AI and the Best Interests Duty: Where Automation Stops in Mortgage Broking
No Australian law addresses AI use by mortgage brokers. That doesn't mean the question is open — the best interests duty already answers most of it, and a privacy deadline in December closes the rest.
There is no Australian law that tells a mortgage broker how to use artificial intelligence. There is no ASIC guidance on it. The Mortgage and Finance Association of Australia has published a discussion paper, but no regulator has issued a rule, a standard, or an enforcement action that turns on a broker's use of a model.
It would be easy to read that as an open question. It isn't. The obligations that govern a broker's work are drafted to be technology-neutral, which means they applied to AI the moment anyone started using it, without anybody needing to write them again. The question was never whether the rules cover this. It is which existing rule bites first, and where.
This is a working view of that, written from inside the industry rather than about it. It is general commentary, not legal advice, and anyone making decisions on it should get their own.
The absence of new law is the regulatory position
In December 2025 the Australian Government released its National AI Plan. The plan confirmed there will be no standalone AI Act, and that the mandatory guardrails for high-risk AI proposed the year before will not be mandated. The approach instead relies on existing technology-neutral legal frameworks supported by voluntary guidance.
That decision is often reported as a reprieve. It is closer to the opposite. A dedicated AI statute would have told you what compliance looks like. Its absence means the duties you already hold expand to cover conduct nobody drafted them for, and you find out where the edges are through supervision and enforcement rather than through a document.
For a mortgage broker the duty that expands furthest is the best interests duty.
The duty is assessed on process, and proved by records
The best interests duty was inserted into the National Consumer Credit Protection Act by the 2020 Hayne response legislation and commenced on 1 January 2021. ASIC's guidance in Regulatory Guide 273 is unusually direct about how compliance gets tested.
There is no safe harbour. ASIC states that brokers "will need to take all steps necessary" and that the obligations are high-level principles that "do not contain prescriptive steps." What ASIC does say is that "the processes and actions of the mortgage broker are a key consideration when determining whether the best interests duty has been complied with," and — the sentence that matters most here — that "evidence of compliance with the best interests obligations will come predominantly from the broker's records."
Read those two together and the shape of the risk becomes clear. The duty is discharged by a process of reasoning about a particular borrower. It is demonstrated, months or years later, by a written record of that reasoning. The record is not a by-product of compliance. In any review, it is the whole of the evidence.
That is precisely the seam an AI system slides into, because generating a plausible written record is the easiest thing a language model does.
The failure mode ASIC described without mentioning AI
On 22 July 2026, ASIC Commissioner Alan Kirkland addressed the MFAA National Conference on the best interests duty. The speech does not mention artificial intelligence, automation, algorithms or software anywhere in its text. It is worth reading anyway, because one line describes the exact way AI-assisted file notes fail.
Kirkland said: "If the reasons for a recommendation are boilerplate factors that could apply to anyone, then it will be hard to demonstrate that the recommendation was in that customer's best interests."
He also said that "practically all aspects of your work require the application of judgement," and that acting in a customer's best interests "sometimes means giving them advice that may not be what they requested or expected."
I want to be precise about what follows from this, because it is easy to overstate. ASIC has not linked AI to the best interests duty. It has not said a broker cannot use a model to draft a file note. The connection I am drawing is my own reasoning from technology-neutral guidance, not a regulatory expectation anyone has published.
But the reasoning is not difficult. A language model asked to justify a recommendation will produce fluent, well-structured, plausible reasons. Those reasons are generated from the general shape of mortgage recommendations, not from the specific circumstances of the borrower in front of you — unless the specific circumstances actually drove them. Boilerplate that could apply to anyone is not a risk of AI-assisted record-keeping. Absent deliberate design, it is the default output.
A file note that reads well and reflects no actual reasoning is worse than a rough one that does. It looks like compliance while being the opposite, and it will not survive being read closely by someone who is entitled to ask.
What the regulator found when it looked
In October 2024 ASIC published REP 798, its first review of AI adoption by licensees. It examined 23 AFS and credit licensees running 624 AI use cases in production or development. Credit licensees were in scope.
The findings are worth stating plainly. Only 12 of the 23 licensees had policies referencing fairness, bias, discrimination or inclusivity. Only 10 had documented requirements or principles about disclosure to consumers when they were interacting with, or affected by, AI. No licensee had implemented specific contestability arrangements for AI-assisted decisions. Thirty per cent of use cases relied on third-party developed models, and four licensees relied on third-party models entirely.
ASIC's framing of the gap: "some licensees are adopting AI more rapidly than their risk and governance arrangements are being updated to reflect the risks and challenges of AI."
The report is equally clear that existing obligations already apply. Licensees must provide services efficiently, honestly and fairly, and ASIC says they "should consider how their AI use may impact their ability to do so." Directors' duties of care and diligence "extend to the adoption, deployment and use of AI." Outsourcing changes nothing: licensees remain responsible and must choose suitable providers and monitor their performance.
None of that is new law. All of it was already binding.
December 2026 is a real deadline
The one date on the horizon comes from privacy, not credit.
The Privacy and Other Legislation Amendment Act 2024 inserted automated decision-making transparency requirements that commence on 10 December 2026. Where an entity has arranged for a computer program to make, or to do something substantially and directly related to making, a decision that could reasonably be expected to significantly affect an individual's rights or interests, and personal information is used in that program, the entity's privacy policy must disclose the kinds of personal information used and the kinds of decisions involved.
Two features matter for broking. Credit decisions are expressly given as an example of decisions that significantly affect rights or interests. And keeping a human in the loop does not automatically take you outside the obligation — a program that recommends a decision or guides a human decision-maker can be caught where the recommendation is a key factor.
If a system shortlists lenders, scores serviceability, or ranks products in a way that materially shapes what a broker recommends, that is the scenario the provision describes.
Two honest caveats. The OAIC released an issues paper in May 2026 and final guidance is still pending, so the practical detail is not settled. And whether a given broking business is bound by the Privacy Act at all depends on the small business operator exemption and how it applies to a business that discloses client information to lenders — a question worth getting advised on rather than assuming either way.
Where the line actually sits
The MFAA's 2024 discussion paper put it in one sentence: "Don't forget you are the ultimate decision maker."
That is the whole of it, and it is a better articulation than anything in the regulatory material. The duty attaches to the broker. It cannot be delegated to a system, and it cannot be delegated to a vendor. A model can gather information, surface options you would have missed, structure a comparison, and draft around reasoning you have already done. What it cannot do is hold the duty. That split — the system handles the volume, the human holds the decision — is the boundary we've argued for in Knowing When to Hand Off, except here it is not a design choice; it follows from the duty itself.
The practical test I would apply to any AI tool in a broking workflow is this: if a file were pulled tomorrow and the record examined, would the reasoning in it be reasoning that actually happened? If yes, the tool made you faster. If no, the tool manufactured evidence of a process that did not occur — and that is a materially worse position than having no tool at all. It is the broking-specific form of the question that should gate any AI build: what does being wrong cost, and can you catch it?
The regulators have not drawn that line for the industry. On the current trajectory they are not going to. It has to be drawn inside each business, before someone else draws it for them.
Evaluating Language Models for Regulated Work: Accuracy, Auditability, Cost
In finance and professional services you can't ship an AI feature on vibes. Evaluating models for regulated work means measuring accuracy, auditability and cost as one system.
The Integration Layer: Turning Fragmented Systems Into One Intelligence Surface
Most business AI value isn't blocked by the model. It's blocked by data trapped in disconnected systems. The unglamorous integration layer is where intelligence becomes possible.
Prompt to Production: Shipping AI Features Without Breaking Things
A prompt that works in a playground is not a shipped feature. Here's the internal pipeline we use to take AI from a working prompt to something safe to run in production.