory Compliance
The EU AI Act, the UK's evolving AI regulation framework, and sector-specific AI rules create material compliance obligations. Directors who cannot assess whether management's compliance representations are adequate — because they lack the knowledge to evaluate them — are exposed to liability if those representations prove false.
Identify Red Flags
Effective board oversight requires the ability to recognise when something is wrong. In the context of AI, red flags include: AI systems deployed without adequate testing, AI-assisted decisions made without human oversight, AI vendor contracts that do not include appropriate data protection provisions, and AI incident reports that are incomplete or minimised. Directors who cannot recognise these red flags cannot fulfil their oversight function.
The Liability Exposure
Director liability for AI governance failures is no longer theoretical. Several categories of exposure are now clearly established:
| Failure Type | Liability Exposure | Precedent |
|---|---|---|
| EU AI Act non-compliance | Up to 7% of global turnover | Regulatory enforcement |
| Data breach via AI system | GDPR penalties + civil claims | Established GDPR case law |
| AI-assisted discrimination | Employment tribunal + regulatory | Emerging case law |
| Shareholder derivative claims | Personal director liability | US precedent expanding to UK |
| Investor misrepresentation | Securities law exposure | SEC AI disclosure guidance |
"The question is no longer whether directors can be held personally liable for AI governance failures. The question is when the first significant case will be decided — and what standard it will set for the boards that follow."
What Adequate AI Literacy Looks Like
AI literacy for board directors does not require technical expertise. It requires governance competence — the ability to ask the right questions, evaluate the answers, and recognise when additional scrutiny is warranted. Specifically, directors should be able to:
- Explain the difference between generative AI and agentic AI, and why the distinction matters for governance
- Describe the EU AI Act's risk-tier framework and identify which tier applies to the company's key AI deployments
- Articulate the key questions to ask management about AI risk, including data governance, model monitoring, and incident response
- Evaluate whether the company's AI governance framework is proportionate to its AI exposure
- Identify the circumstances under which AI-assisted decisions require additional human oversight
Building Board AI Literacy: A Practical Framework
Boards that take this obligation seriously should implement a structured AI literacy programme:
- Baseline assessment: Evaluate current AI knowledge across all board members using a structured questionnaire
- Targeted training: Commission governance-focused AI training — not technical training — for all directors, with particular depth for audit committee members
- Expert access: Ensure the board has access to independent AI expertise — whether through a Fractional CAIO, an AI advisory board, or an AI governance platform — that does not rely solely on management
- Regular briefings: Schedule quarterly AI governance briefings as a standing board agenda item
- Skills matrix update: Update the board skills matrix to include AI governance competence as a required capability, and factor it into director recruitment and succession planning
The boards that act on this now will be ahead of the regulatory curve. Those that do not will find themselves facing the same conversation about AI literacy that they faced about financial literacy a generation ago — but with the added urgency of an enforcement regime that is already in motion.
Veriqo AI Shadow Board
Independent AI Intelligence for Your Board
Give your board independent, structured AI analysis that does not rely on management's framing. Five AI executives. Zero agenda. Full audit trail.