European Boards, American risk: AI chats and the discovery problem.
Two US court decisions in 2026 opened a risk most Boards have not yet considered: AI-assisted Board discussions may not be privileged — and may be discoverable in litigation. The rulings are American. The exposure is not. By Barbara Cresti, Founder, StratEdge.
Two US court decisions in 2026 have opened a risk most Boards have not yet considered. Discussions involving AI — including AI-assisted Board deliberations — may not be protected by attorney-client privilege. And they may be subject to discovery in litigation.
The rulings are American. The exposure is not.
This is the case I have been making to the Boards we advise.
What the American courts just decided.
Two decisions establish the pattern.
In U.S. v. Heppner, Judge Jed Rakoff of the Southern District of New York ruled that AI chat logs are discoverable, on the grounds that AI is ‘not a person and thus not an attorney.’ Attorney-client privilege, by its legal definition, protects communications between a client and a human legal advisor. AI, whatever else it may be, does not qualify.
In Fortis Advisors v. Krafton, the CEO’s ChatGPT-guided earnout strategy was entered as evidence against the company. The chat logs became part of the litigation record. The outcome added 258 days to the earnout period — a specific, measurable financial consequence traceable directly to the AI-assisted conversation.
On 22 July, Fried Frank — one of the leading international law firms — issued a formal warning. Directors using AI for legal questions, the firm said, ‘risk creating discoverable, non-privileged records.’ Its advice to Boards: assume AI use may be discoverable, and put policies in place accordingly.
Why this lands on European Boards.
European Boards may be tempted to see this as an American problem. That reading is wrong for three reasons.
First — cross-border exposure. Any European company with US operations, US listings, or US legal ties can be pulled into US discovery proceedings. The AI chats behind an M&A decision, a restructuring, a compliance dispute — all of these can be requested by US courts, and the American rulings apply. European Boards with US touchpoints inherit the risk immediately.
Second — the substantive confidentiality gap. Regulation of AI systems in Europe governs how AI is deployed, monitored, and audited. It does not extend confidentiality protection to discussions held with AI. A Board member consulting an AI tool on a governance question generates a record. That record has no equivalent of legal privilege — in Europe or anywhere else.
Third — the adoption pattern. According to Diligent’s Q2 2026 survey, 82% of directors now use AI for Board work. Of those, 54% have no AI guidance, and only 6% have formal policies. The Board-level AI conversation is already happening at scale. The governance around it is not.
The Boards that continue on this trajectory are building unmanaged evidentiary exposure — one prompt at a time.
The three exposures European Boards face.
Litigation.
When an AI-assisted decision is challenged — an acquisition price, a workforce restructuring, a disclosure judgment — plaintiffs can subpoena the AI conversations that informed it. The chat history becomes part of the discovery record. Whatever the Board thought it was discussing privately is now in the case file.
Reputation.
Leaked AI chats can reveal unfiltered discussion, draft language never intended for external eyes, and the reasoning behind decisions the Board would prefer to present in a considered final form. The gap between how Boards work in private and how they present in public is where reputational damage lives.
Director liability.
Under European corporate law, directors are held to a fiduciary standard. Directors who rely on AI for material decisions without adequate oversight — no policy, no controls, no audit trail — may find themselves accused of breaching that duty. The AI conversation that shaped the decision becomes evidence of the process, or the lack of one.
What Boards can do now.
Four protective moves are available to any Board today. None require waiting for regulatory guidance.
Restrict Board AI use to closed-loop, corporate-controlled tools with legal oversight. Consumer AI tools generate records outside the company’s control, on infrastructure the company cannot audit. Corporate-controlled tools with legal oversight give the Board the same governance apparatus it applies to other sensitive corporate systems.
Define AI governance policies specific to Board work. Not a general staff AI policy repurposed for directors. A Board-specific policy that names which questions can be put to AI, which tools are approved, what records are retained, and who has access.
Train Board members on AI’s legal risks and the limits of privilege. This is not a technology briefing. It is a legal-risk briefing on what happens to the conversations directors have with AI, and what protections exist — or do not.
Simulate discovery requests. Run the exercise before a real request arrives. What would the company need to produce? What would that produce reveal? Which conversations, if turned into evidence, would create exposure? Simulation is the fastest way to find the vulnerabilities before an adversary does.
Where this leaves Boards.
Every company using AI is making a trade-off between speed and exposure. In most Boards, that trade-off has never been named, discussed, or approved.
What can enter an AI system. What must stay inside the firm. What could later become discoverable.
These are governance decisions, and they belong on the Board’s agenda now — before they become someone else’s decisions, made in a courtroom.
This is what we work on every day at StratEdge.
Turn this insight into action.
Book a 30-minute conversation with StratEdge to explore what this means for your Board, executive team or organisation.
Book a meetingAI compliance in Switzerland: GDPR, FADP and the EU AI Act
Which AI and data rules apply to Swiss companies? A plain guide to the GDPR, the Swiss FADP and the EU AI Act — and a checklist for Boards.
[ ART_01 ]Data governance: from mere compliance to value creation. An IP-driven perspective
In most boardrooms, data is discussed as a compliance risk. Data and intellectual property are intertwined, and IP experts must deep dive into data governance.
[ ART_02 ]Roche is redesigning its R&D operating model.
Roche is shifting its scientists' roles from operators to governors of its autonomous AI labs. A new operating model for R&D that could serve as a playbook to other industries.
[ ART_03 ]