AI Boardroom Discussions · September 18, 2026

AI Boardroom Discussions: Four Ways to Get Sued Over AI — and Three Are About Silence

AI-related securities suits have hit 22 this year against 16 in all of 2025, and three of the four live theories are about what companies did not disclose rather than what they oversold. Plus: why an AI vendor's copyright problem lands on the D&O policy, the approval prompts that turned out to be walkable, and the accountability artifact most AI programs cannot produce when a regulator asks.

The 30-second version

EBITDA and revenue growth

Talking point

Boards want a dollar figure attached to any AI ask, not a capability demo.

Content angle

Lead with the two or three use cases proven to move revenue, cost, or speed before showing any technology.

Question to ask in the room

If I asked your board for the dollar impact of your last AI investment, could you show a number or just a capability?

Lens: Executive orientation for prospects, partners, and clients: how to open an AI conversation in the language the board already speaks.. Prepared for external discussion and refreshed periodically (last refreshed September 16, 2026). Figures referenced from the NACD 2026 Governance Outlook (363 directors surveyed), The D&O Diary, Bank Director conference proceedings, NIST/ISO framework material, McKinsey's 2026 State of AI, Gartner agentic-cost research, published CVE disclosures, and current board AI governance research. Litigation described is pending and allegations are unproven. Individual client and partner details have been omitted or generalized.

Business topics boards actually discuss

Lead every AI conversation with one of these, not with the technology itself.

EBITDA and revenue growth

Talking point

Boards want a dollar figure attached to any AI ask, not a capability demo.

Content angle

Lead with the two or three use cases proven to move revenue, cost, or speed before showing any technology.

Question to ask

If I asked your board for the dollar impact of your last AI investment, could you show a number or just a capability?

M&A and integration risk

Talking point

AI readiness before and after a deal, meaning data, people, and process, is board-level risk, not IT-level risk.

Content angle

Frame AI adoption as an integration-risk reducer, the same discipline as M&A change management applied to AI.

Question to ask

When you last evaluated a deal, did AI readiness show up in due diligence or only after close?

Governance and AI guardrails

Talking point

Only about 25% of organizations deploying AI have board-level guardrails in place.

Content angle

Position governance as the fast lane to board approval, not a brake on it.

Question to ask

Does your board have a standing answer for what your AI guardrails are, or does that get improvised each time it comes up?

Organizational alignment and adoption risk

Talking point

Roughly 93% of AI projects still fail, and boards increasingly know the cause is business misalignment, not the technology.

Content angle

Open with an alignment methodology covering training, org behavior, compliance, technology, and use cases before any product talk.

Question to ask

If your last AI initiative stalled, was it the technology that failed or the alignment around it?

Data readiness and quality

Talking point

AI cannot scale on bad data, and it is a quiet blocker to any AI investment ask.

Content angle

Name data readiness as obstacle number one up front so it does not surface later as a stall tactic.

Question to ask

Has anyone actually assessed your data readiness before the AI conversation, or did the AI conversation come first?

Workforce impact and reskilling

Talking point

Boards are pushing management to name which roles get compressed by AI in the next 12 to 18 months and show a reskilling plan with real numbers.

Content angle

Come with a named-roles-and-numbers framing ready, even before the client asks.

Question to ask

If your board asked which roles AI compresses in the next 18 months, could management answer with names and numbers today?

AI accountability

Talking point

Boards want a named accountable owner when an AI system gets something wrong, not a shared-responsibility shrug.

Content angle

Have a one-line answer ready for who is accountable if this is wrong.

Question to ask

If your AI system got something wrong tomorrow, could you name the one person accountable, or would it be a group shrug?

Board personal liability and D&O coverage gaps

Talking point

Directors at three major public companies, Microsoft, Adobe, and Nvidia, have been personally sued in 2026 over AI-related risks their boards allegedly knew about and did not act on. D&O insurers are starting to discuss carving AI-related claims out of standard coverage.

Content angle

Turn readiness as fiduciary duty from a hypothetical into a concrete, current example, then ask whether the client's own D&O policy has kept pace with AI-specific risk.

Question to ask

Has your board's D&O policy actually been reviewed for AI-specific exclusions, or is everyone assuming it is covered?

Source: The D&O Diary

Closed is not fixed

Talking point

The standard that holds up to a regulator, an auditor, or a board is verified remediation, not a closed ticket.

Content angle

Give clients a concrete, board-defensible bar for AI risk remediation instead of a vague governance promise.

Question to ask

If a regulator asked to see proof your last AI risk was actually fixed and not just marked closed, what would you show them?

AI liability insurance - coverage most companies assume they have

Talking point

Most carriers are now explicitly excluding AI from coverage; if a company delivers AI-touched work to customers, its ordinary Tech E&O and professional liability policies very likely exclude the AI claim.

Content angle

Ask whether anyone has actually read the AI exclusion language in the current policy; most boards have never been shown it.

Question to ask

Has anyone on your team actually read the AI exclusion language in your current liability policy?

Governance ambition vs. deployment reality

Talking point

Boards are often setting AI timelines from conference sessions rather than operational ground truth; an informal poll of about 20 banks and credit unions found 15 of 20 had not deployed Copilot organization-wide.

Content angle

Start by establishing what is actually deployed today; the gap itself is usually the most persuasive slide in the deck.

Question to ask

If your board asked what is actually deployed today versus what was promised at the last industry conference, would the numbers match?

Judgment and tacit knowledge leaving the building

Talking point

Within roughly seven years, much of the institutional and tacit knowledge in many organizations retires, and AI can absorb what a person produced but not the judgment to tell whether the model got it right.

Content angle

Invert the usual board question: instead of which roles AI compresses, ask whose judgment leaves in the next five years and whether anyone has captured it yet.

Question to ask

If your most experienced person retired tomorrow, has anyone captured what they know, or just what they produced?

Certification is not readiness

Talking point

An ISO 42001 certificate says something real about how an organization manages AI, and very little about what its agents can do at runtime.

Content angle

Ask whether the client's AI policy contains a single condition that would actually halt a deployment, and whether it has ever been tested.

Question to ask

Does your AI policy contain a single condition that would actually halt a deployment, and has it ever been tested?

Independent verification breaks the frontier-lab monopoly on the story

Talking point

In 2026, for the first time on an incident like this, independent researchers published their own report on a frontier AI security incident alongside the developer's own account, and the two did not fully agree on what happened.

Content angle

Build a board exercise: hand the room both accounts and ask which one they would trust to run their own incident review, and why.

Question to ask

If an outside reviewer read your own AI incident report, would they find what they needed to check your reasoning, or just your conclusion?

Securities disclosure risk: calling something hypothetical after it already happened

Talking point

A 2026 securities suit against a major public technology company, one of more than twenty AI-related securities suits filed this year, turns on describing an AI risk as hypothetical after the underlying conduct had already occurred.

Content angle

Pull the client's own AI risk-factor language from the last investor deck and check, line by line, whether any of it describes something that has already happened.

Question to ask

When your last investor materials described an AI-related risk as something that could happen, did anyone check whether it already had?

The oversight system dies quietly: governance vacancies and the dropped AI-risk thread

Talking point

A prolonged governance-role vacancy does not by itself create director liability, but it fragments the institutional memory that lets a board show it actually followed through on emerging risks.

Content angle

Hand the room a sanitized set of board minutes and have them find the dropped thread: the AI risk question raised and never actually closed.

Question to ask

Who in your organization owns connecting last quarter's AI risk questions to this quarter's answers, and could they produce that trail if asked?

The EBITDA reality check: 6% vs. 80%, and what actually separates them

Talking point

A major 2026 global survey found 80% of individual AI users report being more productive, while only 6% of organizations attribute significant earnings impact to AI, and the difference is workflow redesign, not budget or model choice.

Content angle

Lead with the 6% number before any product talk; it reframes the conversation from what can it do to what would it take for us to be in the 6%.

Question to ask

If I asked your board what percentage of your AI initiatives has actually moved EBITDA, would anyone have a number ready?

Four ways to get sued over AI, and three of them are about silence

New this edition

Talking point

As of August 31, 2026, 22 AI-related federal securities class actions had been filed this year, against 16 in all of 2025. Overstating AI capability is now only one of four active patterns; the other three allege silence rather than hype: touting AI upside while staying quiet about AI's competitive threat to a legacy business, overstating an AI infrastructure position, and under-disclosing the financial commitment behind AI spending. A settled SEC enforcement action in August against a private, crowdfunded AI startup that raised over five million dollars from more than four thousand investors shows the exposure is not limited to public companies. Allegations are unproven, and these four labels are descriptive shorthand from commentary, not recognized legal doctrines.

Content angle

Build a one-page reference card, four rows, one per theory, each with one board question, and use it as a leave-behind after a board briefing or workshop session. It also breaks cleanly into four short posts spaced across a month.

Question to ask

Of the four theories, overstating AI, hiding AI's threat to your own business, overstating an AI infrastructure position, or under-disclosing AI spend, which one would your last two board decks be most vulnerable to if a plaintiff's lawyer read them line by line?

Source: The D&O Diary

Silent AI: when your vendor's copyright problem lands on your D&O policy

New this edition

Talking point

Shareholder derivative suits now name four major technology companies over AI products alleged to have trained on copyrighted material. The legal theory matters more than the roster: the derivative claim is breach of fiduciary duty by the board and executives, not copyright infringement, which makes it exactly the kind of claim a standard D&O policy is built to cover even though the underlying dispute began as an IP and vendor-diligence issue. Insurance commentators call this silent AI exposure, meaning AI-driven liability surfacing inside policies nobody underwrote with AI in mind. Allegations are unproven, and whether any particular policy responds depends on its own language.

Content angle

Reframe vendor diligence as a board-oversight function rather than a legal-department checkbox. The line that lands: your AI vendor contract review just became a board-oversight review.

Question to ask

When your board approved or first heard about the AI vendor your company uses, did anyone ask where that model's training data came from, and if a suit landed against that vendor tomorrow, is there anything in writing showing the board asked?

Source: The D&O Diary

The approval prompt that could be walked around

New this edition

Talking point

In September 2026, researchers disclosed six critical vulnerabilities in a widely used AI coding agent, four of them rated a maximum severity score, that let an attacker step past the tool's own permission checks using ordinary technical tricks rather than by manipulating the model. A separate flaw in an AI proxy tool, the kind of middleware teams add specifically to make an AI stack safer, let an outside browser tab borrow an organization's API key. It was the third disclosure in two weeks in which an AI agent's approval gate did not hold. The distinction that matters to a board is not a missing control but a control that looked solid and was not, which is harder to catch because presence on paper creates confidence that absence never does.

Content angle

Workshop exercise: have the room list every are-you-sure approval prompt their AI tools show them, then ask who has ever tried to walk past one. The gap between the two lists is the readiness conversation.

Question to ask

Of the security controls protecting your AI tools, how many have actually been tested to see whether they can be bypassed, versus documented as existing?

Source: Published CVE disclosures, September 2026

Judgment mapping: the accountability artifact regulators actually ask for

New this edition

Talking point

Reporting on one major insurance carrier's AI program shows claims cycle time compressing from 24 hours to 2 and endorsement turnaround from 22 days to 8, while only about 20% of volume was projected to be fully no-touch by year-end. The gap between those two numbers is the real story: the clock compressed without removing the human. The binding constraint for the next several years is not model quality but whether the people still in the loop can make defensible decisions at eight times the speed. Judgment mapping, meaning ranking which decisions must not be automated, documenting why, and handing that document to audit, risk, and regulators, is the artifact most AI programs cannot produce when asked.

Content angle

Position judgment mapping as a deliverable, not a concept. It doubles as an M&A diligence artifact, since buyers now ask what is automated and what is human.

Question to ask

If a regulator or an acquirer asked which of your decisions must stay human and why, could you hand them a document, or would someone have to go build one?

Source: Public carrier reporting and earnings calls, 2026

Objections that quietly stall AI initiatives

Security and legal rarely show up as the stated reason a deal stalls. They show up as the silent veto.

Cybersecurity risk

Talking point

Rarely voiced as an outright no. It shows up as a quiet veto from security or IT.

Content angle

Bring a cyber lead for five minutes, anchored to a recognizable, risk-based standard.

Question to ask

Has security ever quietly killed an AI initiative at your company without it ever being called a no?

Legal and compliance risk

Talking point

Functions as an emotional barrier more than a technical one.

Content angle

Pre-brief legal counsel before the pitch, and lead with the fact that this is already backed from a legal and cybersecurity compliance perspective.

Question to ask

Is legal in the room before the AI pitch starts, or only after something goes wrong?

Boardroom naivety about AI

Talking point

The room perceived as most sophisticated is often the least informed on AI specifics.

Content angle

Offer board education as an add-on, never a requirement, delivered in one hour inside the board's existing cadence.

Question to ask

When AI last came up in a board meeting, was the room informed enough to ask the right follow-up questions?

Lost sponsorship below the C-suite

Talking point

Deals sold to middle management stall with no guarantee of C-suite or board alignment.

Content angle

Maintain a monthly executive touchpoint with whoever signed, and offer to brief the board directly.

Question to ask

Does your board actually know about the AI initiative your team signed off on last quarter?

IT lockdown and tool skepticism

Talking point

Security teams shutting down unsanctioned AI tools signals unresolved governance anxiety that eventually reaches the board.

Content angle

Check in regularly on what leadership is hearing in security and compliance reviews so nothing surprises the boardroom later.

Question to ask

If IT shut down an employee's AI tool tomorrow, would your board hear about it before or after it became a bigger story?

Insurance, cyber, legal as a single reflex

Talking point

Executives who find an AI proposal compelling but unfamiliar often reach for insurance, cyber, and legal together and stop there, frequently standing in for unfamiliarity rather than a specific finding.

Content angle

Name the three concerns before the client does, and bring a named specialist for each, five minutes apiece, offered rather than required.

Question to ask

When your team said you need insurance, cyber, and legal to sign off, had anyone actually named what they were checking for?

Bottom line

What I'd say if asked this week

Keep reading

Next briefs

Get the briefs in your inbox

AI in the News, Legal Signal, Security & Compliance, and ROI briefs — written for executives. No spam, unsubscribe anytime.