Who Is Responsible When AI Shapes Corporate Decisions? Director Duties and Corporate Accountability under Indian Company Law
A company is deciding whether to acquire another business. An artificial intelligence system examines financial records, market data and compliance risks, and recommends that the deal should proceed. The directors approve it. Months later, the acquisition causes serious loss. The board signed the resolution, but the model shaped the information and the choice. Who was really responsible? This article examines that question through section 166 of the Companies Act, 2013. It argues that directors may use AI, just as they use lawyers, auditors and other advisers, but they must not allow assistance to become substituted judgment. The relevant legal question is not whether the model was perfect. It is whether the directors understood its purpose, considered its limits, questioned important assumptions and retained the practical ability to reject its recommendation. The article distinguishes routine assistance, decision support and decision substitution. It then explains how opacity, automation bias, defective data and fragmented vendor arrangements may weaken accountability. Drawing on Indian company law and comparative principles reflected in the European Union Artificial Intelligence Act and Indian financial regulation, the article proposes five safeguards: disclosure of material AI use, board-level competence, governance-level explanation, records and continuing model review, and non-delegable human responsibility. Corporate governance may become algorithmically informed, but it cannot become algorithmically unaccountable.
Introduction: when the board approves an AI recommendation
A company is considering a major acquisition. The board receives a short report from an artificial intelligence system. The report brings together thousands of financial entries, market indicators and regulatory records. It concludes that the acquisition is likely to succeed. The directors discuss the recommendation and approve the transaction. A year later, the acquisition fails. The model had relied on incomplete sales data and had underestimated a regulatory risk. The board made the legal decision. The system, however, shaped the picture on which that decision was based.
This example reveals a problem that company law has not had to face in quite this form. Corporate power is exercised through identifiable people. Directors supervise the company, approve major decisions and owe duties that can be applied to their conduct. Section 166 of the Companies Act, 2013 requires good faith, care, skill, diligence and independent judgment. The structure assumes that an important corporate decision can be traced to people who can explain what they considered and why they acted.1
AI does not normally remove the board from the process. It changes what happens before the board votes. A system may select the relevant information, compare possible outcomes and recommend one course of action. By the time the matter reaches the directors, one option may already appear to be the obvious choice. The formal resolution remains human, while much of the analysis that made the resolution possible may have been produced elsewhere.
The difficulty becomes sharper when something goes wrong. Directors may point to senior management. Management may point to a technology vendor. The vendor may say that the company supplied poor data or used the model outside its intended purpose. Each participant may have played a part. Yet the algorithm itself cannot hold office, act in good faith or answer for breach of a statutory duty. Technological complexity cannot become a place where responsibility disappears.2
This article asks a narrow question: who remains responsible when AI materially shapes a corporate decision? It argues that existing directors’ duties remain the correct legal starting point. Directors may draw on AI, and company law should not discourage useful technology. But reliance is defensible only when directors remain capable of understanding the system’s function, questioning important assumptions and choosing a different course. The legal standard should therefore be informed and critical reliance, not prohibition and not blind trust.
The article proceeds in five further parts before concluding. Part II explains how AI enters the boardroom and distinguishes routine assistance, decision support and decision substitution. Part III asks when directors may reasonably rely on AI under section 166 and how such reliance affects judicial restraint. Part IV allocates responsibility among the board, the company and external technology providers. Part V draws limited comparative lessons from AI and financial regulation. Part VI develops a practical governance framework for boards.
How AI enters the boardroom
AI enters corporate governance in stages. It may begin by organising information, then move towards predicting outcomes and ranking choices. The legal concern grows as the system moves closer to the board’s final judgment.
A. From information to recommendation
Boards have always relied on information prepared by others. Management reports, audited accounts, legal opinions, investment advice and technical studies make complex decisions possible. AI belongs within this wider history of assisted decision-making, but it can exercise a different kind of influence. It can process more material, find patterns that are difficult to see and convert those patterns into forecasts, scores or ranked options.
Companies now use such systems in compliance monitoring, fraud detection, financial forecasting, customer assessment, resource allocation and strategic planning. A compliance tool may identify unusual transactions. A risk model may rank possible acquisition targets. A forecasting system may recommend whether a factory, product line or business division should be retained. In each example, the board still holds legal authority. But the system may decide which facts appear important and which options appear safe.
The attraction is obvious. Directors face limited time and an expanding volume of information. AI can reduce delay and bring consistency to repetitive analysis. It may also identify risks that ordinary review would miss. The concern is therefore not that directors use technology. The concern begins when a useful recommendation becomes difficult to question simply because it appears comprehensive, numerical or technically sophisticated.3
B. Three levels of influence
Three forms of AI involvement should be kept separate. The first is routine assistance. The system organises documents, checks arithmetic, monitors deadlines or flags unusual entries. It helps the board see information but does not recommend the final choice. Ordinary controls will often be sufficient at this level.
The second is decision support. The system predicts an outcome, assigns a risk score or ranks several business options. Directors remain free to decide, but the recommendation can shape the discussion. This is where most of the difficult legal questions arise. The board must know enough to decide whether the output deserves the authority it is being given.4
The third is decision substitution. The board formally approves the result, but no meaningful judgment occurs. Directors may accept the output because they lack the time, confidence or technical knowledge to challenge it. Human approval then becomes ceremonial. The system has not become a director in law, but it has begun to perform the practical role of deciding.
The boundary between support and substitution will not always be clear. A board may discuss an AI report at length and still fail to test its central assumption. Conversely, directors may rely heavily on a well-validated model while genuinely considering alternatives. The correct inquiry is therefore functional. Did the system help the directors exercise judgment, or did it make judgment unnecessary?
C. Why AI is not quite the same as a human expert
Directors regularly rely on specialists because no board can possess every kind of expertise. The comparison with AI is useful but incomplete. A lawyer, auditor or engineer can ordinarily be asked to explain the reasoning, identify uncertainty and respond to a different factual assumption. Some AI systems may provide useful explanations. Others may produce a recommendation whose internal path is difficult even for the operator to reconstruct.
The difference matters because section 166 imposes personal duties. A director need not reproduce an expert’s work. The director must still decide whether the advice is suitable for the decision being made. With AI, this requires attention not only to the output but also to the system’s purpose, data, known limits and deployment context. The more important the decision and the greater the model’s influence, the stronger the need for scrutiny.5
When may directors rely on AI?
The law does not require directors to work without expert assistance. The real question is what reasonable reliance looks like when the adviser is a system that may be powerful, opaque and difficult to challenge.
A. Section 166 and the continuing duty to judge
Section 166 remains the doctrinal centre of the problem. It requires directors to act in good faith for the company and relevant stakeholder interests, to exercise due and reasonable care, skill and diligence, and to exercise independent judgment. These duties do not disappear because the information reaching the board was produced by software.6
Good faith asks whether the board honestly used the system for the company’s interests rather than to conceal a preferred outcome or avoid responsibility. Care and diligence ask whether the directors made reasonable inquiries before relying on the output. Independent judgment asks whether the decision remained their own. These questions are familiar. AI changes the facts through which they must be answered.7
Directors do not need to become data scientists. That would be unrealistic and might discourage capable people from serving on boards. They should, however, understand why the system is being used, what kind of information it considers, what it does not consider, what limits are already known and what happens when conditions change. The board must be able to ask sensible questions and receive intelligible answers.8
A useful legal principle follows. The required oversight should rise with the system’s influence and the importance of the decision. A tool that sorts documents does not require the same inquiry as a model that recommends an acquisition, predicts regulatory exposure or decides which employees should be removed during restructuring. Proportionality makes the duty workable without reducing it to a checklist.9
B. Informed and critical reliance
Directors may rely on AI. The alternative would be both impractical and economically unwise. The legal limit is reached when reliance replaces judgment. A board that understands the recommendation, examines the main assumptions, considers other information and remains willing to reject the output has used AI as assistance. A board that approves the output because the model appears objective has allowed assistance to become substitution.
Automation bias explains why this distinction matters. People may fail to notice a problem when an automated system does not flag it, or may follow a recommendation even when other reliable information points elsewhere. The danger is not simply a defective machine. It is a human tendency to give automated advice more authority than it deserves.10
The European Union Artificial Intelligence Act offers a useful comparative description of meaningful oversight. Article 14 requires high-risk systems to be provided in such a way that the persons assigned to oversee them are enabled to understand the system’s capacities and limitations, remain aware of automation bias, interpret its outputs correctly and decide to disregard, override or reverse them. The provision does not create Indian directors’ duties. It nevertheless helps explain what active human involvement looks like.11
For company law, the standard should be reasonable, informed and critical reliance. Reasonable reliance permits the board to use expert systems. Informed reliance requires enough knowledge of purpose, data and limits to assess suitability. Critical reliance requires a real ability to question the output and choose differently. All three elements are necessary where AI materially influences an important decision.
C. Judicial restraint and algorithmic deference
Courts generally avoid judging business decisions with hindsight merely because the result was poor. Directors, not judges, manage the company. This restraint is justified when directors acted in good faith, considered relevant information and exercised judgment. It is less convincing when the board cannot explain the assumptions that drove an AI recommendation or show that anyone tested them.
This does not mean that courts should examine source code or decide whether a model was technically optimal. The proper inquiry is procedural. What was the system asked to do? What information did the directors receive about its limits? Did they seek clarification? Did they consider conflicting evidence? Could they realistically reject the recommendation? These questions test whether judgment occurred without asking a court to remake the commercial decision.12
The danger is algorithmic deference. A quantified output may appear neutral and scientific. Directors may therefore question it less than they would question a human adviser. If a court then defers to the board without examining whether the board itself deferred to the model, legal protection may end up shielding technological output rather than business judgment. Company law should protect assisted judgment, not substituted judgment.13
Who bears responsibility when the system fails?
An AI-assisted decision may involve several actors, but the presence of many contributors should not create an accountability vacuum. Responsibility should follow the function performed by each actor, while the board remains answerable for the final corporate judgment.
A. The board
The board remains responsible for the final governance decision. Directors choose whether the company will use the system, how much weight to place on its recommendation and whether further inquiry is needed. They may delegate analysis. They cannot delegate the statutory question whether reliance is justified.14
This does not make directors guarantors of every output. A carefully selected and properly supervised system may still fail. The relevant question is whether the board’s process was reasonable in light of the decision, the known risks and the system’s influence. Liability should turn on the quality of oversight, not on hindsight alone.
B. The company as deployer
Responsibility may also belong to the company as an institution. A board cannot supervise technology if the organisation has no process for selecting systems, checking data, reporting limitations or escalating unusual results. The company should therefore maintain controls around acquisition, deployment, access, security, validation, monitoring and record-keeping.15
Institutional responsibility is particularly important where AI is used repeatedly across different departments. A model may begin as a narrow compliance tool and later shape investment or employment decisions for which it was never designed. Company-level governance should prevent this quiet expansion of purpose.
C. Developers, vendors and data providers
External actors may share responsibility according to function. A developer may be responsible for a design defect or a misleading statement about capability. A vendor may fail to disclose a known limitation. A consultant may configure the system for a purpose it cannot reliably perform. A data provider may supply incomplete or unlawfully obtained information.
Recognising this shared responsibility does not remove the board’s responsibility. The distinction is between sharing responsibility and displacing it. Developers answer for design, vendors for representations and implementation, data providers for the material they supply, and directors for the decision to rely. No participant should avoid scrutiny merely by pointing to another part of the chain.16
D. Why the AI system cannot bear the duty
AI may cause or influence a result, but causation is not the same as legal responsibility. A director can hold office, owe duties, respond to sanctions and be removed or disqualified. An AI system cannot act loyally, form good faith or experience punishment. It remains an object governed by law, not a person to whom fiduciary judgment can presently be entrusted.17
Assigning responsibility to the system would also create a practical danger. Directors could use the language of autonomy to weaken their own accountability. The more independent the system appears, the easier it may become to say that no human really decided. Company law should take the opposite approach. Greater technological influence should produce clearer allocation of human and institutional duties.
What comparative regulation teaches company law
Comparative regulation does not replace section 166. It helps translate familiar duties of care and independent judgment into practical safeguards for technologically influenced decisions.
A. The EU Artificial Intelligence Act
The EU Artificial Intelligence Act does not rewrite Indian company law. Its relevance is narrower. It identifies governance ideas for systems that can seriously affect people or institutions: risk management, data governance, technical documentation, records, accuracy and effective human oversight. These ideas help explain what reasonable corporate supervision may require when a board relies on an influential model.18
Article 14 is especially helpful. It treats human oversight as a practical capacity, not the presence of a signature at the end of the process. The overseer should be able to understand the system’s limits, detect unexpected performance, remain alert to over-reliance and disregard or reverse the output. This is closely aligned with section 166’s demand for care and independent judgment, even though the legal sources remain distinct.
B. Indian financial regulation
Indian financial regulation points in a similar direction. The Reserve Bank of India (Digital Lending) Directions, 2025 address creditworthiness assessment, borrower disclosure, data use, privacy and technology standards. A regulated lender remains responsible for the digital lending arrangement even when technology providers perform important functions.19
The Directions do not govern board decisions generally. They nevertheless illustrate a useful institutional principle: outsourcing technology does not outsource regulatory responsibility. In corporate governance, the company and its directors should likewise remain answerable for the way technological systems are chosen, supervised and used.
C. Four lessons
Four lessons follow. First, technological sophistication does not eliminate identifiable responsibility. Second, human oversight requires knowledge, engagement and practical authority to intervene. Third, explanation should be sufficient for governance, even when full technical disclosure would be impossible or commercially harmful. Fourth, records, validation and monitoring matter because responsibility must be assessed through evidence of the process, not merely the final result.
These lessons support institutional adaptation rather than legal revolution. Section 166 already supplies the relevant duties. Comparative regulation helps translate those duties into a setting in which the decisive information may be generated by an algorithm rather than a human adviser.20
A practical framework for responsible AI-assisted governance
The preceding analysis points towards a modest governance framework. The aim is not to restrict useful technology, but to ensure that material AI influence remains visible, reviewable and connected to human responsibility.
A. Visibility and board capacity
A responsible framework should begin with visibility. A company need not disclose every ordinary software tool. It should record and, where the legal context requires, disclose when AI materially influences a major recommendation or corporate decision. The record should identify the system’s function, the decision affected and the extent of reliance.21
This is governance transparency, not source-code transparency. The aim is to ensure that AI does not become an invisible determinant of an important outcome. Appropriate confidentiality may still be protected.
i. Board-level competence
The board must have enough institutional capacity to question the system. Every director need not understand model architecture. The board as a whole should understand the system’s purpose, main data categories, known limitations, validation results and the conditions in which it should not be used.
Companies may build this capacity through directors with relevant experience, a board committee, independent technical advice or continuing education. The form can vary. What matters is that someone with authority is able to ask difficult questions and translate the answers for the board.22
B. Explanation, records and continuing review
Complete technical explainability is neither always possible nor always useful. Directors generally need a governance explanation: what the system was designed to do, which factors carried significant weight, what information was excluded, what uncertainty remains and what limitations affect the recommendation.
This form of explanation allows directors to supervise the system without pretending to become programmers. It also creates a basis for shareholders, regulators or courts to understand whether reliance was reasonable. Protecting proprietary technology is legitimate. Giving no intelligible reason for an influential output is different.23
i. Records, validation and review
Records should show the system used, its purpose, the recommendation produced and how the board considered, changed or rejected it. These records preserve evidence that judgment occurred. They also make it easier to learn from later errors.
Validation should ask whether the model is fit for the particular governance purpose. A system designed for short-term forecasting should not quietly be used for long-term strategy. Review must continue because data, markets and corporate conditions change. A model that performed well at introduction may deteriorate over time.24
C. Non-delegable human responsibility
The final safeguard is simple. Directors may delegate analytical work, but they cannot delegate responsibility for deciding whether reliance is justified. Internal teams and external providers may share duties according to their functions. The board nevertheless remains responsible for the final corporate judgment.25
This principle leaves room for innovation. It does not punish every model error or demand perfect foresight. It insists only that corporate power remain connected to people and institutions capable of explanation, correction and legal accountability.26
Conclusion
AI will become a normal part of corporate decision-making. It can help directors see more information, identify difficult patterns and compare risks with greater speed. Company law should not resist those benefits. The legal problem begins when the authority of the recommendation becomes greater than the board’s willingness or ability to question it.
Section 166 already provides the right starting point. Good faith, care, skill, diligence and independent judgment can govern AI-assisted decisions if they are applied to the real process rather than the formal vote alone. Directors may rely on AI, but they should understand its purpose, test important assumptions, consider its limits and remain willing to choose differently.
Responsibility may be shared among directors, the company, developers, vendors and data providers. It must not be displaced onto the algorithm. The article’s five safeguards make that principle practical: visibility of material AI use, board-level competence, governance-level explanation, records and continuing review, and non-delegable human responsibility.
The question is not whether a machine can produce a recommendation. It is whether corporate law can still identify the people who judged that recommendation worthy of action. Corporate governance may become algorithmically informed, but it cannot become algorithmically unaccountable.
*****
Footnotes
1. The Companies Act, No. 18 of 2013, India Code (2013), § 166; Needle Indus. (India) Ltd. v. Needle Indus. Newey (India) Holding Ltd., (1981) 3 SCC 333; Dale & Carrington Invt. (P) Ltd. v. P.K. Prathapan, (2005) 1 SCC 212; Official Liquidator v. P.A. Tendolkar, (1973) 1 SCC 602; Shanti Prasad Jain v. Kalinga Tubes Ltd., (1965) 35 Comp. Cas. 351 (SC).
2. Companies Act, §§ 2(34), 149, 152, 153, 166.
3. John D. Lee & Katrina A. See, Trust in Automation: Designing for Appropriate Reliance, 46 Human Factors 50, 51–53 (2004), https://doi.org/10.1518/hfes.46.1.50_30392.
4. Lee & See, supra note 3, at 54–57; Paul Davies, Sarah Worthington & Chris Hare, Gower: Principles of Modern Company Law (11th ed. 2021).
5. Companies Act, § 166(3); Official Liquidator v. P.A. Tendolkar, (1973) 1 SCC 602 (observing that a director closely associated with the management of the company “cannot shut his eyes to what must be obvious to everyone who examines the affairs of the Company even superficially”); Sangramsinh P. Gaekwad v. Shantadevi P. Gaekwad, (2005) 11 SCC 314.
6. Companies Act, § 166(1)–(6); Needle Indus. (India) Ltd. v. Needle Indus. Newey (India) Holding Ltd., (1981) 3 SCC 333; Dale & Carrington Invt. (P) Ltd. v. P.K. Prathapan, (2005) 1 SCC 212 (stating that the directors’ fiduciary capacity “enjoins upon them a duty to act on behalf of a company with utmost good faith, utmost care and skill and due diligence and in the interest of the company they represent”).
7. Companies Act, § 166(2)–(3); Official Liquidator v. P.A. Tendolkar, (1973) 1 SCC 602; Sangramsinh P. Gaekwad v. Shantadevi P. Gaekwad, (2005) 11 SCC 314 (stating that a director “indisputably stands in a fiduciary capacity vis-à-vis the Company”).
8. Companies Act, § 166(3).
9. Cf. Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 Laying Down Harmonised Rules on Artificial Intelligence (Artificial Intelligence Act), art. 14(3)–(4), https://eur-lex.europa.eu/eli/reg/2024/1689/oj (as amended by Regulation (EU) 2026/1744 of the European Parliament and of the Council of 8 July 2026, https://eur-lex.europa.eu/eli/reg/2026/1744/oj).
10. Raja Parasuraman & Victor Riley, Humans and Automation: Use, Misuse, Disuse, Abuse, 39 Human Factors 230 (1997), https://doi.org/10.1518/001872097778543886; Linda J. Skitka, Kathleen L. Mosier & Mark Burdick, Does Automation Bias Decision-Making?, 51 International Journal of Human-Computer Studies 991, 991–93 (1999), https://doi.org/10.1006/ijhc.1999.0252.
11. Regulation (EU) 2024/1689, art. 14(4)(a)–(d).
12. See Tata Consultancy Servs. Ltd. v. Cyrus Invs. Pvt. Ltd., (2021) 9 SCC 449; cf. LIC v. Escorts Ltd., (1986) 1 SCC 264 (stating, of State action in the commercial sphere, that the court “will not debate academic matters or concern itself with the intricacies of trade and commerce”).
13. See Aronson v. Lewis, 473 A.2d 805, 812 (Del. 1984), overruled on other grounds by Brehm v. Eisner, 746 A.2d 244 (Del. 2000); Smith v. Van Gorkom, 488 A.2d 858, 872–73 (Del. 1985), overruled in part on other grounds by Gantler v. Stephens, 965 A.2d 695, 713 n.54 (Del. 2009). See generally Stephen M. Bainbridge, Corporate Law (3d ed. 2015).
14. Companies Act, §§ 149, 166; Dale & Carrington Invt. (P) Ltd. v. P.K. Prathapan, (2005) 1 SCC 212; Official Liquidator v. P.A. Tendolkar, (1973) 1 SCC 602.
15. See In re Caremark Int’l Inc. Derivative Litig., 698 A.2d 959, 970 (Del. Ch. 1996); Marchand v. Barnhill, 212 A.3d 805, 821–22 (Del. 2019); Regulation (EU) 2024/1689, arts. 16, 26.
16. Regulation (EU) 2024/1689, arts. 16, 26; see also id. art. 25.
17. Companies Act, §§ 149, 152, 164, 166, 169.
18. Regulation (EU) 2024/1689, arts. 9–15, 16, 26.
19. Reserve Bank of India, Reserve Bank of India (Digital Lending) Directions, 2025, RBI/2025-26/36, DOR.STR.REC.19/21.07.001/2025-26, ¶ 5(vii), chs. III–IV (May 8, 2025), https://www.rbi.org.in/Scripts/NotificationUser.aspx?Id=12848&Mode=0.
20. Companies Act, § 166(2)–(3); Umakanth Varottil, Corporate Governance in India: The Transition from Code to Statute, in Corporate Governance Codes for the 21st Century 97, 97–114 (Jean J. du Plessis & Chee Keong Low eds., 2017), https://doi.org/10.1007/978-3-319-51868-8_5.
21. Companies Act, § 166(2)–(3); Smith v. Van Gorkom, 488 A.2d 858, 872–73 (Del. 1985), overruled in part on other grounds by Gantler v. Stephens, 965 A.2d 695, 713 n.54 (Del. 2009); Regulation (EU) 2024/1689, arts. 11–14.
22. Regulation (EU) 2024/1689, art. 14(4).
23. Sandra Wachter, Brent Mittelstadt & Luciano Floridi, Why a Right to Explanation of Automated Decision-Making Does Not Exist in the General Data Protection Regulation, 7 International Data Privacy Law 76, 82–84 (2017), https://doi.org/10.1093/idpl/ipx005.
24. See In re Caremark Int’l Inc. Derivative Litig., 698 A.2d 959, 970 (Del. Ch. 1996); Marchand v. Barnhill, 212 A.3d 805, 821–22 (Del. 2019).
25. Companies Act, §§ 149, 166; Dale & Carrington Invt. (P) Ltd. v. P.K. Prathapan, (2005) 1 SCC 212; Regulation (EU) 2024/1689, arts. 14, 16, 26.
26. Companies Act, § 166.