Practical AI governance guides, regulatory analysis, and research, for enterprise leaders, businesses, and individuals navigating the AI landscape.
Boards, APRA, ASIC, controls & programmes
Start herePrivacy Act, ACCC consumer law, AI6 basics
Start hereFounder guide, investor due diligence, EU AI Act
Start hereYour rights, Right to Disconnect, AI at work
Start hereGoogle has announced autonomous search agents that research, monitor, and act on behalf of users. OpenAI and Anthropic are building similar capabilities. These AI agents create new governance questions for every organisation: what happens when AI agents make decisions using your data, your products, or your services, and what governance do the agents themselves need?
Read article2026
On 7 May 2026, EU lawmakers reached provisional agreement to delay key AI Act deadlines. High-risk AI obligations pushed to December 2027 and August 2028. Transparency obligations still apply from August 2026. A new prohibition on non-consensual intimate imagery was added. What changed, what didn't, and why organisations pausing their compliance work will be massively behind when the new deadlines arrive.
2026
On 14 May 2026, Colorado Governor Polis signed SB 189, delaying the Colorado AI Act effective date from 30 June 2026 to 1 January 2027 and significantly scaling back its original requirements. A federal court paused enforcement in April after xAI's lawsuit. The DOJ intervened. This is the first major casualty of Trump's December 2025 Executive Order targeting state AI regulation, and a sign of what's coming for other states.
2026
What Agent 365 going GA, GPT-5.5, Project Glasswing and Gemini Spark change for enterprise AI governance: agent registries, shadow AI exposure, and the controls that matter.
2026
Microsoft 365 Copilot is now embedded in Word, Excel, Outlook, Teams, and SharePoint across most enterprises. Copilot operates within Microsoft 365 boundaries and your data is not used to train foundation models, but that does not mean it is safe by default. The governance controls organisations need before allowing Copilot to access company data, and what APRA and ASIC expect from regulated entities.
2026
ChatGPT Enterprise and Claude Enterprise provide stronger data protection than consumer versions. OpenAI surpassed $25 billion in annualised revenue. Anthropic is approaching $19 billion. Both are now standard enterprise tools, but their governance controls work differently from Microsoft Copilot. What the differences mean, how to deploy them safely, and what to address in vendor contracts.
2026
Australian non-profits are adopting AI at pace, from donor management to service delivery to fundraising automation. The Australian Government's National AI Centre released Guidance for AI Adoption (AI6) in October 2025 with specific resources for the social sector. ACNC governance standards apply. The Privacy Act ADM transparency obligation hits in December 2026. The practical guide for charity boards, CEOs, and operations leaders.
2026
The National AI Plan released on 2 December 2025 is Australia's most comprehensive AI policy statement. It confirmed the voluntary approach, established the AI Safety Institute, consolidated SME and non-profit support, and launched the AI Accelerator funding program. What it means in practice for businesses, non-profits, government agencies, and the workforce, and how to align your AI governance with the plan's direction.
2026
The Digital Transformation Agency published AI Model Clauses for use across the Australian Public Service. With the APS being a major purchaser of AI products and services, and Microsoft committing A$18B to Australia AI infrastructure through 2029, these clauses are setting market norms. What the model clauses require, how they affect AI vendors selling to government, and what private sector buyers can learn from them.
2026
Most organisations end up with multiple AI tools, Microsoft Copilot is embedded by default, employees use ChatGPT and Claude personally, and Google Workspace AI features arrive automatically for Google customers. Understanding the differences matters for procurement, governance, and security. The practical comparison and what to consider when choosing.
2026
Australian AI governance is being built in real time across government bodies, standards committees, professional associations, and consultancies. For risk professionals who want to actively contribute, not just consume, there are five concrete pathways with specific entry points, contact bodies, and named individuals. The practical guide to building influence in Australian AI policy and risk management.
2026
APRA's 30 April 2026 industry letter set a specific expectation: regulated entities should use globally recognised control frameworks and apply integrated assurance across cyber security, data governance, model performance, operational resilience, privacy, and conduct risks. For risk practitioners building AI governance programs, the term 'integrated assurance' is doing more work than most boards realise. What it actually means, where ISO standards fit, and why frontier AI systems break the static assurance model entirely.
2026
AI startups are raising at unprecedented valuations on capability claims that often don't survive technical due diligence. The checklist for VCs, PE acquirers, and corporate development teams investing in or acquiring AI startups in 2026, covering model claims verification, training data provenance, IP exposure, regulatory readiness, and the specific governance maturity expected at each stage.
2026
Enterprise AI procurement in 2026 is no longer about choosing the best demo. It's about evaluating vendors against operational, regulatory, security, and governance criteria that did not exist 18 months ago. The structured guide for procurement teams, technology leaders, and the executives signing off on AI vendor commitments, covering RFP design, vendor evaluation, contract terms, and ongoing management.
2026
Subjective vendor evaluation produces inconsistent decisions and disappointing outcomes. The structured scorecard framework for evaluating AI vendors quantitatively, covering 40+ criteria across technical capability, governance maturity, security posture, regulatory compliance, commercial terms, and operational continuity. Designed for procurement teams running parallel evaluations and for enterprise architects standardising vendor selection.
2026
Frontier AI models, Claude, GPT, Gemini, Mythos, have capabilities that traditional vendor evaluation does not assess. Static benchmark scores miss the capability shifts between model updates. The structured approach to assessing what a frontier model can actually do for your use case, how its capabilities are changing, and what dynamic assurance looks like in practice.
2026
Private equity firms now hold AI exposure across portfolios that traditional governance frameworks did not anticipate. Operating partners need a standard playbook for assessing portfolio company AI readiness, embedding governance during the hold period, and positioning companies for exit. The structured approach for PE operating partners, value creation teams, and portfolio company executives.
2026
Financial services is the most heavily regulated sector for AI deployment. APRA, ASIC, FCA, MAS, the Federal Reserve, and the OCC have each issued specific AI expectations in 2024-2026. The complete guide for AI governance in banking, insurance, asset management, and capital markets, covering prudential expectations, model risk management, conduct obligations, and operational resilience.
2026
Healthcare AI sits at the intersection of medical device regulation, health information privacy, clinical safety, and emerging AI-specific obligations. The complete guide for hospitals, health systems, medical device manufacturers, digital health companies, and the clinicians making AI deployment decisions, covering FDA, TGA, MDR, HIPAA, the Privacy Act, and clinical governance.
2026
The legal profession is using AI faster than its professional conduct rules anticipated. Law societies, bar associations, and courts in Australia, the US, UK, and Singapore have all issued AI guidance in 2024-2026, and the rules now have teeth. The complete guide for law firms, in-house legal teams, and individual practitioners, covering professional conduct obligations, court filing requirements, client confidentiality, billing, and the practical AI operating model.
2026
Educational institutions are navigating AI use across teaching, learning, assessment, research, and administration simultaneously. The complete guide for universities, schools, and EdTech providers, covering academic integrity policy, student and staff data privacy, pedagogical integration, research ethics, and the institutional governance model that holds it together.
2026
Public sector AI deployment carries the highest accountability burden. Citizens are not customers, they cannot exit the relationship. Decisions affect rights, benefits, and obligations. The complete guide for government departments, agencies, statutory bodies, and the contractors building public sector AI, covering the AU GovAI initiative, US Federal AI Use Cases, UK Government AI Playbook, EU AI Act public sector obligations, and the operating model that satisfies all of them.
2026
Manufacturing AI sits at the intersection of machine safety regulation, product liability, workforce health and safety, and quality systems. The complete guide for manufacturers, industrial operators, and the engineers and operations leaders embedding AI in plant operations, covering EU Machinery Regulation, Product Liability Directive, ISO standards, and the operating model for AI in production environments.
2026
Retail AI sits at the intersection of consumer protection law, privacy regulation, and competition law. The complete guide for retailers, marketplaces, and DTC brands deploying personalisation, dynamic pricing, recommendation engines, fraud detection, and supply chain AI, covering ACCC, CMA, FTC, and EU consumer protection obligations.