APRA’s 30 April 2026 letter to industry and ASIC’s 8 May 2026 open letter have drawn steady commentary, most of which is focused on what regulators expect with the rapid development of frontier AI models. It is clear that Boards must govern AI; risk frameworks must keep pace; and cyber controls must be uplifted. The message is consistent and the direction is clear.
What the commentary has largely left unanswered is the operational reality – the more challenging, practical question sitting beneath all of it:
In your organisation, right now, who is actually accountable when something goes wrong during or as a result of the use of an AI model?
For most organisations, whether in financial services, healthcare, energy, retail and beyond, the likely answer is that no single person is. And that answer could, in itself, attract regulatory scrutiny.
The Accountability Vacuum
Walk through the typical organisational structure of a major bank, insurer or superannuation trustee deploying AI at scale. It may well be the case that the Chief Information Officer owns the technology infrastructure, the Chief Data Officer governs the data pipelines, the Chief Risk Officer owns the risk framework, the Chief Digital Officer drives AI strategy and adoption, legal counsel reviews vendor contracts, and the compliance team monitors whether regulatory obligations are met.
Each of these executives and teams touches AI risk. None of them, however, owns it end-to-end.
The result is a fragmented accountability architecture where responsibility for an AI model’s full lifecycle, from procurement and validation through to deployment, monitoring and decommissioning, is distributed across functions that may not necessarily share a common framework, reporting line or escalation threshold. In practice, this means that when something goes wrong, accountability is either contested or non-existent.
Some organisations may feel the pressure to introduce a Chief AI Officer, assuming it would resolve the issue around diffusion of accountability. However, creating a new role per se may not be a one-size-fits-all solution. Regardless of whether it is a single executive or a committee with specific mandate, the critical question is whether a single line of oversight exists, underpinned by well-defined roles and clear points of handoff.
In its April 2026 letter, APRA identifies governance maturity lagging AI adoption as one of its key observations, with specific gaps in how entities manage the AI lifecycle including post-deployment monitoring, change management and decommissioning. APRA has noted a tendency to treat AI risk as merely another technology risk, overlooking what sets it apart – predictive modelling, adaptive behaviour, inherent bias, and heightened privacy and data concerns.
Tellingly, APRA lists clear “ownership and accountability across the AI lifecycle” among its minimum governance expectations. This is not a finding about strategy or aspiration. It is a stark reminder about organisational design.
The Broader Regulatory Dimension
The absence of AI-specific legislation does not create a regulatory vacuum. Existing obligations apply to the use of AI across industries, and regulators expect organisations, boards and management to adapt governance, risk and compliance frameworks accordingly.
In terms of establishing clear accountability lines, below are some perspectives that should kick off the conversation:
- Existing APRA frameworks, such as Financial Accountability Regime (FAR), CPS 234 and CPS 230, apply to the use of AI. For instance, entities captured under FAR should evaluate how AI is being used across the organisation and ascertain if there is clear allocation of responsibilities amongst its ‘accountable persons’ for the selection, deployment and use of AI and how AI risks are being managed from end-to-end.
- ASIC’s warning is that AI-amplified cyber risk cannot be treated as a future or purely technical issue. Cyber resilience is not simply ‘nice to have’ – it is a core regulatory obligation for licensees and market participants. Recent judgments by the Federal Court, such as Australian Securities and Investments Commission v FIIG Securities Limited [2026] FCA 92, illustrate this. Boards and executives are expected to act now, with clear governance, escalation, control and incident-response frameworks that allocate accountability across the full lifecycle of AI-related risk, supported by adequate resourcing.
What a Defensible Accountability Architecture Looks Like
There is no single correct model, and organisational design will vary by organisation size and complexity. However, a defensible accountability structure for AI risk should address three aspects clearly.
Designated owner(s) with defined scope
First, a designated owner for the AI risk lifecycle.
In most institutions, this will sit with the Chief Risk Officer, an individual (or a small group of individuals) with a mandate that explicitly spans AI model governance from procurement through to decommissioning.
Global research shows that the share of organisations with a Chief AI Officer has risen from 26% in 2025 to 76% in 2026, reflecting a broad consensus that AI accountability cannot remain a secondary responsibility within an existing executive portfolio.
The critical point is that the mandate is explicit, documented and connected to the entity’s accountability and risk governance framework.
For APRA-regulated entities, this also means documenting the mandate and appropriately mapping it to the entity’s accountability map.
Clear handoff points between functions
Second, clear handoff points between functions.
For instance, the Chief Information Officer, Chief Data Officer and business unit leaders will retain operational roles in AI deployment. The accountability architecture must define where their responsibilities end and the AI risk owner’s begins.
Practically, this means documenting escalation triggers – what constitutes a material model change, what requires the risk owner’s sign-off before deployment, and what automatically gets escalated to the board.
Independent challenge at board level
Third, board-level visibility that is not filtered through the functions being overseen.
APRA’s letter specifically flagged over-reliance on vendor presentations and management summaries. The board’s AI risk reporting should include independent challenge, whether from internal audit, an external technical assurance provider or a board-level AI advisory function.
Ultimately, the operational realities of AI within the organisation should reflect its risk appetite.
Board exerciseThe Question to Ask This WeekConvene the relevant C-suite executives and ask each of them independently:
If the answers are inconsistent, or if each describes a portion of the issue, the accountability gap is confirmed. That exercise takes less than an hour and will do more to sharpen board focus on resolving the governance gap. |
Next in the series
Establishing accountability is the prerequisite. But it immediately raises the next question: How do organisations go about verifying that the controls aimed at managing AI risks are working?
Traditional audit and assurance methodologies were not designed for adaptive, probabilistic systems that can behave differently from how they were validated. That challenge, and what credible AI assurance looks like in practice, is the subject of the next article in this series.
Why Ironbridge Legal
Ironbridge Legal advises boards, executives and regulated entities on the governance, accountability and risk frameworks that sit at the centre of this article. Our regulatory practice helps clients translate evolving regulatory expectations into arrangements that hold up to scrutiny: clearly designated ownership, documented mandates, and accountability that maps to the relevant regime.
For boards and management weighing how to allocate responsibility for AI risk, that combination matters: considered, commercially grounded advice, backed by the ability to act decisively if matters escalate. To discuss how these expectations apply to your organisation, please get in touch.
[This is not intended to be a comprehensive AI governance guide. Readers are recommended to seek independent advice tailored to their own organisational context and regulatory environment].
Further Information
For further information about AI governance, accountability across the AI lifecycle, APRA and ASIC regulatory expectations, or designing defensible AI risk frameworks, please contact the author of this article: