In this edition, we cover Australian Securities Exchange's (ASX) consultation on proposed updates to the Corporate Governance Principles and Recommendations. In regulatory news, we cover the Australian Securities and Investments Commission’s (ASIC) three-year ban on two former directors of NextGen Financial Group Pty Ltd (NextGen) for failing to comply with Australian Financial Complaints Authority (AFCA) determinations. We also consider the Takeovers Panel (Panel) application concerning Adslot Ltd (ASX: ADS) (Adslot).
In Over the Horizon, we consider the Australian Government’s latest artificial intelligence (AI) consumer-safety priorities and what boards should consider.
Governance
ASX consults on updated governance principles.
On 21 July 2026, ASX opened an eight-week consultation on the draft fifth edition of its Corporate Governance Principles and Recommendations. Developed with input from ASX’s Advisory Group on Corporate Governance, the draft retains the eight principles and the ‘if not, why not’ reporting framework, and is intended to refine, rather than redesign, the existing framework. Contentious changes to diversity, equity and inclusion requirements, which were the primary barrier to consensus among the former members of ASX’s Corporate Governance Council, have largely been abandoned in favour of a less prescriptive approach.
If adopted, the fifth edition would apply to a listed entity’s first full financial year beginning on or after 1 July 2027. For 30 June year-end entities, that would mean reporting for the year starting 1 July 2027 and for calendar-year entities, the year starting 1 January 2028. Written submissions close at 5.00pm (AEST) on 14 September 2026 and ASX will hold public forums in each major capital city in August. Directors should ask management to test the draft against current processes regarding board capability, succession, induction, independence, culture and risk oversight to identify any practical concerns for submission before the deadline.
Regulatory
ASIC bans former NextGen directors for three years amid record enforcement outcomes.
On 24 July 2026, ASIC banned former NextGen directors, Mr Nicholas Brookes and Mr Vitorio Turco, from controlling or managing a financial services business for three years. ASIC found that each director was linked to NextGen’s failure to give effect to at least two AFCA determinations concerning inappropriate advice about establishing self-managed superannuation funds to purchase property. NextGen failed to make the required payments and affected consumers later received compensation through the independent not-for-profit company, the Compensation Scheme of Last Resort. Mr Brookes’ and Mr Turco’s orders took effect on 15 and 17 July 2026, respectively, and both have the right to apply to the Administrative Review Tribunal. The bans come amid a record ASIC enforcement period. On 20 July 2026, ASIC reported $830 million court-imposed civil penalties and $644 million being returned to consumers in 2025–26. ASIC expects directors of Australian financial services licensees to take appropriate steps to comply with AFCA determinations, including assigning clear executive ownership, tracking compliance through board reporting and verifying the completion of required payments and corrective actions.
Legal
Panel application flags disclosure risks in Adslot share transfer.
On 21 July 2026, the Panel received an application from Adslot substantial shareholder, Mr Andrew Barlow (the Applicant), concerning the off-market transfer of 723,878,279 Adslot shares from Private Portfolio Managers Pty Ltd (PPM) to Penstock Consulting Pty Ltd (Penstock). The shares represented 12.24% of Adslot’s issued ordinary shares and were transferred for $723.87, against an approximate market value of $723,870 based on Adslot’s last traded ASX price. The application raises concerns that the market was not adequately informed about the shares’ beneficial owner, the relationship between Penstock and Adslot executive chair, Mr Andrew Dyer, and the rationale for the transfer. Mr Dyer has voting power of approximately 9.16% in Adslot and is also a PPM director. The Applicant alleges a possible undisclosed association between Mr Dyer and Penstock, a potential breach of section 606 of the Corporations Act 2001 (Cth) (Corporations Act), and breaches of the substantial holding notice requirements in section 671B of the Corporations Act by PPM and Penstock. The Applicant seeks interim orders restricting voting, dealings and further acquisitions. His proposed final orders include corrective disclosure, sale of the shares through ASIC and removal or disregard of voting rights attached to the shares. When the application was announced, the Panel had not decided whether to conduct proceedings and made no comments on the merits of the application. Directors should note that share transfers with potential control implications can attract scrutiny where disclosure is unclear on beneficial ownership, party relationships and associations that may affect voting power.
Over the Horizon
The Australian Government flags five AI consumer-safety priorities.
On 20 July 2026, the Australian Government outlined five AI safety priorities:
- a digital duty of care requiring AI companies to build safety in by design and proactively address potential harm
- privacy reforms to strengthen, modernise and simplify Australia’s personal data protection laws
- workplace AI safety through the tripartite Artificial Intelligence Workplace and Employment Forum
- consumer law options to address risks such as retail surveillance pricing and agentic commerce
- a framework to better regulate automated decision-making within federal agencies.
These are policy workstreams, not new legal obligations. No commencement dates have been set, and the Government says the priorities are not exhaustive. However, it is clear from the priorities that AI governance is likely to extend beyond technology and cyber security into product safety, consumer protection, privacy, employment and the fairness, accuracy and transparency of automated decisions. Directors should understand where the company uses AI in customer-facing services, employment processes and material decision-making. They should ensure management has:
- mapped the risks
- allocated accountability
- tested for safety and privacy issues
- set escalation processes for inaccurate, discriminatory or unexpected outcomes.