Key takeaways
- Governance is lagging. Without adequate governance of AI use, boards and directors are at heightened risk of regulatory scrutiny and personal liability. ASIC and APRA have both signalled they will act where entities and individuals fall short.
- The duties are the same; the context is new. Directors’ duties have not changed, but AI introduces novel vectors for decision-making and gives courts and regulators fresh lines of inquiry into how duties are being discharged.
- AI can inform judgment; it cannot replace it. Directors cannot delegate their responsibilities to a machine. Given the inherent risks that AI presents, directors must treat it differently from other technology systems.
- Doing nothing is itself a risk. Boards that avoid AI governance risk regulatory and other action. Boards that avoid AI altogether invite scrutiny and competitive disadvantage.
- AI leaves a trail. Every prompt, output and chat log may become discoverable. Boards should manage AI-related records proactively.
- Board composition matters. Technology experience remains underrepresented in many boardrooms. Directors need the technological literacy to challenge management on AI.
- Governance must be proportionate, not perfect. APRA’s standard is governance proportionate to the entity’s size, scale and complexity. Smaller organisations need not replicate the frameworks of a major bank but they must demonstrate considered, risk-based engagement with AI.
The Hon Andrew Bell AC, Chief Justice of NSWIt is not difficult to imagine a wave of litigation occurring down the track from the use by corporations and directors and officers of AI”
Introduction
Artificial intelligence (AI) has moved from the margins to the centre of corporate life. Boards now use AI to summarise board packs, in-house teams use generative tools to draft and review, and operational systems increasingly rely on AI to make or support decisions that affect customers. The technology promises real gains in speed, insight and cost savings. It also raises questions that the law did not have in mind when it was framed.
This matters now for three reasons. First, adoption is accelerating. Second, governance is lagging and regulators are watching closely. Third, the courts have issued warnings, with cases undoubtedly to follow.
The regulatory environment is also set to shift. On 15 July 2026, Prime Minister Anthony Albanese delivered a speech titled AI in Australia’s interest, announcing the immediate establishment of a new Office of AI, which will coordinate the government’s AI policy and regulatory work, including the design of new national standards (see our update: Australian Government announces mandatory AI standards for large-scale data centres and new Office of AI). While the full legislative detail remains to be seen, this is expected to at least address “large-scale” data centres. For boards, this underscores the importance of building governance frameworks that can adapt as the regulatory ground moves beneath them.
Overarching governance issues
There are two distinct governance issues for directors arising from AI use:
- The first is enterprise AI risk: how the business deploys and monitors AI in products, operations and customer-facing decisions.
- The second is board and executive use of AI as a tool: how directors and officers use AI to digest materials, test assumptions and strategy, and prepare for meetings.
The legal analysis differs for each. However, both require directors to grapple with AI.
Global statistics suggest that AI is increasingly becoming a boardroom agenda item, but two-thirds of directors still lack meaningful AI fluency, and a third say their boards are not spending enough time on the issue.
Source: Deloitte 2025 Global Boardroom Program
AI and enterprise risk
Regulators are watching and have warned they will act
APRA, April 2026Where entities fail to adequately identify, manage or control AI risks in a manner proportionate to their size, scale and complexity, [APRA] will take stronger supervisory action and, where appropriate, pursue enforcement.”
We have separately examined the regulatory landscape in our article AI governance: existing obligations, regulatory expectations and increased scrutiny.
In short, the Australian Prudential Regulation Authority (APRA) bluntly warned in its recent letter to industry that “AI adoption is moving fast, but governance maturity is lagging”. Many boards are still building the technological literacy they need to challenge management and set strategy. Too often, boards take vendor sales pitches at face value without testing the key risks for themselves. However, it appears that the grace period is over and APRA has warned it will act.
The Australian Securities and Investments Commission (ASIC) has been equally direct. Since at least 2024, ASIC has warned that the legal duties applying to directors are technology neutral. They apply to the adoption, deployment and use of AI just as they apply to any other business decision. Directors are expected to know how AI is being used within their organisations, how much they are relying on AI-generated information to discharge their duties and what risks that reliance brings.
The implication is clear: directors cannot plead ignorance of AI risks simply because AI-specific legislation has not yet arrived.
We will consider the Office of the Australian Information Commissioner’s (OAIC) position in more detail in our upcoming privacy and confidentiality article.
AI and directors’ duties
The fundamentals of directors’ duties in the AI context
Unless and until the Government introduces new AI-specific legislation, existing obligations prevail, including those under the Corporations Act 2001 (Cth) (Corporations Act), the key obligations of which are that directors (and officers) must:
- exercise care and diligence to the standard of a reasonable person in the corporation’s circumstances and in the same office: s 180(1)
- act in good faith in the best interests of the corporation and for a proper purpose: s 181
- not improperly use their position or information: ss 182 and 183.
Importantly, these duties apply equally to officers, which can include General Counsel and other senior executives who exercise governance functions.
Breaches can lead to pecuniary penalties, disqualification and compensation orders. Reckless or dishonest breaches of these duties can attract criminal liability under s 184. These statutory duties also sit alongside directors’ fiduciary and equitable duties.
As AI literacy becomes normalised across Australian boardrooms, the standard of the “reasonable person” in that person’s circumstances under s 180(1) will likely evolve. If regulators expect every director to engage with AI (as ASIC’s former Chair urged), a baseline technological literacy may become an implicit element of the duty of care. Directors who remain ignorant of AI’s risks and opportunities may find it increasingly difficult to demonstrate that they have met the standard expected of a person in their position. This expectation is already starting to play out for lawyers in the UK, who have been warned that they could be found to have acted negligently by failing to use AI in circumstances where a competent member of their profession exercising "reasonable care and skill" would have done so.
Boards must also confront the risks of not using AI. Failure to use AI where competitors and peers are doing so can itself be a governance failure, exposing the organisation to strategic risk and competitive disadvantage. Management should assess the risks associated with not implementing AI alongside the risks of deploying it.
Statutory protections?
Directors may have statutory protections when one of their decisions is challenged. However, as the Hon Andrew Bell AC, Chief Justice of NSW, outlined in the 2026 Harold Ford Memorial Lecture, the usual protective provisions in the Corporations Act do not fit neatly with AI:
- Delegation. Directors can delegate powers to others and avoid liability where they believe the delegate to be reliable and competent (ss 198D and 190). But AI is not a "person" under the Act, so delegation to AI is not possible. Directors can still use AI, but the buck stops with them.
- Reliance on expert advice. Under s 189, directors may rely on information or advice from experts. AI output is not itself an expert. It may inform the work of an expert, but directors need to understand who is responsible for the advice, what assumptions and data were used, what limitations apply and whether the reliance is reasonable in the circumstances.
- The business judgment rule. The most familiar protection, s 180(2), treats a director as having met the duty of care if they make a business judgment in good faith, for a proper purpose, without a material personal interest, inform themselves appropriately, and rationally believe the judgment is in the company’s best interests. But the rule demands something AI cannot supply on a director's behalf: a reasoning process personal to the decision-maker. The opacity of the “black box” makes it near impossible to evidence the conscious evaluative act required. AI should be used to aid judgment, not replace it. A director who uses AI as one input among several and can demonstrate their own independent assessment may still satisfy the rule. But a director who uncritically adopts an AI recommendation without more will not find safe harbour.
In Inspired Medical Pty Ltd v S Mohindra Pty Ltd [2026] QSC 78, the Supreme Court of Queensland recently rejected an attempt to tender ChatGPT output as evidence of the ordinary meaning of “medical centre” in a lease dispute. In particular, the Court noted that the “accuracy of any answer provided by a [GenAI chatbot] is unknown” and, without verifying the source of information, may be unreliable. Ultimately, the questions posed were issues for the Court – not a chatbot - to determine. This reasoning reinforces the view that AI is unlikely to be an “expert”, a delegable entity or, more simply, a reliable source for directors to rely on, without more.
How FAR?
The Financial Accountability Regime (FAR) sharpens the personal exposure for accountable persons at banks, insurers and superannuation trustees. Entities should consider appropriate responsibilities for AI and the obligations of accountable persons, including to take ‘reasonable steps’ to prevent matters that could harm the entity’s prudential standing or reputation. 'Reasonable steps' include to:
- have appropriate governance, control and risk management
- safeguard against inappropriate delegations
- have procedures for identifying and remediating problems
- respond to non-compliance.
Key risk areas for directors
Technology may assist comprehension, but it cannot displace judgment.”
Australian case law is in its early stages, but the courts have begun to weigh in. ASIC v Bekier (Liability Judgment) [2026] FCA 196 is the first Australian judgment to address AI use by directors.
In a notable forward-looking passage, Justice Lee acknowledged the potentially “profound impact of artificial intelligence” in assisting directors in navigating material provided by management. However, his Honour cautioned that:
- any use of AI should be “controlled and transparent” and governed by formally adopted policies
- “the use of technology may assist comprehension, but it cannot displace judgment”. The statutory obligation under section 180(1) “remains personal, and it requires informed human judgment”.
Strategic adviser or non-privileged evidentiary trail?
A recent US decision from the Delaware Court of Chancery, Fortis Advisors, LLC v Krafton, Inc, is a cautionary tale for directors seeking to stress test strategy with a bot rather than their lawyer. A buyer’s CEO wanted to self-engineer a way out of a US$250 million earnout obligation (whereby additional consideration is paid once predetermined benchmarks are met). Rather than seek legal advice, he asked ChatGPT and adopted its suggestions. The CEO’s chat logs were used against him at trial, without privilege protections, evidencing the pretextual nature of his conduct. The CEO’s attempt to delete the logs only damaged his credibility further.
In Australia, a similarly powerful illustration comes from In the matter of Lanmar Pty Ltd (No 2) [2026] NSWSC 800. Two majority director-shareholders sought to force out the third equal minority director-shareholder. Rather than first consulting lawyers, they turned to ChatGPT to develop their strategy, which erroneously treated the dispute as an "HR problem" and applied an employment-law framework. Black J relevantly stated that ChatGPT "did not prove to be a prudent choice of adviser so far as matters of Australian corporate law were concerned". The Court found that the majority had engaged in oppressive conduct. While the specific claim for breach of directors' duties was not established, the Court observed that the ChatGPT-derived strategy had "expressly contemplated steps which would potentially have contravened" directors' duties.
The practical lessons are clear: AI records may become adverse evidence, deletion or poor retention practices may damage credibility and executives who act on AI output without proper legal oversight risk both personal and corporate exposure with unintended consequences.
Key risks for directors related to AI use
The principal risks for directors related to AI use are:
- Over-reliance and the loss of independent judgment. As Bell CJ recently observed, AI produces output with “great confidence and clarity of language, features which it has in common with the most accomplished of fraudsters.” The risk is that fluency breeds unwarranted trust. A director who treats an AI recommendation as the answer, rather than one input to consider, exposes both themselves and the company to risk. Further, deference to a confident AI output can dampen debate and promote groupthink, threatening the productive conflict on which good boards depend.
- Boardroom records, privilege and discovery. AI recording and transcription tools raise numerous practical and legal risks. AI use in this regard may generate what Bell CJ called a “new avalanche” of material that becomes discoverable in litigation. Conversely, a fully recorded, searchable boardroom risks stifling the frank debate that good governance requires.
- AI washing. Directors may face personal exposure if the company overstates its AI capabilities, known as “AI washing” - an emerging frontier. We will examine this risk in detail in a forthcoming article.
- Cyber and data breach liability. AI systems processing large volumes of personal or sensitive data are high-value targets for attackers. ASIC’s May 2026 open letter urged entities to strengthen cyber resilience as AI accelerates threats. For directors, this means ensuring the company's cyber defences keep pace with AI development and deployment and that governance frameworks address AI-specific vulnerabilities and threats.
- Third-party AI provider risk. ASIC Report 798 specifically flagged risks associated with third-party AI platforms. Directors should ensure appropriate contractual protections are in place with AI vendors. Reliance on a third-party tool does not relieve the board of its governance obligations.
- Accessorial and ‘stepping stone’ liability. Where a director’s failure to exercise care and diligence contributes to the company contravening the law, ASIC can pursue the director personally under s 180(1). This “stepping stone” approach, endorsed by the courts, means that a director’s failure to prevent or address AI-related misconduct by the company (such as misleading conduct or privacy breaches) can itself ground personal liability.
- Consumer harm. ASIC found that nearly half of the licensees it reviewed had no policies addressing consumer fairness or bias, and even fewer governed disclosure of AI use to consumers. Without controls, the risks include misinformation, unintended discrimination and data and privacy failures.
Practical tips for boards and directors
Board level
- Have the conversation. Set an AI risk appetite and decide where the company and the board will and will not use AI.
- Build board-level AI literacy. Directors must be able to challenge management. Consider whether technology expertise is adequately represented. Consider a multi-layered approach; capability at the board table itself, supported by structured expertise below.
- Formalise AI policies. Tolerating ‘shadow’ use is a risk. Give staff and the board sanctioned, secure tools so they do not resort to public platforms and establish clear protocols and policies.
- Protect personal information, confidentiality and privilege: Use closed or enterprise AI systems for sensitive matters; avoid uploading personal information, confidential or privileged material to public GenAI tools. Before deploying AI recording or transcription tools, particularly in board meetings, establish clear policies on retention, deletion, confidentiality and privilege to manage discovery risk.
- Strengthen cyber defences. Ensure your company's security posture keeps pace with the evolving threat landscape.
- Govern AI-related public statements. Do not overstate what your AI can do or how far results depend on it.
Individual director level
- Keep judgment at the centre. Technology assists comprehension; it cannot displace the director’s personal obligation to exercise judgment.
- Critical analysis: When using and relying on AI, directors must be able to justify why that reliance is reasonable given AI’s inherent qualities and limitations. A director who delegates routine data analysis to a well-tested proprietary tool is in a different position from one who relies on a generative chatbot for strategic advice.
- Require disclosure of AI use in board materials. Management should disclose when AI has been used to prepare papers, with clear policies for verifying output.
For practical guidance, boards can also draw on the Australian Institute of Company Directors’ suite of director-focused resources, including AI use by directors and boards: Early insights, A Director’s Introduction to AI, A Director’s Guide to AI Governance , Data Governance Foundations for Boards, and Effective board minutes and the use of AI.
Conclusion
The legal duties have not changed, but how they will be tested has. AI gives directors powerful new tools and new avenues of criticism, with a fresh trail of records for regulators and plaintiffs to follow. The message from the Chief Justice, ASIC and APRA is consistent: AI governance is not a future compliance project. The existing legal framework applies now. Boards that cannot demonstrate effective, proportionate and evidence-based governance face rising scrutiny. Directors who engage actively, stay literate, govern AI use deliberately and keep their own judgment at the centre of decision-making will be well placed when the foreseeable wave of AI litigation arrives.
Our next instalments will examine AFSL duties, legal professional privilege and AI use, and “AI washing”, with further topics to come.