AI and ESG aren't creating new D&O risks, they're just new routes to old ones, Trisura expert says

Boards worried about exotic new liabilities from AI and ESG are missing the point, the real exposure is the same old duties of accuracy and oversight, just running through new channels

AI and ESG aren't creating new D&O risks, they're just new routes to old ones, Trisura expert says

Professional Risks

By Branislav Urosevic

Boards worried that artificial intelligence and ESG have opened entirely new categories of liability are, for the most part, misreading the risk, according to Lesley Rowe (pictured), vice-president of executive solutions at Trisura, which writes directors and officers cover primarily in the small and mid-market space. Neither is a new peril, she said. Both are new avenues to the exposures boards have always faced.

ESG is the clearer case, because the term is not new even if the pressure around it is. It covers environmental, social and governance factors – often non-financial indicators that nonetheless carry real financial consequences, Rowe said. The environmental piece is intensifying mainly because boards have to think about it more often. Where a flood might once have been treated as a one-in-100-year risk, she said, in some regions it is now closer to one-in-10, which forces questions about whether operations can continue and whether there is a continuity plan. "Do you have a continuity plan in place for those kinds of risks that are becoming more frequent now?" Rowe said, adding that the risk management those questions demand costs money – a company may need a second location to operate from if one site is under threat.

The sharper ESG exposure, though, is the gap between what a company says and what it does. Rowe said the area drawing attention now is whether a company's external representations match its actual operations, whether it is making public commitments without the practices to back them.

"Are you calling yourself green when in fact you're not, or you're not doing anything to manage that?" she said. That mismatch, she said, is where greenwashing becomes a trigger for Competition Act violations or investigations – conduct that would once have fallen under false advertising, but which regulators have specifically legislated against to stop companies making claims they cannot measure or prove. Public companies also carry disclosure and supply-chain obligations, she noted, including obligations under Canada's Fighting Against Forced Labour and Child Labour in Supply Chains Act (sometimes referred to as modern slavery legislation).  Certain private companies can also be subject to its requirements depending on their activities and size.

AI follows the same logic, Rowe said, even though the technology is newer. Large language models are not new to insurers, who have long used them on large data sets; what is new is agentic and generative AI. For companies using an out-of-the-box tool rather than building their own, the obligation is to understand the technology and its pitfalls – and to supervise its use, which may mean bringing in expertise. The exposure it creates, she said, is not novel so much as amplified. "What AI does and can do is amplify existing issues," Rowe said.

Her example is hiring. A company that already has bias in its hiring practices, and lets an AI tool learn from that pattern without checking whether the model has drifted or is running properly, can still end up with a discrimination claim – the same employment-practices liability boards already face. The difference is scale. Run that flawed process across a far larger volume of resumes, Rowe said, and the question becomes whether the resulting exposure is bigger than it would have been by hand. It is, in her framing, the potential scaling of a problem rather than a new problem. Even so, she said, "we're not really seeing it as a new peril in the D&O."

The same is true of AI-washing, the AI counterpart to greenwashing, which she said mostly affects public companies making disclosures. The exposure arises when a company represents that AI is doing something it is not – streamlining a process, say, in a way that lets it claim it can scale operations and take on larger clients. If that turns out to be untrue and the company cannot hold its contractual commitments or deliver the services it promised, Rowe said, it becomes misrepresentation – and misrepresentation is familiar territory. It can drive Competition Act violations, shareholder lawsuits when the forecast earnings do not materialise, and unhappy clients when the promised service does not.

That, she said, is the thread tying both together. The regulatory hooks, the shareholder claims and the employment exposures are the same ones D&O has always responded to; AI and ESG simply create new routes into them. The practical takeaway for boards, in her telling, is not to treat either as an exotic new risk to be insured against separately, but to recognise that the old duties – accuracy in what you represent, oversight of how you operate – now apply to a wider set of tools and claims.

"It's not exactly a new kind of peril," Rowe said, "but a new avenue for those types of issues."

Related Stories

Keep up with the latest news and events

Join our mailing list, it’s free!