White Paper on
AI Governance
Leadership insights and the Voluntary AI
Safety Standard in practice.
Sponsored by:
Governance Institute of Australia – White Paper on AI Governance 1
Contents
About the Governance Institute of Australia............................................................................3
About the National Artificial Intelligence Centre....................................................................3
Foreword............................................................................................................ 4
Introduction...................................................................................................... 13
Understanding AI in the Australian context..............................................................................13
1. AI ethics and governance....................................................................... 15
Deciding to use AI.....................................................................................................................16
RAI and AI ethical principles for decision-making........................................................17
2. AI risks and opportunities...................................................................... 26
AI risks...........................................................................................................................................27
Balancing AI opportunities with risk mitigation............................................................29
3. AI as an enabler........................................................................................ 31
Building the business case and value proposition for AI...........................................31
Open-source AI: opportunities and challenges.............................................................34
Organisational readiness for AI............................................................................................35
Best practices: taking a tailored approach
to meet organisational needs....................................................................... 37
Conclusion......................................................................................................... 39
Governance Institute of Australia – White Paper on AI Governance 2
About the Governance Institute of Australia
A national membership association, Governance Institute of Australia advocates for a community
of governance and risk management professionals, equipping over 8,000 members with the tools
to drive better governance within their organisation. We tailor our resources for members in the
listed, unlisted, not-for-profit and public sectors, and ensure our members’ voice is heard loudly.
As the only Australian provider of chartered governance accreditation, we offer a range of short
courses, certificates and postgraduate study to help further the knowledge and education of the
fast-growing governance and risk management profession. We run a strong program of thought
leadership, research projects and news publications and draw upon our membership of the Chartered
Governance Institute to monitor emerging global trends and challenges to ensure our members are
prepared. Our members know that governance is at the core of every organisation – and in these
tumultuous times, that good governance is more important than ever before.
About the National Artificial Intelligence Centre
The National AI Centre (NAIC) was established in 2021 to support and accelerate Australia’s AI industry.
It aims to help Australia become a global leader in developing and adopting safe and responsible
artificial intelligence. NAIC is doing this by: supporting AI adoption for small and medium businesses
by addressing barriers and challenges, growing an Australian AI industry, convening the AI ecosystem,
uplifting safe and responsible AI practice.
Governance Institute of Australia – White Paper on AI Governance 3
Foreword
In today’s rapidly evolving technological landscape, artificial intelligence (AI) stands at the forefront of
innovation, transforming industries and redefining the way we live and work. I am thrilled to present
this joint thought leadership report in collaboration with the National AI Centre, which delves into the
profound impact of AI and its potential to shape our future.
This report is a culmination of three specialist roundtables with key insights from industry experts,
and real-world case studies that highlight the transformative power of AI. It explores the latest trends,
challenges, and opportunities in AI, providing a comprehensive overview of how businesses can
harness this technology to drive growth, enhance efficiency and create value.
It also examines the critical role of governance in the ethical and responsible deployment of AI.
Good governance is essential to ensure that AI technologies are developed and used in ways that
are transparent, fair, and aligned with societal values. Our partnership with NAIC underscores our
commitment to not only advancing AI but doing so in a manner that upholds the highest standards of
integrity and accountability.
We are proud to share our knowledge and expertise through this report, aiming to inspire and guide
organisations on their AI journey.
I would like to extend my gratitude to the talented team of researchers, analysts, and contributors who
have made this report possible. Their hard work and dedication have resulted in a valuable resource
that we hope will serve as a catalyst for meaningful discussions and strategic initiatives in the AI
domain.
I would also like to sincerely thank our sponsored partners, Clayton Utz, Diligent and PKF for their
support in bringing this report to life and for their continued involvement with the work of the
Governance Institute of Australia.
As you explore the insights and findings within this report, I encourage you to think boldly about the
future of AI and its potential to drive positive change. Together, we can harness the power of AI to
create a smarter, more connected, and more prosperous world.
Thank you for your interest in our AI thought leadership report. We look forward to continuing this
journey of innovation and discovery with you.
Megan Motto FGIA FCG FAICD
Chief Executive of Governance Institute of Australia Ltd and of the Australian
Division of The Chartered Governance Institute
Governance Institute of Australia – White Paper on AI Governance 4
Sponsored by:
Clayton Utz
Proudly Australian and globally connected, Clayton Utz gives confident, innovative and incisive advice
beyond clear matters of law. We are one of Australia’s oldest and largest law firms, with offices in
six cities, nearly 200 partners, and provide a full range of legal services for large private sector and
government clients. At the forefront of legal innovation we blend technology with legal acumen to
provide inventive commercial solutions.
“The extraordinary advancements in AI technology in recent years have triggered a global conversation
about how AI is governed and regulated. Governance and regulation play a critical role in the safe
and responsible development and use of AI technologies - to build consumer trust and encourage
adoption. Applying appropriate governance, compliance and risk management to policies, projects and
procurement should be an essential component of any successful adoption of AI.”
Diligent
Diligent is the leading GRC SaaS company, empowering more than 1 million users and 700,000 board
members and leaders to make better decisions, faster. The Diligent One Platform helps organisations
connect their entire GRC practice - including governance, risk, compliance, audit and ESG - to bring
clarity to complex risk, stay ahead of regulatory changes and deliver impactful insights, in one
consolidated view.
“Continuous risk management and stakeholder engagement are key recommendations that resonate
deeply with our practices at Diligent. Ensuring that AI deployments are in line with organisational goals
and ethical considerations is essential for sustainable and responsible governance.”
PKF
PKF is part of a global network, where dynamic business advisors can belong, grow, and thrive.
In Australia, with more than 100 partners and 800 talented people, they deliver advisory, audit and
tax solutions to create powerful opportunities for their clients, their people and their communities.
A can do attitude & strong project management skills lie at the heart of any successful initiative & this
would equally apply to any move to use AI. Poor disciplines more broadly will lead to poor outcomes
which could be accelerated through technology such as AI. Similarly, a strong data governance
framework should enhance & secure productivity & innovation gains from responsible use of AI—not
forgetting the overriding responsibility of quality control, quality management & earning the right to rely
on its outcomes.
Governance Institute of Australia – White Paper on AI Governance 5
List of Roundtable participants:
AI ethics and governance
Letecia Allen, Senior Product Marketing Manager, Diligent
Leah Baker, Department of Finance
Simon Berglund, Senior Vice President & General Manager, APAC, Diligent
Adriana Eufrosina Bora, AI and Modern Slavery Researcher, QUT Centre for Data Science
Angela Clark, Australian Government Department of Finance
George Gorman, Chief Information Officer, Zip Co
Jordan Hatch, Assistant Secretary, Regulatory Reform Division, Department of Finance
Mayleah House, Head of Stewardship, Ethical Partners Funds Management
William Howe, Partner, Forensic and Technology Services, Clayton Utz
Tom May FGIA, Company Secretary, UniSuper Limited
Megan Motto FGIA FCG, CEO Governance Institute of Australia
Robyn Parkin, Sustainability Research and Advocacy, Ethical Partners Funds Management
Mark Salomon FGIA, Manager, Risk and Compliance, Mackillop Family Services
Kenneth Weldin FGIA, Partner & National Governance Leader, PKF Australia
Beth Worrall, Responsible AI Network Manager, National AI Centre, DISR
Boming Xia, Research Technician, Risk Assessment for Responsible AI, Data61, CSIRO
Judy Zheng, Program Assistant, Data61, CSIRO
Liming Zhu, Research Director Software and Computational Systems, Data61, CSIRO
Risk and opportunity
Daniel Atkin FGIA, Group Head of Risk, IDP Australia
Baidy Barton, Commercialisation Director, The Melt
Jason Brown, Principal Advisor to Board Risk and Security, Thales
Kylie Dalton FGIA, Chief Operating Officer, Child Cancer Research Foundation
William Howe, Partner, Forensic and Technology Services, Clayton Utz
Simon Newcomb, Partner, Technology, Clayton Utz
Daniel Popovski, Senior Policy & Advocacy Advisor, Governance Institute of Australia
Dottie Schindlinger, Executive Director, Diligent Institute
Stela Solar, Director, National AI Centre, DISR
Kenneth Weldin FGIA, Partner & National Governance Leader, PKF Australia
Beth Worrall, Responsible AI Network Manager, National AI Centre, DISR
Boming Xia, Research Technician, Risk Assessment for Responsible AI, Data61, CSIRO
Governance Institute of Australia – White Paper on AI Governance 6
AI as an enabler
Adriana Eufrosina Bora, AI and Modern Slavery Researcher, QUT Centre for Data Science
Chris Burling, Head of Strategy, Customer and Digital Technology, The GPT Group
Martin Curtis, Director, Google Partners ANZ
Francesca Dickson FGIA, Chair, Risk and Technology Committee, Governance Institute of Australia
Donna Forlin, Trust Architect, National AI Centre, DISR
William Howe, Partner, Forensic and Technology Services Clayton Utz
Anji Kurian, National Manager, Programming, Governance Institute of Australia
Phil Lim, Director of Product Management, Diligent
Michelle Moffatt, Partner AI Ethics, Risk & Compliance, Emergent Labs
Daniel Popovski, Senior Policy & Advocacy Advisor, Governance Institute of Australia
Kumar Srinivasan, Director (CRO), Risk and Insurance, University of Technology Sydney
Kenneth Weldin FGIA, Partner & National Governance Leader, PKF Australia
Beth Worrall, Responsible AI Network Manager, National AI Centre, DISR
Boming Xia, Research Technician, Risk Assessment for Responsible AI, Data61, CSIRO
Governance Institute of Australia – White Paper on AI Governance 7
Governance Institute of Australia – White Paper on AI Governance 8
Executive Summary
In today’s rapidly evolving technological landscape, Australian business leaders face a unique
challenge and opportunity: the adoption of Artificial Intelligence (AI). Despite AI’s transformative
potential, confidence and adoption, rates among Australian businesses lag behind those in
comparable countries. It is this very issue that we explore in this report by surfacing leadership
insights gathered from roundtables, and aligning best practice from the recently released Voluntary AI
Safety Standard.
Australian businesses are not fully leveraging AI, leading to missed opportunities for innovation and
efficiency. Additionally, AI presents significant ethical dilemmas that require thoughtful leadership and
robust frameworks. This document offers strategic recommendations and practical guidance to help
business leaders navigate AI adoption. We present a tailored approach that considers the specific
needs and challenges of Australian businesses, from SMEs to larger firms.
Data-Driven Insights: We provide up-to-date statistics and comparative analysis to highlight the
current state of AI adoption in Australia.
Ethical Considerations: The report delves into the ethical implications of AI, offering approaches to
address these challenges responsibly.
Actionable Recommendations: Clear, actionable steps from the latest frameworks are outlined to
help business leaders implement AI effectively and ethically.
This report is designed for organisational and business leaders across various sectors, including SMEs
and larger enterprises. It aims to equip them with the knowledge and tools needed to lead their
organisations through the AI transformation.
This report complements additional guidance published by the Australian Government, in particular,
the Voluntary AI Safety Standard.
Understanding and adopting AI is crucial for staying competitive in today’s market. Through this
report, business leaders will gain valuable insights and practical strategies to harness the power of AI
safely and responsibly, ensuring their organisations remain at the forefront of innovation.
Governance Institute of Australia – White Paper on AI Governance 9
Recommendations in this report
Throughout this report we have extracted two types of recommendations. The best practice guardrail
from the Voluntary AI Safety Standard that was recently published by the National AI Centre, and the
Expert Tip which came from the leadership insights during the roundtable discussions as well as from
our partners.
Voluntary AI Safety Standard
Guardrail 1: Expert tip:
Establish, implement and Consider how AI can help
publish an accountability monitor and achieve ESG
process including governance, goals, and how ESG principles
internal capability and a can act as a first step to
strategy for regulatory inform the design of AI
compliance. governance frameworks.
Governance Institute of Australia – White Paper on AI Governance 10
Voluntary AI Safety Standard1
Summary of 10 Guardrails
1. Establish, implement and Guardrail one creates the foundation for your organisation’s use
publish an accountability of AI. Set up the required accountability processes to guide your
process including governance, organisation’s safe and responsible use of AI, including:
internal capability and a
• an overall owner for AI use
strategy for regulatory
compliance. • an AI strategy
• any training your organisation will need.
2. E
stablish and implement a Set up a risk management process that assesses the AI impact
risk management process to and risk based on how you use the AI system. Begin with the full
identify and mitigate risks. range of potential harms with information from a stakeholder
impact assessment (guardrail 10). You must complete risk
assessments on an ongoing basis to ensure the risk mitigations
are effective.
3. Protect AI systems, and You must have appropriate data governance, privacy and
implement data governance cybersecurity measures in place to appropriately protect AI
measures to manage data systems. These will differ depending on use case and risk profile,
quality and provenance. but organisations must account for the unique characteristics of
AI systems such as:
• data quality
• data provenance
• cyber vulnerabilities.
4. Test AI models and systems to Thoroughly test AI systems and AI models before deployment,
evaluate model performance and then monitor for potential behaviour changes or
and monitor the system once unintended consequences. You should perform these tests
deployed. according to your clearly defined acceptance criteria that
consider your risk and impact assessment.
5. Enable human control or It is critical to enable human control or intervention mechanisms
intervention in an AI system as needed across the AI system lifecycle. AI systems are
to achieve meaningful human generally made up of multiple components supplied by different
oversight across the life cycle. parties in the supply chain. Meaningful human oversight will
let you intervene if you need to and reduce the potential for
unintended consequences and harms.
1 National AI Centre, Voluntary AI Safety Standard
Governance Institute of Australia – White Paper on AI Governance 11
6. Inform end-users regarding AI- Create trust with users. Give people, society and other
enabled decisions, interactions organisations confidence that you are using AI safely and
with AI and AI-generated responsibly. Disclose when you use AI, its role and when you are
content. generating content using AI. Disclosure can occur in many ways.
It is up to the organisation to identify the most appropriate
mechanism based on the use case, stakeholders and technology
used.
7. Establish processes for people Organisations must provide processes for users, organisations,
impacted by AI systems to people and society impacted by AI systems to challenge
challenge use or outcomes. how they are using AI and contest decisions, outcomes or
interactions that involve AI.
8. Be transparent with other Organisations must provide information to other organisations
organisations across the AI across the AI supply chain so they can:
supply chain about data,
models and systems to help • understand the components used including data, models and
them effectively address risks. systems
• understand how it was built
• understand and manage the risk of the use of the AI system.
9. Keep and maintain records to Organisations must maintain records to show that they
allow third parties to assess have adopted and are complying with the guardrails. This
compliance with guardrails. includes maintaining an AI inventory and consistent AI system
documentation.
10. Engage your stakeholders It is critical for organisations to identify and engage with
and evaluate their needs and stakeholders over the life of the AI system. This helps
circumstances, with a focus on organisations to identify potential harms and understand if
safety, diversity, inclusion and there are any potential or real unintended consequences from
fairness. the use of AI. Deployers must identify potential bias, minimise
negative effects of unwanted bias, ensure accessibility and
remove ethical prejudices from the AI solution or component.
Governance Institute of Australia – White Paper on AI Governance 12
Introduction
Artificial intelligence (AI) has emerged as a transformative force
across various sectors. It is driving innovation and efficiency at an
unprecedented scale. However, the rapid advancement (such as General
Purpose AI) and integration of AI technologies into our daily lives
present significant challenges and opportunities that demand careful
examination.
This is also underscored by key policy discussions, such as the US
Executive Order on the Safe, Secure, and Trustworthy Development and
Use of Artificial Intelligence, the Bletchley Declaration, and the European
Union (EU) AI Act – the first of its kind – reflecting a global consensus
on this critical issue.
Understanding AI in the Australian context
Approaching AI safety and responsible AI (RAI) necessitates joint efforts
from multidisciplinary communities such as AI, software engineering
(SE) and governance. To better understand Australia’s stance on RAI,
we hosted 3 roundtable discussions with panelists from different fields.
These session topics covered:
• AI ethics and governance
• AI risk and opportunity
• AI as an enabler.
Each session explored crucial aspects of AI development and
deployment, providing a holistic understanding of the implications,
and the potential and responsibilities associated with AI technologies.
The findings and recommendations from those discussions are
presented across the three core topics in this white paper.
Governance Institute of Australia – White Paper on AI Governance 13
Roundtable themes
Explores the fundamental principles and frameworks needed to
ensure that AI systems are developed and deployed ethically and
responsibly.
1. AI ethics and governance
It addresses the moral, legal and societal implications of AI,
emphasising the importance of AI ethics principles, their
implementation and operationalisation, and governance for AI.
Examines the dual facets of AI. It highlights the potential risks,
including biases, security concerns and unintended consequences,
2. AI risk and opportunity
while also exploring the immense opportunities AI presents for
innovation, problem-solving and enhancing human capabilities.
Investigates how AI can be a powerful tool for enabling progress
across various domains. It focuses on the transformative impact
3. AI as an enabler of AI on industries, the economy and society at large, showcasing
the role of AI in driving sustainable development and addressing
complex global challenges.
Governance Institute of Australia – White Paper on AI Governance 14
1. AI ethics and governance
The rapid advancement of AI underscores the necessity for robust
ethical frameworks and governance mechanisms. AI ethics and
governance have emerged as essential areas of study and practice,
aiming to ensure that AI technologies are developed and deployed in
ways that are responsible and safe.
There are a wide range of considerations for AI ethics. For instance,
Australia’s AI Ethics Principles2 call on organisations to:
• avoid bias and discrimination
• understand and adopt cultural and linguistic diversity and
gender equality
• drive confidence through reliable, safe and accurate decision-
making.
Ultimately, they present the fundamental ‘do no harm principle’.
AI ethics involves a meticulous examination of the moral implications
of AI decisions, the responsibilities of AI developers and users, and the
societal consequences of AI deployment. The ethical dimension of AI
requires interdisciplinary approaches, drawing from philosophy, law,
sociology and computer science, to address the multifaceted challenges
posed by these technologies.
AI governance refers to the frameworks, policies and regulations
that oversee the development and implementation of AI systems.
Effective AI governance aims to establish standards and guidelines that
promote ethical AI practices, protect individual rights and mitigate risks
associated with AI. It involves the collaboration of various stakeholders,
including governments, international organisations, industry leaders
and society, to formulate and enforce policies that ensure AI systems
are used responsibly and for the benefit of all.
The intersection of AI ethics and governance is crucial in addressing the
profound impacts of AI on society.
As AI systems become increasingly autonomous and
complex, the potential for unintended consequences and
ethical dilemmas grows. That is why it is imperative
to establish comprehensive governance structures to
address current ethical concerns while being adaptable
to future technological advancements.
2 Australian Government Department of Industry, Science and Resources, n.d. Australia’s AI
Ethics Principles.
Governance Institute of Australia – White Paper on AI Governance 15
Deciding to use AI
AI holds transformative potential across various sectors, enabling
advanced operational efficiencies that can redefine industry standards,
yet the motivations for integrating AI vary significantly among
organisations. The justification for AI deployment must be scrupulously
crafted to align with specific organisational contexts, cultures and
strategic goals. It is crucial for each organisation to precisely identify
its unique drivers for AI adoption, which may range from enhancing
operational productivity to securing tangible competitive advantages in
the marketplace.
The strategic imperative of AI is further highlighted by its necessity
for maintaining competitiveness in a rapidly evolving technological
landscape. A reluctance or delay in embracing cutting-edge
technologies like AI can result in significant missed opportunities and
a risk of falling behind other organisations. This urgency is fuelled by
both external market dynamics and internal demands for continual
innovation. Notably, younger employees, often more conversant
with emerging technologies, play a pivotal role in advocating for AI
integration. Their enthusiasm for technological assimilation compels
organisations to embed AI strategies within their core initiatives for
sustained relevance and innovation.
Aligning AI deployment with organisational purposes is
essential for strategic success.
Organisations must ensure that AI adoption not only supports their
strategic goals but also enhances operational efficiency. This strategic
alignment is crucial as it directly influences an organisation’s ability to
leverage AI to its full potential, optimising processes and catalysing
innovation in service delivery and product development. For instance,
companies in the financial services sector tend to adopt AI more
cautiously, updating data and information security policies to harness AI
capabilities while ensuring compliance with evolving regulatory standards.
The drive to adopt AI transcends merely staying current with
technology trends; it is fundamentally integrated into strategic
imperatives that dictate competitive advantage and operational
excellence. Yet successfully adopting and integrating new AI technologies
involves navigating a complex landscape of challenges, including:
• data privacy concerns
• the need for substantial investments in skills and infrastructure
• managing ethical considerations.
By embedding ‘the value-add’ of AI into strategic frameworks or
business models, organisations can address these challenges while
leveraging the full potential of AI to achieve transformative operational
capabilities. This strategic integration ensures that organisations can
assess the benefits and associated costs and risks, meaning they can
meet the immediate demands for innovation but also position
Governance Institute of Australia – White Paper on AI Governance 16
themselves at the forefront of their respective industries. Effective
Voluntary AI Safety Standard
harnessing of AI capabilities, as detailed in Topic 2, offers both
challenges and opportunities, necessitating robust RAI and AI
governance mechanisms to foster an environment conducive to
innovative growth and strategic enhancement.
Guardrail 1:
Establish, implement and
RAI and AI ethical principles for decision-making
publish an accountability
process including governance, As AI becomes increasingly integral to organisational operations
internal capability and a and strategies, the importance of RAI and ethical principles
strategy for regulatory escalates. Various sets of principles have been developed by different
compliance. organisations and government agencies worldwide, such as Australia’s
AI Ethics Principles3, OECD AI Principles4 and Hiroshima AI Process5.
These principles have a similar fundamental focus on areas of fairness,
transparency, accountability and explainability.
These principles reflect the wide range of ethical dilemmas and
operational challenges that AI can introduce. Serving as essential
high-level guidelines, they ensure that AI systems operate responsibly
and safely. However, due to their abstract nature, these principles
often require further operationalisation to be effectively implemented
within specific contexts. This process of transforming high-level ethical
guidelines into actionable operational practices is crucial as it ensures
that AI systems adhere to established ethical norms and are tailored to
meet the nuanced requirements of diverse organisational environments
and societal expectations.6 Some of the shared fundamental principles
are explored below.
ESG and human-centered design
Integrating Environmental, Social and Governance (ESG) criteria
into AI development is essential for a comprehensive evaluation of
a technology’s broader impacts. ESG is a good starting block for
considering how to effectively manage AI across an organisation –
ensuring AI initiatives promote sustainability, ethical governance and
social responsibility. AI can also assist organisations to achieve their
ESG goals and ambitions. AI technologies can be leveraged to provide
useful insights into ESG metrics, such as identifying and mitigating
unethical labour practices and unsustainable material sourcing across
the supply chain.
In addition to ESG, prioritising human-centered design within this
framework ensures that AI systems are accessible, intuitive and
designed with the end-user’s welfare in mind, thereby enhancing user
experience and adherence to ethical norms.7
3 Australian Government Department of Industry, Science and Resources, n.d. Australia’s AI
Ethics Principles.
4 OECD, 2019 (updated May 2024), OECD AI Principles.
5 Google, n.d. AI Principles.
6 Xia B, Lu Q, Perera H, Zhu L, Xing Z, Liu Y and Whittle J, May 2023, ‘Towards Concrete and
Connected AI Risk Assessment (C2AIRA): A Systematic Mapping Study’, 2023 IEEE/ACM 2nd
International Conference on AI Engineering–Software Engineering for AI (CAIN):104–116, IEEE.
7 Alphinity Investment Management and CSIRO, 2024, The intersection of Responsible AI and
ESG: A Framework for Investors.
Governance Institute of Australia – White Paper on AI Governance 17
ESG becomes a good framework to consider AI risks
because they know how to report it. Many risks
already captured in ESG are relevant for AI, such as
emission consequences, social and governance risks
[…] We need to look at additional AI risks that the
board needs to be careful about. Some risks are wholly
new and not covered in traditional ESG, especially in
the social and governance aspects.
– Liming Zhu
Fairness, transparency and explainability
Achieving fairness in AI necessitates that systems are thoughtfully
designed and undergo rigorous, regular audits to identify and mitigate
biases, ensuring equitable outcomes for all users. This commitment
to fairness must be embedded from the initial design phase through
to deployment and beyond, with continuous assessments to adapt to
evolving data and contexts.
Transparency complements this commitment, requiring that the
operations and decision-making processes of AI systems are clearly
articulated and accessible to users. This clarity is vital, as it not only
builds trust and confidence among users and stakeholders but also
ensures that AI actions are comprehensible and defensible. A striking
illustration of the importance of these principles is a study which
identified gender biases in 44% of 133 AI systems analysed.8 This
statistic highlights a significant concern and underscores the critical
need for robust mechanisms to ensure fairness and transparency in AI.
By prioritising these principles, organisations can provide stakeholders
with insights into the inner workings of AI technologies, demystifying AI
processes and reinforcing the ethical integrity of their applications.
Bias can creep into an AI selection tool in a number of ways. For
example, there can be:
• historical bias
• sampling bias
• measurement bias
• evaluation bias
• aggregation bias
• deployment bias’.9
Expert tip:
These biases could cause the AI to produce output which is harmful or
Consider how AI can help violate anti-discrimination laws. This is particularly problematic when
monitor and achieve ESG AI is used to make decisions or given agency to act in an autonomous
goals, and how ESG principles way. These risks require human oversight and accountability to prevent
can act as a first step to
inform the design of AI 8 mith, G and Rustagi, I 2021 “When good algorithms go sexist, why and how to advance AI
S
gender equity.
governance frameworks.
9 Sheard N, 2022, ‘Employment Discrimination by Algorithm: Can Anyone be Held
Accountable?’, UNSW Law Journal, Volume 45(2):617–648.
Governance Institute of Australia – White Paper on AI Governance 18
and mitigate them, for example, by reviewing and adjusting the
outcome to account for any biases. There have been some instances
of this problem in the context of recruitment. For example, a claim
brought against Workday alleged that an AI screening tool made
available by Workday discriminated against applicants on the basis of
race, disability, and age – each of which are protected attributes under
discrimination laws.
Privacy and cyber security
In the digital age, where data breaches are increasingly frequent,
establishing robust privacy and security protocols for AI systems is
crucial. These systems must implement stringent measures to safeguard
personal and sensitive information against unauthorised access,
aligning with the Privacy Act and global data protection regulations
such as the General Data Protection Regulation (GDPR). In the context
of generative AI, it is vital to address copyright and licensing issues
rigorously. AI systems often create new content by learning from vast
datasets that are often crawled online10. Similarly, organisations using
their enterprise data with generative AI must ensure that the use of
such data complies with privacy, confidentiality and copyright laws and
licensing agreements. This commitment not only secures stakeholder
trust but also upholds the integrity of data and content created or
processed by AI, emphasising an organisation’s dedication to ethical
data usage and intellectual property rights.
The use of third-party material or personal information to train, prompt or
ground AI could violate Australian copyright or privacy laws. In particular:
• The process of training AI often involves a reproduction of
copyright material in the training data. Using a model may
generate reproductions of the training data or reproduce other
material to ground or prompt the model. These reproductions
may infringe copyright if there is no appropriate licence or
statutory exception.
• To the extent training data or prompting data includes personal
information, privacy laws impose a restriction on how that data
may be collected, used and disclosed.
In Australia, copyright laws are not currently broad enough (with some
limited exceptions) to allow for the use of data to train AI models
without an appropriate licence. Globally, copyright issues have resulted
in a wave of litigation against AI companies that is currently making its
Expert tip: way through the courts. The AI industry is also dealing with this issue
in a number of ways, including by negotiating licences with content
Implement a continuous
creators and by providing guarantees to consumers that their products
improvement feedback model
are not infringing.
to identify and mitigate biases
and drive fairer outcomes for
10 Z
hang D, Xia B, Liu Y, Xu X, Hoang T, Xing Z, Staple M, Lu Qinghua and Zhu L, 2023,
all users interacting with it. ‘Navigating privacy and copyright challenges across the data lifecycle of generative ai’, arXiv
preprint arXiv:2311.18252.
Governance Institute of Australia – White Paper on AI Governance 19
A notable example of training AI in violating privacy laws is the case
Voluntary AI Safety Standard
of Clearview AI – an AI company that used images scraped from the
internet to create biometric information stored in its facial recognition
database, a practice which the Office of the Australian Information
Commissioner declared to have breached the Australian Privacy Act 1988.
The use of AI also creates new security challenges for organisations and
Guard rail 3: individuals. This is due in part to the need for the AI to access – and
Protect AI systems, and therefore for the organisation to retain – large quantities of data. The
implement data governance retention of this data increases the risk and potential consequences of
measures to manage data a security breach. So, organisations should ensure appropriate controls
quality and provenance. are in place to prevent and mitigate the risk.
Technological advancements in AI may also increase the opportunity
for malicious activity. For example, the potential to create higher quality
deepfakes – being hyper realistic but false depictions of a person or
thing – which may aid cybercrime, including identity theft and phishing,
or spread misinformation, among other things.
Reliability and safety
Ensuring the reliability and safety of AI is a fundamental concern
across all branches of AI. AI models and/or systems must undergo
rigorous testing and validation to perform reliably under diverse
conditions without introducing unforeseen risks. Continuous monitoring
and thorough safety evaluations are essential, not only to adhere
to regulations such as those under consideration by the Australia
Government11 or those in the European Union Artificial Intelligence Act
(EU AI Act) but also to maintain trust and operational integrity.
As we delve into the realm of generative AI, these concerns become even
more pronounced due to its versatile capabilities. Generative AI, which
can produce text, images and other content, requires additional layers
of scrutiny. The capability evaluations for these systems are particularly
critical – to assess the ability of generative AI and other branches of AI to
handle tasks safely and effectively. Importantly, these evaluations cover
both intended capabilities envisioned by developers and unintended
capabilities that could emerge as byproducts of complex interactions
within the AI model. This comprehensive approach ensures that the
outputs are not only high quality but also ethically sound and free from
harmful content. Given their potential impact, it is imperative that these
evaluations are comprehensive (for example, both model- and system-
level, with considerations across the AI supply chain12)and adapt to the
rapid advancements in generative AI.
In this context, continuous adaptation to emerging threats and the
ability to respond to anomalies swiftly are paramount. This ensures that
generative AI systems not only comply with stringent safety standards
but also uphold the ethical standards necessary for their widespread
adoption in sensitive and impactful domains. This is particularly necessary
in high-risk settings such as medical diagnostics and road safety.
11 Introducing mandatory guardrails for AI in high-risk settings: proposals paper - Consult hub
([Link])
12 Xia B, Lu Q, Zhu L and Xing Z, 2024, ‘Towards AI safety: A taxonomy for ai system
evaluation’, arXiv preprint arXiv:2404.05388.
Governance Institute of Australia – White Paper on AI Governance 20
Ensuring the reliability and safety of AI systems is important in complying
Voluntary AI Safety Standard
with many legal obligations. For example, inaccurate information could
lead to claims of negligence, breach of contractual warranties, breach
of Australian consumer laws (including laws preventing misleading or
deceptive conduct) or defamation. Many sector-specific laws may also
apply (such as regulation of Software as a Medical Device).
Contestability and accountability
Guardrail 4: AI systems must enable affected parties to contest decisions effectively,
Test AI models and systems to providing a robust process for airing grievances and implementing
evaluate model performance corrections. This capacity for contestability ensures overall safety in
and monitor the system once AI decision-making processes. Accountability complements this by
deployed. requiring clear organisational governance structures, including clear
identification of roles and responsibilities, and protocols to manage and
rectify any adverse outcomes or errors. This principle is essential for
upholding ethical standards and enhancing organisational credibility.
To effectively operationalise accountability in AI systems, it is critical to
structure it around 3 core pillars:
• Responsibility – defines ‘who is accountable and to whom’,
establishing clear roles and responsibilities among developers,
users and other stakeholders. This foundational aspect sets the
stage for measurable and enforceable accountability.
• Auditability – focuses on ‘what one is accountable for’. This
ensures that all actions and decisions made by AI systems are
traceable and auditable, which is essential for maintaining
transparency and facilitating the evaluation of AI systems
against agreed standards and regulations.
• Redressability – addresses ‘how entities are accountable and
can rectify issues’. It includes establishing mechanisms for
correcting any mistakes or misjudgements made by AI systems
and providing effective remedies for those adversely affected.13
13 Xia B, Lu Q, Zhu L, Lee SU, Liu Y and Xing Z, 2023, ‘Towards a Responsible AI Metrics Catalogue:
A Collection of Metrics for AI Accountability’, arXiv preprint arXiv:2311.13158.
Governance Institute of Australia – White Paper on AI Governance 21
Figure 1: Implementing contestable accountability
processes in AI systems: A 3-pillar approach
Identify responsible
employees, officers
or third-party
stakeholders
Clearly articulate what
an individual or team
is accountable for
and audit
their activities
Embed processes to
Real-time information identify, mitigate
processing adds velocity and rectify issues
to this feedback loop identified by
responsible parties
The increased use of AI in decision-making introduces a range of issues
company directors and other responsible persons must consider when
discharging their existing duties under the Australian Corporations Act
2001, notably, the duty under s180 to exercise reasonable care and
diligence. Directors may be accountable for an outcome, even if the
decision-making process has been automated.
Expert tip: Similar issues exist in government. Administrative decision-makers
Adopt the 3-pillar approach to must afford procedural fairness, must only act within the scope of their
implement contestability and decision-making power and must only consider relevant considerations
accountability in AI systems – any use of AI must not detract from those principles. Further, in some
by identifying responsible cases, decisions are legally required to be made by a person. In those
employees, agents or entities, cases, a decision made by AI will be invalid.
articulating expectations of
AI governance
their activities and auditing
their actions, and embedding Effective governance of AI is essential to ensure that AI technologies
processes to assist in the are developed, deployed and used responsibly, adhering to safety and
identification, mitigation and ethical norms, and complying with regulatory standards. AI governance
rectification of issues. involves comprehensive practices and policies that guide the lifecycle of
AI systems, aimed at mitigating risks and maximising societal benefits.
Governance Institute of Australia – White Paper on AI Governance 22
Approach to AI governance
Strategic oversight and ethical alignment: AI governance starts
with strategic oversight, involving the setting of clear goals and ethical
guidelines for AI use within organisations. This includes aligning
AI strategies with the organisation’s overarching goals and a firm
commitment to ethical practices at all levels. Leaders must champion a
culture of ethical integrity and accountability, ensuring AI solutions are
responsibly developed and used. AI governance should form part of an
AI Risk Management Framework.14
If artificial intelligence is to be used safely and
responsibly within an organisation, we know that it
is vital for leaders to be actively involved in shaping
policies and procedures.
– Stela Solar
Regulatory compliance and ethical standards: Compliance with local
and international regulations is essential. AI governance frameworks
must adapt to the evolving legal landscape, incorporating standards
that address new ethical challenges such as privacy concerns, bias
mitigation and transparency. Effective governance requires creating
regulatory settings that support the safe and responsible adoption of AI
while fostering innovation.
Risk assessment and management: Central to AI governance is
the rigorous management of potential risks, covering both technical
vulnerabilities and ethical dilemmas. AI systems must be evaluated for
their impact on fairness, privacy and security. Effective risk management
strategies involve identifying and mitigating immediate risks and
anticipating future challenges as technology and societal norms evolve.
If you manage a risk better than your competitors,
then it’s an opportunity.
– George Gorman, Zip Co.
Stakeholder engagement and public trust: Continuous engagement
with a broad range of stakeholders, including technologists, policymakers,
affected communities and the public is crucial. This engagement
Expert tip:
ensures that diverse perspectives and values inform AI development
Report issues to senior officers and deployment. Building public trust through transparent practices
and directors when known and open communication is critical for the broad acceptance and
issues may have financial successful integration of AI systems.
or reputational harm to the
Monitoring, auditing and continuous improvement: Ongoing
business, particularly as it
monitoring and regular auditing of AI systems are essential to ensure
relates to s 180 Duty of Care
they operate as intended and adhere to ethical standards over time.
and Diligence and ASX Listing
This process of continuous assessment and adaptation keeps AI
Rule 3.1 regarding Continuous
governance frameworks responsive to rapid technological
Disclosure.
advancements and changing societal expectations.
14 NIST, 2023, AI Risk Management Framework.
Governance Institute of Australia – White Paper on AI Governance 23
Figure 2: Inclusive AI governance framework
Strategic oversight and
ethical alignment
Risk management and
assessment
Monitoring, auditing and
continuous improvement
mechanisms
Regulatory compliance and Stakeholder engagement
ethical standards and public trust
Challenges in AI governance
AI governance faces several significant challenges that can complicate
the effective management and oversight of these technologies:
• Complexity of AI systems: The inherent complexity of AI
algorithms and their decision-making processes can make
transparency and accountability difficult. This complexity
often requires specialised knowledge, posing a barrier for
stakeholders attempting to understand or oversee AI systems.
‘Black box’ system processes affect trust and confidence across
the AI supply chain and create hesitancy in risk-taking by senior
officers and directors, potentially stifling business innovation.
• Rapid technological advancement: The fast pace of AI
development can outstrip current governance frameworks and
regulatory guidelines, making it difficult to keep up with new
technologies and their potential impacts. Real-time information
and continuous feedback loops can assist where technological
capabilities are being stretched into new business domains.
Governance Institute of Australia – White Paper on AI Governance 24
• Global disparities in regulations: Differences in AI regulations
across countries can lead to governance gaps, especially for
multinational corporations operating in multiple jurisdictions.
Harmonising these differences remains a formidable challenge.
However, fundamental principles and concepts of safe and
responsible AI development and deployment are gaining traction.
Expert tip: • Ethical ambiguities: Ethical standards in AI are continually
evolving, and there can be significant disagreements on what
Implement an inclusive AI constitutes ethical use, particularly in areas like facial recognition
governance framework with and predictive policing. Social norms will continue to evolve
continuous feedback loops and change over time. Organisations should be aware of their
that address key regulatory consumer and supplier risk appetite and ethical parameters.
compliance and ethical
standards frameworks. • Resource allocation: Adequate resources, including funding,
expertise and tools, are essential for effective AI governance
but are often lacking, especially in smaller organisations or in
sectors with rapid AI integration. Capability uplift across the
organisation in otherwise non-technical roles can be leveraged
to address the resource gap.
By addressing these challenges head-on, organisations can enhance
their AI governance frameworks, ensuring that AI technologies are
leveraged responsibly and ethically across all applications.
Governance Institute of Australia – White Paper on AI Governance 25
2. AI risks and opportunities
The integration of AI into various sectors presents a unique blend
Voluntary AI Safety Standard
of risks and opportunities that organisations must skilfully navigate.
This section explores the dual nature of AI’s impact, focusing on
the practical implications for business and society, offering a more
pragmatic exploration of how AI reshapes industries and introduces
new challenges.
AI technologies introduce risks that require vigilant management,
Guardrail 6:
including the risk of disseminating or relying on inaccurate, unreliable
Inform end-users regarding or biased/discriminatory content, intellectual property infringement
AI-enabled decisions, risks and data privacy risks where personal information might be
interactions with AI and AI- compromised, if not designed and deployed with clear ethical
generated content. guidelines, generative AI can have unintended consequences and
potentially cause real harm.15
The opportunities presented by AI are transformative. AI facilitates
the automation of complex tasks, yields insightful analytics from
large datasets, and enables unprecedented levels of personalisation
in customer service and product offerings. For instance, generative
AI revolutionises creative processes and content generation, leading
to significant operational efficiencies, cost reductions and enhanced
market competitiveness.
By strategically leveraging AI, organisations can
improve their internal processes, redefine customer
interactions and expand into new markets, driving
substantial business growth.
Governments understand the need to balance innovation and risk-
taking with precautionary principles that factor risks associated with
AI. International governments have taken different approaches in
managing risks and opportunities, with some jurisdictions taking a
more precautionary approach to AI risk management, creating clear
limits on high-risk activities such as those outlined in the EU AI Act. The
US Government also recognised the potential for significant harm of
unregulated AI by creating the Executive Order on the Safe, Secure, and
Trustworthy Development and Use of Artificial Intelligence. The Australian
government has published a Mandatory Guardrails Proposals Paper
open for consultation16. Governments are aware of the tremendous
benefits to society and the economy that AI can bring but remain
cognisant to the potential harms of unabated AI development.
15 Managing the Risks of Generative AI ([Link])
16 Australian Government, Mandatory Guardrails Proposal Paper
Governance Institute of Australia – White Paper on AI Governance 26
Australia is also following this precautionary approach. AI regulation has
been on the Government’s agenda since the release of its discussion
paper ‘Safe and responsible AI in Australia’ in June 2023 which was
then followed by an interim response paper in January 2024 signalling
that mandatory regulation would follow. At the time of writing this
paper in September 2024, the Australian Government has released a
consultation paper proposing the introduction of regulations requiring
10 mandatory guardrails focusing on testing, transparency and
Guardrail 2: accountability to be adopted by Australian organisations in developing
or deploying high risk AI systems.
Establish and implement a
risk management process to
identify and mitigate risks.
AI risks
The development, deployment and use of AI technologies presents
a complex interplay between risks and opportunities, necessitating
vigilant management and strategic governance. These risks are
intertwined with opportunities, highlighting the need for a balanced
approach to harness AI’s full potential while meeting ethical standards.
Integrated risk and opportunity management
Managing AI involves a nuanced approach that starts with testing
initial value propositions iteratively, then adjusting strategies based
on comprehensive risk and impact assessments. This incremental
and iterative method helps identify and mitigate risks early, ensuring
that AI implementations are deliberate and considerate. For example,
the deployment of AI in loan approval processes can be tested in
controlled environments to identify unintended biases against certain
demographics before full-scale implementation.
Scaling AI risk management
As AI technology becomes more accessible, the challenge of managing
its risks also scales. The expansion of AI capabilities increases the scope
of potential impact, meaning that errors or missteps in AI applications
can have consequences that extend beyond affecting just small groups
of individuals. These errors can have wide-reaching effects, potentially
impacting entire populations or causing systemic failures across entire
networks or sectors. This underscores the need for robust standards
and training for the safe development, deployment and use of AI – and
these must be comprehensible to non-specialists. As AI becomes more
accessible to individuals and employees, the risk of improper use and
integration of AI into organisational tasks and activities requires greater
training and accountability across all levels of the organisation.
Governance Institute of Australia – White Paper on AI Governance 27
Voluntary AI Safety Standard
Governance and legal frameworks
Effective governance requires anticipation of AI’s broader impacts,
necessitating structures that can adapt to change. As AI applications
permeate various sectors, organisations must ensure their governance
frameworks can handle evolving legal and market dynamics. The role
of voluntary guidance in shaping responses to AI challenges is another
crucial consideration for proactive governance planning.
Guardrail 8: AI is currently regulated in a non-specific way in Australia by many
existing laws - including the Privacy Act 1988 (Cth), Competition and
Be transparent with other
Consumer Act 2010 (Cth), Copyright Act 1968 (Cth), Online Safety
organisations across the AI
Act 2021 (Cth), Corporations Act 2001 (Cth), administrative laws, anti-
supply chain about data,
discrimination laws, sector-specific laws and general laws like contract
models and systems to help
and tort laws. Establishing a clear understanding of these laws and how
them effectively address risks.
they apply to AI is critical to ensure compliance.
The Australian Government is also proposing to introduce AI specific
regulation and various AI related reforms to existing laws.
Given the application of existing laws to AI, a solid foundation of
compliance infrastructure within organisations is likely to be in place
already. That should be reviewed for its application to AI. Then, AI
specific issues and cross framework integration can be handled by an AI
specific framework.
Supply chain risk assessment
The establishment of common industry standards and frameworks
is essential for facilitating negotiations and ensuring equitable
agreements between parties of varying sizes. Adopting global best
practices to update existing frameworks with AI-specific elements is
crucial. For example, traditional supplier risk management evaluates
vendors based on financial stability and compliance with general
business regulations. However, AI-specific supplier risk management
expands these evaluations to address unique AI challenges such as
ethical data usage, algorithmic transparency and bias mitigation. It
involves auditing AI development processes, scrutinising the data sets
used for training algorithms, and continuously monitoring AI outputs to
ensure they adhere to ethical standards and regulatory requirements.
This comprehensive approach ensures that third-party vendors meet
stringent standards necessary for the safe and ethical deployment of
AI technologies to align with both existing regulations and emerging
Expert tip: standards specific to AI.
Establish an understanding
Complexities in AI procurement and contractual issues
of existing law and how they
apply to AI. Review existing The procurement of AI technologies presents some unique challenges
compliance frameworks to that differ from those associated with more traditional rule based
make sure they work with AI. technologies. This requires rethinking some of the traditional approaches
to procurement such as how to develop requirements specifications
Also, implement an AI policy (favouring an outcome-based approach), iterative development,
and compliance framework testing processes and addressing data provenance and management.
that deals with AI-specific Procurement contracts should be written to handle these new
issues and integrates with approaches also address any AI-specific risks - for example, the risk of
existing frameworks. copyright or privacy infringement associated with the use or creation of
data using generative AI.
Governance Institute of Australia – White Paper on AI Governance 28
Contracts for the deployment of AI should explicitly incorporate ethical
Voluntary AI Safety Standard
considerations and values to proactively address risks such as bias,
security and transparency. This ensures that accountability measures
are embedded throughout the AI lifecycle, from development to
deployment and operation, enhancing both compliance and ethical
integrity in AI applications.
Guardrail 7: Addressing the challenge of non-specialist understanding
It is crucial that AI risks are understandable to a broad audience.
Establish processes for people Simplifying complex technical details without losing the necessary
impacted by AI systems to depth requires careful communication strategies that enhance
challenge use or outcomes. transparency and facilitate broader engagement.
Balancing AI opportunities with risk mitigation
AI offers transformative opportunities for businesses and society,
though it comes with inherent risks that necessitate strategic
management. By embracing AI opportunities strategically and
managing associated risks diligently, organisations can not only improve
their operational efficiencies but also drive innovation responsibly.
Balancing these aspects requires continuous
assessment, adaptive strategies and an inclusive
approach to AI integration, ensuring AI deployments
enhance capabilities while safeguarding against
potential risks.
Strategic adoption and deployment
The potential of AI to catalyse significant business growth is increasingly
acknowledged across industries. Adopting AI strategically, with a
balanced focus on both its risks and opportunities, is critical in cultivating
a culture that prioritises responsible exploration and innovation. Tools
like Microsoft Copilot, for instance, are being integrated into business
workflows to enhance productivity and decision-making processes. This
showcases how AI can be seamlessly incorporated into daily operations
to drive efficiency and competitive advantages, demonstrating the
strategic integration that yields substantial benefits.
To ensure this integration is both effective and secure, organisations
must implement a proactive risk management strategy. This strategy
extends beyond addressing immediate risks, such as data breaches or
ethical concerns, to include the anticipation of long-term challenges like
Expert tip:
the impact of AI on business processes and compliance requirements.
Embed AI related legal, Effective risk management requires continuous evaluation of AI systems
ethical and commercial for vulnerabilities, enabling organisations to adapt to new threats and
considerations and practices maintain control over AI operations. By aligning risk management with
by design into AI procurement strategic deployment, organisations can safely and effectively harness
and contracts. AI’s capabilities, leading to progressive advancements rather than
stagnation.
Governance Institute of Australia – White Paper on AI Governance 29
Adopting a holistic approach to AI deployment involves forming multi-
Voluntary AI Safety Standard
functional teams to comprehensively scrutinise AI applications.
Developing guidelines for responsible AI use, especially in customer-
facing and internal business operations, is vital for compliance without
compromising operational integrity.
The strategic appointment of people with diverse
Guardrail 10: viewpoints, including sceptics, for AI initiatives can
Engage your stakeholders enrich governance processes, ensuring rigorous
and evaluate their needs and
circumstances, with a focus on
scrutiny and a balanced perspective on AI’s potential
safety, diversity, inclusion and and pitfalls.
fairness.
By integrating strategic deployment, risk management and
comprehensive governance, organisations can achieve a robust
framework that not only supports innovative AI applications but
also ensures they are ethically sound and compliant with regulatory
standards. This integrated approach ensures that AI deployments
enhance capabilities while safeguarding against potential risks,
promoting a responsible and sustainable advancement in AI
technology.
If you approach something with a ‘what can we do,
how do we do this responsibly’ mindset, it changes the
dynamic.
– Kenneth Weldin
Expanding AI opportunities across diverse sectors
AI is playing a transformative role across various sectors, including
the not-for-profit sector, where its impact is particularly notable
in enhancing operational efficiency even in resource-constrained
environments. In these settings, AI excels in data analysis, streamlining
governance processes and facilitating nuanced policy development.
For instance, AI tools can automate the analysis of large volumes of
donor data to identify trends and insights that drive more targeted and
effective fundraising strategies. AI can be employed to monitor and
report on governance practices, ensuring compliance and transparency
to strengthen donor trust and engagement. These capabilities not only
revolutionise how services are provided and how donor relationships
are managed but also enhance overall organisational efficiency, making
AI a valuable asset in extending the reach and impact of not-for-profits.
Expert tip:
Implement a continuous
evaluation model to detect
AI system vulnerabilities and
threats to maintain effective
control over AI operations.
Governance Institute of Australia – White Paper on AI Governance 30
3. AI as an enabler
AI’s enabling power spans diverse applications and fields. Unlike traditional
technologies, AI possesses the ability to learn, adapt, and perform tasks
that typically require human intelligence, making it a versatile tool for
organisations seeking to stay competitive in a rapidly evolving market.
AI fosters collaboration between humans and machines, augmenting
human abilities and enabling new forms of interaction and problem-
solving. This synergy can democratise access to information and resources,
empowering organisations with limited capabilities to achieve their
missions more effectively. In sectors such as healthcare, education and
not-for-profit, AI can bridge gaps and provide tailored solutions that
were previously unattainable. Laborious time-consuming and repetitive
activities can now be replaced with further human creativity and
innovation.
AI is a complementary tool to assist in human labour that
will augment human activities to higher value-add
activities.
Recognising AI as an enabler involves understanding its strategic
importance, the necessity for robust implementation frameworks and
the ethical considerations essential for responsible deployment. AI still
requires human supervision and judgement. By leveraging AI’s capabilities,
organisations can enhance their operational efficiencies and drive
meaningful societal impact. This ensures sustainable and inclusive growth
in the digital age, fostering innovation while addressing global challenges.
Building the business case and value proposition
for AI
Establishing a compelling business case for AI involves demonstrating
its potential to deliver significant value across various organisational
dimensions, including enhancing operational efficiencies, improving
decision-making processes and fostering innovation.
Expert tip: Strategic importance and urgency
Business leaders are increasingly recognising the strategic importance
Assess the strategic
of AI in maintaining a competitive edge and in fostering innovation.
importance and imperative
This strategic move is driven by an era of hyper-personalisation that
of AI adoption across the
aims to tailor products and services to better meet consumer needs,
business and the broader
along with enhanced supply chain integrity and transparency to achieve
industry.
ESG goals and meet stakeholder expectations.
Governance Institute of Australia – White Paper on AI Governance 31
Voluntary AI Safety Standard AI’s role goes beyond just automating tasks. It
enhances the agility of an organisation, allowing it
to respond more swiftly to market forces, including
evolving consumer needs.
Guardrail 5: AI plays a crucial role in the development of both current employees
and the future workforce by integrating advanced technologies into
Enable human control or educational programs and workplace software applications. These
intervention in an AI system initiatives not only prepare individuals for a digital future but also
to achieve meaningful human ensure that organisations are continually revitalised with fresh ideas
oversight across the life cycle. and new approaches to problem-solving. To effectively harness
AI’s potential, however, organisations should adopt an incremental
integration approach. This involves facilitating careful evaluation and
governance, with a realistic understanding of AI’s capabilities and
limitations so its application is both ethical and effective.
Enhancing operational efficiency and security
AI’s transformative capabilities are evident in sectors like healthcare.
In healthcare, AI tools play a pivotal role by analysing vast amounts of
patient data to forecast health outcomes and tailor treatment plans
to individual needs. This not only boosts the efficiency of healthcare
delivery but also elevates the quality of patient care.
In the realm of security, AI-enhanced surveillance systems are
instrumental. These systems scrutinise behaviour patterns to detect
anomalies and promptly alert human operators, thereby averting
potential security threats before they escalate. Through these
innovations, AI is not just streamlining operations but is also bolstering
safety and security across diverse fields.
Accelerating startup development
Startups, especially in the technology sector, are leveraging AI to
accelerate their development processes and enhance market analysis.
By incorporating AI, these nimble businesses can automate significant
portions of manual processes. This automation allows businesses to
allocate more time and attention to other aspects, such as refining
design and user experience, which can differentiate a product in
competitive markets. The use of AI not only fast-tracks the product
development cycle but also contributes to substantial reductions in
labour costs. These efficiencies are crucial for startups, where speed and
cost-effectiveness are often paramount to success. The speed of market
access and penetration is the new competitive advantage.
Startups are demonstrating a strong willingness and a
Expert tip:
greater risk appetite when it comes to adopting AI. AI
Leverage AI tools to enhance
the monitoring and mitigating
helps them get products to market faster – usually half
security of digital assets and the time and half the cost.
online environments.
– Michelle Moffatt
Governance Institute of Australia – White Paper on AI Governance 32
Facilitating sustainable practices and economic efficiency
In sectors such as advanced manufacturing, AI is becoming a key player
in promoting sustainability and enhancing economic efficiency. AI
enables companies to optimise their energy consumption and minimise
waste through smarter management of resources. For example, AI can
help with predictive maintenance, which not only prevents unexpected
equipment failures but also extends the lifespan of the machinery,
conserving resources and reducing waste. AI can help fine-tune supply
chain operations, ensuring that materials and products are moved more
efficiently, further cutting down on excess and inefficiency. Together,
these applications of AI support a more sustainable manufacturing
process, aligning operational goals with environmental stewardship.
Generative AI: lowering barriers and encouraging innovation
Generative AI represents a significant evolution towards more advanced
AI systems. Unlike its predecessors, generative AI can create new
content, from textual outputs to images and code, demonstrating a
leap in AI’s creative and functional capabilities. ChatGPT is a prominent
example of generative AI, known for producing coherent and
contextually relevant text in a conversational style. It is an example of
the democratisation of AI.
This capability has broadened the scope of AI
applications in everyday tasks and business operations.
In parallel, APIs provide accessible and streamlined access to powerful
generative AI models, enabling developers and businesses to easily
integrate these capabilities into their own applications. This empowers
even small businesses and individual entrepreneurs, who can now
deploy advanced AI technologies without the need for extensive resources
or deep technical expertise. By making these tools widely accessible,
generative AI enhances creative processes and efficiency, fostering
innovation and providing a competitive edge across various industries.
Small business operators should still seek to understand how AI may
affect their business decisions, legal compliance and operations.
Some particular considerations for creators and innovators include:
• Ownership of content: Copyright generally does not subsist
in AI-generated works in Australia because copyright law
requires there to be a human author. So, creators may not
own the copyright in their content if it was generated by AI.
Expert tip:
Others may then use that content without infringing copyright.
Collaborate with your Similarly, patent law requires a human inventor, so an invention
organisation’s team leaders generated by AI may not be patentable.
to identify and recognise the
• Liability for output of an AI: AI may produce output that
benefits AI deployment across
is inaccurate, unreliable, misleading, biased, defamatory or
the supply chain, starting with
otherwise inappropriate. The risk increases where AI is used to
pre-production services to
make decisions or there is no effective human review. The fact
post-production activities.
that AI produced the output is unlikely to be a legal defence.
Governance Institute of Australia – White Paper on AI Governance 33
• Use of third party data: Organisations should ensure they have
appropriate rights (from a copyright, confidentiality and privacy
perspective) before providing data to an AI system.
• Protecting data from training: AI systems are often trained
on a large quantity of data scraped from the internet.
Organisations should consider if they are comfortable with their
data being viewed by AI models and, if not, taking technical or
legal steps to prevent that from occurring.
The barrier for adoption has really come down...the
cost to get going with experiments and using the
technologies is very low, the amount of skill required to
engage with the technologies also just dropped away.
Chris Burling
Open-source AI: opportunities and challenges
Open-source AI has revolutionised the way organisations, from startups
to multinational corporations, access and use advanced technology.
However, while it provides transformative opportunities for technological
advancement and collaborative innovation, effectively navigating its
landscape demands a deeper understanding of both its benefits and
inherent risks.
By making AI models and frameworks publicly available, it enables a
global community of developers to innovate and accelerate technological
advancements. For instance, open sourcing pre-trained AI models
empowers a global community of developers to innovate and tailor
these models to their specific needs through fine-tuning. This approach
not only democratises access to cutting-edge technology but also
accelerates the pace of innovation across and between various sectors,
enabling customised solutions that address unique challenges and
enhance competitive advantages.
However, the rapid development cycle of using open-
source models, while advantageous, presents its own
set of challenges when compared to developing and
deploying proprietary systems.
Expert tip: Open-source AI allows for quicker adaptation and integration, offering
a significant edge over slower, closed-source developments from scratch.
Prioritise the robustness of Yet, this can sometimes result in less rigorous testing and variability in
data privacy, cyber security quality. Organisations must balance the speed of adoption with thorough
and backup systems in the validation processes to ensure reliability.
initial stages of AI technology
adoption to safeguard against Startups face distinct challenges when integrating open-source AI,
immediate and long-term particularly due to their reliance on external AI services which may
operational risks. experience interruptions. To mitigate such vulnerabilities, it is advisable
for startups to develop diversified technology strategies. These should
Governance Institute of Australia – White Paper on AI Governance 34
encompass a variety of open-source options, alongside alternative
solutions and comprehensive backup systems. Drawing on insights
from the volatile crypto industry, it is essential for startups to prioritise
robustness and data privacy from the initial stages of technology
adoption. This approach not only safeguards against immediate
operational risks but also establishes a foundation for long-term
resilience and sustained growth.
Guardrail 9:
Keep and maintain records to
allow third parties to assess
compliance with guardrails.
Organisational readiness for AI
Getting an organisation ready for AI will help harness the full potential
of AI while aligning its use with broader strategic objectives.
Technological infrastructure
Successful AI adoption requires a robust infrastructure tailored to the
demands of AI technologies. Organisations must assess their current
systems to identify gaps, focusing on enhancing data processing
capabilities and security measures. Upgrading hardware and implementing
advanced encryption and automated bias detection tools are essential
for responsible AI practices. Alternatively, organisations can leverage
cloud-based services, which offer scalable and cost-effective solutions for
AI deployment without the need for extensive on-site upgrades. This
approach simplifies the integration of advanced AI technologies and
ensures compliance with evolving data protection and privacy standards.
Workforce preparedness
Preparing the workforce for AI integration involves equipping
employees with the technical skills necessary for working with AI
Expert tip: technologies and a deep understanding of responsible AI.
Align AI training with
Continuous education and training programs are
existing digital literacy
training programs such as essential for developing AI literacy across the organisation.
cyber security training to
uplift capabilities across the These programs should focus on fostering a culture of responsible
organisation. innovation, ensuring employees are proficient in using AI tools while
understanding the ethical considerations and best practices for
deploying AI responsibly.
Cultural readiness and leadership
Fostering a culture that promotes innovation, agility and responsible AI
practices is essential for successful AI integration. Organisations that
encourage collaboration, experimentation and continuous improvement
are better equipped to implement AI effectively. Strong leadership plays
a crucial role in this process by championing AI initiatives and establishing
Expert tip:
governance frameworks that cover risk management and ethical
Develop and apply considerations. Embedding responsible AI principles into the culture
governance frameworks that ensures that ethical considerations are central to AI projects, enhancing
drive cultural change in AI both productivity and ethical standards. Leaders must ensure that these
adoption within teams and values are upheld throughout the organisation, guiding teams toward
across the organisation. ethical and innovative AI solutions.
Governance Institute of Australia – White Paper on AI Governance 35
Figure 3: Driving cultural change across the organisation
Create a safe environment
for experimentation
Accessible education and
Encourage collaboration
awareness building progams
and knowledge sharing
A framework to
Provide access to resources drive cultural Align AI adoption with
and support strategic goals
change in AI
adoption
Assess organisational Reward the growth mindset
readiness and audit existing by recognising and
systems rewarding innovation
Lead by example
Governance Institute of Australia – White Paper on AI Governance 36
Best practices: taking a
tailored approach to meet
organisational needs
Successfully integrating AI into an organisation requires a comprehensive strategy encompassing
proactive risk management, ethical governance, continuous learning and culture change. There is no one-
size-fits-all approach. What may work well for one organisation may not work for others.
Leveraging reusable patterns, such as those highlighted in the Voluntary AI Safety Standard, RAI
patterns17 and process metrics18, can streamline the adoption process and ensure best practices are
followed. The following best practice recommendations aim to guide organisations in effectively
adopting and managing AI technologies while ensuring alignment with broader organisational goals and
ethical standards.
A checklist for AI governance
Adopt a proactive approach: Organisations should continuously learn and adapt to the evolving
AI landscape. This involves fostering a culture of proactive risk management and ethical AI
deployment. By staying ahead of technological advancements and potential risks, organisations
can better navigate the complexities of AI integration.
Integrate AI into existing frameworks: AI considerations should be integrated into existing
organisational structures such as ESG frameworks. This ensures that AI deployment aligns with
broader organisational and governance goals. Add AI specific frameworks on top to address AI
specific issues and to ensure that there are no gaps. Standards such as ISO42001:2023 Artificial
Intelligence management system and the Australian Government’s Voluntary AI Safety Standard
can help with this.
Enhance digital literacy and education: Boards and executives must prioritise digital literacy
and upskilling to effectively engage with AI-related issues. Continuous education and training
programs are essential to equip employees with the necessary skills and understanding of AI
technologies. These programs should focus on developing intuitive standards and clear guidance
for both technical and non-technical users, fostering a knowledgeable and adaptable workforce.
Adopt the Voluntary AI Safety Standard: Adopt comprehensive governance frameworks that
address both internal and third-party AI use. The Voluntary AI Safety Standard supports safe and
responsible AI deployment across all levels of the organisation, including suppliers and partners.
Integrate AI considerations into existing governance frameworks and policies, such as developing
a hardened sandbox environment for testing AI systems and ensuring comprehensive supplier risk
management.
Foster collaboration and adhere to standards: Global collaboration and adherence to
international standards are crucial for effective AI governance. Aligning with frameworks such as
the EU AI Act and other international guidelines ensures responsible AI deployment and promotes
consistency across different jurisdictions. Collaboration also involves sharing best practices and
leveraging reusable patterns like RAI to streamline AI adoption.
17 CSIRO, 2024, Responsible AI Pattern Catalogue [web page].
18 Xia B, Lu Q, Zhu L, Lee SU, Liu Y and Xing Z, 2023, ‘Towards a Responsible AI Metrics Catalogue: A Collection of Metrics for AI
Accountability’, arXiv preprint arXiv:2311.13158.
Governance Institute of Australia – White Paper on AI Governance 37
Conclusion
The three sections of this white paper highlight the multifaceted nature of AI, emphasising its potential
to drive innovation, enhance operational efficiency, and address complex societal and environmental
challenges. However, the adoption of AI also brings significant risks and ethical considerations that
organisations must appropriately identify and navigate.
The roundtable discussions reinforced that responsible AI adoption requires a holistic approach,
integrating ethical considerations, robust governance, proactive risk management, strategic
innovation and culture change. By adopting best practices and aligning with international standards,
organisations can harness AI’s transformative benefits while ensuring compliance with ethical and
regulatory requirements. This comprehensive approach will enable organisations to leverage AI for
strategic success, driving innovation, operational excellence and positive societal impact.
Governance Institute of Australia – White Paper on AI Governance 38
Governance Institute of Australia
1800 251 849
Level 11/10 Carrington Street,
Sydney NSW 2000
[Link]
Governance Institute of Australia – White Paper on AI Governance 39