Adobe told the public, through 2024 and into 2025, that its Firefly AI model was trained only on licensed Adobe Stock content and public domain material, safe for any customer to use commercially without a second thought. A shareholder suit filed this April alleges Firefly traces instead to the disputed Books3 dataset. Microsoft's board authorized a commitment of more than thirteen billion dollars to OpenAI while, a second suit filed in June alleges, staying silent in its own public filings about the AI risk that commitment carried. Nvidia told the public one story about how its models were sourced while, a third suit filed in July alleges, an internal message told staff the company had "umbrella approval of all the data." Three different companies, three different courts, three different datasets. The same structure underneath all three.
None of these cases needs a judge to first decide whether an AI model actually infringed a copyright. That question will get argued, eventually, by people paid to argue it. It is not what makes the suit work against the board. What makes it work is older and simpler than anything about artificial intelligence. A company said something about itself, in public, on the record. Later, a plaintiff's lawyer set that sentence beside what the company's own internal record showed was happening at the time it was said. The gap between the two sentences is the entire claim. No new fact about the technology was required. The company had already supplied both halves of the case.
THE LAW OF THE SELF-WRITTEN EXHIBIT
Every public claim a board allows the organization to make about its own practices becomes, the moment it is published, a standing representation the organization must be able to prove true for as long as the claim stands. The organization does not get to decide later that the sentence was only marketing, or only investor relations, or only a line in a code of conduct nobody expected to be read closely. The reader decides what weight the sentence carries, and in each of these three cases the reader turned out to be a plaintiff's attorney with a complaint already drafted around it.
This law holds with more force now than it did a decade ago, not because boards have become less careful, but because AI claims are written faster and reviewed less than almost any other category of public statement a company makes. A pricing claim goes through finance. A safety claim goes through engineering and often through outside counsel. An AI training-data claim, in the pattern across all three of these suits, appears to have gone through marketing and come out the other side as settled fact, repeated in a code of conduct, a proxy statement, or an investor update, without anyone being assigned to confirm it stayed true as the underlying system kept changing underneath it.
The mechanism is not malice. It is closer to a quiet confidence that nobody checks the fine print on a claim this specific, paired with a genuine, if untested, belief that the claim was true when it was first written. Both companies and individual directors fall into this the same way, because the pressure that produces an overconfident public claim, the desire to reassure a customer base or a market worried about AI risk, applies with equal force in the boardroom and in the marketing department. The difference is that only the boardroom's version of the claim ends up in a proxy statement that a federal securities complaint can quote by exhibit number.
The violation cost in the Microsoft case is the clearest illustration available anywhere right now. The complaint does not stop at the company. It names fourteen directors and officers individually, under a federal securities claim, for approving statements about the AI strategy that the complaint alleges did not match what the board already knew. A corporate defendant absorbs a judgment and moves forward. A named individual defendant carries the exposure personally, by name, in a public filing that outlives the fiscal quarter in which the statement was made.
The application is not a new committee or a new quarterly review nobody has time for. It is a standing discipline applied to one narrow category of sentence: anything the organization says in public about what trains its AI, what that AI touches, or who is watching it. Before that sentence goes out, someone inside the organization has to be able to stand behind it, by name, as still true today, and has to be asked to do so again every time the underlying system changes. A sentence nobody is assigned to keep true is not a settled fact. It is an exhibit, waiting only for a reader with a reason to go looking for it.
Glenn E. Daniels II, Touch Stone Publishers