Regulatory exposure. Australia still does not possess a single AI Act as the EU has. However, the regulators are not delaying action. The ACCC has laid out its expectations regarding the enforcement of AI. The OAIC regards AI in the same way as any other automated decision system — requiring accountability, transparency, and human oversight.
Whenever your automation tool is making decisions on matters such as credit, employment, access to health services, or customer service, there will be someone keeping an eye on the situation. That person doesn't necessarily need to be monitoring your compliance, but will be looking for complaints. When complaints are received, an investigation is initiated, and such investigations involve a financial cost.
An unmonitored system that violates these principles can attract fines up to AUD $50 million or 10% of turnover (ACCC enforcement), privacy breach notifications (OAIC), reputational harm from media coverage of unfair or biased decisions, and class action lawsuits if the harm affects multiple customers.
Liability arising from biased outcomes. AI systems do not pick up fairness naturally through osmosis; instead, they learn patterns from data. If the data contains historical bias, the system will reinforce that bias. A hiring tool that is trained on past recruitment data will discriminate against candidates from underrepresented groups, and a credit assessment tool based on lending history will disadvantage certain demographics.
You won't realise that this is taking place unless someone makes a complaint or a journalist carries out an investigation.
The Australian courts have now started to take automated bias seriously, with judges asking whether an audit of the tool was carried out, whether tests for bias were conducted, and whether there were any human review processes. If the answer to all three of these questions is no, then the liability falls heavily on the company.
Compliance drift. Laws are constantly changing, your business is constantly changing, and so are customer expectations; your automation tool only adjusts when you instruct it to.
A chatbot which has been trained using the customer service policies of 2023 could provide wrong advice in 2024 should your product terms have changed. An automation tool designed to comply with GDPR requirements might fail to meet the amendments to Australia's Privacy Act. A workflow that was in line with the requirements two years ago might now breach current consumer protection guidelines.
Monitoring involves carrying out scheduled audits — this includes testing the outputs, checking for any drift, and verifying that they remain in line with the current policy. Without it, you have a compliance debt that keeps on growing.