Privacy policies need an automated decision-making section by 10 December 2026.
Draft yours free

AI in Australian financial services

No AI-specific statute governs Australian financial services. Instead, ASIC and APRA have both said existing licensee obligations, director duties and prudential standards apply in full to AI, and both regulators have put the industry on notice about governance gaps. A hard legislative deadline is coming: automated decision-making disclosure under the Privacy Act from 10 December 2026.

ASICAPRAOAICAUSTRAC

Last reviewed September 2026. Every entry links to its official source.

The rules

What applies today

ASIC's first review of AI use by 23 licensees covering 624 use cases across banking, credit, insurance and advice. It found adoption accelerating while governance lagged: nearly half of licensees had no policies covering consumer fairness or bias. ASIC's position is that existing consumer protection provisions, director duties and licensee obligations already put the onus on institutions to govern AI properly. No new law is needed for those duties to bite.

Who this affects: AFS licensees and credit licensees using or planning AI.

Latest updates

What changed recently

  1. The Office of AI in PM&C opened consultation on the Australian Standards for AI, proposing mandatory standards for large data centres and conditions for AI training rather than obligations on organisations deploying AI; submissions close 9 October 2026.

    PM&C: have your say on AI training and infrastructure
  2. The Information Commissioner told the Law Council the OAIC is on the verge of releasing its guidance on the automated decision-making transparency obligation that commences 10 December 2026.

    OAIC: Law Council of Australia address
  3. The Council of Financial Regulators flagged frontier AI and critical third parties as system-wide operational risks and noted the APRA and ASIC roundtable paper.

    Council of Financial Regulators quarterly statement
  4. The Attorney-General released the Privacy Amendment (Personal Data Protection) Bill 2026 exposure draft, with a fair and reasonable test for handling personal information and express coverage of AI-derived information; submissions closed 18 September 2026.

    AGD consultation: privacy reform
  5. APRA and ASIC published Resilience at Frontier AI Speed, insights and a board preparedness checklist from nine industry roundtables, warning entities to move from awareness to tested action.

    ASIC media release 26-201MR
  6. National Cabinet agreed the Commonwealth will legislate nationally consistent AI laws and mandatory standards for large data centres in early 2027, complementing state and territory planning processes.

    National Cabinet communique
  7. Parliament appointed a Joint Select Committee on Artificial Intelligence, naming financial services among the sectors it will examine, reporting by 30 November 2026.

    Parliament of Australia: Joint Select Committee on AI
  8. The Prime Minister announced an Office of AI within PM&C and a commitment to legislate Australian Standards for AI, with legislation expected early 2027. Financial services obligations remain regulator-led until then.

    PM media release: AI in Australia's interests
  9. APRA's System Risk Outlook named AI a key system risk, warning that AI is being adopted rapidly across all regulated industries while governance arrangements have not matured at the same pace.

    APRA System Risk Outlook
  10. ASIC issued an open letter to all AFS licensees demanding an urgent cyber uplift against AI-accelerated threats, with twelve actions and a direction to table the letter at board level.

    ASIC 26-092MR
  11. The OAIC opened consultation on guidance for the automated decision-making transparency obligation that commences 10 December 2026, with guidance expected before commencement.

    OAIC ADM consultation
  12. APRA published its letter to industry on AI, setting minimum board and executive expectations and flagging stronger supervisory action and possible enforcement where AI risks are unmanaged.

    APRA letter to industry on AI

Getting ready

Compliance checklist

  • Keep an inventory of every deployed and planned AI use case, with policies covering consumer fairness, bias and disclosure. ASIC found nearly half of licensees lacked these. See the rule

  • Treat efficient, honest and fair services, misleading-conduct prohibitions and director duties as applying fully to AI outputs today. Do not wait for AI-specific legislation. See the rule

  • Build board AI literacy: the board should be able to genuinely challenge AI strategy and receive AI risk reporting with defined escalation triggers. See the rule

  • Fold AI into CPS 230: register AI vendors and foundation-model dependencies as potentially material service providers and test contingency plans for supplier concentration. See the rule

  • Harden AI-specific security: test for prompt injection, data leakage and insecure integrations, and extend identity management to non-human and agentic actors. See the rule

  • Update your privacy policy before 10 December 2026 if automated systems use personal information to make or substantially contribute to decisions that significantly affect people. See the rule

  • Document AI transaction-monitoring tools in your reformed AML/CTF program and keep qualified human oversight over suspicious-matter reporting. See the rule

Show your customers you're across all of this

Certification against Australia's AI Ethics Principles is independent proof that your business uses AI responsibly, before a client, regulator or tender asks.

Get certified