In short
Executive Summary
- ASIC's Chair placed directors 'on notice' for AI governance in March 2026. The Corporations Act s180 duty of care now includes AI oversight.
- Allianz Risk Barometer ranked AI as the number one business risk in Australia for 2026. Boards that ignore this are exposed.
- The Board AI Risk Register maps five categories of AI risk (Autonomy, Misuse-Destruction, Misuse-Power, Economic Displacement, Unknown) to director duties.
- ADM Transparency requirements land 10 December 2026. If your board hasn't started preparing, you're already behind.
Detail
Overview
AI governance isn't optional for Australian boards anymore. It's a legal obligation.
ASIC's Chair made this explicit in March 2026, placing directors on notice that AI oversight falls within their s180 duty of care under the Corporations Act. If your board can't articulate how AI risk is managed across the organisation, you've got a governance gap that regulators will find.
The Board AI Risk Register is the tool I use with every board engagement. It maps Dario Amodei's five categories of AI risk directly to director duties. Autonomy risk: AI systems making decisions without human oversight. Misuse risk (destruction): AI enabling harm at scale. Misuse risk (power concentration): AI consolidating control inappropriately. Economic displacement: the projection that 50% of entry-level white-collar jobs face displacement within one to five years. And unknown risks: the things we haven't identified yet.
Each category gets a likelihood score, an impact score, existing controls, gaps, and an owner. It sits alongside your existing risk register, not in a separate AI silo. Boards should review it quarterly at minimum.
The practical mechanics matter. Governance doesn't mean slowing everything down. It means defining which AI decisions need board visibility and which management handles autonomously. A customer service chatbot doesn't need board approval. An AI system making credit decisions does. The risk register draws those lines.
53.4% of C-suite executives hide their AI use from colleagues. That tells you shadow AI is already inside your organisation. Governance brings it into the light where it can be managed, not banned.
ASIC's s180 duty of care isn't theoretical. It requires directors to exercise reasonable diligence, and that now includes understanding how AI systems make decisions that affect customers, staff, and financial outcomes.
The ADM Transparency deadline on 10 December 2026 requires organisations to disclose when automated decision-making materially affects individuals. If your AI governance framework doesn't address this, start now. Compliance takes months to build properly.
Commercial impact
Why It Matters for Organisations
The regulatory trajectory is one-directional. More disclosure. More accountability. More enforcement.
OAIC has shown it will pursue organisations for AI-related privacy breaches. Consumer law applies to AI-driven decisions. The Privacy Act amendments are tightening data handling requirements. Directors who treat AI governance as a future problem are mispricing the risk.
Allianz ranked AI as Australia's top business risk for 2026. Not cyber. Not climate. AI. That ranking reflects the speed at which AI is being deployed without adequate controls.
From a fiduciary perspective, boards that can demonstrate structured AI governance are in a materially better position if something goes wrong. The Board AI Risk Register provides documented evidence that directors considered AI risks, assessed them against the five categories, assigned ownership, and monitored controls. That's the difference between a defensible position and personal liability.
75% of AI pilots fail to reach production. Many of those failures trace back to governance gaps: no clear accountability, no risk assessment, no compliance review before deployment. Governance doesn't kill innovation. Lack of governance kills successful scaling.
The commercial case is equally strong. BCG data shows AI-mature companies with strong governance frameworks generate 1.7x revenue growth. Governance creates the trust that allows organisations to move faster with bigger bets, because the guardrails exist.
Podcast
Listen to how Australian executives are applying AI
Use the podcast to pressure-test the ideas in this article against real operator conversations. Each episode focuses on what leaders are shipping, where the friction is, and what actually lands.
The trusted source for Australian executives navigating AI strategy, governance, and adoption. I translate technical complexity into practical business outcomes — growth, margins, and time-to-value.
In practice
Examples or Practical Context
An ASX 200 insurer built their Board AI Risk Register in a single board workshop. They identified 11 AI systems in production that the board had no visibility into, including one processing claims decisions without documented human review. Within 90 days, they'd established oversight protocols, retrained the claims team, and created quarterly AI reporting to the risk committee.
A mid-market professional services firm discovered through a governance review that 35% of staff were using generative AI tools with client data and no contractual protections. Three of those tools stored data offshore with no Privacy Act compliant processing agreements. The board mandated an enterprise AI policy within 30 days, deployed approved tools with data loss prevention controls, and established a simple AI register tracking every deployment.
A $400M retailer's board failed to implement AI governance. When their AI-driven pricing algorithm created discriminatory outcomes across regional postcodes, they faced an OAIC investigation with no documented risk assessment, no controls framework, and no clear accountability. The remediation cost exceeded $2M before legal fees.
One ASX-listed financial services board now requires every AI business case to include a risk register entry before funding approval. It adds two days to the process. It's prevented three deployments that would have breached Privacy Act obligations.
What to do
Key Takeaways
- Build a Board AI Risk Register mapping all five categories of AI risk to director duties. Review it quarterly.
- Audit your organisation for shadow AI immediately. 53.4% of executives hide their AI use, which means ungoverned AI is already inside your walls.
- Prepare for the ADM Transparency deadline (10 December 2026) now. Compliance takes months to implement properly.
- Integrate AI governance into existing risk and audit committees. Don't create standalone structures that become siloed.
- Require every AI business case to include a risk assessment before funding approval.
Newsletter
Get the Executive Brief each week
Stay ahead of the next board question with short, practical analysis built for Australian executives. It cuts past recycled AI news and focuses on the decisions that matter now.
The trusted source for Australian executives navigating AI strategy, governance, and adoption. I translate technical complexity into practical business outcomes — growth, margins, and time-to-value.
Assessment
Run the AI Readiness Assessment
Benchmark where your organisation stands and see what needs attention first. Use it to move from interest to an operating plan with clear next steps.
The trusted source for Australian executives navigating AI strategy, governance, and adoption. I translate technical complexity into practical business outcomes — growth, margins, and time-to-value.
Read next
Behind this page
Where this thinking came from
Where this sits
Explore This Pillar
Next step