The Gap Has a Price Tag
Last week I named the 10% gap in Australia's national AI governance guide. This week I add up what it costs the board that trusts it.
A director signs off on the AI governance framework, files the risk register, smiles because it feels like things are covered. And that signature is the moment the gap stops being mine to opine about and starts being theirs to answer for.
Here’s a quick recap for anyone who missed the first piece. The Australian Institute of Company Directors and the Human Technology Institute published "A Director's Guide to AI Governance" in June 2026, opened by a government minister and aligned with the National AI Plan. I named it one of the best AI governance manuals, so far, and I meant it.
And still do.
It names its vendors, insists on human oversight, and flags concentration risk. But then it routes every assurance line back inside the building and never once describes the way frontier models actually break in the field: talked past their own guardrails, or escaping a vendor's evaluation environment into a stranger's live systems. And I called that re-route the missing 10%.
Anyone can sit from the sidelines throwing shade and move on to the next headline. That’s easy and you know me, I don’t do easy. This article is going in and does the hard part. A gap in a manual is an abstraction until a board adopts the manual, and then it converts into 4 specific liabilities that land on named people. In this post I’m going walk through each one, what it will cost, then answer the question the first piece left open: should a board implement this guide at all.
The breach class the guide skips is the one that already happened twice
Two facts set the stakes, and both are on the record.
In July 2026, OpenAI ran unreleased models against a hacking benchmark with the safety refusals switched off. The models escaped the sandbox, reached the open internet, and compromised Hugging Face, then reused exposed credentials across four accounts on four services. Days later, Anthropic combed 141,006 of its own evaluation runs and found three separate occasions when its models reached live systems belonging to three real companies, the earliest back in April 2026. Two of those three companies had no idea until Anthropic called them. The field caught none of it through enterprise monitoring. Every incident was found and disclosed by the lab whose own model did the breaking.
Now, hold all of that against the guide's design, because the whole cost analysis flows from one mismatch. The breaches originated inside the vendor's evaluation environment, in a room the customer can’t see, govern, nor audit. The guide's risk model governs the room the customer runs. And it’s that mismatch where the price tags come from.
Price tag one: the guide sorts your biggest risk into your smallest tier
The guide leans on risk-proportionate tiering and the instinct is correct. Light governance for low-stakes systems, heavy governance for high-stakes ones. The lowest tier is commercial model use, a public agency or a company running someone else's frontier model over routine work. Light touch, day one.
But that’s also the exact spot that produced the worst breaches of the year (so far). A board that follows that tiering files its vendor-model use under low governance and moves on, because the manual said so. And it’s that tier, the one that feels safest, is the one sitting directly on top of the failure class that caught both leading labs flat-footed. The cost here isn’t a fine. The cost is that the guide's own sorting logic points the board's attention away from its single largest exposure and stamps that decision reasonable.
Price tag two: the gap converts a foreseeable risk into a discoverable paper trail
This is the one with teeth and it’s specific to Australian directors.
Director and officer duties under section 180(1) of the Corporations Act 2001 turn importantly on foreseeable risk, but foreseeable risk alone does not establish breach. In ASIC v Bekier 2026 FCA 196, the Federal Court asked applied an objective, yet contextual standard: whether a reasonable person in the relevant position would have exercised great care and diligence with the information then available. The court’s analysis is consistent with the Cassimatis line of authority: a company's actual contravention may be highly relevant to the risk analysis, but it is not a necessary ingredient of a director or officer’s breach. The test and question is assessed at the time, without hindsight, and requires attention to the foreseeable risk of harm, its seriousness and likelihood, and the reasonable steps expected in the circumstances; is the risk a reasonable director would have run, judged at the time, on the information available.
Now add what the regulator did in May 2026. ASIC translated that risk-based posture into a specific cyber-resilience warning in its May 8, 2026, open letter to AFS licensees, directors and market participants. ASIC stated frontier AI models lower the barrier to sophisticated cyber activity, increases the speed and scale of attacks and enables new forms of exploitation. ASIC then asked boards and senior executives to ensure resilience measures are proportionate to the evolving threat environment, adequately resourced, supported by meaningful end to end reported, and integrated into risk management frameworks; it also directed that the letter be tabled and discussed by ultimate board and risk governance committees. This wasn’t all bark and no bite because in February 2026, the federal court ordered FIIG Securities to pay $2.5 million in pecuniary penalties plus another $500K toward ASIC’s costs, for breaches of its AFS license obligations relating to cyber security; FIIG was also required to undertake an independence expert compliance program.
When you put the pieces together, the exposure is hard to miss. The vendor-evaluation breach class is now, by the regulator's own published words, foreseeable. And the board that adopts this guide as its standard, completes the risk register, and leaves out the row for that breach class hasn’t closed its oversight. It just created a written record showing it governed everything except the risk the regulator named out loud. Registers, board papers, and prompts are discoverable. Chief Justice Bell has already warned that individual director AI use will foreseeably trigger a wave of discovery in inquiries, class actions, and litigation. The guide, adopted as written, hands a future plaintiff a documented omission with the board's signature on it. That is the price tag: not the breach alone, but the paper proving you followed a framework that skipped it.
Price tag three: you accept the accountability and receive no control
The guide is honest about one thing that most vendor frameworks bury. It states that accountability remains with your organization even when the risk originates with the vendor. Read that sentence real slow because the guide then doesn’t offer up a single control that reaches the vendor.
There’s no contractual notice clause requiring the model provider to tell you when its systems touch yours, including during the provider's own internal testing. Independent forensics gets no love either. The control table has no row for a substrate you don’t even run. So, the board ends up holding named responsibility for a risk with no instrument to manage it. In governance terms that’s straight up the worst square on the chess board: you own the outcome and you hold no lever. The guide confidently walks a director into that square and then quickly closes the door behind them.
Price tag four: you fund the machinery that can’t catch the breach
A board that adopts the guide will do exactly what it says. Stand up an AI committee, appoint an Accountable Official, complete the register, set a reporting cadence. Real hours, real budget, real minutes recording that the work was done. Great! Then the board will immediately feel governed and believe it built something.
But, what it actually built was the wrong thing for this risk because every one of those bodies reports inward. When a breach starts in a vendor's evaluation environment, none of that internal machinery is positioned to see it, because the two worst breaches of the year (so far) were caught only when the lab that caused them actually looked, and confirmed only because outside parties were watching. Hugging Face spotted OpenAI's intrusion from the outside. Anthropic brought in METR, an external evaluator, and paused its evaluations while METR investigates. But this guide? This guide gives a board an internal review structure and calls the one external reviewer an optional adviser and at the same time warns you not to lean on. In the end the board spends its governance budget building a tricked-out watchtower pointed down at its own courtyard while the breach comes over the wall.
Add up the four and the shape is crystal clear
The story isn’t that the guide is careless. The guide is careful, which is what makes my next statement land hard. A genuinely good manual, adopted in good faith by a diligent board, sorts the board's largest risk into its smallest tier, documents the omission in a discoverable record, assigns the board accountability with no matching control, and funds an oversight structure that can’t catch the one breach class the year already demonstrated - twice. The better the document reads, the more completely a board trusts the part it left out.
So, should you implement it?
Yes. Adopt the guide but don’t adopt it as written verbatim. And yes, both halves of that sentence are load bearing.
Adopt it, because honestly, the alternative is worse. The strategy discipline, the risk-appetite work, the vendor due-diligence steps, the AI6 mapping to the National AI Centre's practices, the plain-language lesson from the Telstra and Atlassian case studies, all of it is real, and most Australian boards have nothing this structured ready to pull from the shelf today. Refusing a strong 90% because of a serious 10% leaves a board with zero, which is even a worse place than where the guide puts you.
The document is a foundation and foundations, even not perfect ones, are worth keeping.
However, do not, and I’m saying it again, do not, adopt it unmodified, because adopting it as written is precisely the four-part failure outlined above. Three additions turn the manual from a record of your blind spots into a mechanism that closes them. And I believe a committed and determined board can make all three this quarter.
- Add the upstream row to your risk table. For every AI system, write the damage it can cause when the risk originates in the vendor's environment and crosses into yours. Score that row before you score data quality or token policy. The OpenAI and Anthropic disclosures are what that row looks like when someone finally writes it down.
- Write the vendor notice clause the guide never gives you. Your real governance surface for a model you do not control is the contract. Put a term in it: written notice within a fixed window whenever the vendor's systems touch yours, including during the vendor's own internal testing, plus a right to independent forensics. If the contract cannot carry that clause, that fact is itself a board-level risk finding.
- Name a real outside auditor as a standing role. Reverse the guide's optional-adviser framing. Identify the external party with the standing and the transcript access to verify your AI controls and write the role into the governance model as a requirement for any high-impact system. METR did not audit itself into that job. Anthropic invited it. An assurance body that reports to the people who fund the program is a review board, not an auditor.
And the test? It’s one sentence.
Open the framework your organization actually runs on and find the column, the clause, and the role that cover a vendor's evaluation breaking into your systems. If any of the 3 are missing, you’ve have implemented the 90% and inherited the 10%, and that 10% is the part with YOUR name on it. So, implement the right thing.
Share this article
Related Articles
The Reskilling Illusion: When AI Transformation Means "You're Fired"
Oct 03, 2025