Australia fits the pattern of most of this series (no AI-specific statute, existing law applied), but with an unusually blunt piece of supervisory homework attached: ASIC has already measured the gap between AI adoption and AI governance in licensed firms, and told licensees to close it.
ASIC: “Beware the gap”
In October 2024 ASIC published Report 798, Beware the gap: governance arrangements in the face of AI innovation, its review of how AI was being used and adopted by licensees. ASIC analysed 624 AI use cases in use or development as of December 2023 at 23 licensees across banking, credit, insurance and financial advice [1].
Two findings carry the weight. First, ASIC reinforced that existing regulatory frameworks apply to AI: licensees must consider their obligations before deploying AI, and governance must account for consumer impact, not just business risk. Second, the report’s title is its warning: licensees are adopting AI technologies faster than they are updating their risk and compliance frameworks, a gap ASIC says creates real risk of consumer harm.
For an advice licensee, the translation is familiar from the UK guide: there is no future compliance date to wait for. The general obligations attach to AI-assisted work today.
APRA: CPS 230 catches AI vendors
For APRA-regulated entities, Prudential Standard CPS 230 (Operational Risk Management) has applied since 1 July 2025, replacing and consolidating the previous outsourcing standard [2]. CPS 230 requires entities to identify material business processes, set disruption tolerances, and manage risks from material service providers, with board-level oversight and tested fallback plans.
AI slots straight into that machinery: a third-party AI provider supporting a material business process is a material service provider, and AI embedded in processes like credit decisioning or customer service at scale is likely to trigger CPS 230’s most demanding requirements [2].
The wider frame: from guardrails to a national plan to promised legislation
The whole-of-economy story has moved twice since the 2024 consultations. The mandatory guardrails for high-risk AI consulted on in 2024 [3] were never introduced as legislation: the National AI Plan of December 2025 dropped the standalone-AI-Act approach in favour of existing laws, sector regulators, voluntary guidance and a new Australian AI Safety Institute. The ten-guardrail Voluntary AI Safety Standard was superseded in late 2025 by the Guidance for AI Adoption, which condenses the same substance into six essential practices (governance and accountability, impact assessment, risk management, transparency, testing and monitoring, human oversight) aligned to the international standards examiners recognise [4].
Then, in July 2026, the government moved again: an Office of AI in the Prime Minister’s department and a stated commitment to legislate “Australian Standards for AI”, with legislation expected in 2027. The sensible reading for a licensee: the six practices are today’s checklist, and they are also the likely skeleton of whatever gets legislated.
The date that is actually fixed: 10 December 2026
One genuinely binding change is already scheduled. The Privacy Act reforms enacted in 2024 commence their automated-decision-making transparency duty on 10 December 2026: privacy policies must disclose decisions made substantially by automated means that significantly affect individuals, and the duty covers rule-based systems as well as AI. For any firm whose systems score, price, approve or triage clients automatically, the compliance step is concrete: identify those decisions and say so in the privacy policy before December.
What this means in practice
The controls are the ones in the overview: an inventory of AI in use, a named accountable owner, meaningful human review of client-facing output, vendor due diligence (formalised under CPS 230 where it applies), and records that evidence the lot. ASIC has already told the market the gap exists; the firms that close it before an examiner asks are buying themselves a very short conversation. Cross-border client bases layer the usual extras on top; see AI governance for cross-border financial advisers.
This article is for informational purposes only and does not constitute regulated financial advice, legal advice, or a compliance opinion. Consult a qualified compliance professional for advice specific to your firm.
Sources
[1] ASIC, ‘REP 798 Beware the gap: Governance arrangements in the face of AI innovation’, 29 October 2024. Available at: https://www.asic.gov.au/regulatory-resources/find-a-document/reports/rep-798-beware-the-gap-governance-arrangements-in-the-face-of-ai-innovation/
[2] APRA, ‘Prudential Standard CPS 230 Operational Risk Management’, in force 1 July 2025. Available at: https://www.apra.gov.au/system/files/2023-07/Prudential%20Standard%20CPS%20230%20Operational%20Risk%20Management%20-%20clean.pdf
[3] OECD.AI Policy Observatory, ‘Mandatory Guardrails for Safe and Responsible AI (Australia)’. Available at: https://oecd.ai/en/dashboards/policy-initiatives/mandatory-guardrails-for-safe-and-responsible-ai-8090
[4] Department of Industry, Science and Resources, ‘Voluntary AI Safety Standard’. Available at: https://www.industry.gov.au/publications/voluntary-ai-safety-standard