Governance framework · Australia
A note for boards and their advisers
'We did not program it to do that' is not a defence at the disparate impact standard.
Boards are deploying AI into high-volume operational decisions while retaining accountability structures designed for deterministic systems. This creates a gap between how decisions are made and how responsibility is exercised—a gap that existing governance frameworks do not address.
Large language models learn from historical data. That data encodes past organisational behaviour—including behaviours that were once legal but are now prohibited under Australian law. The optimisation functions that make AI effective at operational decisions will rediscover these patterns precisely because they worked. This is not a design flaw. It is how the technology functions.
Output shaping—alignment techniques, bias filters, fairness constraints—operates at the wrong layer. It can modify what the system produces. It cannot reach back into what the system has learned. The patterns remain in the model. The risk does not go away because the output has been shaped.
Australian discrimination law does not require discriminatory intent. Disparate impact—outcomes that disadvantage a protected class—is sufficient to establish liability. This is the operative standard.
The exposure crystallises at the intersection of three facts:
Once the evidence of prohibited patterns in training data is established as a known risk, the question for regulators and courts becomes: what did the organisation do to prevent those patterns from being installed in current operations? That question applies to every AI system already deployed.
Not all AI deployments carry equal exposure. The risk concentrates in a specific profile:
This profile is the governance triage test. It identifies where the reasonable steps obligation is most exposed and where board liability attaches first.
Technical compliance does not reach this problem. Documenting the model, following vendor best practice, and running pre-deployment bias testing are necessary but not sufficient. They address the design layer. The problem is in the data.
A defensible governance position requires three things:
The 'don't deploy' option is underused. For high-volume operational decisions, the risk/benefit calculation often does not close once liability exposure is properly priced. Deployment decisions made under competitive pressure, without a documented governance trail, are the most exposed.
Current AI governance frameworks are built around design intent. They ask: was the system built correctly?
The regulatory direction of travel—in Australia and internationally—is toward a different question:
You knew the prohibited patterns were in the data. You could not fully isolate them. What did you do to prevent them from being installed in current operations?
This is not a technical question. It is a governance question. The answer does not live in the model documentation. It lives in the board papers, the pre-deployment decisions, and the ongoing monitoring records.
Most organisations cannot yet demonstrate a defensible answer.