Privacy

Why Clear Third-Party AI Evidence Requirements Are Non-Negotiable for Risk Management Success

ASD’s Australian Cyber Security Centre and the UK National Cyber Security Centre show why AI supplier assurance must cover the full lifecycle and extended supply chain. Moffatt v Air Canada demonstrates that business accountability remains with the organisation using the automated service.

Why AI Risk Management Must Treat Privacy as a Dynamic, Context-Specific Challenge

The UK Information Commissioner’s Office expects AI transparency and supply-chain due diligence to evolve as processing purposes become clearer. NIST’s AI Risk Management Framework shows how privacy risk should be documented, measured and monitored throughout the AI lifecycle.

Balancing Security and Privacy: Lessons from Facial Recognition Tests

Coles and Woolworths have described limited facial-recognition testing while emphasising that no deployment decision has been made. OAIC guidance and the Bunnings tribunal outcome show that necessity, proportionality, notice and documented privacy assessment must come before rollout.

Why AI Risk Management Must Address Vendor Change Controls to Prevent Operational Disruption

Microsoft Azure AI Foundry and Amazon Bedrock show how model retirement can shorten notice periods, stop requests and require code changes. The EU's DORA framework shows why notification, objection and exit rights must connect to a tested operational response.

Third-Party AI: Someone Else Built the Autopilot, but You’re Still Flying the Plane

APRA's April 2026 letter named third-party AI risk as the biggest gap in bank and insurer oversight — and weeks later, a compromised account at AI tooling vendor Context.ai gave attackers a path into Vercel's infrastructure. This piece uses both to show why vendor assurance paperwork isn't AI risk management, and what to ask instead.

Regulator sharpens the warning on facial recognition

The OAIC has updated its facial recognition guidance for APP entities using biometric technology in high-volume, publicly accessible retail spaces. The update reflects the ART’s March 2026 Bunnings decision and reinforces that each deployment needs…

Beyond Model Risk: Managing AI Risks Embedded in Complex Vendor Ecosystems

Three real 2026 outages — AWS's cascading Middle East failure, Microsoft Copilot's five-hour blackout, and Claude's multi-model cascade — show why AI risk management can't stop at the vendor you signed with. With EU AI Act deployer obligations enforceable from August 2026 and Gartner naming \u201cfourth-party\u201d AI risk directly, boards need to map the AI hiding inside their vendors' vendors.

The Qantas privacy finding: a positive lesson in third-party oversight

A serious data breach does not automatically mean governance failed. The more important question is whether an organisation can demonstrate that it understood the risks, assessed the third party, monitored its controls and responded effectively...

Recent posts