As generative artificial intelligence (AI) continues to be adopted at exponential rates, the key question for directors, senior business leaders and legal teams is no longer whether we should adopt it, but rather, how do we ethically and strategically implement and use it?
In this alert, we set out the current regulatory landscape, key ethical and governance obligations, possible risk assessment tools and key takeaways for directors, senior business leaders and the legal teams that support them.
AI: A rapidly evolving landscape
Many businesses are grappling with AI and how to use it in a way that realises its benefits while mitigating associated risks.
As reported in our recent Directions report which was published earlier this month, implementing and extracting value from AI has emerged as a clear top priority for Australian business, with an overwhelming 70.8% of directors and senior business leaders surveyed describing their organisation’s strategic ambition for AI as a productivity opportunity and/or enabler of growth (up from 56.8% in 2025). While nearly half of surveyed organisations report tangible productivity improvements from AI adoption, a significant proportion remain in early implementation stages, highlighting the ongoing gap between strategic ambition and realisation. More information about what is ‘top of mind’ for Australian directors and senior business leaders is available here.
For directors and senior management, this means ensuring appropriate oversight and governance frameworks are in place, including in respect of their own use of AI (e.g. reviewing board papers, note-taking and minutes at board meetings).
Meanwhile, for legal teams, it also means advising on compliance and managing the practical risks of AI use in legal work and being cognisant of how their (or their external advisers’) legal advice may be subsequently used internally through AI tools. Recent research by the Victorian Legal Services Board + Commissioner from a survey of Victorian lawyers has revealed that:
- 36.7% of survey respondents are using AI tools, with over half of these using them daily or weekly;
- AI use was most common among those aged under 30 (48.7%) and use generally decreased with age and years of practice; and
- the most common uses were in the areas of information-gathering, drafting and administration, rather than court documents or decision-making, with 71.3% agreeing that enhanced efficiency and productivity is a major benefit.[1]
At the same time, the regulatory environment has had to evolve quickly to match the accelerated pace of AI adoption. Law societies, federal and state courts and overseas jurisdictions have published practice notes and guidelines. For directors, this evolving landscape creates governance obligations to ensure their organisations keep pace with regulatory expectations. For legal teams, it requires staying current with professional obligations and advising clients accordingly.
In early 2024, we considered the ethical obligations of lawyers as generative AI emerged here. Since then, courts have increasingly considered AI misuse in connection with court documentation and proceedings, in breach of ethical obligations by solicitors and barristers.
Common themes which have emerged in recent practice notes, guidelines and court decisions include:
- all AI outputs must be verified by a human and all facts, citations and legal authorities must be confirmed as existing, accurate and supporting of propositions stated;
- legal teams must carefully consider their use of AI in light of their confidentiality obligations, legal professional privilege and implied undertakings (if any), and, in the process, draw a clear distinction between public or unsecured AI tools and closed systems; and
- particular care must be taken in respect of expert witnesses and evidence, affidavits etc., which may be subject to absolute prohibitions on AI use.
Equally, commercial teams, business leaders, company secretaries and directors need to be aware of potential loss of legal professional privilege (and associated confidentiality considerations) when using AI in relation to legal advice received either from in-house teams or external legal advisers. In the case of United States v Heppner, a former CEO used Claude, a consumer AI tool (without any suggestion or direction from his legal counsel to do so), to:
- draft legal defence strategies;
- analyse legal arguments; and
- synthesise information.
In doing so, the CEO also inputted into Claude information that he had learned from his lawyers and subsequently shared some of the AI outputs with his lawyers. The US District Judge Jed S. Rakoff ruled that the CEO had waived all claims to legal privilege and that even if the AI documents were prepared “in anticipation of litigation,” they were neither “prepared by or at the behest of counsel” nor reflective of counsel’s strategy.[2]
Ethical and governance obligations
Duties in relation to AI
Both directors and lawyers have duties that are enlivened by AI adoption and use.
For directors, the Corporations Act 2001 (Cth) requires them to exercise their powers and discharge their duties with care and diligence,[3] in good faith and for a proper purpose[4] and not to improperly use their position[5] or information.[6] Where AI is deployed within an organisation, directors must ensure appropriate oversight, risk management and governance frameworks are in place.
Meanwhile, lawyers have specific ethical obligations including to act competently and in the best interests of their clients, not disclose client confidential information and not mislead the court.[7]
There are significant consequences for AI misuse
It is important that lawyers and directors exercise informed human judgement when using AI.[8] The consequences of AI hallucinations and misuse (including a lack of human judgement or validation) are already materialising for both lawyers and directors.
Over the past year, Australian courts have imposed costs orders, issued formal warnings and made referrals to professional regulatory bodies.
Recent UK decisions also highlight that misuse of AI can lead to significant consequences, where lawyers are subject to similar ethical duties of not misleading the court, competency and confidentiality. In serious cases, the UK courts have considered that misuse of AI may also amount to contempt of court or indeed criminal prosecution for perverting the course of justice.
Last year in R (Ayinde) v London Borough of Haringey and Al-Haroun v Qatar National Bank QPSC [2025] EWHC 1383 (Admin) (Ayinde), the Court considered the conduct of several lawyers where a barrister submitted grounds for judicial review containing five case citations that did not exist. When opposing counsel queried the five citations, the barrister and instructing solicitors responded without clarifying those citations. The partner and senior associate were referred to the Solicitors Regulation Authority; the barrister’s conduct was considered to meet the threshold for contempt of court but, in the circumstances, was referred to the Bar Standards Board.
As observed by the Court in that case:
"Artificial intelligence is a powerful technology. It can be a useful tool in litigation... Its use must take place with an appropriate degree of oversight, and within a regulatory framework that ensures compliance with well-established professional and ethical standards if public confidence in the administration of justice is to be maintained."[9]
Earlier this year, the approach in Ayinde was confirmed in Cork & Ors v Smith [2026] EWHC 1199 (Ch), where in a routine insolvency application, a letter from Pinsent Masons set out what appeared to be a quote from the Insolvency Rules. The Court was unable to locate the relevant Rule, asked Pinsent Masons for clarification and a second letter stated that the wording was “not intended as a direct quotation” but was a “summary conclusion” drawn from another rule. Witness statements disclosed that a pilot AI program had been used by a junior lawyer in the preparation of both letters to the Court, with neither the senior associate nor the partner responsible being aware of either the use of AI or the hallucinations.
Since false material had been put before the Court on two occasions and “[a]ll three lawyers should have been aware of the dangers of using AI to conduct legal research”,[10] the Court found that there was at the very least a prima facie breach of the duty not to mislead the Court and the duty not to waste Court time.
In mitigation, Pinsent Masons had self-referred to the SRA, agreed to pay the additional costs of its former clients and was reviewing its AI policies and safeguards.
The Court concluded that publication of the judgment alone was insufficient and the firm, the partner and the senior associate were referred to the SRA. In doing so, the Court emphasised that “legal professionals bear ultimate responsibility for their work and cannot outsource the process of legal research or of legal reasoning to an AI. It is a tool to be used with caution. AI has the potential to be wholly unreliable. AI may of course provide a jumping-off point for research and legal reasoning but it does not, at least at present, do away with the need for proper research and thought on the part of a legal professional, even a very junior legal professional”.[11]
But there are also serious consequences for not using AI
However, not using AI can also lead to significant consequences, both commercially and in terms of lawyers’ ethical duties. For directors, this may also engage questions of whether they have discharged their duty of care by failing to consider AI tools that could materially improve organisational efficiency or risk management.
On a practical level, directors and legal teams should expect that in contract negotiations, a counterparty may be using AI to mark up and review the relevant agreement (and any publicly available existing agreements, such as template standard terms on company websites). This awareness may assist in identifying and explaining inconsistencies in amendments or arguments (e.g. if liability provisions have been “transposed” by AI from another jurisdiction and do not work in the relevant agreement).
Courts are also proactively testing how AI can be used to cut down case costs – a recent example of this being when Justice Michael Lee in the Federal Court issued orders last month requiring McDonald’s and the Shop, Distributive and Allied Employees Association to explore with technology experts how they could use AI to prepare for mediation and a 10-week trial over alleged underpayments listed for 2028.[12]
Regarding a positive duty to consider or use AI, the UK Jurisdiction Taskforce’s (UKJT) recent Legal Statement on Liability for AI Harms concluded that professionals can be liable for failing to use AI if “a reasonable professional of a comparable rank/specialism” would have used it in the same situation. This will inevitably turn on professional bodies’ regulations and guidance (if any) and on expert evidence as to the actions of competent professionals in the field. While the statement focuses on professionals, its reasoning has implications for directors: a board that fails to consider AI tools that are widely adopted by comparable organisations may face scrutiny under the duty of care. Examples given by the UKJT include:
- a radiologist failing to use an AI system that is extremely effective at identifying cancerous tumours and could have been procured at reasonable cost;
- an auditor failing to use an AI system to help detect anomalies and fraud in a business that involves a very large number of similar individual transactions, where individual human review would be impossible in practical terms; and
- a solicitor in the Business and Property Courts failing to advise their client that it may wish to consider some form of AI-assisted tool to review large volumes of documents.
Following the UK decisions noted above, in May this year the UK Bar Standards Board issued guidance on the use of AI and other technologies, which affirmed that lawyers should maintain a sufficient level of competence in technology and AI to understand how these may impact their practice. The guidance encourages a “risk-based” approach to technology adoption and use, considering three factors (and their interaction) to identify the level of risk: the application, use and type of technology. Potential levels of risk for each factor are set out in a risk matrix in the guidance as follows:[13]
Corporations Act 2001 (Cth) s 180.
Ibid s 181.
Ibid s 182.
Ibid s 183.
More information about the interplay between these ethical obligations and AI is available here: Navigating Generative AI & Legal Ethics.
This was recently confirmed in the Star Entertainment judgment which we have written about elsewhere: ASIC proceedings against directors and officers of The Star Entertainment Group.
R (Ayinde) v London Borough of Haringey; Al-Haroun v Qatar National Bank QPSC [2025] EWHC 1383 (Admin) para [4].
Cork v Smith [2026] EWHC 1199 (Ch) para [70].
Ibid para [95].
|
|
Likely low risk
|
Likely medium risk
|
Likely high risk
|
|
Application
|
Administrative uses for improved client experience (e.g. meeting reminders) |
General client work or preliminary research, work with sophisticated clients |
Court submissions, work with vulnerable clients, areas of law likely to correlate with certain protected characteristics or vulnerability |
|
Use
|
Spelling/grammar, minor text edits, certain general administrative tasks |
Legal research |
Text generation, drafting, automated/agentic features |
|
Technology
|
Spelling/grammar tools with sufficient data protection or used on non-sensitive documents |
Legal-specific AI tools, general purpose generative AI tools within secure environment |
Agentic AI, general purpose generative AI tools without adequate data protections |
Key takeaways
For directors, senior management, company secretaries and legal teams grappling with artificial intelligence, it is important to:
- understand the benefits and limitations of AI – while it is not a substitute for professional judgement, it can materially assist with efficiency, decision-making support and (for legal teams) managing legal spend and delivering advice in a more timely and digestible way;
- implement clear, risk-based AI governance policies – for directors, this means ensuring the organisation has appropriate frameworks, oversight mechanisms and accountability structures, while for legal teams, it means distinguishing between levels of AI tools (public, closed or commercial) and categories of information (public, confidential or privileged);
- always verify AI output such that no AI-generated output is ever relied upon or sent without human review by a person with sufficient expertise to identify errors and hallucinations; for directors, this also means building verification requirements into organisational processes;
- appropriately identify where material has been prepared with AI assistance, both internally (for governance and audit purposes) and externally (where required by professional or regulatory obligations); and
- recognise where material (e.g. confidential or subject to legal professional privilege) should not be prepared with AI assistance and/or uploaded into AI tools and what safeguards can be put in place to ensure that this is enforced, e.g. communicating appropriate guardrails through appropriate AI training and/or including clear warnings in documents which should not be uploaded to AI platforms.
At Mallesons, our approach to emerging technologies like generative AI brings together strong governance, market-leading technology and high-quality skill building. We work with directors and legal teams across industries to develop AI governance frameworks, policies and practical guidance.[14]
For further information, please contact a member of the Mallesons team. We are here to steer you and your company through this rapidly evolving landscape to ensure you are well-positioned for the future.
More information about our firm’s approach to artificial intelligence is available here: Innovation at Mallesons (formerly KWM).
