Key takeaways

  1. Governance is lagging. Without adequate governance of AI use, boards and directors are at heightened risk of regulatory scrutiny and personal liability. ASIC and APRA have both signalled they will act where entities and individuals fall short.
  2. The duties are the same; the context is new. Directors’ duties have not changed, but AI introduces novel vectors for decision-making and gives courts and regulators fresh lines of inquiry into how duties are being discharged.
  3. AI can inform judgment; it cannot replace it. Directors cannot delegate their responsibilities to a machine. Given the inherent risks that AI presents, directors must treat it differently from other technology systems.
  4. Doing nothing is itself a risk. Boards that avoid AI governance risk regulatory and other action. Boards that avoid AI altogether invite scrutiny and competitive disadvantage.
  5. AI leaves a trail. Every prompt, output and chat log may become discoverable. Boards should manage AI-related records proactively.
  6. Board composition matters. Technology experience remains underrepresented in many boardrooms. Directors need the technological literacy to challenge management on AI.
  7. Governance must be proportionate, not perfect. APRA’s standard is governance proportionate to the entity’s size, scale and complexity. Smaller organisations need not replicate the frameworks of a major bank but they must demonstrate considered, risk-based engagement with AI.