top of page
Search

AI Governance in Australia: What Every Board Director Needs to Know in 2026

Feb 25
5 min read

Updated: Mar 4

With ASIC warning of a growing "governance gap" and the National AI Plan now in effect, Australian directors can no longer treat artificial intelligence as simply another IT or cyber concern. Here is the essential board-level guide to AI governance in Australia today.


Artificial intelligence has arrived in the Australian boardroom, but for many organisations, the governance frameworks needed to manage it responsibly have not kept pace. In October 2023, ASIC published a report explicitly titled Beware the Gap: Governance Arrangements in the Face of AI Innovation, putting directors on notice that the regulator is watching how organisations manage AI. The regualtor's message was unambiguous: boards that cannot demonstrate oversight of their AI systems face regulatory, legal, and reputational exposure.


This guide provides Australian directors and senior executives with a clear, practical overview of the AI governance landscape in 2026; what is required, what is coming, and how to close the gap before it becomes a liability.


The Importance of AI Governance as a Board-Level Responsibility


You won't find specific duties for directors regarding AI in the Corporations Act 2001, the Act already requires every director to exercise care and diligence. When an AI system is involved in making significant business decisions, handling sensitive customer data, or affecting the provision of financial advice, the issue of whether a director has reasonably overseen that system is clearly covered by existing legal responsibilities.


ASIC's guidance makes clear that financial services providers must ensure AI systems are governed with the same rigour as any other material operational risk. Similarly, APRA's Prudential Standard CPS 234 (Information Security) already captures the data security dimensions of AI, and CPS 230 (Operational Resilience) addresses the reliability of systems, including AI-powered ones, that support critical business functions.

For directors outside financial services, the picture is similar. The Privacy Act 1988, the Australian Consumer Law's prohibition on misleading or deceptive conduct, and workplace discrimination legislation all apply to AI systems ... and boards are ultimately accountable for how their organisations deploy them.


Australia's AI Governance Framework: What Applies Now?


A common point of confusion for Australian directors is the absence of a single, comprehensive AI law. Unlike the European Union, which has enacted an AI Act with tiered risk categories and mandatory controls, Australia currently relies on a combination of existing laws and voluntary frameworks. Understanding which apply to your organisation is the foundation of any AI governance strategy.


The Guidance for AI Adoption (AI6): Released by the National AI Centre in October 2025, this framework replaces the earlier Voluntary AI Safety Standard (VAISS) and consolidates responsible AI practice into six essential practices. While voluntary, the reality is that alignment with AI6 is increasingly expected by regulators and institutional investors as evidence of good governance. Furthermore, in a rapidly evolving space organisations that can demonstrate compliance with AI6 will be better positioned as mandatory obligations inevitably emerge.


The Australian AI Ethics Principles: The Australian Government established eight principles in 2019, covering fairness, accountability, transparency, privacy and security, and human-centred values - the ethical foundation for AI governance in Australia. These align with OECD AI Principles and are referenced by regulators when assessing whether an organisation has acted responsibly.


ISO/IEC 42001: This international standard for AI management systems provides organisations with a structured approach to implementing, operating, and continuously improving AI governance. For organisations seeking a certifiable governance benchmark, particularly those with international clients or partners , ISO 42001 provides both rigour and credibility.


Sector regulators: ASIC, APRA, the OAIC, and the ACCC all have existing powers that extend to AI use in their respective domains. The OAIC, for instance, published detailed guidance in October 2024 on how the Privacy Act applies to AI systems, both for those developing generative AI and those deploying commercially available tools.


The Privacy Act Reforms Every Board Must Prepare For


While Australia does not yet have an AI Act, it does have a critical AI-adjacent reform coming into effect in December 2026. From that date, all entities subject to the Privacy Act that use personal information in automated or semi-automated decision-making — where the decision could have a significant effect on an individual's rights or interests — will be required to disclose this in their privacy policy.


The implications are broader than they may first appear. Any organisation using AI to inform hiring decisions, creditworthiness assessments, personalised pricing, or customer segmentation will likely be captured. Non-compliance carries penalties of up to $62,600 per offence, with potential for far greater liability for serious or repeated breaches.


Boards should be asking management now: which of our current AI systems process personal information in ways that could trigger this obligation? Is our privacy policy fit for purpose? Do we have the audit trails needed to demonstrate how these decisions are made?


What "Good" AI Governance Looks Like in Practice


Based on leading practice from the AICD, OAIC, and ISO 42001, an effective board-level AI governance framework includes the following elements:


  • AI inventory and risk classification

  • Board-level accountability

  • Human oversight mechanisms

  • Transparency and explainability

  • Third-party due diligence

  • Regular review and stress-testing


The Trust Deficit: Why Getting This Right Matters


A 2025 study by the University of Melbourne and KPMG found that only 30% of Australians believe the benefits of AI outweigh the risks, and just 30% believe current laws and safeguards are adequate. For organisations whose value depends on stakeholder trust, financial institutions, healthcare providers, professional services firms, this trust deficit is a material business risk.


Boards that can demonstrate responsible AI governance, through transparent policies, credible oversight mechanisms, and proactive regulatory engagement, are better positioned to build and retain the trust of customers, employees, employees, and investors alike.


A key question for your next board meeting: Has management provided the board with a clear map of all AI systems in use, the risks they pose, and the governance controls in place? If not, this should be on the agenda before year-end.

Conclusion: The Window to Act Is Now


Australia's AI governance landscape is evolving rapidly. The National AI Plan, Privacy Act reforms, evolving ASIC and APRA expectations, and the global pull of the EU AI Act all point in the same direction: boards that establish robust AI governance frameworks now will be better prepared, less exposed, and more trusted than those who wait for mandatory obligations to force their hand.


The directors who navigate this well will be those who understand AI governance as a strategic and fiduciary responsibility, and built the oversight structures to match.


Need support building your AI governance framework? Our team of specialist governance advisors works with Australian boards and executive teams to design, implement, and audit AI governance structures aligned to ASIC expectations, the AI6 framework, and ISO/IEC 42001.  Contact us to arrange a board briefing.

 
 
 

Comments


bottom of page