Introduction

AI is already in your organisation. Is your governance?

The most honest answer to the question “what is our AI risk?” is, for many Boards right now, “we do not yet know in full”. That admission is uncomfortable. It is also the right starting point.

Conventional risk frameworks assume that a risk can be described, ranked and assigned an owner before controls are put in place. Artificial intelligence inverts that sequence. The technology is advancing faster than most oversight rhythms, use cases are multiplying inside organisations through vendor systems and individual experimentation, and the harm pathways are still being mapped. As the Australian Institute of Company Directors observed in March 2026, waiting for perfect clarity is, in effect, a decision to accept risk.

That observation is not an argument for paralysis, nor for another lengthy policy. It is an argument for governance mechanisms that surface risk as it evolves, rather than after the fact. For directors, audit and risk committee members and executives charged with governance, four mechanisms matter most.

1. An AI inventory you can actually rely on

You cannot govern what you cannot see. Most organisations underestimate where AI is already operating, particularly where it is embedded in third-party systems such as cloud platforms, HR and payroll tools, customer service software and procurement systems. There is also the issue of unsanctioned use, where staff input sensitive information into public AI tools without disclosure or approval.

The Australian Government’s Voluntary AI Safety Standard, and the more recent Guidance for AI Adoption issued by the Federal Department of Industry, Science and Resources in October 2025, both make accountability and visibility across the AI supply chain a foundational expectation. A current AI inventory, refreshed regularly and inclusive of embedded vendor AI, is the foundation on which every other control depends.

2. Clear autonomy boundaries

Boards do not need to understand the technical detail of every model. They do need to be clear on where AI is permitted to act, where it may recommend but not decide, and where a human must approve. IT teams should, however, be aware of the detail and should provide necessary information to the CEO, who provides assurance to the board. Setting those guardrails and boundaries surfaces the high-risk use cases, focuses assurance effort where it counts, and gives executives a defensible position if outcomes are later challenged. This is also where directors’ duties of care and diligence under the Corporations Act 2001 are most directly engaged.

3. A reporting cadence proportionate to the pace of change

Annual policy reviews are not enough for a technology that shifts meaningfully every quarter. A practical baseline includes a standing AI item on the audit and risk committee agenda, with reporting on incidents and near misses, material model or vendor changes, and any new high-risk use cases. A full board briefing once or twice a year keeps directors connected to the substance, not just the headlines. CommBank research published in January 2026 found that Australians correctly distinguished AI-generated images only 42 per cent of the time, below the rate of random guessing. Trust-based controls, such as recognising a familiar voice or writing style, no longer work in isolation. Reporting cadence and the questions asked at the table need to reflect that.

4. Third-party assurance with AI-specific scope

Many of the most material AI dependencies sit outside the organisation. Contracts with vendors who embed AI in their products often pre-date current expectations on transparency, audit rights and incident notification. A focused and regular review of critical supplier contracts, with AI-specific questions about model changes, data use and breach reporting, is one of the most practical uplift activities available to a board this year.

The accountability point

AI does not change who is accountable. Directors, executives and those charged with governance retain responsibility for decisions made with AI assistance, for control failures and for the consequences that follow. What is changing is the standard of diligence a reasonable director is expected to apply. Stakeholders, regulators and auditors are asking increasingly specific questions about AI oversight, and “we did not know” is unlikely to remain a sufficient answer.

The more reassuring point is that governing AI well does not require certainty about every risk. It requires the discipline to keep looking, the structures to keep reporting, and the willingness to act on what is found.

How Moore Australia can help

Moore Australia’s Governance and Risk Advisory teams work with Boards and Audit and Risk committees to put AI governance arrangements and guardrails in place that are practical, proportionate and ready for the conversations stakeholders are already having. That includes diagnostic reviews to map current AI use and governance maturity, design of governance frameworks and reporting cadences, internal audit and assurance over high-risk use cases, and uplift work on third-party arrangements.

If your Board is asking the right questions but is not yet confident in the answers, that is a useful place to begin a conversation.