← Blog & Resources
Corporate governance · Chile2026-08-08·8 min

Can a Board Be Liable for Not Adopting Compliance AI?

Juan Ignacio Weber

Juan Ignacio Weber

Co-Founder, vario

Legal notice: This content is educational information about compliance regulation and does not constitute legal advice. Specific requirements vary by jurisdiction, sector and company history. Consult your certified legal advisor before implementing changes.

The duty of care is no longer a fixed standard

For decades, the fiduciary duty of directors and officers was understood in relatively static terms: act in good faith, with the diligence of a reasonably prudent person, in the best interest of the company. Chile's own Corporations Law (Ley 18.046, Article 41) codifies this as the "care and diligence that men ordinarily employ in their own business."

But the diligence standard has never been a fixed snapshot. It's a mirror of what a reasonable administrator would do under current circumstances — and current circumstances now include two elements that didn't exist a decade ago:

  1. A dramatically expanded corporate criminal framework: Chile's Economic Crimes Law (Ley 21.595), in force for individuals since August 2023, with its amendments to the corporate criminal liability regime (Ley 20.393) applying since September 1, 2024.
  2. Preventive detection technology — NLP- and AI-based communications monitoring — that is commercially accessible, validated by academic literature, and already used by regulators themselves.

When the available tools change, what it means to be diligent changes with them. That's the thesis of this article — and it matters well beyond Chile's borders.

Why a Chilean statute should matter to a foreign parent company

If your group's headquarters sit in New York, Madrid or São Paulo and Chile is "just a subsidiary," it's tempting to treat this as local counsel's problem. It isn't. Ley 21.595 extends personal criminal exposure to directors and senior executives of the Chilean entity — and parent-company board members who sit on, appoint, or supervise that subsidiary's governance can be pulled into the same conversation, whether through formal liability, reputational contagion, or the disclosure obligations that follow a Chilean indictment back to group headquarters. Chile is also one of the most active antitrust and anti-corruption enforcers in the region, with a competition authority (the FNE) that actively pursues leniency-driven cartel cases. For any multinational with LATAM operations, Chile is frequently the jurisdiction where enforcement risk crystallizes first — which makes it a useful test case for how "reasonable diligence" is being redefined across the region.

From paper compliance to effective oversight

Ley 20.393 conditions a company's exemption from corporate criminal liability on the effective adoption and implementation of a crime prevention model. Ley 21.595 raised the stakes further: it expanded the catalogue of predicate offenses, toughened penalties, and — critically — reinforced the personal exposure of executives and directors.

The operative word is effective. A policy manual in a drawer, an annual training session and a whistleblower hotline nobody uses do not constitute effective oversight. Courts and legal doctrine converge on a simple idea: the prevention model must be proportional to the company's actual risk profile, and it must work.

This raises an uncomfortable question: if technology exists that can detect early signals of collusion, fraud or corruption in corporate communications — where these offenses are typically born and coordinated — and the board decides not to even evaluate it, can it still credibly claim its oversight is "effective"?

The conceptual precedent: Caremark and the duty to monitor

In Delaware corporate law, the line of cases beginning with In re Caremark (1996) and refined in Marchand v. Barnhill (2019) established that directors breach their duty of loyalty when they:

  • Fail to implement any reasonable system of information and reporting on the company's central compliance risks, or
  • Having implemented one, consciously ignore the red flags that system produces.

Marchand is particularly instructive: the Delaware Supreme Court allowed a claim against the board of a food company to proceed precisely because the board had no monitoring system specific to its critical risk (food safety), even though general compliance infrastructure existed. And in In re McDonald's (2023), the Court of Chancery went further, extending these oversight duties to senior officers, not just directors. The lesson transfers cleanly to the Chilean context: a company whose critical risk is antitrust, fraud or corruption needs monitoring systems designed for that risk, not generic controls bolted on for appearances.

Chile has no formal Caremark doctrine, but the same logic is already embedded in its legal framework through a different route: the requirement of an adequate and effective crime prevention model as a condition for the criminal liability exemption, combined with the general duty of care under Article 41 of Ley 18.046. The practical outcome is analogous: a board that fails to monitor its critical risks using reasonably available means is exposed — under Delaware doctrine, under Chilean statute, or under both if the corporate structure spans both.

Diligence is a moving target: the T.J. Hooper rule

There's a classic common-law principle, articulated by Judge Learned Hand in The T.J. Hooper (1932), that captures the point better than any modern treatise: an entire industry can lag in adopting available precautions, and that collective lag does not excuse liability. "Nobody else does it either" is not a defense when the precaution is accessible and its omission causes the harm.

Applied to this context:

  • Academic evidence (the OECD's work on screening tools in competition investigations, and computational cartel-detection research including natural language analysis of communications) validates that these techniques identify patterns associated with collusive and fraudulent conduct, and that they cover the full universe of communications, which manual or sample-based review cannot.
  • Competition authorities already use these tools to find cartels: Chile's FNE created an Intelligence Unit within its Anti-Cartel Division and, together with ChileCompra, built a tool that monitors the full universe of public procurement tenders, while Brazil's CADE has run its Projeto Cérebro for years to the same end.
  • The cost of adopting this technology is a fraction of the cost of an investigation, a fine, or a conviction under Ley 21.595.

When the regulator uses AI to detect you, and you decide not to use AI to prevent the underlying conduct, the imbalance stops being merely strategic — it starts becoming legally relevant to how your diligence gets evaluated after the fact.

The asymmetry no board should accept

Leniency programs — both Chile's delación compensada in antitrust matters and effective-cooperation frameworks in criminal proceedings — sharpen the problem. These mechanisms reward whoever gets there first: the company that detects misconduct internally and self-reports can obtain full immunity or substantial fine reductions; everyone else pays the full price.

This turns early-detection capability into a strategic asset with direct legal value, comparable to how conflict-of-interest programs function as both a prevention tool and a source of self-reporting evidence. A board that lacks that capability doesn't just assume sanction risk — it forfeits, by omission, the single most powerful mitigation tool the law offers. It's hard to imagine a harder decision to defend to shareholders after a conviction, particularly when the underlying conduct (say, bribery) was preventable with tools the board never evaluated.

What this means in practice for a board with Chilean exposure

This doesn't mean every board must sign a contract for AI-based monitoring tomorrow. It means the decision-making process must exist and be documented. Concretely:

1. Formally evaluate the available technology. The duty of care requires being informed. A diligent board must know what preventive detection tools exist for its critical risks, and should document that evaluation in board minutes.

2. Map the communications risk. Collusion, fraud and corruption don't happen in financial statements — they happen in emails, chats and messages. If the crime prevention model's risk map doesn't treat communications as a vector, it's incomplete.

3. Decide with a documented rationale. Adopting or not adopting monitoring technology is a protected business judgment — provided it's an informed one. What's indefensible isn't saying "not yet"; it's never having asked the question.

4. If you adopt it, do it right. Communications monitoring must be implemented with privacy by design, proportionality, and full compliance with Chile's data protection law (Ley 21.719), which takes full effect on December 1, 2026. Invasive or disproportionate monitoring creates the very risk it was meant to mitigate.

5. Review periodically. The diligence standard will keep moving. What counts as "emerging good practice" today will be the minimum expected baseline tomorrow.

Conclusion: omission is also a decision

Modern fiduciary responsibility isn't limited to avoiding bad decisions. It extends to accounting for the decisions that were never made: the systems that were never evaluated, the alerts that never existed because nobody built the mechanism to generate them.

Ley 21.595 raised the consequences. The technology reduced the excuses. At that intersection, the question for any board with Chilean exposure — whether the Chilean entity is the parent or a subsidiary of a multinational group — is no longer "can we afford to adopt preventive AI-based monitoring?" It's "can we defend, in front of a prosecutor, a court, or our own shareholders, the decision never to have considered it?"

vario builds NLP-based communications monitoring technology designed specifically for the risks embedded in Chile's legal framework — antitrust, fraud and corruption — with data protection built in by design.


If you lead a board, a legal team or a compliance function and want to know what effective oversight looks like in 2026, let's talk. Talk to us.

Does your company carry this risk?

vario keeps you ahead of signs of collusion and corruption in your corporate communications.

Request a demo