All guides
SecurityBy Jake Carp

AI assistants inherit your permissions, not your information barriers: what a credit fund has to check.

Important takeaways.

  • Section 1043F of the Corporations Act gives a body corporate a defence to the insider trading prohibition in section 1043A(1). It has three limbs. The third is factual: the information was not so communicated and no such advice was so given. Arrangements that could reasonably be expected to work satisfy the second limb, not the third.
  • ASIC reissued Regulatory Guide 181 on 16 December 2025, superseding the version it had run since August 2004. Table 3 of the guide describes an information barrier as a control that prevents or restricts staff from transferring or accessing information, including data. The framing is about access, not only about conversations.
  • Microsoft 365 Copilot is scoped to the signed-in user. Microsoft documents that it only reaches data that user is already permitted to reach, and that it grounds through Microsoft Graph on that user's emails, chats and documents. The assistant is therefore exactly as segregated as the permissions underneath it.
  • Microsoft Purview Information Barriers restricts two-way communication and collaboration in Teams, SharePoint and OneDrive. In SharePoint and OneDrive it prevents a user accessing a site or its content and prevents searching a site. Microsoft states that only two-way restrictions are supported, so a one-way barrier is not available.
  • Microsoft states that information barrier policies cannot restrict communication and collaboration in email messages, including Exchange Online, and points to Exchange mail flow rules instead. In a credit fund the borrower pack usually arrives by email. That makes the mailbox the part of the barrier the product does not hold.
  • A bilateral loan is not itself a Division 3 financial product. Section 1042A(1) lists securities, derivatives, interests in a managed investment scheme, government debentures, stocks and bonds, superannuation products, and other financial products able to be traded on a financial market. The exposure runs through the borrower's traded securities and through the fund's own units.

A credit fund collects information it never asked for. A borrower requests an amendment, hands over next year's forecasts, or opens a quiet conversation about a restructure. When that borrower has shares or bonds on issue, the lending team is now on the private side of a wall.

Most funds have that wall written down. The narrower question is what happens to it the week an AI assistant is switched on across the fund's files and mail. This guide answers for Australia, where both the sections and the regulatory guidance are specific. The mechanism holds wherever the barrier does.

What the barrier protects, and which products it reaches.

The insider trading prohibition does not attach to everything a credit fund holds. It attaches to Division 3 financial products, defined in section 1042A(1) of the Corporations Act 2001. That definition covers securities, derivatives and interests in a managed investment scheme. It also covers government debentures, stocks and bonds, superannuation products, and any other financial products able to be traded on a financial market.

A bilateral loan agreement is not on that list. The borrower's traded shares and bonds are, and so are interests in a managed investment scheme, which is what units in a fund are. So the exposure runs two ways. A private lending relationship informs a view on securities someone else in the firm can trade, and it informs the value of the fund's own units.

Multi-strategy credit platforms run both sides on purpose. A liquid credit sleeve and a direct lending sleeve under one manager is the ordinary case, and it is the arrangement an information barrier exists to make workable.

Section 1043F has a limb that policy cannot satisfy.

Section 1043F is the statutory Chinese wall defence for a body corporate. It provides that the body corporate does not contravene section 1043A(1) merely because of information held by one of its officers or employees, if three things hold. The decision was taken by other people. The body corporate had arrangements in operation that could reasonably be expected to ensure the information was not communicated to the decision makers, and that no advice was given by anyone holding it. And the information was not so communicated and no such advice was so given.

Read the second and third conditions next to each other. The second is about what the fund set up. The third is about what actually happened. A well drafted barrier policy, a restricted list and an annual attestation all speak to the second condition. None of them help once the information has reached the person who decided.

The tipping limb is drawn just as widely. Section 1043A(2) prohibits an insider from communicating inside information, directly or indirectly, or causing it to be communicated, where the relevant products can be traded on a financial market operated in this jurisdiction. Section 1043G puts partnerships in the same position as bodies corporate. A retrieval layer that answers a public-side question with a private-side document is a problem about the third condition, not about the policy.

ASIC already describes the barrier as a control over data.

The licensing obligation behind all of this is the conflicts management obligation in section 912A(1)(aa). ASIC reissued Regulatory Guide 181 on 16 December 2025, superseding the version it had run since August 2004. RG 181.70 lists measures for avoiding a conflict. The first is having information barriers in place, physical or virtual, between business units, to prevent the flow of confidential information.

Table 3 of the same guide is the more useful passage for an IT team. It describes the control as robust information barriers that prevent or restrict staff from transferring or accessing information, including data. Accessing, and including data. The framing was already about what a person can reach rather than only about what they can be told.

RG 181 does not mention artificial intelligence anywhere in its 42 pages. That is the point rather than a gap. The obligation is technology neutral, so the licensee obligations a fund already carries are the ones that apply.

What the tooling enforces, and where it stops.

Most credit funds sit on Microsoft 365, so take that as the worked example. Microsoft documents that Copilot is scoped to the signed-in user and is not given tenant-wide visibility. It grounds through Microsoft Graph on the emails, chats and documents that user has permission to reach. The assistant is therefore exactly as segregated as the permissions underneath it.

Microsoft Purview Information Barriers is the product built for this problem. It restricts two-way communication and collaboration in Teams, SharePoint and OneDrive. In SharePoint and OneDrive it prevents a user accessing a site or its content, prevents sharing, and prevents searching a site. Used properly, that is a technical barrier rather than a written one.

Two documented limits matter to a fund. Microsoft states that only two-way restrictions are supported, so a barrier that blocks one direction and permits the other is not available. Microsoft also states that information barrier policies cannot restrict communication and collaboration in email messages, including Exchange Online, and points to Exchange mail flow rules for that instead.

The second limit lands hard in a credit fund. The compliance certificate, the amendment request and the restructuring draft arrive as email attachments, because that is how counterparties send things. Once private-side material sits in a mailbox the wrong person can open, the barrier product is not the control, and an assistant grounded on that mailbox will find it. Microsoft says the general version of this itself: overshared or poorly governed content affects results and increases risk.

What to check before you clear an assistant.

  • Which side of the wall does each repository sit on, and is that recorded in permissions rather than in a folder name?
  • Does the assistant ground on mail as well as files, and whose mail?
  • Is the restriction applied to every query, or only when the index is built?
  • Does the fund need a one-way barrier, and can the tooling give it one?
  • If a trade is questioned in two years, can you show what the assistant was asked, what it returned and who saw it?

The last question is the one funds reach late, and it decides how a suspected crossing gets resolved. A record of the prompt, the documents retrieved and the person who read them turns an open question into a bounded, provable event. The same record answers a separate question about the same documents. Where AI arrived tool by tool, each tool holds a fragment and nobody holds the set. Where it runs through one layer, the barrier and the record are properties of the layer, set once and evidenced on request.

Primary sources for the law: the Corporations Act 2001 compilation for sections 1042A, 1043A, 1043F and 1043G, and ASIC Regulatory Guide 181, issued 16 December 2025. Primary sources for the tooling: Microsoft Purview Information Barriers, and Microsoft on how Copilot reaches data and on its data protection architecture. General information, not legal advice: how these sections apply turns on a fund's own facts. Vendor documentation changes, so confirm the current position before relying on it.

Questions this guide answers.

Does Microsoft 365 Copilot respect our information barriers?

In Teams, SharePoint and OneDrive it does, because Copilot is scoped to what the signed-in user can already reach and Purview Information Barriers restricts that access. Microsoft also documents that information barrier policies cannot restrict email, including Exchange Online, and Copilot grounds on the user's mail through Microsoft Graph. So the honest answer is that the barrier holds where it is expressed in permissions. The mailbox is a separate gap to close, with Exchange mail flow rules or by keeping private-side material out of general mailboxes.

Does an AI assistant surfacing a private-side document breach insider trading law?

That turns on facts a guide cannot settle, so it is a question for the fund's own advisers. What is checkable is where the risk sits. Section 1043F protects a body corporate only where the inside information was not in fact communicated to the person who made the decision. Section 1043A(2) reaches information communicated directly or indirectly, or caused to be communicated, where the relevant products can be traded on a market in this jurisdiction. A retrieval layer that puts the document in front of a public-side analyst raises a question about what happened rather than about what the policy said.

Do information barriers matter to a fund that only writes private loans?

The conflicts management obligation in section 912A(1)(aa) applies to every AFS licensee, and ASIC's RG 181 lists information barriers as a way to avoid or control a conflict. The insider trading prohibition is narrower, because it attaches to Division 3 financial products and a bilateral loan agreement is not one. A fund with no exposure to traded securities therefore has a conflicts question to answer rather than an insider trading one. It should still check how applications and redemptions in its own units are treated, because interests in a managed investment scheme are on the Division 3 list.

What should we ask a vendor about information barriers?

Ask where the restriction is enforced and what it covers. Whether the barrier is applied at retrieval time on every query, or only when the index is built. Whether mail is in scope, and whose mail. Whether the restriction can run one way, since a symmetric block is not always what a fund needs. Then ask for the record: what the assistant was asked, what it returned, and who read the answer.

Working with Levercon.

Levercon helps investment firms put AI to work they can trust, and adopt it to unlock their full potential. It does that through one of three routes: Levercon Agents, Levercon Systems or Levercon Strategy.

Talk to us: you can get in touch here.

This guide is general information, not advice. Factual claims that rely on public sources link to those sources in the text. Practical guidance also draws on patterns Levercon observes across Australian credit funds. No client is named and no figure is attributed to one. Written by Levercon, reviewed before publication and revised in place as the facts change.