Governance

AI Agent Security: What the RubyGems and Hugging Face Incidents Reveal

Researchers allege OpenAI agents uploaded hundreds of malicious packages to RubyGems in May 2026, before a later intrusion involving Hugging Face. The incidents show why AI agent security requires stronger containment, monitoring and accountable governance.

When Fraud Syndicates Exploit Loan Processes: What Australia’s $600 Million Scam Reveals About Control Failures

NSW police allege a criminal syndicate defrauded banks of up to $600 million using false loan applications and insider help from accountants and money mules. This case uncovers how multi-party collusion exploits gaps in loan processes, demanding tighter fraud controls and cross-agency scrutiny.

Why AI Risk Management Must Treat Privacy as a Dynamic, Context-Specific Challenge

The UK Information Commissioner’s Office expects AI transparency and supply-chain due diligence to evolve as processing purposes become clearer. NIST’s AI Risk Management Framework shows how privacy risk should be documented, measured and monitored throughout the AI lifecycle.

Balancing Security and Privacy: Lessons from Facial Recognition Tests

Coles and Woolworths have described limited facial-recognition testing while emphasising that no deployment decision has been made. OAIC guidance and the Bunnings tribunal outcome show that necessity, proportionality, notice and documented privacy assessment must come before rollout.

Cross-Border Financial Crime Exposes Control and Governance Gaps

NSW Crime Commission Operation Ragamuffin and NSW Police Strike Force Danberta allege deleted sales records, interstate cash movement and restrained assets linked to pork-industry businesses. AUSTRAC’s 2026 risk material shows why cash-intensive operations and opaque structures require integrated financial-crime controls.

When National Alerts Miss Local Needs: Queensland’s Opt-Out from AusAlert

Queensland opted out of AusAlert this bushfire season despite a 94% national test success rate. This isn't about whether that call was right — it's about the resilience discipline it illustrates: weighing your own specific variables today and making a definitive decision ahead of the event that will test it.

Risk Maturity in Action: Turning Customer Promises into Reliable Outcomes

Two recent ASIC matters provide a useful opportunity to think differently about risk management. They can be read as stories about compensation, penalties and compliance shortcomings. But the more valuable question is not simply what...

Regulatory Growth Objective: A New Approach

Treasurer Jim Chalmers's new Statement of Expectations tells APRA and ASIC to back growth, not just guard against risk. The UK gave its regulators the same mandate in 2023 — and a 2025 Lords inquiry found it hadn't shifted the culture at all. Here's what Australian boards should watch for.

Recent posts