Australia fits the pattern of most of this series — no AI-specific statute, existing law applied — but with an unusually blunt piece of supervisory homework attached: ASIC has already measured the gap between AI adoption and AI governance in licensed firms, and told licensees to close it.
ASIC: “Beware the gap”
In October 2024 ASIC published Report 798, Beware the gap: governance arrangements in the face of AI innovation — its review of how AI was being used and adopted by licensees. ASIC analysed 624 AI use cases in use or development as of December 2023 at 23 licensees across banking, credit, insurance and financial advice [1].
Two findings carry the weight. First, ASIC reinforced that existing regulatory frameworks apply to AI: licensees must consider their obligations before deploying AI, and governance must account for consumer impact, not just business risk. Second, the report’s title is its warning — licensees are adopting AI technologies faster than they are updating their risk and compliance frameworks, a gap ASIC says creates real risk of consumer harm.
For an advice licensee, the translation is familiar from the UK guide: there is no future compliance date to wait for. The general obligations attach to AI-assisted work today.
APRA: CPS 230 catches AI vendors
For APRA-regulated entities, Prudential Standard CPS 230 (Operational Risk Management) has applied since 1 July 2025, replacing and consolidating the previous outsourcing standard [2]. CPS 230 requires entities to identify material business processes, set disruption tolerances, and manage risks from material service providers — with board-level oversight and tested fallback plans.
AI slots straight into that machinery: a third-party AI provider supporting a material business process is a material service provider, and AI embedded in processes like credit decisioning or customer service at scale is likely to trigger CPS 230’s most demanding requirements [2].
The wider frame: voluntary guardrails
At the whole-of-economy level, the government consulted on mandatory guardrails for high-risk AI in 2024 [3] and published a Voluntary AI Safety Standard — ten guardrails covering accountability, testing, transparency and human oversight — as practical guidance for all Australian organisations [4]. Voluntary, but familiar: the guardrails describe the same converged core financial regulators expect, and an AFS licensee that runs them is simultaneously answering ASIC’s gap warning.
What this means in practice
The controls are the ones in the overview: an inventory of AI in use, a named accountable owner, meaningful human review of client-facing output, vendor due diligence (formalised under CPS 230 where it applies), and records that evidence the lot. ASIC has already told the market the gap exists; the firms that close it before an examiner asks are buying themselves a very short conversation. Cross-border client bases layer the usual extras on top — see AI governance for cross-border financial advisers.
This article is for informational purposes only and does not constitute regulated financial advice, legal advice, or a compliance opinion. Consult a qualified compliance professional for advice specific to your firm.
Sources
[1] ASIC, ‘REP 798 Beware the gap: Governance arrangements in the face of AI innovation’, 29 October 2024. Available at: https://www.asic.gov.au/regulatory-resources/find-a-document/reports/rep-798-beware-the-gap-governance-arrangements-in-the-face-of-ai-innovation/
[2] APRA, ‘Prudential Standard CPS 230 Operational Risk Management’, in force 1 July 2025. Available at: https://www.apra.gov.au/system/files/2023-07/Prudential%20Standard%20CPS%20230%20Operational%20Risk%20Management%20-%20clean.pdf
[3] OECD.AI Policy Observatory, ‘Mandatory Guardrails for Safe and Responsible AI (Australia)’. Available at: https://oecd.ai/en/dashboards/policy-initiatives/mandatory-guardrails-for-safe-and-responsible-ai-8090
[4] Department of Industry, Science and Resources, ‘Voluntary AI Safety Standard’. Available at: https://www.industry.gov.au/publications/voluntary-ai-safety-standard