Directors are personally accountable for taking reasonable steps on the risks AI brings into the organisation. Australia has no AI Act, so those steps are measured against existing law, regulator letters and published guidance. AI Compass gives the board a live risk position across every AI use case, traced to the exact obligations behind it, with a dated record that oversight happened.
When a regulator, an insurer or a court asks whether the board exercised care and diligence over AI, the inquiry reduces to three questions. Most boards today cannot answer any of them with evidence.
Including the third-party tools and vendor APIs management adopted without a paper trail. You cannot oversee what is not on a register.
No AI Act does not mean no obligations. Privacy, consumer, anti-discrimination and sector law apply now, and regulators have said so in writing to boards.
A defensible position is a dated record: assessments run, risks scored, obligations identified, decisions minuted. Assertions do not survive scrutiny. Records do.
Management operates AI Compass. The board receives its outputs: a defensible, current, clause-linked view of the organisation's AI risk, refreshed every cycle.
Every AI use case in one place, bespoke and third-party, each with an owner. The answer to question one, kept current by management.
Each use case mapped to the instruments that reach it under Australia's technology-neutral approach, at clause level, in plain language.
Deterministic risk levels per use case, rolled into one board view. Identical inputs always score identically, so the position is auditable and comparable cycle to cycle.
A board-ready document each cycle: the position, what changed, why, and the decisions sought. Written for directors, not developers.
A regulator letter, a statutory date, a new standard: the landscape moves, affected use cases re-score, and the risk committee hears about it before it matters.
Every assessment, score, alert and committee review, dated and preserved. If the reasonable-steps question is ever asked, the answer already exists.
AI Compass turns AI oversight into a repeatable governance rhythm, the way boards already govern financial, cyber and safety risk.
Management registers every AI use case, including vendor tools and shadow adoption.
Compass links each use case to the obligations that reach it, at clause level.
Owners complete curated, guided assessments. Scoring is deterministic and auditable.
The risk committee receives the position, the changes and the decisions sought.
The cycle is recorded and dated. The board's reasonable steps become a matter of record.
A worked example, from a director's question to a minuted position. Step through it. Concept mockup, illustrative content.
Regulators stopped writing to compliance teams and started writing to boards. The 2026 calendar sets the pace.
The National AI Plan confirms technology-neutral regulation. Responsibility shifts to organisations, and to the directors who govern them, under existing law.
Four named weak spots: information security, governance immaturity, supplier concentration, inadequate assurance.
Addressed to board and risk-committee level. The letters become the closest written benchmark for reasonable steps under existing directors' duties.
Impact assessments, accountable officials and Chief AI Officers, with procurement pulling the supplier base into scope.
The hardest statutory date on the AI calendar, and the sharpest test of whether the board saw its own exposure coming.
Compass maps the landscape industry by industry, starting where regulator attention on boards is sharpest.
The fastest way to evaluate AI Compass is to run it once, on your own register. In a single cycle the board sees its current AI risk position, the obligations behind it, and what the oversight record looks like when it exists.