Friday 02 Oct 2026
main news image

ARTIFICIAL Intelligence (AI) recommends. The board approves. Liability stays human. 

The Companies Act 2016 does not mention AI — but Section 213 of the CA 2016 was never waiting for one. As boards race to adopt and optimise AI, the law continues to hold directors to the same standard of reasonable care, skill and diligence, and the director shall at all times exercise his powers for a proper purpose, in good faith, and in the best interest of the company. What has evolved is the technology sitting between the board and the decision, and with it, the questions directors must now be able to answer and to account for.

Malaysian boardrooms are quietly confronting a problem the law never anticipated: what does "reasonable care, skill and diligence" require when part of the information placed before a director has been generated by a machine? Or by algorithms not fully understandable? 

Section 213(2) CA 2016 sets a dual standard. Directors must exercise the care, skill and diligence expected of someone in their position; and any additional skill or experience they personally hold. It is a standard built for human judgment: read the contract, question the numbers, seek professional advice where needed. In Tengku Dato' Ibrahim Petra bin Tengku Indra Petra v Petra Perdana Bhd (2018), the Federal Court affirmed a subjective-objective test: did the director honestly believe the decision was in the company's best interests, and could a reasonable director in the same position have held that belief?

AI does not lower the bar, but it makes the director’s decision harder to explain. A credit-scoring model, a fraud-detection algorithm, a generative tool drafting board papers — these increasingly sit between the data and the director's signature. The board is still accountable for the outcome. The question is whether it understands enough about the tool and its limitations to exercise its own judgment.

Here, boardrooms risk falling into a simple but important trap: treating AI like just another piece of software. When a director reviews a financial model built on a standard spreadsheet, a formula error is a mechanical mistake; the technology calculates, but it does not fabricate. Generative AI operates differently. It is probabilistic, meaning it can synthesise plausible-sounding analysis, market trends, or legal arguments without those conclusions necessarily being accurate or complete.

The often-cited case study for this verification failure remains Mata v Avianca, Inc (2023), where US courts sanctioned counsel for submitting AI-generated briefs containing entirely fabricated case law. The court’s reprimand was not for using technology, but for the complete absence of human verification before sign-off. Unfortunately, Mata v Avianca did not deter human conduct from dangerous wholesale reliance on AI without verification. The more recent case of Whiting v City of Athens (2026) saw two Tennessee attorneys sanctioned with over US$116,000 for submitting appellate briefs containing more than two dozen fake, AI-hallucinated case citations and factual misrepresentations. 

The lesson for boards is not that AI should not be used. It is that automated output cannot become authoritative simply because it appears convincing. Whether a board is reviewing a legal risk assessment or an AI-summarised financial projection or market trends, the information still requires appropriate scrutiny. Speed cannot replace judgment. Decisions made under pressure compound the challenge, but do not justify sole reliance on AI.

The numbers suggest this gap is real, not theoretical. PwC Malaysia's Corporate Directors Survey 2024 found that 79% of directors agree investing in generative AI is important for their business over the next three to five years — yet only 18% feel well-informed about generative AI trends and developments. Only about 10% of directors have confidence in their own or their management's ability to oversee and execute the company's generative AI strategy well, without risk implications. The figures illustrate the governance challenge: AI is moving at breakneck speed into corporate decision-making while directors are still developing the knowledge needed to oversee it.

Malaysia's governance architecture is racing to catch up. The Malaysian Code on Corporate Governance (MCCG) 2021 remains silent on AI specifically — its reforms centred on sustainability integration, board diversity and independence, not algorithmic oversight. But movement is underway. The upcoming MCCG revision is pivotal to address sweeping changes. 

A Securities Commission consultation on corporate governance closed on July 31 with AI oversight named as a key focus area, alongside a separate consultation on Malaysia's first cross-sector AI Governance Bill. The Malaysian Alliance of Corporate Directors has separately called for explicit board-level oversight of AI ethics and risk as part of wider governance reform. The framework may still be developing, but the duty does not wait.

Other jurisdictions are moving faster. In May 2025, the UK's Financial Reporting Council rolled out an updated Corporate Governance Code emphasising digital competency as a boardroom priority, while the US Securities and Exchange Commission introduced guidance on public company boards to disclose their AI oversight policies and board-level technology expertise. For Malaysian boards, these developments are worth watching. Disclosure expectations travel fast once institutional investors start asking the difficult questions. 

This is precisely where the chartered governance professional's role stops being administrative and starts being part of the board's governance framework. The courts have already shown what protects directors in high-pressure, high-complexity decisions: written professional advice, active board-level deliberation, and a documented record — not a rubber stamp. In Pioneer Haven Sdn Bhd v Ho Hup Construction (2012), the Court of Appeal sided with directors precisely because they had sought written advice and genuinely engaged with the decision under time pressure. The business judgment rule under Section 214 CA 2016 exists to protect exactly that kind of process — not the outcome, but the rigour behind it. But what happens when the “advice” itself comes from AI? Who is responsible?

The courts are already answering that question by drawing a hard line on algorithmic reliance. Recent judicial sentiment across corporate litigation has made it clear that raw, self-sought AI outputs hold zero legal weight in court, explicitly warning that algorithmic generation is no substitute for properly verified professional advice. 

This judicial scepticism is also emerging across Commonwealth jurisdictions. In Australia, the Federal Court decision in ASIC v Bekier (2026) provided a major landmark on AI in the boardroom. Addressing the real-world problem of board pack or material overload, the court acknowledged that while AI can legitimately help directors process massive volumes of information, using AI summaries as a substitute for careful, independent reading directly increases legal exposure. The court’s warning to boards was blunt: informal, "shadow" use of AI by directors offers no protection, and delegating actual critical judgment to an algorithm violates a director’s non-delegable duty of care.

For boards, this creates a governance trap: substituting human expertise with an unvetted AI paper trail does not build a Section 214 defence — it dismantles it. That places governance professionals in an increasingly important position, pushing boards towards three concrete habits: mandating AI risk assessments before adoption, not after an incident; requiring management to explain — in terms directors can genuinely interrogate — what data trains the model and where its blind spots lie; and minuting the deliberation, not just the decision, so that if an AI-assisted call goes wrong, the board's process can withstand scrutiny.

AI has not created a new category of directors' liability. The underlying duty remains the same. What has changed is the context in which directors are required to discharge it. Boards that treat AI oversight as IT delegation, rather than a governance duty, are gambling on the answer to a question the Federal Court of Australia has already asked under a section 213(2) scenario: could a reasonable director, in your position, honestly have believed this was enough?

Mary-Ann Ooi Suan Kim (Kim) is Barrister of Lincoln’s Inn, Advocate and Solicitor of Malaya, Adjunct Professor of Practice, Sunway University, External Advisor (Industry) Board of Studies, Faculty of Law, Universiti Kebangsaan Malaysia, Member of the Board of Advisors, University of Sheffield School of Law, Member of the Legal Professional Advisory Panel, Taylor’s University and RICS Accredited Mediator.

      Print
      Text Size
      Share