Can Boards Rely on AI-Assisted Management Reports?

Under corporate law, boards of directors have long had the right to rely on reports and other information supplied by management. This “right of reliance” derives from the board’s power to delegate day-to-day operational responsibility to management. However, it is unavailable when the board is on notice that reliance may be unwarranted, which creates a duty to confirm management’s judgment and diligence in the preparation of reports to the board and its committees.

The increasing use of AI to prepare those reports has complicated the situation. For most organizations, AI can strengthen consequential corporate decisions, helping leadership explore alternatives, challenge assumptions, and identify implications that might otherwise escape attention. However, the current risk environment calls for greater awareness of how much AI is contributing to management-to-board reports.

AI may influence management’s evaluation of an issue at several levels before it reaches the boardroom. An analyst’s summary can become a department’s forecast, then an executive recommendation. Errors or unsupported assumptions can accumulate while their origins become less visible. Underlying data can also be simulated or inputted using AI. Boards need an understanding of where AI enters the reporting process, where verification occurs, and who takes responsibility for the resulting conclusions.

Boards need to do more than just ask, “Did AI write this?” Rather, they should ask, “Can we trace this recommendation to credible evidence and data, understand how it was developed, and defend the judgment behind it?” The following four-part framework can guide that inquiry:

Data and information: Establish the foundation. Every recommendation should begin with trustworthy inputs. Directors should understand where material information originated, whether it is current and complete, and which figures represent observed results, estimates, or projections. AI-generated assertions must not quietly become accepted facts; assumptions and references should have identifiable sources. Uncertainty and any interpolation should remain visible throughout the process.

Analysis: Examine how the evidence was interpreted. AI can help compare scenarios, test assumptions, and explore relationships across large amounts of information. Management should explain the analytical approach and its limitations, the level of confidence in the data and analysis, , and the method of checking important results or conclusions. Directors need to know enough about the process to determine whether the conclusion changes under different assumptions. A polished presentation is not evidence that the underlying analysis is sound.

Insights: Connect findings to the company’s circumstances. Analysis becomes useful when it illuminates what matters for the organization. An option that appears financially attractive may create unacceptable consequences. Management should explain how it interpreted the findings, which competing explanations it considered, and where organizational knowledge changed or challenged AI’s output. This is where context and human judgment become especially important.

Decisions: Make accountability explicit. Management should “own” the recommendation and explain its tradeoffs. Directors should understand why the proposed course is preferable to reasonable alternatives, what uncertainties remain, and what developments would warrant reconsideration. AI can inform that judgment; accountability remains with both those who offer the recommendation and those who make the decision.

The goal is to determine whether management has combined AI’s analytical capabilities and efficiency with human judgment in a manner sufficient to support informed decision-making. The appropriate balance will depend on the decision’s significance, the uncertainty of the evidence, and the consequences of error. Management should demonstrate that material inputs were verified, assumptions and alternatives were meaningfully challenged, and the recommendation reflects the organization’s mission and circumstances.

The practical test is whether directors understand the basis for the recommendation, have satisfactory answers to material concerns, and can explain why proceeding is reasonable.

Traceability is the ability to follow a recommendation and ultimate decision back through its insights, analysis, and evidence. Defensibility is the ability to explain why the decision was reasonable given the information, alternatives, and uncertainties at the time. Neither requires directors to recreate management’s work. It does, however, require discipline from board leadership to pursue the inquiries. The role of AI is to strengthen judgment and enhance the efficiency and effectiveness of decisions while preserving a clear, reviewable basis for those decisions that is consistent with stakeholder interests and long-term organizational viability.

For some leadership teams, such an approach will seem ponderous and ineffective. And that’s understandable when compared with past practices. But the injection of AI into the process changes the equation, not only to the extent it replaces human judgment with machine learning, but also to the extent that it injects unprecedented risks into the analytical and deliberative processes. Decision-making necessarily becomes more complex when AI is involved.

State corporate law has yet to adopt standards for board oversight of AI deployment. We do not know, for example, if the forgiving Caremark approach to director liability will extend to board oversight of AI. Yet there are clear warning signs of a lack of leadership accountability emerging from litigation claims, early judicial decisions, and policy discussions on AI regulation. In such an environment, the board that eschews scrutiny of AI-influenced management reporting does so at its own peril.

Good corporate governance should include a decision-making process that scrutinizes how AI was used in preparing any management reports—at least until case law indicates that such scrutiny is no longer necessary. The general counsel, perhaps teaming with the chief technology officer, is a logical senior executive to guide the board through this process.

Michael W. Peregrine is a retired attorney, a fellow of the American College of Governance Counsel, and an executive fellow with healthcare consulting firm SullivanCotter. Aaron Sorensen is a senior partner at Lotis Blue Consulting, an affiliate of SullivanCotter.

Leave a Reply

Your email address will not be published. Required fields are marked *