Corporate Governance 2025

GERMANY Trends and Developments Contributed by: Stephan Waldhausen, Moritz Pellmann, Justus Anacker and Cristina Hajek Gross, Freshfields

and enhanced market foresight. Generative AI, in particular, accelerates innovation by automating knowledge-intensive tasks. However, this massive potential introduces new uncertainties. Rapid AI development challenges business models, disrupts sectors, and raises complex ethical and legal questions. For boards, the task is not merely adoption, but responsible governance aligned with fiduciary duties. Therefore, boards should institutionalise the following six key principles with respect to the usage of AI generated information in decision- making processes at board level: Legality The board must ensure compliance with all applicable laws, particularly AI-specific regula - tions such as the EU AI Act and data protection regulation such as the GDPR (Regulation (EU) 2016/679). Careful decision-making Boards must make well-informed decisions on whether and how to deploy AI, weighing both opportunities and risks. Given the potential impact of AI developments on most businesses, abstaining from decision-making is no longer a risk-free option. Consequently, the management and supervisory boards should establish clear responsibilities through their internal rules of procedure. Non-delegable responsibility While AI can support decision-making, the ulti - mate responsibility and decision-making author - ity must remain with human board members. Fur - thermore, board members must validate the AI’s output and assess its plausibility. The rationale behind AI-generated recommendations must be both explainable and traceable. The board must

also be able to demonstrate how AI-informed decisions were reached, and explain why these decisions were reasonable and in the company’s best interests. Human supervision The board members need to ensure continuous supervision of AI systems, especially for those that learn and evolve, to identify potential mal - functions or unintended outcomes. Technical competence Board members also need to ensure that the organisation has sufficient knowledge of AI use, since understanding, overseeing and critically assessing AI-generated results is essential. Organisational measures If AI tools are introduced, boards are expected to implement effective risk management, monitor - ing, and documentation processes for AI usage. This includes: • regular audits of AI systems to detect and correct bias in training data and outputs, in order to reduce the risk of discriminatory outcomes and support the legitimacy of AI- assisted decisions; • protection of AI systems against manipula - tion, external attacks, and operational failures (including aligning with recognised cyberse - curity standards and ensuring resilience when integrating AI into existing IT infrastructures); • continuous monitoring and documentation of the performance, stability, and data quality of AI systems, ensuring that AI systems remain fit for purpose. The EU’s AI Act (Regulation (EU) 2024/1689) reinforces these requirements by introducing a binding classification system for AI applica - tions, including prohibited risk (eg, social scor -

320 CHAMBERS.COM

Powered by