Director Exposure in the Age of AI: What Engineering Firm Directors Need to Know

share this insight

Engineering firms are adopting AI faster than most governance frameworks can keep up: for design support, structural calculations, tender responses, and client reporting. That speed of adoption is reshaping what directors are responsible for, and two recent Australian court decisions, including one involving an engineering business, show that the exposure is already real, not theoretical.

This article sets out how AI expands director liability, what the regulators are saying, and how insurance fits into your response.

Why This Is a Governance Issue, Not a Technology Issue

The Australian Prudential Regulation Authority has said that governance and risk management practices “are not keeping pace with the scale, speed, and complexity of AI adoption,” and singled out boards that had relied on vendor presentations without properly examining how the models actually behave.

ASIC Chair Joe Longo has echoed this, telling directors at the AICD Governance Summit in March 2026 that “directors are not passive recipients of information. They must discharge their duties with a high degree of curiosity and care.”

Your existing duties of care, diligence and good faith under the Corporations Act 2001 already apply in full to any AI systems your company deploys. Directors are exposed to this shift in two distinct ways: how the company uses AI, and how directors personally use it. Both are already generating legal cases.

How Your Company Uses AI

As your firm adopts AI tools and systems, whether for design support, quality checks, or client reporting, you carry the same duties of oversight you would apply to any other significant operational change. A failure to understand and govern that usage is a failure of your director’s duties, not a technology problem you can delegate to an IT team or a software vendor.

There is no separate, lower standard because a decision was made by, or with the help of, a model, and outsourcing AI to a vendor does not transfer your accountability for how it is used. The regulators are explicit that oversight of company AI use is not a future problem; it is a current one.

How Directors Personally Use AI

Boards and directors are increasingly turning to AI tools to draft correspondence, summarise a dispute, analyse a complex issue, or research and inform a difficult decision.

That convenience carries a governance cost. AI-generated output may influence, inform or even shape the reasoning behind a board decision. If that decision is later scrutinised, the relevant question will not be whether an AI tool produced the analysis, but whether the director exercised appropriate judgment in relying upon it. The output may become part of the factual record of how a decision was reached, and it will ultimately be judged as part of the director’s reasoning.

This makes the personal use of AI a governance issue, not simply a productivity choice. Directors should understand the limitations of the tools they use, independently verify material facts and assumptions, and avoid treating AI-generated analysis as a substitute for professional advice or their own judgment. Where AI materially informs a decision, directors should also consider whether its use, inputs and outputs should be documented.

Case Study: In the Matter of Lanmar Pty Ltd (No 2)

This case sits especially close to home for engineering firm directors, because the business at the centre of it was a consulting and engineering business.

Two majority directors of the firm used ChatGPT to obtain advice on how to deal with a fellow director and shareholder, and then acted on that advice. The Supreme Court of New South Wales found their conduct, guided by ChatGPT, amounted to oppression under section 232 of the Corporations Act 2001 and involved breaches of directors’ duties under section 181. The directors’ reliance on the AI output formed part of the factual circumstances that led to that finding.

The court ordered a receiver to sell all the shares in the company, effectively forcing a sale of the entire business.

It is a stark reminder that AI tools can inform your thinking, but the judgment, and the legal responsibility for it, remains squarely yours. For an engineering firm board, that same principle applies whether the AI output relates to a shareholder dispute, a project decision, or a technical sign-off.

AI-Generated Information Overload

Using AI allows employees to generate detailed reports, analyses, summaries and supporting materials in minutes, dramatically increasing the volume of information presented to decision-makers without necessarily improving its quality, relevance or reliability. For engineering firms managing complex project data, design documentation, and client reporting, this risk is particularly live.

This can create a significant governance risk. Important risk intelligence may be technically present but effectively invisible to the board. A critical warning can be buried among hundreds of pages of AI-generated analysis, repetitive material, or low-value commentary. The mere inclusion of information somewhere in a board pack does not necessarily mean the board was adequately informed.

In the judgment of recent case, ASIC v Bekier, a key finding was that critical risk intelligence existed within the organisation but never reached the board in a form that enabled it to be understood and acted upon. AI-generated information overload is not a defence to inadequate governance. Boards must be able to rely on reporting systems that identify and surface the information they need to discharge their oversight responsibilities.

Case Study: ACCC v Trivago N.V.

The Australian Government’s AI Safety Standard cites Trivago by name as an example of the risk that algorithms pose to consumers. Trivago’s hotel price comparison website used an algorithmic ranking system to decide which offers appeared most prominently. The Federal Court found consumers were led to believe the top ranked offer was the best deal, when the ranking was heavily influenced by the commission the booking site paid Trivago. The court found breaches of the Australian Consumer Law and imposed a $44.7 million penalty.

Trivago is a Netherlands based company, so this case was pursued against the corporation rather than individual directors. It remains directly relevant to any engineering firm using AI or algorithmic tools, including automated tender evaluation, design optimisation, or scheduling tools, as a similar finding against an Australian company would put its directors’ oversight of that system squarely in the frame.

How Insurance Can Protect You

ThreatPolicy That RespondsHow It Applies
A director is alleged to have breached their duty of care through poor AI oversightDirectors and Officers LiabilityCovers defence costs and damages for claims that a director failed to understand, govern or verify the company’s AI use, consistent with the standard set in cases like Bekier.
An AI system is involved in a data breach, ransomware attack or system outageCyber InsuranceCovers breach response costs, notification, business interruption and, increasingly, specific AI endorsements insurers are now adding to clarify how AI-related incidents are treated.
AI-assisted engineering or professional advice turns out to be wrong and a client suffers lossProfessional IndemnityResponds to negligence claims where AI tools assisted the advice, provided the failure sits within the scope of the professional service being provided.
AI used in recruitment or performance management produces a biased or discriminatory outcomeEmployment Practices Liability (within Management Liability)Covers claims from employees or applicants affected by automated HR decisions, on the same basis as any other discrimination or unfair treatment claim.
A regulator fines the company or a director for an AI governance failureDirectors and Officers Liability or Statutory LiabilityDefence costs for the investigation are typically covered; the fine or penalty itself is usually not insurable, and cover for it is often excluded or capped.
Your firm’s AI system fails and causes a customer financial lossYour IT provider’s own Technology Errors and Omissions, after you have paid the lossResponds to your claim against your IT provider alleging negligence or breach of contract from AI hallucinations, model errors, integration failures, or an AI agent taking an unintended action.

Where This Leaves Engineering Firm Directors

AI governance is not a side issue for engineering firms; it sits directly within existing director’s duties, and it is already generating enforcement action and litigation. The practical response is straightforward: understand where AI is used across the business, put real oversight in place, verify decisions relying on AI output are properly tested, and make sure your insurance programme is structured to respond when something goes wrong.

As your risk partner, we work with engineering firm boards to review where AI exposure sits in the current programme and where the gaps are. If you would like to talk through how your Directors and Officers Liability, Cyber, and Professional Indemnity cover responds to these risks, we are here to help.

The information on this page is intended for general educational purposes and necessarily simplifies some concepts for clarity. Insurance policies can differ widely between insurers, policy types, and jurisdictions. For guidance on your specific circumstances, you should review your policy documents carefully and consult a qualified insurance adviser, broker, or legal professional.