- The risk: Pasting board papers into public AI tools can expose confidential data, waive privilege, or leak papers within the organisation.
- The duty: Corporations Act duties haven't changed, but "informed basis" has. Uncritical AI reliance - or ignoring AI - may breach the duty of care.
- The fix: Leaders are shifting to purpose-built, ring-fenced tools, mandatory training and clear guardrails for trust and accountability.
When Professor Nicholas Davis sits down with leaders to discuss AI use in the boardroom, he finds that even those with an open mind can quickly become defensive.
“As the conversation develops, others at the table often become quite judgemental,” explains the professor of emerging technology and co-director of the Human Technology Institute at the University of Technology Sydney. Someone at the table will inevitably claim they would never use AI to summarise a paper or draft an opinion, he says.
“And then those who’ve admitted [using AI] start to regret it and get defensive, clarifying things like ‘Well, of course I strip out all the confidential information.’”
It’s a dissonance that will be familiar to almost everyone working in corporate Australia in 2026, and it’s a shame, reflects Davis, because these are really important conversations to have honestly and openly.
In reality, across Australian boardrooms, directors are already using tools like Claude and Microsoft Copilot to triage board packs, parse complex financial information and draft questions – often before any formal policy exists.
So the question many board members are asking themselves is: Can you paste a board paper into ChatGPT?
The answer is more complex than a simple yes or no.
What information are you exposing?
Law firms are warning that board papers shared in public tools can expose sensitive information and waive legal privilege. The AICD’s own guidance, developed in partnership with HTI at UTS, instructs directors not to rely on AI-generated summaries or analysis as a substitute for their own review and interrogation of board papers.
Valeska Bloch MAICD is a partner and head of technology, media and telecommunications and cyber at law firm Allens. She says “shadow use” – people using unauthorised AI tools to summarise or parse packs and board papers and formulate their own responses – is the single most common mistake she sees directors make with AI.
She warns that pasting board papers into public consumer AI tools can expose personal data, waive legal privilege and undermine confidentiality, with no control over where that information might surface again.
“If it includes confidential or commercially sensitive information, there are risks there,” she says.
But one of the big challenges for directors can be that they are not always given an enterprise-level licence by the organisation, or specific guidance on how and where they can and should use AI in their preparation and decision-making. As Bloch highlights, personal-use products are far less secure than enterprise environments and licences.
Importantly, she says that even inside an enterprise AI environment, you need special protocols and firewalls.
“Unless you have appropriate guardrails in place, you might unintentionally be feeding confidential board papers into an AI system that makes them accessible to people inside the organisation,” she explains.
Security risk
Pasting board papers directly into public or enterprise AI tools leaks private data outside corporate boundaries. Those risks are one reason some boards have chosen not to let shadow AI use evolve organically. At Telstra, for example, directors didn’t use AI in their work until the company built a dedicated, secure Board AI agent.
“Our board members didn’t use AI in their work for Telstra until we developed a trusted, purpose-built AI tool to give them a faster way to find and connect information,” says the telco’s group company secretary and general counsel Craig Emery.
Telstra launched its Board AI agent this year to securely support its directors as they prepare for board and committee meetings. It was specifically designed not to tell them how to think, as erosion of judgement is also a persistent concern as organisations adopt more sophisticated AI tools.
“The result is better access to information and more time spent applying judgement and experience,” explains Emery.
Telstra has put clear guardrails around how the agent is used. All directors completed the company’s Responsible AI training before gaining access, which includes guidance on how to critically evaluate AI outputs rather than accepting them at face value.
Start with strategy, not the technology
Many organisations treat an enterprise licence for Copilot or Claude as a de facto AI strategy or blanket approval. People essentially think, “IT has turned it on, so it must be fine to use.”
But as Davis explains, there is a big difference between procurement of a tool and strategy. “The conversation needs to move beyond ‘Which AI do we use?’ to ‘Why and where do we use AI to further our business objectives?’ and importantly, ‘Where do we deliberately choose not to use it?’”
Emery stresses that at Telstra, technology doesn’t change where responsibility sits. “Technology can support better decisions, but accountability remains with people,” he says. “Directors still apply the judgement, challenge and experience that good governance relies on.”
Bloch says that’s the right approach. The matter is actually simpler than it can feel. “Directors remain subject to the same duties under the Corporations Act and under case law,” she says. “So their duties haven’t changed. There’s still an expectation that they’ll bring an independent, active mind to all decision-making.”
Act on an ‘informed basis’
What has changed, she says, is what an “informed basis” looks like – and the exposure runs both ways.
“If you’re just adopting the recommendation of an AI tool without applying your own judgement, you may not be acting with reasonable care,” she says. “But equally, the duty to act on an informed basis doesn’t stand still, and so if AI can materially improve the quality of data analysis that’s available to directors, then that duty to act on an informed basis may evolve to require its use in certain situations.”
In other words, a director who refuses to engage with these tools at all may end up as exposed as one who leans on them uncritically. What AI cannot do is discharge the obligation itself. It can help a director process the information; it cannot understand, interrogate and evaluate it for them.
For boards still working out their approach, Emery suggests three guardrails: Create trusted environments where people can use AI confidently and securely; ensure transparency, so directors can understand where information comes from and validate it; and keep accountability and judgement firmly with people.
“Technology will continue to evolve quickly,” he says, “but those principles are enduring.”
Latest news
Already a member?
Login to view this content