AI Governance & Assurance

Your AI Framework Governswhat somebody remembered to declare.

Australia has seven AI governance instruments. What almost no organisation has is a process — an inventory, a named owner, an assessment gate, a decision record.

492MCP servers found exposed with no authentication
10 Dec 2026Automated decisions must be disclosed
AdvisoryAI Safety Institute has no enforcement power
5 daysHugging Face investigated before the source was known

Passive only — no systems, networks or accounts are accessed at any point.

Seven Instruments. Two That Bind Anybody.

Australia is not short of AI guidance. It is short of AI obligation, and that has produced a peculiar failure mode: organisations with a well-drafted AI policy, approved by the executive, that governs approximately none of the AI actually running in the business.

The current position, stated precisely:

AI Ethics Principles (2019)

Eight voluntary principles. Useful as vocabulary, not as a control. Status: voluntary.

Ten mandatory guardrails (proposed September 2024, shelved December 2025)

Testing, transparency, data governance, human oversight, accountability, incident reporting and conformity assessment. Worth reading anyway — it remains the clearest statement of what regulators think good looks like. Status: not in force.

Guidance for AI Adoption (October 2025)

Six essential practices from the National AI Centre, superseding the Voluntary AI Safety Standard published twelve months earlier. Status: voluntary, and currently the primary government guidance.

Australian AI Safety Institute (2026)

Approximately A$29.9 million to test AI systems, assess risks and recommend reforms. Status: advisory and monitoring only — no enforcement power.

Commonwealth agency requirements (15 June 2026)

AI impact assessments, procurement guidance, foundational AI training and Chief AI Officers, with full compliance due 10 December 2026. Status: binding — on Commonwealth agencies.

Office of AI and announced legislation (15 July 2026)

An Office of AI established within the Department of the Prime Minister and Cabinet, with plans to legislate Australian Standards for AI. Status: announced; legislation anticipated 2027.

Read that list againOf the instruments above, the only ones imposing an obligation apply to Commonwealth agencies. Everything binding on the private sector sits in law written before any of this: directors’ duties, the Privacy Act, the Australian Consumer Law, anti-discrimination law. That is why the process question matters more than the policy question — and why waiting for an AI Act is not a strategy.

Frameworks Govern What Was Declared

Every AI governance framework begins from a register. None of them tells you how to build one that reflects reality rather than intent.

Declared systems are the ones that went through procurement. Found systems include the AI features switched on by default in software you already bought, the coding agent an engineer installed last month, the model endpoint someone stood up for a prototype, the agent wired into the ticketing system, and the department pasting client material into a public chatbot because it was faster.

That second category is now an external attack surface class in its own right. Security tooling released through 2026 fingerprints more than sixty model-serving, gateway, MCP and RAG platforms on public endpoints, and researchers identified 492 MCP servers exposed to the internet with zero authentication. An MCP server is, by design, a remote execution surface — its entire purpose is to let something else take actions in your environment.

The uncomfortable positionAn organisation can hold a defensible AI governance framework — approved-use register, vendor assessments, an ISO/IEC 42001 programme — and still have several unauthenticated model endpoints on its public perimeter appearing in none of it. The framework governs what was declared. Nothing governs what was not.

What a BlackFlag Advisory AI Governance Assessment Covers

  • External AI infrastructure discovery — model serving endpoints, inference gateways, MCP servers and vector stores reachable from the public internet and attributable to your organisation
  • Declared-versus-actual reconciliation against your AI register, procurement records and policy scope
  • Automated decision identification — which of your systems make substantially automated decisions significantly affecting individuals, which is the precise question the 10 December 2026 obligation asks
  • Process control review across discovery, ownership, the assessment gate, the decision record, monitoring and the failure path
  • Agent blast radius — what untrusted content your agents read, what actions they can take, what they could reach if hijacked, and whether the activity would be observable
  • Framework mapping to Guidance for AI Adoption, ISO/IEC 42001, CPS 234, the Essential Eight and the Australian Privacy Principles as applicable
Passive Only — No Systems AccessedBlackFlag Advisory identifies exposed AI infrastructure using publicly available data and passive observation only. No endpoint is queried, prompted, enumerated or tested. No systems, networks or accounts are accessed at any point.

Who This Is For

Boards and risk committees

Where the question has moved from “are we using AI” to “what are we running, who owns it, and could we describe how it fails”.

Organisations preparing for 10 December 2026

Where the automated-decision disclosure obligation requires an accurate inventory, and the assessment is harder than the drafting.

Anyone selling to Commonwealth government

Agencies have carried mandatory AI requirements since 15 June 2026 — impact assessments, procurement guidance, AI training and Chief AI Officers. Those requirements reach the private sector through tender documents before they reach it through a regulator.

Engineering-led organisations

Where coding agents run against production repositories, MCP servers were stood up in a fortnight, and none of it went through a change request.

Organisations pursuing ISO/IEC 42001

Where a certifiable management system needs a defined scope, and undiscovered systems are outside scope by accident rather than by decision.

How the Engagement Runs

Five steps. The only ones that require your time are the first and the last.

1. Scope

We agree the entities, domains and cloud address space in scope, and the framework the findings should map to — Guidance for AI Adoption, ISO/IEC 42001, or your own internal policy.

2. External discovery

We identify AI infrastructure reachable from the public internet: model serving endpoints, inference gateways, MCP servers and vector stores. Passive observation only — no endpoint is queried, prompted, enumerated or tested.

3. Declared-versus-actual reconciliation

We compare what the external view shows against your AI register, procurement records and policy scope. The gap between the two documents is the finding.

4. Process review

We assess the six controls that constitute functioning governance: discovery, ownership, the assessment gate, the decision record, monitoring, and the failure path. Each is either present with evidence, or it is not.

5. Delivery

A dual-audience report: a Board section stating the position plainly, and a working section your technology and legal functions can act on — including the systems that must appear in your privacy policy before 10 December 2026.

Frequently Asked Questions

The questions we are asked most often by boards, general counsel and technology leaders.

Does Australia have an AI Act?

Not yet. Ten mandatory guardrails for high-risk AI were proposed in September 2024 and shelved in the December 2025 National AI Plan in favour of technology-neutral regulation under existing law. On 15 July 2026 the Government announced plans to legislate Australian Standards for AI and established an Office of AI within the Department of the Prime Minister and Cabinet, with legislation anticipated in 2027.

What happens on 10 December 2026?

Under the Privacy and Other Legislation Amendment Act 2024, APP entities must disclose in their privacy policy the kinds of personal information used in substantially automated decisions that significantly affect the rights or interests of an individual, and the kinds of such decisions made. Meeting that obligation accurately requires an inventory of automated decision systems, which most organisations do not currently hold.

What is shadow AI, and why does it matter more than the framework?

Shadow AI is AI in use that was never declared, assessed or assigned an owner — features switched on by default in software you already bought, a model endpoint someone stood up for a prototype, an agent wired to internal systems. A governance framework can only govern what was declared. Discovery has to come first, and it has to come from outside the organisation’s own conception of itself.

Do you assess the models themselves?

No. We assess governance process and external exposure: what AI infrastructure is reachable from the public internet, what is declared against what exists, and whether the six process controls that constitute functioning governance are actually in place. Model evaluation, bias testing and red-teaming are separate disciplines.

Is ISO/IEC 42001 worth pursuing?

ISO/IEC 42001 provides a certifiable AI management system standard covering scope, policy, risk assessment, controls, monitoring and continual improvement. It maps cleanly onto the National AI Centre’s Guidance for AI Adoption and is increasingly requested in procurement. For organisations selling into government or regulated sectors it is a practical way to evidence maturity ahead of legislation.

Packages are set out on the assessment packages page, or book a short call to discuss scope against your obligations.

Assessed Against the Obligation
You Actually Carry

Every engagement is the same passive methodology. What changes is the framework the findings are mapped to, and the audience the report is written for.

APRA CPS 234
CPS 234 Assessment

Independent external exposure evidence mapped clause by clause to the APRA prudential standard — for your Board and internal audit function.

View Assessment →
ASD Essential Eight
Essential Eight Assessment

Externally verified evidence against the mitigation strategies that can honestly be assessed from outside — and an explicit statement of those that cannot.

View Assessment →
Privacy Act & APPs
Privacy Act & APP 11 Assessment

What your organisation exposes, mapped to the Australian Privacy Principles — including tracking, consent sequencing and overseas disclosure.

View Assessment →
Supply Chain
Third-Party Risk Assessment

What your suppliers actually expose, observed from outside without their cooperation. Evidence rather than questionnaires.

View Assessment →
AML/CTF Tranche 2
Tranche 2 Cyber Assessment

For law firms, accountants, conveyancers and agencies now holding seven years of client identity documents under obligations that commenced 1 July 2026.

View Assessment →

You Cannot Govern
What You Have Not Found.

A BlackFlag Advisory assessment finds the AI infrastructure that was never declared — exposed model endpoints, agent interfaces and shadow deployments — so your governance scope reflects what you run rather than what was written down.

Request an Assessment →
Assessments
AI Governance CPS 234 Essential Eight Privacy Act & APP 11 Third-Party Risk Tranche 2 Cyber Which one do I need? →
Intelligence
All briefings Romania land registry Tranche 2 commenced ASD advisories, 2026
Practice
GRC Partnerships Pricing Privacy
Start
Threat Scan Enquire Sample report