Governance

AI governance and policy for Australian boards

Australian AI policy moved 4 times in the last 10 months, and most published guidance still cites guardrails that no longer exist. Here is the current position and what it asks of a board.

Updated

Voluntary does not mean optional. No Australian statute yet compels a board to adopt an AI policy, and none is expected before 2027. Directors instead carry AI accountability under the duties they already hold, principally the duty of care and diligence in section 180(1) of the Corporations Act, which is the provision the Federal Court applied in ASIC v Bekier. The AICD's Director's Guide to AI Governance (opens in a new tab) takes the same position: AI oversight sits inside existing directors' duties.

The position as it stands

Since late 2024, 4 changes replaced the framework most boards were briefed on, so a paper written against the 10 guardrails describes a document that has been superseded.

When What changed
Sep 2024 The Voluntary AI Safety Standard (opens in a new tab) published the 10 guardrails most existing guidance still cites.
Oct 2025 Guidance for AI Adoption (opens in a new tab) superseded the guardrails, folding them into 6 essential practices aligned to ISO/IEC 42001.
Dec 2025 The National AI Plan (opens in a new tab) dropped mandatory guardrails for high-risk AI. Australia relies on existing law and sector regulators.
Mar 2026 ASIC v Bekier [2026] FCA 196, the first Australian judgment to consider AI use in a board setting.
Jul 2026 An Office of AI established within the Department of the Prime Minister and Cabinet, with AI legislation expected in early 2027.
Dec 2026 The remaining obligations under the Commonwealth's policy for AI use in government (opens in a new tab) take effect, and flow down to its suppliers.

The pattern matters more than any single entry. Regulation is arriving through guidance, procurement and the courts rather than through an AI act, so the standard of care rises without a commencement date a board can plan around.

What the court said about AI

ASIC v Bekier [2026] FCA 196, decided on 5 March 2026, is a judgment about Star Entertainment's governance failures under section 180(1). Its significance for AI lies in observations Justice Lee made along the way, which law firms have been briefing boards on (opens in a new tab) since: AI tools may legitimately help directors manage the volume of board material, but they cannot substitute for a director's own judgment, and their use belongs inside deliberate, transparent governance rather than informal habit.

Those observations are guidance rather than binding precedent, and they are the closest thing Australian boards have to a judicial statement on AI. Since March 2026, "we never decided how directors may use AI" reads as a governance gap a court has already described.

Do we need an AI policy?

If your people use AI at work, you already have an AI policy. It is unwritten, it varies by person, and nobody approved it. The choice in front of a board is between a policy it adopted and one that grew by habit, and everything above, from the 6 practices to ASIC v Bekier, points to adopting one deliberately.

What an AI policy contains

An AI policy is the document that records which tools are approved for which work, what data may leave the business, and who can stop an agent.

A workable policy is short, and it makes a small number of decisions explicit rather than restating the privacy policy at length:

  • Approved tools, by task. Which systems may be used for which classes of work, and which uses are prohibited.
  • Data boundaries. What company, customer and personal information may enter which tools, and what never leaves the business.
  • Human oversight. Which outputs a person must review before they act on the world, and how agents are supervised.
  • Accountability. Who owns the policy, who approves exceptions, and who can stop a tool or an agent.
  • Incidents. What counts as an AI incident, and where it is reported.
  • Review. How often the policy is revisited, because the ground has moved 4 times in 10 months.

The 5 decisions that sit with the board

Management drafts the policy, but 5 decisions cannot be delegated below the board:

  • Which tools are approved for which work
  • What company and customer data may leave the business
  • How agents are supervised, and who can stop one
  • Who owns redesigning how the work gets done
  • How you will know it is working

The 6 essential practices

The Guidance for AI Adoption replaced the 10 guardrails with 6 essential practices, and they now play the role the Essential Eight plays in cyber security: no law compels them, while boards, auditors, insurers and large customers treat them as the standard of care.

Practice What it asks of a board
Accountability A named owner for AI governance, with authority over the policy and its exceptions.
Impact assessment Benefits and harms assessed before a system is deployed, in proportion to its stakes.
Risk management AI risks measured and managed like any other enterprise risk, on a register the board can see.
Information sharing People are told when AI is being used, and essential information reaches those it affects.
Continuous testing Systems tested before deployment and monitored after it, because behaviour drifts.
Human oversight A person can intervene in, and stop, any AI system or agent.

From December 2026 the practices acquire a commercial edge. The Commonwealth's AI policy requires its agencies to run impact assessments and report AI incidents, and its procurement guidance asks suppliers to disclose AI use and accept accountability for it, so selling to government increasingly means evidencing the practices above.

What to put in front of the board next quarter

  • An AI policy adopted, or the existing one re-tested against the 6 practices
  • A register of AI use as it stands today, approved or otherwise
  • An impact assessment for the highest-stakes use in the business
  • A standing item: what management reports to the board about AI, and how often
  • If you sell to Commonwealth agencies, a plan for the December 2026 obligations

How Veriet works on governance

Veriet's governance engagements produce three things: an AI policy the organisation can operate, guardrails matched to the six essential practices, and a reporting rhythm that lets directors govern AI rather than watch it. We work with the board and the executive together, because a policy written apart from the people who use the tools stops being followed within a quarter. Governance is one part of a broader advisory practice covering strategy, operating model and fluency, so the policy serves the strategy it belongs to.