Skip to main content

    Executive guide

    AI Risk for Boards: Director's Guide

    AI risk management for board directors comes down to one question: can your board demonstrate it exercised reasonable care over every AI system in your organisation? Under Section 180 of the Corporations Act, directors who deploy AI without governance frameworks face personal liability when those systems cause harm. ASIC found nearly 50% of financial services licensees lacked fairness policies. The evidence package you build now is the evidence you present to regulators later.

    The Regulatory Pressure on Australian Directors

    Four active regulatory pressures create director risk right now:

    ASIC REP 798. Published October 2024. 624 AI use cases reviewed. Nearly 50% lacked consumer fairness policies. ASIC's enforcement focus is financial services, but the principles (fair treatment, transparency, accountability) apply across sectors. If AI causes consumer harm in any regulated industry, ASIC's "reasonable care" test applies to directors.

    ADM Transparency Deadline. 10 December 2026. Mandatory. No extensions. Every organisation using automated decision-making must disclose it in privacy policies. Directors who allow this deadline to pass without compliance face OAIC enforcement action and the board governance question: "Why wasn't this done?"

    OAIC Privacy Sweep. Active since January 2026. 60 entities targeted. Penalties up to $66,000 per non-compliant privacy policy. If your organisation collects personal data (and it does), OAIC is watching.

    APRA CPS 230. Live since July 2025. Operational risk management requirements for APRA-regulated entities. AI systems fall under operational risk. Human accountability is required for AI outcomes, not per-transaction review.

    The risk of inaction follows a predictable path: an OAIC enforcement notice, then rush compliance at 2x to 3x cost as the deadline closes, then a missed ADM deadline on 10 December 2026, then ASIC investigation and director liability exposure the following year. I've presented this timeline to half a dozen boards. The ones that moved fast avoided every step. The ones still debating are running out of time.

    Five AI Risks Every Board Must Track

    Risk 1: Algorithmic Bias and Consumer Harm

    Your AI system denies credit, insurance, or service to a customer based on variables that correlate with protected characteristics. The customer complains. ASIC investigates. Your board has no bias testing documentation.

    Mitigation: Independent bias testing for every AI system that affects customer outcomes. Documented fairness assessment reviewed quarterly. Board-approved fairness policies with clear thresholds.

    Risk 2: Unexplainable Decisions

    ASIC found "black box" credit scoring at one licensee where nobody could explain what variables influenced outcomes. If your AI makes decisions you can't explain in plain English, that's a regulatory and legal risk.

    Mitigation: Explainability requirements for all customer-facing AI. Plain-language decision summaries for each automated process. Regular audit of decision logic.

    Risk 3: Data Sovereignty and Privacy Breaches

    28% of enterprises downloaded OpenAI's Atlas browser within one week. No IT approval. Whatever employees are signed into, the browser has access to. Consumer AI tools processing personal data on overseas servers creates Privacy Act exposure.

    Mitigation: AI tool inventory across the organisation. Enterprise-grade tools with data sovereignty guarantees. Policy prohibiting consumer AI accounts for business data processing.

    Risk 4: Governance Gap (No Framework)

    Many Australian firms have no AI governance procedures. Without governance, every AI decision is an unmanaged risk. Directors can't claim "we didn't know" when the obligation is to know.

    Mitigation: Board-approved AI governance framework covering fairness, transparency, and accountability. Named human accountability for each AI system. Governance review at minimum quarterly.

    Risk 5: Compliance Deadline Failure

    The ADM transparency deadline is a legislative hard stop. Missing it is a compliance breach, not a governance weakness. The difference matters: governance weakness suggests room for improvement. Compliance breach triggers enforcement.

    Mitigation: ADM inventory completed within the first 6 weeks. Privacy policy updates finished at least 3 months before the 10 December 2026 deadline.

    The Board AI Risk Register

    A board-level AI risk register should track, at minimum:

    Risk CategoryAI SystemLikelihoodImpactMitigationOwnerReview Date
    Algorithmic biasCredit scoring modelMediumCriticalQuarterly bias testingCTO/CAIOQuarterly
    Unexplainable decisionsFraud detectionLowHighExplainability auditCTOBi-annually
    Privacy breachEmployee AI toolsHighHighTool inventory + policyCISOMonthly
    Governance gapAll AI systemsMediumCriticalGovernance frameworkBoardQuarterly
    ADM non-complianceAutomated decisionsLow (if acting now)CriticalADM SprintComplianceDec 2026

    The register isn't complex. Five columns, reviewed quarterly. What matters is that it exists, it's current, and it's in board minutes. That's your evidence of reasonable care.

    You Don't Balance Innovation and Compliance

    You sequence them. First 6 to 8 weeks: achieve compliance. Lock in governance, update privacy policies, build the evidence package. Then innovate. Most boards try both simultaneously. They end up slow on innovation and exposed on compliance.

    The 18% of organisations that track all three value horizons (efficiency, revenue, transformation) see higher value AND fewer risk incidents (McKinsey). Compliance isn't the enemy of innovation. It's the foundation that makes innovation safe.

    Related Resources

    Download the AI Risk Register Template and complete it with your current AI systems. If you can't fill in every row, that's the gap. Book a governance diagnostic to close it.

    Related Topics

    Explore This Pillar

    Go deeper with the matching master pillar and the most relevant supporting topics for this page.