The review
What ASIC looked at
ASIC analysed the AI use cases that the 23 licensees were using or developing as at December 2023, limited to uses that affected consumers directly or indirectly, and including generative AI and advanced data analytics models. It also asked the licensees about their risk management and governance for AI and their plans, and met 12 of them in June 2024.
Findings 1 to 8
The eight findings
| Finding | What ASIC found |
|---|---|
| 1 | How far licensees used AI varied widely: some had used it for years, others were just starting. Overall, adoption was accelerating fast. |
| 2 | Most current uses relied on long-established techniques, but there was a move to more complex and opaque ones, and generative AI use was rising sharply. |
| 3 | Deployment was mostly cautious. AI supported human decisions or made work more efficient, generally did not decide on its own, and mostly did not deal with consumers directly. |
| 4 | Not every licensee had adequate arrangements for managing AI risks. |
| 5 | Some licensees judged risk from the business’s side rather than the consumer’s, with gaps around risks particular to AI, such as algorithmic bias. |
| 6 | AI governance varied widely, with weaknesses that could open gaps as AI use speeds up. |
| 7 | Governance and risk management did not always keep pace with the nature and scale of AI use; where they lagged, ASIC saw the greatest risk of consumer harm. |
| 8 | Many licensees leaned heavily on third parties for their AI models, and not all governed the risks that brings. |
Among the report’s key statistics: 57% of all use cases were under two years old or still in development; 61% of the licensees planned to increase their AI use in the next 12 months; only 12 licensees had AI policies that referred to fairness or related ideas, and only 10 had policies that referred to telling affected consumers about AI use.
The title
The gap ASIC means
ASIC’s reasoning is that governance and risk arrangements are “by their nature, slow to change”, so any gap between AI use and governance is likely to widen as adoption increases. In the case of two licensees, it found governance already lagged AI use. Its response is that licensees should review and update those arrangements regularly so they do not fall behind their changing use of AI, and that governance “should lead their AI use”.
The report names consumer risks it has in mind, among them: biased outputs falling hardest on vulnerable people, including being refused credit or insurance or paying more; advice that looks right but contains errors; confidential or sensitive information reproduced without consent, and exposure to cyber attacks and leaks; and marketing that plays on customers’ feelings or narrows their choices.
Existing obligations
The obligations ASIC points to
The report points to the law that already applies: it says the regulatory framework for financial services and credit is “technology neutral”, and that licensees need to consider their existing obligations before deploying AI. Among ASIC’s examples, in its own summary:
- providing financial or credit services “efficiently, honestly and fairly”;
- not engaging in unconscionable conduct, including through AI use;
- making sure what a licensee says about its AI use, model performance and outputs matches how it actually operates;
- adequate risk management systems, reviewed for how AI changes the risk profile;
- staying responsible for outsourced functions, with measures to choose, monitor and deal with service providers;
- directors’ and officers’ duty of care and diligence, which ASIC says extends to adopting, deploying and using AI.
The full list, which also covers compliance measures and technological and human resources, is on pages 33 and 34 of the report. The directors’ duty is section 180 of the Corporations Act 2001. Its first two subsections read:
“(1) A director or other officer of a corporation must exercise their powers and discharge their duties with the degree of care and diligence that a reasonable person would exercise if they: (a) were a director or officer of a corporation in the corporation’s circumstances; and (b) occupied the office held by, and had the same responsibilities within the corporation as, the director or officer.”
“(2) A director or other officer of a corporation who makes a business judgment is taken to meet the requirements of subsection (1), and their equivalent duties at common law and in equity, in respect of the judgment if they: (a) make the judgment in good faith for a proper purpose; and (b) do not have a material personal interest in the subject matter of the judgment; and (c) inform themselves about the subject matter of the judgment to the extent they reasonably believe to be appropriate; and (d) rationally believe that the judgment is in the best interests of the corporation. The director’s or officer’s belief that the judgment is in the best interests of the corporation is a rational one unless the belief is one that no reasonable person in their position would hold.”
Pages 35 and 36
ASIC’s eleven questions for licensees
ASIC expects licensees to weigh their readiness to deploy AI safely and responsibly, and suggests its findings and a set of questions to help. The questions sit under eleven headings, all of them here: taking stock; AI strategy; ethics and fairness; accountability; risk; alignment; policies and procedures; resourcing; oversight and monitoring; third parties; and regulatory reform. The first asks whether a licensee knows where AI is used in its organisation and keeps an AI inventory, the same kind of record the national guidance calls an AI register in the six essential practices.
Back to the registerThe laws a business already answers to, beside the guidance.