New report: Australia tops 121 economies for AI use, new index shows.
Read The Trust Dividend

AI in Australian financial services

No AI-specific statute governs Australian financial services. Instead, ASIC and APRA have both said existing licensee obligations, director duties and prudential standards apply in full to AI, and both regulators have put the industry on notice about governance gaps. A hard legislative deadline is coming: automated decision-making disclosure under the Privacy Act from 10 December 2026.

ASICAPRAOAICAUSTRAC

Last reviewed August 2026. Every entry links to its official source.

The rules

What applies today

ASIC's first review of AI use by 23 licensees covering 624 use cases across banking, credit, insurance and advice. It found adoption accelerating while governance lagged: nearly half of licensees had no policies covering consumer fairness or bias. ASIC's position is that existing consumer protection provisions, director duties and licensee obligations already put the onus on institutions to govern AI properly. No new law is needed for those duties to bite.

Who this affects: AFS licensees and credit licensees using or planning AI.

Latest updates

What changed recently

  1. The Prime Minister announced an Office of AI within PM&C and a commitment to legislate Australian Standards for AI, with legislation expected early 2027. Financial services obligations remain regulator-led until then.

    PM media release: AI in Australia's interests
  2. APRA's System Risk Outlook named AI a key system risk, warning that AI is being adopted rapidly across all regulated industries while governance arrangements have not matured at the same pace.

    APRA System Risk Outlook
  3. ASIC issued an open letter to all AFS licensees demanding an urgent cyber uplift against AI-accelerated threats, with twelve actions and a direction to table the letter at board level.

    ASIC 26-092MR
  4. The OAIC opened consultation on guidance for the automated decision-making transparency obligation that commences 10 December 2026, with guidance expected before commencement.

    OAIC ADM consultation
  5. APRA published its letter to industry on AI, setting minimum board and executive expectations and flagging stronger supervisory action and possible enforcement where AI risks are unmanaged.

    APRA letter to industry on AI

Getting ready

Compliance checklist

  • Keep an inventory of every deployed and planned AI use case, with policies covering consumer fairness, bias and disclosure. ASIC found nearly half of licensees lacked these. See the rule

  • Treat efficient, honest and fair services, misleading-conduct prohibitions and director duties as applying fully to AI outputs today. Do not wait for AI-specific legislation. See the rule

  • Build board AI literacy: the board should be able to genuinely challenge AI strategy and receive AI risk reporting with defined escalation triggers. See the rule

  • Fold AI into CPS 230: register AI vendors and foundation-model dependencies as potentially material service providers and test contingency plans for supplier concentration. See the rule

  • Harden AI-specific security: test for prompt injection, data leakage and insecure integrations, and extend identity management to non-human and agentic actors. See the rule

  • Update your privacy policy before 10 December 2026 if automated systems use personal information to make or substantially contribute to decisions that significantly affect people. See the rule

  • Document AI transaction-monitoring tools in your reformed AML/CTF program and keep qualified human oversight over suspicious-matter reporting. See the rule

Show your customers you're across all of this

Certification against Australia's AI Ethics Principles is independent proof that your business uses AI responsibly, before a client, regulator or tender asks.

Get certified