Governance counsel for
organisations deploying AI.

Four regulatory deadlines converge in 2026 (the Privacy Act, the EU AI Act, APRA CPS 230, and the Australian Consumer Law). Organisations deploying AI without governance documentation, updated vendor contracts, and human oversight protocols are exposed to enforcement under laws already in force. We help you identify the gaps and close them.

Close the gap between AI adoption
and legal accountability.

Most organisations now use AI in their operations. Far fewer have governance that would survive scrutiny from a regulator or a court. The distance between what you deploy and what you can account for is where enforcement is concentrated.

What the data shows

Our research indicates that only a fraction of organisations deploying AI have functioning governance in place. Unmanaged 'Shadow' AI is already a source of enterprise-level data breaches, disproportionately exposing personal information and intellectual property.

An organisation that cannot produce an inventory of its AI systems is in a difficult position if a regulator asks for one. The gap between what is deployed and what is documented is where accountability obligations attach.

Where enforcement is coming from

The OAIC's determination against Bunnings over its facial-recognition deployment. The Federal Court's finding in ASIC v Bekier that AI cannot displace independent director judgment. Doubled ACL maximum penalties of $100 million per contravention.

There is no standalone Australian AI Act, and waiting for one is not a strategy; enforcement is already running through the Privacy Act, the Corporations Act, the ACL, and APRA standards that your organisation answers to.

AI governance in practice.

The six areas reflect where AI governance actually sits in an organisation: in policy and risk management, in vendor relationships, in employment law, and in how a board exercises oversight. Engagements are scoped to the AI your organisation deploys and the regulatory obligations those deployments create; most draw from several areas rather than treating each as a standalone project.

POL 01

AI Policy & Acceptable Use

Board-endorsed policy covering acceptable use, tiered approval pathways, and prohibited-use schedules.

REG 02

AI Inventory & Risk Register

Every AI system mapped to intended use, data inputs, and risk tier.

AIA 03

Impact Assessments

Privacy and algorithmic impact assessments for high-risk applications and deployments.

VEN 04

Vendor Contract Uplift

Model-change notices, audit rights, data exit, and training restrictions negotiated upstream.

EMP 05

Employment & Discrimination

Screening reviews, anti-discrimination overlays, and oversight protocols for AI-assisted HR.

BRD 06

Board & Director Governance

Board accountability structures and governance documentation built to withstand scrutiny.

The AI rules and obligations
already in play.

Australia does not have a standalone AI Act. That does not mean AI is unregulated. The Privacy Act, the Corporations Act, the Australian Consumer Law, and APRA's prudential standards all impose obligations on organisations deploying AI, and all are already in force. What applies to your organisation depends on who you are and what you deploy.

All organisations

Privacy Act — automated decisions

APP 1.7, commencing 10 December 2026, requires APP entities that use personal information in automated or semi-automated decisions with a significant effect on individual rights to disclose data input categories and decision types in their privacy policy. The trigger is the significance of the effect; rule-based logic and GenAI both qualify. OAIC infringement penalties reach $330,000 per contravention. OAIC v Bunnings confirmed that technical complexity does not displace privacy obligations where personal data is operationally processed.

Australian Consumer Law — AI claims

Maximum ACL penalties doubled to $100 million per contravention from 28 March 2026. AI-washing (unsubstantiated claims about capability, accuracy or safety) constitutes misleading conduct under ss 18 and 29 of the Australian Consumer Law. The ACCC's 2026–27 enforcement priorities name AI-washing, algorithmic pricing and dark patterns as focal areas. Prior enforcement on algorithmic misrepresentation is already on record.

Directors' duties

In ASIC v Bekier [2026] FCA 196, Lee J confirmed that AI can assist discharge of the duty of care under s 180(1) of the Corporations Act 2001 (Cth) but cannot replace independent human judgment. The Court required evidence of transparent collective board governance over AI use in decision materials. Directors unable to demonstrate oversight of material AI-driven decisions are exposed on the existing statutory duty.

Financial services

CPS 230 — material service providers

Prudential Standard CPS 230 took effect 1 July 2025; material service-provider provisions — documented exit strategies, audit rights, ongoing performance oversight — become fully operational 1 July 2026. APRA has taken the position that AI vendors embedded in critical financial-services operations meet the material service-provider threshold where their failure would materially disrupt regulated operations. LLMs in customer communications, algorithmic credit systems and model-driven risk tools all sit within the CPS 230 perimeter. APRA has signalled direct supervisory engagement with AI suppliers, making vendor due diligence no longer solely a contractual matter.

Employers

Fair Work and discrimination law

No AI-specific employment statute exists, but the Fair Work Act 2009 (Cth), the Disability Discrimination Act 1992 (Cth) and state anti-discrimination frameworks apply to algorithmic decisions affecting workers and applicants. Vicarious liability for biased screening outcomes attaches to effect, not intent. In the landmark US case of Mobley v Workday, the court certified a collective action against the operator of an AI screening system on the basis that the operator relationship gave rise to liability independent of the end-user employer. Human oversight of AI screening and performance tools is fast becoming an objective standard for responsible deployment.

EU market participants

EU AI Act — high-risk obligations

High-risk obligations under Regulation (EU) 2024/1689 apply from 2 August 2026. The Act follows GDPR's extraterritorial model: Australian providers and deployers placing systems on the EU market, or whose outputs are used within the EU, are in scope regardless of where the system is developed or hosted. High-risk classifications cover employment screening, credit decisioning, education, biometric identification and law enforcement-adjacent uses. Penalties reach EUR 35 million or 7% of global annual turnover, whichever is higher. EU procurement processes are already testing conformity requirements; Australian vendors supplying EU public-sector clients are being assessed against the Act whether or not they have taken steps to comply.

A governance system, not just a document.

AI governance only works if your team actually uses it. We build systems designed for ongoing operation: an inventory, a policy, monitored contracts, and a reporting cadence.

  1. Inventory

    Map every AI system in your organisation.

    Identify what each AI system does, what data it processes, who is affected, and which regulatory regime applies. The inventory is the foundation — you cannot govern what you have not mapped.

  2. Classify

    Score systems against applicable risk tiers.

    Each system is scored against the Voluntary AI Safety Standard guardrails and EU AI Act risk tiers. High-risk and prohibited-use cases are identified and separated from lower-risk productivity tooling.

  3. Document

    Draft the policy and impact assessments.

    Draft the AI policy tiered for employee productivity tools, customer-facing systems, and high-risk applications. Impact assessments — PIAs and algorithmic assessments — are produced in working, auditable form alongside board governance documentation.

  4. Contracts

    Uplift vendor agreements to close the gaps.

    Identify AI vendor agreements that lack model-change notices, audit rights, or data exit provisions. Gaps are prioritised by risk exposure and contract term, and negotiating positions are prepared for each.

  5. Embed

    Stand up monitoring and reporting cadence.

    Standing board reporting, a quarterly review cadence, and incident response integration with your NDB programme. Governance that runs; not a document that sits in a drawer.

What in-house counsel asks first.

The questions we field at the first call. If yours isn't here, ask us.

  • We already have an AI policy. Do we need more?

    An AI policy is one document. Governance is a system: an inventory that maps AI to its risk, impact assessments for high-risk applications, oversight protocols, vendor contracts that include audit rights, and a monitoring cadence. Most organisations have the policy; few have the system. Complying with the automated decision-making obligations, CPS 230, and the EU AI Act each requires more than a documented policy; they require a working system.

  • What triggers the Privacy Act automated decision-making obligations?

    APP 1.7 applies to entities using personal information in automated or semi-automated decisions that have a significant effect on an individual's rights, opportunities, or interests. The definition captures rule-based logic as well as machine-learning systems. Significant effect is not limited to adverse outcomes; credit approvals, employment recommendations, and content-access decisions are all within scope. The obligation is to disclose the types of data used and the categories of decisions made, in your privacy policy. Commencement: 10 December 2026.

  • Does the EU AI Act apply to an Australian company?

    It does if your company places an AI system on the EU market, uses an AI system whose outputs are used in the EU, or has EU customers who are affected by an AI system's decisions. The high-risk obligations (employment screening, credit, education, biometric categorisation) applied from 2 August 2026. The extraterritorial scope mirrors the GDPR model.

    The GDPR comparison is instructive. The GDPR technically applied to very few Australian companies; only those with an EU establishment or that systematically target EU residents fell within scope. Despite that, GDPR concepts were proactively imported into Australian practice: the Privacy Act was subsequently reformed with GDPR principles in mind, and GDPR-aligned documentation became a benchmark that clients, auditors, and procurement processes reached for. The EU AI Act is following the same path. Whether or not your organisation has EU exposure, its framework (risk tiering, algorithmic impact assessments, human oversight requirements, conformity documentation) is already the reference standard that Australian regulators and large procurers are adopting. Building to that standard now makes sense regardless.

  • How long does a governance engagement take?

    An initial AI governance engagement (inventory, risk classification, AI policy, and priority impact assessments) typically runs three to six weeks. Vendor contract uplift is scoped separately; timing depends on which agreements need renegotiation and how cooperative the suppliers are.

  • What does vendor contract uplift involve?

    Most SaaS AI vendor agreements (Copilot, Workday, Salesforce Einstein, and their equivalents) are silent on model change, training data usage, data exit, and audit rights. Uplift involves reviewing what your current agreement actually permits the vendor to do with your data, identifying which gaps create material risk under CPS 230 or the Privacy Act, and negotiating the key provisions: model-change notice periods, prohibition on training on your data without consent, portability and exit provisions, audit rights, and indemnity scope for AI-generated outputs.

Master your AI deployment

Tell us where your organisation is in its AI rollout and the governance gaps you are aware of. We will come back with a practical assessment of what needs attention first .

Quick scoping call

We map the AI systems you are running and the regulatory exposure those systems create. Typically one call followed by a short written summary.

Robust AI Governance

We can deliver a fixed-fee/scope engagement delivering the inventory, policy, impact assessments, and vendor contract review your organisation needs.

Fast pricing

Online Statement of Work once we've agreed to help. Quick summary of the work and the estimate. Don't sign anything until you've seen ours.