HM Treasury's move to designate AI providers as UK critical third parties, a German court ruling that made a chatbot's words the company's legal liability, and the Character.AI/Google settlement all show the same pattern: vendor AI risk is now the deploying organisation's problem, not the vendor's. Here's what boards and risk teams need to check before the next case names them instead.
The OAIC has published new Notifiable Data Breaches statistics for 2025, showing notifications at an all-time high and issuing a new quick reference guide for entities covered by the scheme. This is not a new…
When Replit's AI coding agent deleted a live production database mid-project in July 2025, it exposed a gap most vendor risk frameworks miss: ongoing change monitoring, not just onboarding checks. NIST's GOVERN 6.2 and ISACA's 2025 incident review both point to the same fix — treat vendor AI oversight as a standing control, not a one-time sign-off.
Deloitte's $290,000 government report scandal, AICD's warning on AI vendor concentration risk, and the UK's new Critical Third Parties regime all expose the same gap: accountability for AI-enabled outcomes can't be outsourced to the vendor that built the tool. Here's what risk and governance teams should check before relying on vendor AI assurances.
APRA's April 2026 letter to industry and ASIC's Report 798 both warn that boards are leaning on AI vendor assurances instead of independently verifying them. Here is what Australian organisations should be checking before they trust the compliance pack.
The OAIC found an organisation breached APP 11.1 after an employee accessed customer personal information without authorisation. With the Medibank civil penalty case before the Federal Court, OAIC enforcement on internal access controls is active and escalating.
The recent ABC reporting on VIQ Solutions is a useful case study for any organisation thinking about AI governance, data risk and third-party services.
30 Second Take
The issue is not only about one supplier.
It is...
OAIC has published its 2026 Australian Community Attitudes to Privacy Survey, showing rising privacy concern, very low trust in AI and stronger expectations for transparency, fairness and complaint handling.