Blog
Field notes on AI governance, written by a practitioner.
Long-form writing for risk, security, and board readers. Framework-anchored, regulator-literate, and informed by what actually happens in mid-market deployments.
Privacy Act
The Privacy Act reforms changed the AI compliance baseline. Most organisations have not updated.
The Privacy and Other Legislation Amendment Act 2024 brought a statutory tort, expanded OAIC enforcement, and surfaced automated decision-making in legislation. The AI deployments most Australian organisations are running now sit under privacy obligations they were not designed for.
AI · Authorisation
MCP and the new authorisation surface nobody is reviewing
Model Context Protocol turns every internal API into a tool an agent can call on a user's behalf. The authorisation model most teams ship with is naïve, and the audit log usually proves it.
Digital employees
Digital employees, with the governance attached
Why most digital employee deployments fail their first audit, and what a governance-first build looks like: identity, data access, supervision, and the accountability question almost no-one is answering well.
APRA CPS 230
Mapping APRA CPS 230 to your AI tooling: a practical checklist
Translating CPS 230 material service obligations to Microsoft 365 Copilot, ChatGPT Enterprise, and Claude deployments: what changes when an AI vendor becomes a material service provider.
Platform engineering
Securing CI/CD pipelines without slowing engineering down
Pipeline security is the gap between policy and reality. Most regulated firms have written rules about code review and signed releases that the actual pipeline does not enforce, and the audit evidence is whatever the runner happened to print to stdout.
Shadow AI
Shadow AI in financial services: discovery without panic
A staged discovery method for surfacing personal AI account usage without destroying staff trust or productivity. What to look for, what to ignore, and what to do with what you find.
Stay informed
Get new posts by email.
One email a fortnight. Long-form content only, no promotional sequences. Unsubscribe at any time.
Get started
Bring AI risk under board oversight in two weeks.
A thirty-minute discovery call costs nothing. We confirm fit, scope, and timing, then issue a fixed-fee statement of work within two business days.