LeadershipNot yet confirmed elsewhere1 publisher3 min readPublished
Wachtell Lipton wants boards to know what their own AI agents are allowed to do
Wachtell Lipton urges boards to check that cyber reporting captures AI risk, citing more than 22,000 AI-related complaints to the FBI in 2025. Delaware's Caremark duty turns on whether that reporting exists, so the firm wants a company's own AI agents inside it.
The Board Room · Leadership desk

What happened
- The memo warns that a company's own AI agents, once compromised, could open a path to sensitive data and to operational or payment systems.
- An advanced AI model reportedly found thousands of previously undetected security flaws in April, including in a widely used, well-defended open source operating system.
- A group of autonomous AI agents worked together to hack a company's systems in July, according to the memo.
- Deepfake risk is rising: in one recent test cited by the authors, 48% of video call participants believed an AI agent was a live human.
Compiled by The Board RoomSomething wrong?How this is made
Why it matters
- exposure A board whose records show no question about agent permissions or AI vendor dependence gives a Caremark plaintiff the kind of specific allegation that has reached discovery.
- decision Audit and risk committees have to decide whether the current cyber report takes on agent permissions, critical-data maps and AI vendor dependence, or whether those need their own escalation line.
- cost Most of the new work lands on management: an agent inventory and a map of critical data have to exist before the board has anything to review.
- constraint Agents that can act on payment or operational systems without human sign-off get harder to defend once the board has asked when human approval is required.
Delaware makes oversight liability hard to establish. Under the Caremark line of cases, directors face it only where they utterly fail to implement a board-level reporting system, or consciously fail to monitor it or respond to red flags [5]. The claim also needs a showing of bad faith [5]. Martin Lipton, Kevin S. Schwartz and David M. Adlerstein, the memo's authors [1], wrote that "ineffective or unsuccessful oversight alone is not enough" [6]. Courts have still let stockholder claims proceed to discovery where the complaint alleges those failures with specificity [7].
The memo's main request is a test boards apply to their own structures. Directors "should consider whether existing reporting-and-escalation structures adequately capture AI-related cyber risks," the authors wrote [8]. Caremark asks whether a reporting system exists and whether anyone watched it [5]. A reporting line built before a company let software agents into its data can pass the first part of that test and still say little about the agents.
For agents, the board's share is a general understanding of the actions they are permitted to take, the controls on their reach into systems and data, the testing of those controls, and the points where a significant action needs human approval [11]. Management builds the rest. That includes a framework identifying the company's most critical data, where it resides and how AI systems use it, with clear accountability for protecting it [9]. It also includes assessing key AI vendors, so the board can see where the company depends on them and what contingency plans exist [12]. Training covers personnel at every level of seniority and may include periodic simulations for spotting deepfakes [14].
An audit committee chair could fairly say the quarterly cyber briefing already covers this. The memo largely keeps that arrangement. Management tracks AI-enabled threats and defenses, drawing on the NIST Cybersecurity Framework and qualified outside experts, and the board receives periodic reports on significant incidents, testing results, remediation status and whether mitigation is working [10]. The difference is in what the briefing has to contain, scaled to a company's size, industry, regulatory environment, data assets, AI uses and threat profile [13].
The loss figures are smaller per incident than the capability claims suggest. Reported losses nearing $900 million across the FBI's AI-tagged complaints for 2025 [4] come to less than about $41,000 per complaint on average [15]. The memo's case rests on capability: AI systems that find and exploit latent vulnerabilities at increasingly modest cost, at a speed and scale beyond human hackers or conventional tools [2], plus the April and July incidents [17][18]. The memo does not identify the model or the company involved.
I think the order of work matters more than the list. The capability claims rest on a handful of incidents, while the reporting question is one a board can answer this quarter [8]. An inventory of agent permissions and a data map drawn up now become the baseline that later testing results and remediation reports are read against [9][11]. Without it, the periodic reports the memo describes have nothing to be compared with [10].
What to watch
- A Delaware Caremark complaint that pleads a board's failure to oversee AI agents or AI vendors with specificity, and whether it survives a motion to dismiss.
- The FBI Internet Crime Complaint Center's next annual figures, and whether AI-tagged losses grow past the nearly $900 million reported for 2025.
- Named details on the April vulnerability finding and the July agent hack, showing whether either is a pattern or a single case.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence40
- Adoption
- Insufficient
- Hype gap+15
- Incentives40
- Confidence55
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
The Harvard Law School Forum post is based on a Wachtell, Lipton, Rosen & Katz memorandum by Martin Lipton, Kevin S. Schwartz and David M. Adlerstein.
- [2]
At increasingly modest cost, AI systems can identify and exploit latent software vulnerabilities, such as by planting malicious code or stealing data, at a speed and scale beyond the reach of human hackers or conventional automated tools.
- [3]
A corporation's own AI agents, if compromised, can become a gateway to sensitive data and to operational or payment systems.
- [4]
In 2025 the FBI Internet Crime Complaint Center received over 22,000 cybercrime complaints with an AI-related descriptor, with reported losses nearing $900 million.
- [5]
Under the Caremark line of Delaware cases, directors may face liability for breach of fiduciary duty only where they utterly fail to implement a board-level reporting or information system or consciously fail to monitor it or respond to red flags; such a claim requires a showing of bad faith.
- [6]
ineffective or unsuccessful oversight alone is not enough
- [7]
Courts have allowed stockholder claims against directors to proceed to discovery where the complaint alleges such failures with specificity.
- [8]
Boards should consider whether existing reporting-and-escalation structures adequately capture AI-related cyber risks.
- [9]
Boards should oversee a data governance framework that identifies the company's most critical data, maps where it resides, tracks how AI systems access or use it, and assigns clear accountability for its protection.
- [10]
Management should track AI-enabled cyber threats and defenses, drawing where appropriate on the NIST Cybersecurity Framework and qualified outside experts; boards should receive periodic reports on significant incidents, testing results, remediation status and the effectiveness of mitigation efforts.
- [11]
Boards should understand in general terms what the company's AI agents are authorized to do, what controls limit their access to systems and data, how those controls are tested, and when human approval is required before they take significant actions.
- [12]
Management should assess the cybersecurity, resiliency and data-handling practices of key AI service providers, and boards should understand where the company is significantly dependent on or exposed to them and what protections and contingency plans are in place.
- [13]
Appropriate measures depend on a company's size, industry, regulatory environment, data assets, AI uses and threat profile.
- [14]
Personnel at all levels of seniority should understand permitted AI uses and safeguards and undergo training, which may include periodic simulations, to identify and flag deepfakes and other threats.
- [15]
Average reported loss per AI-related complaint to the FBI in 2025 was less than about $41,000.
- [16]
In one recent test, 48% of video call participants believed an AI agent was a live human.
- [17]
In April an advanced AI model reportedly uncovered thousands of previously undetected software security flaws, including in a widely used and well-defended open source operating system.
- [18]
In July a group of autonomous AI agents worked together to hack a company's systems.
Sources
1 independent publisher whose own reporting we read for this story.
- corpgov.law.harvard.eduCybersecurity Risk Oversight in the Age of AI
1 article · October 9, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.
Entities
- Wachtell, Lipton, Rosen & KatzFollow
- Martin LiptonFollow
- Kevin S. SchwartzFollow
- David M. AdlersteinFollow
- Harvard Law School Forum on Corporate GovernanceFollow
- FBI Internet Crime Complaint CenterFollow
- NIST Cybersecurity FrameworkFollow
- Caremark Oversight DoctrineFollow