ASIC tightens AI rules for Australia’s financial firms
Australia’s corporate regulator has issued stronger rules and licence conditions for financial firms using AI to reduce consumer and market risks.
The Australian Securities and Investments Commission (ASIC) this week published updated requirements for regulated firms that use artificial intelligence in financial services, credit and market operations. The rules introduce stronger safeguards, clearer governance requirements and new obligations for testing, documentation and consumer protection to limit AI-related risks.
The requirements apply to automated advice, credit decisioning, trading algorithms and customer-facing chatbots. Firms must complete documented algorithmic risk assessments before deploying systems, maintain versioned model documentation and keep auditable logs of inputs and outputs. Key decisions must have demonstrable human oversight.
Firms are required to run pre-deployment tests on representative data, monitor model performance continuously and keep plans to fix errors or withdraw systems that produce unsafe outcomes. Where firms use third-party AI services, contracts must include rights to audit and access model evidence.
Regulated entities must tell consumers when significant decisions affecting them are made with substantial automated input. Firms that use AI to provide financial product advice must meet existing duties of best interests and responsible lending and keep human advisers able to intervene if automated recommendations could cause harm.
Compliance teams within firms will be required to report significant AI incidents to ASIC. The regulator said it will use existing powers, including licence conditions, infringement notices and civil penalties, against firms that fail to manage AI risks. ASIC plans targeted reviews of higher-risk AI activity and expects boards to demonstrate adequate model risk governance.
Guidance sets out controls for data quality and governance. Firms must document data provenance, check for bias and representativeness, and keep records that allow reconstruction of decisions. Cybersecurity expectations require treating models and training data as critical assets, applying strong access controls and protecting systems against data poisoning and model-extraction attacks.
The rules address staff competence and governance. Responsible managers and board members should understand how models are built and used. Firms must maintain training programmes for staff who design, implement or oversee AI systems. Internal audit and risk functions are expected to test model controls and escalate material weaknesses to senior management and the board.
ASIC noted the guidance does not ban AI but clarifies how existing laws on misleading conduct, disclosure, privacy and anti-discrimination apply when firms deploy automated systems. Industry groups and firms can engage with ASIC on implementation timelines, and the regulator will publish examples of supervisory focus areas and assessment criteria to help firms align their compliance programmes. Regulators globally have raised concerns about opaque AI decision-making, bias and potential systemic risk when models are widely used in financial services.








