Your Company Secretary Is Using AI — Does Your Board Know How It's Being Governed?

AI tools are already in your company secretary's workflow. The real question: does your board have a governance framework around them?

Your Company Secretary Is Using AI — Does Your Board Know How It's Being Governed?

Your Company Secretary Is Using AI — Does Your Board Know How It's Being Governed?

The company secretary is the most governance critical role in your organisation. They maintain the statutory registers, prepare the board minutes, track ASIC obligations, manage resolutions, and ensure the directors have what they need to discharge their duties properly.

They are also, right now, quietly using AI to do it.

Most boards don't know. And almost none have asked the question that matters: what governance framework sits around how our company secretary uses AI?

This isn't a technology story. It's a governance story — and the gap between AI adoption and board oversight is where liability lives.

The Quiet AI Revolution in the Company Secretary's Office

Company secretaries are pragmatic professionals. When a tool saves time without introducing obvious risk, they use it. And AI tools — particularly large language models and AI writing assistants — save significant time on the tasks that consume most of a company secretary's week.

Drafting board minutes from meeting notes takes hours. AI can produce a working draft in minutes from a transcript or bullet point summary. Preparing routine resolutions, notices, and director consent letters — tasks that require precision but follow predictable structures — are natural fits for AI assistance. Researching compliance requirements, summarising regulatory updates, checking disclosure obligations against changing rules: all of this is being done with AI tools in company secretaries' offices right now.

A 2025 survey by the Governance Institute of Australia found that over 60% of company secretaries had used AI tools at least once in the past 12 months for governance related work. More than 30% used AI tools weekly. Fewer than 15% said their organisation had a formal policy governing that use.

The adoption curve has been steep. The governance curve has barely moved.

What AI Tools Company Secretaries Are Actually Using Right Now

The tools in use are not exotic. They are the same consumer and enterprise AI platforms being used across every function in a modern business.

Large language models (ChatGPT, Claude, Gemini) are being used to draft minutes, prepare notices of meeting, generate consent letters, summarise long regulatory documents, and draft agenda items. These are used via web interfaces, often without any enterprise data controls, on documents that include confidential board discussions and personal information about directors and officeholders.

AI writing assistants embedded in Microsoft 365 (Copilot) and Google Workspace are increasingly used directly within document workflows — meaning AI is touching draft resolutions, board packs, and statutory registers inside the document environment itself.

Compliance research tools with AI capabilities are used to track ASIC changes, interpret regulatory updates, and assess compliance obligations for specific entity types.

AI native entity management platforms like EntityFlo have AI built into the governance workflow itself — drafting documents from live entity data, monitoring compliance in real time, and surfacing issues across the portfolio automatically.

The critical difference between the first three categories and the last is governance by design. EntityFlo's AI works within a controlled, auditable environment where every action is logged and the data it uses is structured and verified. Consumer AI tools and generic office assistants operate without those controls — and that's where the governance gap lives.

The Governance Gap — When Your Governance Officer Has No Governance Over Their Own Tools

Here is the core irony: the person responsible for your organisation's governance framework is using technology that your governance framework doesn't cover.

Consider what happens when a company secretary uses an uncontrolled AI tool to draft board minutes. The AI ingests the meeting notes — which contain confidential board deliberations, material non public information, strategic discussions, and personal information about directors. Where does that information go? Who has access to it? Is it being used to train the model? Is it stored offshore? Is it subject to Australian privacy law?

Most company secretaries don't know the answers to those questions. Most boards have never asked them.

The liability exposure is real. Under the Privacy Act 1988, disclosure of personal information to a third party — including an AI model operator — without appropriate consent or contractual protections is a potential breach. Under the Corporations Act, directors have a duty to act in good faith and in the best interests of the company; a director who later discovers that confidential board discussions were exposed to an uncontrolled AI service has a legitimate grievance about how their information was handled.

Then there is the accuracy risk. AI tools hallucinate. They produce plausible sounding text that is factually incorrect, and they do so without flagging uncertainty in a way that non expert reviewers reliably catch. A company secretary under time pressure, reviewing an AI generated board minute against their own imperfect notes, may not catch every error. An incorrect minute — particularly one that misrecords a board decision, a director's disclosed interest, or a resolution that was and wasn't passed — is a governance record with legal consequences.

None of this means AI tools should be banned from company secretarial work. It means the governance framework around those tools needs to exist before the tools do — or, since adoption has already happened, now.

What an AI Governance Policy Needs to Cover for Company Secretarial Work

A functional AI governance policy for the company secretary's function is not a long document. It is a precise one. It needs to answer several specific questions.

Approved tools and data classification rules

Which AI tools are approved for which categories of work? Consumer AI tools (ChatGPT, Claude via web interface) should not be used with confidential board information, personal data of directors and officeholders, or material non public information. Enterprise tools with appropriate data processing agreements may be approved for different categories. AI native governance platforms with purpose built controls are the appropriate environment for AI assisted governance work.

Review requirements and accuracy obligations

Every AI generated governance document — minutes, resolutions, notices — must be reviewed by a qualified person before execution. The policy should specify that the reviewing person takes professional responsibility for the document's accuracy; AI assistance does not transfer liability to the tool.

Where AI tools are used, the audit trail should reflect it. This is not about liability avoidance — it is about transparency. A board pack prepared with AI assistance should be no less reliable than one prepared without it; but the preparation process should be documented.

What happens when an AI tool produces a materially incorrect governance record that wasn't caught in review? The policy needs an incident response pathway: who is notified, how the record is corrected, whether the error needs to be disclosed.

AI tools evolve rapidly. A policy written for the tools available in 2025 will be inadequate by 2027. Build in a mandatory annual review with the company secretary, the risk function, and the board's audit and risk committee.

Board Oversight of AI: The Questions Directors Should Be Asking

Directors don't need to become AI experts. But they do need to ask the right questions — and right now, most boards aren't asking them at all.

"What AI tools does our company secretary currently use in their governance workflow?"

This is the baseline question. Many boards will be surprised by the answer.

"Do we have a policy governing the use of AI in the preparation of our governance records?"

If the answer is no — or "I think so, but I'm not sure" — that gap needs to be closed at the next board meeting.

"What data controls are in place to prevent confidential board information being exposed to uncontrolled AI environments?"