Artificial intelligence (AI) is revolutionising how companies and their directors receive, review and interpret information. One of the key benefits of AI is its ability to rapidly evaluate large-scale data. However, AI also brings risks including hallucination, over confidence in AI outputs and increased breaches of cyber security, privacy and confidentiality. These risks are heightened when human judgment is supplanted or overridden by AI. In this environment company directors must ensure that AI is used to benefit the company while minimising its risks. Directors must also ensure that the company is transparent about how it uses AI. In doing so, company directors should develop policies, and exercise oversight, to govern AI use by the Board, individual directors and the company as a whole. Even if the company does not use AI, directors must ensure that the company takes steps to protect the data it holds from breaches by external AI agents.
Directors must comply with their directors’ duties, including their duty to exercise the care and diligence of a reasonable person in the position of the director under s 180(1) of the Corporations Act 2001 (Cth) (the Act). This duty requires the exercise of human judgment. The risk of breaching the duty of care and diligence extends beyond a director's personal use of AI, also including reliance on officers or advisers who use AI, as well as oversight of how AI is deployed throughout the organisation.
This article considers recent judicial commentary on directors' use of AI and examines the governance, transparency and privacy obligations that boards must address to ensure AI is used responsibly and lawfully.
The question of how directors may lawfully engage with AI in the discharge of their duties, was recently considered by Justice Lee in the Federal Court decision of Australian Securities and Investments Commission (ASIC) v Bekier (Liability Judgment) [2026] FCA 196 (Bekier)[1]. There, ASIC brought claims against directors of Star Entertainment Group Ltd (The Star) for failing to adequately consider the money laundering and criminal risks associated with operating a major casino.
Whilst no one argued that the directors’ alleged breach flowed from AI usage, the directors raised the oft-heard argument that they had received “board packs spanning hundreds of pages” and consequently “should not be expected to read and absorb board materials in full”[2]. This prompted his Honour to acknowledge the commercial reality that individual directors are now commonly using AI to help them navigate board materials. On this point, Justice Lee decisively reminded directors that they have a non-delegable obligation to “take a diligent and intelligent interest in the information available to them”[3] and were not permitted to rely on an “inability to cope with the volume of information they receive”.
His Honour found that the duty of care and diligence which is imposed on directors under s 180(1) of the Act, is a personal duty which requires directors to exercise informed human judgment[4]. While AI can be used to assist comprehension, it should not be a substitute for directors’ own reading and interrogation of board papers[5]. On this point, it is useful to consider the extent to which directors may lawfully delegate to or rely upon others in the age of AI.
Under s 198D(d) of the Act directors are empowered to delegate functions to “any other person”. In his 2026 Harold Ford Memorial Lecture (the Lecture)[6], Chief Justice Andrew Bell highlighted that since AI is not yet a person within the meaning of the Act, directors will not be protected where they delegate their functions directly and solely to AI[7]. This includes a director who solely tasks AI with summarising board packs and then relies substantially on the AI generated summary of materials.
Whilst directors are generally entitled to rely on the advice of management and other officers, they still have a duty to undertake further enquiry where any fact would have awoken the suspicion of a prudent director. On this point, Bell CJ concluded that a director “would need to justify why their trust in a delegate who themselves was relying on AI was reasonable, in light of … the limitations of AI, including its scope for seductive self-confidence and sycophantic agreement, bias, or hallucination.”[8] Some safeguards which directors may impose to assist in this inquiry include:
In summary, AI does not alter the fundamental principle that directors must exercise their own informed judgment. The legal question is not whether AI was used, but whether the director's reliance on AI, or on others who used AI, was reasonable in the circumstances. This focus on accountability and oversight provides the foundation for the broader governance obligations discussed below.
Justice Lee’s second salient observation was that there must be greater transparency about how information is summarised and analysed by AI, and relied upon both by management in preparing board materials and by directors in reviewing that material. Instead of individual directors using AI in an ad hoc way, his Honour observed that boards should ‘deliberately govern any AI use by formal adoption of policies’ to ensure AI use is transparent and responsible[9]. This reflects a director’s broader responsibility to oversee how companies deploy AI.
3.1 Public-facing Privacy Policies
In response to growing public concern about how entities are allowing AI to use consumers’ personal information to make decisions, the Australian government has introduced new Australian Privacy Principles imposing explicit AI obligations under the Privacy Act 1988 (Cth). These will come into effect on 10 December 2026[10] and will apply to all organisations to which the Australian Privacy Principles apply, including government agencies, private sector organisations with a turnover greater than $3 million and smaller organisations that handle sensitive information such as health data or provide health services. Consequently, relevant entities must ensure that their privacy policies disclose in plain English:
where the decisions in question could be reasonably expected to affect the rights or interests of an individual and personal information about the individual is being used by the automated tool (such as AI)[11]. Relevant decisions may include hiring processes, credit assessments, differential pricing and more.
To comply with these changes, directors must ensure audits are conducted of the way AI is used to enhance decision-making throughout all business units. These changes are particularly relevant to directors, whose primary function is often decision-making, which is the very function targeted by the legislation. Directors must therefore not only comprehensively consider their own uses of AI or reliance on officers who use AI, but must also ensure that they comply with the automated decision making sections of the company’s privacy policies to avoid personal liability for breaches of consumer privacy.
3.2 Internal Governance Procedures & Liability Concerns
AI governance should be focused on managing organisational compliance with AI regulation and managing potential liabilities, whilst continuing to maximise the opportunity presented by AI to streamline workflows and increase productivity. Some of these liability concerns may include:
Consequently, it is imperative that internal governance policies and procedures seek to mitigate the aforementioned risks by for instance, setting out Data Breach Response Plans, prohibiting the use of public AI systems and by extension developing in-house systems or other secure alternatives.
It is important for organisations to simultaneously consider that stringent record keeping protocols and other policies surrounding AI usage can expose officers and the company to increased liability by creating records that may be required to be produced in litigation. For example, AI generated transcripts and detailed minutes of directors’ meetings may expose the directors and company to an increased risk of litigation and indeed may as a result stifle healthy debate and discussion by the board[16]. Directors should evaluate the optimal balance between having sufficient records to enable an assessment of the reliability of advice provided and decisions made, and protecting the company from excessive liability.
Ultimately, whilst AI can assist directors in the efficient discharge of their duties, it must not replace a director’s irreducible obligation to exercise their own judgement to make decisions in the company’s best interest. Directors will not be excused from liability on the basis that they delegated to, or relied upon, AI. Nor will directors be excused if they unreasonably delegated to or relied upon the advice of an officer, whom they were aware was employing AI to assist in the creation of that advice. Directors must also ensure that governance is continuously developed to reflect rapid changes in technology and to ensure compliance with legal obligations. Directors must ensure that safeguards are in place to monitor and control the organisation’s use of AI tools.
Authors: Nicola Nygh and Preethika Mathan.
Image Credit: Getty images via Unsplash.
[1] Australian Securities and Investments Commission (ASIC) v Bekier (Liability Judgment) [2026] FCA 196 (‘Bekier’) (Lee J).
[2] Bekier, [388].
[3] ibid, [395].
[4] ibid at [1956]
[5] ibid at [393] and [1956]
[6] The Honourable Chief Justice of NSW Andrew Bell AC, ‘Corporate responsibility and directors’ duties in the era of Artificial Intelligence’ (Harold Ford Memorial Lecture, University of Melbourne Law School, 21 May 2026) (‘Lecture’).
[7] Lecture, [57].
[8] Lecture, [62].
[9] Bekier at [394]
[10] Privacy and Other Legislation Amendment Act 2024 (Cth) amending Privacy Act 1988 (Cth) Schedule 1 (Australian Privacy Principles) (APP).
[11] Office for the Australian Information Commissioner, ‘Chapter 1: APP 1 Open and transparent management of personal information’, OAIC (Website, 3 October 2025).
[12] Australian Institute of Company Directors & UTS Human Technology Institute, ‘A Director’s Guide to AI Governance’, p. 24 (29 June 2026).
[13] ibid p. 24.
[14] David Swan, ‘Rogue agent or human error? What OpenAI’s Medicare breach means for you’, The Age (Website, 24 September 2026).
[15] UK and R (on the application of Munir) v Secretary of State for the Home Department [2026] UKUT 81 [21].
[16] Lecture at [87].

The High Court of Australia recently delivered an unanimous judgment in Zip Co Ltd v […]