Home | Partners | Sophos partner | AI Governance
AI Governance for Australian Businesses
AI governance is the set of decisions, policies and controls that determine which AI tools your business uses, what data goes into them, who is accountable for the output, and how you prove any of it. For an Australian SME in 2026 it is no longer optional housekeeping: your staff are already using AI, your clients are starting to ask about it in contracts, and the Commonwealth has signalled that mandatory standards are coming. 4iT builds practical AI governance for Sydney SMEs, sized to a business of twenty to a hundred people rather than to a bank.
Sydney MSP
Greater Sydney, NSW
- Microsoft Partner
- Sophos Partner
- Ubiquiti Partner
Quarterly
review cadence for most clients

Key facts
- Australia has no AI Act. The National AI Plan of 2 December 2025 chose to govern AI through existing technology-neutral laws and sector regulators rather than a standalone statute.
- That position has since shifted: the Government announced an Australian Standards for AI framework in July 2026 and established an Office of AI, with reporting that National Cabinet endorsed developing those standards as mandatory on 26 August 2026 and legislation flagged for early 2027.
- The Voluntary AI Safety Standard and its ten guardrails remain the published Commonwealth guidance, and they align to ISO/IEC 42001:2023 and the NIST AI Risk Management Framework.
- ISO/IEC 42001:2023 is the certifiable AI management system standard, with 38 Annex A controls across nine objectives, and it integrates with ISO 27001 because both use the same harmonised structure.
- The Privacy Act applies to AI use today with no amendment needed, and serious interferences carry penalties up to the greater of AU$50 million, three times the benefit obtained, or 30 per cent of adjusted turnover.
- 4iT delivers AI governance as a staged engagement: discovery of what is already in use, a policy and register your staff will actually follow, then the technical controls behind it.
What does AI governance actually cover?
Six things, and they are all answerable in a morning for most SMEs. Which AI tools are approved and which are not. What data may be put into them, and what may never be. Who is accountable when an AI output is wrong and it reaches a client. What gets disclosed, to staff and to customers. What records you keep. And who reviews it when the business or the tooling changes.
What it is not is an ethics statement. A page on your website saying you use AI responsibly is not governance, because nobody can act on it and nobody can audit it. The test is whether a new starter could read your policy and know, on day one, whether they may paste a client contract into a public chatbot.
Why does an SME need this now?
Three forces, and only one of them is regulatory.
The first is that the tools are already in the building. In every environment we have assessed this year, staff were using AI tools nobody had approved, usually on a personal account outside the tenant, usually with real client data. That is a data exposure and a confidentiality problem before it is anything else.
The second is commercial. Enterprise and government clients have started adding AI clauses to contracts and questionnaires, asking whether you use AI in delivering their services, whether their data trains a model, and what your governance framework is. “We have not thought about it” is becoming a losing answer in a tender.
The third is regulatory, and it is the one with a clock on it. Australia decided in December 2025 not to legislate mandatory guardrails, then reversed direction through 2026 with an Australian Standards for AI framework, an Office of AI, and National Cabinet endorsement of mandatory standards with legislation flagged for early 2027. Businesses that already run to the voluntary guardrails will find that transition cheap. Businesses starting from nothing will not.
What does 4iT actually do?
- Discovery. We find what AI is already in use, including the tools nobody told you about, by looking at tenant sign-in data, browser and endpoint telemetry and expenditure, not by sending out a survey.
- Risk and impact assessment. We work out where AI touches personal information, client confidentiality, decisions about people, or anything you would have to explain to a regulator.
- Policy and register. A short AI acceptable use policy people will actually read, and an AI register that records every approved tool, what it is used for, what data it touches and who owns it.
- Technical controls. The enforcement half: tenant-level controls on which AI services are reachable, data loss prevention rules on what can be pasted or uploaded, Copilot and Microsoft 365 permission clean-up, and logging.
- Review. Quarterly for most clients, because the tool list changes faster than the policy does.
We map the result to the Voluntary AI Safety Standard guardrails, so when the mandatory standards land you are mapping to something rather than starting from zero, and to ISO/IEC 42001 where a client intends to certify.
Do we need ISO 42001 certification?
Most SMEs do not, and we will tell you that rather than sell you a programme. Certification is a real project with external audits, a three-year cycle and annual surveillance, and it makes sense when a major client or tender requires it, or when AI is core to what you sell. For everyone else, using ISO/IEC 42001 as the structure without certifying gives you most of the benefit for a fraction of the effort.
The exception worth watching: if you already hold ISO 27001, adding 42001 is far less work than it looks, because both standards share the same harmonised structure and the management system you already run does most of the lifting.
Frequently Asked Questions
There is no AI Act. AI is governed by existing laws, including the Privacy Act, consumer law, copyright and sector-specific regulation, supported by the Voluntary AI Safety Standard. That picture is changing: the Government announced an Australian Standards for AI framework in 2026, with mandatory standards endorsed by National Cabinet and legislation flagged for early 2027, so the sensible position is to run to the voluntary guardrails now.
Approved tools, prohibited data, who is accountable for checking AI output before it goes to a client, what must be disclosed, and who owns the policy. Three or four pages. If it runs to thirty, nobody reads it and it protects nothing.
You can, and it will not work. A ban moves the usage onto personal accounts and personal devices where you have no visibility and no control, which is a worse position than approving two tools and controlling them. Every blanket ban we have been asked to enforce has produced more shadow AI, not less.
For a 20 to 50 person business, two to four weeks to discovery, assessment, policy and register, then the technical controls alongside. The ongoing part is a quarterly review, which is usually an hour.
Heavily. Putting personal information into an AI tool is a use and sometimes a disclosure, and Australian Privacy Principle 11 still requires reasonable steps to protect it. Most of the AI governance work we do doubles as privacy work, which is why we run the two together rather than as separate engagements.
If you do not know which AI tools your staff are using right now, that is the place to start and it takes us a few days to answer. Get in touch to arrange an AI governance review.
Ready to Talk to a Sydney IT Specialist?
4iT Support covers SMEs across Greater Sydney including the Hills District, North Shore, Parramatta, and the CBD. No lock-in contracts. Straight answers.







