AI Governance in Australia Has an Announcement Problem.
What it does not have is a process.

Could you produce a list of every AI system your organisation uses, with a named owner for each, by Friday? A passive external assessment is where the honest answers begin: what you expose to the outside world, and who owns that risk.

Assess Your Exposure →

Australia is not short of AI guidance. It has AI Ethics Principles from 2019, a Voluntary AI Safety Standard from 2024, ten proposed mandatory guardrails that arrived in September 2024 and were shelved in December 2025, a National AI Plan, a funded AI Safety Institute, Guidance for AI Adoption from the National AI Centre, updated directors’ guidance, and as of 15 July 2026 an Office of AI inside the Department of the Prime Minister and Cabinet with legislation anticipated in 2027.

What Australian organisations mostly do not have is a process.

Australian AI governance, as at 4 August 2026
0
mandatory guardrails proposed in September 2024
0
of them currently in force
0
A$ funding for the AI Safety Institute — advisory only
0
days from publication to the 10 December 2026 obligation
Sources: DISR Safe and Responsible AI Proposals Paper (September 2024); National AI Plan (December 2025); Privacy and Other Legislation Amendment Act 2024.

That distinction is the whole subject of this article. In the assessment work we do, the finding is almost never that an organisation lacks an AI policy. The finding is that the policy exists, is well drafted, was approved by the executive, and governs approximately none of the AI systems actually running in the business — because nobody ever built the process that would connect the two.

The distinction that mattersPolicy states what should happen. Process is what causes it to happen, repeatably, and produces evidence that it did. Regulators, courts and insurers are interested in the second. Almost all Australian AI governance effort to date has gone into the first.

What governance actually exists in Australia right now

Before diagnosing the gap it is worth being precise about what is genuinely in place, because the answer is neither “nothing” nor “an AI Act”. Seven instruments matter, and only two of them bind anybody.

Seven instruments, two that bind
November 2019
AI Ethics Principles

Eight voluntary principles — human wellbeing, fairness, privacy, reliability, transparency, contestability, accountability. Status: voluntary. Useful as vocabulary, not as a control. Nothing in them tells an organisation what to do on a Monday.

Click any point to read what happened
Sources: DISR; National AI Centre; National AI Plan (December 2025); Commonwealth AI requirements commencing 15 June 2026; Government announcement of 15 July 2026.
Read that list againOf seven instruments, exactly two impose an obligation on anybody — and both apply to Commonwealth agencies rather than to business. Everything binding on the private sector sits in law that was written before any of this: directors’ duties, the Privacy Act, the Australian Consumer Law. That is the actual governance position, and it is why the process question matters more than the policy question.

Why the regulatory position is not the problem

It is worth dispensing with the policy debate quickly, because it has become a very effective excuse for inaction.

The proposed mandatory guardrails were shelved, then legislation was announced. Whichever way that lands, the obligations that already apply did not change and are not waiting:

  • Directors’ duties are technology-neutral. Approving a system that makes consequential decisions without understanding how it fails is exposure under provisions that predate machine learning by decades.
  • The Privacy Act and the Australian Privacy Principles apply to every AI system that touches personal information — including the infrastructure it runs on and any vector index derived from a document repository.
  • The Australian Consumer Law covers misleading AI claims, with the ACCC active in this area against a substantially increased penalty regime.
  • Anti-discrimination law engages on outcomes, not on whether disparity was intended or understood.
  • From 10 December 2026, privacy policies must disclose substantially automated decisions that significantly affect individuals.

None of that is contingent on an AI Act. All of it requires the same underlying thing: knowing what you run.

The six process controls that constitute AI governance

Strip away the framework language and functioning AI governance is six repeatable processes. Each has an owner, a trigger, an output and a record. If you cannot describe all six in your organisation, you do not have AI governance — you have an AI policy.

Process 1 — Discovery: how do new AI systems get found?

Not declared. Found. The distinction is the entire problem.

Declared systems are the ones that went through procurement. Found systems include the AI features switched on by default in software you already bought, the coding agent an engineer installed last month, the model endpoint someone stood up for a prototype, the agent wired to the ticketing system, and the department that pasted client material into a public chatbot because it was faster.

A discovery process needs at least three inputs: a periodic internal amnesty request framed explicitly as no-consequence; a review of SaaS contracts and release notes for AI features enabled since signing; and an external assessment of what AI infrastructure is visible on your own perimeter. That third input is the one almost nobody runs, and it is the only one that does not depend on someone remembering to tell you.

Output: a dated inventory. Failure mode: a one-off inventory built for an audit and never refreshed.

Process 2 — Ownership: who is accountable for each system?

Per system, by name, with authority to change or switch it off. Not “IT.” Not “the AI Committee.” A person.

The Commonwealth requirement for agencies to appoint Chief AI Officers from 15 June 2026 reflects this, but the officer is the process owner — not the accountable party for every system. Someone must own the recruitment screening model. Someone must own the customer service agent. Those are different people with different authority.

Output: an owner field on every inventory row that is never blank. Failure mode: ownership assigned to a role that has since been vacated or restructured.

Process 3 — The assessment gate: what must happen before deployment?

A gate is a point at which a system cannot proceed without an assessment being completed. If your assessment can be skipped, or completed after go-live, or waived by the person deploying, it is not a gate.

The assessment itself does not need to be elaborate. It needs to answer: what decisions does this make, about whom, with what effect; what data does it use and where does that data go; what does it do when it fails; what can it reach if it is compromised; and who signed off.

For agentic systems the last question matters more than the rest. An agent that reads untrusted content, can take actions, and can communicate externally has the combination that makes a compromise consequential — and most useful agent deployments have all three by design.

Output: a completed assessment per system, dated and attributed. Failure mode: the gate exists for procured systems only, so anything built or installed internally bypasses it entirely.

Process 4 — The decision record: why was this approved?

This is the control that Australian organisations most consistently lack, and the one that will matter most if anything goes wrong.

Governance is not the absence of risk. It is the presence of a reasoned decision to accept a risk, made by someone with authority, recorded at the time. A regulator asking why a system was deployed does not want a policy. It wants the record of the decision.

Contemporaneous documentation is worth considerably more than a framework adopted afterwards, because a framework adopted afterwards demonstrates that you did not have one at the time.

Output: a dated, attributed decision per system with the rationale stated. Failure mode: decisions recorded in meeting minutes as “noted” with no rationale and no name.

Process 5 — Monitoring: how would you know it had gone wrong?

Model behaviour changes. Vendors update models beneath you, sometimes without notice, and a model upgrade alone has been observed to produce emergent behaviour that did not exist before. Data drifts. Usage expands well beyond the original scope, usually because the system was useful.

A monitoring process needs a defined signal, a defined frequency, and a defined person who looks. Output sampling, complaint and appeal volumes, override rates, and per-action logging under a distinct identity for agentic systems. An agent operating under a shared service account is unattributable by construction — you cannot monitor what you cannot separate.

Output: a monitoring record with dates. Failure mode: monitoring defined in the policy and performed by nobody.

Process 6 — The failure path: what happens when it goes wrong?

Who can switch a system off, and how quickly? How does an affected individual contest a decision, and does that path actually work? What triggers a notification assessment under the Notifiable Data Breaches scheme? What is the rollback position — is there a human process that can absorb the volume if the automated one stops?

Most organisations have never tested the last of these. The answer is frequently that there is no fallback, because the headcount that used to do the work was removed when the system was deployed.

Output: a documented and tested procedure. Failure mode: an incident response plan that does not mention AI systems at all.

Do you have a process, or a policy?
The six process controls, expressed as eight statements. Tick what is true today.
We could produce a dated inventory of every AI system in use, including AI features enabled by default in software we already bought.
Every AI system has a named individual owner with authority to change or switch it off.
No AI system can go live without a completed assessment that cannot be waived by the person deploying it.
For every deployed system there is a dated, attributed record of who approved it and why.
We have a defined monitoring signal, a defined frequency, and a named person who actually looks.
Agentic systems run under their own identities with per-action logging, not a shared service account.
We have a tested procedure for switching a system off and falling back to a human process.
We know which of our systems make substantially automated decisions significantly affecting individuals.
Tick every statement that is true of your organisation

The 10 December 2026 test

There is one firm statutory date on the Australian AI calendar, and it functions as an unintentional audit of whether the six processes above exist.

From 10 December 2026, under the Privacy and Other Legislation Amendment Act 2024, an APP entity’s privacy policy must disclose the kinds of personal information used in substantially automated decisions that significantly affect the rights or interests of an individual, and the kinds of decisions made.

Drafting that disclosure takes an afternoon. Being able to draft it accurately requires you to know:

  • Which of your systems make decisions about individuals — Process 1
  • Which of those are substantially automated — Process 3
  • Which significantly affect the person — Process 3
  • What personal information each uses — Processes 1 and 3
  • Who can confirm any of it is still accurate — Processes 2 and 5

An organisation with the processes will produce the disclosure in a week. An organisation without them will produce a vague paragraph that is either wrong or so general it discloses nothing — and an inaccurate privacy policy is itself an APP 1 problem.

The commercial angle most organisations are missingCommonwealth agencies have had mandatory AI requirements since 15 June 2026 — impact assessments, procurement guidance, foundational training and Chief AI Officers — with full compliance due 10 December 2026. Agencies buy from the private sector, and procurement guidance flows into contracts. If you sell to government, these requirements will reach you through a tender document before they reach you through a regulator. That is the real commencement date for most Australian businesses.

Where to start, in order

  • Week 1 — run the discovery. Amnesty request internally, contract and release-note review, external assessment of your perimeter for exposed model endpoints, agent interfaces and MCP servers. Expect the result to be larger than anyone predicts.
  • Week 2 — assign owners. Every row gets a name. Rows that cannot get a name are your highest-risk items, not your lowest.
  • Week 3 — triage against 10 December. Flag every system making decisions about individuals. That subset gets assessed first.
  • Week 4 — install the gate. Define what must be completed before any new AI system goes live, and who cannot waive it.
  • Ongoing — record and monitor. Decisions dated and attributed. Monitoring signals defined with a named reviewer and a frequency.

Map the result to whichever framework your stakeholders recognise — the National AI Centre’s Guidance for AI Adoption and its six essential practices, the eight elements in the updated directors’ guidance, or ISO/IEC 42001 if you need certifiable evidence for procurement. The framework is presentation. The six processes are the substance, and they are identical regardless of which framework you present them through.

The point

Two policy reversals in eight months is a fair signal that the settled Australian position has not been found. It would be unwise to assume July 2026 was the last word, and equally unwise to wait for one.

The organisations that will handle whatever arrives in 2027 are not the ones that predicted the policy correctly. They are the ones that can answer, today, without a project: what do we run, who owns it, why did we approve it, and how would we know if it went wrong?

Passive only — no systems accessedBlackFlag Advisory supports Process 1 — discovery — from the outside. We identify exposed model endpoints, inference gateways, MCP servers and AI infrastructure attributable to your organisation using publicly available data only. No systems, networks or accounts are accessed, probed or tested.
SourcesDepartment of Industry, Science and Resources, Safe and Responsible AI: Proposals Paper (September 2024); National AI Centre, Guidance for AI Adoption (October 2025); Australian Government National AI Plan (December 2025); Commonwealth whole-of-government AI requirements commencing 15 June 2026; Australian Government announcement of 15 July 2026 establishing the Office of AI; Privacy and Other Legislation Amendment Act 2024; OAIC Australian Privacy Principles Guidelines; Productivity Commission interim report (2025); ACCC enforcement priorities; ISO/IEC 42001. This article is general information and is not legal advice. Analysis by BlackFlag Advisory.

A Governance Framework Covers
Only What Was Declared.

BlackFlag Advisory finds the AI infrastructure that was never declared — exposed model endpoints, agent interfaces and shadow deployments on your public perimeter — so your governance scope reflects what you actually run, not what was written down.

Request an Assessment →
Passive Only — No Systems Accessed

All BlackFlag Advisory assessments use exclusively passive OSINT techniques and publicly available data sources. No systems, networks, or accounts are accessed, probed, or tested at any time. Board-ready output delivered within three to seven business days.