Regulators Are Watching: What Directors Need to Know About AI Governance Expectations
The regulatory landscape for AI has shifted from "should you consider it?" to "can you demonstrate you are addressing it?"
In 2024 and 2025, regulators around the world moved from issuing guidance to publishing enforceable expectations. The direction of travel is clear: boards are expected to oversee AI, and regulators expect to see evidence of that oversight.
The Global Picture
European Union: The AI Act
The EU AI Act establishes a risk-based regulatory framework for AI systems. It applies extraterritorially — if your organisation deploys AI systems that affect individuals in the EU, the Act applies to you.
The Act imposes obligations on organisations that deploy high-risk AI systems, including requirements for risk management, data governance, transparency, human oversight, and documentation. Directors of organisations subject to the Act should be aware that these obligations carry significant penalties.
United Kingdom: The AI Governance Framework
The UK has taken a principles-based approach, with five cross-sector principles: safety, transparency, fairness, accountability, and contestability. The Financial Conduct Authority (FCA) has been particularly active, requiring regulated firms to demonstrate that their AI systems are used fairly and do not harm consumer outcomes.
United States: Sectoral Regulation
The US has not enacted comprehensive AI legislation, but sectoral regulators are active. The Federal Trade Commission (FTC) has made clear that existing consumer protection laws apply to AI. The Equal Employment Opportunity Commission (EEOC) has issued guidance on AI in hiring. The Consumer Financial Protection Bureau (CFPB) has addressed AI in lending decisions.
Australia: The Emerging Framework
Australia's approach is still developing, but several developments are relevant for directors:
- The Australian Human Rights Commission has called for stronger AI regulation, particularly around algorithmic bias.
- ASIC has indicated that existing obligations under the Corporations Act apply to AI-related decision-making, and it expects boards to exercise appropriate oversight.
- The Privacy Act Review has recommended stronger protections for automated decision-making, including a requirement for privacy impact assessments.
- The Safe and Responsible AI in Australia consultation paper has outlined potential regulatory options, including mandatory guardrails for high-risk AI.
Common Themes Across Jurisdictions
Despite different approaches, common themes emerge:
- Human oversight. Regulators expect meaningful human involvement in AI-driven decisions, particularly those that affect individuals.
- Transparency. Organisations should be able to explain how AI systems work and what data they use.
- Fairness and non-discrimination. AI systems should not produce systematically biased outcomes.
- Accountability. Someone must be responsible for each AI system's outcomes.
- Documentation. Regulators expect evidence of governance, not just assertions.
What This Means for Australian Boards
You do not need to wait for comprehensive AI legislation to act. The existing regulatory framework already imposes obligations that apply to AI:
- Corporations Act 2001 (Cth): Directors' duties of care and diligence extend to AI oversight.
- Privacy Act 1988 (Cth): The use of personal information in AI systems must comply with privacy principles.
- Anti-Discrimination legislation: AI systems that make decisions about people must not discriminate.
- ASIC Act and consumer law: AI systems that interact with consumers must not mislead or deceive.
Practical Steps for Your Board
- Conduct a regulatory gap analysis. Identify which regulatory obligations apply to your organisation's AI use. Document any gaps.
- Monitor regulatory developments. Assign a director or committee to track AI regulatory developments in your sector.
- Engage with management. Ensure management is preparing for likely regulatory changes, not just reacting to them.
- Document your oversight. Minutes, board papers, and committee reports should reflect the board's consideration of AI governance.
- Seek advice. Consider engaging legal or governance expertise with specific AI regulatory knowledge.
The Bottom Line
Regulators are not waiting for perfect legislation. They are using existing tools to enforce existing obligations in the context of AI. The question for directors is not whether regulation will come — it is whether your board will be able to demonstrate that it was paying attention when it did.
The boards that prepare now will be the ones that regulators trust.