As AI powered Monitoring and Forecasting Tools Become Standard Business Practice, the Legal Test Directors are Held to Shifting with Them
07-09-2026

Section 588G of the Corporations Act 2001 (Cth)1 requires a director to prevent a company incurring a debt at a time when there are reasonable grounds to suspect the company is, or will become, insolvent as a result.2 Breach exposes a director to civil liability once the company is in liquidation, pursued by a liquidator or creditor under section 588M,3 and to criminal liability where dishonesty is involved.4 This sits alongside the general duty of care in section 180(1)5, which requires the degree of care and diligence a reasonable person would exercise in that office.6 Both duties are objective, and both are increasingly read through the lens of how directors govern the information systems, including AI systems, that feed their decisions.
The test asks what a reasonable director in the company's circumstances should have known, not what the director believed.7 That standard moves with what tools are reasonably available to directors generally at the time. Monitoring solvency is a responsibility a director cannot delegate away, regardless of what tools or advisers are in place.
As tools flagging cash flow deterioration, payment risk or reporting anomalies become standard, the bar for what a reasonable director should have known moves with them. A warning generated and ignored is the kind of detail a liquidator can point to later. The absence of a tool does not automatically excuse a director either, since the standard is what was reasonably available, not what was installed.
ASIC has said directors obligations are principle based rather than technology specific, applying equally to outcomes produced by AI as to any other process, and that AI use by companies deserves particular attention.9 Monitoring AI use, including in sectors where it already informs risk decisions such as banking, credit, insurance and advice, is a stated ASIC strategic priority.10 It is now understood that human judgment must remain central to any AI informed decision rather than being displaced by it.11
In Australian Securities and Investments Commission v Bekier12, the Federal Court found the former CEO and General Counsel of The Star Entertainment Group Limited breached their duty of care under section 180(1)13 by failing to escalate risk information to the board.14 Part of the reasoning turned on how information reached the board at all and the risks of unsupervised AI used in filtering board material.15
For solvency monitoring, this means the duty of care concerns not just whether the ultimate call was reasonable, but whether the board's systems could surface a genuine warning sign in time, and whether the AI tool's limitations were understood before its output was relied on.
A director is generally entitled to rely on information from an employee or adviser reasonably believed competent and reliable.16 That reliance must involve independent assessment, good faith, and reasonable grounds as to the competence of the person relied upon.17 The Corporations Act frames this test around persons, not systems, so an AI tool cannot itself be treated as an expert. The better view is that competence sits with whoever is responsible for the system.
This matters for the business judgment rule too. Section 180(2) only protects a director who has actually exercised a judgment, in good faith, for a proper purpose, without a material personal interest, and after informing themselves appropriately.18 Adopting an AI output without real interrogation raises real doubt that any judgment was exercised, meaning the defence is never engaged.19 Directors need not understand how a tool works technically, but must be able to explain how its outputs were tested, challenged and acted upon.
Separately, from 10 December 2026 new obligations under Australian Privacy Principle 1 require disclosure in a privacy policy where a computer program is used to make, or substantially assist in making, a decision that could significantly affect an individual's rights or interests.20 These obligations, inserted by the Privacy and Other Legislation Amendment Act 2024 (Cth), are not limited to generative AI.21 Where a monitoring tool affects an individual, for example in assessing a customer's credit risk, boards should check now whether their privacy policy needs updating.
A warning that's ignored is hard to defend later. A warning that's acted on and documented is one of your strongest protections. We help directors respond properly when it counts.
1 Corporations Act 2001 (Cth) s 588G(1).
2 Corporations Act 2001 Cth) s 588G(2)
3 Corporations Act 2001 (Cth) s 588M.
4 Corporations Act 2001 (Cth) s 588G(3).
5 Corporations Act 2001 (Cth) s 180(1).
6 Ibid; Paula Pyburne and Jaan Murphy, Directors Duties: A Quick Guide, Research Paper, Parliamentary Library, Parliament of Australia, 17 June 2022.
7 Corporations Act 2001 (Cth) s 588G(2).
8 Corporations Act 2001 (Cth) s 588G(1)(c); AWA Ltd v Daniels (1992) 7 ACSR 759.
9 Joe Longo, 'We're Not There Yet: Current Regulation Around AI May Not Be Sufficient', Australian Securities and Investments Commission, 31 January 2024.
10 Australian Securities and Investments Commission, Corporate Plan 2024–25 (Report, August 2024).
11 Australian Institute of Company Directors and Human Technology Institute (University of Technology Sydney), A Director's Guide to AI Governance, 12 June 2024.
12 Australian Securities and Investments Commission v Bekier (Liability Judgment) [2026] FCA 196.
13 Corporations Act 2001 (Cth) s 180(1).
14 Australian Securities and Investments Commission v Bekier (Liability Judgment) [2026] FCA 196.
15 Ibid.
16 AWA Ltd v Daniels (1992) 7 ACSR 759, 868 (Rogers CJ).
17 Ibid.
18 Corporations Act 2001 (Cth) s 180(2).
19 Australian Securities and Investments Commission v Rich [2009] NSWSC 1229; (2009) 236 FLR 1.
20 Privacy Act 1988 (Cth) sch 1 cl 1.7-1.9, Privacy and Other Legislation Amendment Act 2024 (Cth) pt 15; Office of the Australian Information Commissioner, 'Chapter 1: APP 1 Open and Transparent Management of Personal Information'.
21 Ibid.

07-11-2018

25-02-2020

02-03-2020
Sign up for our newsletter to get the latest articles and blogs—delivered straight to your inbox!