On 22 May 2026, ICC Judge Mullen handed down his judgment in Cork v Smith.
The case was routine. A block transfer application concerning insolvency practitioners, the kind dealt with on the papers, without a hearing, dozens of times a year. A junior solicitor at Pinsent Masons LLP used the firm's AI tool to research the legal basis for releasing a liquidator from liability. The AI produced a coherent, authoritative-sounding passage purporting to set out the text of Insolvency Rule 12.37(5). The rule did not exist. The text was fabricated.
When the court queried the provision, the firm turned to AI again to draft its response. The AI produced a second fabrication, claiming the invented wording had been a summary conclusion rather than a direct quotation. The judge described the junior solicitor as having almost entirely outsourced the thinking process to the program. The firm was referred to the Solicitors Regulation Authority. The judgment served, in the judge's own words, as a public admonishment.
This did not happen in a boardroom. It happened in a back office, on a procedural point so routine that it would ordinarily have been resolved without a hearing.
That is precisely what makes it one of the most important AI cases a director should read in 2026.
AI is no longer just a tool in the boardroom
On 2 August 2026 the EU AI Act became enforceable. Three days later the World Economic Forum published a significant analysis tracing exactly where boards stand in their relationship with AI, and where that relationship is heading.
The WEF identified three stages of AI in the boardroom. First, AI-assisted document review, where AI reads board materials and surfaces analysis for directors to consider. Second, AI observers participating in real time during board discussions. Third, autonomous agents operating within predefined parameters, capable of monitoring compliance, coordinating responses and executing defined tasks without constant human instruction. Many organisations are already at stage one. Some are moving to stage two. The governance implications of stage three are only beginning to be understood.
That trajectory is not inevitable, and for professional directors it is not appropriate to simply follow it without question. Personal liability cannot be passed to an algorithm. The regulatory frameworks governing directors in every jurisdiction make that clear. The director reads the analysis, challenges the output, applies their judgment and decides. AI informs. The director decides. That sequence is the only one consistent with the personal liability framework that governs every director.
Directors have a narrowing window to prepare. AI is already reshaping the information boards receive and the decisions they oversee. The governance question boards face is not which decisions to hand to AI. It is how to ensure AI analysis is grounded, verified and transparent enough that the director can exercise meaningful judgment on everything it surfaces, and document that judgment for the record.
The adoption gap
The Diligent Institute's Q2 2026 Director Confidence Index surveyed US public company directors. It found that 82% had used generative AI in their board work in the past six months, up from 66% in September 2025.
54% said there was no guidance for directors' use of AI in place at their company.
Only 6% reported a formal AI policy specific to the board.
30% had used AI to summarise board pack and meeting materials, often among the most sensitive documents a company produces.
49% had heard of board members using publicly available consumer AI tools rather than company-approved systems for board work.
The What Directors Think 2026 report, also from Diligent Institute, found that only 8% of directors rate their board as having strong AI expertise, the lowest score across every domain surveyed. 22% have AI governance processes in place for the board's own AI usage.
Clearly adoption is accelerating, but governance frameworks are not keeping pace.
What the law now requires, and what changed on 2 August 2026
The FCA published the Mills Review on 6 July 2026, a 147-page assessment of how AI will reshape retail financial services by 2030. Its central finding on accountability was direct: the Senior Managers Regime continues to apply as AI systems become more autonomous. As autonomy increases, evidencing meaningful human control becomes progressively harder. The pressure falls upward, to the senior manager, and through them, to the board. Accountability does not transfer to the machine. It stays with the person.
On 2 August 2026, three weeks ago, the EU AI Act moved from future compliance project to live enforcement. The European AI Office became formally entitled to exercise its powers to investigate and enforce obligations on providers of general-purpose AI models. Transparency obligations now apply to many AI systems in market. The European AI Office can request information and documentation, obtain access to models for evaluation, require corrective measures and impose fines of up to €15 million or 3% of worldwide annual turnover.
For boards of companies deploying AI systems that touch the EU market the questions are direct: which systems are covered, who is accountable for compliance on each, and can the organisation produce technical documentation, model provenance, transparency notices and vendor commitments if a regulator asks? For directors of fund structures, the questions are different but equally important: do any portfolio companies have EU AI Act exposure, is the fund manager using AI systems that fall within scope, and what oversight does the board have over AI tools being used in the management of the fund? The obligation to understand the exposure is the same. The specific questions depend on the structure.
The high-risk system requirements were deferred to December 2027 under the Digital Omnibus. That is runway, not a reprieve. Boards that wait for 2027 will be building their governance frameworks under regulatory pressure rather than ahead of it.
In Delaware, the courts have established through the Caremark and Marchand decisions that boards must install dedicated oversight of mission-critical risks. Academic commentary published in 2026 has argued directly that AI now qualifies as mission-critical under this standard, and that boards which cannot demonstrate structured AI oversight carry personal exposure that charter protections do not cover.
US AI rules remain fragmented and contested. A single copy-and-paste governance model will not work across EU and US jurisdictions simultaneously. Boards with transatlantic exposure need frameworks that address both.
The financial exposure
In the United States, AI-related securities class actions are accelerating sharply. According to NERA, 18 AI-related federal securities class actions were filed in the first half of 2026 alone, already exceeding the 17 cases filed during the whole of 2025, and arriving at nearly twice the prior year rate. These are US federal filings, but the exposure is not confined to US-incorporated companies. Directors of funds with US investors, US general partners or US-listed portfolio companies sit within the reach of this litigation environment. AI cases accounted for 13% of all securities class action filings in H1 2026 but a disproportionately large share of alleged investor losses. Average settlement values reached $54 million, the highest in a decade. As EU AI Act enforcement matures and the FCA's accountability framework develops, equivalent exposure in European and offshore jurisdictions will follow.
The litigation theory is evolving. The securities class action filed against ZoomInfo on 25 June 2026 represents what commentators have described as the next phase. The complaint does not allege that ZoomInfo fabricated its AI initiatives. It alleges that management accurately described its AI initiatives but failed to disclose that AI was simultaneously disrupting its own legacy business model. A shift from alleged AI washing to alleged under disclosure of AI-related business risk.
The trend is consistent. More exposure, more sophistication in how courts and plaintiffs understand what directors owe in the AI context, more personal consequence for boards that have not documented their AI governance decisions.
Why human judgment becomes more important, not less
The WEF analysis makes an important point that is worth stating clearly. As AI becomes more embedded in governance processes, human judgment does not become less important. It becomes more important.
AI can outperform directors in processing volumes of information, identifying inconsistencies and surfacing blind spots in real time. But governance demands ethical reasoning, balancing competing stakeholder interests, assessing long-term societal impact and exercising accountability for outcomes. Those capabilities cannot be computed. They cannot be transferred to a system. They rest with the director.
The most effective directors will be distinguished less by what they know and more by how they think. Critical reasoning, intellectual curiosity, ethical judgment and the ability to challenge assumptions when evidence conflicts with incentives. Emotional intelligence, reading people, building trust and navigating ambiguity, also becomes a stronger differentiator as routine analytical work is assisted by machines.
A board where every director has read the same AI summary of a board pack, drawn the same AI-generated conclusions and consulted the same AI tool about a governance question is not a board exercising independent judgment. It is a board that has introduced a single point of analytical failure into its most important decision-making process. The WEF identifies this directly - boards must govern AI actively, not simply consume its outputs.
What good AI governance at board level looks like
The WEF analysis identifies five practical priorities for boards:
Build sufficient AI literacy at board level to oversee AI-related risks and opportunities effectively. The 8% of boards rating themselves as having strong AI expertise is not a foundation for meaningful oversight.
Revisit board skills matrices and succession planning. Judgment, critical thinking and ethical reasoning must remain central capabilities as AI assists with specialist knowledge and analytical work.
Define clearly that AI informs board decisions and never replaces them. Establish explicit boundaries on AI use that preserve the director's judgment, accountability and final authority at every stage.
Establish accountability, audit and monitoring mechanisms for AI-assisted analysis. A director who questioned an AI tool's output and documented their reasoning is in a different legal position from one who accepted it without challenge.
Integrate AI governance into existing governance, risk and compliance frameworks rather than treating it as a standalone initiative. The EU AI Act, the FCA Mills Review and the Marchand standard all point in the same direction: AI governance is board governance, not a technology workstream.
The question is no longer whether AI will transform governance. The question is whether boards are prepared to lead that transformation, with human judgment, human accountability and human liability firmly at its centre.
Governance is the competitive advantage
The boards that will navigate the AI decade most effectively are not those that resist AI. They are those that have decided, deliberately, documented and on the record, how they govern it.
That means knowing which AI systems the organisation deploys, who is accountable for each, and whether the board can evidence meaningful human oversight at the point where AI outputs inform board-level decisions. It means building the AI literacy to ask the right questions rather than accepting AI outputs as authoritative. It means ensuring the director always reviews, always challenges and always decides.
The boards that treat AI governance as a competitive capability rather than a compliance exercise will set the standard for the next era of corporate oversight.
MyDirector-OS was built specifically for the professional director navigating exactly the governance landscape this article describes.
BoardLens is the jurisdiction-aware AI document review feature within MyDirector-OS. When a director adds a board pack linked to a specific appointment, BoardLens reviews it through the lens of the regulatory framework that governs that appointment, identifying risks, decisions required, actions and potential questions for the board. Every review is grounded in a verified regulatory corpus covering 14 jurisdictions, independently evaluated for accuracy. The director knows exactly what the AI is drawing from, can challenge the output and applies their own judgment to everything it produces. BoardLens also generates a voice briefing so the director can listen to a summary before walking into the meeting. It does not replace the director. It prepares them.
The Director's Assistant is a private governance advisor available throughout the MyDirector-OS workspace. It answers governance questions grounded in the specific regulatory framework of the director's appointments, not general principles. It cites the specific instrument it is drawing from. It acknowledges when it cannot find a verified answer rather than inventing one.
Both tools operate within defined guardrails. They do not provide legal advice. They do not speculate beyond the verified corpus. They do not answer outside the scope of the director's governance role. They do not fabricate. Where the answer is not in the corpus, they say so. That is the direct and deliberate response to cases like Cork v Smith, where the absence of guardrails allowed confident, plausible, entirely fabricated output to be presented as fact.
Both tools are stateless. No board pack content is retained after review. No conversation is stored beyond the director's own workspace. No content is used to train any AI model. The director's data belongs to the director.
The director reads the analysis. The director challenges the output. The director decides.
That is not generic AI. That is governed AI. Built for the professional director.
