AI Governance Consulting
Enough governance to move safely, and not one page more. Acceptable-use policy, AI register, risk sized to consequence, and your Privacy Act obligations mapped to what you actually do.
You Are Already Regulated. Just Not by Anything Called an AI Act.
Australia has no single AI statute. It has a stack of obligations you already carry that apply the moment an AI system touches your business.
The most common misunderstanding we meet is the belief that AI is currently unregulated in Australia and that governance can therefore wait for legislation. It cannot, because the obligations that matter are already in force under different names. The Privacy Act 1988 and the Australian Privacy Principles govern personal information regardless of what processes it — the law does not care whether the thing handling your customer’s details is a spreadsheet, a contractor or a language model. Australian Consumer Law applies to what your AI tells a customer; an automated misrepresentation is simply a misrepresentation with better grammar. Anti-discrimination law applies to automated decisions in hiring and credit. And your sector regulator has its own view.
Above that sits Australia’s Voluntary AI Safety Standard. It is not law, and that leads people to dismiss it, which is a mistake — it is becoming the reference point organisations get measured against in practice, particularly in procurement. If you sell to enterprise or government, the questionnaire is coming, and “we have not thought about it” is a losing answer regardless of what the statute book says.
Meanwhile, the actual risk in most businesses is not the system you are planning. It is the one already running. Your staff are using public AI tools with company information right now — not out of recklessness, but because the tools work and nobody gave them a sanctioned alternative. Every AI register we build turns up tools nobody in management knew about. That discovery is usually the single most valuable hour of the engagement, and it is why governance is the one service we sometimes recommend before the audit.
What we do not do is sell you a compliance industry. Governance should be proportionate to consequence: a meeting-notes summariser and a system influencing credit decisions are not the same risk, and governing them identically means either strangling the harmless one or under-governing the dangerous one. Over-governance fails exactly the way under-governance does — people route around it — and it costs more on the way.
The Governance Floor
Six artefacts. Three to four weeks. The test is whether your staff read the policy and know what to do on Monday.
Acceptable-Use Policy
Plain English, with examples from your business rather than abstractions. A policy that just says "do not use AI" is ignored by lunchtime and leaves you worse off than none at all.
- What may go into which tools, with real examples
- The serious categories named explicitly
- An approved tool, so there is a legitimate path
- Written to be read, not to be filed
AI Systems Register
Every AI system in use — including the ones staff adopted without asking. The discovery exercise behind this always finds something management did not know about.
- Sanctioned and unsanctioned tools both captured
- What data each one touches
- Vendor, data residency and contract terms
- Kept current, not a one-off snapshot
Risk Sized to Consequence
A risk position per system, proportionate to what it actually does. Not one heavyweight framework applied uniformly to a summariser and a decision engine.
- Assessment scaled to actual consequence
- Specific mitigations, not generic controls
- Human-in-the-loop where it genuinely matters
- Documented reasoning a board can follow
Privacy Act Mapping
Your obligations under the Privacy Act 1988 and the APPs, mapped to your real use cases — where personal information goes, who it is disclosed to, and what your notices say.
- APP obligations mapped to actual use cases
- Cross-border disclosure positions made explicit
- Privacy notices reviewed against what you do
- Data retention and deletion addressed
Shadow AI
The tools already in your business that nobody approved. Handled as a supply problem rather than a discipline problem, because the alternative drives it underground.
- Discovery of what is actually being used
- Sanctioned alternatives, so people have a path
- Amnesty framing rather than enforcement theatre
- Ongoing visibility rather than a single sweep
Accountability & Review
One named person per system, senior enough to switch it off. Plus a review cadence, because a policy written once and filed is decoration.
- A named owner per system — not a committee
- Authority to stop, not just to be consulted
- Scheduled review as tools and staff change
- Board-level reporting line defined
The Australian Regulatory Picture
What applies to your AI today, under names that do not mention AI.
Privacy Act 1988 & the Australian Privacy Principles
Governs personal information regardless of what processes it. If your AI touches customer data, you are in scope — including where that data goes, who it is disclosed to, and whether your privacy notice matches reality. Cross-border disclosure to an overseas model provider is a disclosure, and needs to be treated as one.
Australian Consumer Law
Applies to what your AI says to customers. Misleading or deceptive conduct does not become acceptable because a model generated it, and "the AI said it" has never been a defence. Anything customer-facing needs guardrails on claims, pricing and representations.
Voluntary AI Safety Standard
Not law, but increasingly the reference point in procurement and board expectations. If you sell to enterprise or government, expect the questionnaire. Aligning with the substance costs far less than being caught without a position when a major customer asks.
Anti-Discrimination Law
Automated decisions in hiring, credit and service provision carry the same obligations as human ones. A model that produces disparate outcomes is a legal exposure regardless of intent, which is why we push hard on human-in-the-loop for any decision affecting a person’s access to something.
Sector & State Regulators
Financial services, health, legal and government-adjacent work each add their own layer, and state privacy regimes apply to state-sector and contracted work. Which of these bites depends on what you do — we map the ones that actually apply rather than listing all of them.
ISO/IEC 42001
The international standard for AI management systems. Genuinely useful if a customer requires it or AI is central to your product. For a mid-market business using AI internally, align with the substance and certify only when someone actually asks.
This is general information about how these obligations typically apply, not legal advice. We work alongside your lawyers — and we will tell you plainly when a question needs one rather than us.
How a Governance Engagement Runs
Three to four weeks. Delivered remotely across Australia.
Discovery
What AI is actually in your business right now, sanctioned or not. This is usually the most revealing part, and it is always more than management expects.
Map the Obligations
Which regulations genuinely bite for your use cases — Privacy Act, ACL, sector rules — mapped to what you actually do rather than listed in the abstract.
Write the Artefacts
Policy, register, risk positions, named owners. Plain English, proportionate, and drafted so your staff can act on them without an interpreter.
Embed & Review
Roll it out, brief the staff, set the review cadence and the board reporting line. Then it is maintained rather than filed.
Related Services
Governance is rarely the whole answer, but it is often the right first step.
AI Training for Teams
A policy nobody understands is decoration. Training is what turns the rules into behaviour.
Team trainingFractional AI Officer
Governance needs maintaining as tools and staff change. This is who maintains it when you cannot justify a hire.
Ongoing ownershipAI Readiness Assessment
The $3k audit covers governance as one of six dimensions, alongside the opportunity register.
The auditFrequently Asked Questions
What Australian businesses ask about AI governance, policy and risk.
There is no single AI Act in Australia. What exists is a set of obligations you already have that apply to AI whether or not anyone has thought about it that way. The Privacy Act 1988 and the Australian Privacy Principles govern personal information regardless of what processes it — an AI system that touches customer data is in scope exactly as a spreadsheet would be. Australian Consumer Law still applies to what your AI says to customers; an automated misrepresentation is a misrepresentation. Anti-discrimination law applies to automated decisions in hiring and credit. Sector regulators add their own layers. On top of that sits Australia’s Voluntary AI Safety Standard, which is not law but is rapidly becoming the reference point people are measured against — including by customers running procurement questionnaires. The practical position: you are already regulated, just not by anything with "AI" in the title.
It is close to universal, it is rarely malicious, and treating it as a disciplinary matter is the fastest way to drive it underground where you genuinely cannot see it. People are using these tools because they work and because nobody gave them a sanctioned alternative. The realistic response has three parts: give them an approved tool with an appropriate data agreement so there is a legitimate path; write an acceptable-use policy in plain English that says what may and may not go into which tools, with examples from your actual business rather than abstractions; and be specific about the genuinely serious categories — customer personal information, health information, anything under an NDA, anything you would not email to a competitor. A policy that just says "do not use AI" is ignored by lunchtime and leaves you worse off than having no policy, because now you have a documented rule you are demonstrably not enforcing.
Considerably less than the compliance industry wants to sell you, and more than nothing. For most Australian mid-market businesses the useful floor is four artefacts: a plain-English acceptable-use policy people actually read; a register of AI systems in use, including the ones staff adopted without asking; a risk position per system, sized to what the system actually does; and a named human accountable for each one. That is a few weeks of work, not a programme. Governance should be proportionate to consequence — an internal meeting-notes summariser and a system that influences credit decisions are not the same risk, and treating them identically means either strangling the harmless one or under-governing the dangerous one. In practice, over-governance fails the same way as under-governance: everyone routes around it.
Probably not, and we will usually say so. ISO/IEC 42001 is the international standard for AI management systems, and it is genuinely useful if you are selling into enterprises or government buyers who ask for it, or if AI is central to your product and certification is a commercial differentiator. For a mid-market business using AI internally to reduce admin, it is a large cost for an answer nobody has asked you for. The pragmatic path is to align with the substance — the risk register, the accountability, the review cadence — without buying the certification, then certify if and when a customer actually requires it. If a consultant leads with certification before asking what you do, they are selling an audit rather than solving a problem.
One named person per system, senior enough to stop it. Not a committee — committees are where accountability goes to be diffused, and "the AI working group" has never once made a hard call. The accountable person does not need to understand transformer architecture; they need to understand the business process the system touches, and they need the authority to switch it off. Above that, someone senior should hold the overall position: the policy, the register, the board answer. In a business with the volume to justify it that becomes a real role. In most mid-market businesses it is a few days a month, which is exactly the gap a fractional AI officer fills.
Working artefacts, not a framework document. An acceptable-use policy in plain English with examples drawn from your business. A register of AI systems actually in use — and the discovery exercise behind it is often the most revealing part, because it always finds tools nobody knew about. A risk assessment per system, proportionate to what it does, with mitigations that are specific. A named accountable owner for each. A position on your Privacy Act 1988 obligations mapped to your real use cases rather than in the abstract. And a review cadence, because a policy written once and filed is decoration. Usually three to four weeks. The test is whether your staff can read the policy and know what to do on Monday.
Your Staff Are Already Using AI
The only question is whether you know which tools, with what data. Start with a free hour and we will tell you what governance you actually need — which is usually less than you fear.