First Mill FIRST MILLAI CONSULTING
Free AI use-case audit Accuracy assured Measured monthly No lock-in contracts
Learn / AI strategy

What is AI governance? What a small business needs

AI governance for Australian business: what it means, the six essential practices, the December 2026 privacy rule, and the smallest version that works.

Most Australian businesses did not decide to adopt AI. It arrived, one licence and one embedded feature at a time, and now somebody senior is being asked who signed off on it. That question is what governance is for.

The short answer

AI governance is the set of rules, roles and records that decide how your organisation uses AI and who answers for the outcome. Not the models, not the vendors, not the prompts. Who is accountable, what is allowed, what gets written down, and when somebody checks.

The reason it sounds heavier than it is comes from where the language originated. Governance vocabulary was written for banks and government agencies running credit models and eligibility decisions. A twelve-person firm using AI to draft quotes needs the same four ideas at roughly one percent of the weight.

Why the question is landing now

The Australian Bureau of Statistics put AI use at around 12 per cent of businesses in 2024-25, up sharply from the near-zero rates before generative tools existed. Adoption is heavily skewed by size: about 35 per cent of large businesses, 22 per cent of medium ones, and roughly 11 per cent of small and micro businesses.

Those are the numbers for deliberate, reported adoption. The gap that creates governance problems is the undeclared kind, where a tool is in daily use on real customer data and no one has written it down.

Regulators have started saying so out loud. ASIC reviewed 23 licensees in its 2024 report on AI governance arrangements and titled the findings “Beware the gap”, which is a reasonably clear signal about what it found between AI use and the controls around it. Financial services rules do not apply to most businesses, but the pattern the review describes does.

The six essential practices

In October 2025 the National AI Centre published its Guidance for AI Adoption, which sets out six essential practices for safe and responsible AI governance. It evolves and simplifies the ten guardrails of the earlier Voluntary AI Safety Standard, and it is the most useful starting point for an Australian business because it is free, plain, and written for people who are not lawyers.

  1. Decide who is accountable. One named person, not a committee and not “the leadership team”. Complexity is what creates the gap where nobody owns the outcome.
  2. Understand impacts and plan accordingly. The same tool carries different risk depending on use. An internal drafting assistant and an AI screening job applicants are not the same decision.
  3. Measure and manage risks. Risk management specific to AI, not a line item folded into the existing IT risk register.
  4. Share essential information. People should know when they are dealing with a machine, and you should know which machines you are running.
  5. Test and monitor. AI behaviour drifts. A system that was accurate at launch is not automatically accurate a year later.
  6. Maintain human control. Oversight proportionate to the stakes, with a clear point where a person can pause, override or switch the thing off.

Read down that list and notice how few of the six are technical. Five are organisational. That is the honest shape of the work.

What Australian law actually requires

There is no Australian AI Act. The guidance above is voluntary. What is not voluntary is everything that already applied before AI arrived: the Privacy Act, Australian Consumer Law, anti-discrimination law, work health and safety, and whatever governs your sector.

One obligation has a date on it. The Privacy and Other Legislation Amendment Act 2024 introduced an automated decision-making transparency obligation. From 10 December 2026, entities covered by the Privacy Act that use personal information in automated decisions with the potential to affect a person’s rights or interests must set out in their privacy policy the kinds of personal information used and the kinds of decisions made that way. The OAIC ran a consultation through to June 2026 to inform its guidance on scope.

Businesses turning over $3 million or less usually sit outside the Privacy Act, though health service providers and businesses trading in personal information are covered regardless of turnover. If you are under the threshold, the date is still worth knowing, because your larger customers will start asking you to answer for it in their supply chain.

The smallest version that actually works

For a business with under about fifty people, governance that fits on a few pages beats a framework nobody opens. Four artefacts:

  • An AI policy. What AI may and may not be used for, who approves the risky uses, what data staff may paste into a tool, when a human must review output, how to report a problem, and the review date. The National AI Centre publishes a template that covers exactly these points.
  • An AI register. A list of every AI system in use, including the AI embedded in software you bought for something else. This is usually the artefact that produces a surprise, because it is how you discover three teams running the same unapproved tool on customer records.
  • A named owner. One person accountable, with the authority to say no.
  • A review date in the calendar. Governance that is written once and never revisited stops describing reality within about two quarters.

That is the whole minimum. It is a morning of work and a recurring hour, and it is the difference between being able to answer a client’s security questionnaire and not.

How to tell whether yours is working

Governance is easy to fake and easy to test. Three questions, answered from records rather than memory:

  1. Can you produce the list of AI systems in use, today, without asking around?
  2. For the riskiest one on that list, can you name the person accountable and the last date anyone checked its output?
  3. Has anything ever been refused or paused under the policy?

A policy that has never said no to anything has not been used. That is not always a failure, but it is worth knowing before you claim the process works.

Where governance meets the rest of the work

Governance is not a project on its own. It is the part of an AI strategy that decides what you are allowed to build, and the part of AI foundations that makes the first build defensible. If systems are already running, AI operations is where the monitoring and human-control practices have to live day to day, and the AI maturity assessment is how you find out honestly where you currently sit.

If you are starting from nothing, the free government material above is genuinely enough for a first policy and register, and most small businesses should use it rather than pay anyone. Outside help earns its place when personal information is involved and the setup has to be documented rather than improvised, when a client or insurer is asking you to evidence controls, or when AI is already running in production and nobody can say what it decides.

If that is where you are, the free AI use-case audit looks at what is actually running in your business and what it would take to put proper control around it, in plain English, with no obligation attached. For the systems that control gets written around, see what the AI agency installs. Sydney businesses can also start from the artificial intelligence consultant Sydney page, and Victorian ones from AI consultant Melbourne.

Common questions


What is AI governance?

AI governance is the set of rules, roles and records that decide how an organisation uses AI and who answers for the outcome. It covers what AI is allowed to do, who approves the higher-risk uses, what data staff may put into tools, where a person has to stay in the loop, and how any of that gets reviewed. It is an accountability question rather than a technical one.

What is an AI governance framework?

A framework is the published structure you govern against, so decisions are not made case by case. In Australia the reference points are the National AI Centre's six essential practices, the ten guardrails in the Voluntary AI Safety Standard, and internationally the NIST AI Risk Management Framework. A framework tells you which questions to ask about every AI system. Your policy and register are how you answer them.

Is AI governance mandatory in Australia?

There is no single Australian AI Act, and the National AI Centre guidance is voluntary. Existing law still applies in full: privacy, consumer law, anti-discrimination, work health and safety, and sector rules. One concrete obligation is already dated. From 10 December 2026, entities covered by the Privacy Act that use personal information in automated decisions affecting a person's rights or interests must describe that in their privacy policy.

Does a small business need AI governance?

Yes, but a much smaller version than the word suggests. If staff are putting customer or supplier information into AI tools, you need a written policy, a list of the tools in use, one named person accountable, and a rule about which decisions a human must still make. That is a morning's work, not a programme, and it is the version most small businesses are missing.

What is the difference between AI governance and AI ethics?

Ethics is the set of principles you say you hold. Governance is the machinery that makes them hold when nobody is watching. Australia's AI Ethics Principles describe the intent, such as fairness, transparency and contestability. Governance is the named owner, the approval step before a risky use goes live, the register that says which tools exist, and the review date in the calendar.

What should an AI policy contain?

Six things, per the National AI Centre's own template guidance: what AI can and cannot be used for, who approves higher-risk use cases, what data staff may put into tools, when staff must oversee AI output, how people report a problem or misuse, and when the policy gets reviewed. Anything longer than a few pages tends to stop being read, which defeats the purpose.

What does an AI governance consultant do?

An AI governance consultant helps a business set up and evidence control over its AI use: an inventory of the systems running, a policy staff will actually follow, a named owner, risk checks on the higher-stakes uses, and a review rhythm. For a small business the useful version is a short, bounded piece of documentation and decision-making, not a standing programme.

Related reading
Sources

How every engagement runs

How we work →
01 · Visibility audited
Where Google and AI engines actually rank you. Measured, not guessed.
02 · Fixes implemented
Schema, content and conversion work shipped on your store, not a slide deck.
03 · Impact measured
Rankings, AI citations and conversion deltas tracked every week.
04 · Reported plainly
One monthly report: what moved, what we did, what happens next.