Board Brief: AI Governance and the Fiduciary Empathy Mandate






Board Brief: AI Governance and the Fiduciary Empathy Mandate | Touch Stone Publishers


Touch Stone Publishers: Board Intelligence Brief

AI Governance and the Fiduciary Empathy Mandate

Three Decisions Every Board Must Make Before the Next Proxy Season | 2026

The Governing Problem

Three concurrent legal frameworks have made AI human oversight a hard board-level fiduciary obligation. Delaware’s Caremark doctrine now requires a functioning reporting system for AI risks: not a declaration of AI ethics. The SEC’s Cyber and Emerging Technologies Unit is prosecuting companies that claim AI autonomy while concealing human labor, establishing that human empathy and judgment are undisclosed enterprise assets. The EU AI Act mandates that high-risk AI systems be technically designed for human oversight, not merely managed by governance policy. The consequence of failing any one of these three obligations is personal director liability, securities fraud exposure, or regulatory penalty. Sixty-four percent of boards have none of the governance architecture these three obligations require.

Three Board-Level Decisions

Decision 01: Governance Architecture

Does our board have a functioning AI oversight reporting system, or a declaration of AI governance intent?

The evidence making this decision urgent now: The Oxford Law Blogs’ March 2026 analysis of director obligations under Caremark is unambiguous. A board that consciously fails to establish a reporting system for known AI-related risks faces potential liability for breach of the duty of loyalty. Not the duty of care. Personal liability for each director who served while the reporting system was absent. The NACD’s 2026 Board Practices Survey found that only 36 percent of boards have implemented a formal AI governance framework and only 6 percent have established AI-related management reporting metrics (WilmerHale, January 2026). Glass Lewis named AI governance the defining theme of the 2026 proxy season, meaning institutional investors are evaluating this at every company in their portfolio. In June 2026, shareholders of Alphabet tested exactly this question directly, with a proposal asking the board to write AI oversight into the Audit Committee Charter. The board recommended against it and the vote failed, but the proposal reaching a ballot at the most AI-exposed company in the world is itself the signal. A board does not need a shareholder proposal filed against it to close this gap; it needs the charter language, the reporting cadence, and the documented record before the proposal, the inquiry, or the plaintiff arrives (SHARE, Parnassus Investments, and PFA Pension, shareholder proposal, Alphabet 2026 proxy statement).

The governance architecture that resolves this decision: The board must designate a committee with AI oversight authority written into its charter, require a structured quarterly management report with defined content (AI system inventory, incident log, human override rates, disclosure review confirmation), implement a pre-publication review for every investor communication that describes AI capabilities, and approve a written AI incident response plan before an incident occurs. All four elements are required. A board with three of the four has a governance gap the Caremark doctrine will not overlook.

Board question to ask at the next session: “Can management produce, within 24 hours, a document showing every deployed AI system, the named human owner of each, and the override threshold for each, as a governance record rather than an IT inventory?”

Decision 02: Disclosure Integrity

Has every AI capability claim in our investor communications been reviewed against documented human oversight in the past 12 months?

The evidence making this decision urgent now: The SEC’s Cyber and Emerging Technologies Unit enforcement action against Nate, Inc. (April 2025) established the legal theory: a company that raised $42 million based on representations of 93 to 97 percent AI-driven automation, while routing the majority of its transactions through contract workers in the Philippines, faced securities fraud charges. Not a regulatory fine. The SEC and DOJ treated the concealment of human labor as material misrepresentation. This is not an isolated case. In March 2024, the SEC charged Delphia (USA) Inc. and Global Predictions Inc. with the identical failure pattern, false claims about AI capability, and both firms paid civil penalties totaling $400,000 (U.S. Securities and Exchange Commission, Press Release 2024-36, March 2024). Every 10-K risk factor section, proxy statement, earnings call script, and investor presentation that describes AI capabilities now carries the same exposure. The CFO who certifies a Sarbanes-Oxley Section 302 disclosure containing an unverifiable AI capability claim is certifying a misrepresentation (DLA Piper, April 2025; Harvard Law School Corporate Governance Blog, May 2025).

The governance architecture that resolves this decision: A named officer must certify, before each quarterly disclosure cycle, that every AI capability claim in the organization’s investor communications is supported by documented human oversight, that no claim of AI autonomy conceals undisclosed human labor, and that the disclosure is consistent with the organization’s internal human authority documentation. This certification is filed as part of the disclosure governance record. It is the document that separates the organization from the Nate enforcement architecture.

Board question to ask at the next session: “Has a named officer reviewed every AI-related claim in our last 10-K, proxy statement, and earnings call against our human authority documentation, and certified that review in writing before publication?”

Decision 03: Workforce Trust Architecture

Has our CEO made an explicit, documented commitment to employees whose roles will be affected by AI deployment: and does our board measure the workforce trust outcomes?

The evidence making this decision urgent now: The 2026 Edelman Trust Barometer records that 70 percent of U.S. employees believe their leaders will not be honest about which jobs AI will eliminate. The Gallup 2026 State of the Global Workplace report finds that 23 percent of all employees, and 32 percent in financial services, fear job elimination within five years due to AI. An actively disengaged employee costs approximately 18 percent of their annual salary in lost productivity (Gallup 2026). In a workforce where nearly one in four employees fears replacement, the disengagement cost is a financial exposure that belongs in the board’s AI governance oversight alongside legal liability. The NBER’s 2026 research identifies “knowledge collapse” (the atrophy of human judgment in over-automated organizations) as the primary long-term governance risk. When AI executes the tasks that develop human expertise, the organization loses the institutional capacity to audit the AI’s performance.

The governance architecture that resolves this decision: The board must require the CEO to produce a specific, documented workforce transition commitment (what the organization will do for workers displaced by AI deployment) and to conduct the four-element accountability conversation with each C-suite officer. The board’s quarterly AI governance report must include a workforce trust metric, a structured measurement of employee confidence in the organization’s AI governance posture, not a general engagement survey. When the metric deteriorates, the board’s oversight committee has the specific signal required to direct management action. JPMorgan Chase’s pairing of a $19.8 billion technology investment with a CEO-level redeployment commitment is the operating model (Jamie Dimon, Shareholder Letter, April 2026).

Board question to ask at the next session: “What specific commitment has our CEO made to workers whose roles will change materially due to AI deployment, and how are we measuring whether workforce trust in our AI governance is being maintained or eroding?”

The Board Question Bank

Five specific questions, drawn from the three decisions above, that every board member should be able to answer from documented sources before the next governance review:

  1. Which officer has accepted written accountability for each deployed AI system’s decisions and outputs, and what authority have they been granted to halt or override those systems?
  2. When did our board last review a structured quarterly AI governance report, with incident log, human override rates, and disclosure review confirmation, as distinct from a management briefing on AI strategy?
  3. Has a named officer certified, in writing, that every AI-related claim in our most recent investor disclosures is supported by documented human oversight?
  4. What specific commitment has our CEO made to employees whose roles will be materially altered by AI deployment, and is that commitment documented and measured?
  5. Have we approved and tested an AI incident response plan that names escalation authority, notification timelines, and public disclosure protocols: before we need it?

This brief does not describe what the problem is. It identifies three specific decisions your board must make this quarter, the evidence that makes each decision urgent, and the governance architecture that resolves each one. The complete architecture: minimum viable structure, 30-60-90 day implementation calendar with named owners, the Working Artifact Suite with verbatim-usable charter amendment language and accountability contract templates, and the full C-suite function-by-function governance framework: is developed in the Leadership Reinvention in the AI Era Executive Leadership Playbook and the Board of Directors White Paper (complimentary research) produced by Touch Stone Publishers.

Have your executive assistant schedule a 20-minute conversation: touchstonepublishers.com/contact

The board that builds this governance architecture before the first enforcement inquiry arrives has built something its successors will benefit from. That is what governance architecture looks like when it is not built in response to litigation.

Touch Stone Publishers Limited  |  touchstonepublishers.com  |  2026
This brief is a research document. It does not constitute legal advice, compliance certification, or a promise of specific business results.