The accountability gap is structural, not incidental — and it sits between three functions that each assume someone else owns it
AI governance in Australian government communications has not failed because agencies lack diligence. It has failed because the functions responsible for managing risk were each designed to own a different slice of a problem that no longer divides along those lines. Legal teams assess AI through an administrative-decisions lens — asking whether automated outputs constitute reviewable decisions under the Administrative Decisions (Judicial Review) Act 1977. Digital leads treat content generation tools as procurement line items — evaluated at panel entry, then largely invisible to governance processes thereafter. Communications divisions operate under creative-approval workflows that presuppose human authorship at every stage: a copywriter drafts, a director reviews, a senior officer signs. When the copywriter is a large language model, that workflow does not break — it simply proceeds, with the fiction of human authorship intact at the point of sign-off and the accountability gap hidden inside it.
Three frameworks, three remit assumptions, one blind spot
The APS AI Ethics Framework, the Digital Service Standard, and the Communications 2.0 guidelines were each written with distinct and internally coherent remit assumptions. The AI Ethics Framework (DISER, 2019, updated 2023) addresses AI as a decision-support or automated-decision tool — its eight principles are calibrated to contexts where AI recommends or decides, and a human reviews that output. The Digital Service Standard governs service design and delivery, with its accountability logic built around named team members responsible for each touchpoint. Communications 2.0 governs tone, accessibility, and cultural safety for citizen-facing content, with its obligations falling on the agency as author. None of these instruments anticipated AI as an upstream content generator — a system that produces the sentences, selects the images, and constructs the narrative that a human then approves, often without visibility into how that output was generated or what the model's known failure modes are.
The diffusion of responsibility when incidents occur
When an incident does occur — a health campaign containing a factually incorrect drug interaction warning, a recruitment advertisement that encodes demographic bias from training data — responsibility diffuses across branch heads, contracted vendors, platform providers, and the individual officer who pressed approve. Senate Estimates questions cannot easily trace that diffusion. The absence of a named accountability officer is not an administrative oversight that can be corrected after the fact; it is a structural feature of how AI-assisted communications tools have been absorbed into existing workflows without corresponding governance reform. The pattern is predictable, the exposure is real, and the instruments needed to close it are available — they simply have not been applied to this domain.
Existing APS policy instruments assume human authorship at the point of sign-off — a fiction that agentic content workflows have already made untenable
The Australian Government AI Ethics Framework (DISER, 2019, updated 2023) enshrines human oversight as a core principle — one of eight that agencies are expected to operationalise across their AI deployments. In practice, the operationalisation guidance treats oversight as a checkpoint: a human reviews an AI recommendation before it has effect. This model was adequate for early-generation decision-support tools, where AI output was clearly bounded and the human decision remained separable from the machine input. It is not adequate for agentic content workflows, where a model may generate thirty variations of campaign copy, a prompt engineer selects three, a content strategist lightly edits one, and an approving officer signs the final version — often without any formal record of which model produced the original, what instructions it was given, or what the model's documented performance characteristics are for the relevant audience demographic.
When AI generates the content and a human approves it without knowing the model's failure modes, sign-off is a ritual, not governance.
The Digital Service Standard's accountability gap in AI-assisted pipelines
The Digital Service Standard's seventh criterion — 'make the team' — implicitly requires a human accountable for each service touchpoint. In a conventional content team, this accountability is straightforward: the content designer owns the copy, the accessibility specialist owns WCAG compliance, the product manager owns the service as a whole. AI-assisted content pipelines fragment this accountability across model vendors, prompt engineers, content strategists, and approving officers in a way that no current instrument reconstitutes into a single named responsibility. The model vendor is typically offshore, operating under a terms-of-service agreement that explicitly limits liability for content outputs. The prompt engineer may be a contractor outside the panel arrangement. The approving officer signed something, but signed it without documentation of what the model produced, under what instructions, or against what quality and safety criteria.
Communications 2.0 and the provenance problem
The Communications 2.0 guidelines govern tone, accessibility, and cultural safety for citizen-facing content. They contain no provisions for outputs where provenance — who or what generated a given sentence, image caption, or translation — is technically obscured by model intermediation. This is not a gap the guidelines' authors could reasonably have anticipated at the time of their drafting. It is, however, a gap that agencies are now responsible for closing in their own operational practice, because the guidelines remain the operative standard and AI-generated content is being produced and approved under them daily. The fiction of human authorship is not merely a legal exposure; it is an integrity problem, because it prevents agencies from accurately describing their own content production processes if asked to do so — by an audit body, a minister's office, or a Senate committee.
The procurement panel is the wrong detection mechanism for AI content risk — and agencies are relying on it anyway
Federal and state agencies accessing AI-assisted content tools through existing creative services panels — whether the Australian Government's Digital Marketplace, the Commonwealth's Multi-Use List arrangements, or state-level equivalents such as the NSW Government's ICT Services Scheme — are applying vendor assessment criteria that evaluate human capability, professional indemnity, portfolio quality, and editorial process. These criteria are appropriate for assessing a human-staffed communications agency. They do not map onto model-level risk, because model-level risk is a different category of problem: it concerns training data provenance, demographic performance gaps, hallucination rates on domain-specific content, and the absence of any mechanism by which the procuring agency can audit the model's behaviour post-delivery.
What panel arrangements transfer — and what they do not
Panel arrangements typically transfer liability to the vendor for errors of craft: a factual error introduced by a copywriter, a design that fails accessibility standards, a translation that misrepresents the source text. These are errors for which professional indemnity insurance exists, for which the vendor carries clear responsibility, and for which the agency has contractual remedies. AI-generated content introduces a category of error — model hallucination, training-data bias, cultural misrepresentation arising from underrepresentation of Australian demographic groups in training corpora — for which standard professional indemnity clauses offer no coverage. No panel arrangement currently assessed by this analysis contains a clause requiring vendors to disclose model provenance, document known failure modes, or provide the procuring agency with audit access to model outputs over the contract term.
| Risk category | Human-authored content (panel coverage) | AI-generated content (panel coverage) |
|---|---|---|
| Factual error by craft | Professional indemnity — vendor liable | Not covered; model hallucination not classified as craft error |
| Accessibility failure | DDA obligations on agency; vendor remediation clause standard | Accountability chain from model output to named officer not articulated |
| Cultural misrepresentation | Agency sign-off; vendor responsible for brief compliance | Training-data bias not disclosed; no audit mechanism in panel terms |
| Bias / demographic harm | Rare; human editorial process as primary control | Systematic; no panel criterion assesses model performance by demographic |
| Post-delivery audit | Standard record-keeping; vendor retains drafts | No contractual requirement for model output logs or version records |
The NSW Audit Office precedent
The NSW Audit Office's 2023 review of digital fraud and cyber risks established a directly relevant precedent: audit scrutiny of automated public-facing systems without named accountability officers is legitimate, and the absence of such officers constitutes a governance deficiency that audit bodies will note. That finding was made in the context of fraud-detection and citizen-service systems, not communications. But the logic transfers. An AI-assisted content pipeline producing public-facing government communications is an automated public-facing system. If no named officer holds documented accountability for its outputs, the same audit deficiency applies. No state audit body has yet extended this precedent to the communications domain — but the analytical basis for doing so exists and is well-established.
When AI generates the content and a human approves it without knowing the model's failure modes, sign-off is a ritual, not governance.
When AI-generated communications cause measurable harm, the incident taxonomy does not yet exist to classify it
The absence of an incident taxonomy for AI-generated communications harm is not a theoretical problem. It is an operational one that will determine how quickly agencies can respond, how clearly they can report to ministers, and whether they can demonstrate to oversight bodies that their response was proportionate and systematic. At present, a factual misstatement in a health campaign generated by a large language model occupies ambiguous territory between communications error, automated-decision harm, and vendor failure — categories that trigger different ministerial reporting obligations, different legal remedies under different instruments, and different remediation workflows with different owners.
Factual error: communications fault or automated-decision harm?
A factual error introduced by a human copywriter is a communications error: the agency reviews its approval process, corrects the content, and considers whether the vendor's professional indemnity should be invoked. A factual error generated by a large language model hallucinating on domain-specific health content — drug dosages, eligibility criteria, safety warnings — does not fit cleanly into that category. It may constitute automated-decision harm under the emerging framework that the Australian Human Rights Commission's 2021 Human Rights and Technology final report applied to public communications, which identified the accountability gap for automated systems producing content that influences citizen behaviour or understanding. It may also constitute a vendor failure, but only if the contract contained clauses requiring the vendor to disclose model limitations relevant to health content — which existing panel arrangements do not require.
Culturally unsafe content and the AHRC accountability gap
Culturally unsafe content in ATSI-targeted advertising — a misinformed phrase generated by a model trained on non-representative corpora, an AI-generated image that misrepresents community composition, a translation error from a multilingual model with documented underperformance on First Nations language contexts — implicates the accountability gap analysis in the AHRC's 2021 report directly. That report found that automated systems producing public communications content can cause rights-relevant harm, and that existing accountability frameworks do not assign clear responsibility for that harm to a named decision-maker. Three years after that finding, no agency communications policy references the AHRC analysis as a relevant instrument for AI-generated content. The gap the Commission identified has widened, not closed, as AI content tools have become more capable and more widely deployed.
Accessibility failures and the DDA accountability chain
Accessibility failures in AI-generated content — machine-generated captions that are inaccurate for Deaf audiences, alt-text produced by vision models that omits context relevant to screen-reader users, plain-language summaries that a model has simplified in ways that introduce ambiguity — fall under Disability Discrimination Act 1992 obligations and WCAG 2.1 AA requirements that apply to all government digital content. The accountability chain from model output to the named officer responsible for DDA compliance has not been articulated in any whole-of-government guidance. AGIMO's legacy accessibility frameworks assumed human production of content. The DTA's current guidance on digital accessibility does not address AI-generated content as a distinct category. The result is that agencies are producing DDA-obligated content through AI pipelines with no documented accountability for whether that content meets the standard — and no mechanism for an audit body to identify the responsible officer if it does not.
GDS UK's AI Playbook offers the most directly transferable accountability architecture — and Australian agencies have not yet adopted its core instruments
The UK Government Digital Service AI Playbook, published in 2024, is the most directly relevant international comparator for Australian federal and state agencies considering how to govern AI-assisted communications content. It was developed by a team with deep familiarity with the operational realities of government communications at scale, and its accountability instruments are designed to function within machinery-of-government constraints — not as ideal-state frameworks that assume organisational conditions that do not exist.
Model cards as the foundational accountability instrument
The GDS AI Playbook mandates model cards for any AI system producing citizen-facing output. A model card is a structured document — typically two to four pages — that records training data provenance, known failure modes, demographic performance gaps (disaggregated by the population groups the system will serve), and the human roles responsible for each stage of deployment. Model cards create an audit trail that survives machinery-of-government changes, vendor transitions, and staff turnover — the three conditions under which accountability most commonly disappears in government technology programmes. Per the GDS Playbook, model cards must be updated when a model is retrained or when a significant change in deployment context occurs, and they must be available to the accountable officer at the point of sign-off.
Australian agencies piloting equivalent tools have no GDS-equivalent instrument requiring model cards. The DTA's current AI guidance does not mandate their production for communications workloads. Agencies reviewing vendor proposals through the Digital Marketplace do not assess whether vendors can produce or maintain model cards. The information architecture that would enable meaningful accountability — knowing what system produced a given output, under what conditions, with what known limitations — simply does not exist in most current Australian government AI content deployments.
Human-in-the-loop sign-off as an informed governance act
GDS's human-in-the-loop sign-off requirement for citizen-facing content specifies not merely that a human approves final output — a requirement that, as noted above, Australian agencies nominally satisfy already — but that the approving officer has reviewed the model card, understands the system's known limitations relevant to the specific content being approved, and accepts named accountability for the decision to publish. This standard transforms sign-off from a procedural step into an informed governance act with documentary evidence. It means the approving officer cannot subsequently claim they were unaware of the model's known failure modes; the model card review is on record. It also means that if the system's known limitations were not disclosed to the approving officer — because the vendor did not produce a model card, or because the internal procurement process did not require one — the accountability for that failure sits with the procurement and governance process, not with the individual officer.
The US OMB AI governance memo establishes the agency AI officer model — an institutional design Australian agencies should assess for communications-specific adaptation
OMB M-24-10, issued by the US Office of Management and Budget in March 2024 under the title Advancing Governance, Innovation, and Risk Management for Agency Use of Artificial Intelligence, represents the most structurally significant federal AI governance reform in any comparable jurisdiction in the current period. Its relevance to Australian agencies is not in its specific regulatory mechanism — which reflects US constitutional and administrative law — but in its institutional design logic: the principle that accountability for AI deployment must be attached to a named senior officer before a system deploys, and that the information needed to exercise that accountability must be systematically collected and maintained.
The Chief AI Officer model
OMB M-24-10 requires each US federal agency to designate a Chief AI Officer with authority over AI use-case inventories, risk assessments, and annual reporting to the OMB. The Chief AI Officer is a structural accountability role — not an advisory function, not a coordination position, but an officer with named authority and named responsibility. The design logic is that if someone at Senior Executive Service equivalent must put their name to the agency's AI programme before deployment, the incentive structure for rigorous pre-deployment governance changes materially. 'The algorithm decided' becomes a harder answer to give when a named SES officer approved the algorithm's deployment and accepted accountability for its outputs.
Use-case inventories and the visibility problem
The OMB memo's use-case inventory requirement — agencies must catalogue all AI applications, including content generation tools, with risk classifications and named responsible officers — directly addresses the visibility problem that allows AI content tools to operate below any formal governance threshold in Australian agencies. At present, individual staff members in Australian government communications teams routinely access AI content generation tools through personal or team SaaS subscriptions, outside any formal procurement process, without any mechanism for the agency to know the tool is being used, assess its risks, or assign accountability for its outputs. A use-case inventory requirement would not eliminate this practice immediately, but it would create a documented obligation that could be audited, and it would shift the default from 'tools are invisible until an incident' to 'tools must be registered before use'.
Adapting the OMB model to the Australian context
Adapting the OMB institutional design to Australia requires reconciling it with APS Code of Conduct obligations — which assign accountability to individual officers, not to designated roles — the Office of the Australian Information Commissioner's emerging guidance on automated systems, and the distinct machinery-of-government relationship between communications divisions and ministerial offices, where communications decisions are frequently made under political direction that sits outside the APS governance framework. These are genuine complications, but they are tractable design problems. The APS already operates with analogous designated-officer models: the Chief Information Security Officer, the Chief Financial Officer, the Information Access Officer. A designated AI Communications Accountability Officer at SES Band 1 or equivalent is an extension of existing institutional logic, not a structural novelty. The absence of a local equivalent to the OMB model is a policy choice that has not been made explicitly — it is the result of AI content tools being absorbed into existing frameworks faster than those frameworks could be assessed and updated.
The Robodebt lesson was that 'the algorithm decided' is not accountability. AI-generated comms are next in line for that reckoning.
What accountable AI communications governance actually requires — a minimum viable framework for the current parliamentary term
The governance response does not require new legislation, a whole-of-government policy reset, or a multi-year reform programme. It requires four components that agencies can begin implementing through existing administrative authority, contract variation powers, and internal policy instruments. The framing below is a minimum viable framework — sufficient to close the accountability gap that is currently exposed, and sufficient to answer the provenance question if it is put to an agency in a Senate Estimates hearing or an audit review during the current parliamentary term.
The four components of a minimum viable AI communications governance framework
- Mandatory model cards for any AI system contributing to citizen-facing communications output — produced by vendors as a contract deliverable, maintained by the agency as a records management obligation, and reviewed by the approving officer as a condition of sign-off. Model cards should document: model name and version, training data provenance (including Australian demographic representation), known failure modes relevant to the content domain, performance gaps by demographic group, and the human roles responsible at each deployment stage.
- A designated AI Communications Accountability Officer at SES Band 1 or equivalent — a named officer who accepts accountability for the agency's AI content programme, maintains the use-case inventory, reviews model cards for high-risk deployments, and is the named respondent if an audit body or Senate committee requests documentation of the agency's AI content governance.
- An output audit trail that records, for each piece of AI-assisted communications content: the model used, the version at time of production, the human review steps completed, the approving officer's name, and the date of publication — maintained in the agency's records system in a form that survives vendor transitions and staff turnover.
- An incident classification taxonomy that maps AI-generated communications harm — factual error, cultural misrepresentation, accessibility failure, demographic bias — to existing ministerial reporting obligations, legal remedies, and remediation workflows, so that when an incident occurs the agency's response is systematic rather than improvised.
What agencies can demand from vendors now, without waiting for policy reform
Vendor contracts for AI-assisted content services can be amended through existing contract variation mechanisms to require: disclosure of model provenance and version; documentation of training data characteristics relevant to Australian demographic and cultural contexts; disclosure of known performance gaps for First Nations communities, culturally and linguistically diverse audiences, and people with disability; and audit access to model output logs for the duration of the contract term. These requirements do not conflict with any existing panel arrangement and do not require ministerial approval to implement as contract variations. Agencies with active creative services panel arrangements should assess their current contracts against these requirements and initiate variation discussions with vendors. Agencies entering new panel arrangements should include these requirements in their statements of work.
The internal inventory as the starting point
Before any of the above can be implemented systematically, agencies need visibility of what AI tools are currently in use. Internal communications teams should conduct a rapid inventory — a structured survey of team members identifying all AI content generation tools in current use, including tools accessed under personal or team SaaS subscriptions outside formal procurement. The inventory should assess each tool against the four-component framework above and produce a gap register: tools with no model card, tools with no named accountability officer, tools whose outputs are not captured in any audit trail. That gap register serves two purposes: it is the basis for a remediation plan, and it is the document that demonstrates to a ministerial office or audit body that the agency has assessed its exposure and is managing it — a materially better position than being unable to answer basic provenance questions when they are put.
For agencies engaged with digital communications infrastructure or seeking to review their content governance frameworks, the inventory process is also an opportunity to assess whether AI tool deployment is consistent with the agency's broader digital strategy and with the commitments made in its digital investment plans.
Senate Estimates is the accountability mechanism that will force this issue — agencies that cannot answer the provenance question are already exposed
Senate Estimates committees have developed a consistent and increasingly sophisticated approach to scrutinising automated systems in public administration. The pattern is well-established across welfare (the Robodebt programme), immigration (automated visa processing), and taxation (ATO data-matching). In each case, the committee's accountability demand was the same: who decided, what did they know, when did they know it, and how was that decision documented? In each case, 'the system decided' or 'the algorithm decided' proved to be an answer that Estimates committees would not accept — and in the Robodebt case, the Royal Commission made explicit that algorithmic decision-making without named human accountability is not a governance model compatible with the APS values and the rule of law.
The Robodebt lesson was that 'the algorithm decided' is not accountability. AI-generated comms are next in line for that reckoning.
Why communications is the next domain of Estimates scrutiny
Communications presents a more immediate ministerial exposure than service delivery in one specific respect: the outputs are public, attributable, and often visible to the journalists and civil society organisations that bring issues to the attention of Estimates members. A factual error in a government health campaign will be noticed. A culturally unsafe image in ATSI-targeted advertising will be raised. An accessibility failure in a digital campaign will be documented by disability advocacy organisations. When those issues reach Estimates, the question will not be whether the agency had an AI policy in the abstract — it will be whether the agency can produce documentation showing which content was AI-assisted, which model produced it, what human review it received, and who accepted named accountability for its publication. Agencies that cannot answer those questions are already exposed. The exposure exists now, not at some future point when AI content tools become more prevalent.
The proactive response is available now
The proactive governance response — model cards, designated accountability officers, output registers, updated vendor contracts, an incident classification taxonomy — is available within existing administrative authority. It does not require new legislation. It does not require whole-of-government policy reform, though such reform would be appropriate and would benefit from the institutional design models that GDS UK and OMB have already developed. It requires agencies to make a deliberate decision to treat AI-assisted communications content as a governance question, not merely a procurement or creative quality question, and to act on that decision before an incident forces a reactive response.
Agencies that have reviewed comparable governance implementations in other digital programme contexts will recognise the pattern: proactive documentation and named accountability are consistently less costly — in political capital, in ministerial time, in reputational exposure — than reactive responses to incidents that were foreseeable and whose governance failure was structural rather than individual.
The accountability gap in AI-generated government communications is not an emerging risk on the horizon. It is a present condition that is being managed, in most agencies, by the absence of any management at all. The instruments to close it exist. The precedents — from GDS, from OMB, from the AHRC, from the NSW Audit Office — have been established. What remains is the organisational decision to apply them.
SoudCoh works with government communications teams to implement model card frameworks, vendor contract amendments, and AI output audit trails that close the accountability gap before Senate Estimates forces the question. Enquiries regarding agency-specific governance assessments are handled through the SoudCoh government practice.

