Background Information
The Australian Securities and Investments Commission (ASIC) has intensified its focus on cyber security and artificial intelligence (AI) in response to the evolving digital landscape and increasing reliance on technology across financial services. The introduction of the Cyber Security Act 2024 and ASIC’s Report 798 on AI governance mark a pivotal shift in regulatory expectations.
The Cyber Security Act 2024, which received Royal Assent in November 2024, establishes mandatory standards for smart devices and outlines obligations for financial service entities to protect information assets, detect and respond to cyber incidents, and recover from breaches. Concurrently, ASIC’s review of AI adoption revealed that while usage is accelerating, governance frameworks are lagging, creating significant risks for consumers and market integrity.
Licensee Obligations
Under section 912A of the Corporations Act 2001, licensees are required to act efficiently, honestly, and fairly, and to maintain adequate risk management systems. These obligations apply equally to digital systems, including AI and cyber infrastructure.
ASIC expects licensees to:
- Implement cyber security controls that protect key assets and enhance resilience across the digital supply chain
- Reassess cyber risks regularly using threat intelligence and vulnerability assessments
- Ensure AI systems, particularly those involving automated decision-making (ADM), are transparent, ethical, and compliant with privacy laws such as the Privacy Act 1998 and the Privacy and Other Legislation Amendment Bill 2024
- Obtain informed consent from clients before using ADM systems for financial risk assessments or personalised recommendations
- Avoid over-reliance on AI and maintain human oversight to prevent breaches and ensure accountability.
Updates from ASIC
ASIC’s Media Report 798 highlights key findings from its review of AI adoption among 23 licensees, these include:
- 60% of licensees plan to increase AI usage, yet nearly half lack policies addressing consumer fairness or bias.
- Many licensees use AI to support human decisions, but the shift toward generative AI and opaque models raises transparency concerns.
- ASIC warns of a “governance gap” where AI adoption outpaces compliance frameworks, risking misinformation, discrimination, and privacy failures.
ASIC Chair Joe Longo emphasises that existing consumer protection laws, director duties, and licensee obligations already require institutions to manage AI risks responsibly. Therefore, licensees should avoid waiting for new AI-specific legislation but instead ensure their governance frameworks are fit for purpose.
What This Means for Licensees
Licensees must act decisively to align their cyber and AI practices with ASIC’s expectations.
Key actions should include:
- Cyber Security: Establish and maintain robust cyber risk management frameworks, conduct regular assessments, and ensure incident response plans are in place.
- AI Governance: Develop and implement AI policies that address ethical use, transparency, and consumer protection. This includes documenting ADM systems and obtaining client consent.
- Training and Oversight: Provide staff with training on AI and cyber risks, and ensure human oversight remains central to decision-making processes.
- Compliance Monitoring: Update risk management procedures to reflect AI use and cyber threats, and report breaches promptly via the ASIC Regulatory Portal.
Licensees must proactively strengthen their frameworks to ensure ethical, secure, and compliant use of technology. Those who fail to adapt risk enforcement action, reputational damage, and consumer harm.
Recommended Training Opportunities
To support licensees in meeting ASIC’s compliance expectations, it is strongly recommended that organisations implement structured and ongoing training programs. GRC Essentials has created an AI Training Course, and Cyber Security Training Course that can assist licensees in providing their employees with information about the expectations and obligations associated with utilising AI in the workplace and maintaining cyber security protocols.
It is recommended that licensees should prioritise participation in these sessions and maintain accurate training registers to demonstrate competency and regulatory alignment.
Want to Know More?
If you would like to be enrolled into these courses, or have any questions about digital technologies in the financial services industry, please contact us at support@grcessentials.com.au

0 Comments