Cyber Ethos

Your Team Is Already Using AI. Is Anyone Governing It?

Here is an uncomfortable question for most boards and executive teams: not “should we adopt AI,” but “who in this organisation is already using it, with what data, and does anyone actually know?”

Because the honest answer, in almost every Australian business right now, is that AI adoption already happened. It did not wait for a strategy paper or a board decision. Someone in finance is pasting figures into ChatGPT to write a summary. Someone in HR is using an AI tool to screen resumes. Your existing software vendors have quietly switched on AI features you never evaluated. The technology is in the building. The governance, usually, is not.

That gap is the real risk, and closing it is more urgent in Australia than most leaders realise, for a reason that surprises people.

In short: AI risk in your organisation is not hypothetical or years away. It is here now, mostly ungoverned, created by staff using tools you may not know about. And Australia has deliberately chosen not to pass an AI Act, which sounds like less pressure but means the opposite: there is no “we complied with the AI law” to hide behind, so the standard you will be judged against is being set by existing law, regulators, insurers and your own customers. The organisations that get ahead of this govern AI sensibly without strangling it, and it is very doable.

The risk is already inside your organisation

Most AI risk articles talk about the future: agentic systems, autonomous decisions, what is coming. That is worth understanding, but it distracts from the point that matters today. The risk is not coming. It is already here, in three ordinary forms.

Shadow AI. Your people are using public AI tools to do their jobs, often helpfully, and often by pasting in customer data, financial information or confidential material that then leaves your control. Most have no idea they are creating a data breach, because the tool is so easy and feels so harmless.

Embedded AI. The software you already pay for, from your CRM to your office suite, keeps adding AI features. Each one processes your data in new ways, and most were switched on without anyone assessing them.

Relied-upon AI. Staff are starting to trust AI outputs without checking them. A confidently wrong answer, a fabricated reference, a subtly biased recommendation, acted on as if it were verified fact. This is where the real damage tends to happen.

None of this requires your organisation to have “adopted AI” in any formal sense. It is happening in businesses that have never held a single meeting about it.

Why Australia’s approach raises the stakes, not lowers them

This is the part boards most often get wrong.

Australia has decided not to introduce a standalone AI Act. The National AI Plan confirmed that AI will be governed through existing, technology-neutral laws and sector regulators, supported by voluntary guidance rather than a dedicated AI statute or mandatory guardrails for business. On the surface, that reads like a lighter touch.

It is actually heavier, and here is why. When there is a specific law, “we complied with it” is a defence. When there is not, that defence does not exist. Your AI use is still fully governed, just by laws that were already there: the Privacy Act when AI mishandles personal information, the Australian Consumer Law when an AI tool misleads a customer, anti-discrimination law when an AI decision is unfair, and copyright law when generated content infringes. Regulators apply these to AI failures using powers they already hold.

And increasingly, the standard of care is being set outside the law altogether: by insurers pricing AI risk into your cover, and by your own enterprise customers writing AI clauses into their contracts and procurement questionnaires. In that environment, “there was no rule against it” protects no one. Sensible governance is not box-ticking. It is how you stay insurable, win contracts, and avoid becoming the case study.

The direction of travel is clear too. From mid-2026, Commonwealth agencies became subject to their own mandatory AI requirements, including impact assessments and appointed AI officers. What government mandates for itself has a way of becoming the expectation it holds of its suppliers.

Show Image

Governance without strangling innovation

The goal is not to ban AI. Businesses that lock it down entirely just push it further into the shadows and forfeit the genuine benefits. The goal is to let people use AI productively inside sensible guardrails, so you capture the upside without carrying invisible risk.

Helpfully, you do not need to invent the framework. Australia’s National AI Centre has published guidance built around six essential practices, which have become the practical baseline for responsible AI use here. Translated into plain English, they are your governance checklist:

  1. Decide who is accountable. Name a person or group responsible for AI in your organisation. Unowned risk is unmanaged risk.
  2. Understand the impact. Before using AI for something that affects people, customers, staff, or decisions about them, think through what could go wrong and who it could affect.
  3. Manage the risk. Fold AI into how you already assess and treat risk, rather than treating it as a separate mystery.
  4. Be transparent. Be clear, internally and with customers, about where and how you use AI, especially where it affects them.
  5. Test and monitor. Check that AI tools are doing what you think, and keep checking, because their behaviour and your usage both drift over time.
  6. Keep humans in control. Make sure a person, not a model, holds final responsibility for consequential decisions, with the ability to review and override.

Notice that none of these are technical. They are governance disciplines, and they are the same instincts a good board already applies to every other kind of risk.

What to actually do first

If you want somewhere concrete to start this month, in order:

  • Find out what is actually being used. Ask your teams, honestly and without blame, which AI tools they use and for what. You cannot govern what you cannot see, and people will only tell you if it is safe to.
  • Write a short, readable AI use policy. Not a fifty-page document nobody reads. A page or two that says clearly what staff can and cannot put into AI tools, which tools are approved, and when a human must check the output. Plain rules people will actually follow.
  • Set a hard line on data. The single most important rule for most businesses: never paste customer, personal, financial or confidential information into a public AI tool. That one guardrail removes a large share of the risk.
  • Keep a simple AI register. A running list of where AI is used across the business, including the features baked into your existing software. This is the AI equivalent of an asset inventory, and it is the foundation everything else sits on.
  • Assess your higher-risk uses. Any use of AI to make or heavily influence decisions about people, such as hiring, credit, eligibility or performance, deserves real scrutiny for accuracy and fairness before you rely on it.
  • Fold it into what you already have. If you run ISO 27001 or an enterprise risk framework, AI risk belongs inside it, not in a separate silo. For organisations that want to formalise further, ISO 42001 is the international standard for an AI management system, and it slots alongside the governance you already run.

This is a board issue, not just an IT issue

The instinct is to hand AI to the IT team and move on. That is a mistake, because the biggest AI risks are not technical failures. They are governance failures: a discriminatory decision, a privacy breach, a misled customer, a confidential leak. Those land on the board and the executive, not the help desk.

Directors do not need to understand how a large language model works. They need to ask the questions any responsible board asks of a material risk. Who owns AI here? What are we using it for, and where could that harm someone? How would we know if it went wrong? Can we override it? If the leadership team cannot answer those clearly, that is the finding, and the place to start. Translating this kind of technical risk into questions a board can act on is precisely where governance succeeds or fails.

How Cyber Ethos helps

Cyber Ethos helps Australian boards and executive teams get their arms around AI risk without slowing the business down or drowning it in jargon. We help you find where AI is really being used, set a practical policy and guardrails your people will actually follow, assess your higher-risk uses, and fold AI governance into the security and risk frameworks you already run rather than bolting on another silo. Led by Dr Kiran Kewalramani, a governance specialist and board advisor, our focus is turning AI risk into decisions a board can make with confidence.

Want to know where your AI risk really sits? Book a consultation or call 1800 CETHOS (1800 238 467), and we will help you see it clearly and decide what to do about it.

Frequently asked questions

Does my business need to follow an AI law in Australia?

There is no standalone AI Act in Australia, and none is currently planned. But your AI use is still governed by existing laws, including the Privacy Act, Australian Consumer Law, anti-discrimination law and copyright law, which regulators apply to AI failures. Because there is no dedicated AI law to comply with, “there was no rule against it” is not a defence, which makes sensible governance more important, not less.

What is shadow AI, and why is it a risk?

Shadow AI is staff using AI tools that the organisation has not approved or does not know about, often by pasting sensitive data into public tools like ChatGPT. It is a risk because that data leaves your control, potentially creating a privacy breach, and because nobody is checking the AI’s outputs for accuracy or bias. The first step to managing it is simply finding out, without blame, what your teams are actually using.

Where do I start with AI governance?

Start by finding out what AI is actually being used across your business, then write a short, readable AI use policy, set a hard rule against putting confidential or personal data into public AI tools, and keep a simple register of where AI is used. Australia’s National AI Centre guidance sets out six practical practices: decide accountability, understand impact, manage risk, be transparent, test and monitor, and keep humans in control.

Is AI risk an IT problem or a board problem?

Both, but primarily a board and executive one. The most serious AI risks are governance failures, such as a discriminatory decision, a privacy breach or a misled customer, and those land on leadership, not the IT team. Directors do not need technical knowledge, but they do need to ask who owns AI, what it is used for, how the organisation would know if it went wrong, and whether a human can override it.

Can we manage AI risk without banning AI?

Yes, and banning it usually backfires by pushing use into the shadows and forfeiting the benefits. The aim is to let people use AI productively inside clear guardrails: an approved-tools list, firm data rules, human review of consequential outputs, and scrutiny of higher-risk uses. Good governance enables safe adoption rather than blocking it.

Kiran Kewalramani

Kiran Kewalramani

Kiran Kewalramani stands as an acclaimed technologist with over two decades of robust executive experience in technology, cybersecurity, data privacy and cloud solution enablement. His illustrious career has been marked by transformative roles in esteemed organizations, including Cyber Ethos, Queensland Department of Education, Gladstone Area Water Board, NSW Rural Fire Service, NSW Police Force, Telstra, American Express, and more.