Most board and executive conversations I’m part of about AI start in familiar territory: proof-of-concept projects, high-level discussion about what’s coming, and – when governance surfaces – an AI policy of some kind, a framework, a mention of good judgment.

Governance frameworks matter. Documented decisions matter. Good judgment matters.

The Chief Justice of New South Wales recently asked a harder question about the use of AI by directors in practice: what does the law actually say when AI-generated advice turns out to be wrong, and a director relied on it?

Chief Justice Andrew Bell AC delivered the 2026 Harold Ford Memorial Lecture at the University of Melbourne Law School on 21 May, examining what the Corporations Act’s director protections actually say about AI-assisted decision-making. The lecture is published on the NSW Supreme Court website.

His conclusion is uncomfortable: the three provisions directors typically rely on when things go wrong do not cover the situation most boards are currently walking into.

Where the safe harbours don’t reach

When the reasoning is unknowable

Directors can rely on advice from an employee, expert, or fellow director – provided they make an independent assessment of it. The critical word is assessment. If an AI system generated the analysis, and the director cannot interrogate how it reached its conclusions, that assessment hasn’t been made – it has effectively been skipped. As the Chief Justice frames it: how do you independently assess information when the reasoning process behind it is unknowable? That is a black box problem, and now also a legal one.

There is a further complication. Where a delegate used AI to prepare the advice, the director’s trust in that person must now extend to the delegate’s competent and responsible use of AI. As the Chief Justice noted, that is “an untested standard” – no one yet knows where the line sits.

When the delegate isn’t a person

There is no power to delegate a director’s function directly to AI. AI is not a person under the Act. This is unambiguous. The harder question – whether a delegate who uses AI to perform a legitimately delegated task has effectively sub-delegated to a non-person – remains, the Chief Justice observed, unresolved.

When there is no conscious decision

A director who “simply adopts the recommendation of an AI bot” has not, in the Chief Justice’s view, made a conscious decision with an arguable reasoning process behind it. Without an arguable reasoning process, the business judgment rule defence is unavailable.

Air Canada recently discovered what this looks like in practice. Its AI chatbot told a grieving passenger they could claim a bereavement fare retrospectively. The customer later tried, and the airline refused. When it was escalated to a Canadian tribunal after months of trying, the tribunal held the company fully liable. The assumption had been that errors by the chatbot were the chatbot’s problem. The tribunal’s view was different: the organisation owned every output the system produced.

Side note: there are lots of lessons here about organisational design, company values, measuring performance, and human-in-the-loop design, but those are for another article.

The argument cuts both ways

The Chief Justice’s analysis then becomes genuinely unsettling for the prudent director.

As AI becomes the expected standard for processing the volumes of information relevant to board decisions, the business judgment rule may increasingly favour directors who did consult appropriate AI. Not consulting it, when it was available and applicable, may erode the defence from the other direction as that standard rises. As the Chief Justice puts it: directors may need to ask themselves not only “Have I formed a rational belief based on my own independent assessment?” but also “Have I consulted appropriate AI programs, to the extent necessary, to support or validate that belief?”

Neither blind reliance nor deliberate avoidance provides the protection directors currently assume.

The sensible solution is not only individual AI proficiency – that becomes (or is becoming) table stakes. It is governance infrastructure: directors with enough working understanding of AI to genuinely assess what it produces, access to appropriately grounded and secured AI-powered governance advisory tools, management disclosure of when and how AI was used in preparing board materials, and board charters that reflect the environment most organisations are now operating in.

A survey of the top 21 Australian public companies by market capitalisation, conducted in April 2026 as part of the lecture’s research, found that the majority have no reference to Gen AI in their board charters.

ASIC has signalled enforcement action for poor use of AI in its 2025-26 Corporate Plan. From December, the Privacy Act will require organisations to disclose when AI systems are making significant decisions about individuals – which first requires organisations to know what those systems are.

Five months is not much time to build governance infrastructure that was never there.