In 2024, a board approved a high-risk acquisition after its AI due diligence tool flagged minimal concerns. Six months later, undisclosed liabilities emerged. The directors claimed reliance on AI analysis. Indian courts have no framework to assess this defence yet. AI Is no longer a stranger to the Boardroom

In order to assess the compliance-related issues, the boards now rely on algorithmic systems. However, whenever the outputs generated by these systems influence the Board’s decision that has negative implications, there is still no standards for the attribution of responsibility, exposing a conflict with the existing framework and the current issues.

The current corporate governance framework, which attributes responsibility upon the directors as they have to exercise intelligence and reasoning, does not consider the influence of algorithms; this creates an attribution paradox. AI tools such as BoardPro and Diligent Analysis not only store the information but also contextualise the information so that the board can make effective decisions. They also help in monitoring compliance and conducting risk analysis and strategic scenario analysis.

In the current practice is not limited to just a tool, but as a de facto corporate advisor, because AI influences decisions of the board. However, AI has not been given any legal recognition and hence, it is not held accountable. Hence, this piece seeks to address the Attribution paradox caused by AI influencing the Board’s decision.

Corporate Delegation under Company Law

The Indian legal landscape allows directors to delegate functions but not responsibility. Directors can take assistance from officers, committees, or professional advisors, but have to rely on their independent judgment to make any decision. This framework is mentioned under Section 166 of the Companies Act, which mandates directors to exercise due care, skill and due diligence.[i] Section 179 vests the board with the final decision-making authority.[ii]

Similarly, the European Union framework focuses on oversight rather than attribution, according to Article 39(6) of Directive 2006/43/EC. EU framework focuses on oversight of internal controls and risk management systems rather than scrutinising every delegated act. In the EU’s AI Act, the responsibility is distributed to Providers and deployers of High-risk AI systems.

Furthermore, Indian courts have held directors accountable if they delegate, but assume that the delegation would be strictly limited to someone they can question, for example, a CFO or consultant, but an algorithm cannot be questioned. The directors would be liable if they fail to exercise oversight, as held in the case of Vishal Ahuja v. SEBI.

Why delegation breaks down with AI

The doctrine of delegation assumes that the delegate can be meaningfully supervised, which is presumed to have intelligence. However, AI is different, as it provides probability reports after studying the data, lacking transparent reasoning. AIs work on training data or mechanisms that cannot be comprehended by directors who do not specialise in AI.

This leads to an important question: if the directors cannot comprehend the reasoning behind the AI’s recommendation, then traditional reasonable supervision becomes confusing, as there is no framework in place to address the recommendations by AI. The SC, in the decision of Sanjay Dutt & Anr. v. State of Haryana & Anr,[iii] has held that a director’s conduct must directly connect with the liability of the company in order to be vicariously liable. This decision reinforces that the director must be directly responsible, and there is no framework in place to address the decision taken with the help of an AI algorithm.

Conflict of Section 166(4) and AI-influenced decision-making

Under Section 166(4), directors must apply their own judgment: a principle AI’s opacity threatens to hollow out.[iv] This section is based on the principle that each director is an independent decision-making authority, but the AI’s usage creates a gap as AI gives multiple outputs based on risks and options. Over time, the board can refer to these outputs as more reliable than their independent judgment, as it would be more accurate. In the future, over-reliance can lead to directors questioning these outputs. Therefore, the issue is not delegation of work to AI, but over-reliance on their outputs, eroding the principle of independent judgement.

Paradox of Attribution

The attribution of liability on AI is still unclear as in the USA, Uber’s self-driving car accident in 2018 revealed that there still does not exist any standard legal framework to apportion the responsibility to the AI algorithms; the backup driver had to plead guilty. Furthermore, in Australia, the Robodebt scandal showcased the severe consequences when the automated debt-assessment issued thousands of unlawful notices; the issue arises as to whom to attribute the responsibility, as not a single person, department or process could be held accountable for the harm.

This leads to the paradox of attribution: if a board’s decision fails, who will be accountable? As for shareholders, they cannot hold directors accountable for AI-driven losses. Regulators struggle to enforce oversight standards. Directors face uncertainty: are they liable for AI errors or for not using AI? However, whenever the Board relies on the outputs generated through an AI algorithm. The court assesses the director’s conduct through a pre-AI lens only, examining what the director was aware of and not considering the recommendations of the algorithms. In practice, AI is not a tool like Excel but functions as an advisor, analysing risks, ranking options, and even drafting scenarios. However, these AIs cannot be cross-examined, or can be held liable, or asked to justify

Comparative Regulatory Approach

India does not have a specific AI Regulation; however, the EU AI Act has adopted a risk-based framework where certain AI systems are categorised as “high risk.”[v] Such systems have to comply with enhanced transparency obligations,[vi] mandate an oversight mechanism in order to minimise harm[vii] and impose usage of these systems according to the instructions.[viii] These provisions show how AI systems shall be used in a way that retains human control. However, these do not answer the question of attribution as the EU’s AI Act focuses on pre-deployment controls such as transparency, documentation and human-oversight. The Act still does not specify the responsibility in case of failure of corporate governance.

Similarly, Singapore implemented AI Model-Risk guidance (MAS), dealing with the oversight of AI Risk management, including policies and procedures. MAS mandates control over data management, fairness, and transparency to be applied based on the materiality of the usage of AI. The MAS also mandates that the capacities shall be adequate for AI Usage. However, like the EU framework, MAS addresses internal governance rather than external attribution. The Act is still unclear on how to weigh the influence of AI while assessing corporate decisions.

Way Forward: The missing chapter in India’s AI-governance Debate

Everyone talks about data privacy and algorithmic bias, but no one addresses boardroom accountability. The above-mentioned gaps can be addressed through legislative overhaul, or through governance-led solutions.

1. The boards should mention the specific aspects they have relied on AI for help, and also document the director limitations. Boards should maintain records of (1) which decisions involved AI inputs, (2) what data/models were used, (3) which directors reviewed the methodology and (4) what independent validation occurred.

2. The existing board committees like the Audit Committee and the Risk Committee can conduct oversight on the AI usage.

3. The regulators like SEBI can also issue guidance on reasonable reliance on AI. For example, SEBI’s guidelines on Algorithmic Trading systems; a similar approach can be applied for corporate governance. SEBI could require disclosure of material AI-assisted decisions in board reports. SEBI could pilot mandatory AI audit for listed companies’ top-tier decisions (M&A, capital allocation) to develop case law.

4. The courts can also assess whether the director exercised reason and oversight or completely relied on the AI-generated data in case of a corporate governance failure. Courts should adopt an “AI-augmented Business Judgment Rule”, wherein directors get deference only if they can demonstrate they understood the AI’s limitations, validated its outputs and exercised independent oversight.

Corporate governance always requires strict oversight, and over-reliance on AI erodes this principle. The company law still has to set standards for the attribution of responsibility in case of a corporate governance failure. The legislation needs to recalibrate the “independent judgement” in an AI-influenced decision. It is important to implement the above solutions to remove the structural gap in modern corporate governance.

India is still at a crucial crossroads; as AI embeds itself into corporate decision-making, the silence of the law is hurtful. Without clear standards of attribution through judicial doctrine, guidelines, or legislative reforms, the corporate governance issue would still remain.

[i] Section 166, Companies Act, 2013.

[ii] Section 179, Companies Act, 2013.

[iii] Sanjay Dutt & Ors. v. State of Haryana & Anr. 2025 INSC 34.

[iv] Section 166 (4), Companies act, 2013.

[v] Article 6, EU AI Act (Regulation (EU) 2024/1689).

[vi] Article 13, EU AI Act (Regulation (EU) 2024/1689).

[vii] Article 14, EU AI Act (Regulation (EU) 2024/1689).

[viii] Article 26, EU AI Act (Regulation (EU) 2024/1689).