Skip to content

Menu

LexBlog, Inc. logo
NetworkSub-MenuBrowse by SubjectBrowse by PublisherJoin the NetworkGet StartedSubscribeSupportContact
Search
Close

Guest Post: The UK Board’s AI Blind Spot

By Kevin LaCroix on August 13, 2026
Email this postTweet this postLike this postShare this post on LinkedIn

Table of Contents

  • Two duties, one country
  • The extraterritorial hook few boards see coming
  • A moving deadline, not a vanishing one
  • The UK layer most people miss
  • What this means for D&O practitioners
  • About the author
Paul Noon

In the following guest post, Paul Noon,  OBE, Emeritus Professor of AI and Innovation and former Deputy Vice Chancellor at Coventry University, argues that UK company directors face growing legal and governance risks from AI under both the UK Companies Act and the EU AI Act, whose broad extraterritorial scope can apply even to UK companies with no EU presence if their AI systems affect people in the EU. The author also considers the implications for U.K. boards. We would like to thank Paul for allowing us to publish his article on our site. Here is his article.

*****************************************

This publication has already made the case, convincingly, that AI governance is a fiduciary duty under Delaware law, and that AI risk disclosure in 10-K filings creates its own securities exposure for public companies. Both arguments assume a US frame of reference: Caremark oversight duties, SEC disclosure, securities litigation. For the many boards sitting outside that frame, in the UK, or anywhere with meaningful EU customer or operational exposure, a different and less discussed collision is forming, between an old UK statute and a very new EU one. It is worth boards’ and their D&O programmes’ attention now, not in 2027 or 2028, when the headline compliance deadlines land.

Link to Two duties, one country Two duties, one country

UK company directors owe two statutory duties that matter here. Section 172 of the Companies Act 2006 requires a director to act in the way they consider, in good faith, most likely to promote the success of the company, having regard to, among other things, the likely long-term consequences of any decision and the desirability of maintaining a reputation for high standards of business conduct. Section 174 requires a director to exercise reasonable care, skill and diligence, judged by a two-part test: the general knowledge, skill and experience reasonably expected of anyone carrying out that role, and, where it is higher, the knowledge, skill and experience the individual director actually has.

Neither section mentions artificial intelligence. Both are drafted to bite on foreseeable risk, and AI governance has been squarely foreseeable for UK boards for some time now. A director with genuine sector expertise, or one who has been briefed on AI risk and done little with it, faces a materially higher bar under section 174’s subjective limb than a generalist director who was never briefed at all. That is a considerably lower threshold for a claimant to clear than the Delaware Caremark standard, which generally requires a showing of bad faith, a sustained or systematic failure of oversight, rather than ordinary negligence.

Link to The extraterritorial hook few boards see coming The extraterritorial hook few boards see coming

Layered on top of that domestic exposure is the EU AI Act’s reach, which is broader than most UK boards assume. Article 2 catches not only providers placing AI systems on the EU market, but providers and deployers established anywhere in the world where the output produced by an AI system is used in the Union. That is a much lower bar than the “targeting” test most UK boards learned to apply under GDPR, which requires intentionally aiming at EU customers. A UK company with no EU subsidiary and no interest in EU customers can still end up in scope. If a hiring tool or a credit-scoring system it built or bought produces an output that affects someone sitting in the EU, that is enough to bring the Act’s obligations home.

Link to A moving deadline, not a vanishing one A moving deadline, not a vanishing one

The compliance timetable has just moved, which changes the shape of this exposure without removing it. On 29 June 2026 the Council of the EU gave final sign-off to the Digital Omnibus package, following the European Parliament’s endorsement on 16 June, confirming that high-risk obligations for stand-alone Annex III systems, covering employment, credit, education, essential services and similar use cases, are deferred to 2 December 2027, and that AI embedded in regulated products under Annex I is deferred further, to 2 August 2028. What has not moved is the core Article 50 obligation requiring providers and deployers to disclose to individuals that they are interacting with an AI system, which remains live from 2 August 2026 regardless of the Omnibus delay. A board that reads the Omnibus delay as “AI is now a 2027 problem” is making exactly the kind of oversight error section 174 exists to catch. The obligation to have identified the exposure, and to be building toward it, does not wait for the compliance deadline.

Link to The UK layer most people miss The UK layer most people miss

There is a UK domestic factor compounding all of this. Section 80 of the Data (Use and Access) Act 2025 came into force on 5 February 2026, replacing UK GDPR Article 22 with a new Article 22C, which gives individuals a right to transparency, to human review, and to contest automated decisions made about them. Any UK board using AI in hiring, credit, insurance or similar automated decisions is now managing three overlapping accountability regimes at once: domestic company law, domestic data protection law, and an extraterritorial EU regulatory regime, frequently with a single, thin governance framework covering all three, or none at all.

Link to What this means for D&O practitioners What this means for D&O practitioners

For D&O placement and coverage, the practical questions this raises are different from the US securities-disclosure conversation this blog has already covered well. Does the policy’s regulatory investigation coverage extend to an EU regulator investigating a UK-incorporated insured with no EU establishment, given how broadly Article 2 is drafted? Is AI-related exposure being treated as an implicit carve-out under an existing cyber or technology E&O exclusion, rather than something anyone has actually underwritten on purpose? And, most practically, underwriters assessing section 174 exposure will increasingly want to see the same kind of evidence a Delaware court looks for under Caremark: a named board-level owner for AI risk, a documented risk register, a defined review cadence, and minutes that show real discussion rather than a five-minute AI update tacked onto a routine board meeting. I set out what that evidence base looks like in practice in the PAIGE Framework, a five-pillar model, Policy, Accountability, Intelligence, Governance Mechanics, Ethics, for board-level AI governance. Boards that can produce that evidence have a genuinely stronger section 174 defence than boards that cannot, regardless of which jurisdiction ultimately hears the claim.

The Caremark and 10-K conversations this blog has run this year are necessary reading for any board with US exposure. But for the sizeable number of UK and European boards, and for the US boards with EU customers or operations, who assume that conversation is the whole picture, it is not. The Companies Act has always expected UK directors to identify and manage foreseeable risk. The EU AI Act has just confirmed that a great many of them are managing it whether they intended to or not, and their D&O programmes need to catch up to that reality before a regulator or a claimant does it for them.

Link to About the author About the author

Paul Noon OBE is Emeritus Professor of AI and Innovation and former Deputy Vice Chancellor at Coventry University. He advises UK boards on AI governance and strategy through The Professor-AI, and writes a weekly newsletter on practical, jargon-free AI for senior leaders.

Tags: AI
Photo of Kevin LaCroix Kevin LaCroix

Kevin M. LaCroix is an attorney and Executive Vice President, RT ProExec, a division of RT Specialty. RT ProExec is an insurance intermediary focused exclusively on management liability issues.

Read more about Kevin LaCroixEmailKevin's Linkedin ProfileKevin's Twitter Profile
  • Posted in:
    Business and Commercial, Corporate Governance and Compliance, Technology and AI
  • Blog:
    The D&O Diary
  • Organization:
    Kevin LaCroix
  • Article: View Original Source

Call us at 1-800-913-0988 or email sales@lexblog.com.

Facebook LinkedIn Twitter RSS
The Library at LexBlog
  • About LexBlog
  • The Field We Built
  • Library at LexBlog
  • Our Beliefs
  • Our Team
  • Contact LexBlog
  • Disclaimer
  • Editorial Policy
  • Terms of Service
  • Get Started
  • Publishing Solutions
  • Compass
  • Submit a Request
  • Support Center
  • System Status
Copyright © 2026, LexBlog, Inc. All Rights Reserved.
Law blog design & platform by LexBlog LexBlog Logo