The Director’s Manual That Grades Its Own Homework
A national directors' institute and a university institute just published the best AI governance manual in the run. It names its vendors, insists on human oversight, and routes every assurance line straight back inside the building. Here is what the guide's own diagrams admit, and the five checks to run before your next AI approval.
In an August 5th Fusion Forum post, I talked about the Queensland government readiness paper published last October that designed itself as its own auditor. In June 2026 Australia's national directors' institute published the polished version of the same design, opened by a minister, aligned with the National AI Plan. It names its vendors. It insists on human oversight. Then it routes every assurance line straight back inside the building. Here’s what the guide's own diagrams admit, and the 5 checks you should run before your next AI approval.
A government minister wrote the foreword. And that’s where I want to start, because it tells you just how much authority this document carries before a director ever reads a single page.
"A Director's Guide to AI Governance," version 2, June 2026, comes from the Australian Institute of Company Directors and the Human Technology Institute at the University of Technology Sydney. The Honorable Senator Tim Ayres, Minister for Industry and Innovation, opens it. AICD's CEO and HTI's co-director sign the partners' foreword. 55 pages, with a full operating model, case studies from CBA, Westpac, Telstra, Atlassian, and Canteen, an appendix mapping every relevant Australian law.
And I read all of it so you can decide whether to or not.
You will quickly recognize the core problem because I flagged it in my August 5, 2026, post. The Geological Survey of Queensland and FrontierSI published "Governance in the Age of AI," a state-agency readiness paper that built an accountability chain running entirely inward and called its own internal assurance role "independent." This new guide is the national version of that same framework. It aligns itself with the National AI Plan, the National AI Centre's six essential practices, and the new Australian AI Safety Institute, then designs board oversight as one more internal loop. Taken together, thee state paper and the national guide are the same argument running at two different levels.
Not going to bury the lead and make you wait until the end. So, here’s the verdict up front. The national guide is the better document. It’s more honest than the vendor security frameworks I have taken apart (assessed), and more vigilant than the Queensland paper. And it’s that exact reason why the gap it shares with the Queensland paper matters more, not less.
The Good
My assessment only lands if you trust I’ve read the whole thing, so let me give credit where the guide really earns it.
Let’s start with the vendors because the guide names them. Figure 1 lists Anthropic and OpenAI by name as the makers of the generative models your organization runs on. The strategy section states plainly that most AI tools are built on foundation models from companies such as Anthropic and Google. The guide doesn’t pretend your organization built the intelligence it governs. That candor, especially for a document like this, is rare and it grounds everything I’m about to debate.
Human oversight comes next and the guide refuses to soften it. The ministerial foreword, the partners' foreword, and the board-role section all say the same thing: AI supports the board and never substitutes for it. Justice Michael Lee, quoted in the guide, warns against a quiet normalization of directors leaning on computer-generated summaries. The guide takes that warning seriously.
Concentration risk gets a real solid mention as well. The vendor section names fourth-party cloud exposure and the shareholdings that tie model providers to hyper-scale cloud infrastructure. Most board guidance published these days never gets that specific.
So, this isn’t a hit piece or takedown of a bad document. No, not at all. It’s a closer look at a very good document, aimed at the single line it draws in the wrong place.
Follow the assurance and then watch where it actually goes
Every governance model answers one question that decides whether it works or not: who checks the work, and can they say no.
Now, trace this guide's answer through its own diagrams.
The model sits outside your walls. By the guide's own account, you don’t build nor control the foundation model. Anthropic, OpenAI, and Google do. Your real governance surface for the model itself is a contract with the company that made it.
The assurance sits inside your walls. The AI Governance Operating Model routes risk management, assurance, and reporting through the board and management. The recommended bodies are an internal AI committee, often management-led, an Accountable Official or Chief AI Officer, a stack of risk subcommittees. Now, read the chain. It runs entirely inward.
Any outside check stays optional. The guide mentions engaging an external expert to advise the board and commissioning external assurance or audit. It frames both as choices for larger organizations, then warns against becoming overly reliant on external experts. Hugging Face was able to find out it had a problem because it had a 3rd party looking at its walls. Independent verification is the softest recommendation in the entire assurance section.
Now compare that design to how the field actually caught the breaches I have been documenting all year.
Hugging Face detected OpenAI's evaluation intrusion because an outside party was watching. Anthropic, after finding its own evaluation breakouts, brought in METR, an external evaluator, and handed over transcripts and model samples. In both cases, the check that worked came from outside the organization that caused the problem.
This guide? It has no METR, but it has committees of committees reporting to the sponsors who fund the program, and an optional outside adviser it tells you not to lean on. The document that names Anthropic and OpenAI as your model-makers never once contemplates that a model-maker's own systems could reach into your environment, including during that vendor's internal testing, and hack you. And that’s precisely what happened in the July 2026 OpenAI and Hugging Face breakout. The guide's risk tables have no row for it. None.
The gap you can see in one table
Table 5 is straight up the operational heart of the guide, the page a real board could actually work from. Its agentic AI row lists a documented risk appetite for agent tasks, access controls on what agents can read or action, and logging of agent actions. Each of them sound controls but every single one of them facing inward. Its cyber security row lists rapid patching, encryption, red teaming. Again, controls you apply to systems you run. Not one control on that page addresses the case where the risk starts in the vendor's environment and crosses into yours.
The guide's own vendor section admits the bind. It says accountability remains with your organization even when the risks originate with vendors. Then it hands the board a control table with no vendor-substrate row and no contractual notice mechanism.
Read those two things together and you get the inversion in a single sentence: the guide tells the board it owns a risk upstream and gives it no control that reaches upstream.
Part 3 quietly argues against Part 2
The measurement section is where I found the guide to be the most candid, and where a thorough director should slow down.
Part 3 reports that 80% of organizations have seen no profitability impact from generative AI, a figure that traces to MIT's NANDA "State of AI in Business 2025" study, and that 95% of AI pilots fail, from the same study. It then reports KPMG's Global AI Pulse for the first quarter of 2026, where 64% of organizations claim meaningful business value, rising to 82% among the mature minority KPMG calls AI leaders. It adds that relatively few organizations have moved past the pilot phase at all.
Now place Part 3 next to Part 2 and you get a core ripping tension that the guide never resolves. The operating model asks for the deployment of heavy internal machinery, committees, officers, registers, reporting cadences, to govern investments that, by the guide's own account, mostly don’t pay off yet. The returns concentrate in a small, mature group. But the governance overhead applies to everyone. A board that builds the full structure for a pilot that joins the 95% has governed a loss with great discipline.
The same inversion, moved one level up
When a vendor writes the security manual, the inversion is super easy to spot. The company that sells you the model writes the rulebook that puts breach-survival onto you while the breach-causing design stays upstream where you can’t reach it. You should expect the conflict, so you are actively looking for it.
But when a government agency writes the readiness manual, the inversion hides better, because you’re reading it from the assumption that the government is supposed to be the independent party in the room. And that’s the trap I walked you all through in the Queensland paper published in October 2025. When you read its chain of accountability, it runs entirely inward: an Accountable Official, an Executive Steering Group, a Strategy Officer, a stack of subcommittees. All the while, the assurance role is called independent and objective, and it reports to the same steering group that sponsors the program. Independence on an org chart is a completely different animal from independence in fact.
This national guide repeats the design at higher level and with better production values. Its AI Governance Operating Model recommends an internal AI committee, often management-led, an Accountable Official or Chief AI Officer, and internal risk subcommittees. External assurance appears once, but as an option for larger organizations, followed by a warning against becoming overly reliant on external experts.
The Queensland paper called its internal reviewer independent, while the national guide calls its optional external reviewer a risk. Same inversion just better dressed.
Now let’s set both Australian documents against how the field actually caught the breaches this year.
- Hugging Face detected OpenAI's evaluation intrusion because an outside party was watching.
- Anthropic, after finding its own evaluation breakouts, brought in METR, an external evaluator, and handed over transcripts and model samples.
The check that worked? Well, it came from outside the organization that caused the problem, in both cases. The Queensland paper had no METR. The national guide has no METR either. But what do both have? Both have committees reporting to sponsors.
My take and it’s my personal opinion: A directors' institute is the one actor in this assessment with the standing to actually be the independent auditor the vendor frameworks lack, and AICD is better placed to do it than a single state agency.
Full stop.
It could tell its members exactly which contractual notice clause to demand from every model provider, which external verification to commission, and what independence in fact looks like next to independence on an org chart.
The Queensland paper missed that chance because it was one agency governing itself. This guide has the reach to fix it for every board in the country and spent it on internal committees instead. And that’s the costliest choice in the document, and it’s the one nobody will flag, because a minister's foreword and a 55-page operating model read like the answer.
The guide is roughly 90% right and I will say it’s the same 90% the Queensland paper got right. And the missing 10%? Well, it’s the same missing 10%: the part that reaches the way the model actually breaks.
Five checks you could and should run before your next AI approval
Like the recommendation provided in my Anthropic Zero Trust Agents assessment; keep everything in the guide worth keeping, which is most of the document. Then add the five checks it leaves out. You can start this month, this quarter or today.
- Add the upstream row to the risk table. Take Table 5 and add one line the guide omits: for every AI system, name the risk that originates in the vendor's environment and crosses into yours. Score that risk before you score data quality or token policy. The OpenAI and Hugging Face breakout is what that row looks like when nobody wrote it down.
- Ask the substrate question in writing. Before you label a system as low risk, answer one thing on paper. Do you control the model, the evaluation environment, and the disclosure timeline, or does a vendor? If a vendor owns those, your real governance surface is limited to your contract. The guide never gives you that contract, so draft it: written notice within a fixed window whenever the vendor's systems touch yours, even during the vendor's own internal testing.
- Name your METR. Both Australian documents give you an internal committee and call it independent, and this guide adds an optional external adviser but tells you not to depend on. Reverse that. Identify the one outside party with the standing and the access to verify your AI controls and make its review a standing requirement for any high-impact system. METR didn’t audit itself into that role. Anthropic invited it. An assurance body that reports to the people who fund the program is a review board, not an auditor.
- Reconcile the returns tension yourself. For every proposed AI investment, write down which phase it’s in, experimentation, integration, or scaling, and what the guide's own Part 3 says about returns at that phase. If the system is a pilot, plan for the 95% outcome and have the governance overhead to match. Reserve the full operating model for systems you are scaling with the evidence behind them.
- Map the AI6 to a control you can test. The guide adopts the National AI Centre's six essential practices, ending in maintain human control. Translate each one into a control with a test and an owner and make practice six specific: name the exact decision a human must be able to reverse, the time window to do it, and who holds the authority. A principle you can’t test is a value statement, not a control.
A vendor drew this line in the wrong place, then a state agency drew it in the same wrong place, and now the national institute has redrawn it there too, in the best-produced document of the three. The line moves the same way each time: name the outside auditor, write the vendor contract, pull the deferred controls forward. Move it once at national scale and every board that adopts this guide inherits the fix instead of the gap.
Your next step. Open whichever readiness or governance framework your organization runs on, vendor, state, or this national guide. Find the column, the clause, or the role that covers a vendor's evaluation breaking into a stranger's systems. If it’s not there, you are trusting the exact party with the most reason to stay quiet than tell you when it happens.
Share this article
Related Articles
The Reskilling Illusion: When AI Transformation Means "You're Fired"
Oct 03, 2025