AI risk management keeps failing for the same boring reason: nobody actually owns it.
Not IT, not legal, not the business unit running the use case — everyone assumes someone else has it covered. In 2026, that assumption has a name attached to it, and regulators are starting to ask for it directly.
The 30-second take
AI risk management is not a control function’s job — it starts and ends with business ownership.
ASIC and APRA are now both explicit that boards need a named accountable person attached to every material AI use case, not a shared committee or a vague line in a policy document.
Directors who can’t answer who owns this AI use case, and what happens if it goes wrong, are exposed personally, not just organisationally.
Getting ownership right before a regulator or an incident forces the question is the fastest way to speed up AI adoption, not slow it down.
ASIC: “I did not know the algorithm did that” won’t cut it
ASIC’s first deep look at AI governance, Report 798 Beware the Gap, reviewed 624 AI use cases across 23 AFS and credit licensees and found governance lagging well behind adoption — nearly half the licensees reviewed had no policy addressing consumer fairness or bias in their AI use cases.
The tone has hardened since. Speaking at the AICD’s Australian Governance Summit in Sydney in March 2026, ASIC Chair Joe Longo told directors bluntly that “I did not know the algorithm did that” is not a legal defence.
ASIC has framed 2026 as a year of accountability, signalling it will pursue directors who fail to exercise independent judgement over material risks — AI included.
APRA wants a name next to every AI use case
On 30 April 2026, APRA wrote to every bank, insurer and superannuation trustee in the country. The message was blunt: AI deployment is outpacing the governance, risk management and assurance practices meant to oversee it.
The practical requirement is specific — APRA expects entities to hold an inventory of every model, agent, copilot and embedded AI feature, each classified by risk tier and assigned to a named accountable person under the FAR/BEAR regime. A shared governance committee is not an accountable person, and APRA has said so explicitly.
Directors already feel the gap
AICD’s Director Sentiment Index for the first half of 2026, surveying 828 directors through Roy Morgan, found concern over AI risk has surged even as cybercrime and data security hold the top spot for what keeps directors awake at night. Boards know this is live. What the sentiment data doesn’t show is whether anyone in the organisation could actually name the accountable owner if asked tomorrow.
What diffused ownership actually looks like in practice
A documented 2025 case involving a global firm’s AI-powered hiring platform shows how this plays out on the ground.
The platform remained accessible using default vendor credentials for months, exposing candidate data. Nobody caught it because ownership was split three ways: the business assumed IT had secured the platform, IT assumed the vendor’s defaults were adequate, and legal assumed its oversight obligations were covered by the vendor contract.
Each party owned a slice of the decision. Nobody owned the outcome.
Clear business ownership transforms AI risk management from a blocking exercise into a strategic enabler.
Questions to ask your organisation this week
- For every material AI use case in production, can we name the single accountable person — not a committee — responsible for it?
- Would that person’s name and role hold up if ASIC or APRA asked for it in writing tomorrow?
- Have we updated our risk management policies specifically for AI, or are we relying on pre-AI frameworks and hoping they stretch?
- Where AI touches consumers, have we assessed fairness and bias risk from the customer’s perspective, not just the business’s?
- Do our vendor contracts for AI tools actually assign security and oversight responsibility, or do we just assume they do?
- If an AI use case failed publicly tomorrow, do we know right now who would be the one explaining why?
Where to start
So, there are a lot of articles and opinions telling you what the problem is, so what can you do today?
Quite simply, this requires an AI inventory, an owners name against each line of it, and someone senior enough to own the answers when the question gets asked.
The AI Signal BoxTM provides a simple tool to use, and our readiness snapshot at the Innovation of Risk is a great place to see where your organisation stands before the regulator, or an incident, asks first.

