The Delaware Chancery Court Does Not Care How Fast You Shipped the Agent
Your company put an autonomous AI agent into production last quarter. It onboards customers, or routes trades, or screens contracts — real work, run as multi-step tasks without a person checking each move. Standing it up took an afternoon, not a hardware budget and a hiring plan. Here is the part that decides the lawsuit: the board has never discussed it, no committee owns it, and the minutes say nothing. In Delaware, that silence is the case.
The Caremark duty — a board’s obligation to make sure the company has systems in place to catch the risks that go to the heart of what it does — did not speed up when agent deployment did. Under Marchand v. Barnhill and In re Boeing, directors must build a reporting system for risks that are central to the business and then actively monitor it. The obligation cannot be delegated away.1 Whether AI agent governance rises to that level depends on the company. For any company where autonomous agents perform core functions, the analysis is short.
The regulators are already moving. In March 2024, the SEC charged two investment advisers, Delphia and Global Predictions, for false claims about their use of AI; the penalties were $225,000 and $175,000.2 In January 2025, the Commission brought its first AI-washing case against a public company. Presto Automation had told investors its product “eliminated the need for human order taking.” In fact, human workers in the Philippines and India processed the vast majority of orders.3 A month later, the SEC stood up a Cyber and Emerging Technologies Unit — roughly 30 fraud specialists and attorneys — with AI-related misconduct as a named enforcement priority.4
This is not a fringe scenario. Eighty-eight percent of companies now use AI in at least one business function, and close to a quarter are already scaling agentic systems — autonomous agents that execute multi-step tasks without continuous human supervision.56 The infrastructure that once took months of engineering is now a commodity. Anthropic’s Claude Managed Agents, launched into public beta in April 2026, lets any company deploy an autonomous agent — with command-line execution, file operations, web access, and connections to outside services — for cents per session-hour.7 The barrier to deploying is gone. The duty to oversee is not.
This article maps the two-part Caremark test onto AI agent deployment, using the product surface of Claude Managed Agents as the worked example, and ties each element to the KYA Five Pillars governance framework. The output is a board-level reporting template, a litigation-hold protocol, a D&O coverage assessment, and a compliance checklist a board can adopt before the EU AI Act’s deployer obligations are currently scheduled to take effect on August 2, 2026.8 One development would change this analysis: a Delaware court that declines to treat autonomous agents as “mission-critical,” or an SEC that holds to fully principles-based disclosure. Watch for both. As of this writing, neither has happened.
Key Takeaways
- Caremark liability flows from the duty of loyalty, not the duty of care. That single distinction is why the business judgment rule does not apply and why exculpation under DGCL Section 102(b)(7) — the charter provision that shields directors from money-damages liability for care violations — does not protect directors who fail to oversee mission-critical AI risks.9
- The two-part Caremark test requires both a reporting system and active monitoring. As recently as September 2025, the Delaware Court of Chancery allowed Caremark claims to proceed where a company lacked a board committee for regulatory compliance, formal reporting protocols, and employee training systems.10
- Whether AI agent governance is “mission critical” under Marchand is company-specific. But for companies where agents perform core business functions, touch primary regulatory obligations, or operate where failure threatens the enterprise, the analysis tracks directly from Blue Bell, Boeing, and Teligent. Half of companies are buying or leasing generative AI from third-party vendors, according to KPMG’s 2024 survey of companies with revenue above $1 billion.11
- Managed Agents session data persists until you delete it. Anthropic’s feature eligibility table lists Managed Agents as stateful and not eligible for Zero Data Retention: transcripts persist until the deployer deletes them, with no automatic deletion. That favors preservation — but it puts the spoliation risk on deletion. A deployer that purges sessions without a litigation hold, or cannot export them to company-controlled storage, has a board-governance gap, not a vendor one.
- The insurance market is excluding AI across product lines. Berkley and Hamilton have added AI exclusions to D&O and E&O policies. ISO introduced generative AI exclusion endorsements for commercial general liability in January 2026, and ISO forms underpin the substantial majority of U.S. property and casualty policies.12
What Does the Caremark Duty Require for AI Agent Deployment?
Caremark liability requires a showing that the board utterly failed to implement a reporting or information system, or that the board consciously failed to monitor a system that was in place. The Court of Chancery in In re Caremark International Inc. Derivative Litigation established that “only a sustained or systematic failure of the board to exercise oversight — such as an utter failure to attempt to assure a reasonable information and reporting system exists — will establish the lack of good faith that is a necessary condition to liability.”13
The category the claim falls into decides the case. Delaware law splits a director’s fiduciary obligations into a duty of care and a duty of loyalty. In Stone v. Ritter, the Delaware Supreme Court held that the oversight duty sounds in loyalty, not care — which places it beyond the reach of the business judgment rule and of exculpation clauses.9 That placement is the whole ballgame. DGCL Section 102(b)(7) lets a corporation exculpate directors from duty-of-care liability, and of the 288 Delaware corporations that proposed officer-exculpation charter amendments in the 2023 proxy season, stockholders approved 231 — 80.2 percent.14 None of that reaches a loyalty-based Caremark claim. A board cannot draft its way out of the oversight duty.
What Caremark left open was the threshold question: which risks require board-level oversight systems? Marchand v. Barnhill answered it for “mission-critical” operations — but the designation is company-specific, turning on whether the risk goes to the heart of what the company does. Blue Bell Creameries made a single product, ice cream, and its board had no process for monitoring food safety. Management had received reports of listeria, leaking pipes, standing water, and FDA concerns. The board meeting minutes reflected none of it.15 When a listeria outbreak killed three people and forced a company-wide recall, the Delaware Supreme Court reversed the dismissal below, holding that food safety was “essential and mission critical” to Blue Bell’s business.16
In re Boeing extended the analysis to the 737 MAX crisis. The Court of Chancery found that Boeing’s board had no committee charged with airplane-safety oversight; the Audit Committee’s charter addressed financial risk, not product safety. On the books-and-records evidence — the documents stockholders obtained through a Section 220 demand, the Delaware tool that lets shareholders inspect corporate records — the court found the record “does not reveal evidence of any director seeking or receiving additional written information” about FAA certification, pilot training, or airplane safety.17
The doctrine continues to expand. In September 2025, the Court of Chancery denied a motion to dismiss in Giuliano v. Grenfell-Gardner, letting Caremark claims proceed against former directors and officers of the pharmaceutical company Teligent. The court found the complaint adequately alleged that the company lacked a board committee responsible for FDA compliance, formal protocols requiring management to elevate regulatory issues to the board, and training systems to ensure employees knew their compliance obligations.10
No court has applied Caremark to AI governance. That is the honest state of the law, and it is the pivot point a defendant will press. But the legal community is converging on the view that existing doctrine already reaches AI deployment. As Professor Pierluigi Matera argues in the forthcoming St. John’s Law Review, AI “does not alter the legal standard governing Caremark liability but changes the evidentiary terrain”; where “algorithmic tools mediate compliance, safety, or regulatory exposure, they cannot be treated as ordinary operational details.”18 Akin Gump’s governance practice reaches the same conclusion by a different route: because Caremark requires oversight of information and reporting systems, and because AI agents now generate material business outputs that affect SEC disclosure, customer outcomes, and regulatory compliance, the same oversight obligation attaches.19
The bridge is the doctrine’s own logic. Marchand did not hold that food safety is mission-critical to every company. It held that food safety was mission-critical to Blue Bell, a monoline ice cream maker. Boeing did not hold that product safety is universally a board obligation. It held that airplane safety was a board obligation for Boeing, a company that makes airplanes. The common thread is not the industry. It is that the risk went to the heart of the business.
For companies that deploy AI agents to run core functions — an investment adviser using agents to manage client portfolios, a healthcare company using agents to process clinical data, a financial institution using agents to execute trades — the “mission critical” argument maps straight from Blue Bell and Boeing. For companies using agents in peripheral or purely internal roles, the argument is weaker. The question is always what the agent does relative to what the company does.
How Does the Two-Part Caremark Test Apply to Managed Agents?
The Caremark test has two independent prongs, and missing either one is a breach.
Prong 1: Implement a reporting system. The board must adopt a formal AI agent governance framework and assign oversight to a specific committee. A generic “risk oversight” reference in the Audit Committee charter is not enough — Boeing teaches that blanket language addressing “risk” in general, without naming the mission-critical risk category, does not satisfy the first prong.20 The National Association of Corporate Directors reports that more than 62 percent of directors now set aside agenda time to discuss AI, and 76 percent say AI will factor into their 2026 growth strategy.21 But agenda time is not a governance framework. The board resolution should name the framework (such as the KYA Five Pillars), designate the responsible committee, and define what information flows to the board, how often, and from whom.
The SEC’s Investor Advisory Committee sharpened the point on December 4, 2025, when it voted to recommend that the Commission require issuers to disclose “board oversight mechanisms, if any, for overseeing the deployment of AI at the company.”22 Chairman Atkins signaled skepticism about prescriptive AI rules. But the recommendation still creates a disclosure expectation that a plaintiff’s attorney will cite in any Caremark complaint involving AI governance.23
Prong 2: Actively monitor the system. Board minutes must show that directors received periodic AI agent governance reports and acted on them. Passive receipt is not enough. Marchand held that Blue Bell’s management-level compliance programs were insufficient because the information never reached the board.24 For Managed Agents deployments, the board or its designated committee should review — at least quarterly — incident counts, control-gap assessments, regulatory-deadline tracking, and vendor change logs.
Matera’s March 2026 analysis names a set of “second-order red flags” boards should watch for in algorithmic systems: model drift, performance degradation, unexplained stability in alert rates, or divergence between algorithmic outputs and external indicators.25 Each is a sign that the monitoring infrastructure itself may be failing. A board that ignores second-order red flags is building the evidentiary record for a Caremark claim against itself.
If your board’s AI oversight is a one-time policy adoption with no reporting after it — you have satisfied neither prong of Caremark.
What Should the Board See? A KYA-Keyed Quarterly Report
The board should receive, at least quarterly, a five-part AI agent governance report keyed to the KYA Five Pillars. Each pillar maps to an oversight dimension a plaintiff’s attorney would examine in a Caremark claim:
| KYA Pillar | Board Report Section | What the Committee Reviews |
|---|---|---|
| KYA-ID (Identity) | Agent inventory and authentication chain | How many agents are in production, what credentials they hold, whether each agent’s actions trace to a specific human authorizer |
| KYA-AUTH (Authority) | Tool-level permissions and change control | Which tools each agent can access, who approved each tool grant, whether any tool scope expanded since the last report |
| KYA-MON (Monitoring) | Logging completeness and retention compliance | Whether session logs are exported to company-controlled storage, retention-period compliance, gaps in the audit trail, and whether server-side session state creates uncharted personal data |
| KYA-IR (Incident Response) | Incident count, severity, and response time | Number of agent incidents since the last report, whether kill-switch protocols were tested, mean time to suspension |
| KYA-COMP (Compliance) | Regulatory calendar and readiness assessment | Status of EU AI Act deployer obligations (currently August 2, 2026, with a Digital Omnibus deferral to December 2027 pending), CCPA privacy risk assessments, SEC AI disclosure expectations, and any new regulatory developments |
This is not aspirational. It is the minimum evidentiary record a board needs to defeat a Caremark claim. Under Marchand, the absence of board-level discussion in the minutes is the red flag. Under Boeing, the absence of a designated committee is the red flag. Under Giuliano, the absence of formal reporting protocols is the red flag. One quarterly report, keyed to the five pillars, answers all three.
Does the Board’s Duty of Oversight Intensify When Litigation Starts?
Yes — and for Managed Agents deployments, the risk is structural. The legal term is spoliation: the loss or destruction of evidence a party had a duty to preserve. Under Zubulake v. UBS Warburg LLC, once a party reasonably anticipates litigation, it must suspend routine document destruction and put a litigation hold in place to preserve relevant evidence.26 FRCP 37(e), as amended in December 2015, lets a court impose sanctions when a party fails to take “reasonable steps” to preserve electronically stored information (ESI): curative measures on a showing of prejudice, and the most severe measures — an adverse-inference instruction, dismissal, or default judgment — only on a finding that the party “acted with the intent to deprive” the other side of the information.27
Agent logging is not a technical feature. It is litigation infrastructure. And for Managed Agents, the retention terms are documented — which moves the risk from the vendor to the boardroom. The data persists until someone deletes it, so the question is whether the deployer has a hold and an export protocol in place before that deletion happens.
Here is what Anthropic’s documentation does say. The Managed Agents overview states that event history is “persisted server-side and can be fetched in full.”28 The engineering documentation describes an “append-only log of everything that happened” within each session, reachable through a getEvents() interface.29 The Session API provides explicit endpoints for deleting and archiving sessions — including an archive endpoint with an archived_at timestamp — which points to a deployer-controlled lifecycle.30
And here is what the retention terms say. Anthropic’s feature eligibility table — which maps each API feature to its data-retention terms and Zero Data Retention eligibility — lists Managed Agents (/v1/agents, /v1/sessions, /v1/environments) as not eligible for Zero Data Retention and not HIPAA-eligible, with one operative line: sessions are stateful resources, and transcripts persist until the deployer deletes them.31 There is no automatic deletion. That is the inverse of the general commercial policy, which auto-deletes API inputs and outputs within 30 days.32 It also differs from code execution containers, the closest sandbox analog, which retain data for up to 30 days and are likewise not eligible for Zero Data Retention.33 The preservation question is therefore not whether the session data will exist — it persists by default — but whether the deployer governs its deletion before litigation, or lets it happen by default.
That gap is the governance problem. “Reasonable steps” under Rule 37(e) means knowing what you have and how long it will be there. If the deployer cannot point to a retention commitment from Anthropic — because the product is in beta and the terms are undocumented — the deployer cannot represent to a court that preservation is assured.
The board should adopt a litigation-hold protocol specific to AI agent deployments, with three elements: (1) a standing, automated log export for all production agent sessions (KYA-MON), pushing session events to company-controlled storage through the getEvents() API rather than relying on Anthropic’s undocumented retention; (2) a defined escalation path from the legal department to the committee responsible for AI oversight; and (3) a board resolution confirming that agent session data sits within the scope of the company’s document-retention policy.
If your company cannot produce a complete record of what your agent did, when, and why — the spoliation question is not hypothetical. It is live.
Will D&O Insurance Cover AI Agent Governance Failures?
Increasingly, no. The insurance market is adding AI-specific exclusions faster than most boards realize, and the direction is one-way. Review your policy before your first Managed Agents deployment.
In January 2026, the Insurance Services Office (ISO) introduced optional generative AI exclusion endorsements for commercial general liability policies: CG 40 47 (a broad exclusion covering both bodily injury and property damage and personal and advertising injury) and CG 40 48 (a narrower one, reaching personal and advertising injury only).12 ISO defines “generative artificial intelligence” as “a machine-based learning system or model that is trained on data with the ability to create content or responses, including but not limited to text, images, audio, video or code.”34 Because ISO forms underpin the substantial majority of U.S. property and casualty policies, these exclusions are expected to spread quickly.35
On the D&O side specifically, Berkley has introduced what it calls an “absolute” AI exclusion for D&O, E&O, and Fiduciary Liability policies, cutting off coverage for any claim “based upon, arising out of, or attributable to” the use, deployment, or development of AI.36 Berkley’s definition reaches “any machine-based system that, for explicit or implicit objectives, infers, from the input it receives, how to generate outputs.”37 Hamilton Insurance Group has introduced a parallel Generative Artificial Intelligence Exclusion for professional liability policies.38 AIG, Great American, and WR Berkley have each filed for regulatory approval to limit liability for AI-related claims.39
Jones Day’s April 2026 analysis recommends that companies scrutinize renewal proposals for new exclusions, negotiate to eliminate or narrow AI-specific exclusions, add carve-outs for incidental use, and consider dedicated AI-coverage products.40
At minimum, the board should direct the general counsel to: (1) obtain a coverage opinion on whether the current D&O policy carries AI-specific exclusions or broadly worded technology exclusions that could capture AI agent deployments; (2) assess whether dedicated AI liability coverage is available and appropriate; and (3) report the findings to the board with a recommendation — and put that report in the minutes.
If your D&O policy was last reviewed before January 2026, it was reviewed before ISO introduced generative AI exclusions. Review it again.
What Evidence Does the Board Need to Produce? A Caremark Compliance Checklist
| Requirement | Evidence the Board Needs to Produce | Primary Authority |
|---|---|---|
| Board-adopted AI governance framework | Board resolution naming a specific framework (KYA Five Pillars or equivalent) and designating a responsible committee | Marchand v. Barnhill; In re Boeing |
| Designated oversight committee | Committee charter explicitly referencing AI agent risk (not generic “risk oversight”) | In re Boeing (blanket charter language insufficient) |
| Formal reporting protocols | Defined information flow from management to the board on AI agent operations | Giuliano v. Grenfell-Gardner (absence of reporting protocols supported Caremark claim) |
| Periodic reporting | Quarterly AI agent governance report reflected in board or committee minutes | Caremark; Marchand |
| Active monitoring | Board-directed action in response to at least one report (investigation, policy change, resource allocation) | Marchand; In re Boeing |
| Incident escalation protocol | Defined board notification thresholds for agent-related incidents | Marchand; In re Boeing |
| Litigation hold protocol | Board resolution extending document retention to AI agent session data, with log export to company-controlled storage | Zubulake; FRCP 37(e) |
| D&O coverage review | Coverage opinion addressing ISO CG 40 47/CG 40 48 endorsements, Berkley/Hamilton AI exclusions, reported to board | ISO CGL AI exclusions (Jan. 2026); Berkley D&O AI exclusion |
| AI disclosure readiness | Mechanism to disclose board AI oversight per SEC IAC recommendation framework | SEC IAC Recommendation (Dec. 4, 2025) |
| Regulatory calendar tracking | Board-level tracking of EU AI Act (Aug. 2, 2026, with a deferral to Dec. 2027 pending), CCPA regulations, SEC CETU priorities, and applicable state AI laws | EU AI Act Art. 26; SEC CETU (Feb. 2025) |
What Happens If the Board Does Nothing?
The convergence is already here: a product that makes deploying an autonomous agent trivially easy, an SEC enforcement unit dedicated to AI-related misconduct, an insurance market actively excluding AI risk from coverage, and a Delaware Court of Chancery that — as recently as September 2025 — allowed Caremark claims to proceed where a company lacked formal compliance-oversight structures.
The plaintiff’s playbook writes itself. Step one: establish that AI agents are mission-critical to the company’s operations under Marchand. Step two: show the board had no committee, no reporting protocol, and no minutes reflecting AI governance discussion under Boeing and Giuliano. Step three: show that the company’s deployer liability exposure was foreseeable, because the regulatory framework, the enforcement trajectory, and the governance literature all said so. The claim is not speculative. The doctrinal pieces are assembled.
The directors who will be protected are the ones who can point to a board resolution, a designated committee, quarterly reports in the minutes, and a documented response to at least one flagged issue. The directors who will be exposed are the ones who treated AI agent governance as an engineering decision that did not need board attention.
The governance framework exists. The KYA Five Pillars supply the reporting structure. The vendor contract clauses supply the contractual infrastructure. This article supplies the board-level protocol. The open question is whether your board adopts it before or after the first AI agent derivative complaint is filed.
Astraea Counsel advises companies on AI agent governance frameworks, board-level compliance protocols, and the regulatory obligations that attach when autonomous systems act on your behalf. If your board is deploying AI agents without a Caremark-ready oversight structure, we should talk.
Disclaimer: This article provides general information for educational purposes only and does not constitute legal advice. Corporate governance and AI regulation are evolving rapidly. Consult qualified legal counsel for advice on your specific situation.
Footnotes
-
Marchand v. Barnhill, 212 A.3d 805 (Del. 2019); In re Boeing Co. Derivative Litig., C.A. No. 2019-0907-MTZ, 2021 WL 4059934 (Del. Ch. Sept. 7, 2021). PDF PDF ↩
-
SEC Press Release No. 2024-36, “SEC Charges Two Investment Advisers with Making False and Misleading Statements About Their Use of Artificial Intelligence,” March 18, 2024. Delphia paid $225,000; Global Predictions paid $175,000. PDF ↩
-
SEC Administrative Proceeding, Release No. 33-11352, In re Presto Automation, Inc., January 14, 2025. The SEC found that Presto violated Section 17(a)(2) of the Securities Act and Section 13(a) of the Exchange Act. The order stated that Presto’s in-house technology “lacked the capability to take orders on [its] own and required substantial human involvement,” with human workers primarily in the Philippines and India processing orders. PDF ↩
-
SEC Press Release No. 2025-42, “SEC Announces Cyber and Emerging Technologies Unit to Protect Retail Investors,” February 20, 2025. CETU is staffed by approximately 30 fraud specialists and attorneys, with AI-related misconduct among its named enforcement priorities. PDF ↩
-
McKinsey & Company, “The State of AI,” November 2025, based on a survey conducted June 25 to July 29, 2025, with 1,993 participants across 105 countries. ↩
-
McKinsey & Company, “The State of AI,” November 2025. Twenty-three percent of respondents report scaling an agentic AI system; 39 percent report experimenting with AI agents. ↩
-
Anthropic, “Introducing Claude Managed Agents,” April 8, 2026. Built-in tools include bash commands, file operations, web search, and connections to external services via MCP servers. All tokens billed at standard Claude model rates plus $0.08 per session-hour. ↩
-
European Parliament and Council, Regulation (EU) 2024/1689 (AI Act), Art. 26 (deployer obligations), with application date of August 2, 2026 per Art. 113. As of this writing, the Digital Omnibus (provisionally agreed May 7, 2026; pending final European Parliament and Council adoption and Official Journal publication) would defer the standalone high-risk deployer deadline to December 2, 2027. August 2, 2026 remains the date in the enacted regulation; confirm the current status before relying on either date. PDF ↩
-
Stone v. Ritter, 911 A.2d 362, 370 (Del. 2006) (directors who “fail to act in the face of a known duty to act, thereby demonstrating a conscious disregard for their responsibilities … breach their duty of loyalty by failing to discharge that fiduciary obligation in good faith”). Because DGCL Section 102(b)(7) permits exculpation only for duty-of-care claims, Caremark liability cannot be exculpated. PDF PDF ↩ ↩2
-
Giuliano v. Grenfell-Gardner, C.A. No. 2021-0452-KSJM (Del. Ch. Sept. 2, 2025) (McCormick, C.). The court denied, in substantial part, a motion to dismiss Caremark claims against former directors and officers of Teligent, Inc., finding the complaint adequately alleged the company lacked a board committee for FDA compliance, formal reporting protocols, and training systems. PDF ↩ ↩2
-
KPMG, “2024 GenAI Executive Survey,” August 2024, surveying 225 senior business leaders at companies with revenue of $1 billion or more. Only 12 percent of companies are building generative AI in-house; 50 percent are buying or leasing from vendors; 29 percent pursue a mix. ↩
-
Insurance Services Office (ISO), CG 40 47 and CG 40 48, generative AI exclusion endorsements for commercial general liability policies, effective January 2026 (cited in Jones Day, “A-Eye on Coverage: Maximizing Insurance for AI Risks Amid Emerging Exclusions,” April 2026, and PHL Firm, “New Generative AI Insurance Exclusions: What Businesses Need to Know in 2026,” February 2026). ISO forms underpin the substantial majority of U.S. property and casualty policies. ↩ ↩2
-
In re Caremark Int’l Inc. Derivative Litig., 698 A.2d 959, 971 (Del. Ch. 1996). PDF ↩
-
DLA Piper, “Amendment to DGCL Section 102(b)(7): Implications for 2024,” May 2024. During the 2023 proxy season, 288 Delaware corporations proposed officer exculpation charter amendments; stockholders approved 231 (80.2 percent). ↩
-
Marchand v. Barnhill, 212 A.3d 805, 822 (Del. 2019). The Delaware Supreme Court found that the board meeting minutes did not reflect board-level discussion of food safety issues that had been flagged by management testing, FDA officials, and state regulators. The plaintiffs alleged the board received only positive information regarding food safety. PDF ↩
-
In re Boeing Co. Derivative Litig., 2021 WL 4059934, at *18–19 (Del. Ch. Sept. 7, 2021). PDF ↩
-
Pierluigi Matera, “From Red Flags to Black Boxes: Corporate Oversight in the Age of Artificial Intelligence,” 100 St. John’s Law Review (forthcoming 2026), available at https://ssrn.com/abstract=6161886. Professor Matera argues that AI tests Caremark’s application in three ways: AI forms part of information and reporting systems, AI reshapes how red flags are generated or missed, and AI complicates the attribution of oversight failures. ↩
-
Akin Gump, “Does AI Care About Caremark? Applying the Core Principles of Corporate Governance to Artificial Intelligence Integration,” 2026. The authors argue that boards must take an “enterprise-level view of AI risk” rather than relying on patchwork oversight, and identify public company disclosure, financial services, healthcare, and safety-critical industries as the areas of highest Caremark exposure for AI governance failures. ↩
-
In re Boeing Co. Derivative Litig., 2021 WL 4059934, at *18 (Del. Ch. Sept. 7, 2021) (finding the Audit Committee’s charter addressed financial risk, not product safety, and that blanket risk-oversight language was insufficient to satisfy Caremark’s first prong). PDF ↩
-
The 62 percent figure is from NACD, “2025 Public Company Board Practices and Oversight Survey,” 2025 (more than 62 percent of director respondents report setting aside agenda time for full-board AI discussions). The 76 percent figure is from NACD’s 2026 Governance Outlook, reported in NACD Press Release, “Boards Prioritize Strategic Execution, Technology and People Heading into 2026,” 2025 (“Seventy-six percent of directors say AI will factor into their 2026 growth strategy”). ↩
-
SEC Investor Advisory Committee, “Recommendation of the Investor Advisory Committee Regarding Artificial Intelligence Disclosure,” approved Dec. 4, 2025, recommending that the Commission require issuers to “disclose board oversight mechanisms, if any, for overseeing the deployment of AI at the company.” PDF ↩
-
SEC Chairman Paul Atkins, Remarks at the Investor Advisory Committee Meeting, December 4, 2025 (“I believe that investors can rely on our current principles-based rules to inform them of how AI impacts companies”). PDF ↩
-
Pierluigi Matera, “Algorithmic Oversight: What Directors and Officers Must Do to Comply with Caremark Duties in the Age of Artificial Intelligence,” Oxford Business Law Blog, March 27, 2026 (summarizing Matera, “From Red Flags to Black Boxes,” infra note 38). ↩
-
Zubulake v. UBS Warburg LLC, 220 F.R.D. 212, 218 (S.D.N.Y. 2003) (Zubulake IV). PDF ↩
-
Fed. R. Civ. P. 37(e), as amended effective December 1, 2015. PDF ↩
-
Anthropic, “Claude Managed Agents overview,” https://platform.claude.com/docs/en/managed-agents/overview (accessed April 2026): “Event history is persisted server-side and can be fetched in full.” ↩
-
Anthropic, “Scaling Managed Agents: Decoupling the brain from the hands,” engineering blog, April 2026, describing an “append-only log of everything that happened” and a getEvents() interface for retrieving session context. ↩
-
Anthropic, Session API Reference, https://platform.claude.com/docs/en/api/beta/sessions (accessed April 2026). The API includes DELETE /v1/sessions/{session_id} for permanent deletion and POST /v1/sessions/{session_id}/archive for soft archival with an archived_at timestamp, suggesting deployer-controlled lifecycle. ↩
-
Anthropic, “API and data retention,” https://platform.claude.com/docs/en/manage-claude/api-and-data-retention (accessed June 2026). The feature eligibility table lists Claude Managed Agents (/v1/agents, /v1/sessions, /v1/environments) as not ZDR-eligible and not HIPAA-eligible, with the note: “Sessions are stateful resources; transcripts persist until you delete them.” ↩
-
Anthropic Privacy Center, “How long do you store my organization’s data?” (accessed April 2026): “For Anthropic API users, we automatically delete inputs and outputs on our backend within 30 days of receipt or generation.” ↩
-
Anthropic, “API and data retention” (accessed April 2026). The feature eligibility table shows code execution and programmatic tool calling retain “Container data retained up to 30 days” and are not ZDR-eligible or HIPAA-eligible. ↩
-
ISO, CG 40 47 and CG 40 48 endorsement language, defining “generative artificial intelligence” (cited in PropertyCasualty360, “General Liability Endorsements: Assault or Battery, Generative AI, Human Trafficking,” October 2025, and PHL Firm, “New Generative AI Insurance Exclusions,” February 2026). ↩
-
Jones Day, “A-Eye on Coverage: Maximizing Insurance for AI Risks Amid Emerging Exclusions,” April 2026. ↩
-
Zelle LLP, “AI Update: The Growing Trend of AI-Related Insurance Policy Exclusions,” October 31, 2025. ↩
-
Jones Day, “A-Eye on Coverage,” April 2026, quoting Berkley’s AI definition. ↩
-
Hamilton Insurance Group, Generative Artificial Intelligence Exclusion endorsement (cited in Zelle LLP, October 31, 2025). ↩
-
Metropolitan Risk Advisory, “Major Insurers Are Pulling Back from AI Liability,” 2025 (noting AIG, Great American, and WR Berkley regulatory filings to limit AI liability). ↩
-
Jones Day, “A-Eye on Coverage: Maximizing Insurance for AI Risks Amid Emerging Exclusions,” April 2026. ↩