Why read this
Read this when an AI proposal is moving from experimentation into an enterprise risk, procurement, or architecture review.
Classify the use before choosing the control
The right control depends on the data, people affected, decision authority, harm potential, and recovery path. Classify the use case, not just the model name, and document the reason for each control.
Evidence: Australian Government AI in Government Policy, Australian Government essential AI practices
Make evidence and accountability visible
Keep an evidence pack with the intended use, data map, evaluation results, known limitations, security assumptions, human review, incident path, supplier terms, and change history. A governance label is not a substitute for those records.
Evidence: OAIC artificial intelligence and privacy guidance, Australian Cyber Security Centre guidance
Test the operating boundary
Challenge prompt injection, data leakage, unauthorised access, unsafe actions, biased outcomes, stale sources, and supplier changes. Give operators a clear stop, escalation, and correction path.
Evidence: Australian Government essential AI practices, Australian Cyber Security Centre guidance
Questions for the buying team
- What data may enter the system and where does it go?
- Who can approve, review, correct, and stop the system?
- What evidence will an auditor, customer, regulator, or incident responder need?
Local evidence boundary: this guide organises questions and sources. It is not a legal, security, clinical, financial, procurement, or implementation approval.
Sources and further reading
- Australian Government AI in Government Policy standards guidance
- Australian Government essential AI practices standards guidance
- OAIC artificial intelligence and privacy guidance standards guidance
- Australian Cyber Security Centre guidance standards guidance