legal247

Board responsibility for AI: what should the board ask before its next meeting?

In brief

Board responsibility for AI follows from the general rules of the Norwegian Companies Act. The board must ensure the business is properly organised, subject to adequate control and that the chief executive is supervised, and this also covers the use of artificial intelligence. The board does not need technical expertise, but it must know where AI is used, what the risk is and who is responsible.

Artificial intelligence is no longer an IT project. It drafts contracts, answers customers, sorts applications and processes personal data. That makes AI a board matter, governed by the same rules that apply to finance, security and internal control. The board does not need to understand the technology in detail, but it must know enough to exercise oversight.

What does the Companies Act say about board responsibility for AI?

The Norwegian Private Limited Liability Companies Act (aksjeloven), referred to here as the Companies Act, does not mention artificial intelligence, but the board’s general duties apply fully to the use of AI. Under Companies Act § 6-12(1), the management of the company is vested in the board, and the board must ensure that the business is properly organised. Under the third paragraph, the board must ensure that the business, the accounts and the management of assets are subject to adequate control.

Companies Act § 6-13 requires the board to supervise the day-to-day management and the company’s business in general. The board may issue instructions to the chief executive (CEO). Under Companies Act § 6-15(2), the board and each individual director may at any time require a more detailed account of specific matters.

These rules are legal standards. What counts as proper organisation changes with the business and its environment. Where AI is used in the core business, it is hard to see how the organisation can be proper unless someone has an overview of that use, rules govern it and someone is responsible for follow-up. The Public Limited Liability Companies Act (allmennaksjeloven) contains corresponding rules for public limited companies.

Which AI decisions belong with the board?

Matters that are unusual in nature or of major importance in light of the company’s circumstances fall outside the day-to-day management, see Companies Act § 6-14(2). Such matters must go to the board.

Buying an AI assistant for case handlers is normally day-to-day business. Building the company’s customer service or product around an AI model, or letting AI make decisions about customers or employees, may on the other hand be of major importance. That applies in particular where the company becomes dependent on a single provider, where large volumes of personal data are processed, or where errors can affect many customers at once.

When can directors be held personally liable?

Directors may be liable in damages where they intentionally or negligently cause loss to the company, its shareholders or others, see Companies Act § 17-1(1). The conditions are the ordinary ones in the law of damages, namely a basis of liability, financial loss and causation.

The standard of care is what a prudent director would have done in the same situation. Liability is individual, so each director is assessed separately. Liability may be reduced under Companies Act § 17-2, see § 5-2 of the Damages Act (skadeserstatningsloven), and it is the general meeting that decides whether the company should bring the claim, see Companies Act § 17-3.

Boards are rarely held liable for making a bad decision. They are held liable for not asking the questions.

There are as yet no Norwegian decisions on board liability relating to the use of AI. Case law on board liability nevertheless shows that the courts attach weight to whether the board obtained a sound basis for its decisions and followed up known risks. A board that has never asked how the company uses AI is in a weak position if an AI error leads to a large loss. The most likely liability scenario is not that the board chose the wrong technology, but that it overlooked a risk that was known or should have been.

Which AI risks should the board be aware of?

The board should have an overview of a handful of risk areas. The table shows the most common ones and where they can hit the bottom line.

Risk Typical example Possible consequence
Wrong answers to customers The chatbot promises a refund that does not exist Customer claims, regulatory action, reputational damage
Contracts without review Management signs an AI-drafted agreement Unforeseen liability and losses in negotiations
Personal data Employees paste customer data into an open tool Data breach, administrative fine, notifying customers
Trade secrets Source code or bid prices are shared with the provider Loss of protection and competitive advantage
Provider dependency Price increase or discontinuation of the service Operational disruption and high switching costs
Regulation New requirements under the AI Act Sanctions and a need to change course

The risk boards most often underestimate is the one they cannot see. Employees start using free versions of AI tools on their own initiative, often with the best of intentions and to work faster. Such use does not appear in any supplier register, is not covered by data processing agreements and is not followed up. A board that only asks about the tools the company has bought therefore gets too rosy a picture.

Each risk has its own legal dimension. The risk of wrong answers is discussed further in the article on liability for AI hallucinations, and the risk of AI-drafted contracts in the article on vibe lawyering. If personal data leaks, separate rules on personal data breaches apply, with deadlines counted in hours.

What should the board ask the chief executive before the next meeting?

Board responsibility for AI is best exercised through good questions. These eight give the board a sound basis.

  1. Which AI tools are used in the company today, including those employees have adopted themselves?
  2. Who is responsible for the use of AI, and how is it reported to the board?
  3. Do we have written rules for employees’ use of AI, and how are they followed up?
  4. What information is entered into the tools, and is it used to train the provider’s models?
  5. Where does AI make decisions or give advice without a human checking the result?
  6. What do the supplier contracts say about liability, confidentiality, data location and exit?
  7. Have employees been trained, and is the training documented?
  8. What is our plan for the AI Act once it is implemented in Norway?

The answers do not need to be perfect. What matters is that the board receives them, assesses them and follows up. If the company has no AI policy for employees, that is often the first measure the board should ask for.

How can the board document that it has done its job?

The board minutes are the most important evidence. Under Companies Act § 6-29, minutes must be kept of the board’s proceedings. The minutes should show that AI has been considered, what basis the board had and what was decided.

The board should also consider setting reporting requirements in its instructions to the chief executive, see Companies Act § 6-13(2), putting AI on the annual board calendar and asking for a short status report at least once a year. For larger AI projects, the board should receive a separate risk assessment before the decision is made.

Does the AI Act apply to the board?

Not directly. The AI Act imposes obligations on the company as a provider or deployer, not on directors personally. Under AI Act Art. 4, the company must take measures to ensure AI literacy among those who use the systems. The requirement applies in the EU, but the regulation has not yet been incorporated into the EEA Agreement or implemented in Norwegian law. The Norwegian government aims to hold a new consultation in autumn 2026 and to present a bill in spring 2027.

If the group has subsidiaries in the EU, the requirements already apply there. The same is true where the company itself supplies AI systems to customers in the EU. The parent company’s board should then satisfy itself that compliance is followed up across the group.

For the board, this means the regulation is a planning task now and a compliance requirement later. Read more about the AI literacy requirement under the AI Act and on the topic page on artificial intelligence.

What should the board do now?

  1. Put AI on the agenda. Ask the chief executive to answer the questions above by the next board meeting.
  2. Assign responsibility. Make sure one person in management has overall responsibility for the use of AI.
  3. Require rules. Ask for a written AI policy for employees and a training plan.
  4. Clarify what goes to the board. Decide that larger AI projects and dependency on a single provider are dealt with by the board.
  5. Build the board’s own competence. Make sure the board as a whole understands enough to assess the answers it receives.
  6. Minute it. Let the minutes show what the board has considered and decided.
  7. Follow up. Ask for an annual review of AI use, incidents and supplier contracts.

Questions and answers

Does someone on the board need technical AI expertise?

The Companies Act does not require it. The board as a whole must nevertheless have enough understanding to ask the right questions and assess the answers. If it lacks that competence, the board should acquire it through training, advisers or at the next board election.

Can the board delegate responsibility for AI to the chief executive?

Day-to-day follow-up can and should sit with the chief executive. The board's duty to ensure proper organisation and supervision cannot, however, be delegated away. The board must make sure someone is responsible, and that the board receives reports that make supervision possible.

Does directors' and officers' liability insurance cover AI-related losses?

It depends on the terms. Many policies exclude fines, cyber incidents and intentional acts, among other things. The board should ask for a review of the policy terms against the company's actual use of AI.

Next legal review: 15 January 2027