The Shifting Corporate Focus on Artificial Intelligence Governance

by John Jenkins

July 31, 2026

By Guest Blogger Yan Ross JD, Editor-in-Chief, Cyber Defense Magazine

NOTE: The author is writing in his individual capacity only, and does not intend this blog to constitute and legal advice or opinion. Some research on the topic employed artificial intelligence resources, but the work product is the author’s alone.

 For legal practitioners of securities law and regulatory compliance, the focus is shifting from “Should the company use AI?” to “Can the board demonstrate that it is exercising informed oversight of AI?”

In today’s fast-changing environment, the greatest legal exposure generally comes from:

  1. Misleading AI-related disclosures to investors (“AI washing”).
  2. Inadequate board oversight that may support fiduciary-duty or derivative claims.
  3. Weak governance and internal controls that allow AI-related risks to affect financial reporting, cybersecurity, or other material disclosures.

For boards of directors, these three issues are increasingly viewed as the core of AI corporate governance. They are also likely to become standard agenda items for audit committees and governance committees as AI adoption expands.

  1. AI Disclosure Risk (“AI Washing”)

This is currently the leading concern.

Securities lawyers worry that companies will exaggerate—or understate—their AI capabilities in SEC filings, earnings calls, investor presentations, and press releases.

Examples include:

  • Claiming products are “AI-powered” when AI contributes very little.
  • Predicting financial benefits from AI without a reasonable basis.
  • Failing to disclose known limitations or material risks.
  • Omitting discussion of AI-related cybersecurity, privacy, or intellectual-property issues.

Potential consequences include:

  • SEC investigations
  • Rule 10b-5 securities fraud lawsuits
  • Shareholder class actions
  • Derivative litigation against directors

It’s worth noting that the SEC has already brought enforcement actions against investment advisers and technology companies for misleading claims about their use of artificial intelligence.  Examples are Delphia (USA) Inc. and Global Predictions, Inc.[1] as well as claims made by the startup company Joonko.[2]

Some fundamental questions securities counsel ask include:

  • Is every AI claim in reports or disclosure documents supported by evidence?
  • Has management documented the basis for forecasts?
  • Would a reasonable investor consider this statement misleading?
  1. Board Oversight and Fiduciary Duty

The second major concern involves directors’ oversight responsibilities.

Among other concerns, Boards are expected to understand how AI affects:

  • Strategy
  • Operations
  • Cybersecurity
  • Legal compliance
  • Financial reporting
  • Enterprise risk management

Lawyers increasingly compare AI oversight to earlier board responsibilities involving, while recognizing that such measures are under constant review, depending upon political and societal norms:

  • Cybersecurity
  • Financial controls
  • ESG disclosures
  • Climate risk

A board that never discusses AI despite heavy corporate reliance could face allegations that it failed to exercise reasonable oversight.

Accordingly, here are some examples of measures securities attorneys increasingly recommend:

  • Regular AI briefings
  • Documented board discussions
  • AI governance policies
  • Defined management accountability
  • Periodic risk assessments

Minutes of board meetings have become particularly important evidence.

3.Governance, Internal Controls, and Accountability

The third concern is ensuring that AI is governed with the same rigor as financial reporting and cybersecurity.

Questions include:

  • Who approves AI use?
  • Who validates AI-generated information?
  • Can AI alter financial reporting?
  • Is human review required?
  • Are employees trained?
  • Are third-party AI vendors adequately vetted?

Research finds that many law firms now recommend that boards be able to answer questions such as:

  1. Where is AI being used throughout the company?
  2. What material risks could AI create?
  3. What controls govern AI use?
  4. How are AI-related disclosures verified before reaching investors?
  5. How does the board oversee management’s AI strategy?

From a functional perspective, attorneys increasingly recommend treating AI as an enterprise governance issue rather than an IT project.

As a result, many companies are developing:

  • AI governance committees
  • acceptable-use policies
  • model validation procedures
  • vendor due-diligence requirements
  • audit trails
  • incident response procedures

This concern is that weak controls can produce not only operational failures but also securities disclosure problems if material errors reach investors.

 

The three listed areas of concern are the current points of focus, but it is a certainty that there will be others as the use of AI becomes more widespread in conducting business of all types.  For the foreseeable future, the use and reporting on artificial intelligence will have to be treated as a dynamic, not static, phenomenon.

###

Top of Form

 

You can reach the author for additional information by email at yan.ross@cyberdefensemagazine.com

 

Yan Ross is a “recovering attorney” and the Editor-in-Chief of the online monthly Cyber Defense Magazine.  In this capacity over the past 7 years, he has edited over 3000 articles by experts in the cybersecurity industry.  From this body of work and independent research, Yan is pleased to provide this monthly guest blog.

Yan is an accredited educator, providing CLE courses for several online providers.

 

He is also co-author of The vCISO Playbook: Virtual CISOs Deliver Enterprise-Grade Cybersecurity to Small and Medium Businesses (SMBs)

[1] https://www.sec.gov/newsroom/press-releases/2024-36?utm

[2] https://www.wsj.com/articles/sec-charges-founder-of-ai-powered-hiring-startup-joonko-with-fraud-b80b0501?utm