Topic · 7 posts
AI governance
Every Inline Code post tagged AI governance, ordered most recent first.
AI research
The state of AGI: what the evidence supports, and what it does not
A sober read of the AGI evidence in 2026: what frontier systems can measurably do, what expert forecasts actually say, how seriously to take the existential question, and what the research shows about humans and AI working together.
AI governance
The AI register: the audit artefact every framework now assumes you have
Auditors, regulators, and insurers now open with the same request: show me the list of your AI systems. What an AI register is, what ISO 42001, NIST AI RMF, the EU AI Act, and Australian government policy expect it to contain, and how to keep one alive.
Security leadership
Fractional CISO services in Australia: cost, scope, and when the model works
What a fractional CISO actually does, what the role costs in Australia, the failure modes nobody advertises, and where the always-on digital CISO fits next. A straight guide for mid-market boards weighing their security leadership options.
AI · Architecture
Long-term memory for agnostic agents: a working architecture on Bedrock AgentCore
Bedrock AgentCore gives you a managed runtime, a long-term memory store, and a deliberately framework- and model-agnostic SDK. That keeps the agent code portable while the memory plane becomes the new audit liability. Here is the architecture that uses AgentCore Memory properly, the governance controls memory-poisoning and Privacy Act obligations force on top of it, and the rollout cadence that keeps the deployment defensible.
Board reporting
Reporting AI risk to the board: a one-page position summary that actually works
What the board actually wants on the AI risk page is the answer to four specific questions. Most AI risk reports answer different questions. Here is the structure that lands, four worked examples by sector, and a template you can lift verbatim.
Privacy Act
The Privacy Act reforms changed the AI compliance baseline. Most organisations have not updated.
The Privacy and Other Legislation Amendment Act 2024 brought a statutory tort, expanded OAIC enforcement, and surfaced automated decision-making in legislation. The AI deployments most Australian organisations are running now sit under privacy obligations they were not designed for.
Regulatory horizon
The EU AI Act has reach. Australian firms should map exposure now.
The Act's territorial scope is broader than most Australian general counsel offices have appreciated. Two questions decide whether your AI deployment is in scope, and the documentation burden if it is, is non-trivial.
Browse other topics
Get started
Bring AI risk under board oversight in two weeks.
A thirty-minute discovery call costs nothing. We confirm fit, scope, and timing, then issue a fixed-fee statement of work within two business days.