Brad Ferris.au
The Director's LensEdition 22 · AI Regulation

The Submission Your Board Never Saw

Submissions to the Reserve Bank's payments review have split the Australian industry over whether AI agents that transact for a customer should be regulated now, with CBA, Westpac and ANZ on one side and NAB, Visa, American Express and Apple on the other. The split is a map of where the loss lands when an agent gets it wrong, and your own company's position on that map was lodged without the board ever reading it.

Published6 September 2026
Read6 minutes
All editions
The Governance Story

On 1 September, Capital Brief reported that submissions to the Reserve Bank's Review of Payments System Regulation have split the Australian payments industry over whether AI agents that transact on a customer's behalf should be regulated now. Commonwealth Bank, Westpac and ANZ argued yes. NAB, Visa, American Express, Apple and the technology lobby groups argued it is premature. Stripe's submission was reported as describing intervention as inevitable. The obvious reading is that regulation is coming for agentic payments and boards should get ready for it. The more useful reading sits in who lined up where, and in a short list of dates published on the Reserve Bank's own website.

Those dates are worth writing down. The RBA released its Issues Paper on 25 June, submissions closed on 7 August, non-confidential submissions were to be published by the end of August, regulatory priorities are due by the end of this year, consultation on those priorities begins by mid-2027, and the review reaches its conclusions in 2028. The Issues Paper itself does not mention artificial intelligence. The industry put agentic payments into a review that was never framed around them, which tells you how urgently the people closest to it are treating the question. It also tells you the timetable was not built for this. Agents that move money will be operating in the Australian market long before 2028, under rules written for a world in which a person pressed the button.

Now look at the split again, because it is not a disagreement about whether agents are risky. Everybody in that room agrees they are. It is a disagreement about where the loss sits when an agent transacts wrongly. The banks sit at the end of the chargeback chain and carry the customer relationship when something goes wrong. The schemes and the platforms set rules, take a fee, and sit further from the loss. Read the alignment that way and it stops being a policy debate and becomes a map of who currently absorbs the cost of a mistake and who would prefer that moved. Your own organisation has a position on that map, and it is now a public document.

That is the governance point, and it has very little to do with payments. Somewhere in your company, a person drafted a submission to a regulator setting out what this organisation wants the liability model for agent-initiated transactions to be. It was probably written by a policy or government affairs team, cleared by an executive, and lodged. In substance it is a strategy paper: it argues for a future operating environment that suits this business model rather than a competitor's, and if the regulator adopts it, the company lives inside that answer for a decade. In most organisations it never went near the board. Directors set direction and management executes within it. A document that asks a regulator to allocate a decade of liability is direction, and it was signed out under a delegation nobody examined.

Questions I'd Ask in the Boardroom
  • Did this company lodge a submission to the RBA's payments review, what did it ask for on agents that transact for a customer, and which director read it before it went?
  • If nothing binding arrives until 2028, what is our own rule for agent-initiated payments between now and then, who wrote it, and when does it take effect?
  • When an agent acting for a customer initiates a payment the customer did not intend, who carries that loss today under our contracts and the scheme rules, and can anyone answer that without taking it on notice?
  • Which of our competitors argued the opposite of what we argued, and what does their position tell us about where they believe the loss should sit?
  • If a customer disputes a transaction their own agent made, does our process treat it as authorised, unauthorised, or as a question nobody has yet decided?
  • Which other submissions, standards responses or consultation papers have gone out in this company's name in the last twelve months, and how many of them did this board see?
Red Flags & Watch Points
  • Regulatory submissions are reported to the board as an activity count rather than tabled as positions the organisation has formally taken in public.
  • Nobody can say whether a payment initiated by a customer's agent is authorised or unauthorised under our current terms, and the question has never been put to legal in writing.
  • The agent product roadmap sits with one team and the regulatory submission sits with another, and the two documents have never been read side by side by anyone.
  • The risk appetite statement covers fraud and cyber but is silent on transactions initiated by software acting for a customer rather than by the customer.
  • Management intends to set an internal position once the RBA concludes, and is describing a three-year wait as prudence.
  • The board has never asked what its largest competitors argued in their own submissions, every one of which is a public document.
Opportunity & Risk Balance

The material here is unusually good, and it is free. Non-confidential submissions to the review were due for publication by the end of August, which means the written positions of the banks, the card schemes and the platforms you compete with and depend upon are now public. A board can read what Commonwealth Bank, Westpac and ANZ asked for, read what NAB, Visa, American Express and Apple asked for, and form its own view about which of those futures is better for this company. That is a rare thing in governance: a set of competitors obliged to write down what they want the rules to be. There is a second opportunity in the timetable. Nothing binding lands until 2028, and an organisation that sets a clear internal standard for agent-initiated payments in the meantime is not merely managing an exposure, it is writing the practice a regulator may later describe as reasonable. Standards of care get built out of what careful operators actually did while the law was still catching up.

The failure mode is a board that files this under policy and waits for the Reserve Bank. Waiting carries two costs. The first is that the liability model gets written by the parties who turned up with a position, and this company either turned up with one the board never approved or did not turn up at all. Both of those are governance failures rather than strategy failures, and they are the kind that read badly in hindsight. The second cost is operational and arrives well before 2028. Agents that initiate payments will be live in this market while the review is still consulting, and when a customer disputes a transaction their own agent made, the answer will be settled by contracts and scheme rules drafted for a world in which a human pressed the button. There is no category yet for a payment authorised in general and unintended in particular. A board that has not decided which it is will have that decided for it.

Director's Recommendation
My position

Do three things this quarter. First, ask management to table this company's submission to the RBA payments review at the next board meeting, alongside the published submissions of two competitors who argued the other way, and treat that as a strategy paper rather than a compliance update, because it is one. Second, adopt a standing rule that any submission to a regulator seeking to shape a liability model, a market structure or a standard comes to the board before lodgement, not after; the delegation that let a decade-long position go out unread is the actual defect here, and payments is simply where it became visible. Third, set an interim internal position on agent-initiated transactions now, with a dollar threshold, a named owner, an irreversibility test and a review date, and do not wait for 2028 to have one. Then form a view on the underlying question, which is whether this organisation wants the loss from an agent's mistake to sit with it or with someone else, and say so out loud in the minutes. Four of your competitors have already told the regulator what they think. A board that has not formed the same view is not neutral on the question, it has simply left the answer to whoever wrote the submission.

Researched and drafted by Brad's agentic AI team. Edited and published by Brad Ferris.