Australia’s AI policy is not a U-turn. It’s a case of two debates colliding.
AI may be new technology, but the boardroom questions remain familiar: who is accountable, what can go wrong, and how do we know the controls work?
Canberra’s signals on artificial intelligence have been unusually difficult to read. But the apparent contradiction between relying on existing law and reaching for new AI standards disguises a more important change: the technology is beginning to do things, not merely say things. This should change the conversation in Australian boardrooms.
For Australian directors trying to work out what they are supposed to make of artificial intelligence, the past nine months have not been especially tidy.
In December, the federal government published its National AI Plan and put existing law at the centre of its regulatory approach. Privacy, competition, consumer, workplace and sector regulation would continue to do much of the work. Businesses were encouraged to adopt AI responsibly, but the government did not proceed with the broad mandatory guardrails that had dominated the preceding policy debate (Department of Industry, Science and Resources [DISR], 2025).
By July, the Prime Minister was at Sydney University announcing Australian Standards for AI and a new Office of AI. The first rules outlined by the government were directed heavily at the physical infrastructure behind AI: the large data centres, electricity and water use among them. They were not a new general code governing every corporate use of artificial intelligence. Even so, the language had plainly shifted. Legislation was back in the conversation (Prime Minister of Australia, 2026a).
Then, this week, came an altogether less theoretical development.
At a press conference in New York, the Prime Minister disclosed that an OpenAI agent had gained unauthorised access in June to the public-facing Medicare Statistics Reporting Service. It had accessed both public and non-public files. The government advises no personal information is believed to have been accessed at this stage, and the forensic investigation is continuing (Prime Minister of Australia, 2026b).
Put those events side by side and it is tempting to see a government executing an abrupt turn: existing laws will do; perhaps they will not; now an AI agent has crossed a government boundary and the mood has changed again.
There has been some movement in policy, but I think this reading misses a more interesting story.
Australia has really been dealing with two separate questions.
The first is a public-policy question: how much new AI-specific law does the country need?
The second is a governance question: are organisations equipped to control what the technology can already do?
The first remains unsettled. On the second, the evidence is harder to ignore.
The distinction I am making is between law and governance. A view that Australia does not need an omnibus AI Act addresses whether new AI-specific legislation is required; it does not establish that regulators already have AI risk in-hand or that an organisation’s existing governance arrangements are adequate.
The National AI Plan did not say that relying on existing law meant regulators already had AI risk in hand or that organisations’ existing governance arrangements were adequate. Instead, it explicitly placed responsibility on businesses to adopt AI responsibly and maintain governance, stewardship and compliance with existing law (DISR, 2025).
Whether existing law can attach liability to an organisation after something goes wrong tells a board very little about whether the organisation has the controls necessary to stop it going wrong in the first place.
And it is the second problem that has moved quickly during 2026.
In 2026, AI is becoming more capable and more consequential
In April, the Australian Signals Directorate began warning organisations that improvements in frontier AI were changing the economics of cyber-attack. Its later assessment was carefully qualified as these systems still have limits, but the direction was clear. Capabilities were improving, vulnerability discovery and exploitation could be accelerated, and organisations should assume increasingly capable tools would become more widely accessible (Australian Signals Directorate [ASD], 2026a, 2026b).
A few weeks later, APRA published the results of work across large banks, insurers and superannuation funds. The regulator found AI adoption was moving ahead of governance, assurance and operational resilience. More pointedly, it found many boards were still developing the literacy required to challenge AI risks and were relying too heavily on vendor presentations and summaries (Australian Prudential Regulation Authority [APRA], 2026).
APRA's writ does not extend to hospitals, universities or most Australian companies.
Nevertheless, its observations do travel well and can be applied to these sectors nonetheless.
Walk into almost any boardroom and the AI conversation will contain a mixture of genuine strategic opportunity, pressure not to fall behind, impressive demonstrations from suppliers and a level of technical uncertainty directors do not disguise.
None of that is particularly alarming. Boards routinely govern things they do not understand at an engineering level.
The difficulty is that the nature of the technology is changing just as organisations are becoming comfortable with the first generation of it.
The early governance discussion around generative AI was mostly about what a model might produce. Could it hallucinate? Could somebody put confidential data into it? Was the output biased? Could an employee rely on it? Who owned what it generated?
Those questions have not disappeared and are still relevant today.
But a system that drafts a board paper and a system that can enter another system, retrieve information, alter a record or send a communication are not variations of the same governance problem.
One generates content.
The other has been given some measure of authority to act.
That is why the Medicare incident is more instructive than its immediate consequences suggest.
On the information disclosed so far, this was not a conventional criminal intrusion and it was apparently not a breach of Australians' individual Medicare records. An AI agent undertaking research gained access to files it was not authorised to access. Investigation is still under way, so sweeping conclusions would be premature. I am sure much is yet to be written on this as a cyber security incident, and government's response, rather than an “AI incident.” (Prime Minister of Australia, 2026b)
Yet from a director's perspective the interesting question is already apparent.
Not: what answer did the AI produce?
But: what was did the AI agent do while trying to produce an answer?
This leads to a different conversation.
We have been governing the model when we should be governing the authority
The technology industry has supplied an increasingly exotic vocabulary for artificial intelligence. Boards have been offered taxonomies of models, foundation models, large language models, generative AI, frontier AI and now agentic AI.
Some of it is necessary.
But there is a simpler way of thinking about the governance problem.
Take the same underlying model and put it to three different uses.
Ask it to improve the prose in a non-sensitive internal memorandum and the consequences of failure are limited. Someone reads the draft and changes it.
Put it inside a recruitment process where it recommends which candidates should proceed and a different set of issues appears: personal information, discrimination, explainability, the design of human review and the consequences for the people being assessed.
Then give an AI agent credentials allowing it to enter a production system, update a record and send a message externally.
The underlying technology may be related. The governance problem is not.
What matters is the combination of the use, the information available to the system, the consequence and the permissions it has been given.
There is a further distinction boards may need to become comfortable with: authority is approved in one place and access is often granted somewhere else.
A project may be approved on the basis that an AI agent can read certain information and perform a tightly defined task. But that authority is ultimately translated into service accounts, machine identities, API permissions and access privileges deep inside the technology environment. Those permissions can change over time. New integrations are added. Products acquire new functionality. Accounts accumulate privileges.
The governance risk is therefore not only that an AI system might behave unexpectedly. It is that what the system is technically capable of reaching can gradually become wider than what the organisation ever intended to authorise.
That suggests a rather practical control: periodically reconcile the two. What was the AI approved to do, what can it actually do today, and do those answers still match?
It is at this point that I will suggest some familiar assurances are becoming less reassuring.
“There's a human in the loop” is a good example.
It can describe meaningful supervision. It can also describe somebody clicking approve after a system has done nearly all of the substantive work.
Healthcare makes the distinction easy to see. A clinician may remain formally accountable for reviewing an AI-generated note. Whether that constitutes an effective control depends on the clinical workflow, the volume of output, the time available for checking and how readily a plausible but incorrect statement can be detected.
The same principle applies to a credit decision, recruitment recommendation, fraud alert or customer communication.
A human’s presence in the workflow does not, by itself, make the human’s presence effective.
The law is beginning to recognise some of this complexity. From December 10, new Privacy Act requirements will require covered APP entities to disclose specified uses of personal information in automated decision-making arrangements where the statutory tests are met. The provisions do not make every AI-assisted decision unlawful or subject to a new approval regime. Their significance is more prosaic: organisations increasingly need to know where software is materially involved in consequential decisions in the first place (Office of the Australian Information Commissioner [OAIC], 2025).
This might be harder than it sounds.
The AI most boards should worry about first may be the AI nobody approved
Board papers tend to focus on initiatives.
There is an AI strategy. There are pilots. There is a steering committee. A responsible-AI policy has been drafted. Perhaps a handful of approved products appear on a register.
It all looks quite orderly.
The organisation itself may be considerably less so.
AI is arriving through software upgrades, productivity suites, specialist platforms and suppliers. Staff are experimenting with public tools. Business units are buying cloud products. Researchers and clinicians may be testing applications for perfectly sensible reasons. Outsourced providers may be using AI somewhere in delivering their service.
Some of this will be material. Much of it will not be.
The governance task is not to build an encyclopaedia of every interaction with a chatbot. That would produce bureaucracy rather than assurance.
The task is to know where the material exposures sit.
Which AI systems touch sensitive or commercially important data? Which influence decisions about customers, patients or employees? Which are connected to production systems? Which can communicate outside the organisation? Which have been given permission to act?
And, as OpenAI is learning, who knows when one of those things changes?
There is another category that may prove just as troublesome: AI that was properly approved, but has changed since.
Most governance systems are good at approval events. A project goes through a risk assessment, privacy review, cyber review and procurement process. The decision is recorded and implementation proceeds.
The difficulty with AI is that approval can have a surprisingly short half-life. The model changes. The vendor adds a capability. A new data source is connected. A service account receives another permission. A tool that originally drafted material is later allowed to send it.
None of those changes necessarily looks dramatic in isolation. Collectively, they can move the system outside the operating envelope the organisation originally approved.
That is why lifecycle governance matters. The governance question cannot simply be “Was this AI approved?” It needs to be “Does the AI we have today still resemble the AI, including the authority, we approved?”
This is one reason AI governance cannot be solved by writing an AI policy and sending it to staff.
Modern enterprise software does not wait for the board's annual policy review before acquiring new functionality.
Neither do AI suppliers.
In health, the TGA's treatment of digital scribes provides a useful illustration. The regulatory position depends on intended purpose and functionality. A product used to record and translate a consultation into notes is not necessarily treated in the same way as software intended to diagnose, predict or recommend treatment (Therapeutic Goods Administration [TGA], 2026).
For a procurement team, that means the answer obtained from a vendor six months ago may cease to be sufficient if the product changes what it does.
This is not unique to healthcare. It is simply a particularly clear example of why AI approval cannot always be a one-off event.
The supplier problem is becoming a board problem
APRA's finding about reliance on vendor presentations deserves more attention than it has received (APRA, 2026).
AI is unusually easy to demonstrate well.
A supplier can show a system answering questions, producing a document in seconds or undertaking an activity that previously consumed hours of human time. In a boardroom, the strategic opportunity is immediately visible.
The operating risk is not.
That appears later, when the system is connected to data, embedded into workflows, changed by the supplier, exposed to real users and dependent on other services further down the technology chain.
I would not expect directors to review AI contracts clause by clause. I would expect management to know what the important clauses say.
Where does the information go? Can it be used for another purpose? Which other providers are involved? What must the supplier tell us when its model changes? What constitutes a reportable incident under the contract? Who receives that notification at two o'clock on a Sunday morning? How quickly can access be suspended? What happens to our data if we leave?
These are not particularly futuristic questions.
In fact, I have formed the view that one of the striking things about AI governance is how quickly the conversation returns to old-fashioned disciplines: procurement, access control, information governance, clinical safety, operational resilience and contract management.
The novelty sits in the technology.
Most of the governance does not.
Resist the urge to build an AI bureaucracy
The natural institutional response to a new risk is to create a new committee.
Sometimes that will be justified. AI programs of sufficient scale and complexity need concentrated expertise.
But creating a parallel governance universe for AI can make the problem worse.
An AI application influencing patient care is still a clinical-governance issue. AI processing sensitive information is still a privacy issue. An agent connecting to critical infrastructure is still a cyber and operational-resilience issue. A $20 million AI program promising productivity benefits is still a capital-allocation and benefits-realisation issue.
The organisation does need a way of joining those perspectives together.
It does not necessarily need to remove AI from the governance systems that already carry accountability for them.
The AICD and Human Technology Institute's updated guidance points in a similar direction: this is becoming an ordinary board governance responsibility even as the technology itself becomes more sophisticated (Australian Institute of Company Directors [AICD] & Human Technology Institute [HTI], 2026).
This is my more reassuring interpretation of recent events.
Directors are not being asked to turn themselves into computer scientists.
They are being asked to apply familiar governance instincts to a less familiar form of delegated capability.
The productivity story deserves the same scepticism as the risk story
There is another side to this.
Anxious boards can over-govern AI. Enthusiastic boards can under-question its economics.
Both make the same mistake: treating AI as exceptional.
The business case for generative AI is often presented through time saved. A task took 40 minutes; it now takes 10. Multiply 30 minutes by the number of employees and working days and a large productivity number appears.
Possibly.
But a theoretical time saving is not a financial return.
Did labour cost fall? Did output rise? Was service improved? Did the employee spend the released time doing something more valuable? What additional checking was required? What did integration, licensing, training and governance cost?
In health, early evidence on AI scribes illustrates the point neatly. A randomised study involving 238 physicians found one of two scribe products reduced time spent writing notes while the other did not produce a statistically significant reduction. Actual use was also much lower than a simple “available to clinicians” measure might imply (Lukac et al., 2025).
It is useful evidence but it does not grant a licence to multiply an assumed saving across the clinical workforce.
Boards should be just as suspicious of an AI business case based on a demonstration as they are of AI risk assurance based on the same demonstration.
Good governance is not there to impede adoption.
It is what allows an organisation to tell the difference between adoption and value.
So did Canberra change its mind?
Not in the simple way the headlines suggest.
The Commonwealth's December position was principally about how Australia should regulate AI. It chose to rely heavily on existing legal and regulatory structures while keeping the system under review (DISR, 2025).
The July announcement added proposed Australian Standards for AI, although the government's initial description focused strongly on data-centre infrastructure rather than setting out a comprehensive new regime for organisational AI use (Prime Minister of Australia, 2026a).
Meanwhile, the operating environment has been changing beneath both positions. AI capabilities have improved. Security agencies have adjusted their advice. Regulators have started seeing how organisations are actually governing the technology. AI is being embedded into ordinary software. And agents are beginning to cross the line between generating an answer and undertaking a task.
A policy framework responding to those developments will inevitably look less settled than one governing a mature technology.
I do not believe this inconsistency is something directors should spend too much time worrying about.
The more consequential inconsistency would be for a board to recognise that AI has changed materially while leaving its own assurance arrangements untouched.
Suppose management brings the board an AI update next month. It describes an AI policy, responsible-use principles, a governance committee, several promising pilots and assurances that humans remain accountable.
All sensible.
Now ask management to put one page on the table showing the material AI systems in operation; what data and systems they are authorised to reach; what their technical permissions actually allow them to reach; whether they only recommend or can also act; the person accountable for each; the principal supplier dependencies; the events that would trigger escalation; and the evidence of benefit since approval.
If that page can be produced readily, the organisation probably has the beginnings of a governance system rather than merely an AI policy.
If it cannot, I am going to suggest the absence of a new Commonwealth AI Act is probably the organisation’s least important worry.
The story of Australian AI in 2026 is not that Canberra decided artificial intelligence was safe and then discovered it was dangerous. It is that the regulatory debate and operational reality are finally catching up with each other.
For boards, the implication is less dramatic than the headlines.
But it is more demanding.
The relevant question is no longer simply what AI the organisation is using.
It is what authority has been handed to AI and whether anybody can show that authority is still properly controlled.
References
Australian Institute of Company Directors & Human Technology Institute. (2026). A director’s guide to AI governance (Version 2). https://www.aicd.com.au/news-media/research-and-reports/a-directors-guide-to-ai-governance.html
Australian Prudential Regulation Authority. (2026, April 30). APRA letter to industry on artificial intelligence (AI).https://www.apra.gov.au/news-and-publications/apra-letter-industry-artificial-intelligence-ai
Australian Signals Directorate. (2026a, April 30). Frontier AI models and their impact on cyber security.https://www.cyber.gov.au/about-us/view-all-content/news/frontier-models-and-their-impact-on-cyber-security-update
Australian Signals Directorate. (2026b, August 5). Frontier AI cyber threat considerations for boards of directors. https://www.cyber.gov.au/business-government/protecting-business-leaders/cyber-security-for-business-leaders/frontier-ai-cyber-threat-considerations-for-boards-of-directors
Department of Industry, Science and Resources. (2025, December 2). National AI Plan.https://www.industry.gov.au/publications/national-ai-plan
Lukac, P. J., Turner, W., Vangala, S., Chin, A. T., Khalili, J., Shih, Y.-C. T., Sarkisian, C., Cheng, E. M., & Mafi, J. N. (2025). Ambient AI scribes in clinical practice: A randomized trial. NEJM AI, 2(12). https://doi.org/10.1056/aioa2501000
Office of the Australian Information Commissioner. (2025, October 3). Chapter 1: APP 1—Open and transparent management of personal information. https://www.oaic.gov.au/privacy/australian-privacy-principles/australian-privacy-principles-guidelines/chapter-1-app-1-open-and-transparent-management-of-personal-information
Prime Minister of Australia. (2026a, July 15). AI in Australia’s interests [Media release]. https://www.pm.gov.au/media/ai-australias-interests
Prime Minister of Australia. (2026b, September 24). Press conference—New York [Transcript]. https://www.pm.gov.au/media/press-conference-new-york
Therapeutic Goods Administration. (2026, January 30). Digital scribes.https://www.tga.gov.au/products/medical-devices/software-and-artificial-intelligence-ai/overview/types-software-based-medical-devices/digital-scribes