ICYMI
Should You Add a Bot to Your Board?
Executive Summary
Courts can treat use of a technology as part of ‘reasonable care’ (the legal standard for the precautions a careful and competent firm would take).
The expected standard of reasonable care moves as technology matures and the benefits become measurable.
Firms can face significant penalties when they fail to implement the technology that is required to deliver reasonable care.
Recent legal developments show how a claim for AI non-use could arise. Expectations are likely to develop task by task.
Firms should document where AI is required, optional or prohibited, and the reasons for each decision.
On 10 March 1928, two tugs were towing coal barges along the New Jersey coast when a gale hit and the barges sank. Storm warnings had been broadcast on the radio, but neither tug had a working receiver. Radios were cheap and available but not yet commonly used by tugs.
When the case came to court, the judge, Learned Hand, rejected the owners’ defence that radio receivers were not yet general practice in the trade. He wrote that “a whole calling may have unduly lagged in the adoption of new and available devices.” The decision showed that a court may rule that use of a technology is a requirement even if the industry has not generally adopted it.
For the past few years, boards have asked whether it is safe to use AI. Soon they may also need to ask whether it is safe, and legally defensible, not to use it.
Expected Standards Move as Technology Matures
Firms are legally required to take ‘reasonable care’ in their duties towards customers, employees or others affected by their conduct. For example, they must provide protections such as hard hats to keep employees safe. The standard of reasonable care is specific to context, and changes over time, sometimes in response to new technology.
Assessing shipyard hearing-loss cases in 1983, Mr Justice Mustill found that the whole industry was taking “the same line of inaction” on ear protection. He concluded that employers failing to provide hearing protection after 1963 were negligent.
A technology breakthrough can change the expected standard almost immediately. Before 1985, blood banks had no licensed test to screen donations for evidence of HIV infection. In March that year, the FDA licensed the first antibody test and US public-health authorities recommended that all donated blood and plasma be tested. Screening then became routine and changed what safe practice required.
Falling Behind Can Create Serious Liability and Penalties
Firms failing to meet the expected standard of reasonable care can face negligence claims. Regulators can also penalise organisations for failing to implement or operate established controls. Britain’s data regulator fined Tuckers, a criminal defence firm, £98,000 after a cyber breach linked in part to missing multi-factor authentication (MFA). It later fined Advanced, an NHS software supplier, £3.07 million after gaps in its deployment of MFA contributed to a ransomware incident. The Information Commissioner, John Edwards, said there was “no excuse for leaving any part of your system vulnerable.”
NatWest offers another example. In 2021 it was fined £264.8 million after an FCA prosecution for money-laundering breaches, as the bank’s automated monitoring system wrongly treated some cash deposits as cheque deposits.
These cases do not prove that firms must use AI, but that liability or penalties can follow when an established control is missing, incomplete or poorly supervised.
The Legal Route to AI Non-Use Liability Is Emerging
Recent developments show how an AI non-use claim might be framed. In July 2026, the UK Jurisdiction Taskforce published a legal statement on liability for AI harms under English law. The Law Society said it clarifies when professionals may be liable for using, or failing to use, AI.
The statement is not a judgment and does not create a general duty to use AI. But it does conclude that existing professional-negligence principles may apply where a reasonably competent professional would have used a particular AI tool for a particular task.
AI Expectations Will Emerge Task by Task
AI use is unlikely to become an expectation across a whole profession or sector at once. Rather, expectations will develop around specific tasks where evidence, availability and adoption come together.
For example, NHS England says AI decision support is now used across every regularly admitting stroke service in England. At primary stroke centres, AI use was associated with a 64-minute reduction in the time taken to assess and transfer patients (other factors also drove the improvement). National deployment does not by itself establish a legal duty, but it does make non-use easier to challenge. A hospital can now be asked whether the AI system was used, and for the reasoning behind the decision.
Clinical guidance is also starting to recognise specific AI uses. The American Diabetes Association’s 2026 Standards of Care say that FDA-approved AI algorithms are an appropriate strategy for improving access to diabetic-retinopathy screening.
Professional bodies are beginning to treat AI knowledge as part of competence. The Bar Standards Board’s guidance lists basic AI awareness, and evaluation of the risks, benefits and costs of new technologies, as good practice.
How to Tell When Non-Use Is Becoming Risky
Non-use of AI becomes more difficult to defend when several signals appear together:
• A recognised benefit in accuracy, speed, safety or cost has been demonstrated.
• The tool is widely available at a proportionate cost.
• Comparable organisations are adopting it for the same task.
• Regulators or professional bodies recognise the use case.
• There is a reliable process for human review, monitoring and accountability.
• Failure to use the tool could have a material consequence.
Actions for Executives
To date, I have not found any example of a prosecution or penalty due to non-use of AI, so immediate risks are low. Nevertheless, firms should establish a framework to ensure that future risks are understood and managed:
Set clear rules for material tasks. Identify tasks where AI could have a meaningful impact on accuracy, safety, consumer protection or regulatory compliance. For each such task, state where AI is required, prohibited or optional.
Build an audit trail. Where AI non-use could be challenged, record the reason for not using it with supporting data. Keep evidence of competence and oversight, including training records and evaluation results.
Update your position periodically. Review regulatory and professional-body guidance. Ask customers, insurers and comparable firms what they regard as normal practice.
Ask your insurers. Premium discounts and underwriting expectations are early signals of where non-use is becoming hard to defend. RLI already prices AI-based safety monitoring into cover.
The barge owners followed common industry practice, but were found liable anyway, as the whole trade had fallen behind the standard the court expected.
AI adoption is moving so quickly that it is hard to determine where its use might become part of reasonable care. Firms that establish a clear framework for managing decisions to use or not to use AI will be better placed when the standard moves.
Board Questions
• Which of our tasks are approaching the point where AI non-use would need to be justified?
• What evidence would cause us to change our current position?
• Could we explain our decisions after an adverse event?
Sources & Notes
1. The T.J. Hooper. 60 F.2d 737 (2d Cir. 1932): Learned Hand held that industry custom is evidence of reasonable care, not its conclusive measure. Judgment.
2. Professional custom. Thompson v Smiths Shiprepairers (North Shields) Ltd [1984] QB 405 treated shipyard employers following “the same line of inaction” on ear protection as negligent from 1963. Case summary.
3. HIV screening. The US Public Health Service recommended screening all donated blood and plasma in January 1985, the FDA licensed the first ELISA test kits in early March, and blood banks were screening routinely within weeks. MMWR report.
4. Missing controls. The ICO fined Tuckers £98,000 in March 2022 and Advanced £3.07 million in March 2025 over missing or incomplete security controls, and the FCA’s prosecution of NatWest ended in a £264,772,619.95 fine in 2021. Tuckers penalty notice. Advanced announcement. FCA announcement.
5. UKJT legal statement. The UK Jurisdiction Taskforce’s July 2026 statement, expert analysis rather than binding precedent, concludes that professional-negligence principles may apply where a reasonably competent professional would have used a particular AI tool. UKJT statement. Law Society summary.
6. NHS stroke pathway. NHS England’s December 2025 evaluation, observational rather than causal, associated AI-supported scan review with a 64-minute reduction in assessment and transfer time at primary stroke centres. NHS England account.
7. Clinical pathways. The American Diabetes Association’s 2026 Standards of Care recognise FDA-approved AI algorithms as an appropriate strategy for diabetic-retinopathy screening, an option rather than a mandate. ADA Standards.
8. Professional competence. The Bar Standards Board’s May 2026 guidance lists basic AI awareness and evaluation of the risks, benefits and costs of new technologies as good practice. BSB guidance.
9. Insurance signals. RLI’s November 2025 premium discounts for AI-based safety monitoring and the Lloyd’s Market Association’s underwriter survey are market signals, not evidence of a legal duty. RLI programme. LMA survey.
10. Current misuse cases. Mata v Avianca, Inc., 678 F. Supp. 3d 443 (S.D.N.Y. 2023), sanctioned lawyers over fabricated AI-generated authorities, and reported litigation to date concerns misuse rather than non-use. Docket.

