Quick answer: Financial planners, accountants, and other AFSL and AML-regulated firms face a direct and growing compliance exposure from shadow AI. Under section 912A of the Corporations Act 2001 (Cth), AFSL holders must have adequate risk management systems, maintain competence, and ensure services are delivered efficiently, honestly and fairly. ASIC issued a formal open letter to AFS licensees in May 2026 directing boards to treat AI governance as a material risk. APRA issued equivalent guidance in April 2026. Shadow AI – staff using AI tools that leadership cannot see, control, or audit – is not a technology problem. It is a governance problem, and it sits squarely inside your licence obligations.
The problem most financial services firms have not yet named
Staff at financial planning practices and accounting firms are using AI tools every day. They are drafting Statements of Advice, summarising client meeting notes, researching product options, preparing tax advice, and processing compliance documents. They are doing this with ChatGPT, Gemini, or consumer-grade Claude.
None of it has been approved. None of it is visible. None of it is governed.
This is shadow AI: artificial intelligence tools used inside your practice without the knowledge, oversight, or approval of your IT or compliance function. Unlike shadow IT of the past, shadow AI does not just store data, it processes and transforms it, submits it to external servers, and in the case of free consumer tools, may incorporate it into training datasets accessible to others.
For financial services firms, this creates a compliance exposure that most practices have not yet mapped. It is not a future risk. It is happening now, inside your business, and your regulators have noticed.
- FREE GUIDE -
AI Governance Checklist for Australian Businesses
Not sure if your organisation's AI use is putting sensitive data, compliance obligations, or client trust at risk?
Download our free AI Governance Checklist and assess your readiness across governance, data protection, staff behaviour, compliance, and incident response. Score your organisation in minutes and identify the gaps that need attention.
✅ 30 practical assessment questions
✅ Board and leadership team friendly
✅ Identify Shadow AI and compliance risks
✅ Instant self-assessment scoring framework
What ASIC said in May 2026, and what it means for your practice
On 8 May 2026, ASIC issued an open letter to AFS licensees and market participants on AI and cyber risk. ASIC’s core observation was direct: frontier AI is changing the cyber threat environment by increasing the capability, speed, and accessibility of sophisticated attacks. Existing controls will be tested more often, at greater speed, and under greater pressure.
ASIC expressly directed boards and risk governance committees to table and discuss the letter. This is not guidance that sits with your IT team. ASIC has placed AI risk governance at board level.
The regulatory framework that catches shadow AI for AFSL holders already exists. Under section 912A(1) of the Corporations Act 2001 (Cth), every AFS licensee must:
- Ensure financial services are provided efficiently, honestly and fairly (s912A(1)(a))
- Maintain adequate risk management systems (s912A(1)(h))
- Have adequate human, technological, and financial resources to carry on the financial services business (s912A(1)(d))
- Ensure representatives comply with financial services laws (s912A(1)(ca))
When an adviser at your practice uses an ungoverned AI tool to draft a Statement of Advice, or when an accountant uploads a client’s financial data to a consumer AI platform, each of these obligations is potentially engaged. The tool is not approved. The data handling is not visible. The risk management system does not cover it.
ASIC’s Regulatory Guide 104 (RG 104: Licensing, Meeting the general obligations) is the detailed guidance on what adequate risk management systems look like. RG 104 makes clear that systems must be reviewed regularly and must address new and emerging sources of risk. AI adoption by staff is precisely that.
What APRA said in April 2026, and why it applies beyond banks
On 30 April 2026, APRA issued formal guidance on AI governance to all banks, insurers, and superannuation trustees under its regulation. APRA’s observation was that AI adoption is accelerating across the sector while governance, risk management, assurance, and operational resilience practices are not keeping pace.
APRA identified four specific concerns: board technical literacy gaps, over-reliance on vendor summaries, third-party dependencies that are not adequately assessed, and weak assurance over AI-related risk. Every one of these applies to financial planning practices and accounting firms, regardless of whether they are APRA-regulated directly.
For firms subject to CPS 234, the information security standard, the APRA guidance reinforces an existing obligation: your information security capability must extend to any service or system that handles your data, including AI tools your staff introduce without IT approval.
For firms not directly regulated by APRA, the guidance still matters. ASIC takes APRA’s risk management frameworks as a reference point. And when a regulatory incident occurs, the question asked is always the same: what reasonable steps did the licensee take?
The RI Advice precedent, and why it is still the benchmark
The Federal Court’s 2022 decision in ASIC v RI Advice Group Pty Ltd [2022] FCA 496 established a clear principle: cyber risk management is not optional for AFS licensees, and failing to take reasonable steps to manage it is a breach of licence obligations.
What made the RI Advice decision significant was the breadth of the court’s reasoning. The court did not require ASIC to prove that a specific harm occurred as a result of inadequate cyber controls. The inadequacy of the controls was itself a breach. The failure to have adequate policies, systems, and resources to manage cyber resilience was the contravention.
Apply that reasoning to shadow AI. If staff in your practice are using AI tools that:
- your compliance function does not know about,
- your risk management system does not address,
- your IT team cannot detect, and
- your policies do not govern,
then the RI Advice framework raises the same question about your practice that it raised about RI Advice’s cyber controls: did you take reasonable steps? The answer, without any visibility or governance, is difficult to make.
You do not need to wait for a client complaint or a regulatory inquiry to find out your governance is inadequate. The absence of controls is itself the exposure.
Five shadow AI risks specific to financial services practices
The risks that shadow AI creates in a financial planning practice or accounting firm are distinct from those in other industries. The data is more sensitive, the regulatory obligations are more specific, and the consequences of a disclosure are more immediate.
1. Client financial data in consumer AI tools
Consumer-grade AI tools, free or personal ChatGPT, Gemini, and Claude accounts, do not provide the data protections of enterprise tiers. Prompts and content submitted to these tools may be used to train the model. For a financial planner who pastes a client’s portfolio summary into ChatGPT to draft advice, or an accountant who uploads a tax return to extract figures, this is a direct exposure under the Australian Privacy Principles. The data is personal information. It has been submitted to a third party without the client’s knowledge or consent. The notifiable data breach provisions may apply if the firm cannot demonstrate controls were in place.
2. AI-drafted Statements of Advice with no audit trail
An adviser who uses an ungoverned AI tool to draft or edit a Statement of Advice creates a record that cannot be audited. If a client complaint is later made about that advice, the firm cannot produce the AI inputs or outputs. It cannot demonstrate what data was used, what the tool generated, or whether the output was reviewed appropriately. ASIC’s expectations around advice quality, record-keeping, and the basis for recommendations cannot be met if the tools used to produce the advice are invisible to the practice.
3. AML/CTF document processing through unmanaged AI
Since 1 July 2026, accounting practices providing designated services are required to conduct customer due diligence, maintain records, and report to AUSTRAC. Staff who use AI tools to process identity documents, summarise CDD records, or draft Suspicious Matter Reports are introducing those documents into uncontrolled AI environments. The AML/CTF Rules 2025 require that records be maintained securely and be retrievable for audit. AI-assisted processing through consumer tools does not meet that standard.
4. No visibility means no evidence of reasonable steps
When ASIC or AUSTRAC investigates a financial services firm, they ask what controls were in place. A practice that cannot produce documentation of its AI governance, which tools are approved, which are blocked, what data protections apply, what staff training occurred, cannot demonstrate that reasonable steps were taken. The absence of evidence becomes evidence of absence. Without governance, you are not in a position to defend your practice, regardless of whether a specific harm occurred.
5. Professional indemnity exposure at renewal
PI insurers are asking financial services firms about AI governance at renewal in 2026. The questions are similar to those being asked of law firms: what AI tools are in use, what is approved, how is client data protected, what controls are in place over AI-assisted advice or document preparation? A practice that cannot answer these questions is a practice that presents an elevated risk to the insurer. The consequence may be premium increases, coverage exclusions, or, in the worst case, questions about whether a claim arising from an AI-related incident is covered at all.
What a governed approach actually looks like
Governing shadow AI in a financial services practice does not require banning AI tools or slowing down your team. It requires visibility, policy, and controls, in that order.
Step 1: Visibility - know what is happening
The starting point is detection. A shadow AI governance solution provides real-time visibility into which AI tools are being accessed across your practice, by which staff, and what data is being submitted. Most practices are surprised by the results. The tools being used, the volume of client data being processed, and the frequency of use are typically far higher than leadership expects.
Step 2: Policy - decide what is approved
Once you know what is happening, you can make deliberate decisions. Which AI tools are approved for which use cases? Which are approved with restrictions – no client data, no file uploads? Which are blocked entirely? These decisions need to be documented, communicated to staff, and reviewed regularly. A policy that exists only in a compliance manual is not a control.
Step 3: Controls - enforce what you have decided
Browser-level controls can enforce your policy in real time. They can allow specific AI tools, restrict file uploads or paste operations within those tools, block unapproved tools entirely, and log all activity to an audit trail. For financial services firms, this produces the evidence base that ASIC, APRA, AUSTRAC, and PI insurers can ask to see: documented, timestamped, and demonstrating that controls were in place and operating.
Step 4: Reporting - demonstrate it to the right people
Board-level and principal-level reporting on AI governance is not optional when ASIC has directed boards to table the issue. A monthly summary of AI tool usage, policy exceptions, blocked events, and data protection status translates your technical controls into the language of governance. It is the evidence that your risk management system is operating, not just documented.
How KMTech's Shadow AI Governance service addresses each risk
KMTech’s Shadow AI Governance service is delivered as a managed service – ongoing, not a one-time project. For financial services practices, it provides:
- Real-time detection of all AI tools being accessed across your practice, including browser-based tools that endpoint and network controls cannot see
- Browser-level controls that enforce your approved tool list, block file uploads to unapproved tools, and prevent client data from being submitted to consumer AI platforms
- A continuous audit trail of AI tool usage – who accessed what, when, and what data category was involved – that is available on demand for ASIC, AUSTRAC, or PI insurer requests
- Monthly governance reports in plain language for principals and boards – not technical dashboards, but the evidence of control your licence obligations require
- Staff awareness communications aligned to your AI acceptable use policy – so the policy exists in practice, not just on paper
We are not an AML compliance adviser, a financial services lawyer, or an AFSL compliance consultant. We are a cyber-first managed IT and security provider. Our role is the technology controls that sit underneath your compliance obligations – the systems and governance capability that ASIC and APRA are asking regulated firms to demonstrate.
Frequently Asked Questions
Does ASIC’s guidance on AI apply to financial planning practices and accounting firms?
Yes. ASIC’s May 2026 open letter was addressed to AFS licensees and market participants, which includes financial planning practices holding an AFSL. For accounting firms, the ASIC guidance applies to those that provide designated financial services. The underlying licence obligations — efficient, honest and fair provision of services; adequate risk management systems; adequate resources — are not new. AI governance is a new source of risk that existing obligations now require you to address.
What counts as reasonable steps for AI governance under ASIC’s framework?
ASIC has not published a specific checklist for AI governance, but the RI Advice decision and ASIC’s RG 104 guidance give a clear framework: you need policies that address the risk, systems that enforce those policies, staff who are aware of their obligations, and evidence that the controls were operating. For AI specifically: a documented acceptable use policy for AI tools, detection and control capability over which tools staff access, data protection measures that prevent client data reaching unapproved tools, and periodic reporting on compliance with that policy.
Can financial planners use AI tools to draft Statements of Advice?
AI tools can be used in the advice preparation process, but not without governance. The obligation to ensure the advice is appropriate, based on the client’s circumstances, and properly documented remains entirely with the licensee. Consumer-grade AI tools are not appropriate for this purpose — they do not provide the data protections required for client financial information, and they do not produce an auditable record. Enterprise-tier tools, deployed with appropriate data governance and reviewed by the adviser, can be part of a governed process. The key is that the tool is approved, the data handling is controlled, and the output is reviewed and owned by a qualified adviser.
Does the Privacy Act apply to AI tool use in a financial services practice?
Yes. Financial services firms that are APP entities under the Privacy Act 1988 (Cth) are required to take reasonable steps to protect personal information they hold, including from unauthorised disclosure. Submitting client personal information to a consumer AI tool that does not provide adequate data protections and may use the content for model training is a potential breach of Australian Privacy Principle 11. If the breach involves personal information that could cause serious harm, it may trigger notification obligations under the Notifiable Data Breaches scheme.
How quickly can shadow AI governance controls be deployed?
KMTech’s Shadow AI Governance service can provide real-time visibility into your practice’s AI tool usage and deploy browser-level controls within one week. There is no software installation required on client devices, and no access to your systems. The controls operate at the browser level. Most practices have their governance baseline in place within five to seven business days of engaging.
Related Articles
Explore our complete range of Shadow AI articles for financial services and other businesses
Insights & Resources
- PI Insurance and AI for Financial Services Firms
- Shadow AI and ASIC Obligations
- APRA CPS 234 and Shadow AI What Boards or Directors of Financial Institutions Need to Demonstrate
- AI Governance for Financial Planners
- The evolution of web filtering and shadow AI
- What Is Shadow AI? Shadow AI Governance and Security Risks
- Directors' Duties for Australian Legal Businesses
Shadow AI & AI Governance Protection
For executives and technical leaders who need visibility and control
Your workforce is already using AI tools. The question is whether you can see it, govern it, and prevent data leakage.
If you're concerned about Shadow AI risk, AI governance gaps, or enabling AI safely without blocking innovation, we'll show you exactly what's happening in your organisation and how to protect it.
Request a demo to view real‑time visibility, protection, and governance controls
Request a Demo Today
About the author
Bradley Kaine is the CEO and Co-Founder of Kaine Mathrick Tech (KMTech), a Melbourne-based cyber-first managed IT and security provider. KMTech works with financial services firms, law practices, and professional services organisations across Australia, providing managed IT, managed security, and compliance-ready technology infrastructure. KMTech holds ISO 27001, ISO 9001, and ISO 45001 certifications and is a consecutive MSP 501 global ranking recipient.
kmtech.com.au | 1300 174 389 | info@kmtech.com.au





