AI is now a board-level risk. The governance, oversight, and disclosure expectations are crystallising fast, and director liability is following.
For: Non-executive directors, audit committee chairs, Chief Risk Officers
For boards and Chief Risk Officers, AI governance has moved decisively from a technology issue to a fiduciary one. APRA's 30 April 2026 industry letter set explicit expectations that boards understand AI risk well enough to exercise effective challenge. ASIC's 8 May 2026 cyber resilience letter framed AI as part of the directors' duty of care. The EU AI Act's deployer transparency obligations from 2 August 2026 will affect any Australian organisation with EU exposure. The work for boards and CROs now is establishing the governance, reporting, and assurance posture that satisfies these expectations without creating operational paralysis.
The substantive AI governance responsibilities that fall to this role under current Australian and global expectations.
Curated coverage selected for this role, frameworks, regulatory developments, and operational guidance you can act on.
The seven questions every director should be asking about AI in their organisation.
What APRA's integrated assurance framing means in practice, and why frontier systems break the static model.
Director exposure under AI obligations and what D&O policies actually cover.
What a credible AI report to the board looks like, monthly and quarterly.
Practical interpretation of the 30 April 2026 industry letter.
How AI use is increasingly material to ESG disclosures and investor expectations.
For board members of PE-owned companies, the governance maturity expected through the hold period.
For statutory body and government agency boards, sovereignty, accountability, and the Australian, UK, US, EU frameworks.
The regulatory frameworks, standards, and guidance documents most relevant to this role.
Australian prudential regulator's explicit expectations on AI governance, control frameworks, and integrated assurance.
Frontier AI and the directors' duty of care, board-tabling directive.
Globally recognised AI management system standard. The de facto answer to APRA's "globally recognised control frameworks" expectation.
US National Institute of Standards reference framework, voluntary but widely adopted by enterprise.
A 10-minute board-level diagnostic of where your organisation stands against APRA, ISO 42001, and NIST AI RMF expectations.
ContinueHow we work with boards and executives to put credible AI governance in place, and be able to demonstrate it. Start a conversation.
ContinueOn-site AI governance frameworks, board reporting outlines, and director briefing material, free to read on the site.
ContinueMonthly intelligence on Australian and global AI governance developments, written for senior decision-makers.
Continue