The obligation is not
to have better AI.
It is to prove what the AI did — and who was in the loop when it did it.
Australian financial services organisations are deploying AI at scale across credit assessment, insurance claims, and fraud detection. These systems make thousands of consequential decisions every day — decisions that affect customers' access to finance, insurance outcomes, and financial security.
APRA and ASIC are intensifying their focus on how these decisions are governed. The regulatory question is no longer whether an organisation uses AI. It is whether the organisation can demonstrate that its AI decisions are auditable, subject to appropriate human oversight, and producing fair and consistent outcomes.
Most organisations cannot answer these questions today. Not because their AI is poor — but because the governance infrastructure to prove what it did does not exist.
The gap is not in the model — it is in the record. APRA-regulated entities operating AI-driven decision systems are exposed to regulatory, legal, and reputational risk not because their models are wrong, but because they cannot reconstruct what the model decided, why, and whether a human reviewed it.