Insights from AICD Directors Guide to AI Governance
- David Roberts
- 7 days ago
- 4 min read

The recently released Directors Guide to AI Governance from the Australian Institute of Company Directors (AICD) and the Human Technology Institute (HTI) makes an important point: organisations should stop treating AI governance as a standalone technology issue and instead view it as an extension of good organisational governance, risk management, cyber security and data governance.
What stood out to me was the guide's emphasis that effective AI governance is built on two distinct but interconnected layers:
Foundational governance capabilities – the data, cyber, risk and operational disciplines required to support any digital capability.
The AI governance layer – the additional controls needed because AI systems are adaptive, probabilistic, autonomous and increasingly agentic
Both of these layers are required for AI governance to be effective.
Foundational Governance
The guide is clear that AI governance cannot be separated from data governance and cybersecurity. AI systems are dependent on data quality, data controls and secure digital infrastructure. Weaknesses in these areas can directly undermine AI performance, increase bias, and create regulatory and reputational risk.Â
Organisations should ensure foundational capabilities are ready to support AI, such as:
Data governance and data quality management
Information classification, labelling and lifecycle management
Cyber security controls and monitoring
Risk management and assurance frameworks
Privacy management and impact assessments
Vendor and third-party risk management
Clear accountability and decision-making structures
Workforce literacy and responsible use practicesÂ
In many organisations, these capabilities already exist but are fragmented. AI often exposes these weaknesses rather than creating new ones.
AI Governance Layer
Once foundational controls are in place, organisations can focus on governance specific to AI.
The AI Governance Operating model identifies four key components:
Strategy
Governance Structure
Governance Practices
Governance EnablersÂ
This includes AI-specific capabilities such as:
AI inventories and registers
AI risk assessments
Escalation and human oversight models
Model testing and monitoring
Explainability requirements
AI accountability frameworks
Guardrails and runtime controls for agentic AI
AI literacy programs
Transparency and disclosure obligationsÂ
Increasingly, boards and executives need visibility not only into where AI is intentionally deployed, but also where AI capabilities are embedded inside third-party platforms or being used through "shadow AI" by employees.Â
An AI inventory or register is the starting point for governance – referred to as the ‘baseline’. You can’t govern what you can’t see.
Guardrails: the Critical Control
One of the themes throughout the guide is the importance of establishing practical controls around how AI can operate and what it is allowed to access, decide, create or execute.
While the guide refers to these through risk controls, policies and human oversight mechanisms, in practice many organisations are beginning to describe these controls as AI Guardrails.Â
In ‘Our Approach to Adopting AI’ published by CBA (Australia’s leader in AI adoption and governance) they reference developing ‘Guardrails-as-a-Service’ to prevent AI from creating harmful, inaccurate or inappropriate results.
AI guardrails provide the operational layer that sits between policy and execution. It should enforce the policy at the time of execution.
This means:
Clearly defining the laws, regulations, polices, rules, limitations & guidelines that should be applied to AI systems
Applying those at the time of the AI systems creating a response, making a decision or taking action, ie. in ‘runtime’
Capturing an auditable trail to demonstrate compliance
These controls become even more important as organisations move from generative AI to agentic AI, where systems increasingly act autonomously across multiple systems and business processes. The guide specifically highlights the elevated risks associated with agentic AI and the need for controls, auditability and clear risk boundaries.Â
From Governance Frameworks to Governance Enforcement
Many organisations already have policies. Far fewer have mechanisms that actively enforce them and provide evidence of assurance.
It has been proven that you cannot rely on the guardrails within the frontier AI models. While they may provide some controls, they are grossly inadequate for organisations as their only form of guardrail.
There is a rise of AI governance tools and platforms and tools that can provide an AI control plane and set of guardrails.
Rather than relying solely on policy documents, governance committees and manual reviews, organisations need technical guardrails that continuously monitor, enforce and evidence compliance within AI environments.
Organisations should be aiming to operationalise governance by:
Embedding governance controls directly into AI workflows
Applying policy-driven guardrails
Supporting auditability and accountability
Enforcing risk and compliance requirements in run time and at scale
Helping organisations move from governance intent to governance execution and assurance
As AI adoption accelerates, governance must become more than documentation. It must become an operational capability with evidence of effectiveness.
Final Thought
The AICD guide is an excellent reminder that successful AI adoption is not simply about deploying the latest model. It is about establishing the governance foundations that create trust, accountability and resilience.
The organisations with the strongest governance foundations and the most effective guardrails will be positioned to accelerate the benefits from AI while mitigating the risks.
AI governance starts with data, cyber and risk governance. But its future lies in the ability to operat
ionalise those principles through automated controls, continuous oversight and practical guardrails that enable innovation without compromising scale and trust.
