Back to Blog

Are You Using AI? Can You Prove How You’re Governing It?

Australia already has AI obligations. The 2027 standards are coming. The gap is evidence, not another policy PDF.

Are You Using AI? Can You Prove How You’re Governing It?

Quick verdict

If your organisation uses ChatGPT, Copilot, an AI coding assistant, a vendor with “AI features”, or an API that influences a decision, you are already using AI. The useful question is the second one: can you prove how you govern it?

Australia does not yet have an EU-style AI Act that covers every private-sector use case. It does have existing law, a hard privacy-policy date of 10 December 2026 for certain automated decisions, a Voluntary AI Safety Standard with ten guardrails, and a July 2026 announcement of Australian Standards for AI with legislation targeted for early 2027. The first wave of those standards is aimed at large data centres and Australian creative works, not a general duty for every chatbot. The organisations that will be ready for whatever comes next are the ones that can already produce an inventory, owners, data flows, risk assessments and controls.

Best for: Australian and Singapore operators who already have AI in the building and cannot answer “prove it” from one system. Honest limit: Cipher Projects is not a law firm and not an assessor. We run Power Hour onboarding and a Power Day that leaves you with a living evidence record. We do not certify you.

Last updated: 31 August 2026. Cipher Projects is an Australian engineering studio. Clear Direction AI is our AI governance practice. We build and operate production systems, then we help you document what those systems actually do.


The two questions that decide whether you need this

Ask the board, the CIO, or the person who signed the last SaaS contract:

  1. Are we using AI?
  2. Do we have a governance framework we can evidence?

Yes and yes: keep the record current. Yes and no: you need an accountability layer. No and no: you are almost certainly wrong about the first answer. Staff, developers, marketing, customer service and your vendors are already using models you do not see.

That is the buying decision. The rest of this page is the background that makes the second question expensive to leave unanswered.


What actually changed in Australia in 2026

Until 2026, Australia relied on technology-neutral law, sector rules and voluntary AI guidance. That is still the core of the regime. What changed is the centre of gravity.

On 15 July 2026 the Prime Minister announced a national AI framework: Australian Standards for AI and an Office of AI inside the Department of the Prime Minister and Cabinet. The government said it would take the approach to National Cabinet in August and aim to legislate the standards in early 2027. Read the speech and the early legal notes carefully. The first defined subjects are large data-centre infrastructure (energy, water, grid) and the use of Australian creative works for training. Norton Rose Fulbright’s August 2026 note is blunt: the speech is not an Australian counterpart to the EU AI Act, and no exposure draft, coverage map or lead regulator has been published.

On 20 July 2026 the government also restated consumer-safety, privacy, automated decision-making, workplace safety and digital duty-of-care as reform areas. On 20 August 2026 Parliament appointed a Joint Select Committee on Artificial Intelligence. Its terms include data sovereignty, consumer protection, cyber security, deepfakes and intellectual property. Submissions closed 14 September 2026. The report is due 30 November 2026.

The direction is formal accountability. The shape of a general private-sector duty is still being written. Waiting for the Act before you know what AI you run is the expensive path.

Full dated table: Australia AI regulation 2026–2027.


What is already binding, without a new AI Act

You do not need 2027 legislation to have obligations today.

Source What it already asks Why AI shows up
Privacy Act and Australian Privacy Principles Collection, purpose, security, access, retention Prompts, logs, embeddings and vendor fine-tunes can hold personal information
APP 1 from 10 December 2026 Privacy-policy text on certain automated decisions You cannot write the disclosure if you do not know which systems decide what, and which personal information they use
Australian Consumer Law No misleading conduct Rankings, “best deal” claims, chatbot promises (Air Canada; Trivago’s $44.7m penalty)
APRA CPS 230 / 234 (if regulated) Operational risk, third parties, information security Model APIs and AI SaaS are third-party technology
WHS, anti-discrimination, sector licences Existing duties of care Hiring, credit, safety and eligibility tools do not get a free pass because a model sat in the middle
Voluntary AI Safety Standard (10 guardrails) Accountability, risk, data, testing, human control, transparency, records Not a statute. It is the artefact boards and counterparties already ask for. Implementation guide: VAISS guide

The December 2026 privacy-policy rule is the nearest hard date for most APP entities. Detail: automated decision-making disclosures.


Why the problem starts before the regulation does

Most organisations already have AI operating inside them. Employees use ChatGPT and Claude. Developers use coding assistants. Marketing uses generative tools. Customer-service systems classify and draft. SaaS vendors have turned on AI features inside products the organisation already depends on. APIs sit in production. Some of those systems influence decisions about jobs, credit, pricing, access or complaints.

Ask the room, out loud:

  • What AI are we actually using?
  • What data does each system receive?
  • Does any of it contain personal information?
  • Where does that data go?
  • Which vendors process it?
  • What decisions does the system make or support?
  • Who approved its use?
  • What risks were assessed?
  • What controls are in place?
  • Has it been tested?
  • Who is accountable?
  • Can you produce evidence of any of this?

The usual answer is a policy, a vendor PDF, a spreadsheet last touched in March, and three people who “just know”. That holds until a customer, a board committee, an APRA supervisor, an OAIC enquiry or a journalist asks you to prove it.

AI compliance is becoming an evidence problem. How to find the tools: AI inventory when staff already use ChatGPT.


What an AI accountability layer actually records

A policy says what is allowed. An accountability layer records what exists. Every AI system gets a living record, not a one-off workshop deck.

Record What you keep
Inventory Tools, models, APIs, embedded SaaS features, shadow use
Data and privacy What goes in, whether it is personal information, where it lands
Risk Use-case risk, who is affected, which obligations apply
Vendors Who runs the model or feature, contracts, subprocessors, residency
Accountability Owner, approver, risk manager — named people, not a committee
Testing Validation, security review, evals, red-team notes
Human oversight Where review, intervention or override is required
Governance Link to the policy, standard, approval and control that covers it
Monitoring Model, vendor, data-flow and risk changes after go-live
Evidence An export you can hand to a lawyer, auditor or board without rebuilding the story

That is the difference between “we have a responsible AI policy” and “here is the record for the system you asked about”. Singapore’s Model Frameworks and AI Verify ask for the same shape of proof, even though they stay voluntary: Singapore AI governance 2026. Europe already requires it for in-scope systems: EU AI Act vs Australia vs Singapore.

Why waiting for 2027 costs more than starting now

If you wait until a standard is legislated, you first have to discover what AI you already use. Then identify the data. Then the risks. Then the obligations. Then the owners. Then reconstruct which decisions were made, and whether controls existed at the time. Some of that reconstruction is expensive. Some of it is impossible: the contractor left, the vendor changed the model, the Slack channel was deleted.

Building the trail while AI is being deployed is a different job. You know what exists. You know who owns it. You know what data it touches. You know what was considered. You can demonstrate it.

Unique insight from the Power Days we run: the first two hours are never the policy. They are a hunt. Finance has a copilot. Marketing has three image tools on personal cards. Engineering has Copilot and a Cursor seat that never went through procurement. A CRM quietly enabled “AI summaries” in a vendor release note nobody filed. Until those rows exist, every later control is theatre.


The objective is not to stop organisations using AI

It is the opposite. Make it possible to adopt AI aggressively without losing control of it. Governance should not be a bureaucratic gate between the organisation and a useful tool. It should be the infrastructure that lets you say:

Yes, we use AI. Yes, we understand where it is. Yes, we understand the risks. Yes, we have controls. And yes — we can prove it.

A Power Hour gets the system and the owners in the room. A Power Day walks the inventory, the data, the vendors and the first risk tier, and leaves a living record rather than a slide pack. What that day produces: AI governance Power Day.


FAQ

Does Australia have an AI Act yet? No. Existing law already applies. The July 2026 announcement creates an Office of AI and aims to legislate Australian Standards for AI in early 2027. The first published subjects are infrastructure and training inputs, not a general high-risk regime for every company.

Is the Voluntary AI Safety Standard mandatory? No. Boards, insurers, customers and APRA-regulated counterparties still ask for it. The ten guardrails are also the cheapest map onto ISO/IEC 42001 if you later certify.

We are under the $3 million Privacy Act threshold. Do we still need this? The December 2026 APP 1 rule applies to APP entities. Small businesses can still be pulled in by health data, credit reporting, or a contract that requires you to match a customer’s governance. Shadow AI is an operational risk either way.

We already have a responsible AI policy. Is that enough? A policy without an inventory is a statement of intent. The question that fails in a review is “show us the system, the owner, the data and the last test”.

Will a Power Day make us compliant? No. It produces a living inventory and evidence record. Counsel and, where relevant, an assessor still own legal sign-off and certification.

We also operate in Singapore or the EU. Do we need a second system? You need one evidence layer that can answer three regimes. The fields are almost the same. The trigger dates are not. Start with the comparison in EU vs Australia vs Singapore. In Singapore the named buyer is the Data Protection Officer.


AI is already inside the organisation

The regulatory framework is evolving. Your evidence should start now. Know the AI. Assess the risk. Keep the record. Be ready for the next question, whether it comes from a customer in October or a statute in 2027.

Related: 2026–2027 timeline · December 2026 ADM rule · AI inventory · Singapore DPO · Power Day · VAISS implementation · Contact

Share this article

Share:

Using AI without an evidence trail?

Power Hour onboarding, then a Power Day: inventory, owners, data flows, and a living record. We build the evidence layer — we do not certify you.