AI Governance in Australia: Latest Developments
The Head of Digital at a consumer lender approved a new customer-facing AI chatbot. The business case seemed straightforward: faster responses, lower servicing costs and improved customer experience. The chatbot sounded polished and confident.
Then the problems emerged.
Some responses resembled personal financial advice. Others were simply wrong. Customers were told they qualified for products they did not. Features were described that did not exist.
By the time the executive team was alerted, the chatbot had become embedded in customer journeys. What appeared to be a technology upgrade had become a governance issue ...
Key takeaways
Across April, May and July 2026, APRA, ASIC, the Chief Justice of NSW and the Prime Minister each signalled, in different contexts, that AI risk is now a board-level governance issue, not simply an IT or innovation matter.
Existing directors' duties, licensing obligations, prudential standards and privacy law already apply. Regulators expect them to be complied with.
Directors cannot delegate judgement to a machine. The Corporations Act 2001 (Cth) (Corporations Act) safe harbours for delegation (ss 198D, 190) and reasonable reliance (s 189) do not, on their face, extend to AI outputs.
The business judgement rule (s 180(2) of the Corporations Act) is unlikely to protect directors who simply adopt AI-generated recommendations without independent reasoning.
Boards should expect to be tested on AI literacy, vendor oversight, real-world output monitoring and human-in-the-loop controls — especially for customer-facing tools.
The Prime Minister’s July 2026 announcement includes proposed Australian Standards for AI, a new Office of AI within the Department of the Prime Minister and Cabinet and protection of copyright in AI training.
Recent developments in AI governance
The past three months have produced an clear message from regulators, policymakers and the judiciary. Although each has approached AI from a different perspective, the conclusion is consistent: governance frameworks that were previously sufficient may not be sufficient when AI materially influences decisions.
On 30 April 2026, APRA laid down expectations on AI governance, board literacy, operational resilience, assurance, information security and third-party risk for banks, insurers and superannuation trustees.
On 8 May 2026, ASIC issued an open letter on AI-accelerated cyber threats, directing Australian financial services licensees and market participants to table the letter at board and risk committees.
On 21 May 2026, the Chief Justice of NSW, The Hon Andrew Bell AC, delivered the Harold Ford Memorial Lecture, testing how corporate responsibility and directors' duties apply when AI sits alongside, and sometimes within, the boardroom.
On 15 July 2026, the Prime Minister announced a proposed national AI framework, including Australian Standards for AI, a new Office of AI within the Department of the Prime Minister and Cabinet and protection of copyright in AI training.
APRA: governance, literacy and operational resilience
APRA’s 30 April 2026 letter to all APRA-regulated entities followed a targeted engagement with selected large banks, insurers and superannuation trustees in late 2025. APRA observed differing levels of maturity across governance, risk management and operational resilience, and also concluded that assurance practices were not keeping pace with the scale, speed and complexity of AI adoption.
APRA treats AI as a material and developing source of prudential risk, and expects boards and senior management to:
maintain sufficient AI literacy to provide effective challenge;
oversee an AI strategy aligned to risk appetite;
ensure robust monitoring, reporting and accountability; and
actively manage third-party and concentration risks.
Operationally, APRA expects entities to consider how AI affects information security, third-party and concentration risk, operational resilience, change management, assurance, human involvement in high-risk decisions and monitoring across the AI lifecycle.
These expectations all sit within APRA’s existing prudential framework, including CPS 220 (Risk Management), CPS 230 (Operational Risk Management) (CPS 230), CPS 234 (Information Security) and, where relevant, CPG 235 (Managing Data Risk).
ASIC: AI as a conduct and cyber risk issue
ASIC’s 8 May 2026 open letter frames frontier AI primarily through cyber resilience and core licensing obligations. The letter states that frontier AI models are accelerating both the capability and accessibility of cyber activity, increasing the speed and scale of attacks and putting existing controls under greater pressure. ASIC’s message is broader than any single model or tool: licensees and market participants should not wait for perfect clarity before strengthening cyber resilience fundamentals.
For customer-facing AI, the conduct risks are obvious. Inaccurate, biased or overconfident outputs at scale can translate into misleading or deceptive conduct, breaches of the obligation to act efficiently, honestly and fairly, exposure to scam and fraud risks, and failures in supervision and monitoring. ASIC's recent enforcement activity in cyber-related matters shows how readily technical failures can be reframed as licensing breaches.
ASIC encourages licensees and market participants to:
strengthen cyber fundamentals and incident preparedness;
identify and protect critical systems and data;
actively manage third-party and vendor risks; and
ensure governance frameworks keep pace with evolving threats.
ASIC’s directed that its letter be tabled and discussed at the next board and risk governance committee meeting. This clearly frames AI as a board-level licensing and governance issue.
While APRA and ASIC focus on governance and regulatory compliance, the judiciary is beginning to explore a related question: what happens when directors themselves rely on AI in corporate decision-making?
Chief Justice Bell on AI and directors' duties
Bell CJ's lecture discussed how existing corporate law doctrines respond when judgement is exercised alongside, and sometimes through, machines. His central point was that directors’ duties remain technology-neutral, but their practical application may become more demanding as AI is adopted in corporate decision-making.
The law has not changed
Australian corporate law has not been rewritten for the AI era. Directors remain subject to the familiar duties under the Corporations Act. Those are the duties of care and diligence (s 180) and good faith (s 181), and the requirement to exercise independent judgement. These duties are expressed broad, technology-neutral terms. It is that generality that allows the law to absorb new risks without legislative amendment.
Independence and the risk of deference
Bell CJ drew a careful distinction between governance of AI (how companies regulate AI in their operations) and governance with AI (how directors themselves use it). The latter raises more acute questions of duty.
AI systems produce outputs with confidence, fluency and apparent authority. That creates a structural risk of deference, sometimes described as cognitive surrender: the substitution of machine-generated certainty for human judgement. Responsibility does not migrate to the machine. It stays with the human director.
Delegation and reliance
Bell CJ's analysis was particularly pointed on delegation and reliance. These are the areas where directors often look for statutory protection when they depend on information or advice provided by others.
In relation to delegation under ss 198D and 190 of the Corporations Act, directors may delegate powers to people, not machines. AI cannot be a director, delegate or shadow director under Australian law. Where tasks are delegated to management or advisers who themselves rely on AI, directors remain responsible unless they can satisfy the strict conditions of reasonable belief in the delegate's competence and reliability. Bell CJ queried what "competence" means when the advice is substantially machine-generated.
In regard to reasonable reliance under s 189 of the Corporations Act, the statutory safe harbour protects reliance on information or advice given by persons. On its face, it does not extend to reliance on AI outputs. Directors may need to show that the human adviser was competent not only in the subject matter, but in the responsible use of AI. Bell CJ highlighted the difficulty of making an "independent assessment" where the underlying data and reasoning of AI systems are opaque.
The practical effect is that directors should not assume existing reliance provisions will operate smoothly where AI plays a material role.
The business judgement rule
Bell CJ expressed scepticism about the availability of the business judgement rule (s 180(2) of the Corporations Act) where directors simply adopt AI-generated recommendations. The rule requires directors to inform themselves and reach a rational belief through their own reasoning process. A judgement effectively outsourced to an algorithm may struggle to meet that threshold.
Consider a board assessing an acquisition where management presents financial forecasts generated substantially by AI. Even if directors receive those forecasts through management, the statutory duties remain theirs. The question is not whether AI prepared the analysis, but rather whether directors exercised independent judgement in relying on it.
Board process, records and the chilling effect
Bell CJ also addressed the growing use of AI in board administration: recording meetings, transcribing discussions, drafting minutes. The efficiency gains are obvious, but so are the risks: discoverability, loss of privilege, data security and, most importantly, a chilling effect on frank discussion. Healthy boards depend on challenge and contest. Bell CJ placed responsibility on chairs and company secretaries to ensure technology does not erode the dynamics that underpin effective governance.
The Prime Minister’s July announcement: a national AI framework
The Prime Minister’s speech and related announcement add a new dimension to the regulator and judicial focus. The Federal Government has proposed Australian Standards for AI, with the stated objective of creating a simple and consistent regulatory framework for AI training and ensuring that AI development aligns with Australia’s national interests and values.
This points to a more centralised national policy architecture for AI. The new Office of AI, established within the Department of the Prime Minister and Cabinet, is intended to accelerate implementation of the Australian Standards and coordinate policy across government.
At this stage, the proposed standards appear to be directed principally at large-scale AI infrastructure and training, including energy, water, grid connection and copyright controls, rather than a complete AI-specific conduct regime for all business users.
AI governance is likely to become less fragmented over time, with clearer expectations about how organisations develop, procure, train, deploy and assure AI systems.
The copyright aspect matters because it brings training data, permissions and content provenance into AI governance. Financial services and media businesses should expect closer scrutiny of whether AI tools have been trained, procured and used in ways that respect creator control. Organisations should therefore treat copyright terms, supplier representations, model training records and procurement due diligence as core governance controls, not peripheral legal issues.
The common thread: existing obligations, emerging AI governance standards
A consistent theme is that directors’ duties, privacy obligations, governance standards and licensing conditions already apply.
Where AI replaces or materially influences human decision-making, regulators, courts and policymakers will ask familiar questions:
Are risk management systems adequate for the activity being conducted?
Is there sufficient human oversight and accountability?
Are third-party arrangements effectively governed, monitored and tested?
Can the entity explain, challenge and control the outputs it relies on?
Can the organisation show that the data and content used to build, train or adapt AI systems has been appropriately authorised, controlled and governed?
The Federal Government’s proposed Australian Standards for AI indicate that organisations should also prepare for more explicit national rules governing AI training, assurance, safety and creator protections.
What to do?
For organisations deploying AI, steps to consider include:
Inventory AI use cases: Know where AI is used, what it does, who relies on it, and what decisions it influences. You cannot govern what you have not mapped.
Strengthen board-level governance: Clarify ownership, escalation paths and board reporting. Table ASIC's open letter at the board and risk committee. Build AI literacy at director level so that challenge can be effective.
Test outputs, not just inputs: Monitor real-world behaviour, drift and error. Vendor assurances about training data are not a substitute for ongoing output testing.
Challenge vendors and third parties: Treat material AI deployments as outsourcing arrangements. Apply CPS 230 (where applicable) and equivalent third-party risk controls. Do not rely solely on marketing materials.
Prepare for the Australian Standards for AI: Monitor the development of the standards and expected legislation, and assess whether existing AI governance frameworks, procurement processes and assurance mechanisms are capable of meeting a more centralised national framework.
Keep humans in the loop on high-impact decisions: Document where independent judgement was applied, what AI input was considered, and why directors and senior managers reached their own conclusions. That record will matter if a duty of care question ever arises.
Contact us if you would like to discuss how these developments affect your organisation’s AI deployment, governance frameworks, procurement arrangements, or board reporting.