This is a service specifically targeted at the needs of busy non-executive directors. We aim to give you a 'heads-up' on the things that matter for the week ahead – all in just a few minutes.

In this edition, we cover upcoming obligations to provide director identification numbers (DINs) to the Australian Securities and Investments Commission (ASIC) and Treasury's consultation on improving the efficiency of climate-related financial disclosures. We also consider the Full Court of the Federal Court's dismissed appeal by Fewstone Pty Ltd, trading as City Beach (City Beach), against an Australian Competition and Consumer Commission (ACCC) product safety penalty. 

In Over the Horizon, we consider the importance of artificial intelligence (AI) governance.

Governance

ASIC announces further DIN requirements from 1 July 2027.

On 24 August 2026, ASIC announced that from 1 July 2027, new laws passed under the Treasury Laws Amendment (Business Registries Stabilisation and Uplift) Act 2026 will require companies to provide DINs to ASIC, including through annual reviews. These changes coincide with DINs being linked to the ASIC Companies Register (as discussed in a previous edition of Boardroom Brief) and together seek to reduce the risk of fraud and identity misuse, improve the accuracy of company records and improve the quality of registry information. Changes to DIN obligations will apply to companies and directors, including where an individual is a director of a registered Australian body, a registered foreign company or an Aboriginal and Torres Strait Islander corporation. Prospective directors without an existing DIN should allow sufficient time to apply for a DIN, noting that it may take up to 56 business days. In preparation for 1 July 2027, companies should confirm that details of all current directors are correctly recorded and ensure consistency of director details on the ASIC Companies Register and the Australian Business Registry Services records.

Regulatory

Treasury consults on cutting the cost of climate-related financial disclosures, with submissions closing 2 October.

On 23 August 2026, Treasury opened a consultation on improving the efficiency of climate-related financial disclosures. The main proposals, which are potential policy reform options only and have not received government approval at this stage, are to change assurance rules to reduce compliance costs, provide clearer guidance on key terms and concepts and reduce the burden of information requests across supply chains. The proposals are intended to lower business costs and administrative burdens while maintaining the quality of reports. Having undertaken their first year of climate-related financial disclosures, Group 1 entities may wish to make submissions or provide direct evidence of the costs and challenges of assurance and supply chain data requests. Group 2 entities should note that the changes being considered will not impact those reporting for the 2026–2027 financial year and Treasury has stated that reporting entities will be provided with receive sufficient notice before any reform is implemented. Submissions close on 2 October 2026.

Legal

Full Federal Court upholds the $14 million City Beach button battery penalty.

On 19 August 2026, the Full Court of the Federal Court dismissed City Beach's appeal against the $14 million penalty imposed in December 2025 for selling more than 60 product types containing button batteries on over 54,000 occasions without complying with the mandatory safety or information standards. The penalty, the first imposed for breaches of the button battery standards, remains in effect. City Beach argued the penalty was manifestly excessive. The Full Court held that the sale of "a very dangerous but very cheap product" in breach of a safety standard may be a paradigm case where the penalty bears no relevant relationship to the profit earned, given the heightened need for deterrence. The ACCC warned that businesses that fail to implement effective compliance systems risk substantial penalties. Directors should ensure that compliance systems detect non-conforming stock before it reaches shelves and that recall decisions are escalated quickly. The court's clear signal is that the seriousness of the safety risk, not the revenue a product generates, will drive penalty outcomes.

Over the Horizon

AI models going rogue underscore the importance of board oversight of AI governance.

On 19 August 2026, CEO of OpenAI, Mr Sam Altman, announced a two-week pause on some aspects of machine learning for its most advanced models to implement additional safety measures, acknowledging that "model capabilities were outstripping the pace of safety." The announcement follows incidents disclosed by OpenAI, Anthropic and Meta of AI models breaking through internal safeguards and autonomously perpetrating cyberattacks. On 10 August 2026, the Australian Broadcasting Corporation reported what is believed to be the first known autonomous cyberattack in Australia. An AI assistant was tasked with booking a user into a fitness class and when the class was fully booked, it independently hacked the gym's booking website in pursuit of its goal. OpenAI has announced that it is implementing stricter security controls, expanding testing and working with external experts. Anthropic similarly announced tighter monitoring and controls around infrastructure for the evaluation of AI models. It remains to be seen whether these measures will be sufficient. Risk management frameworks, cybersecurity controls and vendor oversight arrangements should be calibrated for a threat environment in which AI systems may act unpredictably and autonomously. Where organisations deploy AI agents or rely on third-party AI tools, boards should satisfy themselves that management has the technical literacy and governance structures in place to identify, monitor and respond to AI-related risks.