In this edition, we cover the Australian Institute of Company Directors (AICD) new practical guide on building AI fluency in the boardroom. In Regulatory, we cover the joint consultation by the Australian Securities and Investments Commission (ASIC) and the Australian Prudential Regulation Authority (APRA) on streamlining the Financial Accountability Regime (FAR). In Legal, we discuss a $3.5 million penalty ordered against Venture 5 Group Pty Ltd (trading as CashnGo) (CashnGo). In Over the Horizon, we consider the Attorney-General’s consultation on privacy reform, including the Exposure Draft of the Privacy Amendment (Personal Data Protection) Bill 2026 (Cth) (Personal Data Bill).

Governance

AICD releases practical guidance on AI fluency for directors.

On 2 September 2026, the AICD published a practical guide on building AI fluency for directors. The guide emphasises that AI fluency is not about becoming a coding expert; rather, it is the ability to interpret data dashboards, ask sharp questions of management and effectively challenge AI-related claims and proposals. Directors should apply the same rigorous scrutiny to AI decisions as they do to strategy, risk management and financial accountability.

The guide reinforces that AI governance is an extension of existing director duties, not a separate discipline. In practice, this means ensuring AI is a standing board agenda item, that management provides clear and accessible reporting on AI use, risks and accountability, and that AI fluency is developed across the full board rather than delegated to a single “AI director”. Directors should keep in mind that AI fluency is perishable – it should be treated as an ongoing habit, not a one-off exercise. Practical steps include asking management for a plain-language summary of where AI is being used, on what data, and with what risks, and who is accountable. Directors may also find it useful to maintain a standing checklist of questions on these topics for use at each board meeting.

Regulatory

ASIC and APRA propose to streamline FAR reporting. 

On 2 September 2026, ASIC and APRA released a joint consultation on proposed changes to streamline the administration of the FAR. The proposals include removing key functions requirements from the FAR regulator rules and removing obligation to include information about accountable persons’ direct reports in accountability maps. ASIC and APRA estimate these changes will reduce reporting for all accountable entities and halve the number of updates to accountability maps. Subject to consultation feedback, the regulators intend to finalise the changes by the end of 2026, with effect from early 2027.

Directors of accountable entities should consider whether the proposed simplifications would affect their organisation’s accountability mapping and reporting obligations. Boards may wish to make a submission before 2 October 2026 and should ensure management remains ready to meet existing FAR requirements in the interim.

Legal

Federal Court imposes $3.5 million penalty on CashnGo for unfair contract terms.

On 31 August 2026, the Federal Court of Australia ordered that CashnGo pay a pecuniary penalty of $3.5 million in respect of contraventions of the Australian Securities and Investments Commission Act 2001 (Cth) arising from unfair contract terms in CashnGo’s standard form credit contracts. The unfair terms included indemnity provisions, limitation of liability provisions and terms that allowed the lender to monitor borrowers’ bank accounts and repeatedly attempt withdrawals following a missed repayment, without notice of the timing, frequency or amount of the intended withdrawal. The Court declared the terms void, restraining CashnGo from relying on similar terms and ordered replacement terms allowing consumers to opt out of unscheduled withdrawals. In imposing the penalty, the Court considered that CashnGo had been aware of concerns raised by consumers and ASIC and that these contraventions arose from CashnGo’s systems, contractual terms and the practices of its senior management and directors. The decision is a reminder that unfair contract terms are an enforcement priority for ASIC. Directors should ensure that consumer-facing standard form contracts are reviewed to identify and address potentially unfair terms, particularly where automated systems are used.

Over the Horizon

Privacy overhaul: what directors need to know.

On 31 August 2026, the Attorney General’s Department released the Exposure Draft of the Personal Data Bill, alongside a consultation paper. The reforms are intended to strengthen privacy protections for Australians and address emerging risks from new technologies. We discuss the proposed reforms further in our recent G+T insight article. Key proposals include:

  • One central “fair and reasonable” test. Separate obligations under the Australian Privacy Principles (APPs) will be replaced with an overarching requirement that the collection, use and disclosure of personal information be lawful, fair and reasonable in the circumstances. Compliance centred on consent alone will no longer be sufficient.
  • Stronger data breach obligations. Entities will be required to maintain a data breach response plan and take reasonable steps to mitigate harm as soon as practicable. Breaches likely to result in serious harm must be notified to the Australian Information Commissioner within 72 hours, a timeframe aligned with the EU’s General Data Protection Regulation and, where practicable, to affected individuals at the same time.
  • Controller-processor distinction. The Personal Data Bill formally distinguishes controllers from processors. A processor acts under a controller’s documented instructions and would be exempt from most APPs other than APP 1 (open and transparent management) and APP 11 (security). Critically, a processor’s privacy breaches would be attributed to the controller.
  • Prohibition on “trading” personal information. Disclosing personal information for money, other consideration or direct marketing will be classified as “trading” – a new concept under the legislation. Trading will be prohibited without the individual’s consent, subject to limited exceptions.

Many of the proposed requirements would apply to information already held by organisations, not only information collected after commencement, requiring a broad reassessment of existing data handling practices. Directors should keep in mind that these reforms, if enacted, will require material changes to privacy compliance frameworks. Boards should ensure management is assessing the organisation’s exposure, mapping controller-processor relationships and reviewing data handling practices against the proposed obligations. The consultation closes on 18 September 2026 (with a 1,000-word limit on submissions).