Boardroom Answers · Strategic Command · Risk Management & Governance
Let me be blunt. If this board approves a major decision based on your AI’s analysis, the analysis turns out to be hallucinated, and the company takes a nine-figure loss — who is liable, what happens to my name, and why did your product not prevent it?
The question a Board Member / Non-Executive Director (NED) asks.
The short answer
Liability stays with the board — it always does. What we change is defensibility: four independent controls between a hallucination and your board pack, and a tamper-evident record proving you ran a real challenge process. The business judgment rule protects informed process; we manufacture the evidence of it.
The full executive answer
Let me answer the liability point first, without hiding: the board is liable, as it always was — no AI tool transfers fiduciary duty, and any vendor who implies theirs does is selling you a lawsuit. The correct legal frame is the business judgment rule: directors are protected when they make informed decisions in good faith on a reasonable process. So the real question is whether using Vouli IQ makes your process more defensible or less — and that is a question about evidence, which is exactly what this platform is built to generate. Every analysis carries a hash-chained, append-only record of what was generated, from which inputs, checked by which controls, reviewed and approved by which humans, when. In the litigation scenario you describe, that record is the difference between "the board relied on an unexamined machine" and "the board ran a documented challenge process" — the second is what the business judgment rule protects.
Second, what the product does to prevent the scenario rather than merely document it. Four independent shipped controls stand between a hallucination and your board pack: numeric provenance validation — every figure in the output is traced to source data, and unsupported numbers are flagged before rendering; guardrail hard-blocks that stop policy-violating output entirely; cross-provider consensus on the flagship modules — two independently trained AI systems generate the analysis separately and are compared, with a third model adjudicating material disagreement, so a single model’s confabulation is caught by an engine that does not share its failure modes; and a mandatory human approval gate through the approvals engine before analysis becomes decision input. This is the SR 11-7 model-risk pattern — independent validation and effective challenge — applied to boardroom analysis.
Third, the discipline point, which I will volunteer because it protects you: the product is decision support, not decision delegation, and our own guidance says the board should treat AI analysis the way an audit committee treats management representations — as input to be challenged, with the challenge documented. If a director asks "what did we do to test this analysis?", the platform is the answer to that question. If a board wants a tool that lets them skip that question, we are the wrong vendor, and I would say so in the sales process.
What I will not claim: no system reduces hallucination risk to zero, ours included, and we are pre-launch with no case-law track record. What exists today is layered, independently checking, CI-tested controls plus an evidentiary record designed for exactly the day you are describing. That is more process protection than any board currently gets from the ungoverned AI use already happening inside its management team.
Grounded in: Business judgment rule (fiduciary duty of care) · SR 11-7 (independent validation / effective challenge) · NIST AI RMF (Measure/Manage)
The natural next questions
Related governed answers
- Our vendor-risk policy would normally screen out a company your size. Escrow, data portability, continuity — walk me through why engaging you is a governable risk rather than a policy exception.?
- As a director I see risk through a heat map twice a year, and I know it is theatre. What does board-level risk reporting look like out of your platform, and how is it less theatrical?
- The EU AI Act is now enforcing. Where does your platform sit under it — and is any of it high-risk?
Want this answered live, on your data?