ASIC v Bekier: What the Federal Court's AI Ruling Means for Directors and Company Secretaries
The Federal Court's ASIC v Bekier ruling draws a clear line on AI in the boardroom. Here's what directors and company secretaries managing entity portfolios need to know — and do — right now.
ASIC v Bekier: What the Federal Court's AI Ruling Means for Directors and Company Secretaries
ASIC v Bekier: What the Federal Court's AI Ruling Means for Directors and Company Secretaries
The Federal Court just handed down the most important corporate governance ruling of 2026 — and buried inside the 200+ page judgment is something every director and company secretary needs to read. Justice Lee, in ASIC v Bekier [2026] FCA 196, didn't just rule on casino governance failures. He drew a line in the sand on how AI can — and can't — be used in the boardroom.
If you're managing entity portfolios, overseeing compliance, or sitting on a board, this ruling changes how you think about technology in governance. Here's what happened, what it means, and what you need to do about it.
The Star Entertainment Case: A Quick Recap
ASIC brought civil penalty proceedings against former directors and senior executives of The Star Entertainment Group. The core allegation: governance failures related to Anti Money Laundering and Counter Terrorism Financing (AML/CTF) risks.
Former CEO Matthias Bekier and former General Counsel Paula Martin were found to have breached their duties under section 180(1) of the Corporations Act 2001. They failed to escalate serious AML/CTF risks to the board. They failed to inform directors about law enforcement interest and suspicious conduct.
The seven non executive directors? Their claims were dismissed. The Court drew a clear distinction between failures of management and failures of oversight. Non executive directors were entitled to rely on management to escalate material risks — which, in this case, management failed to do.
The penalty hearing for Bekier and Martin is scheduled for May 27, 2026.
But the headline grabbing governance breach isn't the part that should keep you up at night. It's what Justice Lee said about artificial intelligence.
AI in the Boardroom: A Tool, Not a Replacement
Here's the critical passage from the judgment. Justice Lee acknowledged that AI can serve as a "valuable tool" for directors managing what he called the "heroically vast" volume of board materials. AI can help directors control, process, and analyse information — potentially assisting them in discharging their duty of care and diligence under section 180(1).
But — and this is the part every director needs to internalise — AI cannot replace a director's personal and non delegable duty to exercise informed independent human judgment.
Let me translate that into plain English: You can use AI to help you read faster, spot patterns, and surface risks. You cannot outsource your thinking to it.
The Court explicitly warned that inadequately deployed or misdirected AI could actually increase a director's legal exposure. Using AI without proper governance frameworks isn't just risky — it could be the thing that gets you personally liable.
Why This Matters for Company Secretaries and Compliance Teams
If you're a company secretary managing 50, 100, or 200+ entities, this ruling creates both an opportunity and a mandate.
Justice Lee effectively endorsed the use of AI in governance workflows. This isn't a Luddite ruling. The Court recognises that modern directors face information volumes that are genuinely unmanageable without technology. AI that helps you:
Surface compliance gaps across entity portfolios Track director appointment deadlines and ASIC lodgement dates Reconcile registry data against your internal records Flag overdue annual reviews or missing resolutions
...is exactly what the Court says directors should be using to discharge their duties. The ruling validates technology assisted governance — provided it's done properly.
Here's where it gets sharp. The Court also said that companies need "robust governance frameworks, including formal policies, around the use of AI in the boardroom." That means:
1. Formal AI use policies — You need a documented policy that defines how AI is used in governance and compliance workflows. What tools are approved? What data goes into them? Who reviews the outputs?
2. Transparency requirements — Directors need to know when AI is being used to generate or summarise information they're relying on. No shadow IT. No undisclosed AI summaries feeding into board packs.
3. Data confidentiality protocols — Board materials are sensitive. Entity structures, beneficial ownership data, compliance findings — none of this should be flowing through consumer grade AI tools without proper data handling agreements.
4. Human review as non negotiable — Every AI output needs a human in the loop. AI can surface the risk. A human must decide what to do about it.
Justice Lee was explicit: "Shadow IT" or informal AI use is unlikely to satisfy a director's duty of care. If your team is using ChatGPT to summarise board papers and nobody has a policy around it, you've got a problem.
One of the most significant aspects of this ruling is what it does to the "I didn't know" defence.
Justice Lee stated that directors cannot rely on the volume of information as an excuse for disengagement. Boards must control the information they receive, and directors are expected to take a "diligent and intelligent interest" in available information.
Combine that with the AI endorsement, and the Court is essentially saying: The tools exist to help you manage information overload. If you don't use them, that's on you.
For company secretaries preparing board packs, this changes the game. You need systems that:
Prioritise and flag critical compliance issues, not just dump 300 pages on directors Provide clear audit trails showing what information was presented and when Enable directors to drill into entity level compliance status without manual effort Track acknowledgment and follow up on flagged risks
Manual spreadsheets and shared drives don't cut it anymore. Not because they're old fashioned — because they can't provide the transparency and audit trail that the Court now expects.
The Escalation Duty: What Management Owes the Board
The Bekier ruling also reinforced something critical about information flow in multi entity structures.
The non executive directors were cleared because management failed to escalate material risks. The Court held that NEDs were entitled to rely on management to surface critical issues. When management didn't, the failure sat with management — not the board.
But here's the catch: this protection only works if your governance infrastructure actually enables proper escalation. If a compliance issue is sitting in a spreadsheet that nobody checks, or buried in an email thread from six months ago, the "management didn't tell us" defence starts to look thin.
For organisations managing complex entity portfolios, this means:
Centralised risk registers that connect to entity level compliance data Automated escalation triggers when compliance thresholds are breached Clear ownership of who is responsible for monitoring and escalating at each level Audit trails that prove what was flagged, when, and to whom
The Bekier ruling doesn't exist in a vacuum. ASIC's 2026 enforcement priorities signal an escalation in governance enforcement across the board:
Financial reporting failures are a key target. ASIC is using surveillance data to identify entities that haven't lodged annual or half year reports. If your entity portfolio includes subsidiaries with overdue lodgements, expect scrutiny.
Director and officer requirements are being strictly enforced — including maintaining the required number of directors (and local directors) and having a company secretary in place.