Column
What Are Directors Legally Responsible For When They Deploy Agentic AI?
As agentic AI enters enterprise workflows, the duties directors owe — and to whom — depend heavily on which corporate governance model their jurisdiction and company culture adopt. A new legal analysis maps four governance models onto AI deployment decisions, with direct implications for boards, legal teams, and CHROs.
Hello. This is Keito Inoshita from Affectosphere Group.
Agentic AI deployment decisions are moving up to the boardroom.
The operational questions — which processes to automate, what the cost savings look like — are well underway. But alongside them, a more legally precise question is emerging, especially in European corporate law circles: when a board approves a large-scale agentic AI deployment, what fiduciary duties are triggered, and toward whom?
A study published on arXiv in June 2026 (Deirdre Ahern; arXiv:2606.20453) addresses this directly. It maps the fiduciary duties of directors who deploy agentic AI across four corporate governance models, and identifies the conditions under which employee dialogue and reskilling support become legal obligations — not just good practice.
This is legal scholarship with immediate practical relevance for boards, legal departments, and CHROs.
Three takeaways for today
- The governance model a company operates under determines “for whom” agentic AI must be deployed — and what the board must be able to justify to whom.
- The research raises the question of whether agentic AI should eventually be granted stakeholder status — a framing that is already shifting the regulatory risk landscape.
- Employee dialogue and reskilling support are positioned as part of a director’s fiduciary obligation under a contextual legal framework — not merely as CSR.
① Four governance models, four liability structures
The research’s organizing framework is four corporate governance models, each of which reshapes what directors are obligated to do when deploying agentic AI.
The first is shareholder primacy. Under this model, the sole purpose of the corporation is to maximize shareholder returns. If an agentic AI deployment demonstrably increases shareholder value, directors may face pressure — or even obligation — to pursue it. Headcount reduction costs absorbed by efficiency gains work cleanly in this frame. This is the model historically dominant in the US and UK.
The second is enlightened shareholder value. This model — reflected in UK company law — holds that long-term shareholder value requires attending to the interests of employees, customers, and society. Short-term cost savings from AI-driven displacement that risk long-term brand damage or talent erosion must be weighed in the directors’ deliberation. The duty is still primarily to shareholders, but the time horizon is longer.
The third is the stakeholder-oriented model, best exemplified by Germany’s codetermination (Mitbestimmung) framework. Employees, customers, and communities hold equivalent stakeholder standing alongside shareholders. Under this model, proceeding with large-scale role displacement through AI without meaningful workforce consultation carries direct legal risk.
The fourth is the stakeholder value model, which aligns closely with ESG-oriented governance: the goal is to maximize value creation for all stakeholders collectively. Here, AI deployment decisions must be defensible across the full stakeholder set simultaneously.
For boards constructing an AI governance document, these four models provide a practical taxonomy. Specifying which model governs which class of AI deployment decision — and documenting that reasoning — creates an evidence trail for shareholder litigation defense and regulatory scrutiny alike.
② The stakeholder status question as a forward risk
The research also introduces a question that is genuinely ahead of current legal reality.
If an agentic AI system comes to occupy a role in the company equivalent to or exceeding that of a human employee, should it be accorded stakeholder status?
Today, the answer in every jurisdiction is no — AI holds no legal personhood. But the fact that a legal scholar is asking this in 2026, in the context of corporate governance theory, signals that the regulatory and conceptual groundwork is being laid.
For risk management purposes, what matters is the trend, not the current state of the law. The EU AI Act, which is entering full implementation, is already creating legal categories around “high-risk AI” and “autonomous AI systems” that edge toward attributing quasi-legal significance to AI behavior.
A board that adds “future legal risk related to agentic AI status under evolving regulatory frameworks” to its risk matrix today is not being alarmist. It is reading the direction of travel.
③ A practical framework for boards, legal teams, and CHROs
Taking this research seriously means translating the four-model analysis into internal governance documents before an incident forces the conversation.
The most immediate application is structuring an AI deployment governance document around these four models.
When a board presents an AI deployment decision to shareholders, employees, or regulators, the question will be: “for whose benefit was this decision made, and how did you weigh competing interests?” A document that maps the decision to one of the four governance models — with an explicit account of how tradeoffs were assessed — provides a defensible answer.
A concrete use case: a manufacturing or financial services company where AI-driven process automation is expected to result in significant role changes. The board must approve the deployment. Under enlightened shareholder value, the approval memo should document not just the cost-benefit analysis, but the assessment of long-term employee relations risk, reputational risk, and the mitigation measures (transition support, reskilling programs) adopted.
The KPI worth adding to board-level reporting: not just “number of roles automated” or “FTE reduction,” but “employee engagement rate in AI-affected roles 12 months post-transition.” That second metric is what demonstrates the board took its obligations to the full stakeholder set seriously.
The reskilling obligation directors overlook
The research concludes that a contextual legal framework — one that encourages dialogue with employees and supports reskilling — is beneficial for employees, leadership, and the organization as a whole.
This framing matters because it positions reskilling support not as a discretionary benefit or employer branding exercise, but as part of the responsible exercise of a director’s duty in an AI transition.
For CHROs presenting to the board, this provides a useful anchor. “Our reskilling investment during this AI rollout is part of our directors’ fiduciary obligation under the governance framework we operate in” is a stronger argument than “it is the right thing to do.” It connects people strategy to board-level legal accountability.
For legal teams drafting AI deployment policies, the practical implication is that employee consultation and reskilling support should appear in the same governance documents as the AI procurement and deployment decisions themselves — not as a separate HR initiative.
Documenting authority delegation to agentic AI
There is one risk specific to agentic AI that traditional AI governance frameworks often miss.
Conventional AI tools follow user instructions. Agentic AI acts autonomously — executing multi-step tasks, calling external systems, and making intermediate decisions without per-step human authorization. This is closer in character to delegating authority to an agent than to deploying a tool.
Under the duty of care that directors owe, the critical documentation question becomes: “what authority was delegated to the agentic AI system, and how was that delegation decision approved?”
If an agentic system causes harm and the board cannot produce clear records of what the system was authorized to do, the absence of that documentation itself becomes evidence of governance failure.
“Which agentic AI systems are authorized to take which classes of action, with what oversight thresholds, approved by whom on the board, on what date” — this is the core of defensible AI governance, and it is different from what most companies currently track.
”For whom” is the director’s question
The paper’s underlying message is direct.
Large-scale agentic AI deployment is a board-level governance decision, not a technology procurement decision. Directors must be able to answer “for whom was this done” — and the answer must be consistent with the governance model the company claims to operate under.
The four-model framework is practical shared vocabulary for boards, legal teams, and CHROs to conduct that analysis before deployment, not after litigation.
That is it for today!
Reference
- Deirdre Ahern (2026). Directors Duties in the Age of Agentic Artificial Intelligence. arXiv preprint.
* This article was written in part with AI assistance and may contain inaccuracies.