- Two things are moving at once in 2026. Courts and regulators increasingly expect directors to show they oversee how AI is used in their business, and insurers have begun writing AI exclusions into liability cover. Directors are being handed more personal responsibility for AI just as the insurance that used to stand behind them starts to carve it out.
- AI oversight is becoming a named board duty, not a technical detail to delegate and forget.
- The insurance gap is real. For 2026, standard general-liability policies added generative-AI exclusions, and similar carve-outs are emerging in directors-and-officers cover.
- The exposure is personal. Directors can be held responsible for failing to oversee AI risk, which makes this a board-table issue, not an IT one.
- Handled early, this is simple protection: know where AI touches your decisions, evidence the oversight, and check the policy before you need it.
You assumed the board was covered. That is what directors-and-officers insurance, known as D&O, is for: the backstop that lets capable people take responsibility without betting their own house on every call. Then two quiet shifts arrive in the same year. Regulators start expecting you, personally, to oversee how AI is used across the business. And the insurers start writing AI out of the cover. The safety net is thinning at the exact moment the responsibility grows.
This is not a reason for alarm, and it is well within a board's power to handle. But it is a reason to look, now, before a hard question arrives. The exposure here is personal, and the protection is a few deliberate steps most boards have simply not taken yet. Take them early and this becomes a non-event. Leave it, and you are exposed in a way you did not choose.
Are directors really on the hook for AI now?
Increasingly, yes, and the direction is clear. Governance and insurance analysts tracking 2026 report a clear shift. Courts and regulators now expect directors to understand where and how AI is used in their organisation, to ensure it is governed, and to show that risks such as model failure, data misuse and reliance on third parties have been considered. That is the language of a director's duty. It means AI oversight is no longer something a board can hand entirely to the technology function and assume is handled.
This sits on top of a related exposure you may already know: companies have faced claims for publicly overstating what their AI can do. The through-line is accountability. Boards are expected to know what their AI actually does, govern it, and be able to show they did. It is the same discipline behind being able to stand behind the decisions your AI makes, now with a director's name attached.
Directors are being handed more responsibility for AI, just as the insurance that used to stand behind them starts to carve it out. Check the policy before you need it.
| The shifting ground under directors (2026) | Detail |
|---|---|
| What regulators and courts now expect of directors | evidence of active AI oversight and governance |
| Generative-AI exclusions in 2026 general-liability policies | introduced by insurers as standard options |
| Similar carve-outs in directors-and-officers cover | emerging |
| Where the exposure sits | personal to directors, not only the company |
What is actually changing in the insurance?
The cover is quietly narrowing where AI is involved. For 2026, the body that standardises US insurance policy wording introduced optional exclusions for generative AI in common commercial liability policies, removing cover for harms arising from it. Analysts tracking the market report similar carve-outs beginning to appear in directors-and-officers policies. So the protection a board has long assumed is comprehensive is developing AI-shaped holes, and they are easy to miss until a claim lands in one.
The lower-altitude reaction is to assume the broker has it covered and move on. That is exactly how a gap goes unnoticed. The higher move is to treat your own cover as something to read, not assume. What does your policy now say about AI? Where are the exclusions? What would actually be covered if an AI-driven decision went wrong? Those are board questions now, and they belong alongside the other questions a board should ask before it relies on AI.
So what should a board actually do?
You turn a vague worry into a short, concrete set of actions, and you do them before you need them. The aim is simple protection: know your exposure, evidence your oversight, and close the gaps you can. Work it in this order:
- Map where AI touches real decisions. You cannot oversee what you cannot see. Know where AI shapes decisions that carry legal, financial or safety weight.
- Evidence the oversight. Record that the board considered AI risk and how. If oversight is a duty, being able to show it is the protection.
- Read your cover for AI. Have someone walk the board through what your liability and directors cover now includes and excludes on AI, in plain terms.
- Assign clear ownership. Name who is accountable for AI risk at board level, so it is somebody's job rather than nobody's.
- Review it on a cadence. Both the rules and the insurance are moving. Revisit this at a set interval, not once.
Making sure your board is protected on AI?
The Strategy Session helps boards get ahead of their AI exposure: understanding where the responsibility now sits, evidencing the oversight regulators expect, and closing the gaps before they become a claim. Calm, practical governance, built for the board table.
Book your Strategy SessionWhere does this leave a board?
In a strong, protected position, if you act while it is still easy. The boards that handle this well will not be the ones who panicked or the ones who ignored it. They will be the ones who quietly mapped their AI exposure, evidenced their oversight, read their cover, and closed the gaps, all before anyone forced them to. That preparation is cheap now and expensive later, and it is the kind of steady governance that lets a board back its people to use AI boldly, knowing the downside is handled.
Picture the moment this matters, because for some board it will. A decision made with AI is questioned, and where others scramble, your board can show exactly how it oversaw the risk and where it stands. The exposure that caught others flat is, for you, already managed. That is what good governance buys: not the absence of hard moments, but the readiness to meet them, which is precisely the confidence that lets you lead AI adoption from the front rather than the back foot.
Frequently asked questions
Can directors be personally liable for AI failures?
Does directors-and-officers insurance cover AI risk?
What should boards do about AI liability?

About the author
British technology futurist, AI keynote speaker and advisor. Thirty years across enterprise technology and AI strategy, helping leaders navigate the future of work. The futurist who died.