Current through March 20, 2026
Artificial intelligence has moved from the innovation lab into the decision engine of the modern company. It now screens job applicants, ranks borrowers, flags insurance claims, scores patients for intervention, prioritizes customer complaints, predicts fraud, and recommends legal or compliance actions. That shift matters because the legal risk of AI does not turn on whether software was involved; it turns on whether a company allowed a consequential decision to be made without sufficient governance, disclosure, testing, oversight, and human accountability. For CEOs and boards, the core mistake is to treat AI as a technical procurement issue instead of a corporate-risk issue. Once an AI system influences hiring, lending, healthcare access, insurance, legal services, or other high-stakes decisions, it touches the same body of law that already governs discrimination, consumer protection, fiduciary oversight, deceptive practices, and truthful corporate disclosures. In other words, AI does not create a liability-free zone. It simply changes the mechanism through which familiar duties can be breached. For a business community like Ann Arbor’s, where growing companies often combine software ambition with regulated operations, the practical question is no longer whether AI creates legal exposure. The practical question is which governance choices reduce that exposure before a regulator, plaintiff, investor, or judge asks why no one was watching the machine that mattered. ¹²³⁴
The first legal principle every leadership team should internalize is that responsibility does not disappear when a model, vendor platform, or automated workflow is inserted between the company and the final outcome. In most real-world deployments, the company remains the actor that chose the tool, defined the objective, selected the data inputs, accepted the output thresholds, and decided how much human review would remain in the process. That means liability can attach even where the company did not “build the AI” in any engineering sense. A board cannot sensibly say that the harm belonged to the vendor when the company deployed the system into its own business process, relied on it in a mission-sensitive context, and failed to demand the reporting needed to understand whether it was working lawfully. Likewise, a CEO cannot plausibly reduce the issue to “the algorithm made the call” when management selected the algorithm, approved the business case, and failed to put escalation rules around adverse outcomes. The law is especially unsympathetic where automation becomes a way to scale poor judgment. What courts and regulators tend to look for is whether the company created a reasonable information and control structure around the technology. If the answer is no, then the AI system becomes evidence of weak governance rather than a shield from liability. That is why sophisticated AI governance begins with corporate accountability, not with marketing claims about innovation or efficiency. ¹²
For boards, the most important corporate-law lens remains fiduciary oversight. Delaware law does not impose strict liability every time a business problem occurs, but it does require directors to make a good-faith effort to establish reporting and monitoring systems for central compliance and operational risks. In Marchand v. Barnhill, the Delaware Supreme Court emphasized that directors may face loyalty-based oversight exposure when there is an “utter failure” to attempt to assure that a reasonable reporting system exists, particularly where the risk is “mission critical.” In Blue Bell, that risk was food safety. In many companies today, however, AI may be embedded in a similarly central function: underwriting at an Insurtech company, applicant screening at a recruiting platform, risk scoring in a financial product, triage in a health-services workflow, or decision support inside a legal-services business. The lesson for boards is not that every AI failure creates a Caremark-style claim. The lesson is narrower and more important: when AI touches a company’s core legal, regulatory, or operational risk, the board must be able to show that it required a board-level information flow. A board packet that celebrates AI adoption but says little about model limitations, drift, overrides, complaints, appeal outcomes, or adverse-impact testing is not a governance system. It is a strategy memo. Delaware’s message is that boards need a real reporting architecture for central risks, not occasional optimism from management after the fact. ¹
That oversight duty has immediate consequences for CEO behavior as well. A chief executive who drives AI deployment without building a legal-control environment can create a record that is awkward in both litigation and enforcement. Email traffic that pushes for faster automation, lower labor costs, or full removal of manual review can become damaging when paired with weak validation records and board materials that never confronted the downside. By contrast, management teams that document governance choices place themselves in a far better position. The strongest record usually shows that the company identified where AI would affect protected rights or material business outcomes, mapped the business owner responsible for each use case, tested performance before launch, documented foreseeable misuse, assigned escalation pathways for anomalies, and established recurring reporting to senior management and the board. This is also where the National Institute of Standards and Technology’s AI Risk Management Framework becomes useful. It is not itself a statute, but it gives companies a disciplined vocabulary for governing AI risk through processes that are meant to be practical, adaptable, and use-case sensitive across industries. That matters because judges, regulators, investors, and counterparties often ask a simple question after an incident: what framework were you using? A company that has no coherent answers looks improvised. A company that can point to a structured governance approach looks far more credible, even before anyone debates whether the final outcome was unlawful. ²
The emerging statutory picture reinforces that shift from abstract governance to concrete duties. Colorado’s artificial intelligence law is especially important because it is one of the clearest U.S. examples of a state directly regulating high-risk AI used in consequential decisions. The law defines “high-risk” systems broadly enough to matter whenever AI makes, or is a substantial factor in making, consequential decisions involving areas such as employment, lending, education, housing, insurance, healthcare, essential government services, and legal services. It also focuses not only on developers but on deployers, meaning companies that use the system in the real world. That is a crucial point for CEOs who assume the vendor bears the meaningful legal burden. Under Colorado’s framework, deployers are expected to implement a risk-management policy and program, conduct impact assessments, provide notices, give consumers opportunities to correct data, and, for adverse consequential decisions, provide an appeal process that includes human review when technically feasible. The law also ties enforcement to deceptive trade practice authority and reserves enforcement to the attorney general. Just as significantly, Colorado’s law creates incentives around documented governance by recognizing an affirmative-defense structure tied to compliance with recognized risk-management frameworks and corrective measures. The compliance date was later pushed from February 1, 2026 to June 30, 2026, which gives companies more time, but not a reason to wait. Delay is not the same as forgiveness, and the companies that treat the extra time as dead space will be the least prepared when scrutiny arrives. ²³
Even companies based in Michigan should not dismiss the European Union’s AI Act as someone else’s problem. The Act entered into force on August 1, 2024, with staged obligations already taking effect. The first rules, including prohibited AI practices and AI literacy duties, began applying on February 2, 2025. The rules for general-purpose AI models began applying on August 2, 2025, and the Act is generally scheduled to become fully applicable on August 2, 2026, subject to certain transition periods. For U.S. businesses, the significance is less about geography in the abstract and more about commercial reach. If a company develops, offers, integrates, or deploys AI systems into products or services that touch the EU market, the Act can become operationally relevant even where leadership thinks of itself as a domestic business. More broadly, the EU Act matters because it reflects the direction of travel in serious AI regulation: high-risk uses are treated as governance-intensive; documentation, transparency, and risk management are expected; and “trustworthy AI” is not left to branding language alone. Boards should pay attention to that logic even when a particular company falls outside direct EU enforcement, because customers, enterprise partners, investors, and procurement teams increasingly borrow from the same expectations. In practice, the EU is helping set the baseline for what mature AI governance looks like, and that baseline is steadily influencing contract terms, diligence requests, and regulator expectations far beyond Europe. ⁴
A separate and often underestimated exposure lies in disclosure risk. Public companies, regulated firms, and companies raising capital frequently describe their AI capabilities in investor materials, pitch decks, customer-facing collateral, website claims, and earnings narratives. The temptation is obvious: AI sounds modern, scalable, and margin-enhancing. But that marketing instinct can create legal problems when the company overstates what the technology actually does, fails to disclose major limitations, or implies that AI controls are more mature than they really are. The SEC’s 2024 enforcement actions against two investment advisers over misleading statements about their supposed use of AI were an early and highly visible warning. The message was simple. The Commission was prepared to treat inflated AI claims like any other potentially false or misleading representation. For boards and CEOs, the lesson reaches beyond registered investment advisers. Whenever a company says it uses AI in a way that could matter to investors, customers, or counterparties, leadership should assume that ordinary rules against material misstatements still apply. That means AI governance and disclosure governance have to be connected. Legal and compliance teams should know what marketing says. Investor-relations personnel should know what the systems actually do. Product teams should not be free to use “AI-powered,” “automated expert analysis,” or “proprietary machine intelligence” as mood-setting phrases unsupported by real functionality. In the current environment, sloppy AI promotion is not just embarrassing. It can become evidence that management preferred the story of AI over the reality of AI. ⁵
One of the most common leadership errors is to treat third-party AI procurement as a liability transfer. Buying rather than building can reduce engineering burden, but it does not reliably reduce accountability. In fact, the use of vendor systems often creates a more complicated governance problem because the company may not fully understand training data provenance, model limitations, excluded use cases, bias controls, retraining intervals, fallback rules, or how much human review the product assumes. Colorado’s statutory structure captures this nicely by imposing duties on both developers and deployers and by expecting developers to provide meaningful documentation about foreseeable uses, limitations, evaluation methods, outputs, and monitoring expectations. For boards and CEOs, that should change the way vendor contracting is handled. The AI contract is not just a software license; it is part of the company’s liability architecture. A prudent company wants documentation rights, audit rights where feasible, incident-notification obligations, cooperation duties for investigations, commitments regarding testing and limitation disclosures, and a clear statement of what the system is not designed to decide. That last point is vital. Many legal problems arise not because the model fails at its intended use, but because the business quietly extends it into adjacent uses without revalidation. A résumé-screening tool becomes a promotion-ranking tool. A fraud model becomes a customer-termination tool. A chatbot becomes quasi-legal guidance. Every such stretch increases the chance that the company drifts from a product description into an ungoverned decision regime. ²³
Human review is often described as the cure for AI risk, but the law is moving toward a more skeptical and more realistic question: was the human review meaningful? A ceremonial human sign-off attached to a model recommendation will not carry much weight if the reviewer lacked authority, time, training, or access to the underlying reasoning and data issues. Colorado’s law is instructive here because it does not merely praise human involvement in the abstract; it connects human review to appeals and adverse consequential decisions where technical feasibility allows. That reflects a broader truth. Human review matters most when it is designed as a legal control rather than as a branding device. The reviewer must know when to override the system, what error patterns to watch for, how to escalate uncertain cases, and how to respond when the individual affected contests the result. For boards, this means that the right oversight questions are concrete. Who can reverse the model? Under what criteria? How often does that happen? Are appeals clustered around particular populations, inputs, or use cases? Are reviewers trained to identify data-quality problems or proxy discrimination? Does the company track whether reviewers actually disagree with the model, or do they function as a rubber stamp? Meaningful human review is expensive because it requires staffing, training, and documentation. But that cost is precisely why it matters legally: it demonstrates that the company chose accountability over the fiction that algorithmic speed alone is a defense. ³
The most defensible companies also treat AI incidents as governance events, not only as technical bugs. A failed model update, unexplained drift, spike in complaints, unexpected override rate, regulator inquiry, or discovery of skewed outputs should trigger a response process that looks more like an internal investigation than a product tweak. Management should be able to reconstruct who approved the deployment, what assumptions were tested, what limitations were documented, what information reached the board, and whether the system was operating inside its intended use. Delaware oversight law makes that paper trail important because liability disputes often turn on whether leaders can show a good-faith effort to put reporting systems in place. NIST’s framework makes it equally clear that AI risk management is not a one-time launch exercise; it requires ongoing measurement, adaptation, and governance. When a company lacks logs, testing records, version controls, escalation notes, and decision rationales, it loses the ability to tell a persuasive story about diligence. Worse, it can create the appearance that management preferred opacity because transparency would have forced uncomfortable choices. The legal stakes grow quickly when the company kept the automation but discarded the evidence. In that scenario, the absence of documentation becomes its own operational fact, one that plaintiffs and regulators can frame as indifference rather than oversight. Good incident response, by contrast, gives leadership a chance to show that it did not ignore warning signs once the system moved from theory into real effects. ¹²
For Ann Arbor businesses, the strategic takeaway is that AI governance should be scaled to consequence, not to company size. A midsize business using AI to rank applicants or determine customer eligibility can face more serious legal exposure than a much larger business using AI only for internal drafting or scheduling. Boards therefore should stop asking the abstract question, “Do we use AI?” and start asking the narrower question, “Where does AI influence a person’s rights, opportunities, price, eligibility, treatment, or professional outcome?” Once that map exists, governance becomes far more manageable. The board can insist on regular reporting for the handful of uses that actually matter, management can build controls proportionate to risk, and counsel can focus on the places where litigation or enforcement is plausible rather than hypothetical. In practical terms, this means boards should expect to see AI surfaced in enterprise-risk discussions, committee agendas, internal audit planning, vendor diligence, and disclosure review. CEOs should expect AI deployment plans to move through legal, compliance, and risk functions before becoming operational mandates. And general counsel should resist the temptation to frame the issue only as privacy or only as discrimination or only as contract drafting. High-stakes AI is usually a layered problem. It implicates corporate governance, operational design, customer-facing fairness, recordkeeping, and external representations all at once. The companies that avoid AI-driven liability will not be the ones that avoided AI entirely. They will be the ones that governed it like the consequential business process it has become. ¹²³⁴⁵
The broad conclusion is straightforward. When AI automates high-stakes decisions, the legal question for CEOs and boards is no longer whether the system is innovative. The legal question is whether leadership treated it as a mission-sensitive source of corporate risk. Delaware oversight doctrine points boards toward reporting systems for central risks. NIST provides a practical governance framework that can help show reasoned risk management. Colorado demonstrates that states are willing to impose specific duties on developers and deployers in consequential decision settings. The EU AI Act shows that documentation, transparency, and staged compliance are becoming normal expectations in serious regulation. SEC enforcement shows that inflated claims about AI can become a securities or disclosure problem even before an underlying model failure causes direct harm. Taken together, those frameworks lead to one practical rule: a company is far safer when it can prove that humans designed the controls, reviewed the outcomes, documented the limitations, and informed the board, than when it simply says the AI system performed as intended. In the years ahead, the legal winners are unlikely to be the companies with the flashiest AI narrative. They are more likely to be the companies whose minutes, policies, contracts, disclosures, testing records, and escalation paths show that someone in authority understood a basic truth: automated decisions may be generated by software, but liability is still governed by human responsibility. ¹²³⁴⁵
Contact Tishkoff
Tishkoff PLC specializes in business law and litigation. For inquiries, contact us at www.tish.law/contact/. & check out Tishkoff PLC’s Website (www.Tish.Law/), eBooks (www.Tish.Law/e-books), Blogs (www.Tish.Law/blog) and References (www.Tish.Law/resources).
Footnotes
- Marchand v. Barnhill, 212 A.3d 805 (Del. 2019). https://bclawreview.bc.edu/articles/109/files/639c133623aaf.pdf
- National Institute of Standards and Technology, Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1 (2023). https://nvlpubs.nist.gov/nistpubs/ai/nist.ai.100-1.pdf
- Colorado General Assembly, SB24-205, Consumer Protections for Artificial Intelligence (2024), as amended by SB25B-004, Increase Transparency for Algorithmic Systems (2025). https://leg.colorado.gov/bills/sb24-205
- Regulation (EU) 2024/1689, Artificial Intelligence Act; European Commission, AI Act implementation materials and timeline notices dated February 3, 2025 and August 1, 2025.
https://eur-lex.europa.eu/eli/reg/2024/1689/oj/eng - U.S. Securities and Exchange Commission, Press Release 2024-36, SEC Charges Two Investment Advisers with Making False and Misleading Statements About Their Use of Artificial Intelligence (March 18, 2024). https://www.sec.gov/newsroom/press-releases/2024-36
This publication is for general informational purposes and does not constitute legal advice. Reading it does not create an attorney-client relationship. You should consult counsel for advice on your specific circumstances.
Top of Form
Bottom of Form
