Deloitte's $290,000 government report scandal, AICD's warning on AI vendor concentration risk, and the UK's new Critical Third Parties regime all expose the same gap: accountability for AI-enabled outcomes can't be outsourced to the vendor that built the tool. Here's what risk and governance teams should check before relying on vendor AI assurances.
APRA, ASIC and the ACCC have all sharpened the rules on AI risk in 2026 — from APRA's step-change governance letter to ASIC's 'Year of Accountability' and the ACCC's doubled penalties for AI-washing. Here's why leaders should treat AI risk management as a business enabler, not a compliance checkbox.
APRA's April 2026 letter to industry and ASIC's Report 798 both warn that boards are leaning on AI vendor assurances instead of independently verifying them. Here is what Australian organisations should be checking before they trust the compliance pack.
Shadow AI is no longer hypothetical: a NSW government contractor uploaded flood victims' personal and health data to ChatGPT, while APRA and ASIC have both issued 2026 letters demanding stronger AI governance and cyber resilience. This post sets out what boards and risk leaders should be asking right now.
APRA's and ASICs AI governance letters have made one thing clear: named business ownership of AI use cases is now the regulatory minimum. Without it, your organisation is carrying unquantified executive risk.
AI initiatives often stall due to unclear ownership and generic vendor assurances. This article explains why business leaders must own AI risks from the start and demand practical, risk-based evidence from third parties to avoid costly delays.
Many organisations unknowingly inherit significant AI risks through third-party technology and vendor services. Without rigorous independent challenge and clear ownership, vendor assurances fall short. Leaders must demand tailored evidence and embed structured AI risk governance that addresses supply chain complexities and local obligations.