Australia Has an Office of AI. Does Your Business Have a Plan?

The Great Pyramid of Giza against a blue sky — a structure built to endure, and a question worth asking of your AI governance approach

Australia is finally getting serious about AI governance.

This week, Prime Minister Albanese announced the establishment of an "Office of AI" within the Department of the Prime Minister and Cabinet. The goal is a whole-of-government approach to developing AI standards, coordinating across ministries rather than responding issue by issue. It's a significant moment. It is, as Albanese put it, the difference between figuring out civil aviation by grounding planes one at a time and actually building an air traffic control system.

It's also long overdue.

Australia currently has no specific AI laws. We rely on a patchwork of privacy and consumer protection legislation, plus a voluntary AI ethics framework that most businesses have never heard of. While other countries have been debating regulation, most Australian organisations have been left to work it out for themselves.

Many haven't worked it out at all.

What "working it out" actually looks like

Here's what I see in practice. A business starts using AI tools, usually because someone on the team discovers a productivity shortcut and word spreads. Before long, staff are running sensitive client data through free AI platforms, making decisions based on outputs no one has reviewed, and the business has no clear view of where AI is being used, by whom, or for what.

No one is trying to do the wrong thing. They're just trying to get through the week.

The problem is that "no policy" isn't a neutral position. It's a risk position. When something goes wrong — and it will, somewhere, eventually — the question is whether you had a framework in place or whether you were making it up as you went.

The government establishing an Office of AI is a signal that Australia is moving toward greater accountability. That's welcome. But accountability frameworks built in Canberra are designed for the economy as a whole. They won't tell your team how to use AI responsibly in your specific context, with your specific clients, data, and risk exposure.

That's a leadership question. And it needs a leadership answer.

What good AI governance looks like in practice

I spend a lot of time working with executives and boards who are trying to get their heads around AI. The conversation usually starts with the technology — what does it do, how does it work, what are the risks — but the more useful conversation is about governance.

Governance isn't about restricting AI. It's about using it with confidence. There's a meaningful difference between an organisation that has thought carefully about how it uses AI and one that is reacting to incidents as they arise.

Good AI governance asks a fairly small number of important questions. Who in the organisation makes decisions about which AI tools are adopted? What data is allowed to go into these systems, and what is never allowed? How are AI-generated outputs reviewed before they reach clients or inform decisions? What do you do when something goes wrong? Who is accountable?

These aren't technical questions. They're leadership and culture questions, and they need to be owned by leadership rather than delegated to IT.

The two traps organisations fall into

In my experience working with organisations on AI governance, most fall into one of two traps — and both of them are expensive.

Trap one: treating AI governance as an IT problem. The board approves AI initiatives, the technology team manages them, and governance is assumed to be happening somewhere in the middle. It rarely is. AI decisions that sit entirely within the technology function tend to be evaluated on technical and commercial criteria, with ethical, social, and reputational risks underweighted or invisible at leadership level. When something goes wrong, the executive discovers it has been flying blind.

Trap two: treating AI governance as a compliance exercise. This is the increasingly common overreaction to trap one. Organisations build an AI governance framework because they've been told they need one, populate it with policies and reporting lines, and then tick the box. The framework exists on paper. The decisions that matter are still made the same way they always were. The documentation is defensible; the governance is not.

The organisations that navigate AI well over the next five years will be the ones that avoid both traps: where leadership actually understands AI risk well enough to govern it, and where the framework reflects how decisions are actually made.

Why I built the AI Governance Confidence Framework

The AI Governance Confidence Framework (AGCF) grew out of conversations I kept having with business owners and executives who understood they needed to do something about AI governance but didn't know where to start. The existing guidance was either too abstract or written for large enterprises with legal departments.

The AGCF is designed to be practical and proportionate. It gives organisations a structured way to assess where they currently sit on AI governance, understand what good looks like, and build toward it in a way that is realistic for their size and context.

It covers six areas: strategy and leadership accountability, risk and policy, data and privacy, people and culture, procurement and supply chain, and performance and review. Each area has practical guidance, not theory. The goal is to help leaders make genuinely informed decisions about AI, rather than hoping they've covered their bases.

The organisations that will lead on AI governance in Australia aren't the ones with the most sophisticated frameworks on day one. They're the ones that started the right conversations early and treated governance as a leadership discipline rather than a compliance obligation.

Don't wait for Canberra

The government moving on AI governance is good news. But legislation takes time, and the AI landscape is moving faster than any regulatory cycle. The organisations that invest in getting this right now will be better placed to meet whatever framework eventually comes out of the process, and better placed to build the trust of their clients and teams in the meantime.

This isn't about compliance. It's about leadership. It's about deciding what kind of organisation you want to be as AI becomes part of how work gets done, and putting the structures in place to live up to that.

The Office of AI will help shape the environment. What happens inside your organisation is still your call.

The AGCF is free to access at linkeleadership.com/agcf. Happy to talk through how it applies to your organisation.


Michael Linke is the founder of Linke Leadership, a strategy and leadership organisation based in Canberra.

← Will Your AI Governance Strategy Stand the Test of Time? What ISO 42001 Requires of Boards and CEOs →

The AI Governance Confidence Framework

Built for Australian businesses, boards, and executives. Practical, proportionate, and free to access. Build genuine AI governance confidence without the jargon.

Explore the AGCF Talk to Michael
Or explore: All Frameworks Guides & Resources More Articles