New Zealand | Governing Corporate AI in Australia 

James Brombergs - 22.09.202620260922

New Zealand | Governing Corporate AI in Australia 

Join our community of 1,000+ IT professionals, and receive tech tips and updates once a week.

Governing Corporate AI in Australia 

New Zealand | Governing Corporate AI in Australia 

For many businesses, artificial intelligence has moved rapidly from experiments and POCs into everyday operations. It now sits behind hiring decisions, credit assessments, customer service, document drafting and analytics. But as AI adoption accelerates, so does the regulatory scrutiny that surrounds it. The question has shifted from capability (can AI do this?) to governance (can we trust AI to do this?).  

Unlike the EU, Australia does not yet have a single, comprehensive, legislated AI Act. However, corporate and government users of AI must comply with a framework of existing legislation, regulatory guidance, sector-specific obligations and government policy whether AI is explicitly included or not. This blog looks at the Australian laws that already apply to enterprise AI, human accountability, recommended compliance posture, and Microsoft tools such as Purview and Entra Agent ID that can help meet these obligations. 

Australian legislation that applies to enterprise AI 

Commonwealth Privacy Act 1988  

Any AI system that collects, trains on, profiles with, or makes decisions using personal information must comply with the Australian Privacy Principles (APPs). This governs lawful collection, use limitation, transparency, data security and breach notification.

Commonwealth Privacy and Other Legislation Amendment Act 2024 

The 2024 reforms strengthened privacy enforcement and sharpened obligations around automated decision-making that significantly affects individuals, increasing transparency expectations and regulatory powers relevant to AI-assisted decisions in credit, employment, insurance and services.  

Commonwealth Competition and Consumer Act 2010 

AI-enabled products and services must not engage in misleading or deceptive conduct. Organisations remain responsible for AI outputs delivered to customers.

Anti-discrimination Legislation 

AI used in recruitment, performance, lending, insurance or eligibility decisions must not produce discriminatory outcomes. The relevant Commonwealth Acts include the Racial Discrimination Act 1975, Sex Discrimination Act 1984, Disability Discrimination Act 1992 and Age Discrimination Act 2004. Liability rests with the organisation deploying the system, making bias testing and human review essential.

Commonwealth Corporations Act 2001

Directors must exercise reasonable care and diligence over material risks and regulators have determined that AI is included. Boards that cannot demonstrate AI oversight, governance and controls face personal liability.  

Information-Security Obligations  

  • APRA CPS 230 (Operational Risk Management) and CPS 234 (Information Security) apply to banks, insurers and superannuation funds, AI systems and material AI service providers must be brought into operational risk and information-security frameworks
  • Commonwealth Security of Critical Infrastructure Act 2018 applies where AI supports critical infrastructure sectors
  • Commonwealth Archives Act 1983 and State/Territory Public Records Acts AI-generated content forming part of official decisions may constitute a record that must be captured, retained and made auditable
  • ASD Information Security Manual (ISM), Essential Eight, PSPF and IRAP specify mandatory security baselines for AI systems handling government data
  • Commonwealth agencies must also meet the Policy for the Responsible Use of AI in Government, including mandatory accountable officials, transparency statements, AI use-case registers, training and impact assessments 

Australian AI Ethics Framework

Although this is a voluntary framework, the principles underpin most Australian AI governance programs. The framework principles cover wellbeing, human-centred values, fairness, privacy, reliability, transparency, contestability and accountability.

Human Accountability

Across every one of these laws sits the consistent expectation that a human must remain accountable for what AI does. Accountability cannot be delegated to AI, and responsibility for any actions taken or decisions made does not sit with the AI or the AI vendor. 

  • Every AI use case and every autonomous agent should have an identifiable human sponsor or owner answerable for its behaviour, access and lifecycle
  • There must be a human in the loop for material decisions. Decisions affecting individuals such as credit, employment, eligibility, health must be subject to meaningful human review and the ability to contest an outcome
  • Board and executive oversight. Directors’ duties require demonstrable governance: risk appetite, controls, monitoring and assurance for AI, not informal experimentation 

AI actions must be auditable. Organisations must be able to explain how an AI decision was made and attribute actions to a responsible person or identity  

Minimum vs. Recommended Compliance Posture

Not every organisation needs the same level of governance on day one. We frame it as a minimum defensible posture (what you should have in place before AI touches production data) and a recommended mature posture (where regulated and higher-risk organisations should be heading).

Control Area Minimum Posture Recommended Posture 
Governance  AI acceptable-use policy and a named accountable executive Cross-functional AI governance committee, defined risk appetite and board reporting 
Privacy  Privacy Impact Assessment for AI using personal data Automated decision-making transparency and contestability processes 
Data protection  Data classification and clear rules on what data may enter AI prompts Sensitivity labelling, DLP and oversharing controls enforced automatically 
Security  Essential Eight / ISM-aligned controls extended to AI environments Continuous monitoring, threat detection and SOC integration for AI activity.  
Risk and fairness  AI risk assessment and bias check before deployment Ongoing bias testing, model assurance and periodic control reviews 
Human oversight  Human review of material decisions; named owner per use case Sponsor model for agents, approval workflows and lifecycle accountability 
Transparency  Disclose where AI generates outputs affecting users Explainability, transparency statements and audit-ready decision records 
Records  Capture significant AI-generated artefacts as records Automated retention, discoverability and lifecycle management 
People Staff AI acceptable-use awareness training Role-based training embedded in onboarding and continuous uplift 

Microsoft Tools 

For organisations using Microsoft 365 and Azure, much of this compliance posture can be operationalised with tooling you may already own or can license. Two capabilities stand out: Purview and Entra Agent ID which together protect the data AI touches and govern the identities AI acts through.

Microsoft Purview 

Purview is Microsoft’s solution for securing and governing data, including data used by AI in Microsoft 365 Copilot, Copilot Studio agents, and third-party AI apps such as ChatGPT and Gemini. Purview Data Security Posture Management (DSPM) for AI gives security teams a central view of how AI interacts with organisational data. Key capabilities that map directly to Australian obligations include: 

  • DSPM for AI discovers AI usage, surfaces oversharing risk, and provides visibility of sensitive data that may be exposed through Copilot and agent interactions
  • Sensitivity labels and Information Protection classify and protect data so AI can’t surface content beyond intended audiences
  • Data Loss Prevention (DLP) can block sensitive information (e.g. PII) being pasted into AI tools, including third-party generative AI sites via Edge
  • Auditing, Communication Compliance and Insider Risk detect risky or unethical AI use, supporting accountability and records obligations
  • Compliance Manager maps regulatory templates and guided assistance to AI regulations

Microsoft Entra Agent ID Governance

As AI agents are deployed, Entra Agent ID gives each agent a managed identity, allowing agents to be governed with the same rigour as people: 

  • A human sponsor per agent requires a named person to be accountable for the agent’s lifecycle and access, with sponsorship automatically transferring to their manager if they leave the organisation
  • Entitlement management and least privilege enforce time-bound, auditable access packages so agents don’t accumulate unaudited standing privileges
  • Conditional Access and Identity Protection for agents evaluate agent risk and can be used to block anomalous or compromised agents
  • Lifecycle workflows mitigate accumulation of orphaned agent identities or lingering permissions
  • Every action performed by a specific agent identity is audited, and can be ingested into Microsoft Sentinel or a third-party SIEM for retention and alerting 

How Insentra can help 

Effective AI governance should help your organisation adopt AI with confidence, not create unnecessary barriers to innovation. 

Insentra helps organisations translate Australia’s evolving regulatory, security and governance requirements into practical controls across data, identity, information management and AI adoption. 

Whether you are starting your AI journey, scaling Microsoft 365 Copilot or introducing AI agents, we can help you build the foundations for responsible and secure adoption through: 

  • AI Momentum engagements to assess your current position, identify governance gaps and define a practical roadmap for responsible AI adoption. Learn more about AI Momentum
  • Information Architecture and Records Management to establish the structures, classification and controls needed to ensure AI works with well-governed information. Learn more about getting your information architecture right for AI
  • Microsoft Purview design and deployment including DSPM for AI, sensitivity labelling, Data Loss Prevention and Compliance Manager to help protect sensitive information and govern how data is used by AI.
  • Microsoft Entra Agent ID governance to establish human sponsorship, least privilege, Conditional Access, entitlement management and lifecycle controls for AI agents.
  • Security control alignment to help design and implement configurations aligned with frameworks such as the Essential Eight and CIS Controls. 

The goal is to give your organisation the confidence to move from AI experimentation to adoption with clear accountability, stronger data protection and governance that can stand up to scrutiny. 

Not sure whether your current AI environment is ready to scale? Contact us about identifying your governance gaps and building a practical path to responsible AI adoption. 

Hungry for more?

If you’re waiting for a sign, this is it.

We’re a certified amazing place to work, with an incredible team and fascinating projects – and we’re ready for you to join us! Go through our simple application process. Once you’re done, we will be in touch shortly!

Who is Insentra?

Imagine a business which exists to help IT Partners & Vendors grow and thrive.

Insentra is a 100% channel business. This means we provide a range of Advisory, Professional and Managed IT services exclusively for and through our Partners.

Our #PartnerObsessed business model achieves powerful results for our Partners and their Clients with our crew’s deep expertise and specialised knowledge.

We love what we do and are driven by a relentless determination to deliver exceptional service excellence.

New Zealand | Governing Corporate AI in Australia 

Insentra maintains ISO/IEC 27001:2022 and ISO/IEC 27701:2019 certifications

We are proud to announce that Insentra has successfully maintained its ISO/IEC 27001:2022 and ISO/IEC 27701:2019 certifications