securiti-verification-id=tPzHErjuz0wZ8Fo+gEjE0zAeNu8ndMOAEvtAxHW5A6I= Insights from AICD Directors Guide to AI Governance
top of page
Search

Insights from AICD Directors Guide to AI Governance

  • Writer: David Roberts
    David Roberts
  • 7 days ago
  • 4 min read

The recently released Directors Guide to AI Governance from the Australian Institute of Company Directors (AICD) and the Human Technology Institute (HTI) makes an important point: organisations should stop treating AI governance as a standalone technology issue and instead view it as an extension of good organisational governance, risk management, cyber security and data governance.


What stood out to me was the guide's emphasis that effective AI governance is built on two distinct but interconnected layers:

  1. Foundational governance capabilities – the data, cyber, risk and operational disciplines required to support any digital capability.

  2. The AI governance layer – the additional controls needed because AI systems are adaptive, probabilistic, autonomous and increasingly agentic


Both of these layers are required for AI governance to be effective.


Foundational Governance

The guide is clear that AI governance cannot be separated from data governance and cybersecurity. AI systems are dependent on data quality, data controls and secure digital infrastructure. Weaknesses in these areas can directly undermine AI performance, increase bias, and create regulatory and reputational risk. 

Organisations should ensure foundational capabilities are ready to support AI, such as:

  • Data governance and data quality management

  • Information classification, labelling and lifecycle management

  • Cyber security controls and monitoring

  • Risk management and assurance frameworks

  • Privacy management and impact assessments

  • Vendor and third-party risk management

  • Clear accountability and decision-making structures

  • Workforce literacy and responsible use practices 


In many organisations, these capabilities already exist but are fragmented. AI often exposes these weaknesses rather than creating new ones.


AI Governance Layer

Once foundational controls are in place, organisations can focus on governance specific to AI.


The AI Governance Operating model identifies four key components:

  • Strategy

  • Governance Structure

  • Governance Practices

  • Governance Enablers 


This includes AI-specific capabilities such as:

  • AI inventories and registers

  • AI risk assessments

  • Escalation and human oversight models

  • Model testing and monitoring

  • Explainability requirements

  • AI accountability frameworks

  • Guardrails and runtime controls for agentic AI

  • AI literacy programs

  • Transparency and disclosure obligations 


Increasingly, boards and executives need visibility not only into where AI is intentionally deployed, but also where AI capabilities are embedded inside third-party platforms or being used through "shadow AI" by employees. 


An AI inventory or register is the starting point for governance – referred to as the ‘baseline’. You can’t govern what you can’t see.


Guardrails: the Critical Control

One of the themes throughout the guide is the importance of establishing practical controls around how AI can operate and what it is allowed to access, decide, create or execute.


While the guide refers to these through risk controls, policies and human oversight mechanisms, in practice many organisations are beginning to describe these controls as AI Guardrails. 


In ‘Our Approach to Adopting AI’ published by CBA (Australia’s leader in AI adoption and governance) they reference developing ‘Guardrails-as-a-Service’ to prevent AI from creating harmful, inaccurate or inappropriate results.


AI guardrails provide the operational layer that sits between policy and execution. It should enforce the policy at the time of execution.


This means:

  • Clearly defining the laws, regulations, polices, rules, limitations & guidelines that should be applied to AI systems

  • Applying those at the time of the AI systems creating a response, making a decision or taking action, ie. in ‘runtime’

  • Capturing an auditable trail to demonstrate compliance


These controls become even more important as organisations move from generative AI to agentic AI, where systems increasingly act autonomously across multiple systems and business processes. The guide specifically highlights the elevated risks associated with agentic AI and the need for controls, auditability and clear risk boundaries. 


From Governance Frameworks to Governance Enforcement

Many organisations already have policies. Far fewer have mechanisms that actively enforce them and provide evidence of assurance.


It has been proven that you cannot rely on the guardrails within the frontier AI models. While they may provide some controls, they are grossly inadequate for organisations as their only form of guardrail.


There is a rise of AI governance tools and platforms and tools that can provide an AI control plane and set of guardrails.


Rather than relying solely on policy documents, governance committees and manual reviews, organisations need technical guardrails that continuously monitor, enforce and evidence compliance within AI environments.


Organisations should be aiming to operationalise governance by:

  • Embedding governance controls directly into AI workflows

  • Applying policy-driven guardrails

  • Supporting auditability and accountability

  • Enforcing risk and compliance requirements in run time and at scale

  • Helping organisations move from governance intent to governance execution and assurance


As AI adoption accelerates, governance must become more than documentation. It must become an operational capability with evidence of effectiveness.


Final Thought

The AICD guide is an excellent reminder that successful AI adoption is not simply about deploying the latest model. It is about establishing the governance foundations that create trust, accountability and resilience.


The organisations with the strongest governance foundations and the most effective guardrails will be positioned to accelerate the benefits from AI while mitigating the risks.


AI governance starts with data, cyber and risk governance. But its future lies in the ability to operat

ionalise those principles through automated controls, continuous oversight and practical guardrails that enable innovation without compromising scale and trust.

 
 
 
bottom of page