The clear answer: yes. ASIC maintains a technology-neutral position, meaning existing laws and duties apply regardless of which tools an adviser uses. The harder questions are whether firms are actually ready, whether their governance frameworks can handle the risks, and whether their clients are protected.
Context makes this urgent. ASIC’s March 2026 Moneysmart research found that nearly one in five Gen Z Australians are already turning to AI platforms for financial information, and 64% of them trust what those platforms tell them. Young Australians are not waiting for the profession to catch up. They are arriving at adviser meetings having already formed views shaped by tools that carry no professional accountability. The gap between what AI tells clients and what advisers are obligated to provide is where the compliance exposure lives.
ASIC’s Technology-Neutral Stance Means There Is No AI Loophole
ASIC does not regulate the tool. It regulates the outcome. Under Section 912A of the Corporations Act, licensees must provide financial services efficiently, honestly, and fairly. That obligation does not bend because an AI produced the output. An adviser who relies on a hallucinated AI recommendation and passes it to a client has not met their best interests duty, even if they did not know the output was wrong.
This framing matters because it shifts the question from “can we use AI?” to “can we demonstrate that using AI still results in compliant, appropriate advice?” There is no grey area or loophole here. The full weight of regulatory compliance rests on the adviser, regardless of where in the process a tool was involved.
Five Risks That Governance Frameworks Must Address
The risks of AI in financial advice are the predictable consequences of deploying powerful tools without matching governance.
Hallucinated outputs are the most visible risk. Generative AI models produce confident responses that can be factually wrong or fabricated. In the context of financial advice, a plausible-sounding but incorrect recommendation does not become safer because it came from a sophisticated model. It becomes harder to detect.
Privacy and cybersecurity exposure follow directly from how AI is used. Inputting sensitive client data into third-party or offshore AI systems raises questions about data sovereignty, storage, and access that most standard engagements with AI vendors do not fully resolve. The adviser’s Privacy Act obligations do not transfer to the vendor.
Governance gaps are perhaps the most systemic risk. Firms are integrating AI faster than they are updating the policies, controls, and risk frameworks that govern it. When something goes wrong – and in any system operating at scale, something eventually will – the question regulators ask is not whether a tool was involved. It is whether the firm had adequate systems to prevent it.
Bias and discriminatory outcomes emerge from training data that reflects historical patterns. An AI model trained on historical financial data may systematically produce outputs that disadvantage certain client segments. ASIC has specifically flagged this risk. The adviser who acts on biased AI outputs carries the liability, not the model provider.
Lack of transparency compounds all the above. When an adviser cannot explain how a recommendation was reached, they cannot discharge their obligation to provide clear, appropriate advice. An invisible decision is an indefensible one. Regulators and clients both expect explanations. “The AI suggested it” is not one.
These risks do not operate in isolation. A governance gap makes hallucinations harder to catch. Opacity makes bias harder to detect. The system fails as a system, not just at individual failure points.
“Human in the Loop” Only Works If the Humans Understand What They’re Looking At
ASIC expects human oversight of AI-assisted advice, and the principle is sound. But human oversight is only meaningful when the humans reviewing AI outputs have the knowledge, time, and tools to identify problems. A cursory review of a confidently-worded AI recommendation does not constitute oversight. It is the appearance of oversight and it is where liability silently accumulates.
This is the expertise deficit that most firms have not yet confronted. The three traditional lines of defence – risk management, compliance, and internal audit – were built to review human decisions. They were not built to evaluate whether an AI model’s output is appropriate, whether its training data introduced bias, or whether its reasoning can withstand regulatory scrutiny. Without AI literacy at each of these levels, the oversight that firms believe they have is largely theoretical.
Management of third-party risk sits alongside this. The fact that an AI model was built and maintained by an external vendor does not transfer accountability for its outputs. Licensees remain fully responsible for the work of outsourced functions, including the AI tools they select, configure, and deploy. Due diligence on AI vendors, for example their data handling, model governance, and liability terms, is not optional. Outsourced technology is not outsourced liability.
Documentation requirements remain unchanged. Every piece of advice influenced by AI must be recorded, with clear evidence of how AI was used and how human judgement was applied to its outputs. This is both a compliance requirement and a practical protection. If a complaint arises, the paper trail matters.
Build Governance Before You Deploy and Update It Continuously
ASIC’s guidance to licensees is direct: establish comprehensive AI governance frameworks, including specific policies, procedures, and codes of conduct, before integrating new AI tools into operations. This is the principle that most firms are currently inverting.
Risk management policies need to be updated specifically for AI. Generic technology risk frameworks do not capture the distinct failure modes of generative AI eg, hallucination, model drift, bias, and opacity, and they do not map onto the advice obligations that apply in this sector.
There is also a static policy problem. A governance document written for the AI tools of 2024 does not govern the AI tools of 2026. The technology is evolving continuously. Regulatory interpretation is evolving continuously. A policy that is not actively maintained becomes a liability of its own, evidence that the firm believed it had addressed a risk it had actually frozen in time and ignored.
Disclosure deserves deliberate attention. When AI directly influences advice, clients have a reasonable interest in knowing. How and when to disclose AI involvement is a governance decision that should be made before deployment, not improvised after a client raises the question.
Adequate resourcing of AI oversight with both the technology infrastructure and the human capacity to monitor it, is part of the obligation. Underfunding oversight while deploying AI at scale is not a cost-saving measure. It is a risk creation measure.
Governance Is a Process, Not a Checkbox
The firms that navigate AI well will not be the ones that asked legal for a sign-off and moved on. They will be the ones that built systems designed to catch predictable failures before those failures reach clients, and then kept updating those systems as the technology and regulatory environment evolved.
ASIC has mapped the problem. The gap between where most firms are and where they need to be is a governance gap, and it is one that only deliberate, ongoing work will close.
AI offers genuine value to financial advisers and, through them, to clients. Getting there requires treating governance not as the price of admission, but as the foundation everything else is built on.
For a detailed examination of the nine AI governance gaps that apply to AFSL holders, see the Galdren report on AFSL risk.