The Regulatory Pressure on Australian Directors
Four active regulatory pressures create director risk right now:
ASIC REP 798. Published October 2024. 624 AI use cases reviewed. Nearly 50% lacked consumer fairness policies. ASIC's enforcement focus is financial services, but the principles (fair treatment, transparency, accountability) apply across sectors. If AI causes consumer harm in any regulated industry, ASIC's "reasonable care" test applies to directors.
ADM Transparency Deadline. 10 December 2026. Mandatory. No extensions. Every organisation using automated decision-making must disclose it in privacy policies. Directors who allow this deadline to pass without compliance face OAIC enforcement action and the board governance question: "Why wasn't this done?"
OAIC Privacy Sweep. Active since January 2026. 60 entities targeted. Penalties up to $66,000 per non-compliant privacy policy. If your organisation collects personal data (and it does), OAIC is watching.
APRA CPS 230. Live since July 2025. Operational risk management requirements for APRA-regulated entities. AI systems fall under operational risk. Human accountability is required for AI outcomes, not per-transaction review.
The risk of inaction follows a predictable path: an OAIC enforcement notice, then rush compliance at 2x to 3x cost as the deadline closes, then a missed ADM deadline on 10 December 2026, then ASIC investigation and director liability exposure the following year. I've presented this timeline to half a dozen boards. The ones that moved fast avoided every step. The ones still debating are running out of time.
Five AI Risks Every Board Must Track
Risk 1: Algorithmic Bias and Consumer Harm
Your AI system denies credit, insurance, or service to a customer based on variables that correlate with protected characteristics. The customer complains. ASIC investigates. Your board has no bias testing documentation.
Mitigation: Independent bias testing for every AI system that affects customer outcomes. Documented fairness assessment reviewed quarterly. Board-approved fairness policies with clear thresholds.
Risk 2: Unexplainable Decisions
ASIC found "black box" credit scoring at one licensee where nobody could explain what variables influenced outcomes. If your AI makes decisions you can't explain in plain English, that's a regulatory and legal risk.
Mitigation: Explainability requirements for all customer-facing AI. Plain-language decision summaries for each automated process. Regular audit of decision logic.
Risk 3: Data Sovereignty and Privacy Breaches
28% of enterprises downloaded OpenAI's Atlas browser within one week. No IT approval. Whatever employees are signed into, the browser has access to. Consumer AI tools processing personal data on overseas servers creates Privacy Act exposure.
Mitigation: AI tool inventory across the organisation. Enterprise-grade tools with data sovereignty guarantees. Policy prohibiting consumer AI accounts for business data processing.
Risk 4: Governance Gap (No Framework)
Many Australian firms have no AI governance procedures. Without governance, every AI decision is an unmanaged risk. Directors can't claim "we didn't know" when the obligation is to know.
Mitigation: Board-approved AI governance framework covering fairness, transparency, and accountability. Named human accountability for each AI system. Governance review at minimum quarterly.
Risk 5: Compliance Deadline Failure
The ADM transparency deadline is a legislative hard stop. Missing it is a compliance breach, not a governance weakness. The difference matters: governance weakness suggests room for improvement. Compliance breach triggers enforcement.
Mitigation: ADM inventory completed within the first 6 weeks. Privacy policy updates finished at least 3 months before the 10 December 2026 deadline.
The Board AI Risk Register
A board-level AI risk register should track, at minimum:
| Risk Category | AI System | Likelihood | Impact | Mitigation | Owner | Review Date |
|---|---|---|---|---|---|---|
| Algorithmic bias | Credit scoring model | Medium | Critical | Quarterly bias testing | CTO/CAIO | Quarterly |
| Unexplainable decisions | Fraud detection | Low | High | Explainability audit | CTO | Bi-annually |
| Privacy breach | Employee AI tools | High | High | Tool inventory + policy | CISO | Monthly |
| Governance gap | All AI systems | Medium | Critical | Governance framework | Board | Quarterly |
| ADM non-compliance | Automated decisions | Low (if acting now) | Critical | ADM Sprint | Compliance | Dec 2026 |
The register isn't complex. Five columns, reviewed quarterly. What matters is that it exists, it's current, and it's in board minutes. That's your evidence of reasonable care.
You Don't Balance Innovation and Compliance
You sequence them. First 6 to 8 weeks: achieve compliance. Lock in governance, update privacy policies, build the evidence package. Then innovate. Most boards try both simultaneously. They end up slow on innovation and exposed on compliance.
The 18% of organisations that track all three value horizons (efficiency, revenue, transformation) see higher value AND fewer risk incidents (McKinsey). Compliance isn't the enemy of innovation. It's the foundation that makes innovation safe.
Related Resources
- ASIC AI Director Duties: Detailed regulatory obligations
- AI Governance Framework: Full governance framework
- AI for Boards: Board training programme
- AI Risk Register Template: Downloadable risk register
- Privacy Act AI Compliance: ADM transparency requirements
Download the AI Risk Register Template and complete it with your current AI systems. If you can't fill in every row, that's the gap. Book a governance diagnostic to close it.
Related Topics
Explore This Pillar
Go deeper with the matching master pillar and the most relevant supporting topics for this page.