More service. The same people.

1 official

accountable for AI, named before the first pilot. The Australian Government's policy for responsible use of AI asks for one; the Guardrails Framework starts there.

Agencies and councils are asked to deliver more with the same staff. Correspondence volumes grow, statutory clock times stay fixed, and community expectations follow what the private sector trains people to expect. The work that can move is the reading, sorting, drafting and assembling, with a public servant deciding.

Federal agencies · Local government and councils · National security agencies

The 1879 council chamber at Port Elliot, South Australia
Transparent by default. On the record by design.

What we hear from agencies and councils.

The same four pressures, whether the counter is a federal call centre or a shire office.

01

Correspondence volume

Ministerials, complaints, requests and submissions arrive faster than they can be read, registered and allocated, and every one has a clock.

02

Records obligations

Every decision must be findable later. Records are made by hand, late, or not at all when the queue is long.

03

Applications and permits

Planning, permit and grant applications checked for completeness by hand, with the same missing documents chased every week.

04

Procurement rules

Any AI tool must clear privacy, security and value-for-money gates before a pilot, which stops most pilots before they start.

First use cases, with the number we scope to.

Each is scoped in the free audit with a target, an accountable official and a human decision point. The targets are what we set; the audit puts your own number on them.

Target: registered and allocated the same day

Correspondence triage

Inbound mail read, classified, registered against the records system and allocated to the right team with a draft acknowledgement, for an officer to check before anything goes out.

Target: every gap named at lodgement

Application completeness

Applications checked against the published requirements at lodgement, missing items requested automatically, and the file marked complete or not before an assessor picks it up.

Target: a record for every decision

Decision records

Briefs, file notes and decision records drafted from the file and the meeting, with sources shown, saved to the records system on the officer's sign-off.

The rules that apply.

Public sector AI has more written rules than any other sector we work in, and most of them are helpful. This is what we check each use case against. It is not legal advice; it is the list your governance committee will ask about.

  1. 01
    Privacy Act 1988 and state privacy law. The APPs for Commonwealth agencies; the PPIP Act in NSW, the Privacy and Data Protection Act in Victoria and the Information Privacy Act in Queensland for state and local bodies.
  2. 02
    Records legislation. The Archives Act 1983 and state records acts (Public Records Act 1973 in Victoria, State Records Act 1998 in NSW). A record an agent drafts is still a public record.
  3. 03
    Policy for the responsible use of AI in government. The Digital Transformation Agency's policy, in force since September 2024, asks Commonwealth agencies for an accountable official and a published transparency statement.
  4. 04
    Protective Security Policy Framework and the Information Security Manual. Data classification, the Essential Eight, and where an AI service may be hosted. IRAP assessment where the classification requires it.
  5. 05
    Local government acts and procurement rules. Council decision-making, delegations and procurement thresholds shape how a tool is bought and who may act on its output.

Guardrails that matter most here

  1. 01
    Named ownership: the accountable official, in the register, with the authority to pause.
  2. 06
    Plainly disclosed: the public is told when an agent drafted or sorted something, in a transparency statement people can find.
  3. 07
    Open to challenge: a decision an agent influenced can be questioned and looked at again by a person.

How a first engagement usually runs.

Three women in a meeting
Photograph: Australian Department of Foreign Affairs and Trade, CC BY 2.0

Week one and two: the free audit, scored against your privacy, records and security obligations rather than a generic checklist. We walk the correspondence flow and one application flow with the officers who run them, and name the accountable official with you.

Weeks three to eight: one use case, usually correspondence triage, on a free trial, with the transparency statement drafted alongside it and every action written to the records system. Nothing goes to a member of the public without an officer's check.

Then the roadmap, with the next use case chosen by the number the first produced. Everything runs against the Guardrails Framework, which is a plain-English translation of the same standards your policy already cites.

Questions.

Can an agent make a decision about a member of the public?

No. Agents read, sort, draft and assemble. The decision, and the record of who made it, stays with an officer. That boundary is written into every workflow before it goes live.

Where is the data hosted?

Where your classification allows. The audit maps each use case's data flow, including which models run where. Australian-hosted and IRAP-assessed services are available for the classifications that need them.

Does this satisfy the DTA's AI policy?

The policy asks for an accountable official, a transparency statement and internal AI governance. The Guardrails Framework gives you all three in a form a 30-person council can run, and the audit tells you which parts you already have.

Where do we start?

With the free audit: a readiness scorecard, your three highest-return use cases with a number on each, and a 90-day roadmap. Three hours of your time.

Can AI be used for decisions affecting the public?

AI should prepare decisions, not make them. Our government use cases keep the delegate in the loop: the system assembles, checks and drafts, the accountable officer decides and signs. Full traceability supports review and FOI rather than fighting it.

Where does the data go?

Nowhere it should not. Deployments run inside your controlled environment with data sovereignty respected, permissions enforced at the data layer, and nothing training public models. Architecture is assessed against your security framework before anything runs.