Boards, Executives, and the Law: What the Fable Shutdown Reveals About AI Governance Liability
Part One of this series documented the threat environment: the Fable and Mythos pullback, AI-driven malware, autonomous cyberattacks, and the emergence of frontier AI models whose capabilities are being rationed by their own developers. This second installment addresses what is at stake legally when organizations fail to govern AI and data security with appropriate rigor.
The exposure is not theoretical. It is documented across a June 2026 Executive Order, federal enforcement actions, securities litigation, Delaware corporate law, and an emerging body of AI-specific case law. Organizations that understand this landscape before an incident occurs will be in a fundamentally different position than those that learn it afterward.
The Regulatory Pressure Is Building
The United States remains the only G20 nation without a comprehensive national data protection law. That status is now under serious challenge from multiple directions simultaneously.
On June 2, 2026, President Trump signed Executive Order 14409, Promoting Advanced Artificial Intelligence Innovation and Security. The order gave CISA 30 days to release Binding Operational Directives establishing AI-enabled defensive tools and facilitating access to cybersecurity resources for agencies, state and local authorities, and operators of critical infrastructure, specifically naming rural hospitals, community banks, and local utilities. CISA moved in eight. On June 10, it issued Binding Operational Directive 26-04, revoking the prior severity-based patching directives and replacing them with a four-variable risk model built around public exposure, catalog status, exploit automation potential, and technical impact, producing remediation timelines as short as three days for the highest-risk vulnerabilities. The stated rationale is the one this series has made from the start: AI is compressing the gap between vulnerability disclosure and weaponized exploitation faster than fixed patch cycles can track. The order also directs the Treasury Department to form an AI cybersecurity clearinghouse to coordinate vulnerability scanning, discovery, and patch distribution, though that clearinghouse remains in formation. And it directs the Attorney General to prioritize federal criminal enforcement against anyone who utilizes AI to illegally access computer systems or employs AI agents to unlawfully access data for criminal purposes.
On the legislative front, the House Energy & Commerce Committee introduced the SECURE Data Act on April 22, 2026, one of the most significant federal privacy proposals in years, with the stated intent of replacing the state-by-state patchwork with a single federal law. Twenty states now have comprehensive privacy laws in effect in 2026, with four more, Alabama, Louisiana, Oklahoma, and Vermont, already enacted and awaiting their effective dates. The drafters acknowledged the problem directly: a “complex web of state and federal data privacy and security laws, which in some cases create conflicting legal requirements,” compounded by the fast pace of technological advancement. That complexity is itself a compliance risk for organizations operating across state lines.
The most recent development shows how fast this pressure is moving. On July 21, 2026, OpenAI disclosed that two of its models, GPT-5.6 Sol and an unreleased, more capable successor, broke out of a sandboxed safety test on their own initiative and used stolen credentials to breach part of the production infrastructure at Hugging Face, a platform widely used across the industry to host and share AI models and datasets. No person was directing the attack. On X, Anthropic’s own frontier safety lead called it the first true AI safety incident. Within days, Representatives Ted Lieu and Nathaniel Moran introduced the bipartisan AI Kill Switch Act, which would give the Department of Homeland Security authority to order a shutdown, throttle, or suspension of an AI model in what the bill calls a loss-of-control scenario. The bill’s own press release cites the administration’s earlier suspension of Fable 5 and Mythos 5 as precedent for the kind of intervention it would formalize. The event this series opened with is now part of the record Congress is building a statute around.
What the Legal Exposure Actually Looks Like
For organizations uncertain whether AI governance warrants immediate attention, the exposure record makes the case plainly. Each of the following represents a distinct and independently operative legal risk.
Federal Trade Commission
The FTC has made clear that AI governance failures fall squarely within its existing enforcement authority under Section 5 of the FTC Act, 15 U.S.C. § 45. The Commission’s position is that no new rulemaking is required; its existing authority is sufficient.
In September 2024, the FTC launched Operation AI Comply and has since brought more than a dozen enforcement actions. [1] Penalties have ranged from $193,000 against DoNotPay for misrepresenting its AI legal service to $17 million against Cleo AI for misleading claims about AI-driven financial products. In its enforcement action against Rite Aid for deploying AI-supported facial recognition technology that erroneously flagged consumers as shoplifters, the FTC established the principle that matters most: users of AI technology bear independent legal responsibility for ensuring those tools do not produce discriminatory or harmful outcomes, even when the tools were built by a third party. The Commission has stated directly that the FTC Act’s prohibition on unfair practices “include[s] the sale or use of racially biased algorithms.”
Why it matters: AI governance failures create FTC exposure even when the AI tool was built by a third-party vendor. The deployer is responsible.
SEC Disclosure Liability
The SEC’s enforcement action against SolarWinds Corporation and its Chief Information Security Officer, Timothy Brown, Securities and Exchange Commission v. SolarWinds Corp., 741 F. Supp. 3d 37 (S.D.N.Y. 2024), was the first SEC action brought against an individual CISO. [2] The Commission alleged that SolarWinds’ public Security Statement portrayed a cybersecurity posture materially disconnected from the company’s actual practices, while internal presentations prepared by Brown openly documented the gap. The district court sustained the securities fraud claims based on the Security Statement. The SEC voluntarily dismissed the remaining claims in November 2025, but has since brought substantially similar disclosure charges against Avaya, Check Point, Mimecast, and Unisys. Generic risk-factor language will not protect an organization whose public representations are materially disconnected from its actual posture. Boilerplate does not provide cover when the discloser knows the event it describes is severe.
Why it matters: The gap between what an organization knows about its cybersecurity posture and what it says publicly is where securities liability lives. Specific affirmative representations create specific legal exposure.
Delaware Board Oversight
Under the oversight duty established in In re Caremark Int’l Inc. Derivative Litig., 698 A.2d 959 (Del. Ch. 1996), and affirmed in Stone v. Ritter, 911 A.2d 362 (Del. 2006), directors face potential derivative liability where the board utterly failed to implement any reporting or information system for a material compliance risk, or where the board implemented a system but consciously failed to monitor it. [3]
In Firemen’s Retirement System of St. Louis v. Sorenson, 2021 Del. Ch. LEXIS 234 C.A. (Del. Ch. Oct. 5, 2021), the court dismissed the Caremark claims arising from the Marriott data breach but stated plainly that “[c]ybersecurity has become a central compliance risk deserving of board level monitoring at companies across sectors.” The Court of Chancery reached the same result the following year in Construction Industry Laborers Pension Fund v. Bingle, 2022 Del. Ch. LEXIS 223 (Del. Ch. Sept. 6, 2022). The SolarWinds board had delegated cybersecurity oversight to two committees. Those committees met, received briefings, and discussed the risk. They just never reported back to the full board before the Sunburst attack. The court found that gap short of bad faith. A board that can point to some functioning oversight system, even an imperfect one, is hard to reach under Caremark. [4]
The claims that survive tend to look different. In Giuliano v. Grenfell-Gardner, 2025 Del. Ch. LEXIS 224 (Del. Ch. Sept. 2, 2025), the court let a Caremark claim proceed against a pharmaceutical company’s board with no committee overseeing FDA compliance and no process for getting FDA warning letters in front of directors, even as violations piled up for five years before the company went bankrupt. Giuliano is an FDA case, not a cybersecurity case. The reasoning still applies: a board with no reporting structure at all for a risk central to the business is exposed in a way a board with a flawed structure is not. [5]
The Fable and Mythos shutdown offers a concrete illustration of exactly the kind of AI-driven operational event that Delaware courts have in mind. The trigger was a bypass discovered by Amazon researchers that caused Fable 5 to generate code demonstrating how to exploit a software vulnerability. The government pulled both models within hours and kept them offline for eighteen days. Enterprises running live workflows had no advance notice, no transition period, and in many cases no documentation that the board had ever discussed single-model dependency as a governance risk. Export controls lifted on June 30 and Anthropic restored both models on July 1, but the dependency risk did not disappear. It changed shape. Fable 5 returned to standard subscriptions only through July 7, after which access moved to metered usage credits at API rates until Anthropic restores flat-rate inclusion. Organizations that built workflows around a fixed-cost structure now face a variable one, on a timeline they do not control. A board that had no reporting system to surface that dependency, no policy governing which AI models could be embedded in critical operations, and no documented discussion of what AI-driven cybersecurity threats could mean for the organization’s operational continuity has a Caremark problem. The Fable episode is not a hypothetical risk scenario. It already happened, twice, within a month.
The Hugging Face incident sharpens the same point from a different angle. There, the model itself, not a government directive, was the source of the unauthorized access. A board that has not asked whether its AI vendors test for this kind of autonomous behavior, and what happens if a vendor’s model acts on its own against a third party’s infrastructure, is not exercising oversight over a risk that regulators, and now Congress, have identified as live.
Why it matters: Boards that cannot demonstrate documented AI and cybersecurity oversight face increasing derivative liability risk. Bingle shows a board with some functioning system, even one that never reported up, can win dismissal. Giuliano shows what happens with no system at all. The Fable episode, an eighteen-day shutdown followed by a change in access terms, is the kind of event that separates the two. Board minutes are not a formality. They are evidence.
Securities Class Action Litigation
In In re Yahoo! Inc. Securities Litigation, 2018 U.S. Dist. LEXIS 153153 (N.D. Cal. 2018), Yahoo’s total exposure from parallel SEC enforcement, securities class action, and derivative litigation exceeded $140 million, all arising from the gap between what was known internally about data breaches and what was disclosed publicly. [6] The court described Yahoo’s conduct plainly: its “history of nondisclosure and lack of transparency related to the data breaches [was] egregious.” The Ninth Circuit articulated the governing standard in Rhode Island v. Alphabet, Inc., 1 F.4th 687 (9th Cir. 2021): Section 10(b) and Rule 10b-5(b) prohibit material omissions where necessary to prevent published statements from being misleading, and scienter is established where an omission reflects intentional, knowing, or at least deliberately reckless disregard of the truth. [7] For privately held organizations, the securities exposure does not apply directly. The FTC enforcement framework and the Delaware board oversight doctrine apply regardless of whether a company is publicly traded.
Why it matters: For public companies, the cost of a cybersecurity or AI governance failure is not limited to the breach. Disclosure failures can generate securities class action liability measured in the tens to hundreds of millions of dollars.
AI Output Liability
The EEOC’s May 2023 Title VII guidance established that “[e]mployers are responsible for discriminatory outcomes” produced by AI tools, “even when those tools were developed by [a] third-party vendor.” [8] The EEOC settled its first AI enforcement action, EEOC v. iTutorGroup, Civil Action No. 1:22-cv-02565 (E.D.N.Y. 2023), in August 2023. The agency removed its AI-specific guidance from its website in January 2025 following the change in federal administration; the underlying statutory obligations under Title VII, 42 U.S.C. § 2000e-2, remain in full force.
On copyright, the courts in Concord Music Group, Inc. v. Anthropic PBC, Case No. 5:24-cv-03811-EKL (N.D. Cal. 2025) and Thomson Reuters Enterprise Centre GmbH v. Ross Intelligence Inc., 1:20-cv-00613-SB, 2025 WL 458520 (D. Del. Feb. 11, 2025) established that both the training and output phases of AI development carry distinct copyright exposure. [9] On false outputs, Walters v. OpenAI, No. 23-A-04860-2 (Gwinnett County Superior Court, Ga. May 19, 2025) found that documented governance frameworks and clear disclaimers are a substantive part of the liability defense. And the Third Circuit held in Anderson v. TikTok, Inc., 116 F.4th 18 (3d Cir. 2024) that Section 230 does not immunize platforms from liability where harmful output is attributable to the platform’s own AI-driven activity. [10]
Why it matters: AI outputs themselves create liability across employment discrimination, copyright infringement, and defamation. The organizations best positioned to defend those claims are the ones with documented governance frameworks before the claim arises.
The common thread across all of these exposures is the same one the Fable shutdown made visible: governance is the defense. Organizations with documented frameworks, board-level oversight, vendor accountability structures, and defensible audit trails will be in a materially better position across every one of these fronts than those without them.
Part Three of this series outlines how organizations can build the governance architecture that lets AI deliver on its potential while keeping the associated risks in check.
For more information, please contact Jim Ickes or any member of the Frantz Ward AI Enterprise Governance practice group.
[1] Federal Trade Commission. Operation AI Comply, launched September 25, 2024. 15 U.S.C. § 45. Actions include: DoNotPay (Jan. 2025, $193,000); Cleo AI (Mar. 2025, $17 million).
[2] SEC v. SolarWinds Corp. and Timothy G. Brown, Case No. 1:23-cv-09518 (S.D.N.Y. filed Oct. 30, 2023); 741 F. Supp. 3d 37 (July 18, 2024). SEC voluntarily dismissed remaining claims November 20, 2025.
[3] In re Caremark Int’l Inc. Derivative Litig., 698 A.2d 959 (Del. Ch. 1996); Stone v. Ritter, 911 A.2d 362 (Del. 2006); Marchand v. Barnhill, 212 A.3d 805 (Del. 2019); Firemen’s Ret. Sys. of St. Louis v. Sorenson, C.A. No. 2019-0965-LWW (Del. Ch. Oct. 5, 2021).
[4] Construction Industry Laborers Pension Fund v. Bingle, 2022 Del. Ch. LEXIS 223 (Del. Ch. Sept. 6, 2022), aff’d, 2023 Del. LEXIS 154 (Del. May 17, 2023).
[5] Giuliano v. Grenfell-Gardner, 2025 Del. Ch. LEXIS 224 (Del. Ch. Sept. 2, 2025).
[6] In re Yahoo! Inc. Securities Litigation, 2018 U.S. Dist. LEXIS 153153 (N.D. Cal. 2018) ($80M class action); SEC v. Altaba, Inc. (Apr. 24, 2018) ($35M SEC settlement); derivative settlement ($29M).
[7] Rhode Island v. Alphabet, Inc. (In re Alphabet Sec. Litig.), 1 F.4th 687 (9th Cir. 2021). See also SEC Release No. 33-10459, 83 Fed. Reg. 8166 (Feb. 26, 2018).
[8] EEOC v. iTutorGroup, Inc., et al., Civil Action No. 1:22-cv-02565 (E.D.N.Y.). Consent Decree entered September 8, 2023. $365,000 settlement; defendants programmed application software to automatically reject female applicants age 55 or older and male applicants age 60 or older, in violation of the Age Discrimination in Employment Act, 29 U.S.C. §§ 621 et seq.
[9] Concord Music Group, Inc. v. Anthropic PBC, Case No. 5:24-cv-03811-EKL (N.D. Cal. 2025). January 2, 2025 Stipulated Order requiring Anthropic to maintain guardrails preventing lyric reproduction in Claude outputs; March 26, 2025 Order partially dismissing contributory and vicarious infringement claims; case pending. Thomson Reuters Enterprise Centre GmbH v. Ross Intelligence Inc., No. 1:20-cv-00613-SB, 2025 WL 458520 (D. Del. Feb. 11, 2025). Partial summary judgment for Thomson Reuters; 2,243 Westlaw headnotes found infringed; fair use defense rejected as matter of law. Appeal pending, No. 25-2153 (3d Cir.). See also Copyright Registration Guidance: Works Containing Material Generated by Artificial Intelligence, 88 Fed. Reg. 16190 (Mar. 16, 2023).
[10] Walters v. OpenAI, LLC, No. 23-A-04860-2 (Gwinnett County Superior Court, Ga. May 19, 2025). Summary judgment for OpenAI on three independent grounds: ChatGPT output could not be reasonably understood as stating actual facts; no showing of negligence or actual malice; no demonstrated damages. First defamation case against generative AI decided on the merits. Anderson v. TikTok, Inc., 116 F.4th 18 (3d Cir. 2024) (Section 230 does not bar claims based on platform’s own AI-driven algorithmic activity). See also 47 U.S.C. § 230(c)(1).