Practical AI governance guides, regulatory analysis, and research, for enterprise leaders, businesses, and individuals navigating the AI landscape.
Boards, APRA, ASIC, controls & programmes
Start herePrivacy Act, ACCC consumer law, AI6 basics
Start hereFounder guide, investor due diligence, EU AI Act
Start hereYour rights, Right to Disconnect, AI at work
Start hereTechnology companies face two intersecting AI governance obligations: governing the AI you use internally, and governing the AI you embed in products sold to customers. The complete guide for SaaS providers, platform companies, and B2B software vendors, covering ISO 42001 readiness, EU AI Act provider obligations, enterprise customer expectations, and the product-level AI governance that scales.
Read article2026
Telecommunications carriers operate critical infrastructure that AI is increasingly embedded into. The complete guide for telco operators, ISPs, and connectivity providers, covering network operations AI, customer-facing AI, regulatory obligations under the Telecommunications Act, SoCI Act, and the security obligations that come with critical infrastructure designation.
2026
Energy and utilities are deploying AI across generation, transmission, distribution, and customer-facing operations under critical infrastructure obligations that exceed most other sectors. The complete guide for energy companies, network operators, retailers, and renewables developers, covering AEMO, AER, NERC, FERC, and ENTSO-E expectations, plus the critical infrastructure security frameworks.
2026
The three hyperscalers, AWS, Microsoft Azure, and Google Cloud, are now the largest AI vendors by revenue and the default AI procurement choice for most enterprises. The complete guide to engaging hyperscaler AI responsibly, covering data residency, foundation model access (Bedrock, Azure OpenAI, Vertex), governance documentation, audit rights, and the specific contract terms that matter.
2026
Engaging foundation model providers directly, rather than through hyperscaler marketplaces, gives access to the newest capabilities first but requires distinct governance work. The complete guide to direct engagement with OpenAI, Anthropic, and Google DeepMind, covering enterprise tier offerings, contractual terms, data handling, capability access, and the trade-offs versus hyperscaler-mediated access.
2026
AI startups frequently offer capabilities that hyperscalers and incumbents do not match, but engaging them as an enterprise buyer requires governance work that standard procurement does not anticipate. The complete guide for technology buyers, procurement teams, and innovation leaders engaging early-stage AI vendors, covering due diligence, contract terms, financial stability assessment, and exit planning.
2026
Most AI vendor procurement failures show warning signs in due diligence that buyers either miss or rationalise away. The complete catalogue of AI vendor red flags, covering commercial signals, technical signals, governance signals, and behavioural signals that should trigger deeper investigation or procurement stop.
2026
On 30 April 2026 APRA wrote to every regulated entity with findings from its late-2025 AI deep-dive: boards lack the literacy to challenge AI risk, assurance is not keeping pace, and identity systems haven't adjusted to AI agents. The letter names minimum board expectations and flags enforcement. Here is what it says and what to do.
2026
The first instalment of our Australian regulator watch: ASIC's 8 May letter urging licensees to harden cyber resilience against frontier AI threats, the OAIC's progressive guidance ahead of the 10 December automated decision-making deadline, and APRA's April expectations letter. What changed, who is affected, and what to do this quarter.
2026
The second instalment of our regulator watch: APRA's CPS 230 transition has closed and the standard now applies in full, the EU Digital Omnibus has been formally adopted by both the European Parliament and the Council, and the OAIC's automated decision-making guidance is still pending. What changed, who it touches, and what to do in the next 30 days.
2026
The transition for pre-existing material service provider contracts has closed and the April amendments commenced. What applies now and what APRA examiners ask for first.
2026
A December executive order, a litigation task force, a stayed and replaced Colorado law, and state statutes already in force in Texas and California. The US AI rulebook in mid-2026 is a live constitutional contest, and the durable compliance core underneath it is smaller and clearer than the noise suggests.
2026
The Digital Omnibus on AI was provisionally agreed on 7 May 2026, but it has not been adopted or published. Until the Official Journal says otherwise, 2 August 2026 remains the legal date for high-risk obligations. Here is the procedural state of play and what to do with it.
2026
On 12 February 2026, New South Wales became the first Australian jurisdiction to impose AI-specific duties on employers under workplace health and safety law. The Work Health and Safety Amendment (Digital Work Systems) Act 2026 requires PCBUs to ensure AI systems used to allocate work do not put worker health and safety at risk, and gives unions the right to inspect those systems. Here is what the law says, when it applies, and what organisations need to do.
2026
Colorado's landmark AI Act (SB 24-205) is gone. Governor Polis signed SB 26-189 on 14 May 2026, fully repealing and replacing it with a disclosure-focused framework effective 1 January 2027. The original high-risk AI regime, with its duty of care, risk management programmes, and impact assessments, no longer exists. Here is what the replacement law requires, what it drops, and what it means for organisations operating across US states.
2026
The Digital Omnibus deferred the high-risk rules, not this. Chatbot disclosure, AI content labelling and deepfake duties apply from 2 Aug 2026. The day-one checklist.
2026
On 2 June 2026, President Trump signed a new AI executive order, 'Promoting Advanced Artificial Intelligence Innovation and Security', adding cybersecurity mandates and a voluntary frontier model security framework. It is the third major federal AI executive action since January 2025. Here is what it does, how it fits with the December 2025 preemption order, and what it means for organisations with US AI exposure.
2026
The Model Context Protocol has become the de facto standard for connecting AI agents to enterprise systems. Most Australian organisations are already using it. Almost none are governing it.
2026
APRA told boards to hold an AI inventory, prove effective challenge and stop relying on vendor summaries. Every expectation unpacked with the actions that satisfy it.
2026
AI agents are operating inside enterprise systems with access that no individual employee would ever be granted. The governance frameworks designed for human access have not been extended to nonhuman actors. APRA has named this gap explicitly.
2026
You cannot govern what you cannot see. Three separate Australian regulatory frameworks now require organisations to maintain a documented inventory of their AI tools and use cases. Most organisations do not have one.
2026
A practical guide to the AI governance tools and dashboards available in 2026, what Credo AI, Microsoft Agent 365, and the security platforms actually offer boards, where the gaps are, and what a genuinely board-readable AI governance view needs to show.
2026
Australia's Security of Critical Infrastructure Act requires responsible entities to manage material risks through a board-approved risk management program. AI systems and AI vendors now sit squarely inside that obligation. Here is how the CIRMP, the four hazard vectors, and the annual board attestation apply to AI.