TheAICommand Brief

From Letters to Workplans

TheAICommand BriefSeptember 2026Audience: generalPublished 1 September 2026

In April, APRA wrote Australian financial services a letter about artificial intelligence. In August, four Australian institutions published something harder to file away: workplans, a guidance note and a nine-government commitment to legislate. The distance between a regulator's opinion and a regulator's published programme is the distance between reading something and being asked to show something.

The month in AI: August 2026

August was not a month of dramatic capability announcements. It was a month in which the frameworks around AI became more concrete in two directions at once. Open weights reached a scale that changes who can host a capable model. And in Australia, the supervisory posture stopped being a set of observations and became a set of dated commitments.

August 2026 in five dates
Figure 1. August 2026 in five moves: EU enforcement begins on 2 August, DeepSeek publishes open weights on 13 August, APRA's corporate plan lands on 20 August, the Fair Work Commission publishes its guidance note on 24 August, and National Cabinet plus ASIC's corporate plan arrive together on 26 August.

Models and platforms

13 and 25 August: frontier-scale weights were published under a permissive licence, twice. DeepSeek published DeepSeek-V4-Pro-0813 under an MIT licence on 13 August. Twelve days later Z.ai published GLM-5.3 and GLM-5.3-Flash, also MIT, with the Flash model described on its own model card as "the first natively multimodal model in the GLM-5 series" carrying "320B total parameters and just 18B active parameters" and outperforming its predecessor "at one-tenth the price". GLM-5.3-Flash had passed 379,000 downloads as at 31 August 2026.

The governance consequence is not that these models are better. It is that a permissively licensed, natively multimodal model at this scale can be run inside your own boundary. That changes two conversations at once. It weakens the argument that a capable model necessarily means an offshore processor, which matters for data residency. And it moves the entire control stack onto you: evaluation, versioning, logging, fallback and decommissioning stop being a vendor's contractual obligation and become your own operational burden. If your AI register counts vendors, it is worth reading it alongside the piece on vendor counts hiding a single foundation model, because self-hosting changes the concentration picture without removing it. The provenance question raised by Inkling's open weights applies here too: an open licence tells you what you may do with a model, not where it came from.

Regulators and governments

2 August: the European Union's enforcement machinery switched on. The European Commission's own framework page states that "from 2 August 2026, the AI Office and authorities of the Member States are responsible for implementing, supervising and enforcing the AI Act", and that the AI Office holds enforcement powers over general-purpose AI models. The transparency rules took effect in the same month. High-risk obligations for standalone systems remain deferred to 2 December 2027.

For Australian organisations the practical test is unchanged from what we wrote when the date arrived: if you deploy a general-purpose model into a European-facing process, the evidence you can produce about that model is now someone's supervisory business, not just your own risk appetite.

Australia

20 August: APRA published its 2026-27 Corporate Plan. The plan is focused on "strengthening industry's resilience to geopolitical tensions, cyber-attacks and frontier AI", and commits APRA to "ensuring regulated entities are strengthening their resilience to AI-enabled cyber threats, and stepping up APRA's focus on quantum computing risks". Read against April's letter to industry, which found that governance, risk management, assurance and operational resilience practices were not keeping pace with AI adoption, the corporate plan converts that finding into a supervision priority for the year.

24 August: the Fair Work Commission published a generative AI guidance note. The Commission's President released a statement and the guidance note, which applies from 20 October 2026, alongside a research report on the use of AI by applicants. The note sets three requirements where generative AI is used to prepare documents: "you must tell us when and how you used GenAI"; "you must check your document is correct and relevant to the case"; and where the document is a witness statement or declaration, "you must check that it is based on your own knowledge, reflects your own words and is true to the best of your knowledge". The Commission's application and response forms are being updated by 20 October to support the requirement.

This is the most operationally specific of August's Australian moves, and the one with the shortest runway. It reaches any organisation that lodges or responds to a matter, which includes most employers.

26 August: National Cabinet backed national AI laws. The communique records that "following the Commonwealth's world leading action on artificial intelligence (AI) to develop national laws by early 2027, First Ministers agreed the emerging technology represents a generational opportunity for Australia if properly harnessed". It confirms that the Australian Government "will introduce AI laws in Australia's Interests, a nationally consistent regulatory framework that will set minimum requirements for large data centres", announced by the Prime Minister on 15 July 2026, and that "the Commonwealth will work with state and territory governments to develop consistent mandatory standards for data centre energy, water and land-use, and support skills and training opportunities". The Commonwealth "intends to legislate the AI standards in early 2027", and the legislation is "designed to complement, not duplicate, state and territory planning and approval processes".

Two things are worth separating here. The data centre standards are concrete and infrastructure-facing. The broader national AI laws remain a stated intention with a date attached, not enacted law. Treat the first as a planning input and the second as a horizon.

26 August: ASIC published its Corporate Plan 2026-27. The same day, ASIC named "enabling the safe adoption of artificial intelligence (AI)" among its areas of focus, observed that "AI is transforming ASIC's operating environment", and warned that "weakening information quality, reduced accountability and AI technologies can increase exposure to misleading and unreliable financial information outside traditional firm channels". Two commitments are specific enough to plan against. Under market integrity, ASIC "will assess and address AI-driven manipulation and market integrity risks, including deepfakes and misinformation, using generative AI, social media monitoring and cross-market analysis". Under its banking work, ASIC states plainly that it "will monitor increased use of AI by banks to identify harms or risks to consumers". ASIC also described its own AI governance, including an AI board providing "independent approval and oversight of AI use cases".

What it means for your desk

Four published documents in seven days is not a coincidence of the calendar. It is what happens when supervisory interest matures. The useful response is not another risk assessment. It is to make one thing about your AI use legible to somebody outside your team, because that is what each of these documents is asking for in its own vocabulary.

Workers Compensation

The Fair Work Commission's requirement is not a workers compensation rule, but the standard it sets travels. When a document you produced with AI assistance reaches an external decision-maker, the question of what the model contributed becomes answerable rather than assumed. Determinations, statements and reconsideration material all move outward in the same way.

The move for September is a short AI-use note attached internally to any document that leaves the file for an external reader: which tool, at which step, and who checked the facts against source. It is not a disclosure to the claimant and it does not change the decision. It records what a reviewer would otherwise have to reconstruct. Pair it with the discipline in statement summaries needing source IDs, and test the output against the plain-English reader test rather than adding new reasons.

Work Health and Safety

National Cabinet's data centre standards will not reach most WHS teams directly. The change load will. August's regulatory tempo is a reminder that AI-driven change in a workplace arrives as a sequence of small updates rather than one rollout, and consultation duties attach to the change, not to the announcement.

The move is a single consultation record for the AI changes already in flight: what changed, who was consulted, what workers raised, and what was done about it. If health and safety representatives have asked how a deployed tool changes the work, a vendor slide is not an answer. Where several updates overlap, map the combined load before assessing any one of them.

One AI use, four readers
Figure 2. The September legibility test: the same AI-assisted piece of work has to answer a tribunal, a regulator, a health and safety representative and an internal reviewer, and each of them asks for the same underlying record in different words.

GRC

The two corporate plans are the most useful artefacts August produced, because they are workplans rather than opinions. APRA has committed to resilience against AI-enabled cyber threats. ASIC has committed to monitoring bank AI use for consumer harm and to addressing AI-driven market manipulation.

The move is a one-page crosswalk from those published commitments to your own AI controls, marking each as covered, partly covered or absent. Absent is an acceptable answer in September; unknown is not. Two controls deserve early attention because both regulators keep returning to them. Test whether your fallback is a recovery plan or just a second path to the same dependency. And confirm that when a regulator asks for the file, you can produce the source rather than the AI summary of it.

HR

The Fair Work Commission's guidance note lands on HR before it lands on lawyers, because the people who prepare responses to Commission matters usually sit in HR. From 20 October, a response prepared with generative AI has to say so, has to have been checked for accuracy and relevance, and where it is a witness statement, has to be in the witness's own words and own knowledge.

The move is a briefing, in writing, to everyone who prepares or lodges Commission material, delivered well before 20 October so the practice is settled when the requirement starts. Two adjacent checks are worth running at the same time: whether the people you asked to use the tool can actually use it, and whether your digital work systems would withstand an inspection request.

Leadership

The signal for leaders is the date. Australia now has a stated intention to legislate national AI laws in early 2027, endorsed across nine governments. That is far enough away that a large programme is premature, and close enough that having no position is a choice.

The move is a one-page internal position on what the announced framework would mean for the organisation, written now while it is cheap: which of our AI uses would plausibly sit inside minimum requirements, what we would need to evidence, and what we would want to have started by mid-2027. Grade it honestly, because an update without an evidence grade invites more confidence than the material supports. And make sure the position is not held by one team alone, since an AI advantage confined to a single group does not survive contact with a regulator asking organisation-wide questions.

Four commitments, one crosswalk
Figure 3. The September crosswalk: every published regulator commitment maps to one of your controls and gets marked covered, partly covered or absent, with a named owner against each row.

Prompt of the month

This prompt builds the GRC crosswalk described above. It is written for a general assistant with no access to your systems, so it produces a structure you populate rather than an answer it invents.

Prompt
You are helping me build a regulator-commitment crosswalk for AI controls in an
Australian financial services organisation. You have no access to our systems and
must not invent our controls.

I will paste published regulator commitments about AI. For each one, produce a row
with these fields:

1. Source (regulator, document, date)
2. The commitment, quoted or closely paraphrased
3. The question a supervisor could reasonably ask us because of it
4. The internal artefact that would answer that question
5. Status: leave blank for me to mark covered, partly covered or absent
6. Owner: leave blank

Rules:
- Do not assess whether we comply. You do not know.
- Do not merge commitments from different regulators into one row.
- Where a commitment is an intention with a future date rather than a current
  obligation, say so explicitly in the row.
- If a commitment is too vague to generate a specific supervisory question, say
  so rather than inventing one.

Output a markdown table. After the table, list any commitment you could not turn
into a specific question, and explain why.

Do not paste customer data, claim material or personal information into a general assistant to run this. The inputs are published regulator documents and the output is a blank framework.

Glossary

Corporate plan. An annual public document in which a Commonwealth entity sets out its purposes, operating environment and planned activities. For a regulator, it is the closest thing to a published supervisory workplan.

Frontier AI. The most capable current generation of general-purpose models. Both APRA and ASIC used the term in August to describe a source of cyber and market risk rather than a product category.

General-purpose AI model. In the European AI Act, a model capable of competently performing a wide range of distinct tasks. From 2 August 2026 the AI Office holds enforcement powers over these models.

Open weights. A release in which the model's trained parameters are published for download. It is distinct from open source: the weights may be permissively licensed without the training data or process being disclosed.

MIT licence. A short permissive software licence allowing use, modification and redistribution with attribution and no warranty. Applied to model weights, it removes most licensing barriers to self-hosting.

Mixture of experts. An architecture in which only a subset of a model's parameters activates for any given input, which is why a model can carry 320 billion total parameters while activating 18 billion.

References

  1. Prime Minister of Australia, Meeting of National Cabinet, 26 August 2026.
  2. Australian Prudential Regulation Authority, APRA publishes 2026-27 Corporate Plan, 20 August 2026.
  3. Australian Securities and Investments Commission, Corporate Plan 2026-27, published 26 August 2026.
  4. Fair Work Commission, Use of AI in Commission cases, 24 August 2026.
  5. European Commission, AI Act regulatory framework, accessed 31 August 2026.
  6. Z.ai, GLM-5.3-Flash model repository, published 25 August 2026.
  7. DeepSeek, DeepSeek-V4-Pro-0813 model repository, published 13 August 2026.
  8. Australian Prudential Regulation Authority, APRA calls for a step-change in AI-related risk management and governance, 30 April 2026.

General information and education only. Not legal, compliance, financial or professional advice. Verify against the primary sources before acting.

← All editions

General information and education only. Not legal, compliance, financial, or professional advice.

TheAICommand. Intelligence, At Your Command.