What Is ASIC's Position on AI?
ASIC's regulatory approach is technology-neutral. Existing financial services laws apply equally to AI-driven decisions. There are no special AI exemptions, no waiting period, and no reduced obligations because a machine made the call instead of a person.
Report 798, titled "Beware the Gap," was published 29 October 2024. The findings were specific and damning:
- 624 AI use cases reviewed across banking, credit, insurance, and advisory services
- Nearly 50% of licensees lacked policies for consumer fairness or bias
- Even fewer had policies governing AI disclosure to consumers
- One licensee was running "black box" credit scoring where nobody could explain what variables influenced outcomes
When ASIC finds a licensee using AI without governance and that AI causes consumer harm, the question isn't "did the AI make an error?" The question is "did the directors exercise reasonable care in overseeing this system?"
How Section 180 Applies to AI
Section 180 of the Corporations Act requires directors to exercise their powers with the degree of care and diligence a reasonable person would. Applied to AI, this creates four specific obligations:
1. Understand what AI your organisation uses. You don't need to understand how GPT-4 works. You need to know that your credit scoring system uses machine learning, your fraud detection runs automated rules, and your customer service chatbot makes decisions that affect consumers. If you can't list your AI use cases, you can't govern them.
2. Ensure governance frameworks exist. Board-approved policies covering fairness, transparency, and accountability. Not 80-page documents nobody reads. Practical policies that match ASIC's expectations and your operational reality.
3. Maintain human oversight mechanisms. ASIC expects humans to be accountable for AI outcomes. Not reviewing every decision (that's impossible at scale), but accountable for the system design, its operations, and the results it produces.
4. Document everything. If ASIC investigates, your defence is the paper trail. Board minutes showing governance discussions. Risk assessments of AI use cases. Fairness testing reports. Audit trails showing human intervention when things went wrong.
The Liability Exposure
Director liability under AI governance isn't theoretical. Here's the scenario most boards aren't prepared for:
Your AI denies a customer credit. The customer alleges discrimination. ASIC investigates. They find: no bias testing, no fairness policies, no documented governance, no board oversight of the AI system. Under Section 180, directors who failed to establish reasonable governance can face personal liability.
The governance accelerator isn't an investment. It's director liability insurance. I've made this argument to four boards in the past three months. The ones who moved fast are sleeping better. The ones who didn't are still debating.
But here's the complication: governance alone doesn't eliminate risk. It demonstrates reasonable care. The distinction matters. No framework prevents all AI errors. The framework proves you took the steps a reasonable director would take.
Evidence Package: What Demonstrates Reasonable Care
If ASIC investigates your AI use, directors need to show four things:
- Board-approved AI governance framework covering all active AI use cases
- Risk assessment documenting known risks and mitigation strategies for each AI system
- Policies for fairness, transparency, and accountability that are active, not aspirational
- Human oversight mechanisms with clear escalation paths and documented interventions
This evidence package is what separates a defensible board from an exposed one. I've helped six organisations build theirs in the past quarter. Every one of them had AI systems running for over a year with zero governance documentation.
The Compliance Timeline
Here's what the risk of inaction looks like:
Board does nothing: March 2026, OAIC enforcement notice. September 2026, rush compliance at 2x to 3x cost. December 2026, miss ADM deadline. 2027, ASIC investigation plus director liability exposure.
Board acts now: 6 to 12 weeks to full governance framework. 7 months buffer before the ADM deadline. ASIC-defensible documentation in place. Board sleeps at night.
The cost difference between acting now and acting later isn't just financial. Early movers get fixed-price certainty and available capacity for ADM compliance. Late movers pay more because every advisory firm in Australia will be at capacity.
Related Resources
- AI Governance Framework: Complete governance framework for Australian businesses
- Privacy Act AI Compliance: ADM transparency requirements
- AI Risk for Boards: Board-level risk management guide
- AI Compliance Checklist: Step-by-step compliance verification
Frequently asked questions
Your board is either in the compliant 50% or the liable 50%. Find out which before ASIC does. Book a 90-minute governance diagnostic at no cost.
Book Your Governance DiagnosticRelated Topics
Explore This Pillar
Go deeper with the matching master pillar and the most relevant supporting topics for this page.