Skip to main content
v2026.11,858 entries · CC-BY 4.0

Board Oversight of Frontier AI: What Caremark Actually Requires

Delaware’s Caremark doctrine requires boards to attempt in good faith to ensure a reasonable information and reporting system exists. Firms are now extrapolating that duty to AI risk the way they did for cybersecurity a decade ago — but no Delaware court has yet applied Caremark to an AI-risk fact pattern. This is what the doctrine actually holds, what NACD’s new director certificate teaches, and where that leaves a board writing an AI-oversight charter today.

Written and maintained by CASRAI Editorial Board

Last updated

Last verified: September 20, 2026. Delaware’s Caremark doctrine does impose a real, decades-old board oversight duty of care — but no Delaware court has yet applied it to an AI-risk fact pattern. What consultancies and law departments now call a board’s “AI oversight duty” is an extrapolation from a settled corporate-law doctrine to an unsettled one, not itself settled law. This guide separates the two, and looks at where CASRAI’s own NIKOLAI project offers an independent, unendorsed vocabulary for the record-keeping side of that extrapolation.

This page explains what Delaware case law says and does not say. It is general information, not legal advice, and it is not a substitute for advice from qualified Delaware corporate counsel about any specific board’s obligations.

What the Caremark Doctrine Actually Holds

In re Caremark International Inc. Derivative Litigation, 698 A.2d 959 (Del. Ch. 1996), is the origin case. Then-Chancellor William T. Allen of the Delaware Court of Chancery addressed a derivative suit alleging that Caremark’s board had failed to prevent employee conduct that led to federal Anti-Kickback Statute violations and roughly $250 million in fines and civil settlements. The opinion did not find the board liable — it approved a settlement — but its reasoning became the doctrine’s foundation.

  • Case: In re Caremark Int’l Inc. Derivative Litigation, 698 A.2d 959 (Del. Ch. 1996).
  • Court: Delaware Court of Chancery (Chancellor William T. Allen).
  • What it requires: a director must make “a good faith attempt” to ensure “a corporate information and reporting system” exists, adequate to bring material risks and compliance issues to the board’s attention.
  • Liability standard: oversight liability attaches only where there is “a sustained or systematic failure of the board to exercise oversight” — not merely a bad outcome, a missed risk, or an imperfect system.
  • What it is not: a duty to catch every problem, or a basis for second-guessing a board’s substantive business judgment. Caremark liability runs to the board’s failure to try to know, not to any specific decision it made once informed.

Marchand v. Barnhill: The Doctrine’s Most Consequential Application

Marchand v. Barnhill, 212 A.3d 805 (Del. 2019), is the case that reaffirmed and sharpened Caremark more than two decades after it was decided. The Delaware Supreme Court reversed a Court of Chancery dismissal in a derivative suit against the board of Blue Bell Creameries, following a 2015 listeria outbreak traced to Blue Bell ice cream that caused several deaths and a nationwide product recall.

  • Case: Marchand v. Barnhill, 212 A.3d 805 (Del. 2019).
  • Court: Delaware Supreme Court.
  • Key fact pleaded: Blue Bell’s board had no committee, no protocol, and no regular reporting channel addressing food safety — the company’s single most “mission critical” compliance risk — even though food safety was central to its entire business.
  • Holding: the plaintiff’s Caremark claim survived a motion to dismiss because the complaint pleaded particularized facts that the board had made no effort at all to put a monitoring system in place for that central risk. The Court restated Caremark’s core language directly: an “utter failure to attempt to assure a reasonable information and reporting system exists” is what triggers liability.
  • Why it matters beyond Blue Bell: Marchand signaled that Delaware courts will let a Caremark claim proceed past the pleading stage where a company’s board can be shown to have had no monitoring system at all for a risk that is central — “mission critical” — to that company’s business, not a general failure to anticipate every conceivable harm.

Is There an “AI Oversight Duty” Under Caremark? Not Yet.

No Delaware court, Court of Chancery or Supreme Court, has decided a Caremark case built on an AI-risk fact pattern as of this writing. Every claim in this section that goes beyond that fact is explicitly labeled as extrapolation, not as existing law, because that is exactly what it is.

  • What is settled: Caremark and Marchand establish that a board owes a duty to attempt, in good faith, to put a reasonable information and reporting system in place for risks that are central to the company’s business, and that an utter failure to do so can support liability.
  • What is not settled: whether, or how, a court applying that standard to frontier AI development or deployment would treat AI safety risk as “mission critical” in the Marchand sense, what would count as a “reasonable” AI-oversight information system, or how a board’s good-faith effort would be judged against a field where the underlying technical risks are still being defined.
  • The pattern this follows: risk consultancies and corporate law departments extrapolated Caremark to cybersecurity oversight in a similar way roughly a decade ago, well before any single Delaware decision resolved what a board’s cyber-oversight duty specifically required — treating a general doctrine as a lens for a new risk category ahead of case law that tests it directly. AI-oversight discourse is following the same pattern now: real doctrine, applied by analogy, ahead of any court actually deciding the question.
  • What this means in practice: a board, or a vendor, that asserts boards already have “an AI oversight duty” under Delaware law is overstating the state of the law. The accurate statement is narrower: Caremark’s general oversight duty exists, is well established, and would plausibly apply to a company whose central business risk includes frontier AI development or deployment — but no court has yet said so, and what a “reasonable” AI-specific reporting system would look like has not been tested.

What Boards Are Actually Doing: NACD’s AI Oversight Certificate

Separately from the open legal question, boards are visibly building AI-oversight competency right now. The National Association of Corporate Directors (NACD), in partnership with Carnegie Mellon University’s Heinz College, offers the Effective AI Oversight for Directors Certificate — confirmed directly from NACD’s own program page. It is a ten-module, fully online curriculum (about 22 hours of coursework, up to six months to complete, followed by a final exam with two attempts) aimed specifically at corporate directors rather than technical staff.

  • Program: Effective AI Oversight for Directors Certificate.
  • Offered by: NACD, in partnership with Carnegie Mellon University’s Heinz College.
  • Format: 10 asynchronous online modules, ~22 hours total, up to 6 months to complete, final exam included.
  • Two modules of direct relevance here: “Responsible AI Governance” and “Securing AI: Ensuring Resilience, Reliability, and Trustworthiness.”
  • Other modules: enterprise data management fundamentals, aligning data and AI strategy, data-driven decision making, demystifying AI, data/AI infrastructure for stakeholders, the role of the data and AI leader, and a closing integration module.

The existence of a director-level certificate program is itself evidence of the trend this guide describes: boards are formalizing AI-oversight competency well ahead of any Delaware court resolving what Caremark specifically requires of them on AI risk. A certificate is a competency credential, not a legal compliance floor — completing it does not, by itself, satisfy or define a Caremark-style oversight duty, settled or extrapolated.

Where NIKOLAI Fits

CASRAI’s own NIKOLAI project — an independent, unendorsed reference dictionary of frontier-AI-safety terms, not a governance standard — includes an element built for exactly the record-keeping gap this guide describes: Accountable Decision-Maker and Sign-Off (N9, Commitments and Governance track). Verified directly against NIKOLAI’s live element page on September 20, 2026, the element defines a record capturing “the named role (and, where applicable, the named person) who approves a threshold determination, risk-acceptance decision, deployment decision, redaction, or framework change, together with documentation of what was approved, by whom, and when.” NIKOLAI’s own page is explicit that this is “CASRAI’s own proposed definition, not a definition any named organisation has agreed to” — it is not offered as a legal standard, a Caremark compliance checklist, or anything endorsed by Delaware courts, NACD, or any AI developer.

The connection to this guide is structural rather than legal: whatever a board decides an AI-oversight information and reporting system should capture in order to satisfy its good-faith Caremark obligation, that system needs a record of who signed off on what and when. NIKOLAI’s N9 element is one independent, unendorsed proposal for the shape of that record — named role, named person where published, and a timestamped approval trail — that a board could choose to borrow when drafting an AI-oversight charter, the same way it might borrow a vocabulary rather than a rule. NIKOLAI’s own crosswalk work on this element (documented on the element page itself) found real variation among frontier AI developers in who actually holds sign-off authority — Anthropic and OpenAI point to CEO or designated-leadership sign-off, Meta names a Chief AI Officer, the EU’s GPAI Code of Practice spreads responsibility across five organizational levels, and Google DeepMind and xAI describe named governance functions without specifying a role as precisely — which is itself a useful data point for a board asking what “reasonable” looks like elsewhere in the field, short of any of it being an adopted or endorsed standard.

What This Means for a Board Writing an AI-Oversight Charter

None of the following is legal advice, and none of it is a claim about what Delaware law currently requires. It is a practical reading of where the settled doctrine, the unsettled extrapolation, and the visible market response (NACD’s certificate, NIKOLAI’s proposed vocabulary) currently leave a board.

  1. Do not describe an “AI oversight duty” as settled Delaware law in board materials or public disclosures. Caremark’s general oversight duty is settled; its application to AI risk is not, and overstating that distinction creates its own disclosure risk.
  2. Treat AI risk as “mission critical” wherever it plausibly is one, in the sense Marchand used that phrase — a company whose products, safety posture, or regulatory exposure depend materially on frontier AI systems is the kind of company where a court would most plausibly extend Caremark’s logic, by analogy to how it extended it to food safety at Blue Bell.
  3. Put a reporting system in place before a court asks whether one existed. The lesson of both Caremark and Marchand is that the absence of any system, not the imperfection of an existing one, is what exposes a board — a committee, a regular reporting cadence, and a named point of escalation for AI safety issues are the low bar Caremark actually sets.
  4. Keep a timestamped sign-off record independent of whether NIKOLAI, NACD, or any other vocabulary is used to structure it — the record itself, not the label attached to it, is what a good-faith reporting system needs.
  5. Revisit this as Delaware case law develops. The moment a Delaware court decides a Caremark claim on an AI-risk fact pattern, the “extrapolation” framing in this guide will need to be updated to reflect settled law; it has not happened as of this writing.

Frequently Asked Questions

Does Delaware law require boards to have an “AI oversight duty”?

Not as a distinct, named legal duty. Delaware’s Caremark doctrine requires directors to make a good-faith attempt to ensure a reasonable information and reporting system exists for risks central to the company’s business, and Marchand v. Barnhill (2019) shows that duty applied to a “mission critical” risk (food safety). No Delaware court has yet decided a Caremark case built on an AI-risk fact pattern, so whether or how that standard applies specifically to AI risk remains an open question, not settled law.

What is the actual legal standard under Caremark?

Oversight liability requires “a sustained or systematic failure of the board to exercise oversight” — language from In re Caremark Int’l Inc. Derivative Litigation, 698 A.2d 959 (Del. Ch. 1996), quoted and applied in Marchand v. Barnhill, 212 A.3d 805 (Del. 2019). A single missed risk or an imperfect system is not enough; the standard targets an utter failure to even attempt to put a reasonable reporting system in place.

What did Marchand v. Barnhill actually decide?

The Delaware Supreme Court held that a derivative Caremark claim against Blue Bell Creameries’ board could proceed past a motion to dismiss, because the complaint pleaded particularized facts that the board had no committee, protocol, or reporting channel for food safety — the company’s central “mission critical” risk — following a 2015 listeria outbreak. It did not resolve the underlying liability question on the merits; it held the claim was well-pleaded enough to proceed.

Is NACD’s AI oversight certificate a legal requirement?

No. The Effective AI Oversight for Directors Certificate, offered by NACD with Carnegie Mellon University’s Heinz College, is a voluntary director-education credential. Completing it is not a Caremark compliance requirement and does not, by itself, establish that a board has satisfied any oversight duty, settled or extrapolated.

Is NIKOLAI’s Accountable Decision-Maker element a governance standard boards must follow?

No. NIKOLAI is CASRAI’s own independent, unendorsed reference dictionary. Its N9 Accountable Decision-Maker and Sign-Off element is a proposed vocabulary for recording who signed off on an AI-related decision and when — useful as a starting structure for a board’s own AI-oversight charter, but not an endorsed standard, a legal requirement, or a substitute for qualified corporate counsel’s advice on Delaware fiduciary duties.

Related Reading

Follow CASRAI

Research-administration guidance, standards updates and independent tool reviews.

Ask CASRAI · free to try

Ask about Board Oversight of Frontier AI: What Caremark Actually Requires

Ask your first 2 questions free below. Subscribers get 150 a day for $29 a month.

Ask CASRAI answers research-administration questions and cites the passages behind every claim. When our sources don't cover a question, it says so.

Answers draw on CASRAI's guides and dictionary plus the federal and funder documents we index: Federal Register, Grants.gov, Regulations.gov and UKRI.

Works on this site and inside Claude, Cursor and the AI tools you already use.

Everything CASRAI publishes — this page, the dictionary, the guides and the news — stays free to read, with no account and no card.

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →