Your AI Just Drafted the Board Minutes. Who Answers If It’s Wrong?
Artificial intelligence is fast becoming the Company Secretary’s most capable assistant. It is also opening new fault lines with the law. Here is where the opportunity ends and the obligation begins.
It is eleven o’clock the night before a board meeting. A Company Secretary has a dense, half-finished set of resolutions to clean up and a deadline that will not move. So the draft goes into a popular AI chatbot with a simple instruction: tidy this up and make it sound formal. Ninety seconds later, the output is elegant, well-structured and ready to circulate. A small miracle.
Except that, in those ninety seconds, a confidential set of board resolutions — possibly carrying price-sensitive information — has quietly left the company’s control and entered a third-party system the company neither owns nor governs. The document is better. The governance is worse. And almost no one in the room would know it happened.
That single scene captures the promise and the peril of AI in the governance function. Used well, it is the most useful colleague a Company Secretary has ever had. Used casually, it can breach confidentiality, data-protection and disclosure obligations before anyone notices. The difference between the two is not the technology. It is judgement — the very thing the profession exists to provide.
The Quiet Revolution in the Boardroom
Strip away the hype and AI is, for a Company Secretary, a force-multiplier on exactly the work that consumes the day. It can monitor a shifting calendar of filing deadlines and statutory obligations, and flag what is due before it is missed. It can produce first drafts of notices, agendas, minutes and reports in minutes rather than hours. It can read through volumes of legislation and amendments to surface the relevant provision far faster than manual research. It can analyse corporate data for patterns, generate board-ready dashboards, and identify pockets of compliance risk before they harden into problems.
None of this replaces the professional. It removes the drudgery that stops the professional from doing the higher-value work — advising the board, strengthening controls, and thinking ahead. AI handles the routine; the Secretary keeps the judgement.
Why Governance Professionals Should Hold the Reins
Corporate governance rests on four plain ideas: transparency, accountability, fairness and responsibility. They sound abstract until something goes wrong, at which point they become the only things that matter. The Company Secretary sits at the centre of that system — principal adviser to the board, the link between management, directors, shareholders and regulators, and the person who ensures that decisions are properly recorded and lawfully executed.
That is precisely why the Secretary, and not the IT team alone, should own how AI enters the governance function. The question is never simply “can this tool do the task?” It is “if this tool is wrong, who is accountable, and can we prove what happened?” A profession built around accountability is the right one to answer it.
Where AI Collides With Regulation
This is the part that rarely makes the brochure. AI does not arrive in a legal vacuum; it lands squarely inside an existing web of Indian regulation. Four collision points deserve particular care.
1. Confidentiality and price-sensitive information. Pasting unpublished board material, deal documents or financial results into a public AI tool can amount to disclosure of unpublished price-sensitive information outside a “need-to-know” basis — a serious concern under the SEBI (Prohibition of Insider Trading) Regulations, 2015. Confidential client and company information is also protected by the Company Secretary’s own professional duty of confidence. The convenience of a free chatbot does not suspend either obligation.
2. Personal data and the DPDP regime. Board papers, KYC files, registers and HR records are full of personal data — of directors, employees and shareholders. The Digital Personal Data Protection Act, 2023, with its Rules notified in November 2025 and obligations phasing in through 2026 to mid-2027, requires lawful, purpose-limited processing, reasonable security safeguards and breach reporting. Feeding such data into an AI platform without knowing where it is stored, who can see it, or whether it trains the model is a data-protection exposure, not a productivity hack.
3. Accuracy, hallucination and personal liability. A Company Secretary is a Key Managerial Personnel under the Companies Act, 2013, and signs certifications and filings in person. AI models can produce confident, fluent and entirely wrong output — a misread provision, an invented citation, a subtly incorrect minute. If that error is filed or certified, responsibility does not transfer to the software. It stays with the professional whose name is on the document. AI-generated work must be verified, not trusted.
4. Accountability and the audit trail. Good governance demands that you can show how a decision or record came to be. The Companies Act already mandates audit-trail (edit-log) functionality for accounting software; the same spirit should govern AI use. If a tool contributes to a statutory record, the organisation should be able to evidence what was generated, who reviewed it and who approved it. An output with no human checkpoint and no trail is the opposite of accountable.
A fifth, quieter risk is reputational: claiming AI-driven rigour that does not exist. “AI washing” — overstating the role or reliability of automation — can itself become a false or misleading statement. In governance, what you assert about your process is part of the process.
The EXI View: Adopt the Tool, Keep the Discipline
At Exactitude International, our position is straightforward. AI is not a threat to the governance professional; it is leverage — but leverage without guardrails is just risk at speed. We believe the gains are real and worth pursuing, provided a few principles are non-negotiable.
Keep a human in the loop on anything that is filed, certified or relied upon. Use enterprise-grade, access-controlled tools rather than public chatbots for confidential matter, and redact or minimise sensitive data before it goes anywhere near a model. Put a written AI-use policy in place — what may be used, for what, by whom, and with what review. Maintain a simple record of prompts, reviews and approvals so the trail exists if it is ever needed. And treat AI adoption itself as a board-level governance matter, not an individual’s private shortcut.
Used this way, AI does not dilute governance. It strengthens it — freeing skilled professionals to spend less time formatting documents and more time protecting the institution. The technology changes the tools. It does not change who is responsible.
That responsibility, in the end, is the whole point. The board can delegate the drafting. It cannot delegate the duty.
Disclaimer
This article is intended for general information and awareness only and does not constitute legal, regulatory, tax or professional advice. It reflects the position as understood at the date of writing; laws, rules and regulatory guidance — including the Companies Act, 2013, the SEBI (Prohibition of Insider Trading) Regulations, 2015, and the Digital Personal Data Protection Act, 2023 and Rules made thereunder — are subject to change and to specific facts. Nothing here creates a professional or advisory relationship. Readers should obtain advice tailored to their circumstances before acting. Exactitude International accepts no liability for any action taken, or not taken, in reliance on this content.


Leave a Comment