You're Funding AI. Who Owns the Outcome?
The 5 questions every executive should run before approving more AI investment.
Over the last couple of months, I've been struck by how often decision mapping is still coming up in conversations with boards and leadership teams. It keeps surfacing as an unresolved issue, even as AI adoption continues to accelerate.
During a board risk committee meeting earlier this year, the CRO was asked a direct question: whether any of the AI tools used in the market or credit functions could produce an outcome that would require disclosure under the new APP 1.7 rules coming into effect in December. He said he would need to check.
Three weeks later, the answer came back. At least four tools were already making or heavily influencing decisions that could trigger the disclosure requirement. None of them had a documented owner at executive level.
The tools themselves weren't the problem. The absence of clear ownership was. When no one is explicitly accountable for the decisions a tool is shaping, the exposure doesn't stay contained. It drifts upward until it eventually sits with the people who approved the spend in the first place.

Funding the build while ignoring the breach
The recent Federal Budget committed to lifting the R&D expenditure threshold to $200 million by 2028. The commercial signal from government and shareholders is pointing in one direction: build, adopt, and deploy AI capability.
Parallel to this, a serious breach of the Privacy Act now carries active penalties up to $50 million. The layer between the incentive to build and the penalty for a breach is the governance problem I am watching play out. Very few executive teams are funding that middle layer..
Directors are approving capital for new models, copilots, and agentic workflows based entirely on vendor presentations. The technology functions deploy them to the business. The operational layer then absorbs them without mapping how the underlying decisions change or who assumes the new risks. This leaves the board exposed on two fronts simultaneously.

The 10 December 2026 deadline
From 10 December 2026, new automated-decision rules under the Privacy Act (APP 1.7 to 1.9) require an organisation to explicitly disclose in its privacy policy where it uses a computer program to make decisions that could significantly affect a person's rights or interests.
You cannot disclose what you have not mapped. Finding those hidden decisions takes months of forensic workflow analysis. The exposure sits entirely in the decisions you did not know the products were making on your behalf.
Your D&O insurer reads that exact same signal
APRA wrote to every bank, insurer, and super trustee on 30 April 2026, explicitly stating that governance and assurance practices are failing to keep pace with AI adoption. They noted a dangerous over-reliance on vendor presentations instead of internal assurance.
ASIC identified the exact same gap in REP 798, after reviewing 624 use cases across 23 licensees. A consumer lender in that review was running an AI credit-scoring model it could not explain. No one inside the business could name the variables driving a customer's score.

You cannot delegate duty of care to a model
The legal shield for directors is narrowing......On 21 May 2026, the Chief Justice of NSW, Andrew Bell, delivered the Harold Ford Memorial Lecture on directors' duties and AI. Australia is not writing AI-specific corporations law.
Section 180 still requires directors to exercise care and diligence themselves, even where AI shaped the recommendation. Section 189 may protect reliance on people and board structures, but it does not clearly extend to reliance on a model as the adviser.
AI can support the judgment, but it does not take the judgment off the director.
*Applied AI Australia this week:*Season 3 is here. New episode coming on APP 1.7, automated decisions, and the governance work boards need to start now.
Listen on Apple Podcasts or Spotify.
Compliance exposure runs parallel to a massive waste of capital
BCG studied 1,250 firms and found 74% of companies using AI still have not produced commercial value. McKinsey's data shows the same....
Nearly eight in ten companies have deployed the tools, while roughly the same proportion report no material impact on earnings.
The reason for the wasted capital is the exact same reason the compliance gaps exist: companies are treating AI like a software installation instead of a workflow redesign.
Fund the workflow change, not the AI tool
During my time in General Management at News Corp, driving a turnaround that delivered 160% revenue growth across a legacy portfolio, I learned a simple lesson: technology only shows up in the numbers when the work changes.
We once rolled out a six-figure CRM platform across a commercial sales team. Training was done. Launch support was in place. Six weeks later, one of our best sales leaders showed me her paper notebook. She was still managing pipeline there because the new system took three extra clicks to log a call, and her managers were not using it as the source of truth either.
The tool was good. The workflow around it was worse than what she already had, so she ignored it.
The same failure pattern is now showing up in AI.
Tools are being deployed without the workflow being redesigned. Teams bolt AI onto broken processes and then wonder why the promised time savings disappear into review, rework and confusion.
That exposes the board on both sides: you spend money you can't track to a result, while holding risk you can't explain. The orgs that win force discipline on three things:
- what they fund
- what work stops
- who owns the P&L result.
The OWNER Checklist
For every material AI initiative, the board must confirm five fields. Any field left blank means the initiative is not board-ready.
- O. Outcome: a named, measurable P&L or strategic target. Vague terms like productivity or efficiency are rejected. Which number moves? Revenue, cost, time, or risk.
- W. Who owns it: one named accountable executive. Never a committee or a working group. Diffuse ownership means no one is accountable when value or compliance fails.
- N. Next review: the cadence, plus the specific trigger metric that forces an off-cycle look if accuracy degrades.
- E. Engine change: the exact workflow you redesigned and the specific manual step you retired. Eliminate, automate, and reallocate.
- R. Risk and exposure: privacy (APP 1.7 mapped), conduct, duty of care, and D&O status documented.
Handing AI to the technology function makes the board feel covered, but it does not protect the directors. A CTO can own parts of the technology, security, and control environment. Business-model change and capital allocation belong to the CEO and the P&L owners.
When reviewing the live AI list, you must ask the questions that surface the operating reality.

What to do next
Before Friday: ask management for a one-page register of the three largest AI initiatives currently running in the business.
Run the OWNER checklist against each one.
What number does it move, who owns it, how often is it reviewed, what work has changed, and what exposure does it create?
Then ask the single question that started the CRO's workflow mapping: which of our AI tools are actively making decisions about our customers, and is our APP 1.7 disclosure on track for 10 December 2026?
Forward this to the person on your leadership team who owns AI.

About Applied AI Australia
Applied AI Australia helps executives turn AI into measurable business outcomes.
Staying up to date with AI is hard, so we publish a regular podcast and weekly newsletter to give busy executives the judgment they need in less than an hour a week.
Listen on Spotify orApple Podcasts.
Executive AI Briefing
A limited number of executive briefing slots are now open following the acquisition of Applied AI Australia by Acquire Intelligence.
We are keeping availability tight so the work stays senior, practical, and close to the decisions that matter.
I'm now taking executive briefings with Australian boards and executive teams. We surface where AI matters in your business, what risks need control, and what the right next step looks like before any budget is committed.
What we'll cover
- Where AI is already affecting growth, margins, time, and risk in your business, including governance implications under APP 1.7.
- Which business problems are worth investigating now, and which are noise.
- The right next step: audit, workshop, roadmap, or pilot.
Disclaimer: Nothing in this newsletter is legal, financial, or professional advice. It is research, pattern recognition, and practical operating observations for Australian boards and executives. Before acting on any of it, speak with your own adviser**.**
Ready to deploy AI with confidence?
Get board-ready frameworks and strategic guidance for Australian executives navigating AI transformation.
Discuss your AI problem