top of page
Search

AI Governance: Does Your Board Know How AI Is Being Used in Your Organisation?

Writer: ailsaveiszadeh
ailsaveiszadeh
3 hours ago
4 min read

I recently attended the Associations Forum Symposium and one of the sessions I found particularly interesting was on AI governance, ethics and risk.

 

Like most people, I've been watching how quickly AI is becoming part of the way we work. But one of the things that struck me during this session was that, for organisations, we're probably past the point of talking about whether we are going to use AI.

 

We already are.

 

Staff are using it, executives are using it, and increasingly AI is built into software we're already using for example CoPilot and Gemini. That means there may be AI operating within an organisation that nobody has really stopped to think of as "AI".

 

From a governance perspective, that's a fairly important distinction.

 

The Board doesn't need to understand every new AI tool or become a group of technology experts. But it does need to have some idea of what's being used across the organisation and be asking questions about it.

 

  • What are we using?

  • What information are we putting into it?

  • What information can it access? Are we using it to help make decisions? And who is checking the result?

 

One of the points made during the session was that accountability can't be delegated to AI. It can help with analysis and decision-making, but ultimately a person, a human, still needs to be responsible for the decision that may be influenced by AI technology.

 

That seems obvious when you say it, but I suspect it's something organisations are going to have to think about more and more.

 

Start with what you’re already using

One of the practical things organisations can do now is simply work out where AI is already being used. And that doesn't just mean asking whether people are using ChatGPT. AI functionality is increasingly being incorporated into the software we use every day. So, it is worth looking at your existing systems as well as standalone AI tools.

 

  • What information do those systems have access to? Where is that information stored?

  • Is it being shared with another provider?

  • Has somebody actually looked at the privacy and security implications?

 

This also needs to be considered when buying new software. Privacy, cybersecurity and governance probably need to be part of that conversation before a contract is signed, rather than something considered afterwards.

 

Banning it probably isn’t the answer

This was probably one of my favourite points from the session.

If you make AI use something staff feel they shouldn't admit to, you don't necessarily stop them using it. You may just stop them telling you they're using it. And then you have an entirely different governance problem.

 

I'd much rather have an environment where someone feels comfortable saying, "I've been using AI to help me do this", so the organisation can decide whether that use is appropriate and put some sensible parameters around it.

 

Not all AI use presents the same level of risk either.

Using AI to help draft an internal document is quite different from using it to make, or influence, a decision about a person, like whether you will move a candidate on to an interview after they apply for a position. The controls around those things shouldn't necessarily be the same.

 

There is also a December deadline worth knowing about

Something else raised at the Symposium was the change coming on 10 December 2026 relating to automated decision-making and the Privacy Act. For organisations covered by the Privacy Act, there are new transparency requirements around certain automated decisions that significantly affect individuals.

 

One example discussed was recruitment.

If an organisation uses an automated tool to assess applicants and determine who should progress to interview, that isn't just an efficiency tool. There are privacy and governance considerations attached to how that decision is being made and how the organisation discloses its use of automated decision-making.

 

It's probably a good example of why Boards need to understand how technology is actually being used within their organisation rather than assuming this sits somewhere with IT.

 

So, what should a Board be asking?

I came away from the session thinking that this doesn't have to start with a huge AI governance project.

 

  • It could start with some fairly basic questions:

  • What AI tools are we currently using?

  • Which of our existing systems now have AI functionality?

  • What information can they access?

  • Are we putting personal, confidential or organisational information into them?

  • Is AI being used anywhere to make or influence decisions?

  • Who is responsible for checking the output?

  • Do our existing privacy, cybersecurity and other policies actually cover what we're doing?

 

And then keep asking those questions, because the answers are going to change.

 

I don't think any organisation can realistically say it has AI completely sorted at the moment. The AI landscape is moving too quickly.

 

But there's a big difference between not having all the answers and not knowing what is happening.

 

Boards don't need to become AI experts.

They just need to make sure somebody is asking the right questions.

 

These are my own takeaways from the Associations Forum Symposium session, “AI Governance, Ethics and Risk: What Boards and CEOs Need to Know”. This is general commentary rather than legal advice.

 
 
 

Comments


CONNECT VIRTUAL

© 2026

ABN 21 692 347 187

  • Instagram
  • Facebook
  • LinkedIn
Connect Virtual_Icon_Hi-res digital 300ppi transparent.png
Join our newsletter

Thanks for subscribing!

bottom of page