In short
Executive Summary
- Ask for a named inventory of workflows, not an AI strategy update, or the board will be briefed on the wrong systems
- Ask who owns the privacy-policy wording and which law firm or internal counsel will sign it before 10 December 2026
- Ask where a human is supposed to review the output, and whether that review is real
- Treat silence and Unsure as the finding. A clean paper that cannot name workflows is not assurance
Detail
Overview
The board pack I keep seeing is a slide about generative AI pilots and a line that legal is monitoring Privacy Act reform. That pack cannot tell a director whether the organisation will have a complete privacy policy on 10 December 2026.
Ask these in order. First: where do computer programs currently influence decisions about individuals, using personal information. Demand a list of workflows, not a catalogue of tools. Second: which of those workflows are in the current privacy-policy draft, and which are still Unsure. Third: who is the executive owner of the inventory, and who is the legal owner of the final wording. Those are different jobs. If one person is both, the board should know that too.
Fourth: where a human is described as being in the loop, what do they actually do. Independent review is a practice. A click on a recommended list is not. Fifth: which vendors run part of the workflow, and whether the organisation still treats itself as the party that arranged for the program to be used. Sixth: what happens if the deadline arrives with Unsure still on the page. Hope is not a control.
Keep the papers short. A one-page register with owners and dates beats a 30-page AI ethics statement that never names a decision. The OAIC will not be reading your values slide. Affected people will be reading the policy.
This is not a request to the board to become privacy lawyers. It is a request that directors refuse to be briefed only on the tools the organisation is proud of.
Commercial impact
Why It Matters for Organisations
After 10 December 2026, the question is no longer whether the organisation meant to disclose. It is whether the policy matches the decisions people already experience. Directors who only saw the chatbot program will not have overseen the claims scorer.
Corporations Act duties sit with the directors regardless of how fashionable the technology is. APP 1.7 is a privacy-policy rule, but the failure mode is operational: no inventory, no owner, late legal review, and a December paper that asks the board to note a draft they cannot test.
There is also a sequencing problem. Legal cannot approve kinds of decisions that operations has not supplied. Operations will not supply them unless someone with authority asks. That someone is usually the board, once, in plain language, with a date attached.
Podcast
Listen to how Australian executives are applying AI
Use the podcast to pressure-test the ideas in this article against real operator conversations. Each episode focuses on what leaders are shipping, where the friction is, and what actually lands.
The trusted source for Australian executives navigating AI strategy, governance, and adoption. I translate technical complexity into practical business outcomes — growth, margins, and time-to-value.
In practice
Examples or Practical Context
A board asked “are we ready for the AI transparency deadline” and received a yes based on a completed AI policy for staff use of ChatGPT. The live decisions sat in underwriting and collections. The right follow-up was “show us the workflow list”, not “when was the AI policy approved”.
Another board was told a vendor “handles compliance”. The useful question was who arranged for the program to be used in the organisation’s decision process, and whose privacy policy the customer actually reads. Vendor contracts do not write your APP 1.7 wording for you.
A people-and-culture paper said hiring managers always review AI rankings. The board asked for the override rate. Nobody had it. That is a finding. You cannot claim independent review without a way to see whether it happens.
Where Unsure stayed on the register two meetings running, the board set a date for a Rapid Review rather than another verbal update. The date did the work the discussion had not.
What to do
Key Takeaways
- Demand a workflow inventory with owners, not an AI-tool catalogue
- Separate the executive who owns the map from the counsel who owns the policy wording
- Test “human in the loop” with evidence of independent review, not with an org-chart line
- Treat Unsure that survives more than one meeting as a gap, not as a status
- Set a date before 10 December 2026 for legal sign-off on the actual disclosure text
Newsletter
Get the Executive Brief each week
Stay ahead of the next board question with short, practical analysis built for Australian executives. It cuts past recycled AI news and focuses on the decisions that matter now.
The trusted source for Australian executives navigating AI strategy, governance, and adoption. I translate technical complexity into practical business outcomes — growth, margins, and time-to-value.
Assessment
Run the AI Readiness Assessment
Pressure-test oversight, accountability, and decision rights before risk shows up in the wrong place. Governance and decision control is one of the five dimensions the assessment scores.
The trusted source for Australian executives navigating AI strategy, governance, and adoption. I translate technical complexity into practical business outcomes — growth, margins, and time-to-value.
Read next
Where this sits
Explore This Pillar
Next step