The deployment has already outpaced the policy
AI governance, as a policy discipline, proceeds in consultation cycles measured in years. The operational deployment of generative AI tools inside Australian government communications functions is proceeding in procurement cycles measured in weeks. The gap between those two tempos is not a future risk — it is a present condition.
Operational use is ahead of any sector-specific instrument
Generative AI is in active operational use across Australian government communications. The Australian Taxation Office has deployed plain-language drafting assistance to reduce complexity in taxpayer-facing correspondence. Multiple state governments — including New South Wales and Victoria — have trialled or operationalised AI-assisted social media content generation, sometimes under departmental digital transformation budgets rather than communications budget lines. Service Victoria's digital service evolution, documented in its successive annual reports, reflects a pattern common across jurisdictions: AI tooling enters the workflow through efficiency rationales before governance rationales are considered.
This is not a criticism of the agencies involved. The tools are genuinely useful. The problem is structural: no sector-specific governance instrument existed at the moment of deployment, and none has been promulgated since. The Senate Select Committee on Adopting Artificial Intelligence, in its 2024 interim report, acknowledged the absence of sector-specific guidance for government communicators. What the Committee's framing did not fully capture is that the gap is not merely a matter of missing guidance — it is a matter of missing accountability architecture.
The invisible procurement pathway
Discretionary budget lines established before 2023 — many of them designed for software-as-a-service tooling under existing ICT panels — are funding AI tooling that carries none of the oversight obligations attached to regulated procurement categories. Because generative AI tools are frequently acquired as features within existing subscriptions (Microsoft 365 Copilot being the most pervasive example), they do not trigger the procurement thresholds that would ordinarily require a separate risk assessment or a gateway review.
The consequence is a structural blind spot for audit offices. The Australian National Audit Office's existing performance audit methodology is oriented toward discrete procurement decisions. When AI capability enters an agency through a subscription feature update, there is no procurement decision to audit — and therefore no audit trigger. The NSW Audit Office encountered a version of this problem in its 2023 performance audit of digital transformation in customer service, finding measurement and accountability gaps in technology-assisted service delivery that arose precisely because the technology had been absorbed into existing operational frameworks without corresponding governance revision.
The Senate framing understates the structural problem
The Senate Select Committee's 2024 interim report is a useful marker of where parliamentary attention has reached. It flags the absence of sector-specific guidance for government communicators and recommends that the government develop such guidance. That recommendation is correct. But framing the problem as a guidance gap implies that what is needed is another policy document. What is actually needed is an accountability chain: a named officer, a documented decision trail, an audit-ready register, and commercial clauses that allocate liability. Guidance alone does not produce any of those things.
Why the Voluntary AI Safety Standard does not cover this ground
The Australian Government's Voluntary AI Safety Standard, published by the Department of Industry, Science and Resources in 2024, is the closest instrument Australia currently has to a whole-of-government AI governance framework. It is insufficient for the communications use case, and it is important to be precise about why — because the insufficiency is structural, not incidental.
Scope is defined by decision type, not sector
The Standard is explicitly scoped to high-risk AI systems, with risk defined primarily through the lens of automated decision-making in welfare, justice, and safety-critical domains. The ten guardrails it establishes — covering transparency, human oversight, data governance, and contestability — are sensible for those domains. Communications use cases receive no dedicated treatment. The Standard does not address AI-assisted copy generation, programmatic audience segmentation, algorithmic content personalisation, or synthetic creative production.
This is not an oversight in the drafting. DISR's framing reflects a deliberate risk-tiering approach consistent with the OECD AI Principles and the EU AI Act's risk classification methodology. The problem is that the communications domain sits in an uncomfortable middle ground: it is not high-risk by the Standard's definition (no individual welfare decision is being automated), but it is also not low-risk in any meaningful sense (content that shapes public understanding of government policy, or that uses algorithmic targeting to reach specific demographic cohorts, carries material public interest obligations).
Voluntary instruments produce no usable accountability data
Voluntary instruments carry no audit trigger. An agency can self-assess compliance with the Voluntary AI Safety Standard without disclosing which AI tools are active in its communications stack, which workflows they are applied to, or which outputs they have influenced. The Standard therefore produces no usable accountability data at the whole-of-government level. The Department of Finance, the DTA, and the ANAO have no mechanism under the Standard to compile an accurate picture of AI use in government communications — not because they have chosen not to, but because the instrument does not create that obligation.
The guardrails do not map onto broadcast content workflows
The Standard's ten guardrails presuppose a discrete decision point and an identifiable affected individual. Guardrail 3 (Give affected people the ability to contest AI decisions) and Guardrail 6 (Inform users of AI interactions) both assume that there is a user, in a defined interaction, who can be notified and who can contest a specific outcome. Neither assumption holds in broadcast content generation or programmatic audience segmentation. When an AI system assists in drafting a campaign headline that reaches four million people via paid social, there is no discrete decision point and no identifiable affected individual to notify. The guardrail architecture is simply not calibrated for that workflow.
The DTA Digital Service Standard was not built for this problem
The Digital Transformation Agency's Digital Service Standard, revised in 2023, is the operational governance framework most directly applicable to digital government outputs. It too falls short of the communications AI governance problem — and for reasons that are worth understanding, because they inform what a fit-for-purpose instrument would need to contain.
AI-generated content is absent from the criteria
The 2023 revision of the DTA Digital Service Standard contains no criterion addressing AI-generated content, algorithmic content personalisation, or machine-assisted copy approval. Its user research criteria (Criteria 1 and 2) assume that service design decisions are made by human teams interpreting qualitative and quantitative evidence. Its accessibility criteria assume human authorship of content that will then be tested against WCAG standards. The Standard was designed for the service delivery paradigm that preceded generative AI at scale — a paradigm in which the most sophisticated form of content automation was a templated correspondence system.
That is not a criticism of the Standard's drafters; it reflects the timeline of the revision cycle. The practical consequence is that a government communications team can deploy a generative AI tool to produce campaign copy, test it against AI-driven audience segmentation, and publish it through a DTA-panel vendor — all without triggering any criterion in the Standard that requires disclosure, human review documentation, or risk assessment.
Panel arrangements contain no AI accountability clauses
Panel arrangements established under DTA-coordinated procurement vehicles — including the various communications, creative, and digital services panels — contain no standard clause requiring vendors to disclose AI involvement in deliverables. There is no standing requirement for vendors to attest to their AI governance policies as a condition of panel membership. There is no indemnity provision that explicitly covers AI-assisted output errors. The commercial relationship between agency and vendor is governed by arrangements designed before generative AI was an operational reality in creative production.
This matters because panel arrangements are where most Australian government communications procurement occurs. They are the practical governance layer for the majority of agency spending on content creation, media buying, and audience strategy. If those arrangements contain no AI governance provisions, the governance gap is not merely a policy abstraction — it is a daily operational reality across dozens of active engagements.
Service-delivery orientation versus editorial accountability
The Standard's governance model is oriented toward transaction completion and accessibility. It optimises for the user's ability to complete a government service interaction successfully. This is the right optimisation for digital service delivery. It is the wrong optimisation for communications outputs, which require a different accountability logic: editorial responsibility for the accuracy, fairness, and proportionality of content that shapes public understanding of policy. These are not the same thing, and the Standard's architecture does not accommodate the distinction.
What an accountability void actually looks like in practice
Governance gaps are easier to act on when they are specified concretely rather than described in the abstract. The accountability void in Australian government AI governance for communications has a specific shape, and it produces specific failure modes.
When AI-assisted content causes harm, no current instrument designates an accountable officer — responsibility simply diffuses.
The diffusion of responsibility when things go wrong
When an AI-assisted campaign produces discriminatory targeting logic — for example, an audience segmentation algorithm that systematically excludes a particular demographic cohort from a government health message — no instrument currently designates an accountable officer within the agency. Responsibility diffuses across the communications director (who approved the brief), the digital transformation lead (who approved the tool), the media buyer (who configured the targeting), and the panel vendor (who delivered the creative). Each of those parties has a partial accountability, and none has a complete one. That diffusion is not accidental — it is the predictable consequence of deploying a tool in the absence of a role assignment matrix.
The same diffusion occurs when AI-generated copy contains a factual error that reaches publication. Under existing arrangements, the question of who is responsible for the error — and therefore who must correct the public record, who must brief the minister, and who must appear before a Senate committee — has no clear answer. The communications director will point to the vendor. The vendor will point to the AI system. The AI system has no legal personhood. The gap where accountability should sit is empty.
The NSW Audit Office precedent
The NSW Audit Office's 2023 performance audit of digital transformation in customer service is instructive precisely because it found accountability gaps in a domain that is structurally analogous to the federal communications problem. The audit found that agencies had adopted technology-assisted service delivery without establishing corresponding measurement frameworks or clear accountability chains for technology-mediated outcomes. The Audit Office's findings were not about AI specifically — the audit preceded the current generative AI deployment wave — but the structural problem it identified is identical: technology enters the operational workflow faster than governance frameworks are revised to accommodate it, and the result is a measurement void that audit offices can observe but cannot remedy.
FOI, Senate Estimates, and the reputational second-order effect
Absent a mandated audit trail for AI involvement in content decisions, Freedom of Information requests and Senate Estimates questions about AI-assisted campaigns will produce either silence or inconsistent disclosure. Both outcomes carry reputational risk that is distinct from — and potentially greater than — the risk of the original AI-assisted content error. An agency that cannot answer the question "which of your communications in the past twelve months were AI-assisted, and who approved them?" is not merely non-compliant with anticipated standards. It is demonstrating, in a public forum, that it has been operating without governance. That demonstration is itself the compliance event.
When AI-assisted content causes harm, no current instrument designates an accountable officer — responsibility simply diffuses.
The UK CDDO model demonstrates that named accountability is achievable
The United Kingdom's Central Digital and Data Office published its Generative AI Framework for His Majesty's Government in 2024. It is the most directly applicable international precedent for the Australian government communications AI governance problem, and it warrants close examination — not as a model to be adopted wholesale, but as a demonstration that named accountability in this domain is operationally feasible without primary legislation.
The Senior Responsible Owner as the accountability anchor
The CDDO framework establishes a named Senior Responsible Owner for each AI-assisted communications function. This is a single point of accountability that survives machinery-of-government changes — a critical design feature in a parliamentary system where departmental restructures can otherwise dissolve accountability arrangements. The SRO is not the person who uses the AI tool; they are the person who is accountable for the governance of its use. That distinction matters because it separates operational convenience from governance responsibility, which is the structural separation that current Australian arrangements lack.
The SRO model is directly adaptable to the APS context. The equivalent accountability anchor in the APS would sit at SES Band 1 or Band 2 within the communications or digital division, with the role documented in the branch's accountability framework and disclosed to the agency's audit committee. No legislation is required to establish this. It requires an internal governance decision and the institutional will to make it.
The departmental AI asset register
The CDDO framework requires that any generative AI tool used in public communications be registered on a departmental AI asset register, with documented human review checkpoints before publication. The register is a living document: it records the tool, its risk classification, its approved workflow scope, the designated accountable officer, and the human review protocol. It is updated when tools are added, modified, or retired.
This instrument serves two simultaneous functions. First, it provides the evidentiary base for internal governance — the asset register is what the accountable officer reviews when assessing whether the communications function's AI use remains within approved parameters. Second, it provides the audit trail that both the National Audit Office in the UK and, in the Australian context, audit offices and Senate committees would require. An agency with a well-maintained AI asset register can answer FOI requests and Senate Estimates questions with precision rather than silence.
Separating tool governance from output governance
The CDDO framework's most analytically useful design feature is its separation of tool governance from output governance. The AI system is assessed once at onboarding — its risk classification, its data handling practices, its known failure modes — and that assessment is recorded on the asset register. But every output that enters a public channel requires a separate logged human approval decision. The tool assessment and the output approval are distinct governance acts, producing an auditable chain even under operational time pressure.
This separation matters because it prevents a common governance failure mode: the conflation of "we assessed the tool as low-risk" with "every output produced by the tool is approved." The CDDO framework makes clear that the tool assessment does not substitute for output approval. Each piece of content that reaches a public channel has a named approver and a logged decision. The chain is complete.
The NIST AI RMF GOVERN function offers a structural template for Australian agencies
The National Institute of Standards and Technology AI Risk Management Framework 1.0, published in January 2023, provides a tool-agnostic governance architecture that is adaptable to the APS communications context without requiring new legislation or whole-of-government reform. The GOVERN function of the NIST AI RMF is the relevant component.
What the GOVERN function requires
The NIST AI RMF's GOVERN function defines the organisational policies, roles, and processes that must exist before an AI system is deployed — not after a problem has been identified. It requires that the organisation document its risk tolerance for AI use, assign roles and responsibilities for AI governance, establish processes for ongoing monitoring, and create mechanisms for accountability when AI systems produce adverse outcomes. These requirements are expressed at a level of abstraction that makes them applicable across sectors and jurisdictions — which is precisely what makes them useful for APS agencies operating without sector-specific guidance.
Three concrete instruments for communications governance
Applied to the communications branch context, the GOVERN function produces three concrete instruments that agencies can develop and implement within a standard internal governance cycle:
- An AI Use Policy for Communications: A branch-level policy document that defines permitted AI use cases (for example: drafting assistance, accessibility checking, translation) and prohibited use cases (for example: automated publication without human review, AI-generated imagery without disclosure), establishes the risk tolerance for communications AI use, and designates the accountable officer for each use category. This document requires no ministerial approval and can be operative within the standard internal governance cycle of most agencies.
- A Role Assignment Matrix: A documented matrix that links each active AI workflow to a designated human decision-maker. For each AI tool in use, the matrix specifies who is responsible for tool assessment, who is responsible for output approval, and who is responsible for incident response if the tool produces an adverse outcome. The matrix is reviewed quarterly and updated when the communications function's AI tooling changes.
- A Risk Tolerance Statement: A formal statement, approved at SES Band 2 or equivalent, that articulates the agency's risk appetite for AI-assisted communications. This statement is the governance anchor for all downstream decisions about AI tool adoption and use scope. Its existence means that individual decisions about AI use are made against a documented standard, not ad hoc.
A cleaner liability map than procurement law currently provides
The NIST framework's explicit distinction between the AI developer, the AI deployer, and the affected public provides a cleaner liability mapping than Australian procurement law currently offers for AI-assisted communications. Under existing procurement arrangements, the liability boundary between agency and vendor for AI-assisted content errors is undefined. The NIST framework's tripartite distinction — developer (the vendor who built the AI system), deployer (the agency that applies it to communications workflows), and affected public (the audience of the content) — provides a conceptual architecture onto which commercial liability clauses can be mapped. Agencies that adopt this framework internally will be better positioned to negotiate appropriate indemnity provisions with panel vendors, and better positioned when mandatory standards eventually arrive.
Procurement panels cannot substitute for governance instruments — but they can be retrofitted
There is a category error that recurs in discussions of government AI governance: the assumption that procurement panels, properly designed, can perform the governance function. They cannot. But they can be made to carry governance obligations — and the distinction between those two things is important for procurement officers and communications leads who are looking for near-term actions.
Why panels are structurally insufficient
Procurement panels are designed to establish value-for-money and supplier capability at a point in time — the point of panel establishment or refresh. They are structurally unable to govern how a tool is used after engagement, which is precisely when AI governance risk materialises in communications workflows. The panel assessment determines whether a vendor is capable of delivering AI-assisted communications services. It does not, and cannot, govern the specific AI tools the vendor deploys on a given engagement, the human review protocols the vendor applies to AI-generated outputs, or the liability allocation when AI-assisted content causes harm. Those are engagement-level governance questions, and they require engagement-level instruments.
Three retrofittable panel-level interventions
Three panel-level interventions are available to agencies without waiting for whole-of-government reform. Each can be implemented through existing procurement authority:
| Intervention | Where it sits | What it achieves | Implementation pathway |
|---|---|---|---|
| Mandatory AI involvement disclosure schedule | Statement of Work / Work Order | Creates an audit trail of AI use per engagement; enables post-engagement review | Procurement officer adds schedule to standard SOW template; no panel refresh required |
| Vendor AI governance attestation | Panel evaluation criterion / annual supplier attestation | Establishes that vendors have documented AI governance policies; creates baseline accountability | Added as standing criterion at next panel refresh; interim attestation request to existing panel members |
| AI-assisted output indemnity clause | Contract / Panel deed | Explicitly allocates liability for AI-assisted output errors; closes the liability gap in existing arrangements | Requires legal review; can be added to individual work orders without panel deed amendment |
The GDS and USDS precedent for procurement as governance lever
The Government Digital Service in the United Kingdom and the United States Digital Service have both demonstrated that procurement instrument design — not just policy guidance — is an effective lever for governance change. GDS's approach to its Digital Marketplace, and USDS's work on the Digital Services Playbook, both embedded accountability requirements in commercial relationships rather than relying solely on agency-side policy guidance. The mechanism works because it changes vendor behaviour: a vendor that must attest to its AI governance practices as a condition of panel membership has a commercial incentive to develop those practices that a voluntary standard cannot create. Embedding accountability requirements in the commercial relationship changes vendor behaviour faster than voluntary standards change agency behaviour — and in the current environment, speed matters.
A compliance event is more likely to arrive before 2027 than a mandatory standard is.
The internal instruments agencies can adopt before mandatory standards arrive
The trajectory of AI standards development in Australia makes clear that waiting for mandatory frameworks to resolve the communications AI governance problem is a risk acceptance decision, not a prudent governance posture. The instruments described in the CDDO and NIST models are available to agencies now, within existing authority, without requiring ministerial approval or whole-of-government coordination.
A branch-level AI Use Policy for Communications
A branch-level AI Use Policy for Communications, modelled on the CDDO and NIST frameworks, requires no ministerial approval and can be operative within a standard internal governance cycle — typically eight to twelve weeks from drafting to SES sign-off. The policy assigns accountability (naming the officer responsible for each AI use category), defines permitted and prohibited use cases (providing the decision boundary that operational staff currently lack), and mandates the audit trail (specifying what must be logged when AI is used in content production or audience targeting).
The policy does not need to anticipate every AI tool or use case. It needs to establish the governance logic that applies to any AI use within the communications function — a logic that can then be applied to specific tools and workflows as they are encountered. A policy that establishes the right questions (Who approved this tool? Who approved this output? Where is the log?) is more durable than a policy that attempts to enumerate every current tool, because the tool landscape will change faster than any policy can be revised.
An AI Asset Register for communications tooling
An AI Asset Register for communications tooling is a living document listing every AI system in active use across the communications function, its risk classification, its approved workflow scope, its designated accountable officer, and its human review protocol. It is the evidentiary base that both audit offices and Senate committees will eventually require — and agencies that build it now, voluntarily, will be converting current good practice into future audit evidence rather than scrambling to reconstruct a record after an inquiry has commenced.
The register need not be technically complex. A well-structured spreadsheet, maintained by the communications governance officer and reviewed quarterly by the SES accountable officer, is sufficient for the audit function. The discipline is in the maintenance: the register must be updated when tools are added, when workflow scope changes, and when accountable officers change. A register that is accurate at a point in time but not maintained is not a governance instrument — it is a historical document.
Human review checkpoints as documented workflow steps
Agencies that establish human review checkpoints as a documented workflow step — rather than a cultural norm or an informal practice — will be able to demonstrate compliance with anticipated mandatory standards retroactively. The distinction between a documented checkpoint and a cultural norm is the distinction between audit evidence and assertion. When a Senate committee asks whether AI-generated content was reviewed before publication, an agency with a documented workflow can produce the evidence. An agency that relied on a cultural norm cannot.
The checkpoint documentation does not need to be burdensome. A timestamped approval record — naming the approver, the content item, and the AI system involved — is sufficient for the audit function. The key design requirement is that the checkpoint is part of the workflow system (the content management system, the project management tool, the campaign approval process) rather than a separate documentation exercise conducted after the fact.
The compliance event is more likely than the policy fix to arrive first
The framing of AI governance as a future problem to be resolved by future mandatory standards is, in the Australian government communications context, operationally incorrect. The risk is present. The governance instruments are absent. The gap between those two facts will close — but it is more likely to close through a compliance event than through a policy instrument.
A compliance event is more likely to arrive before 2027 than a mandatory standard is.
The timeline of mandatory standards
The trajectory of AI standards development in Australia — voluntary instruments published in 2024, consultation periods running into 2025, staged implementation following consultation — means mandatory communications-specific AI governance is unlikely to be operative before 2027 at the earliest. The Senate Select Committee's 2024 interim report will produce a final report; that report will produce government responses; those responses will produce exposure drafts; those drafts will produce further consultation. This is how Australian regulatory development works, and it is not a criticism of the process — it is a description of the timeline against which agencies must make governance decisions.
Operational AI use in government communications is not following that timeline. It is following the timeline of software product development, subscription feature releases, and agency digital transformation programs — all of which are measured in months, not years. The gap between the regulatory timeline and the operational timeline is the structural source of the accountability void this article has described.
The anatomy of a compliance event
A single high-profile AI-assisted campaign failure — discriminatory targeting logic that excludes a protected demographic from a government health message; fabricated attribution in AI-generated copy; a privacy breach arising from audience segmentation that re-identifies individuals from de-identified data — will produce a predictable sequence: a Senate inquiry, an audit office referral, and reputational damage to the agency that deployed the tool under no governance framework. The reputational damage will extend beyond the agency to the communications panel vendor, and potentially to the DTA for the adequacy of its panel governance arrangements.
Per the ACCC's 2023 Digital Platforms Report, algorithmic targeting systems used in commercial contexts have already produced documented cases of discriminatory ad delivery in Australia. The technical mechanisms that produce discriminatory ad delivery in commercial contexts are identical to those used in government programmatic communications. The probability that a government communications function using these mechanisms will not encounter a similar outcome, over a multi-year operational horizon, is not high.
Risk acceptance without risk assessment is itself an accountability failure
Agencies that treat this gap as a future problem are, in effect, making a risk acceptance decision without having conducted a risk assessment. That decision itself constitutes an accountability failure under existing APS values and the Public Governance, Performance and Accountability Act's duty of care obligations. Section 15 of the PGPA Act requires accountable authorities to establish and maintain systems of risk oversight and management. An agency head who is aware of the AI governance gap in their communications function — and awareness is not deniable after this body of analysis has been published — and who has taken no steps to address it, has made a governance decision that the PGPA Act is capable of reaching.
The appropriate response is not to wait for the compliance event to define the problem more precisely. The appropriate response is to build the governance instruments now — the AI Use Policy, the Asset Register, the role assignment matrix, the documented human review checkpoints — so that when mandatory standards arrive, the agency can demonstrate continuous governance rather than reactive compliance.
SoudCoh works with government communications teams to design AI governance instruments — asset registers, accountability chains, and panel clauses — that are operative now, not contingent on standards that have not yet been written. For agencies ready to act before the compliance event arrives, the first conversation is the most useful step.

