AI Governance
The rules arrive in 2027. The evidence should already exist.
What is coming
Mandatory is no longer a rumour.
In July 2026 the Australian Government announced the Australian Standards for AI: a single, mandatory framework to be legislated in early 2027, coordinated by a new Office of AI, with enforcement staged through 2028. The signalled shape reaches every business that uses AI: a current register of the AI in use and the data it touches, named accountable owners, impact assessments, audit trails and incident reporting, alongside consent rules for training on Australian creative work. And the laws that already exist, privacy, consumer, anti-discrimination, keep applying to AI today. The detail will move before Parliament settles it. The direction will not.
What we do
Governance as engineering, not paperwork.
Most firms entering this market will sell you policy documents. We operate production AI platforms under exactly the disciplines the Standards will demand: deterministic calculation behind every reported number, citation-or-reject evidence gates, adversarial review, evaluation suites that block releases, immutable audit trails. Our governance work starts from readiness, a register of your AI, a risk classification and a gap report against the Standards trajectory and ISO 42001. It builds to a working management system with the engineering evidence behind it, and it can stand as continuous assurance: monitoring, adversarial testing and an annual attestation pack your board can sign against.
How we work
Inventory, classify, remediate, assure.
Every AI system in use across the business, the data each one touches, and a named accountable owner.
Each use risk-rated against the Standards trajectory, the six essential practices and ISO 42001, so effort lands where exposure lives.
Policy and engineering together: oversight points, provenance and consent trails, testing harnesses, logging, incident response.
Continuous monitoring, periodic adversarial testing and an annual evidence pack, kept current as the law finalises.
What you get
Evidence, not assurances.
Register
An AI system register with data flows, owners and a risk classification for every use.
Gap report
Where you stand against the Standards trajectory and ISO 42001, with a remediation roadmap in priority order.
Governance
Impact assessments, policies with named owners, vendor clauses and an incident runbook that has been rehearsed.
Evidence pack
Test results, provenance and consent registers, audit trails and model documentation, assembled for inspection.
Briefings
Board and team briefings that make the obligations concrete for the people who own them.
Assurance
Board reporting, annual attestation and ISO 42001 certification support as the regime hardens.
When the regulator asks how your AI is governed, the answer should already be a file, not a scramble.
Schedule a Consultation