TwinLadder Weekly
Issue #47 — The Duty Got Lighter. The Liability Got Heavier.
1 August 2026 · Weekly intelligence on judgment, governance, and the boards accountable for both
Editor's Note
From Alex —
Two dates, nine days apart.
On Monday 27 July, Regulation (EU) 2026/1744 entered into force and rewrote Article 4 of the AI Act. The duty to build AI literacy across your workforce became a duty to take measures towards it. The amended text says so in terms: the obligation "does not require providers or deployers to guarantee any specific level of AI literacy of any individual." Every organisation that built a competence programme because a statute demanded an outcome now owes a smaller thing — a documented effort.
On Wednesday 29 July, Cornerstone Research published its midyear count of US securities class actions. Fifteen of the first half's filings were AI-related. Those fifteen carried seventy-three per cent of the alleged investor losses in the entire period: $385 billion of $529 billion.
The floor under the competence obligation dropped in the same fortnight the ceiling over the liability rose.
I have watched enough technology transitions to know what happens next. The calendar sets the pace. The calendar moves. The programme slows. And nobody goes back to re-read why the programme existed.
So this issue asks that question directly, because I think it was answered wrongly the first time. If the work was being done because Article 4 demanded a result, the case for continuing looks thinner this month. If it was being done because the organisation carries the consequences of people who cannot judge an AI output, the case is stronger than it was in June — and stronger by a figure produced by people with nothing to sell on the subject.
Liga has the ledger of those nine days, and the analysis.
— Alex
Nine Days in Late July
Friday 24 July. Regulation (EU) 2026/1744 appeared in the Official Journal — "amending Regulations (EU) 2024/1689, (EU) 2018/1139 and (EU) 2023/1230 as regards the simplification of the implementation of harmonised rules on artificial intelligence." It entered into force on 27 July.
The headline change was the calendar. High-risk obligations for stand-alone Annex III systems moved from 2 August 2026 to 2 December 2027. Annex III covers AI used in employment, education, credit assessment, law enforcement and critical infrastructure — which is to say, the systems most compliance programmes were built around. AI embedded in products under Annex I moved to 2 August 2028. Article 6(1) classification moved to the same date. Member State regulatory sandboxes moved to 2 August 2027. Sixteen months of runway arrived on a single Friday in July.
Monday 27 July. Article 4 changed shape with it. Providers and deployers now "shall take measures to support the development of AI literacy" among their staff and among those operating systems on their behalf, having regard to technical skills, experience, education and context of use. Then the clause that alters the character of the duty: the obligation "does not require providers or deployers to guarantee any specific level of AI literacy of any individual."
The two clauses do different work. The first describes conduct. The second forecloses an outcome test. After 27 July, a supervisor auditing Article 4 asks what the organisation did. Before 27 July, the question available to that supervisor was what the organisation's people could do.
Wednesday 29 July. Germany's AI Market Surveillance and Innovation Promotion Act — the KI-MIG — entered into force. It makes the Bundesnetzagentur the country's central market-surveillance authority for AI, and it hands financial-sector AI supervision to BaFin. RegReportingDesk, reporting on the change, puts the new mandate plainly: since 29 July, BaFin holds market-surveillance powers over AI systems "used by entities listed in section 2(3) KI-MIG where the system is directly connected with a regulated financial activity." AI credit scoring. Chatbot disclosure at a bank. For a German-regulated firm, AI supervision now sits inside the existing supervisory relationship — same people, same file, same consequences for the management board.
Friday 31 July. The three European Supervisory Authorities — EBA, EIOPA and ESMA — issued a joint statement on the ICT risks arising from frontier AI models in the EU financial sector. They called for "a cross-sectoral, risk-based and consistent supervisory approach," and said that financial entities "should have robust governance and risk management frameworks in place to support the effective management and mitigation of cyber risks associated with frontier AI models." Frontier AI has been reclassified by the financial supervisors as an operational-resilience and third-party question. That moves it to the risk committee's agenda.
The same day, the Commission published notice that the AI Office and national authorities begin enforcing the AI Act on 2 August, with new rules "requiring certain AI systems to tell users when they are interacting with AI and when content has been generated or altered by it."
Tomorrow, Sunday 2 August. Article 50 transparency obligations apply. AI-generated or manipulated content must be clearly and visibly labelled and carry machine-readable marks, and users must be told when they are dealing with a system. The Article 99 national penalty framework becomes operative. The Article 101 general-purpose AI fines become operative, and the Commission's one-year adjustment period for GPAI providers ends, so the AI Office may supervise and fine them. The exposure, as Cooley put it in its client note: "Noncompliance can trigger fines of up to €15 million or 3% of worldwide annual turnover, whichever is higher." A grace period runs to 2 December 2026 for marking and detection on generative systems already on the market.
Across those nine days, one duty in the Act got lighter. Every duty carrying a fine either held its original date or acquired a new enforcer.
The Number That Moved the Other Way
Cornerstone Research published its midyear securities-litigation report on 29 July, with the Stanford Law School Securities Class Action Clearinghouse. Filings rose thirty per cent, to 121 in the first half of 2026. Fifteen were AI-related, on pace to nearly double the 2025 total. Technology-sector filings rose from nine to twenty-four.
Then the distribution. AI cases were thirteen per cent of core filings and seventy-three per cent of Disclosure Dollar Loss — $385 billion of the $529 billion index total. Five of the seventeen mega-DDL filings in the half were AI-related, accounting for eighty per cent of mega-DDL. There were no cybersecurity filings at all in the period.
Cornerstone's own summary: "AI-related cases represented a modest share of total filings but an outsized share of alleged investor losses in the first half of 2026." Joseph Grundfest, the Stanford professor and former SEC commissioner who co-directs the clearinghouse, added a caution: "That imbalance highlights the extent to which a small number of high-impact matters can influence trends across securities litigation."
The caution is warranted. Fifteen cases is a small sample, and a handful of very large complaints can carry a whole index. What survives the caution is the subject matter. The AI securities claim of 2024 and 2025 was an AI-washing claim: the company said it had AI and did not. The claim now being filed alleges under-disclosure of AI-related business risk. That is a claim about what the board and management knew, and when, and what they told the market about it.
An AI-washing claim is answered by the marketing department. An under-disclosure claim is answered by the audit committee.
An Obligation of Effort, and an Obligation of Result
An obligation of effort is discharged by a record of what you did. An obligation of result is discharged by a state of the world. They are proved with different documents, and the difference matters more this month than it did last.
After 27 July, Article 4 is satisfied by measures. A curriculum, an attendance log, a policy, a set of module completions. Those artefacts are real and worth having, and an organisation holding them has a defensible position on the statute.
The exposures that moved in the other direction ask for something else. Three of them, and Article 4 governs none.
The disclosure exposure. The Cornerstone data. A plaintiff alleging under-disclosure of AI risk asks what the company knew about its own AI dependency and what it said. A training log is evidence that people attended. It carries no information about whether anyone in the company could tell a sound AI-assisted output from a fluent one.
The supervisory exposure. BaFin from 29 July. The ESAs from 31 July. And, three weeks earlier, the ECB. On 7 July, Claudia Buch, chair of the ECB Supervisory Board, wrote to the chief executive of every significant institution under European banking supervision. Her letter — SSM-2026-0301 — describes AI models that identify software vulnerabilities and generate working exploits at speed, compressing the window between discovery and exploitation. It places the duty precisely: "Responsibility for responding to the evolving cyber-risk environment primarily lies with banks' management bodies. Strategic ICT-related decisions, including ICT investments, resource allocation and ICT risk-related risk tolerance frameworks (RTFs) may need to be revisited." Each bank owes its Joint Supervisory Team a comprehensive action plan by 31 October 2026, with roles, responsibilities and timelines. The ECB moved the IT Risk Questionnaire deadline from September 2026 to February 2027 to make room for the work, and will run a horizontal analysis of what comes back. Somebody on each of those boards is drafting that plan in August.
The oversight exposure. This one has no date on it yet, which is the point.
What Marchand decided
Marchand v. Barnhill, 212 A.3d 805 (Del. 2019), is a food-safety case. Blue Bell Creameries made ice cream — one product — and a listeria outbreak killed three people. The Delaware Supreme Court allowed a claim against the directors to proceed. The reason it gave was structural: the board of a single-product company had no committee, no process and no reporting system for the one risk that was "essential and mission critical" to it.
That is what the case decided. Food safety, one product, no monitoring apparatus.
Behind it runs the doctrine, in an unbroken line from In re Caremark International Inc. Derivative Litigation, 698 A.2d 959 (Del. Ch. 1996), through Stone v. Ritter, 911 A.2d 362 (Del. 2006). Oversight liability attaches on two prongs: where directors "utterly failed to implement any reporting or information system or controls," or where, "having implemented such a system or controls," they "consciously failed to monitor or oversee its operations."
Law firms have already carried the doctrine towards AI. Akin Gump, writing in March 2026, argued that the pace of adoption "makes it plausible that even otherwise well governed companies may lack the minimum reporting systems required for boards of directors to satisfy their duty of oversight."
That commentary aims at the machine: model drift, algorithmic red flags, monitoring the system. Shift the object one step and the logic extends itself. If verifying the machine's output is what your institution sells — and for a bank, an insurer, an audit firm, the verification is the product — then the institution's capacity to verify is the substrate underneath any reporting system a board could point to. A reporting apparatus staffed by people who can no longer distinguish a sound report from a fluent one is a system on paper.
Two limits belong immediately beside that argument.
No case yet. No Delaware court has decided a Caremark claim on AI oversight, and none has been brought on the capacity-to-verify ground described above. Delaware is one jurisdiction, its articulation of the duty is among the strictest on record, and most European boards sit under a softer statement of the same obligation. They sit under it nonetheless.
And a record cuts both ways. A documented erosion followed by four quiet quarters of inaction is exactly the conscious failure the second prong describes. The board that keeps a clock running is protected by its record. The board that lets the clock stop is indicted by the same document. The clock is what makes the record protective.
The instrument Europe already wrote
European law already contains the counter-move, in a regulation most boards in scope have read.
The Digital Operational Resilience Act — Regulation (EU) 2022/2554 — has applied across the bloc since January 2025. Its Article 5 puts the management body at the top without ambiguity: it "shall define, approve, oversee and be responsible for the implementation" of the ICT risk framework and shall "bear the ultimate responsibility" for it. Then Article 5(4): members of the management body "shall actively keep up to date with sufficient knowledge and skills" to understand the risk they oversee, "including by following specific training on a regular basis."
A financial regulator, writing rules about machine resilience, finished by scheduling the board's own capability maintenance. Knowledge kept current, by training, on a clock, with a supervisor entitled to ask.
Article 4 of the AI Act moved the opposite way in July. Both instruments now sit in the same body of European law, and a firm inside both is held to the stricter of the two for its own directors.
The gap the effort standard permits
The Conference Board published Skilling for AI: Critical Factors for Navigating AI Disruption on 28 July, from a survey of nearly 1,300 workers globally plus 35 interviews with enterprise leaders. Two figures sit next to each other in it. Fifty-five per cent of workers use generative AI or AI agents daily or weekly. Thirty-three per cent took part in employer-provided AI training in the past six months. Twenty-eight per cent say their organisation provides none at all, and under half — forty-eight per cent — agree they are given sufficient time for skills development.
Matt Rosenbaum, the principal researcher, put the finding this way: "Many organizations have made progress introducing employees to AI, but AI literacy alone will not create business value."
Hold that against the amended Article 4. An organisation that trained a third of its people in six months has taken measures. It is compliant. It also has half its workforce using these tools every week with no verified capacity to judge what comes back, and that half is where the disclosure exposure, the supervisory exposure and the oversight exposure all begin.
The same gap runs through the board itself. The Diligent Institute's Q2 2026 Director Confidence Index surveyed 104 US public-company directors. Eighty-two per cent had used generative AI in their board work in the previous six months, up from sixty-six per cent in September 2025. Fifty-four per cent said their company gave directors no guidance at all on such use. Six per cent reported a formal policy specific to the board. Kira Ciccarelli of the Diligent Institute: "Directors are not waiting for perfect governance frameworks to experiment with AI."
Eighty-two and six. The distance between those two numbers sits inside the room that would have to answer for everything above.
What This Means for Boards Right Now
One. The document Article 4 now asks for and the document a plaintiff will ask for are different documents. Effort is proved by a training log: dates, attendance, curriculum, completion rates. Capability is proved by a record of a named competent person verifying an output, on a schedule, against a standard. Build the second and the first falls out of it as a by-product. Build only the first and the second never appears — and the first is the one nobody sues over.
Two. The fine risk and the loss risk sit at different scales, and both belong at this table. From tomorrow, an EU authority can fine the group up to €15 million or 3% of worldwide turnover, and the trigger can be a missing disclosure line on a customer-facing chatbot. Over the six months to 30 June, fifteen AI-related complaints carried $385 billion of alleged investor losses. The first number is something a compliance officer can plan against. The second is the number an audit committee should read before it signs the next risk-factor disclosure.
Three. Ask the question the deferral has already answered for you. We slowed down when the deadline moved — what did that tell us about why we started? The evidence is in the board pack. Compare the AI competence programme as it stood in the June papers with the version going to the September meeting, and find out who decided the difference and on what grounds. An organisation that banked the sixteen months has its answer: the programme existed to satisfy a date. An organisation that spent them has a different answer, and a record to show for it.
Reading List
-
What the Digital Omnibus did to Article 4, clause by clause, and what a deployer's file has to hold after 27 July: The Digital Omnibus and Article 4: What Actually Changes
-
Why the two regimes ask for different evidence, and what a file looks like when it is built for capability instead of attendance: GDPR vs the AI Act: Compliance Versus Competence
-
The penalty architecture behind the €15 million headline, and the exposures that sit underneath it: The Hidden Penalties of Article 4: Why EUR 15 Million Is Only the Beginning
What We Are Watching Next
- Whether the AI Office uses the fining powers that become operative tomorrow, and against whom. As at today, no AI Act fine has been publicly announced by any authority, and several sites circulating specific figures contradict each other
- Whether BaFin opens the first AI market-surveillance case under its new KI-MIG mandate, and whether the file reaches the management board
- What the ECB's horizontal analysis of the action plans due on 31 October says about management bodies' own capability, as distinct from their banks' controls
- Whether Cornerstone's full-year count confirms the first-half pace, and whether any of the fifteen AI-related complaints survives a motion to dismiss on the under-disclosure ground
- Whether any European deployer publishes what its Article 4 "measures" now consist of, in a form another organisation could measure itself against
The next issue goes deeper into one of these. If you want a specific function or sector covered, reply to this email.
— Liga
TwinLadder Weekly is a weekly intelligence report on judgment, governance, and the boards accountable for both. Subscribe at twinladder.ai/newsletter. Forward this issue freely.
