Legal 14 min read

Your CEO Could Be Personally Liable Under the AI Act — Here's How

The EU AI Act doesn't just fine companies — it can hold individual executives accountable. We break down the personal liability provisions that every board member and C-suite leader needs to understand before August 2026.

By Dr. Henri Dubois · Published

The Liability No One Is Talking About

When most executives hear about the EU AI Act, they think in terms of corporate fines — up to €35 million or 7% of global annual turnover. That number alone gets attention. But buried in the regulation's enforcement provisions is something far more personal: individual accountability for the people who sign off on AI deployment decisions.

This isn't theoretical. Under the EU AI Act's framework, combined with existing EU Member State corporate governance laws, executives who knowingly deploy prohibited AI systems or wilfully ignore high-risk compliance obligations face potential personal liability, including criminal penalties in some jurisdictions. And unlike GDPR, where enforcement has been somewhat slow, the AI Act was designed with teeth from the start.

How Executive Liability Works Under the AI Act

1. Directing Mind Doctrine

Under EU corporate law principles applied across Member States, when a company commits a regulatory violation, the individuals who constituted the "directing mind and will" of the company at the time can be held jointly liable. If a CEO or CTO approved the deployment of an AI system that violates Article 5 (prohibited practices), they cannot simply hide behind the corporate veil.

2. National Criminal Law Provisions

Several EU Member States are implementing the AI Act with criminal penalties for the most serious violations. Germany's draft implementation includes provisions for individual criminal liability when executives knowingly deploy prohibited AI systems. France and Italy are exploring similar approaches. This means that in certain jurisdictions, deploying a social scoring system or manipulative AI could result not just in a corporate fine, but in criminal charges against the responsible executive.

3. Director Duties and Fiduciary Obligations

Beyond the AI Act specifically, company directors have a fiduciary duty to ensure their organizations comply with applicable laws. Failing to implement an AI compliance program when the company clearly operates high-risk AI systems could constitute a breach of fiduciary duty, exposing directors to personal civil liability from shareholders and investors.

The Three Scenarios That Keep Lawyers Awake

Scenario 1: Deploying a Prohibited AI System

The highest risk for personal liability involves Article 5 prohibited practices, which are already in force since February 2025. These include AI systems that use subliminal techniques to manipulate behaviour causing harm, social scoring systems by public authorities, real-time remote biometric identification in public spaces (with limited exceptions), and AI that exploits vulnerabilities of specific groups. If a CEO greenlights any of these systems with knowledge of the prohibition, they are personally exposed. The fine alone can reach €35 million or 7% of turnover — and in jurisdictions with criminal provisions, it goes further.

Scenario 2: Ignoring High-Risk Compliance Requirements

By August 2026, high-risk AI systems must meet extensive requirements. An executive who is aware that the company operates high-risk AI (for example, AI in recruitment or credit scoring) but deliberately fails to allocate budget or resources for compliance could face fines up to €15 million or 3% of turnover, personal liability for breach of fiduciary duties, and potential insurance coverage denial if D&O insurers determine wilful negligence.

Scenario 3: Providing False Information to Authorities

Under Article 99(4)(e), supplying incorrect, incomplete, or misleading information to national authorities or notified bodies attracts fines up to €7.5 million or 1% of turnover. If a compliance officer or executive signs off on a conformity declaration knowing the documentation is inaccurate, that's a direct personal liability trigger — and it mirrors the kind of executive certification requirements seen in financial regulation (think Sarbanes-Oxley).

What Boards Should Do Now

Step 1: Establish Board-Level AI Governance

Appoint a Chief AI Officer (CAIO) or assign AI Act compliance responsibility to a named board member. This isn't optional — it's about establishing a clear chain of accountability. The worst position to be in is one where "nobody owned it."

Step 2: Get a Legal Risk Assessment

Commission an independent review of all AI systems currently in use across the organization. Map each system against the AI Act's risk categories. Pay special attention to HR and recruitment AI tools, customer scoring and creditworthiness models, content moderation algorithms, and any biometric processing systems.

Step 3: Review D&O Insurance Coverage

Check whether your Directors & Officers insurance explicitly covers AI regulatory violations. Many existing policies have exclusions for "regulatory fines" or "wilful violations" that could leave executives personally exposed. Update the coverage now, before premiums spike post-enforcement.

Step 4: Document Every Decision

Create an audit trail for all AI-related decisions at the board level. Meeting minutes should record that AI risks were discussed, that compliance was considered, and what actions were approved. In any future enforcement action, the difference between "the board was aware and took action" versus "the board never discussed it" is the difference between a corporate fine and personal liability.

Step 5: Budget for Compliance — Visibly

Allocating dedicated budget for AI Act compliance serves as evidence that the organization — and its leadership — took the regulation seriously. If enforcement happens, a documented compliance investment demonstrates good faith, which can significantly reduce fines under the AI Act's proportionality provisions.

The Insurance Problem

Major D&O insurers including AIG, Allianz, and Zurich are reviewing their policy wordings in light of the AI Act. Early indications suggest that policies may exclude AI Act fines from standard D&O coverage, insurers may require evidence of an AI compliance program as a condition of coverage, and premiums will increase for companies operating high-risk AI without documented compliance frameworks. This creates a double exposure: executives are personally liable under the regulation AND may not be insured for that liability.

The Bottom Line

The EU AI Act transforms AI governance from a nice-to-have corporate initiative into a personal legal obligation for executives. The clock is ticking toward August 2026. CEOs, CTOs, and board members who haven't yet engaged with their AI compliance posture are running a risk that is both quantifiable and personal.

Don't be the executive who signed off on a high-risk AI system without reading the regulation.

Need expert guidance on executive AI liability? Search our directory for legal advisors specializing in AI Act compliance and corporate governance.