# Questions and Answers, TheAICommand

978 questions answered across Australian AI governance, workers compensation, work health and safety, HR, leadership and compliance. Each answer links to the article it came from.

Canonical HTML: https://theaicommand.com/questions

## Governance, risk and compliance

APRA, ASIC, AML/CTF and the prudential standards.

### Are ASIC's proposed kill-switch rules in force?

No. ASIC released CP 386, proposing amendments to the market integrity rules for trading systems and automated trading, on 27 August 2025, with comments closing on 22 October 2025. Among the proposals are a requirement for kill switches enabling immediate suspension of aberrant trading algorithm activity, and an extension of the principles-based trading system rules to participants' development, testing, use and monitoring of their algorithms. As at the time of writing, the amended rules had not been made. Treat the items as proposals with a clear direction of travel, not obligations.

Source: [Agentic Trading and the Purpose Problem](https://theaicommand.com/grc/agentic-trading-and-the-purpose-problem#faq-4)

### Are these forecasts hiring advice?

No. They are editorial projections based on regulator, labour-market and salary-guide signals available to 10 July 2026. Employers and candidates should refresh the evidence and obtain professional advice for their circumstances.

Source: [The 2026 AI Governance Talent Market: Assurance Skills Move to the Core](https://theaicommand.com/grc/2026-ai-governance-talent-market-assurance-skills#faq-5)

### Can a superannuation trustee let an AI make a decision?

A trustee can use AI to inform or support a decision, but the core discretions the SIS Act reserves to the trustee cannot be handed to a model. Section 52(2)(h) requires the trustee not to enter into any contract, or do anything else, that would prevent or hinder it from properly performing its functions, and section 52(2)(c) requires the trustee to exercise its powers in the best financial interests of beneficiaries. A decision made or effectively dictated by an AI, where the trustee cannot explain or stand behind the reasoning, is difficult to reconcile with those covenants. The safe pattern is AI supports, the trustee decides, and the reasoning is recorded.

Source: [Super Trustees, AI and the Discretion You Cannot Delegate](https://theaicommand.com/grc/super-trustees-ai-discretion-you-cannot-delegate#faq-2)

### Can AI decide the outcome of a customer complaint?

No. Deciding whether to uphold or reject a complaint, and explaining the reasons, is a regulated decision that a person accountable under RG 271 must own. AI can draft a response for a human to check and approve, but it cannot be the decision-maker, and letting it decide would put an unexplained, potentially unfair outcome in front of an aggrieved customer.

Source: [AI in Complaints Handling: What RG 271 Reserves for a Person](https://theaicommand.com/grc/ai-complaints-handling-rg-271#faq-2)

### Can AI-generated output stand as audit evidence under Standard 14.1?

Not on its own. Standard 14.1 requires information to be relevant, reliable and sufficient. AI output is not obtained directly by the auditor, is not an independent source, and a non-deterministic system cannot guarantee a competent person re-running the work reaches the same result. Corroboration against source records, not generation, earns it a place in the file.

Source: [AI in Internal Audit: What Still Counts as Evidence](https://theaicommand.com/grc/ai-in-internal-audit#faq-2)

### Can an AI agent initiate CDR payments today?

No. The Act is in force but no action type has been designated, so no provider, human or AI, is initiating payments or switches through the CDR yet. That gap is the opportunity. Compliance teams can design the authorisation, consent and audit controls for agent-initiated actions before any money can move, rather than retrofitting them onto a live rail under time pressure.

Source: [Governing AI Agents Before the Consumer Data Right Lets Them Act](https://theaicommand.com/grc/ai-agents-cdr-action-initiation-governance#faq-2)

### Can an LLM make the decision to file a suspicious matter report?

No. The decision to file or not file a suspicious matter report is a judgement the regulated entity makes, with consequences sitting with the entity. LLM-driven triage can support the analyst's decision, but the decision itself should sit with a human. Final certification of customer due diligence is likewise a regulated act requiring human authority.

Source: [AML/CTF and Large Language Models: A Compliance View](https://theaicommand.com/grc/amlctf-and-large-language-models#faq-2)

### Can competitors use the same pricing software?

Common software use is not automatically unlawful. Risk rises when the provider combines competitively sensitive data from multiple competitors or delivers recommendations that reduce uncertainty about rivals' future conduct, the hub-and-spoke pattern regulators keep flagging. Obtain competition advice on the actual design, data flows and contractual restrictions rather than relying on a generic confidentiality clause.

Source: [Your Pricing Agent Is Still Your Competition Risk](https://theaicommand.com/grc/ai-pricing-agent-competition-risk#faq-2)

### Can disclaimers keep an AI interaction inside DDO and general advice?

No. ASIC's communication emphasises that the substance of a communication matters more than the formal classification an institution applies. Disclaimers cannot, on their own, change how the law characterises a communication. If an interaction has substantively crossed into personal advice, a general information disclaimer will not recharacterise it.

Source: [DDO and AI-Driven Personalisation: Where the Boundary Sits](https://theaicommand.com/grc/ddo-and-ai-driven-personalisation#faq-4)

### Can I use an AI model to help build the ADM register and disclosure?

Yes, for structuring, classification logic and first-draft drafting, but only inside a dedicated project space using de-identified inputs with placeholder tokens. Never paste real personal, claim or health data. The model produces a register skeleton and disclosure language. It does not decide what is in scope. A named human checks every scope call against the primary source.

Source: [Automated Decisions Now Belong in Your Privacy Policy](https://theaicommand.com/grc/adm-transparency-privacy-policy-2026#faq-5)

### Can I use an AI model to help review these contracts?

Yes, for drafting a gap checklist, summarising a long agreement against the requirements and producing a first-pass register. It is a drafting aid, not the decision-maker. A named accountable person, with legal advice, decides whether a contract complies and whether an exit or fallback is genuinely feasible.

Source: [CPS 230's 1 July Deadline Just Caught Up With Your AI Vendors](https://theaicommand.com/grc/cps-230-ai-vendor-contract-deadline#faq-5)

### Do the IIA Global Internal Audit Standards mention artificial intelligence?

No. A full-text search of the 2024 Global Internal Audit Standards returns no mention of artificial intelligence, and there is no AI Topical Requirement. The Standards are technology-neutral by design, so AI-assisted work answers to the same evidence, documentation, objectivity and due-care requirements as any other audit work.

Source: [AI in Internal Audit: What Still Counts as Evidence](https://theaicommand.com/grc/ai-in-internal-audit#faq-1)

### Do we need a human to review AI-generated marketing content?

In practice, yes. Because AI-generated advertising is held to the same standard as human-written advertising, and because generative tools can produce inaccurate, outdated or biased claims, a defensible process puts AI-generated marketing through the same substantiation and sign-off you already apply to human content. The person who approves it, not the model, is accountable for whether the final claim is true and not misleading.

Source: [AI Wrote the Ad. ASIC Still Holds You to It.](https://theaicommand.com/grc/ai-washing-and-ai-generated-advertising#faq-3)

### Does a human approval step take an automated system out of scope?

No. APP 1.8 expressly covers decisions where a machine does something substantially and directly related to making the decision and a person finishes it. If a model ranks, scores or recommends and a human clicks approve, the system still shapes the outcome and belongs in the privacy policy.

Source: [Automated Decisions Now Belong in Your Privacy Policy](https://theaicommand.com/grc/adm-transparency-privacy-policy-2026#faq-2)

### Does an AI complaints tool create privacy obligations?

Yes. A complaint file routinely contains sensitive information such as health, financial hardship and family and domestic violence. An AI tool that reads and drafts on that file is processing sensitive personal information, often through a third-party service, so it carries Privacy Act obligations and needs the same governance as any high-consequence system.

Source: [AI in Complaints Handling: What RG 271 Reserves for a Person](https://theaicommand.com/grc/ai-complaints-handling-rg-271#faq-4)

### Does an offline controls console satisfy APRA CPS 230 on its own?

No. CPS 230 requires identifying and managing operational risks, maintaining and testing controls, and remediating gaps on a timely basis. A console does not satisfy it alone. It only makes the working layer of control monitoring and testing more consistent before results enter the official platform.

Source: [Build an Offline GRC Controls Console Without Creating Shadow IT](https://theaicommand.com/grc/offline-grc-controls-testing-console#faq-3)

### Does APRA CPS 230 apply to enterprise AI tools like Copilot, Gemini, Claude and ChatGPT Enterprise?

Yes. Most enterprise AI tools sit inside the third-party arrangements CPS 230 governs. Where AI outputs feed material decisions or critical operations, the standard reaches the model lifecycle as well as the contract, so the question is no longer whether AI is in scope but how to evidence it.

Source: [CPS 230 and AI: A Practical Operational Resilience Playbook](https://theaicommand.com/grc/cps-230-and-ai-operational-resilience-playbook#faq-1)

### Does APRA's AI letter apply to superannuation trustees?

Yes. APRA's 30 April 2026 letter to industry states that APRA conducted a targeted engagement on a group of selected large banks, insurers and superannuation trustees in late 2025, and the expectations it sets out apply across regulated entities including RSE licensees. Among the minimums APRA names are ownership and accountability across the AI lifecycle, an inventory of AI tooling and use cases, human involvement for high-risk decisions and accountability, and staff training on AI use, misuse and limitations.

Source: [Super Trustees, AI and the Discretion You Cannot Delegate](https://theaicommand.com/grc/super-trustees-ai-discretion-you-cannot-delegate#faq-1)

### Does ASIC's RG 234 apply to AI-generated advertising?

Yes. ASIC's updated RG 234, published on 9 June 2026, makes clear that the law and ASIC's guidance apply to AI-generated advertising in the same way they apply to human-written advertising. Using an AI tool to generate a claim does not lower the standard or shift responsibility. The financial services misleading-conduct prohibitions in the ASIC Act and Corporations Act apply regardless of who or what produced the words.

Source: [AI Wrote the Ad. ASIC Still Holds You to It.](https://theaicommand.com/grc/ai-washing-and-ai-generated-advertising#faq-1)

### Does AUSTRAC have AI-specific guidance for AML/CTF programs?

AUSTRAC has not published AI-specific guidance. The AUSTRAC Compliance Guide makes clear the obligation is on the reporting entity to design a program proportionate to its risk profile and operate it consistently with the AML/CTF Rules. LLM use sits inside that obligation, not outside it, and supervisory engagement on AI is increasingly likely.

Source: [AML/CTF and Large Language Models: A Compliance View](https://theaicommand.com/grc/amlctf-and-large-language-models#faq-4)

### Does Australia have an AI Act?

No. The National AI Plan, launched on 2 December 2025, confirmed the government will not introduce a standalone AI Act or the mandatory guardrails for high-risk AI proposed in 2024. Australia has chosen to regulate AI through existing technology-neutral laws, sector regulators, voluntary guidance and an advisory AI Safety Institute, rather than a single dedicated statute.

Source: [Australia Will Not Pass an AI Act. You Are Still Regulated.](https://theaicommand.com/grc/australia-no-ai-act-existing-law-compliance#faq-1)

### Does CPS 230 apply to AI vendors even if the contract is not labelled an AI contract?

Yes. CPS 230 reaches any material service provider, meaning one an entity relies on to perform a critical operation or that exposes it to material operational risk. If a model helps run claims processing, fraud detection or credit decisioning, the provider behind it is captured, whatever the contract calls it.

Source: [CPS 230's 1 July Deadline Just Caught Up With Your AI Vendors](https://theaicommand.com/grc/cps-230-ai-vendor-contract-deadline#faq-2)

### Does CPS 234 apply to AI vendors my organisation uses?

Yes. CPS 234 covers information assets managed by third parties, not just the entity itself. AI vendors introduce new asset categories such as prompts, fine-tuning data, embeddings, and inference logs, all of which the standard treats as in-scope and which must be identified, classified, and protected commensurate with their sensitivity.

Source: [CPS 234 and AI Vendors: A Due Diligence Framework](https://theaicommand.com/grc/cps-234-third-party-ai-vendor-due-diligence#faq-1)

### Does FAR apply to AI tooling decisions in financial services?

Yes. AI tooling decisions sit inside FAR-prescribed responsibilities even when not framed as AI decisions. Deploying AI in compliance monitoring is a compliance system design decision; deploying it in customer-facing operations is a customer outcomes decision. The accountable person owns the consequence regardless of how procurement framed the tooling choice.

Source: [FAR and AI: How Accountability Maps to Tooling Decisions](https://theaicommand.com/grc/far-responsibility-and-ai-tooling#faq-1)

### Does FAR apply to insurers and superannuation trustees for AI governance?

FAR replaced BEAR for ADIs in March 2024 and is being extended to insurers and trustees in stages through 2026. The architecture is the same, though prescribed responsibilities are weighted differently. AI tooling governance should be part of FAR readiness and inside the responsibility map from day one, not a separate workstream.

Source: [FAR and AI: How Accountability Maps to Tooling Decisions](https://theaicommand.com/grc/far-responsibility-and-ai-tooling#faq-5)

### Does human approval remove the competition risk?

No. A human click is a weak control if the reviewer does not understand the inputs, the objective or the market pattern the agent is producing. Human oversight needs authority, information, materiality thresholds and the time to challenge a recommendation before it takes effect.

Source: [Your Pricing Agent Is Still Your Competition Risk](https://theaicommand.com/grc/ai-pricing-agent-competition-risk#faq-3)

### Does market manipulation in Australia require proof of intent?

No. Australia's core prohibitions are drafted on effect. In DPP (Cth) v JM [2013] HCA 30; (2013) 94 ACSR 1; 298 ALR 615, the High Court took a broad view and held that a sole or dominant purpose of creating or maintaining an artificial price is not necessary to a contravention, though it can provide evidence that a transaction is likely to have the prohibited effect. Purpose is evidence rather than an element to prove. It still matters, because a legitimate trader purpose is what saves a price-moving trade.

Source: [Agentic Trading and the Purpose Problem](https://theaicommand.com/grc/agentic-trading-and-the-purpose-problem#faq-2)

### Does the AUSTRAC AI update affect my firm if we already run a mature AML program?

Yes, but differently. The starter kits are not your tool, yet the national risk assessment you must consider now names AI as an enabling capability. Revisit how your enterprise risk assessment, onboarding controls and monitoring scenarios treat AI-enabled identity fraud, document forgery and high-volume, machine-paced structuring.

Source: [AUSTRAC Just Put AI Risk Into Your AML Program Documents](https://theaicommand.com/grc/austrac-ai-risk-in-aml-program-documents#faq-2)

### Does the best financial interests duty apply to AI spending?

It applies to the money the fund spends. Section 52(3A) of the SIS Act states that the best financial interests obligation applies in respect of payments to a third party by, or on behalf of, the entity. So the cost of buying or building an AI system, like any other expenditure, has to be justifiable as being in members' best financial interests, and APRA's SPS 515 reinforces the expectation that controls prevent expenditure that would be unjustifiable against that duty.

Source: [Super Trustees, AI and the Discretion You Cannot Delegate](https://theaicommand.com/grc/super-trustees-ai-discretion-you-cannot-delegate#faq-3)

### Does the FAR relief reduce accountability for AI decisions?

No. ASIC and APRA framed the package as reducing regulatory burden without lowering accountability standards. A named accountable person still owns the consequences of an AI tool deployed inside a regulated function, and the reasonable-steps duty is unchanged. What has moved is the volume of routine reporting, not the underlying obligation to be able to evidence it.

Source: [FAR Eased Up. Your AI Map Still Holds](https://theaicommand.com/grc/far-eased-up-your-ai-map-still-holds#faq-2)

### Does the government mandate apply to private companies?

No. The policy binds non-corporate Commonwealth entities, with some exceptions, not private companies. Its value to a private-sector GRC team is as a template. The field set, the accountable-owner requirement and the reporting cadence show what a government thinks a minimum viable AI register looks like, which is useful reference material for a register built under CPS 230 or the Voluntary AI Safety Standard.

Source: [Canberra's AI Register Mandate Is a Preview](https://theaicommand.com/grc/canberra-ai-register-mandate-is-a-preview#faq-4)

### Does the Office of AI regulate how an organisation uses AI?

No. The joint media release of 15 July 2026 says the Office of AI is established within the Department of the Prime Minister and Cabinet to accelerate implementation of the Australian Standards for AI at a national level. It is a coordinating body inside a central agency. The release gives it no enforcement powers, and no standard, draft or bill has been published. It changes who coordinates AI standards work, not what binds a deployer of AI.

Source: [A New AI Office Is Not a New AI Obligation](https://theaicommand.com/grc/office-of-ai-not-a-new-obligation#faq-1)

### Does the Privacy Act say anything specific about public-facing chatbots?

Yes. The OAIC's guidance on privacy and the use of commercially available AI products, published 21 October 2024 and updated 17 January 2025, says businesses should update privacy policies and notifications with clear information about their use of AI, including ensuring that any public facing AI tools such as chatbots are clearly identified as such to external users. It also states that where AI systems generate or infer personal information, that is a collection.

Source: [Your Website AI Assistant Is Someone Else's Code](https://theaicommand.com/grc/website-ai-assistant-third-party-code#faq-3)

### Does using the business's AI platform impair audit independence?

Not automatically, much like sharing the corporate ERP or email. But Standards 2.1 and 2.2 require objectivity threats to be recognised and managed. The real risk is the dependency never gets written down. Use a dedicated audit workspace, independent validation data, and state the shared-platform dependence in engagement workpapers.

Source: [AI in Internal Audit: What Still Counts as Evidence](https://theaicommand.com/grc/ai-in-internal-audit#faq-4)

### Has ASIC created new AI-specific rules or licensing conditions?

No. ASIC has not imposed a new licensing condition, prohibited specific AI use cases, provided a safe harbour, or signalled immediate legislative change. The existing licensing framework continues to apply. Compliance is judged against existing obligations applied to the specific facts of each AI use case.

Source: [ASIC's AI Supervisory Posture, Decoded](https://theaicommand.com/grc/asic-april-2026-ai-statement-decoded#faq-4)

### How are large language models being used in AML/CTF compliance programs?

They draft suspicious matter report narratives from structured alert data, summarise complex KYC source-of-wealth documentation, triage high-volume transaction monitoring alerts with recommended dispositions, and generate internal training and policy content. Each use case sits inside the regulated AML/CTF program and remains subject to AUSTRAC oversight and the reporting entity's responsibility.

Source: [AML/CTF and Large Language Models: A Compliance View](https://theaicommand.com/grc/amlctf-and-large-language-models#faq-1)

### How can an organisation start an AI incident process without overbuilding?

Create a minimum viable extension to existing incident management: an AI incident intake checklist, an evidence pack template, escalation criteria and post-incident review questions. Link these artefacts to the AI use-case register, privacy assessment, cyber incident playbook and vendor management framework, then have internal audit test consistency.

Source: [AI Incident Response Needs an Evidence Pack, Not Just a Playbook](https://theaicommand.com/grc/ai-incident-response-evidence-pack#faq-4)

### How do APRA's CPS 234 and CPS 230 standards apply to AI cyber risk?

CPS 234 requires boards to approve information security strategies, define cyber risk roles, test and monitor controls, and manage incident reporting. CPS 230 requires operational risk frameworks to cover emerging risks, including AI. Both embed AI cyber risk into enterprise risk management as a strategic, not niche technical, issue.

Source: [AI Cyber Risk Is Now a Board Governance Issue](https://theaicommand.com/grc/ai-cyber-risk-board-governance#faq-4)

### How do GRC teams triage suspected AI incidents?

Build an AI triage layer into existing incident intake. Ask whether AI influenced a decision or communication, whether personal, confidential or regulated data was involved, whether a third party was involved, whether an automated action was performed, and whether a human reviewed the output. The triage outcome should determine escalation.

Source: [AI Incident Response Needs an Evidence Pack, Not Just a Playbook](https://theaicommand.com/grc/ai-incident-response-evidence-pack#faq-3)

### How do I prove the console is genuinely offline?

Open the browser developer tools, switch to the Network tab, reload the file, then import, validate, filter and export. If request count stays at zero, the offline promise holds. Repeat with the machine disconnected entirely. A tool that still works with the network out is genuinely offline.

Source: [Build an Offline GRC Controls Console Without Creating Shadow IT](https://theaicommand.com/grc/offline-grc-controls-testing-console#faq-4)

### How do I set CPS 230 tolerance levels for an AI-supported operation?

AI disruption can be partial rather than binary, so tolerance levels must express both availability and output quality. Put four answers in writing: maximum tolerable availability disruption, maximum tolerable quality degradation, the manual fallback and its throughput, and the named owner accountable for setting the level and triggering escalation when breached.

Source: [CPS 230 and AI: A Practical Operational Resilience Playbook](https://theaicommand.com/grc/cps-230-and-ai-operational-resilience-playbook#faq-2)

### How do I start building an AI use case register?

Start with high-risk or high-impact use cases affecting customers, employees or critical operations. Use a standard template for consistency, integrate with existing risk and compliance systems, train owners and reviewers, automate tracking and reporting, document human oversight clearly, record incidents and complaints, and review and update the register regularly.

Source: [Build an AI Use Case Register That Boards Can Actually Use](https://theaicommand.com/grc/ai-use-case-register-board-evidence#faq-5)

### How do I stop an AI-built controls console from becoming shadow IT?

Treat it as governed end-user computing. Give it a named owner, keep it offline, validate inputs, separate preparer from reviewer, ship a short governance pack, and write a retirement date before use. The code can be identical to shadow IT; only that governance keeps it on the right side.

Source: [Build an Offline GRC Controls Console Without Creating Shadow IT](https://theaicommand.com/grc/offline-grc-controls-testing-console#faq-2)

### How do I turn voluntary AI guardrails into audit evidence?

Convert each guardrail into a control objective stating what must be true, then define controls that make it true and evidence that proves the control operated. Human oversight, for example, becomes a control objective requiring competent human review of material outputs, supported by workflow gating, reviewer training, approval records, exception logs and audit samples.

Source: [From Voluntary AI Guardrails to Audit Evidence](https://theaicommand.com/grc/voluntary-ai-guardrails-to-audit-evidence#faq-2)

### How does AI incident response connect to accountability?

A mature process connects events to accountability by identifying whether governance allocated responsibility before the incident occurred. The practical question is who was accountable for approving, monitoring and accepting residual risk for the AI use case. If that is unclear during an incident, the governance model is probably unclear during normal operations.

Source: [AI Incident Response Needs an Evidence Pack, Not Just a Playbook](https://theaicommand.com/grc/ai-incident-response-evidence-pack#faq-5)

### How does ASIC's AI posture intersect with APRA, AUSTRAC, and OAIC?

ASIC does not operate alone. A single AI use case can attract supervisory questions from multiple regulators: ASIC on conduct, APRA on operational risk, AUSTRAC on AML and CTF, and OAIC on privacy. Mature institutions design AI governance to map to all relevant regimes from inception rather than retrofitting compliance later.

Source: [ASIC's AI Supervisory Posture, Decoded](https://theaicommand.com/grc/asic-april-2026-ai-statement-decoded#faq-5)

### How does the six-monthly DTA cadence compare with APRA's expectations?

The DTA sets a fixed six-monthly reporting rhythm to a central agency. CPS 230 requires APRA-regulated entities to maintain registers and manage operational risk, and to notify APRA of material operational risk incidents, but it does not prescribe a fixed six-monthly submission of an AI register. The lesson is the discipline of a set cadence, not the specific interval.

Source: [Canberra's AI Register Mandate Is a Preview](https://theaicommand.com/grc/canberra-ai-register-mandate-is-a-preview#faq-5)

### How does this connect to APRA's April 2026 AI letter?

The April letter named weak board AI literacy, overreliance on vendor summaries and gaps in AI lifecycle management as live findings. CPS 510 hands boards back time by cutting process paperwork. The practical move is to spend that time closing the gaps the April letter named.

Source: [Freed Board Bandwidth Is for AI Oversight](https://theaicommand.com/grc/cps-510-frees-board-time-for-ai-oversight#faq-4)

### How does using an LLM in an AML/CTF program intersect with the Privacy Act?

Customer data flowing through prompts is in scope of the Australian Privacy Principles, inference logs containing customer data raise use and disclosure questions, and cross-border transfer to an overseas-hosted LLM engages APP 8. The OAIC position is that the Privacy Act applies to AI processing, so deployments must satisfy both AUSTRAC and OAIC frameworks.

Source: [AML/CTF and Large Language Models: A Compliance View](https://theaicommand.com/grc/amlctf-and-large-language-models#faq-5)

### How often does the government register have to be reported?

Agencies must share their register with the Digital Transformation Agency every six months, counting from when the register is first created, by emailing it to the DTA or using a method agreed with the DTA in advance. Accountable officials must also notify the DTA whenever a new high-risk use case is identified.

Source: [Canberra's AI Register Mandate Is a Preview](https://theaicommand.com/grc/canberra-ai-register-mandate-is-a-preview#faq-3)

### How often should AI controls be monitored?

AI assurance cannot be a once-a-year policy check, because models, data, user behaviour and processes all change. Organisations should define what is monitored, how often, by whom and with what escalation triggers. Useful signals include newly detected AI tools, high-risk use cases without review, unresolved red-team findings, human review exceptions, incidents and vendor model changes, fed into ordinary risk reporting.

Source: [From Voluntary AI Guardrails to Audit Evidence](https://theaicommand.com/grc/voluntary-ai-guardrails-to-audit-evidence#faq-5)

### How often should AI use cases in the register be reviewed?

Use cases in production should be reviewed at least quarterly, while pilots should be reviewed monthly. Reviews must verify risk controls, human oversight effectiveness, incident reports, and any changes in scope or technology. Significant issues or emerging risks must be escalated promptly to the board or risk committee with clear recommendations.

Source: [Build an AI Use Case Register That Boards Can Actually Use](https://theaicommand.com/grc/ai-use-case-register-board-evidence#faq-2)

### How often should I test controls for material AI vendor relationships?

Match the testing cadence to the change cadence. Because the underlying model can change without notice, annual-only assurance is unlikely to be sufficient. Quarterly assurance with continuous output monitoring is a reasonable starting point for material vendors, with documented trigger conditions for ad hoc reassessment.

Source: [CPS 234 and AI Vendors: A Due Diligence Framework](https://theaicommand.com/grc/cps-234-third-party-ai-vendor-due-diligence#faq-4)

### How should an AI personalisation engine interact with target market determinations?

The target market determination is the source of truth. The engine's distribution rules should derive from it as a hard filter, not run in parallel. Where an engine optimised for conversion drifts from the TMD, the entity has a control failure supervisors can pursue. Review TMDs for material products against the engine's actual operation.

Source: [DDO and AI-Driven Personalisation: Where the Boundary Sits](https://theaicommand.com/grc/ddo-and-ai-driven-personalisation#faq-3)

### How should board AI literacy training be designed?

Literacy should be role-specific and built around decisions the board actually makes, covering AI strategy, materiality thresholds, high-risk use cases, assurance expectations, regulatory reporting, third-party concentration, cyber exposures and incident escalation. The best programmes use scenarios, revealing whether directors understand materiality, affected stakeholders, failure modes and assurance needs rather than vocabulary recall.

Source: [Board AI Literacy Is Now a Control Expectation, Not a Training Nice-to-Have](https://theaicommand.com/grc/board-ai-literacy-as-control-expectation#faq-5)

### How should I govern AI used in transaction monitoring or screening?

Mirror AUSTRAC's own model from its AI transparency statement: AI surfaces and prioritises while a person forms the suspicion and makes the report, sensitive data never enters public generative tools through protective-security controls, and someone is named accountable for the AI. Keep a record of why the tool is calibrated as it is.

Source: [AUSTRAC Just Put AI Risk Into Your AML Program Documents](https://theaicommand.com/grc/austrac-ai-risk-in-aml-program-documents#faq-4)

### How should internal audit provide assurance over AI controls under CPS 230?

CPS 230 paragraph 56 expects independent assurance. Three approaches are emerging: upskilling internal audit, co-sourcing with external specialists, or establishing a second line AI risk function that audit can review. None is wrong; the test is whether the assurance model produces credible findings. Silence on AI controls is what is unacceptable.

Source: [CPS 230 and AI: A Practical Operational Resilience Playbook](https://theaicommand.com/grc/cps-230-and-ai-operational-resilience-playbook#faq-5)

### How should the change affect an AI use-case register?

Treat it as a prompt to restructure, not to shrink. Split the register into a maintained core that a named owner keeps current and reports on, and an on-request evidence library that stays available but is not routinely filed. The lighter map means fewer scheduled updates, so the register becomes the more important record of where AI actually sits.

Source: [FAR Eased Up. Your AI Map Still Holds](https://theaicommand.com/grc/far-eased-up-your-ai-map-still-holds#faq-3)

### If there is no AI Act, is AI unregulated in Australia?

No, and that is the point most teams miss. AI is regulated by every law that already applies to what the AI does. Misleading AI marketing is caught by the ASIC Act, an AI decision affecting a person engages the Privacy Act, an AI vendor supporting a bank engages APRA's prudential standards. The absence of an AI Act does not mean an absence of obligations. It spreads them across the frameworks you already answer to.

Source: [Australia Will Not Pass an AI Act. You Are Still Regulated.](https://theaicommand.com/grc/australia-no-ai-act-existing-law-compliance#faq-2)

### Is dynamic pricing illegal in Australia?

No. The ACCC states that surge or dynamic pricing is not illegal, but businesses must be clear about the price consumers will pay and must not make false or misleading claims about prices or the reasons for price changes. The risk depends on conduct, including misleading price representations, anti-competitive agreements, cartel provisions and misuse of market power. Independent pricing and clear customer information remain the baseline.

Source: [Your Pricing Agent Is Still Your Competition Risk](https://theaicommand.com/grc/ai-pricing-agent-competition-risk#faq-1)

### Is full-population testing the same as generative AI in audit?

No, and conflating them is a common error. Full-population testing is deterministic analytics, returning the same answer every run, and predates the generative wave. Generative AI helps around the analytics by drafting query logic and threshold rationale, but the deterministic test remains the evidence engine, supported by Standard 14.1 data-reliability work.

Source: [AI in Internal Audit: What Still Counts as Evidence](https://theaicommand.com/grc/ai-in-internal-audit#faq-5)

### Is there a standard salary for an AI governance manager in Australia?

No reliable standard series exists. Use adjacent risk, compliance, audit, privacy, cyber or model-risk benchmarks, then adjust for actual scope, technical depth, accountability, city and observed candidate scarcity. Robert Half's 2026 guide puts adjacent senior risk and compliance roles at a national median of $170,000 excluding superannuation.

Source: [The 2026 AI Governance Talent Market: Assurance Skills Move to the Core](https://theaicommand.com/grc/2026-ai-governance-talent-market-assurance-skills#faq-2)

### Should internal auditors learn to code?

Not every auditor needs to code. Internal audit does need enough technical literacy to scope the system, challenge specialists, obtain appropriate evidence and understand test limitations. Some teams will also need dedicated technical-assurance capability.

Source: [The 2026 AI Governance Talent Market: Assurance Skills Move to the Core](https://theaicommand.com/grc/2026-ai-governance-talent-market-assurance-skills#faq-4)

### What AI typologies should my AML/CTF risk assessment now address?

The article names three shifts: identity fabrication, where convincing fakes and synthetic identities have become cheap; scale, where AI automates manual laundering and runs many machine-paced transactions; and communications, where plausible emails and supporting stories are generated cleanly, removing the sloppiness analysts once relied on to spot launderers.

Source: [AUSTRAC Just Put AI Risk Into Your AML Program Documents](https://theaicommand.com/grc/austrac-ai-risk-in-aml-program-documents#faq-3)

### What are ASIC's five supervisory themes on AI?

The five themes are: personalisation crossing into personal advice; disclosure and explainability; consumer remediation and dispute resolution; market integrity for AI in trading activity; and operational risk and resilience. Together they shape how ASIC expects licensees to apply existing obligations to AI components of their operations.

Source: [ASIC's AI Supervisory Posture, Decoded](https://theaicommand.com/grc/asic-april-2026-ai-statement-decoded#faq-2)

### What are the five components of the AI cyber risk governance operating model?

The article sets out five components: critical asset mapping, decision cadence and reporting, control validation and assurance, incident response exercises, and third-party concentration review. Together they translate ASIC and APRA expectations into actionable board and risk committee practices for managing AI-accelerated cyber risk effectively.

Source: [AI Cyber Risk Is Now a Board Governance Issue](https://theaicommand.com/grc/ai-cyber-risk-board-governance#faq-3)

### What are the key Tranche 2 deadlines I need to meet?

Reforms for existing reporting entities commenced on 31 March 2026. The new Tranche 2 designated services switch on from 1 July 2026, and newly regulated businesses must enrol with AUSTRAC by 29 July 2026. AUSTRAC has been explicit that enrolment is the start of the obligation, not the end of it.

Source: [AML Tranche 2: What AI Can and Cannot Do for Your New Program](https://theaicommand.com/grc/aml-tranche-2-reforms-and-ai#faq-2)

### What artefacts should GRC teams build to turn AI literacy into a control?

GRC teams should build an AI use-case register covering owner, purpose, users, affected stakeholders, data categories, vendor dependencies, risk rating and assurance status; a board reporting pack summarising material uses, exceptions, incidents and assurance outcomes; and a literacy and attestation process for executives accountable for material AI systems. These should be tested through internal audit.

Source: [Board AI Literacy Is Now a Control Expectation, Not a Training Nice-to-Have](https://theaicommand.com/grc/board-ai-literacy-as-control-expectation#faq-4)

### What controls should compliance teams build before actions are designated?

Five. An inventory of every CDR touchpoint marked read-only or action-capable. A policy separating propose from authorise so an agent never holds the trigger. Consent captured at the action, not just the connection. An immutable audit trail recording whether a human or an agent instructed each action. And a named accountable owner for every agent, with documented authority limits.

Source: [Governing AI Agents Before the Consumer Data Right Lets Them Act](https://theaicommand.com/grc/ai-agents-cdr-action-initiation-governance#faq-4)

### What counts as reasonable steps for an accountable person managing AI under FAR?

Section 28 requires accountable persons to take reasonable steps to discharge their accountability. For AI, four categories are likely to be tested: awareness of the AI tools in their portfolio, adequate governance design, monitoring and escalation through existing risk channels, and a response capability covering AI-specific failure modes.

Source: [FAR and AI: How Accountability Maps to Tooling Decisions](https://theaicommand.com/grc/far-responsibility-and-ai-tooling#faq-2)

### What CPS 230 documentation gaps surface most often with AI tooling?

Three recur. First, no documented threshold at which an AI tool becomes a material service provider. Second, a change cadence mismatch, since AI tools update frequently while review frequency is often annual. Third, human-in-the-loop claims that are nominal, lacking evidence of review time, information available, and how often outputs are modified or rejected.

Source: [CPS 230 and AI: A Practical Operational Resilience Playbook](https://theaicommand.com/grc/cps-230-and-ai-operational-resilience-playbook#faq-3)

### What did APRA announce on 16 June 2026?

APRA released an updated draft of CPS 510 Governance for a further round of consultation. It consolidates five existing governance, fit-and-proper and conflicts standards into a single cross-industry standard, sets consistent governance minimums, and removes routine fit-and-proper reporting that had become duplicative under the Financial Accountability Regime, covering around 6,000 individuals.

Source: [Freed Board Bandwidth Is for AI Oversight](https://theaicommand.com/grc/cps-510-frees-board-time-for-ai-oversight#faq-1)

### What did ASIC and APRA change about FAR on 16 June 2026?

They proposed trimming three reporting obligations under the Financial Accountability Regime: removing the prescribed list of key functions from the FAR register, no longer requiring information about accountable persons' direct reports in accountability maps, and raising the materiality threshold at which entities must notify the regulators of changes to accountability arrangements. The regulators will consult on the changes and aim to implement them by the end of 2026.

Source: [FAR Eased Up. Your AI Map Still Holds](https://theaicommand.com/grc/far-eased-up-your-ai-map-still-holds#faq-1)

### What did ASIC's May 2026 cyber uplift warning say?

On 8 May 2026, ASIC urged organisations to urgently enhance cyber resilience, linking the warning to frontier AI intensifying the threat landscape. It emphasised that cyber resilience is not merely an IT issue but a core licensing obligation that boards and risk committees must actively oversee and integrate into existing governance.

Source: [AI Cyber Risk Is Now a Board Governance Issue](https://theaicommand.com/grc/ai-cyber-risk-board-governance#faq-2)

### What did AUSTRAC change in the AML program starter kits on 19 June 2026?

AUSTRAC made targeted updates to the program starter kit documents, refreshing the risk assessment with new information on artificial intelligence, decentralised finance and offshore virtual asset providers. It also clarified that indicators of unusual or criminal behaviour apply during initial customer onboarding, where synthetic identities most often slip through.

Source: [AUSTRAC Just Put AI Risk Into Your AML Program Documents](https://theaicommand.com/grc/austrac-ai-risk-in-aml-program-documents#faq-1)

### What did the 15 July 2026 announcement actually contain?

An office effective that day, a commitment to introduce a set of Australian Standards for AI building on the Data Centre Expectations, a first set of concrete rules aimed at large data centres covering power supply, connection costs, grid support and water efficiency, a sequence of National Cabinet consideration in August with legislation expected early next year, a commitment on Australian creative works, and a promise to outline whole-of-government AI consumer safety priorities in coming weeks.

Source: [A New AI Office Is Not a New AI Obligation](https://theaicommand.com/grc/office-of-ai-not-a-new-obligation#faq-2)

### What did the Australian Government make mandatory for AI use?

Under version 2.0 of the DTA's Policy for the responsible use of AI in government, effective 15 December 2025, the first new mandatory requirement took effect on 15 June 2026: a strategic position on AI adoption, communicated to staff. Mandatory staff training and AI use-case impact assessments phase in by 15 December 2026. Every in-scope AI use case must also have a named accountable owner recorded in an internal register, with the register in place within 12 months of the policy taking effect.

Source: [Canberra's AI Register Mandate Is a Preview](https://theaicommand.com/grc/canberra-ai-register-mandate-is-a-preview#faq-1)

### What did the Privacy Commissioner actually decide in June 2026?

In two determinations dated 11 June 2026 and published on 24 June 2026, the Privacy Commissioner found that Medmate Australia and Monash IVF interfered with the privacy of individuals whose sensitive information was collected through third-party tracking pixels on their websites. The Commissioner's register records the Monash IVF findings against Australian Privacy Principles 3.3, 5.1, 5.2 and 7.1. The media release states the decision establishes that tracking website visitors on health-related sites and then targeting them with social media advertising amounts to a collection of sensitive information for which consent must be obtained.

Source: [Your Website AI Assistant Is Someone Else's Code](https://theaicommand.com/grc/website-ai-assistant-third-party-code#faq-1)

### What does 'reasonable steps' mean when scams are AI-generated?

Reasonable steps is a moving standard, judged against the risk, the available technology and the cost. As AI-assisted detection becomes standard and affordable, the floor of what counts as reasonable rises. Reactive moderation after a customer reports a scam will increasingly read as below the standard.

Source: [The Scams Prevention Framework Meets AI: What 'Reasonable Steps' Now Demands](https://theaicommand.com/grc/scams-prevention-framework-ai-reasonable-steps#faq-2)

### What does a CPS 234 AI vendor due diligence framework cover?

Eight areas: information asset identification and classification, vendor architecture and chain mapping, control commitments, data handling commitments, update and change management, incident notification and response, testing and assurance, and exit planning. Each area produces a documented artefact that becomes part of the vendor file.

Source: [CPS 234 and AI Vendors: A Due Diligence Framework](https://theaicommand.com/grc/cps-234-third-party-ai-vendor-due-diligence#faq-2)

### What does an AI governance professional do?

The work varies, but usually covers AI inventory, risk classification, control design, regulatory mapping, third-party oversight, monitoring, incident governance and evidence for executive or audit review. Some roles own the framework. Others provide independent challenge or technical assurance.

Source: [The 2026 AI Governance Talent Market: Assurance Skills Move to the Core](https://theaicommand.com/grc/2026-ai-governance-talent-market-assurance-skills#faq-1)

### What does APRA's April 2026 AI letter mean for board AI literacy?

APRA's 30 April 2026 letter signals that AI literacy is now connected to risk appetite, control assurance, third-party oversight, resilience and accountability. It expects boards to hold enough literacy to understand AI opportunities, limitations and risks, including risks arising through third-party services and cyber pathways, and to interrogate management's control story.

Source: [Board AI Literacy Is Now a Control Expectation, Not a Training Nice-to-Have](https://theaicommand.com/grc/board-ai-literacy-as-control-expectation#faq-1)

### What does ASIC RG 271 require for handling complaints?

RG 271 is ASIC's internal dispute resolution standard for financial firms. It sets an enforceable maximum of 30 calendar days to give a standard complaint an IDR response, defines a complaint broadly using the AS/NZS 10002:2014 wording, requires IDR responses to explain the reasons for the outcome, and requires firms to identify, escalate and act on systemic issues. Firms also report IDR data to ASIC.

Source: [AI in Complaints Handling: What RG 271 Reserves for a Person](https://theaicommand.com/grc/ai-complaints-handling-rg-271#faq-1)

### What does ASIC's REP 835 actually say about AI in trading?

REP 835 is a landscape review ASIC commissioned from the Digital Finance Cooperative Research Centre, published on 30 June 2026. Its fourth stream deals with AI in trading. It states that agentic AI, increasingly autonomous trading systems and trading systems with limited explainability are hard to assess through traditional notions of trader intent or fixed algorithm design, that this places pressure on ASIC's surveillance capability, and that such systems raise legal and enforcement questions about how to define and prove misconduct distinguished by intent, such as market manipulation.

Source: [Agentic Trading and the Purpose Problem](https://theaicommand.com/grc/agentic-trading-and-the-purpose-problem#faq-1)

### What does the CPS 230 1 July 2026 deadline actually require?

For contracts that already existed when CPS 230 commenced, APRA gave entities until the earlier of the next renewal date or 1 July 2026 to bring the agreement into line with the standard's service provider requirements. Those cover service levels, orderly exit, sub-contracting and fourth-party arrangements, APRA access and inspection, change notification and ongoing monitoring.

Source: [CPS 230's 1 July Deadline Just Caught Up With Your AI Vendors](https://theaicommand.com/grc/cps-230-ai-vendor-contract-deadline#faq-1)

### What does the new APP 1.7 and 1.8 automated decision-making obligation actually require?

It is a transparency rule, not an explainability mandate. From 10 December 2026, an entity must describe in its privacy policy the kinds of personal information its automated systems use and the kinds of decisions made or substantially shaped by those systems. You do not have to explain individual model logic or why one person was declined.

Source: [Automated Decisions Now Belong in Your Privacy Policy](https://theaicommand.com/grc/adm-transparency-privacy-policy-2026#faq-1)

### What fields should an AI use case register include?

Each entry should capture use case name, business unit or owner, AI type, purpose, status, risk category, human oversight, controls or mitigations, impact assessment, privacy considerations, vendor details, review frequency, last review date, and notes or issues. This detail lets boards assess risk, controls and outcomes and supports meaningful oversight.

Source: [Build an AI Use Case Register That Boards Can Actually Use](https://theaicommand.com/grc/ai-use-case-register-board-evidence#faq-1)

### What governance controls should AML/CTF teams apply to LLM use?

Map every LLM workflow to a specific AML/CTF Rules obligation, default to prompt-level de-identification, keep humans accountable for each regulated act, back-test triage decisions monthly, verify every regulatory citation in generated content, capture which model version made each decision, and cover LLM use cases in the independent program review.

Source: [AML/CTF and Large Language Models: A Compliance View](https://theaicommand.com/grc/amlctf-and-large-language-models#faq-3)

### What immediate actions should compliance teams take under ASIC's AI posture?

Three actions: review AI-driven customer interactions against the personal advice test, refreshing structure where the line is blurred; refresh customer disclosure documents for AI-relevant content against the substance test; and build an internal capability to explain AI-influenced decisions within RG 271 dispute resolution timeframes.

Source: [ASIC's AI Supervisory Posture, Decoded](https://theaicommand.com/grc/asic-april-2026-ai-statement-decoded#faq-3)

### What is action initiation under the Consumer Data Right?

Action initiation, sometimes called write access, lets a consumer authorise an accredited provider to initiate actions on their behalf, such as making payments, switching providers, opening or closing accounts and submitting product applications. It became law through the Treasury Laws Amendment (Consumer Data Right) Act 2024, but individual action types must still be designated by the government before anyone can use them.

Source: [Governing AI Agents Before the Consumer Data Right Lets Them Act](https://theaicommand.com/grc/ai-agents-cdr-action-initiation-governance#faq-1)

### What is AI-washing?

AI-washing is overstating the role, sophistication or benefit of artificial intelligence in a product or service. In financial services it looks like marketing that calls a tool AI-powered when it applies simple rules, or that promises tailored AI advice when the tool considers only a couple of data points. It is a species of misleading conduct, and RG 234's update flags disclosing the real capability and limitations of AI-enabled customer tools as part of advertising them accurately.

Source: [AI Wrote the Ad. ASIC Still Holds You to It.](https://theaicommand.com/grc/ai-washing-and-ai-generated-advertising#faq-2)

### What is an offline GRC controls console and what should it be used for?

It is a single-file HTML tool that runs locally to structure evidence, log exceptions, capture reviewer sign-off and produce a clean review pack without sending data anywhere. Use it for one narrow control test as a working layer, never to replace Archer, ServiceNow or any approved system of record.

Source: [Build an Offline GRC Controls Console Without Creating Shadow IT](https://theaicommand.com/grc/offline-grc-controls-testing-console#faq-1)

### What is APRA's model risk thematic review?

A thematic review is APRA's deep-dive supervisory tool. It is not enforcement or consultation, but a structured study of how a sector manages a specific risk. Findings typically feed into supervisory letters, updated guidance, or new prudential standards. APRA ran similar reviews on cyber maturity and operational resilience.

Source: [APRA's Model Risk Thematic Review: What to Expect](https://theaicommand.com/grc/apra-model-risk-thematic-review-preview#faq-1)

### What is ASIC's supervisory posture on AI in financial services?

ASIC's posture is that AI is a use case to which existing law applies. The presence of AI does not change a licensee's conduct, disclosure, design and distribution, or dispute resolution obligations. It changes where the licensee needs to look to evidence compliance, not what the obligations are.

Source: [ASIC's AI Supervisory Posture, Decoded](https://theaicommand.com/grc/asic-april-2026-ai-statement-decoded#faq-1)

### What is the Australian AI Safety Institute?

The Australian AI Safety Institute is an advisory body launched in early 2026 with about 29.9 million dollars in funding under the National AI Plan. It monitors, tests and shares information on emerging AI capabilities, risks and harms. It has no enforcement powers. For GRC its value is as an early-warning signal for where targeted regulation may eventually land.

Source: [Australia Will Not Pass an AI Act. You Are Still Regulated.](https://theaicommand.com/grc/australia-no-ai-act-existing-law-compliance#faq-3)

### What is the correct order of work for a newly regulated firm?

Build the ML/TF risk assessment first, with a person doing the thinking and AI structuring and drafting. Let that assessment drive the program. Use AI to scaffold policies, then edit to what is true. Record why calibration settings landed where they did, and keep that reasoning as a defensible governance record.

Source: [AML Tranche 2: What AI Can and Cannot Do for Your New Program](https://theaicommand.com/grc/aml-tranche-2-reforms-and-ai#faq-5)

### What is the difference between an AI guardrail and a control?

A guardrail describes what good practice looks like, while a control describes how an organisation makes that true and produces evidence that can be tested. A principle such as humans remaining in the loop is not assurance evidence. A workflow plus sampled records showing a reviewer checked output before a decision is finalised is evidence.

Source: [From Voluntary AI Guardrails to Audit Evidence](https://theaicommand.com/grc/voluntary-ai-guardrails-to-audit-evidence#faq-1)

### What is the difference between DDO and personal advice for AI personalisation?

DDO is conceptually about classes of consumer. The issuer defines a target market and the distribution chain operates within it. Personal advice concerns a specific person, triggered when a recommendation considers individual circumstances in a way a reasonable person expects to be taken into account, attracting Chapter 7 licensing and best-interest obligations.

Source: [DDO and AI-Driven Personalisation: Where the Boundary Sits](https://theaicommand.com/grc/ddo-and-ai-driven-personalisation#faq-1)

### What is the first thing a compliance function should do about this?

Build an inventory of every third-party component running on customer-facing pages, including analytics, advertising, session recording, support widgets and AI assistants. For each one, record who supplies it, what it receives, where that goes, whether the categories can include sensitive information, and which notice or consent covers it. Most organisations discover components nobody currently owns.

Source: [Your Website AI Assistant Is Someone Else's Code](https://theaicommand.com/grc/website-ai-assistant-third-party-code#faq-4)

### What is the minimum an in-scope AI use-case register must record?

The DTA's Standard for accountability sets a thirteen-field minimum, including a description of what the AI does, its business objective and, where relevant, the underpinning product name; the AI technology type, being generative AI, machine learning, natural language processing or computer vision; the lifecycle stage; the accountable use case owner's details; and inherent and residual risk ratings from the impact assessment. High-risk use cases also record review dates.

Source: [Canberra's AI Register Mandate Is a Preview](https://theaicommand.com/grc/canberra-ai-register-mandate-is-a-preview#faq-2)

### What is the new triennial board performance review?

Draft CPS 510 strengthens annual board, committee and director performance assessments and requires significant financial institutions to commission an independent external assessment of board performance at least every three years. That assessment is a natural place to test whether the board can genuinely challenge AI risk.

Source: [Freed Board Bandwidth Is for AI Oversight](https://theaicommand.com/grc/cps-510-frees-board-time-for-ai-oversight#faq-3)

### What is the practical control for AI in a super fund?

An AI-decision register. List every current and proposed AI use case, and classify each one as either supporting a trustee discretion or making or dictating it. Put a hard human-involvement gate on anything in the second group, require a documented best financial interests business case for the spend, and keep an accountable owner for each use case under the accountability regime. That register is the evidence APRA and your board will ask for.

Source: [Super Trustees, AI and the Discretion You Cannot Delegate](https://theaicommand.com/grc/super-trustees-ai-discretion-you-cannot-delegate#faq-4)

### What is the practical task list for compliance teams after this update?

Check which starter kit version your documents were built from and whether it predates 19 June 2026. Update the risk assessment for AI typologies, revisit onboarding controls, document any AI used in monitoring against AUSTRAC's model, and keep the reasoning and version history as a defensible record.

Source: [AUSTRAC Just Put AI Risk Into Your AML Program Documents](https://theaicommand.com/grc/austrac-ai-risk-in-aml-program-documents#faq-5)

### What is the risk of reading this relief as less AI documentation?

Under-documentation exactly where supervisors look. Lighter filing does not reduce the need to explain an adverse automated decision or show who owns an AI tool in a regulated process. If a register decays because the map now needs fewer updates, the entity loses the evidence that made an accountable person's position defensible in the first place.

Source: [FAR Eased Up. Your AI Map Still Holds](https://theaicommand.com/grc/far-eased-up-your-ai-map-still-holds#faq-5)

### What is the Scams Prevention Framework and when does it bite?

The SPF is the Commonwealth regime created by the Scams Prevention Framework Act 2025, which amended the Competition and Consumer Act 2010 to make banks, telcos and digital platforms responsible for preventing, detecting and disrupting scams. Treasury released the exposure-draft codes and rules on 28 May 2026, consultation closed on 25 June 2026, and substantive sector obligations are proposed from 31 March 2027.

Source: [The Scams Prevention Framework Meets AI: What 'Reasonable Steps' Now Demands](https://theaicommand.com/grc/scams-prevention-framework-ai-reasonable-steps#faq-1)

### What law sits behind RG 234?

RG 234 is guidance on how to comply with the misleading-conduct prohibitions, principally section 12DB of the ASIC Act, which prohibits false or misleading representations about financial services, and section 1041H of the Corporations Act, which prohibits misleading or deceptive conduct in relation to financial products. RG 234 does not create new law. It sets ASIC's expectations for how advertising, now including AI-generated advertising, meets that existing law.

Source: [AI Wrote the Ad. ASIC Still Holds You to It.](https://theaicommand.com/grc/ai-washing-and-ai-generated-advertising#faq-4)

### What makes a register entry useful rather than poor?

A useful entry provides clear accountability, detailed controls, documented human oversight, evidence of impact assessment and privacy considerations, and an appropriate review rhythm with an escalation process. A poor entry lacks control detail, has no impact assessment, reviews too infrequently for the risk level, and cannot support meaningful board oversight.

Source: [Build an AI Use Case Register That Boards Can Actually Use](https://theaicommand.com/grc/ai-use-case-register-board-evidence#faq-4)

### What parts of AML compliance must a person keep, not AI?

Three lines stay with people: the formation of suspicion and decision to report, the calibration of risk appetite, and accountability, which rests on the reporting entity, its governing body and AML compliance officer. There is also a confidentiality duty: do not feed privileged client detail into a general consumer AI tool.

Source: [AML Tranche 2: What AI Can and Cannot Do for Your New Program](https://theaicommand.com/grc/aml-tranche-2-reforms-and-ai#faq-4)

### What practical actions should GRC teams take for AI personalisation under DDO?

Map every AI-driven customer touchpoint against the DDO and personal advice framework, tagging each as general information, general advice, or personal advice. Test that operational behaviour matches the tag through monthly sampling. Govern recommendation logic, not just outputs. Set a clear policy on generative AI customer interactions and apply CPS 234-style vendor due diligence.

Source: [DDO and AI-Driven Personalisation: Where the Boundary Sits](https://theaicommand.com/grc/ddo-and-ai-driven-personalisation#faq-5)

### What readiness work should a GRC team do before December 2026?

Four moves. Inventory every system that makes or substantially shapes a decision about a person, including older and vendor systems. Classify each by whether it significantly affects rights. Draft the disclosure under the three APP 1.8 categories. Evidence it with the inventory, impact assessments and policy version history. The inventory is the long pole, not the drafting.

Source: [Automated Decisions Now Belong in Your Privacy Policy](https://theaicommand.com/grc/adm-transparency-privacy-policy-2026#faq-4)

### What reporting cadence should boards use for AI cyber risk?

The article recommends the board review cyber risk posture, incident summaries and strategic decisions quarterly; the risk committee review control effectiveness, risk trends and third-party risks monthly or bi-monthly; and IT security and AI ops review operational incidents, patching status and threat intelligence weekly or fortnightly to ensure timely escalation.

Source: [AI Cyber Risk Is Now a Board Governance Issue](https://theaicommand.com/grc/ai-cyber-risk-board-governance#faq-5)

### What should a GRC team do before 1 July 2026?

Four passes over your AI estate. Find the AI inside your material arrangements, starting from the service provider register. Test each contract against the CPS 230 service provider requirements. Build and actually exercise a fallback where AI supports a critical operation. Then manage and document the concentration risk.

Source: [CPS 230's 1 July Deadline Just Caught Up With Your AI Vendors](https://theaicommand.com/grc/cps-230-ai-vendor-contract-deadline#faq-4)

### What should a GRC team do before deploying AI in IDR?

Map every RG 271 obligation to what AI may touch and what stays human, keep a person accountable for the outcome and the reasons, log what the AI drafted versus what the person decided, govern the tool as a system that handles sensitive data, and confirm the deployment against the current RG 271 and Instrument 2020/98 before go-live.

Source: [AI in Complaints Handling: What RG 271 Reserves for a Person](https://theaicommand.com/grc/ai-complaints-handling-rg-271#faq-5)

### What should a GRC team do before the framework applies in 2027?

Confirm scope, build a principle-to-control map across the six principles with named owners and evidence, inventory every AI model in the detection stack, stand up the dispute and reporting pipelines, govern the detection AI as a high-consequence system, and keep the board across the govern principle.

Source: [The Scams Prevention Framework Meets AI: What 'Reasonable Steps' Now Demands](https://theaicommand.com/grc/scams-prevention-framework-ai-reasonable-steps#faq-5)

### What should AI vendor due diligence cover beyond security questionnaires?

Due diligence should cover data use, model changes, logging, incident notification, subcontractors, service availability, exit arrangements and the ability to explain or test outputs. For critical operations, resilience testing should consider what happens if the provider changes the model, the service fails, logs are unavailable or data must be removed quickly, with fallback processes and exit plans documented.

Source: [From Voluntary AI Guardrails to Audit Evidence](https://theaicommand.com/grc/voluntary-ai-guardrails-to-audit-evidence#faq-4)

### What should an AI incident evidence pack contain?

It should capture the incident timeline, AI system involved, business process, stakeholders affected, data categories, prompts and outputs, model or vendor details, access permissions, human review steps, containment, root cause, control failures, customer or employee impact, regulatory assessment and remediation. It should also record confirmed facts, working assumptions and unresolved questions.

Source: [AI Incident Response Needs an Evidence Pack, Not Just a Playbook](https://theaicommand.com/grc/ai-incident-response-evidence-pack#faq-2)

### What should an audit workpaper record when AI is used?

Standard 14.6 documentation must let another auditor reach the same conclusions. Record five things: the tool and version, the prompt given, the raw output before editing, the corroboration performed against source records and by whom, and the corrections made. Keep it proportionate: log only where output influenced an audit judgement.

Source: [AI in Internal Audit: What Still Counts as Evidence](https://theaicommand.com/grc/ai-in-internal-audit#faq-3)

### What should go on the regulatory watch list after a machinery announcement?

Four entries, each with a named owner, an observable trigger and a review date: National Cabinet consideration in August 2026, the Australian Standards for AI text itself, the legislation flagged for early next year, and the whole-of-government AI consumer safety priorities promised in coming weeks. Record against each that there is no current obligation, no control change and no spend, so the assessment is visible rather than assumed.

Source: [A New AI Office Is Not a New AI Obligation](https://theaicommand.com/grc/office-of-ai-not-a-new-obligation#faq-4)

### What should GRC teams do about CPS 230 and AI in the next ninety days?

Four actions. Re-run critical operations mapping with AI treated as a first-class component. Inventory the AI stack against material service provider criteria. Define quality tolerance levels alongside availability ones. Map each material tool's model and infrastructure chain, documenting the contracting party, model provider, inference infrastructure, and data residency.

Source: [CPS 230 and AI: A Practical Operational Resilience Playbook](https://theaicommand.com/grc/cps-230-and-ai-operational-resilience-playbook#faq-4)

### What should GRC teams do given there is no AI Act?

Build a map from each AI use case to the existing obligations it touches, adopt the Voluntary AI Safety Standard as a practical framework, watch the AI Safety Institute and the coming Privacy Act reforms as the direction of travel, and name an accountable owner for each material AI system. The work is compliance mapping and governance, not waiting for a law that is not coming.

Source: [Australia Will Not Pass an AI Act. You Are Still Regulated.](https://theaicommand.com/grc/australia-no-ai-act-existing-law-compliance#faq-4)

### What should GRC teams do now to prepare?

Four actions are sensible regardless of timing: run a model risk inventory completeness check covering AI tools with a documented threshold, map validation methodology by model type, document human-in-the-loop adequacy for material AI outputs, and build third-party AI transparency into procurement and ongoing oversight.

Source: [APRA's Model Risk Thematic Review: What to Expect](https://theaicommand.com/grc/apra-model-risk-thematic-review-preview#faq-5)

### What should trigger an automatic pause of a pricing agent?

Examples include unexplained convergence with competitors, abnormal retaliation against discounting, use of unapproved data sources, missing logs, a material vendor change or prices outside approved bounds. Triggers should be tailored to the market and reviewed by competition specialists, and the pause owner must be named, including outside business hours.

Source: [Your Pricing Agent Is Still Your Competition Risk](https://theaicommand.com/grc/ai-pricing-agent-competition-risk#faq-4)

### When does an AI customer service assistant cross into personal advice?

If a generative AI assistant considers a customer's circumstances, such as account holdings, balance, or transaction patterns, and is presented in a way the customer reasonably expects to take those circumstances into account, it can be personal advice regardless of any disclaimer. Knowing the customer's holdings creates a strong expectation of personalisation.

Source: [DDO and AI-Driven Personalisation: Where the Boundary Sits](https://theaicommand.com/grc/ddo-and-ai-driven-personalisation#faq-2)

### When does CPS 510 commence?

Consultation on the draft is open until 28 August 2026. APRA expects to finalise CPS 510 and a unified practice guide, CPG 510, by the end of 2026, with the new requirements expected to take effect from early 2028.

Source: [Freed Board Bandwidth Is for AI Oversight](https://theaicommand.com/grc/cps-510-frees-board-time-for-ai-oversight#faq-5)

### When does the CDR expand beyond banking?

The read side is widening now. Under the CDR rules, product data sharing obligations apply to non-bank lenders from 13 July 2026, with consumer data sharing from 9 November 2026 for initial providers and 10 May 2027 for large providers. Every new accredited connection is a potential future action surface, which makes the expansion a useful dress rehearsal for the action layer.

Source: [Governing AI Agents Before the Consumer Data Right Lets Them Act](https://theaicommand.com/grc/ai-agents-cdr-action-initiation-governance#faq-5)

### When is the APRA model risk review expected to land?

Multiple signals across 2025 and early 2026 indicate it is likely in the second half of 2026. APRA has not published a terms of reference, so this is a planning input rather than a forecast. The work practitioners should do does not depend on the exact timing.

Source: [APRA's Model Risk Thematic Review: What to Expect](https://theaicommand.com/grc/apra-model-risk-thematic-review-preview#faq-2)

### Where can AI genuinely help a newly regulated firm build its AML program?

AI fits four jobs: drafting the program scaffolding, structuring the ML/TF risk assessment by interviewing the practitioner toward an answer, tuning customer due diligence and monitoring for firms with existing data, and drafting suspicious matter reports once a suspicion is formed. Point it at administrative load, not judgement.

Source: [AML Tranche 2: What AI Can and Cannot Do for Your New Program](https://theaicommand.com/grc/aml-tranche-2-reforms-and-ai#faq-3)

### Where can AI genuinely help in complaints handling?

AI can acknowledge and triage incoming complaints, summarise a long file, draft a first-pass plain-English response for review, keep the language consistent and readable, and analyse complaint data sets to surface possible systemic issues for a human to investigate. Each of these is admin or pattern-spotting that a person still signs off.

Source: [AI in Complaints Handling: What RG 271 Reserves for a Person](https://theaicommand.com/grc/ai-complaints-handling-rg-271#faq-3)

### Where will supervisory pressure focus in the review?

Six areas are likely to see sharp questions: model inventory completeness, validation methodology fit for AI, human-in-the-loop design quality, third-party AI provider oversight, bias and consumer outcome testing, and documentation of model purpose to detect scope creep beyond a model's validated use.

Source: [APRA's Model Risk Thematic Review: What to Expect](https://theaicommand.com/grc/apra-model-risk-thematic-review-preview#faq-4)

### Which AI assurance skills are hardest to hire?

The difficult combination is regulatory interpretation, technical-system literacy, test design, evidence judgement and executive communication. Organisations often find pieces of this profile in different people rather than one complete candidate.

Source: [The 2026 AI Governance Talent Market: Assurance Skills Move to the Core](https://theaicommand.com/grc/2026-ai-governance-talent-market-assurance-skills#faq-3)

### Which AI obligations actually bind an Australian business right now?

The ones that already did. The Privacy Act, including the automated decision-making transparency obligation in APP 1.7 commencing 10 December 2026, the misleading and deceptive conduct prohibitions in the ASIC Act, the Australian Consumer Law, APRA prudential standards such as CPS 230 and CPS 234 for regulated entities, and the AML/CTF regime. The 15 July announcement does not add to or subtract from that list.

Source: [A New AI Office Is Not a New AI Obligation](https://theaicommand.com/grc/office-of-ai-not-a-new-obligation#faq-3)

### Which AI systems will the review likely examine?

Three categories: traditional models augmented with AI components, AI-native decision support systems such as generative tools drafting credit memos or compliance assessments, and autonomous or near-autonomous systems like automated AML triage and underwriting. Many of these are operationally embedded but sit outside the formal model inventory.

Source: [APRA's Model Risk Thematic Review: What to Expect](https://theaicommand.com/grc/apra-model-risk-thematic-review-preview#faq-3)

### Which AI-specific failure modes should I assess in vendor due diligence?

Three the article highlights: prompt injection, where inputs cause unintended behaviour or data exposure; data leakage between customers in multi-tenant inference infrastructure; and training data contamination, where customer data used for training may surface in responses to others. Standard questionnaires omit these, so add them deliberately.

Source: [CPS 234 and AI Vendors: A Due Diligence Framework](https://theaicommand.com/grc/cps-234-third-party-ai-vendor-due-diligence#faq-3)

### Which five standards does draft CPS 510 consolidate?

The reforms bring together CPS 510 and SPS 510 Governance, CPS 520 and SPS 520 Fit and Proper, and SPS 521 Conflicts of Interest into one cross-industry CPS 510, applying consistent governance minimums across banks, insurers and superannuation trustees.

Source: [Freed Board Bandwidth Is for AI Oversight](https://theaicommand.com/grc/cps-510-frees-board-time-for-ai-oversight#faq-2)

### Which prescribed responsibilities can AI tooling decisions fall under?

AI tooling can sit inside operational risk management, regulatory compliance management, customer outcomes management, and information system integrity. For example, AI in claims or underwriting touches operational risk, AI in AML monitoring touches compliance, and AI in personalisation or automated decisioning touches customer outcomes.

Source: [FAR and AI: How Accountability Maps to Tooling Decisions](https://theaicommand.com/grc/far-responsibility-and-ai-tooling#faq-4)

### Which provision catches an AI that learns to place and cancel orders?

Orders that never become transactions sit awkwardly with a prohibition framed around creating an artificial price for entering a transaction. In his paper published by the Supreme Court of NSW, Justice Ashley Black records that DPP (Cth) v JM confirms a significant degree of overlap between sections 1041A and 1041B, and that other conduct with a price effect, including the placing of orders that did not give rise to transactions, would typically fall within the scope of section 1041B. That is the provision an AI-learned order-and-cancel pattern most naturally engages.

Source: [Agentic Trading and the Purpose Problem](https://theaicommand.com/grc/agentic-trading-and-the-purpose-problem#faq-3)

### Who becomes AML regulated under Tranche 2 from 1 July 2026?

From 1 July 2026, around 80,000 to 90,000 businesses move inside the perimeter: lawyers, accountants, conveyancers, real estate agents and developers, and dealers in precious metals, stones and products. These professions handle the transactions launderers favour and had no prior reporting obligation, pushing the total regulated count toward 100,000.

Source: [AML Tranche 2: What AI Can and Cannot Do for Your New Program](https://theaicommand.com/grc/aml-tranche-2-reforms-and-ai#faq-1)

### Who is accountable when an AI tool is procured centrally but used across multiple business units?

Each AI tool should have a clearly designated accountable person, even with multiple users. The emerging pattern designates the person responsible for the most material use as lead, with secondary business units holding supporting accountability for their specific use cases. This only satisfies FAR if it is documented.

Source: [FAR and AI: How Accountability Maps to Tooling Decisions](https://theaicommand.com/grc/far-responsibility-and-ai-tooling#faq-3)

### Who is affected by the FAR reporting changes?

ASIC and APRA estimated the reforms would reduce reporting for all accountable entities and around 4,500 accountable persons. A separate change streamlines responsible manager competence-evidence requirements for roughly 2,000 current AFS licensees from October 2026. The proposals sit inside the Government's Better Regulation reforms announced in the 2026-27 Budget.

Source: [FAR Eased Up. Your AI Map Still Holds](https://theaicommand.com/grc/far-eased-up-your-ai-map-still-holds#faq-4)

### Who owns the pricing-agent risk?

The commercial owner owns the outcome, supported by pricing, legal, competition, data, technology and risk specialists. A vendor may carry contractual obligations, but outsourcing the software does not outsource the organisation's accountability under the Competition and Consumer Act.

Source: [Your Pricing Agent Is Still Your Competition Risk](https://theaicommand.com/grc/ai-pricing-agent-competition-risk#faq-5)

### Who regulates AI agents acting under the Consumer Data Right?

Two regulators share the field. The ACCC accredits CDR data recipients and monitors compliance with the CDR rules and standards, while ASIC governs the conduct and licensing of the financial services activity wrapped around them. An AI agent initiating a regulated action touches both, so control evidence needs to satisfy both lenses. ASIC has also flagged agentic AI as a key 2026 supervisory concern.

Source: [Governing AI Agents Before the Consumer Data Right Lets Them Act](https://theaicommand.com/grc/ai-agents-cdr-action-initiation-governance#faq-3)

### Who regulates the SPF and what are the penalties?

Three regulators share the work: the ACCC is the general regulator and covers digital platforms, ASIC regulates the banking code, and ACMA regulates the telco code, with AFCA as the external dispute resolution scheme. The most serious breaches attract civil penalties up to around 50 million dollars per contravention for a body corporate, alongside a path to consumer compensation.

Source: [The Scams Prevention Framework Meets AI: What 'Reasonable Steps' Now Demands](https://theaicommand.com/grc/scams-prevention-framework-ai-reasonable-steps#faq-3)

### Who should own an AI use case register?

Each use case needs a named senior manager accountable for its performance, risk management and compliance, with access to risk, compliance, IT and privacy teams. The AI governance or risk committee owns the overall register, ensuring completeness and quality and providing regular reports on key risks, changes and incidents.

Source: [Build an AI Use Case Register That Boards Can Actually Use](https://theaicommand.com/grc/ai-use-case-register-board-evidence#faq-3)

### Why do AI incidents need a different incident response approach?

AI failure modes do not always look like traditional outages. A model can produce a harmful recommendation while the platform stays available, a chatbot can expose sensitive data without a breach, or an agent can act on a malicious prompt. Standard time, owner and remediation fields cannot cleanly capture these AI-specific failures.

Source: [AI Incident Response Needs an Evidence Pack, Not Just a Playbook](https://theaicommand.com/grc/ai-incident-response-evidence-pack#faq-1)

### Why does a tracking pixel determination matter to an AI assistant?

Because the architecture is identical. Both are code supplied by another party, embedded in a page you control, which receives what your users do there and sends it somewhere you do not operate. The AI assistant is the higher risk of the two, because a pixel observes clicks while an assistant receives whatever a person chooses to type, including health, financial hardship and identity details you never asked for.

Source: [Your Website AI Assistant Is Someone Else's Code](https://theaicommand.com/grc/website-ai-assistant-third-party-code#faq-2)

### Why does third-party AI most test board literacy?

Many organisations buy software, embed vendor copilots and connect enterprise data to external platforms rather than building models. APRA's letter points to third-party dependencies for board attention. AI due diligence needs questions on model behaviour, data retention, explainability, subcontractors, monitoring, incident notification and exit, beyond traditional security and contractual checks.

Source: [Board AI Literacy Is Now a Control Expectation, Not a Training Nice-to-Have](https://theaicommand.com/grc/board-ai-literacy-as-control-expectation#faq-3)

### Why does this obligation hit Australian financial services hardest?

Three reasons. Credit, insurance and banking decisions affect rights and interests by nature, so the significant-effect threshold is cleared routinely. The systems are layered and old, mixing rules engines, scorecards, vendor services and machine learning across teams. The OAIC has new infringement and compliance notice powers and has flagged privacy policies in high-risk sectors as a focus.

Source: [Automated Decisions Now Belong in Your Privacy Policy](https://theaicommand.com/grc/adm-transparency-privacy-policy-2026#faq-3)

### Why does using AI to detect scams create a second obligation?

The moment an entity deploys AI to meet the prevent, detect and disrupt principles, it puts an AI system into a consumer-facing, high-consequence decision. Too aggressive and it freezes legitimate customers out of their money; too permissive and it misses the scam. That model needs validation, monitoring, false-positive handling, human review and privacy and explainability sign-off.

Source: [The Scams Prevention Framework Meets AI: What 'Reasonable Steps' Now Demands](https://theaicommand.com/grc/scams-prevention-framework-ai-reasonable-steps#faq-4)

### Why is AI cyber risk a board responsibility and not just an IT issue?

ASIC and APRA make clear that cyber resilience is a core licensing obligation boards must actively oversee. AI accelerates attack speed and complexity beyond traditional IT controls, incidents threaten business continuity and reputation, and boards are ultimately accountable for licensing obligations and setting the organisation's risk appetite.

Source: [AI Cyber Risk Is Now a Board Governance Issue](https://theaicommand.com/grc/ai-cyber-risk-board-governance#faq-1)

### Why is AI the part of CPS 230 most likely to be tested first?

On 30 April 2026 APRA published a letter to industry on AI that found entities heavily dependent on single AI providers, few tested exit or substitution strategies, and opaque upstream dependencies. Those are the exact things CPS 230 contracts must address, so the deadline and the supervisory focus have converged on the same clauses.

Source: [CPS 230's 1 July Deadline Just Caught Up With Your AI Vendors](https://theaicommand.com/grc/cps-230-ai-vendor-contract-deadline#faq-3)

### Why is board AI literacy treated as a control rather than awareness training?

Because boards approve strategy, set risk appetite and oversee material risk, they need enough literacy to ask whether AI systems are governed with the same discipline as other material technology, data, outsourcing and operational risks. That is a higher standard than watching a chatbot demonstration or attending a one-hour awareness session.

Source: [Board AI Literacy Is Now a Control Expectation, Not a Training Nice-to-Have](https://theaicommand.com/grc/board-ai-literacy-as-control-expectation#faq-2)

### Why is the AI use-case register the foundation for AI assurance?

The register defines the population of AI activity, so an incomplete register weakens every downstream test. It should capture business purpose, owner, system, users, affected stakeholders, data categories, decision influence, automation level, criticality, risk rating, approval status and review date. The risk rating then determines assurance depth and board visibility for each use case.

Source: [From Voluntary AI Guardrails to Audit Evidence](https://theaicommand.com/grc/voluntary-ai-guardrails-to-audit-evidence#faq-3)

### Why is the standard SaaS security questionnaire not enough for AI vendors?

Standard questionnaires do not ask about prompt retention, training data use, multi-tenant inference isolation, or model-version notice, because the technology was not in scope when they were designed. Build an AI-specific addendum so vendor responses on these points are captured in writing, dated, and signed.

Source: [CPS 234 and AI Vendors: A Due Diligence Framework](https://theaicommand.com/grc/cps-234-third-party-ai-vendor-due-diligence#faq-5)

### Why must JavaScript libraries be vendored into the file rather than loaded from a CDN?

A CDN reference is a live network call, and a live network call breaks the offline promise. Charting and table libraries such as Chart.js, Tabulator, PapaParse and SheetJS are useful, but each must be vendored inline or shipped locally alongside the file, with a dependency note, never pulled from a content delivery network.

Source: [Build an Offline GRC Controls Console Without Creating Shadow IT](https://theaicommand.com/grc/offline-grc-controls-testing-console#faq-5)

## Workers compensation

SRC Act practice, claims, and the Comcare scheme.

### Are household services payable in the first 28 days?

For a non-catastrophic injury, subsection 29(5) excludes compensation for any week within the 28 days beginning on the date of the injury, unless the relevant authority determines otherwise on the ground of financial hardship or the need to provide for adequate supervision of dependent children. Section 29A applies to catastrophic injury and has no 28-day exclusion and no weekly cap. An authorised person confirms which provision applies.

Source: [AI Can Map a Section 29 Household Services Claim. It Cannot Decide What Is Reasonable](https://theaicommand.com/workers-comp/src-act-section-29-ai-household-services-evidence-map#faq-4)

### Can a section 36 rehabilitation assessment decide household services needs?

No. Comcare's scheme guidance states that the rehabilitation authority's section 36 power does not extend to assessing an employee's need for household services. Relevant authorities have separate powers to arrange and pay for a needs assessment under section 70 for Comcare or section 108F for licensees. A rehabilitation assessment must be taken into consideration but cannot be the sole basis for the household services decision.

Source: [AI Can Map a Section 29 Household Services Claim. It Cannot Decide What Is Reasonable](https://theaicommand.com/workers-comp/src-act-section-29-ai-household-services-evidence-map#faq-3)

### Can AI assess permanent impairment under section 24 of the SRC Act?

No. Assessing whole person impairment against the approved Guide is a clinical judgement reserved for a suitably qualified medical practitioner, and the determination is a statutory decision for an authorised delegate. AI can organise the evidence, but it cannot decide the percentage or the entitlement and has no standing to.

Source: [AI and Permanent Impairment: Organise the Evidence, Keep the Judgement](https://theaicommand.com/workers-comp/ai-permanent-impairment-evidence-s24#faq-1)

### Can AI calculate the payable amount?

AI can check transparent arithmetic using verified inputs, but it must not determine the reasonable amount or apply an unverified statutory maximum. The subsection 29(1) weekly maximum is indexed each 1 July and published by Comcare, and the amount also cannot be less than 50 per cent of what the employee pays for the services. The authorised claims manager confirms the current rate, the evidence and the final calculation.

Source: [AI Can Map a Section 29 Household Services Claim. It Cannot Decide What Is Reasonable](https://theaicommand.com/workers-comp/src-act-section-29-ai-household-services-evidence-map#faq-5)

### Can AI decide how much compensation Comcare should recover?

No. AI can triage a de-identified file to flag that an overlap may exist and build a chronology of the parallel claim, which is useful early screening. The offset or recovery amount is a calculation that turns on the exact heads of damage, the sections engaged and the amounts involved, and it is a determination the case manager makes. An AI-suggested figure should never be relied on as the number.

Source: [Preventing Double Payment Under the SRC Act: AI Can Flag the Overlap, Not Calculate the Offset](https://theaicommand.com/workers-comp/preventing-double-payment-under-the-src-act-and-ai#faq-2)

### Can AI decide suitable duties under the SRC Act?

No. The control principle is that AI may organise information, but people must decide. Suitable duties need current medical evidence, knowledge of real work demands, consultation with the injured employee and review when circumstances change. Authorised people make the decision, and AI cannot replace that judgement.

Source: [AI Can Organise Recovery-at-Work Information, but People Must Decide](https://theaicommand.com/workers-comp/ai-recovery-at-work-and-suitable-duties#faq-1)

### Can AI decide whether a claimant had a reasonable excuse?

No. AI can build the analysis on a de-identified file: a chronology, the facts sorted against the subjective and objective limbs, an unable-versus- unwilling read, and a list of missing evidence. The reasonable-excuse finding is an exercise of delegated judgement on the specific facts, and any suspension, refusal or reinstatement that follows is the delegate's decision, recorded in their own reasons.

Source: [Reasonable Excuse Under the SRC Act: AI Can Structure the Analysis, Not Make the Finding](https://theaicommand.com/workers-comp/reasonable-excuse-under-the-src-act-and-ai#faq-3)

### Can AI decide whether a section 5A exclusion applies?

No. Section 5A is a chain of human judgements: characterising the condition, weighing employment contribution, classifying each action, and forming a view on whether conduct was reasonable and reasonably done. Those are evaluative calls a delegate is accountable for under the Act. A model that appears to decide them is worse than useless, because it produces a confident answer with no accountable reasoning behind it.

Source: [AI and the Reasonable Administrative Action Exclusion: Map the Actions, Keep the Judgement](https://theaicommand.com/workers-comp/ai-and-the-reasonable-administrative-action-exclusion#faq-1)

### Can AI decide whether medical treatment is reasonable under section 16?

No. Section 16(1) conditions compensation on the treatment being reasonable for the employee to obtain, and leaves the amount to what the authority determines is appropriate. In practice a properly delegated officer decides both. AI can assemble the picture: the category mapping, the evidence, the cost against the benefit and the gaps. The evaluative weighing and the determination itself stay with the human decision-maker, and a determination made without the delegation is invalid no matter how good the work-up was.

Source: [AI Can Build the Section 16 Picture, Not Make the Call](https://theaicommand.com/workers-comp/ai-section-16-reasonable-medical-treatment#faq-1)

### Can AI decide whether to require a medical examination?

No. AI can prepare and organise the material and draft the referral, but the decision to require an examination under section 57 is a determination the relevant authority must make, and it must comply with the Guide. A model cannot weigh the necessity of the examination, the employee's personal circumstances or the choice of practitioner, and it cannot own a decision that carries a suspension consequence and a right of review. The delegate decides and signs, and a human reviews every AI output first.

Source: [Section 57 Examinations: AI Can Build the Referral, Not Make the Call](https://theaicommand.com/workers-comp/section-57-medical-examination-referrals-with-ai#faq-3)

### Can AI decide which medical opinion to prefer in a claim?

No. Comcare guidance is clear that medical professionals do not determine liability, and a model has even less standing to. AI can organise and compare conflicting opinions so the differences are visible, but the judgement about which opinion to prefer, and the liability determination under section 14 of the SRC Act, stays with the delegate, made on the balance of probabilities.

Source: [Two Doctors Disagree: AI Can Map the Conflict, Not Resolve It](https://theaicommand.com/workers-comp/ai-mapping-conflicting-medical-opinions#faq-1)

### Can AI make a determination under the SRC Act?

No. The determination under the SRC Act is made by the case manager, and the reconsideration by the reconsideration officer. AI output supports those decisions; it does not make them. The human stays accountable for the regulated act, and that accountability must be documented in the workflow design, not just in policy.

Source: [AI Tools in Workers Compensation Claims: Where Value, Where Risk, Where Governance](https://theaicommand.com/workers-comp/ai-tools-in-claims#faq-2)

### Can AI make a section 36 rehabilitation assessment?

No. Subsection 36(2) requires the assessment to be made by a legally qualified medical practitioner nominated by the rehabilitation authority, a suitably qualified person other than a medical practitioner nominated by the authority, or a panel of such people. AI can organise de-identified material for the workflow, but it is not the statutory assessor and cannot determine the employee's capability of undertaking a rehabilitation program.

Source: [AI Can Organise a Section 36 Rehabilitation Assessment. It Cannot Choose the Program](https://theaicommand.com/workers-comp/src-act-section-36-ai-rehabilitation-assessment#faq-1)

### Can AI make a workers compensation determination under the SRC Act?

No. The SRC Act 1988 was written for delegated human decision makers, and decisions under sections 14, 16, 19 and 24 can only be made by an appropriately delegated person. AI can prepare a draft of any of these, but it cannot lawfully make the legal decision itself.

Source: [SRC Act and AI Assisted Determinations: A Practitioner Framework](https://theaicommand.com/workers-comp/src-act-and-ai-assisted-determinations#faq-1)

### Can I paste workers compensation claimant material into a chatbot to build a chronology faster?

No. Claimant material is sensitive health information and the matter ends in a statutory decision under the SRC Act. The safer pattern is to de-identify everything first, then use an LLM only to build an offline tool tested with synthetic rows, so real claimant data never reaches an external service.

Source: [Build a WC Evidence Chronology Tool Without Outsourcing Judgement](https://theaicommand.com/workers-comp/offline-wc-evidence-chronology-builder#faq-1)

### Can I use AI to draft motivational interviewing scripts for recovery-at-work conversations?

Yes, to prepare, never to conduct. AI can draft MI-informed openings, open questions, example reflections and follow-up messages so the human arrives rehearsed rather than improvising. The script is a rehearsal aid, not a teleprompter. Reflective listening cannot be pre-drafted, only rehearsed, and every draft needs human review first.

Source: [AI Can Draft Recovery Conversation Scripts, but the Listening Stays Human](https://theaicommand.com/workers-comp/ai-drafted-motivational-interviewing-scripts#faq-1)

### Can I use AI to summarise treating practitioner reports for a workers compensation claim?

Yes, for the reading task. AI structures long reports into diagnosis, history, treatment, prognosis, and recommendations, surfaces inconsistencies across reports, and reduces cognitive load on entry tasks. It is a navigation aid only. The first read is end to end, every time, and the summary never replaces the source report.

Source: [Treating Practitioner Reports and AI: Where the Workflow Helps and Where It Hurts](https://theaicommand.com/workers-comp/treating-practitioner-reports-and-ai#faq-1)

### Do I have to de-identify the file before using AI?

Yes. Claim files hold names, claim numbers, dates of birth and detailed medical and personal information. None of that should go into an AI tool. Replace identifiers with placeholders, and only ask the model to work on the de-identified structure of the opinions. The comparison AI produces is a working aid, and the delegate applies it back to the real file.

Source: [Two Doctors Disagree: AI Can Map the Conflict, Not Resolve It](https://theaicommand.com/workers-comp/ai-mapping-conflicting-medical-opinions#faq-4)

### Do I need a reconsideration before applying to the ART?

Yes. Reconsideration is the gateway. ART review of a primary determination requires a reconsideration first. Going straight from a primary determination to the ART is procedurally not available. The reconsideration produces a reviewable decision, which is the artefact that triggers the next review tier.

Source: [ART Review Rights Under the SRC Act: A Practitioner's Map](https://theaicommand.com/workers-comp/art-review-rights#faq-2)

### Do I need to de-identify medical reports before using AI on an impairment claim?

Yes, always and first. Replace the name with [CLAIMANT_NAME], the claim number with [CLAIM_NUMBER] and date of birth with [DATE_OF_BIRTH], mask other identifying detail, and keep the re-identification key separate. Use only an approved tool for sensitive data, never a public consumer model where input may be retained.

Source: [AI and Permanent Impairment: Organise the Evidence, Keep the Judgement](https://theaicommand.com/workers-comp/ai-permanent-impairment-evidence-s24#faq-3)

### Do I still need to de-identify if the AI tool is well known and widely used?

Yes. The public profile of a tool is not the same as a documented privacy assessment, so the toolkit applies regardless of vendor. Even where a tool claims no data leaves your environment, de-identify unless inference location, logging, training use, and Privacy Impact Assessment questions are all confirmed. The cost of de-identifying is low; being wrong is high.

Source: [The De-Identification Toolkit for Case Managers Working With AI](https://theaicommand.com/workers-comp/de-identification-toolkit-for-case-managers#faq-5)

### Does a section 36 assessment choose the rehabilitation program?

No. Where an examination is carried out, the written assessment under subsection 36(8) states the employee's capability of undertaking a rehabilitation program and, where appropriate, the kind of program. A section 37 determination that the employee should undertake a program is made separately by the rehabilitation authority, which must have regard to the section 36(8) assessment and the other matters listed in subsection 37(3).

Source: [AI Can Organise a Section 36 Rehabilitation Assessment. It Cannot Choose the Program](https://theaicommand.com/workers-comp/src-act-section-36-ai-rehabilitation-assessment#faq-2)

### Does recovering third-party damages stop SRC Act compensation?

Broadly, yes, for the same injury. Under the framework in sections 46, 48 and 50, once a person recovers damages from a third party for the injury, the relevant authority can recover the compensation it has paid and further compensation is affected, with a limited exception for damages recovered for non-economic loss under a section 45 election. The precise effect depends on the facts, so the guidance and the Act should be read directly.

Source: [Preventing Double Payment Under the SRC Act: AI Can Flag the Overlap, Not Calculate the Offset](https://theaicommand.com/workers-comp/preventing-double-payment-under-the-src-act-and-ai#faq-5)

### Does the Practice Direction apply to a medical report written during the claim?

Clause 3.7 records that the documents a decision-maker is required to give the Tribunal on commencement of a review may include reports that fall within the scope of the Practice Direction. Where a party wants to place particular reliance on such a report but it does not carry the information in clauses 3.1 to 3.5C, the party should consider whether additional information should be sought from the expert and given to the Tribunal. The practical effect is that a report written well before any review is later read against the standard.

Source: [The Medical Report Now Has to Declare Its AI](https://theaicommand.com/workers-comp/art-expert-evidence-ai-disclosure#faq-2)

### Does using AI to draft an SRC Act determination put it at risk at the Administrative Review Tribunal?

No. The Tribunal is not concerned with whether AI tools were used in drafting. It is concerned with whether the determination is supported by evidence, whether the delegate can articulate the reasoning, and whether procedural fairness was observed. Where the reasoning trail is intact, AI use is unproblematic and effectively invisible at review.

Source: [Reading the Reasoning Trail: A Case Note on AI Drafted Determinations](https://theaicommand.com/workers-comp/hansen-v-comcare-2026-art-412-case-note#faq-1)

### How can I use AI to analyse the 2025 SRC Act Review for my organisation?

Set up a project space with a tight system prompt, a reference pack including the SRC Act 1988 and the review report, and a guardrail file. Then run four prompt patterns: triage the recommendations, compare them section by section, map operational impact, and scaffold a submission for legal to finish.

Source: [Leveraging AI to assist dissecting the SRC Act Review](https://theaicommand.com/workers-comp/src-act-review-2025-and-ai#faq-1)

### How can I use AI to help prepare a permanent impairment claim file?

AI can take de-identified medical reports and build a dated chronology tagged by author and body region, map each report to the approved Guide's structure, and flag gaps or inconsistencies. It can also draft a neutral file summary once a person has done the thinking. Every output is a checklist to verify, never a finding.

Source: [AI and Permanent Impairment: Organise the Evidence, Keep the Judgement](https://theaicommand.com/workers-comp/ai-permanent-impairment-evidence-s24#faq-2)

### How do I de-identify a claim file before using AI?

Claim material is sensitive information. Strip names, claim numbers, dates of birth and any identifier before a single line goes near a model, and work in placeholders such as [CLAIMANT_NAME], [CLAIM_NUMBER] and [DATE_OF_BIRTH]. If you cannot de-identify it, it does not go in. This is the precondition for everything else.

Source: [AI and the Reasonable Administrative Action Exclusion: Map the Actions, Keep the Judgement](https://theaicommand.com/workers-comp/ai-and-the-reasonable-administrative-action-exclusion#faq-4)

### How do I de-identify a treating practitioner report before using AI?

Reports carry identifiers in letterheads, signature blocks, practice details, and file references. Apply the five-category de-identification toolkit in full, using placeholders like TREATING_PRACTITIONER, PRACTICE, CLAIMANT_NAME, CLAIM_NUMBER, INJURY_DATE, and CONDITION consistently. Never paste a report into any tool that has not been approved by your scheme operator.

Source: [Treating Practitioner Reports and AI: Where the Workflow Helps and Where It Hurts](https://theaicommand.com/workers-comp/treating-practitioner-reports-and-ai#faq-3)

### How do I de-identify claimant information before prompting an AI tool?

Never enter real names, claim numbers, dates of birth, employee IDs, provider names, exact dates or identifying injury details into a public or unapproved AI tool. Use fictional scenarios and [PLACEHOLDER] fields. Removing a name is not enough if the remaining facts can still identify the person. If context cannot be written without identifying detail, do not proceed.

Source: [AI Can Draft Recovery Conversation Scripts, but the Listening Stays Human](https://theaicommand.com/workers-comp/ai-drafted-motivational-interviewing-scripts#faq-2)

### How do I de-identify workers compensation data before using an LLM?

De-identify before the model ever sees the matter, treating it as a fixed step, not a judgement under time pressure. Use placeholders like [CLAIMANT_NAME], [CLAIM_NUMBER] and [DATE_OF_BIRTH], and neutral tags such as Treating Practitioner A. Raw fields never leave the local environment; a human maps placeholders back at review time.

Source: [Build a WC Evidence Chronology Tool Without Outsourcing Judgement](https://theaicommand.com/workers-comp/offline-wc-evidence-chronology-builder#faq-3)

### How do I make a WC prompt library safe to use?

Build the library from fictional scenarios, de-identified chronologies and placeholder fields rather than real claim material. Tell each prompt what not to do, ban legal conclusions, and require source separation. The second, more important control is that a human reviews every output before it is saved, sent or relied on.

Source: [Prompt Libraries Make WC AI Safer Only When Human Review Comes First](https://theaicommand.com/workers-comp/wc-prompt-libraries-and-human-review#faq-1)

### How do I review an AI-supported recovery-at-work plan?

Review whenever new medical evidence arrives, at agreed checkpoints, and when duties, symptoms or concerns change. Ask whether the plan is still supported by current evidence, whether duties remain safe and genuinely available, whether consultation raised concerns, and whether the reviewer recorded changes made to AI-assisted drafts.

Source: [AI Can Organise Recovery-at-Work Information, but People Must Decide](https://theaicommand.com/workers-comp/ai-recovery-at-work-and-suitable-duties#faq-5)

### How do I stop a neat AI timeline being treated as verified evidence?

A neat timeline is not evidence until a human checks it against the source records. Add an export gate that blocks export until a reviewer confirms in a required note that the source records have been checked. The export must carry a disclaimer that the chronology is a preparation artefact, not a determination.

Source: [Build a WC Evidence Chronology Tool Without Outsourcing Judgement](https://theaicommand.com/workers-comp/offline-wc-evidence-chronology-builder#faq-5)

### How does AI help when medical evidence conflicts?

It removes the sorting so you can spend your time on the weighing. Working from a de-identified file, AI can lay out what clinical question each opinion addressed, the history and evidence each relied on, where the opinions agree, where they diverge, and where the record is missing something. That structured comparison makes the real points of difference obvious, which is where the delegate's judgement is best spent.

Source: [Two Doctors Disagree: AI Can Map the Conflict, Not Resolve It](https://theaicommand.com/workers-comp/ai-mapping-conflicting-medical-opinions#faq-2)

### How does the Clinical Framework bear on reasonableness?

Comcare's scheme guidance points to the Clinical Framework for the Delivery of Health Services, published by WorkSafe Victoria, as the lens for the cost-versus-benefit weighing, and notes the Administrative Review Tribunal has supported its use as a relevant consideration in determining reasonableness. Its five principles cover measured effectiveness, a biopsychosocial approach, empowering the injured person, goals focused on function and return to work, and the best available research evidence.

Source: [AI Can Build the Section 16 Picture, Not Make the Call](https://theaicommand.com/workers-comp/ai-section-16-reasonable-medical-treatment#faq-3)

### How is AI-assisted evidence treated when a determination reaches the ART?

Where AI assisted the original determination, the file note should record its role, the reconsideration reasons should engage with it, and the ART evidence pack should include the AI-assisted artefacts. The pattern that survives review is AI in the analysis, a human in the decision, documented in the reasoning trail.

Source: [ART Review Rights Under the SRC Act: A Practitioner's Map](https://theaicommand.com/workers-comp/art-review-rights#faq-5)

### How should a case manager record that AI was used in drafting a determination?

Add a short file note paragraph recording that AI was used, that inputs were de-identified, and that the case manager reviewed and edited the draft. Silence is not defensible. A clear note signals discipline and is read positively at review, while the absence of such a note is read negatively.

Source: [Reading the Reasoning Trail: A Case Note on AI Drafted Determinations](https://theaicommand.com/workers-comp/hansen-v-comcare-2026-art-412-case-note#faq-3)

### How should I de-identify claim data before using an AI tool?

De-identification is the default for every workflow where claim data leaves the scheme's controlled environment. Remove full names, claim numbers, specific addresses, employer identifiers, and diagnoses linked to identifiers. Use stable internal identifiers the case manager can re-attach afterwards. This is the single highest-leverage control across the entire claims workflow.

Source: [AI Tools in Workers Compensation Claims: Where Value, Where Risk, Where Governance](https://theaicommand.com/workers-comp/ai-tools-in-claims#faq-3)

### How should I de-identify claim information before using an AI tool?

No prompt sent to any external AI tool may contain a claimant name, claim number, date of birth, exact address, treating practitioner name, or employer reference. Replace them with placeholders such as CLAIMANT_NAME, CLAIM_NUMBER, CONDITION and TREATING_PRACTITIONER. This is treated as a control, not a guideline, every single time.

Source: [SRC Act and AI Assisted Determinations: A Practitioner Framework](https://theaicommand.com/workers-comp/src-act-and-ai-assisted-determinations#faq-3)

### How should I document a case where I disagree with the triage model?

Make the determination on the evidence and record the divergence in the file note, capturing the model's prediction, your view, and the basis for the difference. The override is logged in an override register, keeping the reasoning trail intact and protecting every individual determination while also generating data that improves the model.

Source: [Predictive Analytics and Claims Triage: A Risk Analysis for Scheme Operators](https://theaicommand.com/workers-comp/predictive-analytics-and-claims-triage#faq-3)

### How should I format placeholders when de-identifying claim documents?

Use a consistent convention: square brackets, capital letters, no spaces, so AI outputs return in a form you can find and replace at the end. Common placeholders include [CLAIM_NUMBER], [CLAIMANT_NAME], [CONDITION], [INJURY_DATE], and [TREATING_PRACTITIONER]. Build any additional placeholders on the same pattern so each is self-explanatory.

Source: [The De-Identification Toolkit for Case Managers Working With AI](https://theaicommand.com/workers-comp/de-identification-toolkit-for-case-managers#faq-2)

### How should I frame motivational interviewing in the AI prompt?

Name the four elements of the MI spirit, partnership, acceptance, compassion and evocation, and name OARS: open questions, affirmations, reflective listening and summaries. Impose constraints: no persuasion or pressure, no medical advice or recovery predictions, no commentary on liability or claim outcomes, plain Australian English. Unconstrained models default to upbeat salesmanship, the opposite of acceptance.

Source: [AI Can Draft Recovery Conversation Scripts, but the Listening Stays Human](https://theaicommand.com/workers-comp/ai-drafted-motivational-interviewing-scripts#faq-3)

### How should I handle AI for psychological injury claims?

AI should not infer attitude, motivation or credibility from an employee's language, or summarise concerns as resistance or non-compliance unless the evidence genuinely supports that and the decision-maker has considered context. Use AI to draft neutral prompts about whether duties are safe and sustainable, recognising section 37 considerations.

Source: [AI Can Organise Recovery-at-Work Information, but People Must Decide](https://theaicommand.com/workers-comp/ai-recovery-at-work-and-suitable-duties#faq-3)

### How should I record the AI cross-check on the claim file?

Write a brief one-paragraph file note covering four things: the case manager calculated the figure manually, cross-checked it against an AI tool with de-identified inputs, the figures matched or any discrepancy was resolved, and the manual figure is authoritative. The note is not optional and is defensible at audit and review.

Source: [The Incapacity Cross-Check Workflow: AI as a Calculation Auditor](https://theaicommand.com/workers-comp/incapacity-cross-check-workflow#faq-5)

### How should section 19 incapacity calculations from AI be handled?

The case manager should redo the calculation independently, even where the AI got it right, so the figure is genuinely the case manager's. AI assisted maths accepted without the delegate being able to explain it creates calculation opacity. Use the AI result only as a cross-check, with the case manager's figure being authoritative.

Source: [Reading the Reasoning Trail: A Case Note on AI Drafted Determinations](https://theaicommand.com/workers-comp/hansen-v-comcare-2026-art-412-case-note#faq-5)

### Is a report that does not comply inadmissible?

No. Clause 1.11 says a failure to comply may have consequences for the weight the Tribunal gives to the expert's evidence. The note under it records that the Tribunal is not bound by the rules of evidence relating to opinion evidence, citing section 52 of the Administrative Review Tribunal Act 2024, and that the Tribunal will determine the weight given to any evidence before it. The report is not excluded. It can quietly carry less weight.

Source: [The Medical Report Now Has to Declare Its AI](https://theaicommand.com/workers-comp/art-expert-evidence-ai-disclosure#faq-3)

### Is a section 57 examination request now a reviewable decision?

Yes. Comcare's guidance on the amendments confirms that requests to undergo medical examinations under section 57 of the SRC Act are determinations that are reviewable and can be subject to review by the Administrative Review Tribunal, following changes that commenced on 14 June 2024. Because it is a determination for the purposes of section 60, notice of it must be given in writing under section 61 with the terms of the determination and the reasons for it, which raises the bar on how the referral is documented.

Source: [Section 57 Examinations: AI Can Build the Referral, Not Make the Call](https://theaicommand.com/workers-comp/section-57-medical-examination-referrals-with-ai#faq-1)

### Is motivational interviewing proven to improve return to work?

The evidence is promising but thin. A 2017 Canadian trial of 728 claimants found the MI group transitioned to modified duties more often with roughly half the benefit recurrence. A 2021 mapping review found a large research gap, and the 2022 MI-NAV trial cut sickness absence by about seven days, a difference that was not statistically significant.

Source: [AI Can Draft Recovery Conversation Scripts, but the Listening Stays Human](https://theaicommand.com/workers-comp/ai-drafted-motivational-interviewing-scripts#faq-5)

### Should I let AI calculate section 19 incapacity benefits for me?

No. The case manager owns the calculation and runs the maths fully and personally, because section 19 is a delegated decision. AI is well suited to finding discrepancies between two computed figures, so it audits the manual figure rather than producing it. The manual figure stays authoritative every time.

Source: [The Incapacity Cross-Check Workflow: AI as a Calculation Auditor](https://theaicommand.com/workers-comp/incapacity-cross-check-workflow#faq-1)

### Should I let AI draft my submission to government on the SRC Act Review?

No. The AI drafts the scaffold only: a submission outline, points keyed to recommendation numbers, evidence inputs needed, and points requiring legal advice. Government relations and external legal counsel finish the submission. A regulator can usually tell when a position came from the model rather than the organisation.

Source: [Leveraging AI to assist dissecting the SRC Act Review](https://theaicommand.com/workers-comp/src-act-review-2025-and-ai#faq-3)

### What are the five identifier categories I need to remove before using an AI tool?

The five categories are direct claimant identifiers, indirect identifiers, treating practitioner identifiers, third-party identifiers, and free-text leakage. They are deliberately broader than the strict legal definition of personal information, because the goal is robustness rather than minimum compliance. Replace each with a standard bracketed placeholder before pasting anything.

Source: [The De-Identification Toolkit for Case Managers Working With AI](https://theaicommand.com/workers-comp/de-identification-toolkit-for-case-managers#faq-1)

### What are the main risks of relying on AI summaries of medical reports?

Summary drift can subtly distort the practitioner's view, case managers may start reading the summary instead of the report, and privacy creep can leave identifiers in metadata. Audit failure modes include confirmation summarisation, compression of disagreement between treating and IME views, and loss of clinical specificity. Going back to the source is the key control.

Source: [Treating Practitioner Reports and AI: Where the Workflow Helps and Where It Hurts](https://theaicommand.com/workers-comp/treating-practitioner-reports-and-ai#faq-5)

### What are the main risks of using predictive analytics for claims triage?

Six categories arise in practice: procedural fairness drift, training data bias, reasoning trail dilution, vendor opacity, calibration decay, and concentration of effect where one model touches every claim. Each is real even where the model is good, and several only become visible in aggregate or once something goes wrong.

Source: [Predictive Analytics and Claims Triage: A Risk Analysis for Scheme Operators](https://theaicommand.com/workers-comp/predictive-analytics-and-claims-triage#faq-2)

### What are the SRC Act's rules against double payment of compensation?

They stop a person being compensated twice for the same injury. Comcare guidance SRC344 groups them into three overlaps: damages recovered from a third party at common law under sections 46, 48 and 50, an overlapping state or territory workers compensation entitlement under section 118, and compensation under a state or territory scheme that is not workers compensation under section 119. Each has its own recovery mechanism.

Source: [Preventing Double Payment Under the SRC Act: AI Can Flag the Overlap, Not Calculate the Offset](https://theaicommand.com/workers-comp/preventing-double-payment-under-the-src-act-and-ai#faq-1)

### What are the steps in the incapacity cross-check workflow?

Five steps. Calculate the section 19 figure manually. De-identify the inputs with placeholders. Prompt the AI to compute the figure step by step. Compare the manual and AI figures. Document both on file, recording that the manual figure is authoritative. It adds five to ten minutes.

Source: [The Incapacity Cross-Check Workflow: AI as a Calculation Auditor](https://theaicommand.com/workers-comp/incapacity-cross-check-workflow#faq-2)

### What are the three review tiers under the SRC Act?

Review runs in three tiers. Tier 1 is internal reconsideration under section 62, carried out by an uninvolved officer. Tier 2 is a merits review by the Administrative Review Tribunal under section 64. Tier 3 is a Federal Court appeal on a question of law under section 44 of the ART Act.

Source: [ART Review Rights Under the SRC Act: A Practitioner's Map](https://theaicommand.com/workers-comp/art-review-rights#faq-1)

### What are the timeframes for reconsideration, ART review and Federal Court appeal?

Reconsideration of a primary determination should generally be requested within 30 days of the determination being notified. An ART application must generally be lodged within 60 days of the reviewable decision being received. A Federal Court appeal must be lodged within 28 days. Extensions are available only in limited circumstances.

Source: [ART Review Rights Under the SRC Act: A Practitioner's Map](https://theaicommand.com/workers-comp/art-review-rights#faq-3)

### What are the two human review gates in the SRC Act Review AI workflow?

Gate one is senior management reviewing the high-impact recommendation triage before further analysis runs. Gate two is external or in-house legal counsel reviewing the section-by-section statutory comparison before the transitional and submission patterns run. Skipping either gate is the most common failure mode.

Source: [Leveraging AI to assist dissecting the SRC Act Review](https://theaicommand.com/workers-comp/src-act-review-2025-and-ai#faq-2)

### What can the AI cross-check not detect on a section 19 calculation?

It cannot catch inputs that are wrong on file; it will compute the wrong answer correctly. It cannot resolve legal characterisation, such as whether a payment is part of normal weekly earnings. It cannot make the choice of which available figures to use. The case manager remains responsible for these.

Source: [The Incapacity Cross-Check Workflow: AI as a Calculation Auditor](https://theaicommand.com/workers-comp/incapacity-cross-check-workflow#faq-4)

### What can the AI tool do, and what must the delegate decide?

The tool organises facts: it orders events by date, tags evidence types, references sources, flags gaps and drafts review questions. The delegate decides outcomes under the SRC Act, including liability under section 14, injury under section 5A, disease under section 5B, incapacity, impairment, treatment and rehabilitation.

Source: [Build a WC Evidence Chronology Tool Without Outsourcing Judgement](https://theaicommand.com/workers-comp/offline-wc-evidence-chronology-builder#faq-2)

### What can the ART do with a reviewable decision?

The ART conducts an independent merits review and can affirm the reviewable decision, vary it, set it aside and substitute its own decision, or set it aside and remit the matter to the determining authority with directions. There are some limits on substitution, notably for certain rehabilitation decisions.

Source: [ART Review Rights Under the SRC Act: A Practitioner's Map](https://theaicommand.com/workers-comp/art-review-rights#faq-4)

### What claim information can be put into an AI tool?

Use only an approved tool and data pathway. De-identify before upload, using placeholders such as [CLAIMANT_NAME], [CLAIM_NUMBER], [CONDITION] and [DATE_OF_INJURY]. Removing a name alone is not enough if dates, providers, locations or unusual combinations of facts could still identify the person.

Source: [AI Can Organise a Section 36 Rehabilitation Assessment. It Cannot Choose the Program](https://theaicommand.com/workers-comp/src-act-section-36-ai-rehabilitation-assessment#faq-4)

### What counts as household services under the SRC Act?

Subsection 4(1) defines household services as services of a domestic nature, including cooking, house cleaning, laundry and gardening services, that are required for the proper running and maintenance of the employee's household. Whether a claimed task meets that definition depends on its nature and purpose, and the check belongs to the authorised decision-maker, not to a model.

Source: [AI Can Map a Section 29 Household Services Claim. It Cannot Decide What Is Reasonable](https://theaicommand.com/workers-comp/src-act-section-29-ai-household-services-evidence-map#faq-1)

### What de-identification rules apply when using AI on claims data?

Do not enter real claimant names, claim numbers, employee IDs, provider names, exact dates, locations or medical details into unapproved AI tools. Use fictional examples and placeholder fields. Removing a name alone is not enough, because other facts can still identify the person.

Source: [AI Can Organise Recovery-at-Work Information, but People Must Decide](https://theaicommand.com/workers-comp/ai-recovery-at-work-and-suitable-duties#faq-4)

### What does a defensible reasoning trail for an AI assisted determination need to show?

Four things, walked through in order: the legal test that applied (which SRC Act section and threshold), the evidence considered, the reasoning connecting that evidence to the test, and the conclusion that issued. AI drafting can support every step but cannot replace any of them. The delegate must reproduce the trail on demand.

Source: [Reading the Reasoning Trail: A Case Note on AI Drafted Determinations](https://theaicommand.com/workers-comp/hansen-v-comcare-2026-art-412-case-note#faq-2)

### What does a predictive triage model actually do in workers compensation claims?

It sorts incoming claims by likely complexity, expected duration, or risk of dispute, supporting faster triage, load balancing, earlier intervention on escalating claims, and cleaner management reporting. A handful of Australian schemes run production deployments and many more are piloting, so the technology is now business as usual in pockets.

Source: [Predictive Analytics and Claims Triage: A Risk Analysis for Scheme Operators](https://theaicommand.com/workers-comp/predictive-analytics-and-claims-triage#faq-1)

### What does de-identification mean for workers compensation communications?

De-identification means more than removing a name. Claim numbers, employee IDs, provider names, exact dates, locations, unusual role details, injury facts, medical histories and combinations of facts can still identify a person. Use placeholder fields and fictional examples unless the tool, workflow and data handling have been formally approved.

Source: [Prompt Libraries Make WC AI Safer Only When Human Review Comes First](https://theaicommand.com/workers-comp/wc-prompt-libraries-and-human-review#faq-2)

### What does not count as a reasonable excuse?

Comcare guidance is clear that being dissatisfied with the terms of a request does not amount to a reasonable excuse, and neither does a difficulty that arises only from the claimant's personal preference, such as choosing to relocate away from where the requirement can be met. Practical difficulties that are objectively reasonable, such as a remote location, an accessibility need or not receiving the request, are more likely to qualify.

Source: [Reasonable Excuse Under the SRC Act: AI Can Structure the Analysis, Not Make the Finding](https://theaicommand.com/workers-comp/reasonable-excuse-under-the-src-act-and-ai#faq-5)

### What does section 16(1) of the SRC Act actually require?

Three things. The treatment must have been obtained in relation to the compensable injury, it must have been reasonable for the employee to obtain in the circumstances, and compensation is of such amount as the authority determines is appropriate to that treatment. Before any of that, the request must fall within the definition of medical treatment in section 4(1). Something outside that definition is not section 16 medical treatment at all.

Source: [AI Can Build the Section 16 Picture, Not Make the Call](https://theaicommand.com/workers-comp/ai-section-16-reasonable-medical-treatment#faq-2)

### What does section 5A of the SRC Act actually require?

Section 5A excludes compensation for an injury suffered as a result of reasonable administrative action taken in a reasonable manner in respect of the employee's employment. The analysis runs in order: first whether there is a disease under section 5B, then whether any employment causative factor was reasonable administrative action across four questions, then whether the injury was suffered as a result of that action.

Source: [AI and the Reasonable Administrative Action Exclusion: Map the Actions, Keep the Judgement](https://theaicommand.com/workers-comp/ai-and-the-reasonable-administrative-action-exclusion#faq-2)

### What does the ART Expert Evidence Practice Direction 2026 say about AI?

Clause 3.5B requires an expert preparing a written report for a Tribunal proceeding to state whether the report includes content generated by using Generative AI. Clause 3.5C requires, where it does, that the expert clearly identify the AI content and the applications used to generate it, and certify that they have personally checked all of it, including research and other material cited in support, and are satisfied it is all accurate and reliable. Clause 3.5A defines Generative AI and names ChatGPT, Gemini, Microsoft Copilot, Perplexity, Claude, Grok and DeepSeek AI as examples.

Source: [The Medical Report Now Has to Declare Its AI](https://theaicommand.com/workers-comp/art-expert-evidence-ai-disclosure#faq-1)

### What does the Guide require the decision-maker to consider?

Comcare's material on the Guide states that relevant authorities must consider an employee's circumstances, rely as much as possible on relevant information from the injured employee's treating practitioner, and seek and take into account the employee's views about the selection of the person or people who will conduct the assessment or examination. Those are judgement calls about a specific person, which is exactly why they stay with the delegate and are documented in the decision record.

Source: [Section 57 Examinations: AI Can Build the Referral, Not Make the Call](https://theaicommand.com/workers-comp/section-57-medical-examination-referrals-with-ai#faq-4)

### What governance controls does a defensible predictive triage deployment need?

Six controls: a written model description before deployment, ongoing calibration monitoring reviewed quarterly at minimum, an override register reviewed for patterns, bias monitoring across cohorts, reasoning trail integration in file notes, and a Privacy Impact Assessment covering training data, production flow, and output, reviewed annually.

Source: [Predictive Analytics and Claims Triage: A Risk Analysis for Scheme Operators](https://theaicommand.com/workers-comp/predictive-analytics-and-claims-triage#faq-4)

### What is a reasonable excuse under the SRC Act?

It is the ground a claimant relies on when they fail to comply with a requirement, such as attending an examination or undertaking a rehabilitation program. Comcare guidance SRC345 sets a combined test: the delegate weighs both the subjective grounds the claimant advances and whether those grounds are objectively reasonable. The excuse must show the person was unable to comply, not merely unwilling, and it requires more than a rational explanation.

Source: [Reasonable Excuse Under the SRC Act: AI Can Structure the Analysis, Not Make the Finding](https://theaicommand.com/workers-comp/reasonable-excuse-under-the-src-act-and-ai#faq-1)

### What is a safer workflow for AI-assisted WC content?

Use four stages. Select an approved prompt from the library. Insert only de-identified placeholder facts or fictional scenario facts. Review the output against source documents, legislation, policy and tone requirements. Then record the AI assistance, reviewer, sources checked and changes made before the content is saved or sent.

Source: [Prompt Libraries Make WC AI Safer Only When Human Review Comes First](https://theaicommand.com/workers-comp/wc-prompt-libraries-and-human-review#faq-4)

### What is a section 57 independent medical examination?

Under section 57 of the SRC Act, a delegate can require an employee to undergo an examination by a medical practitioner where additional medical information or specialist opinion is needed to make a decision. The resulting independent opinion often sits alongside the treating doctor's report, and the two can disagree. A decision to require a section 57 examination is itself a reviewable determination for the purposes of section 60.

Source: [Two Doctors Disagree: AI Can Map the Conflict, Not Resolve It](https://theaicommand.com/workers-comp/ai-mapping-conflicting-medical-opinions#faq-3)

### What is the daily desk routine for de-identifying before using AI?

Open the source document, save a clearly marked working copy, run a five-category Find and Replace sweep for names, dates, locations, practitioner details, and third parties, then visually scan paragraph by paragraph for anything missed. Once clean, use the working copy in the approved tool while the original stays untouched in the source system.

Source: [The De-Identification Toolkit for Case Managers Working With AI](https://theaicommand.com/workers-comp/de-identification-toolkit-for-case-managers#faq-3)

### What is the difference between administrative and operational action?

Administrative action is directed specifically at the employee and their employment relationship, such as a performance appraisal, counselling, suspension or disciplinary action under section 5A(2). Operational action, a direction about how and when to perform the work itself, is not reasonable administrative action, and any resulting injury is compensable. The distinction decides whether section 5A is even in play.

Source: [AI and the Reasonable Administrative Action Exclusion: Map the Actions, Keep the Judgement](https://theaicommand.com/workers-comp/ai-and-the-reasonable-administrative-action-exclusion#faq-3)

### What is the difference between section 118 and section 119?

Section 118 deals with an overlap between SRC Act compensation and state or territory workers compensation for the same injury, and Comcare may recover the amount it paid. Section 119 deals with an overlap between SRC Act compensation and a state or territory scheme that pays compensation other than workers compensation, such as a motor accident scheme, where Comcare is generally liable only for the excess.

Source: [Preventing Double Payment Under the SRC Act: AI Can Flag the Overlap, Not Calculate the Offset](https://theaicommand.com/workers-comp/preventing-double-payment-under-the-src-act-and-ai#faq-3)

### What is the five-step workflow for AI assisted SRC Act determinations?

Frame the question and identify the legal test. De-identify the input with placeholders. Generate a structured draft. Map the draft to the actual claim file line by line. Then issue the decision, applying the legal test and signing as the delegated decision maker. AI assists only at step three.

Source: [SRC Act and AI Assisted Determinations: A Practitioner Framework](https://theaicommand.com/workers-comp/src-act-and-ai-assisted-determinations#faq-2)

### What is the safe workflow for using AI with a treating practitioner report?

Triage with the full report first, then generate a structured summary as a navigation aid. Cross-check the summary against the original and correct any drift. Use the summary as an aid, not a replacement, when deciding under section 16 or section 14, and capture medical opinion in the practitioner's own words from the source.

Source: [Treating Practitioner Reports and AI: Where the Workflow Helps and Where It Hurts](https://theaicommand.com/workers-comp/treating-practitioner-reports-and-ai#faq-4)

### What is the section 57A Guide?

Section 57A of the SRC Act requires Comcare to prepare a Guide for Arranging Rehabilitation Assessments and Requiring Examinations. The object of the Guide is to support ethical, transparent and accountable decision making in relation to arranging a rehabilitation assessment of an employee under subsection 36(1), or requiring an employee to undergo an examination under subsection 36(3) or 57(1), including appropriate consideration of the employee's personal circumstances. It is a legislative instrument, compliance is mandatory, and it applies to section 36 and section 57 determinations made on or after 30 October 2024.

Source: [Section 57 Examinations: AI Can Build the Referral, Not Make the Call](https://theaicommand.com/workers-comp/section-57-medical-examination-referrals-with-ai#faq-2)

### What is the whole person impairment threshold for a section 24 claim?

Section 24 generally requires the permanent impairment to reach at least 10 per cent whole person impairment, with specific exceptions for matters such as hearing loss and loss of the use of fingers, toes, or the sense of taste or smell. The 10 per cent line is legal; whether the evidence reaches it is a clinical judgement.

Source: [AI and Permanent Impairment: Organise the Evidence, Keep the Judgement](https://theaicommand.com/workers-comp/ai-permanent-impairment-evidence-s24#faq-5)

### What kinds of errors does the AI cross-check actually catch?

Three classes most often. Transposition errors, such as numbers in the wrong order or misplaced decimal points. Statutory interpretation errors, often involving section 8 normal weekly earnings interacting with allowances or prescribed amounts. Sequencing errors, where the order adjustments are applied matters for the legal correctness of the determination.

Source: [The Incapacity Cross-Check Workflow: AI as a Calculation Auditor](https://theaicommand.com/workers-comp/incapacity-cross-check-workflow#faq-3)

### What makes a WC prompt unsafe versus safer?

An unsafe prompt invites real claim information, asks AI to form a conclusion, and risks claimant-facing language without legal review. A safer prompt is narrower: it uses fictional information and placeholder fields, bans liability recommendations, separates evidence, gaps, assumptions and actions, and marks the output as draft-only for human review.

Source: [Prompt Libraries Make WC AI Safer Only When Human Review Comes First](https://theaicommand.com/workers-comp/wc-prompt-libraries-and-human-review#faq-5)

### What must a claimant do if they pursue a third-party damages claim?

Comcare guidance sets out notification duties. A claimant or dependant who decides to pursue a common law claim for damages against a third party must tell the relevant authority in writing as soon as practicable and within 7 days of becoming aware of the claim, and once damages are recovered must notify the authority in writing of the amount within 28 days. Recovering damages for the same injury affects the right to further SRC Act compensation.

Source: [Preventing Double Payment Under the SRC Act: AI Can Flag the Overlap, Not Calculate the Offset](https://theaicommand.com/workers-comp/preventing-double-payment-under-the-src-act-and-ai#faq-4)

### What must be considered under subsection 29(2)?

Subsection 29(2) requires the decision-maker to have regard to five matters: the employee's pre-injury and post-injury contribution to household services, the people living in the household with their ages and needs, those members' contribution before the injury, what household or family members might reasonably be expected to provide for themselves and the employee after the injury, and the need to avoid substantial disruption to their employment or other activities. The subsection is expressed without limiting other matters, so other relevant circumstances may also be considered.

Source: [AI Can Map a Section 29 Household Services Claim. It Cannot Decide What Is Reasonable](https://theaicommand.com/workers-comp/src-act-section-29-ai-household-services-evidence-map#faq-2)

### What must be removed before claim documents reach an AI tool?

Everything identifying: the claimant's name, claim number, date of birth and any detail that could identify them, replaced with placeholders such as [CLAIMANT_NAME], [CLAIM_NUMBER] and [CONDITION]. De-identification is mandatory before any claim material reaches a model, and the material goes only into a tool your organisation has approved for claims work. If no tool is approved, that approval comes first.

Source: [AI Can Build the Section 16 Picture, Not Make the Call](https://theaicommand.com/workers-comp/ai-section-16-reasonable-medical-treatment#faq-4)

### What must the human review cover?

The reviewer verifies every extracted statement against its source, corrects dates and context, confirms de-identification, applies the current Act and Guide, preserves the employee-view and assessor-selection steps, and ensures only qualified and authorised people perform the assessment and determination functions.

Source: [AI Can Organise a Section 36 Rehabilitation Assessment. It Cannot Choose the Program](https://theaicommand.com/workers-comp/src-act-section-36-ai-rehabilitation-assessment#faq-5)

### What permanent impairment tasks must stay with a human, not AI?

The whole person impairment assessment against the Guide, weighing conflicting examiner evidence, combining multiple impairments by the combined values method, section 27 non-economic loss assessment, and the section 24 determination all stay human. A model can flag divergence, but conclusions, percentages and the entitlement decision must be attributable to qualified people.

Source: [AI and Permanent Impairment: Organise the Evidence, Keep the Judgement](https://theaicommand.com/workers-comp/ai-permanent-impairment-evidence-s24#faq-4)

### What should a letter of instruction to a medical examiner now cover?

Enough for the report to answer clause 3.1 on its face: the questions or issues the examiner is asked to address, and a reference to the documents and materials provided. Comcare's guidance on engaging a legally qualified medical practitioner already says proper instructions, including the appropriate scope of the examination, reduce the risk of the examiner straying into areas irrelevant to the claim. Adding a request that the examiner address Generative AI use expressly costs a sentence and closes the gap before it opens.

Source: [The Medical Report Now Has to Declare Its AI](https://theaicommand.com/workers-comp/art-expert-evidence-ai-disclosure#faq-4)

### What should a scheme operator never do with AI in claims?

Never send unredacted claim data to an undocumented tool, treat an AI summary as a substitute for the source documents in a load-bearing decision, let an AI-drafted determination letter leave without case manager review, act on AI-flagged patterns without verifying them against sample claims, or run AI-influenced decisions with no file note record.

Source: [AI Tools in Workers Compensation Claims: Where Value, Where Risk, Where Governance](https://theaicommand.com/workers-comp/ai-tools-in-claims#faq-5)

### What should AI never do with medical evidence in a claim?

AI must not weigh competing medical evidence, apply the section 16 reasonableness test, perform causation analysis under section 14 and section 5B, or judge credibility on disputed history. These require human judgement with the rigour the SRC Act expects. Any AI output that opines on reasonableness or causation is out of scope.

Source: [Treating Practitioner Reports and AI: Where the Workflow Helps and Where It Hurts](https://theaicommand.com/workers-comp/treating-practitioner-reports-and-ai#faq-2)

### What should happen when the AI work-up finds gaps in the file?

A person goes and fills them. If the file holds no functional measure, no stated goal or no current treating practitioner review, the answer is a request back to the practitioner, not a model estimate. The work-up is valuable precisely because it names the gaps instead of papering over them. Asking the model to fill a gap converts missing evidence into invented evidence.

Source: [AI Can Build the Section 16 Picture, Not Make the Call](https://theaicommand.com/workers-comp/ai-section-16-reasonable-medical-treatment#faq-5)

### What should I gather before using AI to organise recovery-at-work information?

Gather combined evidence first: the current medical certificate, treating practitioner guidance, supervisor input on real and available duties, and employee feedback, plus review history. Only then use AI to draft a view of possible duties, restrictions, hazards, review questions and evidence gaps for human checking.

Source: [AI Can Organise Recovery-at-Work Information, but People Must Decide](https://theaicommand.com/workers-comp/ai-recovery-at-work-and-suitable-duties#faq-2)

### What should I never do when using AI on a statutory review of this scale?

Do not paste sensitive internal or Cabinet-in-confidence material into a shared endpoint without confirming data classification rules. Do not let AI draft the submission itself. Do not assume the model has read the report; enforce the citation rule. And do not run the workflow once and stop, since consultation is iterative.

Source: [Leveraging AI to assist dissecting the SRC Act Review](https://theaicommand.com/workers-comp/src-act-review-2025-and-ai#faq-5)

### What should I record in the file note when I use AI on a claim?

Capture the AI's role at the time of decision, not retrospectively. Record which tool was used, what data was sent to it, what the output was, and how the case manager engaged with it. Retrospective reconstruction of the AI's role is significantly harder than capture at the moment of decision.

Source: [AI Tools in Workers Compensation Claims: Where Value, Where Risk, Where Governance](https://theaicommand.com/workers-comp/ai-tools-in-claims#faq-4)

### What should the file note record for an AI assisted determination?

Most scheme operators use a four-line standard: the AI tool and version used, the specific purpose the AI served, confirmation that inputs were de-identified, and a statement that the case manager reviewed and edited the output so the issued text reflects their own reasoning. Four lines, defensible at audit.

Source: [SRC Act and AI Assisted Determinations: A Practitioner Framework](https://theaicommand.com/workers-comp/src-act-and-ai-assisted-determinations#faq-5)

### When should a scheme operator switch off a deployed triage model?

Three conditions justify pausing the model: calibration drift exceeding tolerance so predictions are no longer reliably informative, a systematic bias finding that is not promptly addressable, and vendor changes to the underlying behaviour that the operator has not yet assessed. A paused model can be switched back on once issues are resolved.

Source: [Predictive Analytics and Claims Triage: A Risk Analysis for Scheme Operators](https://theaicommand.com/workers-comp/predictive-analytics-and-claims-triage#faq-5)

### When should AI not be used for SRC Act determinations?

Avoid AI drafting for significant degree disease claims under section 5B, credibility-driven determinations, and determinations involving the interaction of multiple Act provisions such as sections 14, 16, 19 and 24 together. In these, review cost outweighs drafting savings. AI is still useful for narrower sub-tasks like summarisation.

Source: [SRC Act and AI Assisted Determinations: A Practitioner Framework](https://theaicommand.com/workers-comp/src-act-and-ai-assisted-determinations#faq-4)

### When should existing treating-practitioner information be used?

The Guide for Arranging Rehabilitation Assessments and Requiring Examinations 2024 requires the rehabilitation authority to first consider whether existing information is sufficient. If it is insufficient or inconsistent, further information or clarification should be sought from the employee's treating practitioner, and the authority should rely on the treating practitioner as much as possible before involving an independent assessor. The authorised person applies the Guide to the circumstances and records the decision.

Source: [AI Can Organise a Section 36 Rehabilitation Assessment. It Cannot Choose the Program](https://theaicommand.com/workers-comp/src-act-section-36-ai-rehabilitation-assessment#faq-3)

### When should I re-identify the AI output back to real claimant details?

Re-identify only at the final write step, never as an intermediate one. All review and editing happens with placeholders intact, which keeps any discussion privacy safe. When ready to write the final text, run a controlled find and replace from placeholders back to real values inside your case management system, not in the AI tool.

Source: [The De-Identification Toolkit for Case Managers Working With AI](https://theaicommand.com/workers-comp/de-identification-toolkit-for-case-managers#faq-4)

### Where are AI tools actually being used in workers compensation claims?

AI operates across five production workflows in Australian schemes: intake and initial triage, decision support on liability, communications drafting, document analysis and case file review, and quality assurance with pattern detection. Each carries genuine value alongside specific risks, so each needs its own governance baseline rather than a single blanket control.

Source: [AI Tools in Workers Compensation Claims: Where Value, Where Risk, Where Governance](https://theaicommand.com/workers-comp/ai-tools-in-claims#faq-1)

### Which sections of the SRC Act does the reasonable-excuse test apply to?

SRC345 applies the same concept across sections 36(4), 37(7), 57(2), 58 and 118. Suspension for failing a section 36 rehabilitation examination, a section 37 program or a section 57 medical examination is made under sections 36(4), 37(7) or 57(2) and is a determination. A reasonable-excuse assessment on a refusal to deal with a claim under section 58, or a suspension under section 118, is not a determination.

Source: [Reasonable Excuse Under the SRC Act: AI Can Structure the Analysis, Not Make the Finding](https://theaicommand.com/workers-comp/reasonable-excuse-under-the-src-act-and-ai#faq-2)

### Which SRC Act provisions drive these recovery conversations?

Three provisions generate most difficult calls. Section 36 covers assessing an employee's capability of undertaking a rehabilitation program. Section 37 covers providing rehabilitation programs and considers the employee's attitude. Section 40 places a duty on the employer to take all reasonable steps to provide suitable employment. Conversations about what counts as suitable are where trust is most easily lost.

Source: [AI Can Draft Recovery Conversation Scripts, but the Listening Stays Human](https://theaicommand.com/workers-comp/ai-drafted-motivational-interviewing-scripts#faq-4)

### Which words should the chronology tool never use, and why?

Block terms that imply a determination the delegate has not made: accepted, rejected, liable, unreasonable and non-compliant. They suggest decisions reserved under sections 14 and 5A. Use neutral alternatives instead, such as event recorded pending review, gap or question flagged for delegate, and management action flagged for s5A review.

Source: [Build a WC Evidence Chronology Tool Without Outsourcing Judgement](https://theaicommand.com/workers-comp/offline-wc-evidence-chronology-builder#faq-4)

### Why does AI-assisted file note and evidence summary drafting still need human checking?

AI can format notes but must not become the source of truth. A reviewer must verify that every factual statement is traceable to a source document, that SRC Act references and review rights are accurate, and that no legal or medical conclusion has been invented. These are requirements AI cannot be left to approximate.

Source: [Prompt Libraries Make WC AI Safer Only When Human Review Comes First](https://theaicommand.com/workers-comp/wc-prompt-libraries-and-human-review#faq-3)

### Why does it matter whether a reasonable-excuse decision is a determination?

Because the review pathway differs. A suspension under sections 36(4), 37(7) or 57(2) is a determination that can be reconsidered and then reviewed by the Administrative Review Tribunal, so the reasons must withstand that scrutiny. A decision under sections 58 or 118 is not a determination and is not reconsidered, but it can be challenged by judicial review, so procedural fairness and a clear written record still matter.

Source: [Reasonable Excuse Under the SRC Act: AI Can Structure the Analysis, Not Make the Finding](https://theaicommand.com/workers-comp/reasonable-excuse-under-the-src-act-and-ai#faq-4)

### Why does the SRC Act Review matter to employers before legislation is passed?

The review produced 124 recommendations, not legislation. Submissions, consultation forums and stakeholder input happen on the recommendation set, not the bill. An employer who waits for the bill is six to twelve months too late, so forming a coherent organisational position during consultation is the priority.

Source: [Leveraging AI to assist dissecting the SRC Act Review](https://theaicommand.com/workers-comp/src-act-review-2025-and-ai#faq-4)

### Why is AI confidence language a problem in determinations?

AI tools tend to write with assertive, confident prose that reads well at the desk but can read as overstatement at review. Over-confident wording that asserts more than the evidence supports is a long-standing review risk. Every confident assertion must be earned by evidence on file, or the paragraph should be rewritten.

Source: [Reading the Reasoning Trail: A Case Note on AI Drafted Determinations](https://theaicommand.com/workers-comp/hansen-v-comcare-2026-art-412-case-note#faq-4)

### Why must the reasonableness call stay with a human?

The reasonableness test is not prescriptive. There may be more than one reasonable way to take an action, and the question is whether what was done was reasonable in the circumstances. That is a contextual, evidence-weighing judgement that depends on what the employer knew at the time and on the particular employee. A determination has to survive reconsideration and Administrative Review Tribunal review on the strength of the human reasoning.

Source: [AI and the Reasonable Administrative Action Exclusion: Map the Actions, Keep the Judgement](https://theaicommand.com/workers-comp/ai-and-the-reasonable-administrative-action-exclusion#faq-5)

## HR and employment

Fair Work, privacy, hiring, and AI in people processes.

### Can a candidate sue if an AI tool screens them out?

Potentially under several regimes. They may bring an indirect discrimination claim under the Sex Discrimination Act if the tool disadvantages a protected group, or a general protections claim under section 351 of the Fair Work Act, which protects prospective employees. The AHRC can also inquire into the employer's compliance with the positive duty independently of any complaint.

Source: [AI Hiring and Performance Tools Under Australia's Positive Duty: What HR Must Control](https://theaicommand.com/hr/ai-positive-duty-hiring-performance#faq-2)

### Can AI decide whether an employer has reasonable business grounds?

No. Reasonable business grounds under section 65A of the Fair Work Act depend on the employer, the role, the request, the evidence, the consultation and the consequences of refusal. AI can organise those inputs, but an authorised human must make the decision and obtain advice where needed.

Source: [AI Can Map a Flexible Work Request. It Cannot Decide Reasonableness](https://theaicommand.com/hr/ai-map-flexible-work-request-reasonableness#faq-1)

### Can AI grade a workplace practice simulation?

It can organise transcript evidence or draft coaching observations. It should not make a consequential pass, competence or employment decision. Use a defined standard and an authorised human who can consider context, adjustments and evidence quality.

Source: [Use AI to Build Practice Simulations, Not to Award the Pass](https://theaicommand.com/hr/ai-practice-simulations-human-assessment-standard#faq-1)

### Can AI monitoring create a work health and safety problem?

Yes. Under model WHS laws a PCBU must manage psychosocial risks so far as is reasonably practicable. Intrusive or constant surveillance can reduce job control and increase stress, both psychosocial hazards in the Safe Work Australia model Code. Assess and control these risks before deployment, not after a complaint.

Source: [AI Worker Monitoring in Australia: What HR Can and Cannot Do](https://theaicommand.com/hr/ai-workplace-monitoring-australia#faq-5)

### Can AI write a witness statement for the Fair Work Commission?

The draft guidance recommends generative AI not be used to create the substantive content of a witness statement or declaration at all. If AI helps edit or format one, the witness must read it, correct it so it reflects their own knowledge, and declare in the document that it is true and based on what they personally know.

Source: [The Fair Work Commission's Three Rules for AI in a Case](https://theaicommand.com/hr/fwc-three-rules-for-ai-in-a-case#faq-3)

### Can an AI agent make an HR decision about an employee?

An agent can draft, summarise or flag, but a human must own any decision that significantly affects an employee. Under the general protections in the Fair Work Act, if an agent's output drives a performance, disciplinary or termination outcome, the employer carries a reverse onus to show a protected reason played no part. Build the human decision point into the workflow rather than letting the agent's output stand as the decision.

Source: [Your HRIS Now Lets Anyone Build an Agent](https://theaicommand.com/hr/your-hris-now-lets-anyone-build-an-agent#faq-4)

### Can an applicant be ordered to pay costs for AI-invented authorities?

The Commission is ordinarily a no-costs jurisdiction, but section 611 of the Fair Work Act allows costs where a matter is pursued vexatiously or without reasonable cause. In Hoverd v M & J D Pty Ltd the Commission invited the employer to seek costs after the applicant kept relying on non-existent clauses once they had been challenged.

Source: [When the Other Side's AI Invents the Law](https://theaicommand.com/hr/ai-invented-citations-in-fair-work-claims#faq-4)

### Can an employer propose a different arrangement instead?

Yes. Following discussion, the parties can agree to a change that differs from the one requested. Where that happens, the employer must set out the agreed change in its written response within the 21 day statutory period, per section 65A(2)(b) of the Fair Work Act and Fair Work Ombudsman guidance.

Source: [AI Can Map a Flexible Work Request. It Cannot Decide Reasonableness](https://theaicommand.com/hr/ai-map-flexible-work-request-reasonableness#faq-3)

### Can anyone in HR now build an AI agent?

Effectively yes. Workday's Developer Agent lets a person describe an agent in plain language and have it built in minutes inside the HR system, and general-purpose tools like ChatGPT Enterprise and Claude Cowork already let anyone assemble one. The real question is no longer whether HR can build an agent, but who should be authorised to, and what has to be true before it touches live employee data.

Source: [Your HRIS Now Lets Anyone Build an Agent](https://theaicommand.com/hr/your-hris-now-lets-anyone-build-an-agent#faq-1)

### Can HR use a real employee case with the name removed?

That is risky. A distinctive combination of role, event, dates and personal circumstances may still identify someone, and the OAIC treats information about a reasonably identifiable individual as personal information. Build synthetic facts and placeholders rather than lightly disguising a real file.

Source: [Use AI to Build Practice Simulations, Not to Award the Pass](https://theaicommand.com/hr/ai-practice-simulations-human-assessment-standard#faq-2)

### Can I paste sensitive investigation material into a consumer AI model?

No. Classified, confidential or sensitive information should never be disclosed to open-source AI tools or any tool not approved for use. The practical rule: if you would not email the document to a stranger, do not paste it into a consumer model. Use only tools your organisation has assessed and approved.

Source: [AI in Workplace Investigations: Organise the File, Not the Finding](https://theaicommand.com/hr/ai-in-workplace-investigations#faq-3)

### Can I use AI to run reference and background checks?

Use AI for the admin: drafting a consistent set of reference questions, capturing structured notes, and summarising what a referee said so nothing is missed. Do not use it to auto-generate a candidate risk score, scrape social media by default, or decide whether to hire. The Privacy Act limits what you collect and a person must own the decision.

Source: [AI in Reference and Background Checks: Verify Facts, Not Character](https://theaicommand.com/hr/ai-reference-and-background-checks#faq-1)

### Can I use AI to work out an employee's correct pay under a modern award?

Use AI to read and explain a clause and to build a checklist of what to confirm, but never to set the rate. A model states figures as fact with no signal it might be wrong or out of date. Every rate, penalty, threshold and allowance must be verified against the award and the Fair Work Ombudsman Pay and Conditions Tool, and a person makes and records the decision.

Source: [AI Can Read the Award. It Cannot Set the Pay.](https://theaicommand.com/hr/ai-can-read-the-award-not-set-the-pay#faq-1)

### Can managers use AI to write performance management documents?

Yes, for the drafting and structure, with a hard boundary. AI is genuinely useful for turning rough notes into a clear, neutral warning or improvement plan and for checking tone and completeness. It must not be the source of the facts. Every incident, date, policy reference and quotation in the document has to be verified by the manager against the real record before it is used, because the document may end up as evidence in an unfair-dismissal claim.

Source: [AI Can Draft the Warning. It Cannot Fake the Facts.](https://theaicommand.com/hr/ai-performance-management-documents-procedural-fairness#faq-1)

### Can the other side use AI to prepare a Fair Work claim?

Yes. The Commission has not banned it. But an applicant who relies on AI-generated cases or award clauses that do not exist can have the claim dismissed and, as in Hoverd v M & J D, face an application for costs. As the respondent, your task is to verify what the other side cites, not to assume it is real.

Source: [When the Other Side's AI Invents the Law](https://theaicommand.com/hr/ai-invented-citations-in-fair-work-claims#faq-1)

### Can we paste employee data into ChatGPT during a restructure?

Not into a public or unapproved tool. The Privacy Act's employee records exemption gives employers some latitude with their own records, but it does not safely extend to disclosing sensitive employee information to an external AI service, and collecting sensitive information generally needs consent. Use an approved, contained tool with names left out, or fully de-identify the data before it goes anywhere near a model.

Source: [AI Can Build the Redundancy. It Cannot Decide It](https://theaicommand.com/hr/ai-redundancy-restructure-consultation-selection-2026#faq-4)

### Can we put candidate resumes into a public AI chatbot to summarise them?

Not safely. The OAIC's 2024 AI guidance treats personal information entered into a commercial AI product as attracting Australian Privacy Principle obligations, including use limits under APP 6 and accuracy under APP 10. Candidate data should only go into an approved, contracted system that has been assessed for privacy, not a general consumer chatbot.

Source: [AI Hiring and Performance Tools Under Australia's Positive Duty: What HR Must Control](https://theaicommand.com/hr/ai-positive-duty-hiring-performance#faq-5)

### Can we use AI to select employees for redundancy?

No. AI can help design fair, role-related selection criteria, but it should never score or rank named employees. A model's ranking can encode proxies for protected attributes such as age or carer's responsibilities through variables like tenure or leave patterns, and discrimination law applies whether a decision is made by a human or a machine. If you cannot explain a selection in terms a person chose and can defend, the process is exposed.

Source: [AI Can Build the Redundancy. It Cannot Decide It](https://theaicommand.com/hr/ai-redundancy-restructure-consultation-selection-2026#faq-1)

### Did the Commission treat using AI as misconduct?

No. The Deputy President assessed the conduct, which was an inordinate volume of demanding and overbearing communications, a refusal to accept investigation outcomes and dishonesty. The use of AI was considered separately, as possible mitigation, and rejected on the basis that the employee had taken responsibility for the communications. The tool was not the wrong, and it was not the excuse.

Source: [AI Did Not Send Those Emails. Your Employee Did.](https://theaicommand.com/hr/ai-is-not-an-explanation-for-conduct#faq-1)

### Do Australian employers need employee consent to monitor workers with AI?

Generally no, but you need notice. NSW and ACT surveillance laws require written advance notice, not consent. The Privacy Act requires notification under APP 5 and collection that is reasonably necessary under APP 3. Consent matters most for sensitive information and for shortening the NSW 14 day notice period.

Source: [AI Worker Monitoring in Australia: What HR Can and Cannot Do](https://theaicommand.com/hr/ai-workplace-monitoring-australia#faq-1)

### Do Australian privacy rules apply to an agent an HR team builds itself?

Yes, in full. The Privacy Act applies the moment the agent collects, uses or holds employee personal information. You must collect only what is reasonably necessary under APP 3, notify people under APP 5, use the data only for the purpose it was collected under APP 6, and secure it under APP 11. From 10 December 2026 your privacy policy must also disclose where a computer program significantly drives a decision about a person.

Source: [Your HRIS Now Lets Anyone Build an Agent](https://theaicommand.com/hr/your-hris-now-lets-anyone-build-an-agent#faq-3)

### Do candidates have to be told they are being interviewed by an AI, not a person?

Telling candidates is both good practice and the direction of the law. The Privacy Act requires notification about how personal information is collected and used, and from 10 December 2026 your privacy policy must disclose where a computer program makes or substantially drives a decision that significantly affects someone. A clear candidate notice before an AI screening interview is the practical way to meet that expectation.

Source: [Your Recruiter Is Now an Agent, Not a Search Box](https://theaicommand.com/hr/ai-recruiting-agent-screens-before-a-human#faq-2)

### Do I have to consult employees before introducing AI monitoring?

Often yes. Most modern awards and enterprise agreements contain a consultation term covering major change, including new technology likely to significantly affect employees. You must notify affected workers and representatives, discuss the change, provide written information and consider their views. Consultation also helps discharge WHS psychosocial duties.

Source: [AI Worker Monitoring in Australia: What HR Can and Cannot Do](https://theaicommand.com/hr/ai-workplace-monitoring-australia#faq-4)

### Does an AI rollout with no redundancies trigger consultation?

It can. The trigger in the model consultation term is a definite decision to introduce a major change to technology that is likely to have a significant effect on employees. Significant effect is then defined to include a major change in the composition, operation or size of the workforce or to the skills required of employees, and the need for employees to be retrained or transferred to other work. Termination of employment is only one limb of seven. Any single limb is enough.

Source: [Your AI Rollout Triggers a Clause You Already Signed](https://theaicommand.com/hr/ai-rollout-triggers-your-consultation-clause#faq-1)

### Does an employer need a specific AI policy to act on AI-related conduct?

Conduct standards that already exist, covering confidentiality, accuracy, respectful communication and honesty, do most of the work. A specific AI policy earns its place by removing ambiguity about what is approved, what must be verified, what must never be entered into a tool, and whether use must be disclosed. Ambiguity is the practical problem: Australian survey data suggests only a minority of employees think leadership expectations about AI use are clear.

Source: [AI Did Not Send Those Emails. Your Employee Did.](https://theaicommand.com/hr/ai-is-not-an-explanation-for-conduct#faq-3)

### Does recording every meeting create a work health and safety risk?

It can. Under the model WHS laws, a person conducting a business or undertaking must manage the risk of psychosocial hazards, and the recognised hazards include low job control. Always-on capture erodes autonomy and can make people feel watched in the very conversations that should feel safe. The control is the same one the protocol gives you, capture by exception, with consent, never by default.

Source: [AI Note-Takers in HR Meetings: Consent Before the Transcript](https://theaicommand.com/hr/ai-note-takers-in-hr-meetings#faq-5)

### Does the employee records exemption cover job applicants?

No. The OAIC states that the exemption does not cover future employment relationships, so it does not apply to the collection of personal information about prospective employees who are subsequently not employed, such as unsuccessful job applicants. The OAIC also notes that once an employment relationship is formed, the records the employer holds relating to that individual's pre-employment checks become exempt.

Source: [Your Employee Data Is Exempt. That Is Not Permission.](https://theaicommand.com/hr/employee-records-exemption-and-ai#faq-2)

### Does the exemption cover an HR vendor or outsourcer?

No. The OAIC states that the exemption does not cover contractors and subcontractors when they handle the personal information of the employees of another organisation, notwithstanding their contractual arrangements, and gives recruitment, human resource management, medical, training and superannuation service providers as examples. A contractor that collects employee records from an employer must comply with the Australian Privacy Principles, including the notice requirements in APP 5.

Source: [Your Employee Data Is Exempt. That Is Not Permission.](https://theaicommand.com/hr/employee-records-exemption-and-ai#faq-3)

### Does the Fair Work Commission allow generative AI in a case?

Yes, but with conditions. The Commission's draft guidance does not ban generative AI. It requires you to disclose that AI was used in any lodged document, to verify every factual, legislative and case-law reference against an authoritative source rather than against the AI, and to keep AI out of the substantive content of witness statements and declarations.

Source: [The Fair Work Commission's Three Rules for AI in a Case](https://theaicommand.com/hr/fwc-three-rules-for-ai-in-a-case#faq-1)

### Does the new privacy law affect how we advertise jobs?

It can. The OAIC's automated decision-making transparency work notes that using computer programs to target individuals with content and advertisements may have a significant effect on a person if it limits access to employment opportunities. From 10 December 2026, entities that use personal information in automated decision-making that could significantly affect a person must describe it in their privacy policy. If your recruitment advertising relies on algorithmic targeting of personal information, that is worth mapping now, but the immediate issue is fairness of delivery, not just disclosure.

Source: [AI Decides Who Sees Your Job Ad. That Is a Hiring Decision.](https://theaicommand.com/hr/ai-job-ad-targeting-who-sees-the-ad#faq-3)

### Does the positive duty apply to small businesses using a single AI hiring tool?

Yes. The positive duty in section 47C of the Sex Discrimination Act applies to all employers and businesses with obligations under the Act, regardless of size. What counts as reasonable and proportionate scales with the organisation's size and resources, so a small business is expected to do less than a large one, but the duty still applies.

Source: [AI Hiring and Performance Tools Under Australia's Positive Duty: What HR Must Control](https://theaicommand.com/hr/ai-positive-duty-hiring-performance#faq-1)

### Does the Privacy Act apply when HR puts employee data into an AI tool?

It depends on who you are and what the act is. Section 7B(3) exempts a private sector employer where the act or practice is directly related to a current or former employment relationship and to an employee record the employer holds. If either limb fails, for example because the person is an unsuccessful applicant or a volunteer, the Australian Privacy Principles apply in the ordinary way. Australian Government agencies cannot rely on the exemption because section 6C excludes an agency from the definition of an organisation.

Source: [Your Employee Data Is Exempt. That Is Not Permission.](https://theaicommand.com/hr/employee-records-exemption-and-ai#faq-1)

### Does this change how we prepare our own responses?

Yes. Apply the same verification to every authority you cite. The discipline that catches the other side's fabrication is the same discipline that keeps one out of your own filing.

Source: [When the Other Side's AI Invents the Law](https://theaicommand.com/hr/ai-invented-citations-in-fair-work-claims#faq-5)

### How can a job ad discriminate if the wording is neutral?

Because who wrote the ad and who sees it are two different decisions. Once you publish, the platform's delivery algorithm chooses which users are actually shown the ad, and it optimises for who it predicts will engage. Predicted engagement correlates with attributes like gender and age, so the delivered audience can skew even when your targeting was broad and inclusive. A 2019 study of real employment and housing ads found significant skew in delivery along gender and racial lines despite neutral targeting parameters. The wording being clean does not make the delivery neutral.

Source: [AI Decides Who Sees Your Job Ad. That Is a Hiring Decision.](https://theaicommand.com/hr/ai-job-ad-targeting-who-sees-the-ad#faq-1)

### How do I set AI expectations for a new hire on their first day?

Have a five-minute conversation in week one covering which AI tools your organisation has approved and pays for, what they must never paste into a public tool, and where the grounded onboarding assistant lives. People told the rules on day one tend to follow them before a bad habit forms.

Source: [AI-Assisted Onboarding: A 90-Day Plan That Keeps the Human In](https://theaicommand.com/hr/ai-assisted-onboarding-90-day-plan#faq-5)

### How do I use AI for onboarding without giving new starters wrong information?

Build a reusable project in ChatGPT Projects or Claude Projects with custom instructions and your uploaded documents, so the assistant answers only from your real materials. Without grounding documents, a confident answer is just a guess, and a week-one starter cannot tell confident from correct.

Source: [AI-Assisted Onboarding: A 90-Day Plan That Keeps the Human In](https://theaicommand.com/hr/ai-assisted-onboarding-90-day-plan#faq-1)

### How do I use AI on a meeting transcript safely?

Use it only on a consented, de-identified copy, and only to draft. Remove names and identifiers, paste the transcript into your organisation's enterprise ChatGPT or Claude workspace rather than a public consumer tool, and ask for a fact-only action summary of decisions, owners and due dates. A person then verifies the draft and the raw transcript is deleted or locked down per your retention rule.

Source: [AI Note-Takers in HR Meetings: Consent Before the Transcript](https://theaicommand.com/hr/ai-note-takers-in-hr-meetings#faq-3)

### How do I use AI to analyse engagement survey comments without it becoming surveillance?

Run a five-step workflow: de-identify comments before anything goes near a model, theme only at the aggregate level with paraphrases not verbatim quotes, set a minimum group size of five or ten, keep a human reading the themes, and close the loop without scoring people.

Source: [AI Can Analyse Your Engagement Survey Without Surveilling Your People](https://theaicommand.com/hr/ai-engagement-survey-analysis-without-surveillance#faq-1)

### How do you assess a candidate when everyone's application looks strong?

Shift the weight from the application to demonstrated capability. Use a short, role-relevant skills task, a structured behavioural interview with the same questions and scoring for every candidate, and where practical a supervised work sample that shows how the person actually works, including how they use AI. The application becomes a filter for basic requirements, not the thing you hire on.

Source: [Every Application Now Reads Perfectly. Assess the Person.](https://theaicommand.com/hr/ai-generated-applications-assess-the-person#faq-3)

### How do you tell if a cited case was invented by AI?

Check it at the source. A fabricated authority usually has a plausible name but returns nothing in the FWC decisions database or on AustLII, a citation number that does not resolve, or a quoted passage that is nowhere in the judgment. An award clause cited by a number that is not in the current instrument is another common tell.

Source: [When the Other Side's AI Invents the Law](https://theaicommand.com/hr/ai-invented-citations-in-fair-work-claims#faq-2)

### How do you verify an AI-drafted submission for the Fair Work Commission?

You check every claim against a primary source, and never against the AI that produced it. The Commission points to its own Benchbooks, its decisions database, AustLII for court judgments, and the Federal Register of Legislation for statutes and regulations. A generative tool cannot be used to verify its own output.

Source: [The Fair Work Commission's Three Rules for AI in a Case](https://theaicommand.com/hr/fwc-three-rules-for-ai-in-a-case#faq-2)

### How does AI affect procedural fairness in an investigation?

A model that drafts a likely finding before the person is interviewed has quietly prejudged the matter, and a process that prejudges fails. Assessing credibility, weighing evidence, making findings and ensuring fairness are the investigator's responsibilities, not AI tools. An investigator also cannot lean on a model's confident, fluent tone.

Source: [AI in Workplace Investigations: Organise the File, Not the Finding](https://theaicommand.com/hr/ai-in-workplace-investigations#faq-4)

### How long does an employer have to respond to a flexible work request?

Under section 65A of the Fair Work Act, an employer must give the employee a written response within 21 days of receiving a valid request made under the National Employment Standards. The Fair Work Ombudsman confirms the response must state whether the request is granted or refused, and a refusal must meet the statutory requirements.

Source: [AI Can Map a Flexible Work Request. It Cannot Decide Reasonableness](https://theaicommand.com/hr/ai-map-flexible-work-request-reasonableness#faq-2)

### How should a manager raise AI-assisted communication that has become a problem?

Address the observable conduct, not the tool. Name the specific behaviour, its effect on others and the standard expected, and separate that from any substantive complaint the employee has raised, which still has to be dealt with on its merits. A conversation framed as stop using AI invites a dispute about the tool and leaves the actual conduct standard unstated.

Source: [AI Did Not Send Those Emails. Your Employee Did.](https://theaicommand.com/hr/ai-is-not-an-explanation-for-conduct#faq-4)

### How should HR test the simulation for fairness?

Pilot it with varied users, change demographic details that should not affect performance, test reasonable adjustments and compare scenario difficulty. Record failures and require human review before release.

Source: [Use AI to Build Practice Simulations, Not to Award the Pass](https://theaicommand.com/hr/ai-practice-simulations-human-assessment-standard#faq-5)

### How should I handle complaints that may have been written with AI?

The Fair Work Commission has seen a sharp rise in AI-prepared applications, some containing invented citations, misstated law or facts that do not match the person's circumstances. A fluent, authority-citing complaint is not, for that reason, well founded. Verify the substance, do not be moved by the tone.

Source: [AI in Workplace Investigations: Organise the File, Not the Finding](https://theaicommand.com/hr/ai-in-workplace-investigations#faq-5)

### How strictly do regulators read "directly related"?

Strictly. In 'ALI' and 'ALJ' (Privacy) [2024] AICmr 131, decided on 20 June 2024, the Australian Privacy Commissioner adopted the reading that the act or practice must be directly related to the employment relationship and not merely have an indirect, consequential or remote effect on it, denoting an absolute or exact connection. An email to 110 staff naming an employee and describing her health was held to relate directly to the employer's relationship with the other staff, not with her, so the exemption did not apply.

Source: [Your Employee Data Is Exempt. That Is Not Permission.](https://theaicommand.com/hr/employee-records-exemption-and-ai#faq-4)

### Is a return-to-office policy enough to refuse a request?

Not by itself. The employer must follow the statutory process in section 65A, including discussing the request, genuinely trying to reach agreement, considering the consequences of refusal and explaining how reasonable business grounds apply to the particular request. Policies and employment instruments matter, but individual facts and consultation still decide the outcome.

Source: [AI Can Map a Flexible Work Request. It Cannot Decide Reasonableness](https://theaicommand.com/hr/ai-map-flexible-work-request-reasonableness#faq-4)

### Is covert AI monitoring of staff legal in Australia?

In NSW it is prohibited unless authorised by a magistrate through a covert surveillance authority, which is limited to investigating suspected unlawful activity. The ACT similarly restricts covert surveillance. As a rule, never run undisclosed AI monitoring of workers without notice and a clear lawful basis.

Source: [AI Worker Monitoring in Australia: What HR Can and Cannot Do](https://theaicommand.com/hr/ai-workplace-monitoring-australia#faq-3)

### Is discriminatory job advertising unlawful in Australia?

Yes. Section 86 of the Sex Discrimination Act 1984 makes it unlawful to publish or display an advertisement that indicates, or could reasonably be understood as indicating, an intention to do something that is unlawful under Part II of the Act, which includes discrimination in employment. The Age Discrimination Act 2004 and the Disability Discrimination Act 1992 contain equivalent prohibitions on discriminatory advertisements. The law is written for the content of an ad, and the harder modern question is what happens to a lawful ad once an algorithm delivers it.

Source: [AI Decides Who Sees Your Job Ad. That Is a Hiring Decision.](https://theaicommand.com/hr/ai-job-ad-targeting-who-sees-the-ad#faq-2)

### Is it legal in Australia to let an AI agent screen job candidates before a human sees them?

Yes, but the whole existing framework still applies. An AI screen that filters candidates before a person reviews them is automated decision-making affecting someone's interests. You must collect only what is reasonably necessary, notify candidates, keep the process free of discrimination under the Fair Work Act and anti-discrimination laws, and keep a human accountable for the outcome. The tool does not shift the legal responsibility off the employer.

Source: [Your Recruiter Is Now an Agent, Not a Search Box](https://theaicommand.com/hr/ai-recruiting-agent-screens-before-a-human#faq-1)

### Is it legal to screen a candidate's social media with AI?

It is high risk. Automated social-media scraping collects personal and often sensitive information that is rarely reasonably necessary for the role, is frequently inaccurate or about the wrong person, and can surface protected attributes that then taint the decision, exposing you to adverse action claims under the Fair Work Act. If you screen at all, scope it tightly, get consent, and keep a person in the loop.

Source: [AI in Reference and Background Checks: Verify Facts, Not Character](https://theaicommand.com/hr/ai-reference-and-background-checks#faq-3)

### Is it legal to use an AI note-taker in a meeting in Australia?

The Privacy Act does not specifically cover workplace surveillance; state and territory laws do, and they are strict. In NSW, the Surveillance Devices Act 2007 (section 7) makes it an offence to record a private conversation, even one you are part of, unless all principal parties consent. The safe operating rule everywhere is all-party consent before anything records.

Source: [AI Note-Takers in HR Meetings: Consent Before the Transcript](https://theaicommand.com/hr/ai-note-takers-in-hr-meetings#faq-1)

### Is relying on AI a defence if pay is wrong?

No. The Fair Work Ombudsman Voluntary Small Business Wage Compliance Code gives small businesses a path to avoid criminal referral where they have taken reasonable steps to pay correctly. The AI told me the rate is not reasonable steps. Documented verification against the award and the Pay and Conditions Tool, with a human sign-off, is.

Source: [AI Can Read the Award. It Cannot Set the Pay.](https://theaicommand.com/hr/ai-can-read-the-award-not-set-the-pay#faq-5)

### Is the employee records exemption being removed?

Not as at the time of writing. In its response to the Privacy Act Review Report, released on 28 September 2023, the Government agreed in principle that further consultation should be undertaken with employer and employee representatives on how enhanced privacy protections for private sector employees may be implemented in legislation, which was proposal 7.1. The Privacy and Other Legislation Amendment Act 2024 progressed 23 proposals from that response and did not change section 7B(3), which remains in the Act. Plan for the law as it is.

Source: [Your Employee Data Is Exempt. That Is Not Permission.](https://theaicommand.com/hr/employee-records-exemption-and-ai#faq-5)

### Should a candidate be able to ask for a human instead of the AI screen?

Offering a human alternative is prudent, and in some cases required as a reasonable adjustment. A candidate with a disability, or one who cannot complete a video assessment for a reason unrelated to the role, may need an accommodation. Build a simple, visible route for a candidate to request an adjustment or a human screen, and make sure declining the AI format does not itself count against them.

Source: [Your Recruiter Is Now an Agent, Not a Search Box](https://theaicommand.com/hr/ai-recruiting-agent-screens-before-a-human#faq-5)

### Should AI record a grievance or disciplinary meeting?

No. Grievances, complaints, disciplinary meetings, terminations and anything touching health sit in a never-auto-record bucket and are often manual-notes-only. These are the conversations people most need to feel safe in, and an unverified transcript should never stand in for a finding.

Source: [AI Note-Takers in HR Meetings: Consent Before the Transcript](https://theaicommand.com/hr/ai-note-takers-in-hr-meetings#faq-2)

### Should participants be told AI is involved?

Yes. Explain the tool's role, the data collected, access, retention, the review process and whether the activity affects any employment outcome. Provide a way to question errors and raise concerns.

Source: [Use AI to Build Practice Simulations, Not to Award the Pass](https://theaicommand.com/hr/ai-practice-simulations-human-assessment-standard#faq-3)

### Should we try to detect whether a candidate used AI?

No. AI-detection tools are unreliable and produce false positives, and penalising a candidate for suspected AI use is both unfair and legally risky, since it can catch people who simply write well or who used assistive technology. Using AI to apply for a job is now normal. The better response is to stop treating the polished application as evidence of ability and to assess capability directly instead.

Source: [Every Application Now Reads Perfectly. Assess the Person.](https://theaicommand.com/hr/ai-generated-applications-assess-the-person#faq-2)

### Should you accuse a self-represented applicant of using fake AI citations?

Not as your first move. Treat it as a verification gap and ask in writing for the full citation and a copy of each authority. A real one can be produced, a fabricated one cannot, and the applicant can withdraw it. This protects the record and avoids an ambush that can rebound on the representative who launches it.

Source: [When the Other Side's AI Invents the Law](https://theaicommand.com/hr/ai-invented-citations-in-fair-work-claims#faq-3)

### What are the discrimination risks when AI screens candidates?

Refusing to employ someone because of a protected attribute (age, sex, race, disability, family responsibilities and more) is adverse action against a prospective employee under the Fair Work Act. If an AI tool surfaces or infers a protected attribute and it influences the decision, the employer wears the risk. The Sex Discrimination Act positive duty also requires employers to take proactive steps to eliminate discrimination.

Source: [AI in Reference and Background Checks: Verify Facts, Not Character](https://theaicommand.com/hr/ai-reference-and-background-checks#faq-4)

### What are the four onboarding prompts to run inside the assistant?

Run a 30-60-90 plan prompt turning a role description into a structured draft, a role-specific reading map prioritising required compliance reading, a grounded FAQ answering only from uploaded documents, and a structured day-30 check-in held as a human conversation that also surfaces cohort-wide patterns.

Source: [AI-Assisted Onboarding: A 90-Day Plan That Keeps the Human In](https://theaicommand.com/hr/ai-assisted-onboarding-90-day-plan#faq-3)

### What are the legal limits when redesigning hiring around AI?

Selection must stay fair and lawful. Under the Fair Work Act's general protections, adverse action against a job applicant because of a protected attribute is unlawful, so any AI screening you use cannot encode bias. Under the Privacy Act, you can only collect information reasonably necessary for the role and need consent for sensitive information, and offshore screening tools engage cross-border disclosure obligations. Assess capability, not the person's private life.

Source: [Every Application Now Reads Perfectly. Assess the Person.](https://theaicommand.com/hr/ai-generated-applications-assess-the-person#faq-4)

### What are unions doing about AI consultation in Australia?

The ACTU said in February 2026 that it had written to employer peak bodies reminding them of their obligation to consult when they decide to adopt AI, where it is likely to change employees' jobs or how they do them. Assistant Secretary Joseph Mitchell said employers must consult as soon as a decision is made and before implementation, and that the ACTU will coordinate a response to employers who do not, putting them at risk of disputation proceedings and reputation damage.

Source: [Your AI Rollout Triggers a Clause You Already Signed](https://theaicommand.com/hr/ai-rollout-triggers-your-consultation-clause#faq-4)

### What Australian frameworks govern using AI on engagement survey data?

Three apply. Privacy, since free-text comments and inferences are personal information under the Australian Privacy Principles. Psychosocial safety, since the Commonwealth Code of Practice names intrusive surveillance as a recognised hazard. And fairness, since any decision affecting a person must be a human decision made on a fair basis and explained.

Source: [AI Can Analyse Your Engagement Survey Without Surveilling Your People](https://theaicommand.com/hr/ai-engagement-survey-analysis-without-surveillance#faq-4)

### What can AI safely do in a redundancy process?

The preparation. It can model restructure scenarios, assemble the redeployment map the High Court now expects, help design selection criteria, draft the consultation letters and question sheets, and keep the consultation file organised. The decision to make a role redundant, the scoring of individuals, the genuine consultation and the conversation with the person losing their job stay with people.

Source: [AI Can Build the Redundancy. It Cannot Decide It](https://theaicommand.com/hr/ai-redundancy-restructure-consultation-selection-2026#faq-5)

### What changed for pay accuracy in Australia?

Two things shifted at once. From the first full pay period starting on or after 1 July 2026, minimum award wages rise 4.75 per cent and the National Minimum Wage moves to $26.44 an hour. Since 1 January 2025, intentionally underpaying wages or entitlements can be a criminal offence under the Fair Work Act, with severe fines and possible prison time.

Source: [AI Can Read the Award. It Cannot Set the Pay.](https://theaicommand.com/hr/ai-can-read-the-award-not-set-the-pay#faq-3)

### What compliance guardrails apply to AI-assisted onboarding in Australia?

Keep statutory obligations on a checklist a person signs off, since every employee must receive the Fair Work Information Statement and casuals the Casual Employment Information Statement. Protect new-starter personal data, and keep AI on the drafting side of the line, as automated decisions about people may engage Privacy Act rules from 10 December 2026.

Source: [AI-Assisted Onboarding: A 90-Day Plan That Keeps the Human In](https://theaicommand.com/hr/ai-assisted-onboarding-90-day-plan#faq-4)

### What data should be removed before AI use?

Remove names and unnecessary detail about health, disability, caring, pregnancy, family and domestic violence, family members and performance. Use placeholders such as [EMPLOYEE_NAME] and [PROPOSED_ARRANGEMENT], and work only in an approved enterprise system with restricted access.

Source: [AI Can Map a Flexible Work Request. It Cannot Decide Reasonableness](https://theaicommand.com/hr/ai-map-flexible-work-request-reasonableness#faq-5)

### What did Helensburgh Coal v Bartley change for redundancy?

In Helensburgh Coal Pty Ltd v Bartley [2025] HCA 29, the High Court confirmed the Fair Work Commission can ask whether an employer could have reorganised its workforce to redeploy someone, including by insourcing work done by contractors or labour hire. A note that no vacancies existed is no longer the end of the redeployment question, so the redeployment record needs to show the employer genuinely examined reshaping roles and insourcing work.

Source: [AI Can Build the Redundancy. It Cannot Decide It](https://theaicommand.com/hr/ai-redundancy-restructure-consultation-selection-2026#faq-2)

### What did the Commission say about the effect of AI on the employee?

The decision records that his use of AI was unfortunate and counterproductive, that the communications it produced were dense, repetitive and often rambling, demanding and overbearing, and that they lacked context and perspective. It found the use of AI appeared to give him a false sense of security that communications laden with allegations were appropriate in a workplace setting, and that objectively they were not.

Source: [AI Did Not Send Those Emails. Your Employee Did.](https://theaicommand.com/hr/ai-is-not-an-explanation-for-conduct#faq-2)

### What did the June 2026 workplace law change do?

The Workplace Relations Legislation Amendment (Building Cooperative Workplaces No. 1) Bill 2026, introduced on 3 June 2026 and effective 7 July 2026, lets the Commission deal with some dismissal disputes without first holding a jurisdictional hearing, decide suitable matters on the papers, and bar repeat applications already dismissed as having no reasonable prospects.

Source: [The Fair Work Commission's Three Rules for AI in a Case](https://theaicommand.com/hr/fwc-three-rules-for-ai-in-a-case#faq-5)

### What does procedural fairness require in performance management?

In broad terms, the Fair Work Act asks whether there was a valid reason for a dismissal related to the person's capacity or conduct, whether the person was notified of that reason, and whether they were given a real opportunity to respond. AI can help you document each step clearly, but it cannot decide whether a reason is valid, whether a response was genuinely considered, or whether the process was fair. Those are human judgements.

Source: [AI Can Draft the Warning. It Cannot Fake the Facts.](https://theaicommand.com/hr/ai-performance-management-documents-procedural-fairness#faq-3)

### What does the Privacy Act allow me to collect about a candidate?

Under APP 3 you may only collect personal information that is reasonably necessary for the role, and you may only collect sensitive information (such as health or criminal record) with the individual's consent, unless an exception applies. Consent is not inferred just because you gave notice. An AI tool that hoovers up a candidate's whole digital footprint collects far more than is reasonably necessary.

Source: [AI in Reference and Background Checks: Verify Facts, Not Character](https://theaicommand.com/hr/ai-reference-and-background-checks#faq-2)

### What happens if you do not disclose AI use in a Commission document?

The Commission can give the document reduced weight, disregard it, make a costs order, or dismiss the application. A Commission document also carries a declaration of truth, so a knowingly false statement in it is a serious matter that can reach beyond the outcome of the case.

Source: [The Fair Work Commission's Three Rules for AI in a Case](https://theaicommand.com/hr/fwc-three-rules-for-ai-in-a-case#faq-4)

### What if the simulation supports accredited training?

Follow the current training product, the RTO's assessment system, assessor credential rules and evidence requirements. ASQA's assessment guidance applies to RTO assessment under the Standards for RTOs. Obtain qualified advice before relying on an AI-supported activity for a formal competency outcome.

Source: [Use AI to Build Practice Simulations, Not to Award the Pass](https://theaicommand.com/hr/ai-practice-simulations-human-assessment-standard#faq-4)

### What is the discrimination risk when an AI conducts a screening interview?

The risk is that the questions or the ideal answers used to score candidates reward a proxy for a protected attribute rather than the skill itself. Fluency scoring can disadvantage a candidate whose accent or speech is unrelated to the role, and video assessment can pick up disability or age. Under the Fair Work Act and the discrimination Acts, a screen that disadvantages a protected group is the employer's exposure, and general protections claims carry a reverse onus.

Source: [Your Recruiter Is Now an Agent, Not a Search Box](https://theaicommand.com/hr/ai-recruiting-agent-screens-before-a-human#faq-3)

### What is the safe loop for using AI on award questions?

Confirm the award through the Pay and Conditions Tool, not the model. Paste the actual clause text so the model is not working from memory. Ask it to explain the clause and list every variable that changes the answer, not to state the rate. Verify every figure against the award and the Pay and Conditions Tool. Record the award, classification, clauses, rate and who signed off.

Source: [AI Can Read the Award. It Cannot Set the Pay.](https://theaicommand.com/hr/ai-can-read-the-award-not-set-the-pay#faq-4)

### What is Workday's Agent Passport?

Agent Passport tests and verifies every AI agent, whether Workday-built or third-party, before it goes into production and then continuously monitors it. It produces a signed record that the agent was tested against risks such as prompt injection, jailbreak, goal hijacking, system prompt extraction and leaks of employee data, with each result tied to a public standard like the OWASP LLM Top 10 and verified by an independent attestor. Treat its test list as a checklist for any agent you build.

Source: [Your HRIS Now Lets Anyone Build an Agent](https://theaicommand.com/hr/your-hris-now-lets-anyone-build-an-agent#faq-2)

### What parts of a workplace investigation can AI safely handle?

Employment guidance identifies four practical uses: investigation planning against policy, producing records of interview through transcription, organising and arranging evidence chronologically, and drafting procedural correspondence such as allegation letters and the report framework. Each maps onto a real bottleneck, while the human investigator checks and owns the output.

Source: [AI in Workplace Investigations: Organise the File, Not the Finding](https://theaicommand.com/hr/ai-in-workplace-investigations#faq-1)

### What records should we keep when an AI agent screens candidates?

Keep the questions asked, the ideal answers used to score, the rating each candidate received, evidence that a named human reviewed the result before any rejection, the notice given to candidates, consent for any recording, and your retention and access limits. If a rejected candidate later challenges the decision, this is the file that shows the screen was job-related and a person owned the outcome.

Source: [Your Recruiter Is Now an Agent, Not a Search Box](https://theaicommand.com/hr/ai-recruiting-agent-screens-before-a-human#faq-4)

### What should HR actually do about ad targeting?

Own the top of the funnel the way you own the interview. Use broad, neutral targeting rather than proxies for protected attributes, ask the platform what its delivery optimises on, and where a special audience tool for employment ads exists, use it. Then look at the audience the campaign actually reached and compare it to your applicant pool for obvious skew. Keep a named person accountable for the decision about who sees each role, and record it, so the top of the funnel is a governed step and not a setting no one owns.

Source: [AI Decides Who Sees Your Job Ad. That Is a Hiring Decision.](https://theaicommand.com/hr/ai-job-ad-targeting-who-sees-the-ad#faq-4)

### What should I never automate in an investigation?

Do not let AI assess credibility, make findings of fact, determine whether an allegation is substantiated, decide an outcome or recommend a sanction. Do not let it draft the disciplinary rationale. That rationale is the reason a person can be performance-managed or dismissed, so it must be a human's reasoning.

Source: [AI in Workplace Investigations: Organise the File, Not the Finding](https://theaicommand.com/hr/ai-in-workplace-investigations#faq-2)

### What should I never automate in onboarding?

Do not automate belonging, judgements about the person, or any answer you have not grounded. The buddy, team lunch and unprompted check-in make someone stay. Decisions about fit, probation, capability or early performance must be made by an accountable manager, not a chatbot inventing answers.

Source: [AI-Assisted Onboarding: A 90-Day Plan That Keeps the Human In](https://theaicommand.com/hr/ai-assisted-onboarding-90-day-plan#faq-2)

### What should I never automate when analysing survey feedback with AI?

Never let AI score, rank or rate named individuals, never re-identify a result that points to one person, never feed raw identifiable comments into an unapproved public tool, never let AI infer a named worker's health or psychological state and treat it as fact, and never run the analysis silently.

Source: [AI Can Analyse Your Engagement Survey Without Surveilling Your People](https://theaicommand.com/hr/ai-engagement-survey-analysis-without-surveillance#faq-2)

### What should managers never use AI for in performance management?

Never use AI to generate the facts of an incident, to decide the outcome, to weigh an employee's explanation, or to draft a record of a conversation that did not happen the way the draft describes. AI drafts the document from facts you supply and verify. It does not establish what occurred, and it does not make the decision to warn, manage or dismiss. Those stay with the manager.

Source: [AI Can Draft the Warning. It Cannot Fake the Facts.](https://theaicommand.com/hr/ai-performance-management-documents-procedural-fairness#faq-4)

### What should we check before an HR-built agent goes live?

Confirm exactly what employee data it can read and write, test it against prompt injection and jailbreak attempts, check it cannot leak data to the wrong recipient, require a named human to review its outputs before any decision, and keep an auditable record of what the agent can do and who approved it. No agent should touch live employee data until it has passed that gate.

Source: [Your HRIS Now Lets Anyone Build an Agent](https://theaicommand.com/hr/your-hris-now-lets-anyone-build-an-agent#faq-5)

### When did the AHRC get powers to enforce the positive duty?

The AHRC's compliance and enforcement powers commenced on 12 December 2023, one year after the duty itself began on 12 December 2022. Under the Australian Human Rights Commission Act 1986, the Commission can inquire where it reasonably suspects non-compliance, issue compliance notices and accept enforceable undertakings, without needing the organisation's consent.

Source: [AI Hiring and Performance Tools Under Australia's Positive Duty: What HR Must Control](https://theaicommand.com/hr/ai-positive-duty-hiring-performance#faq-4)

### When does consultation have to happen in a restructure?

After the employer has formed a proposal but before the decision is locked. The Fair Work Commission's guidance, quoting case law, describes consultation as a bona fide opportunity to influence the decision maker, not perfunctory advice about what is about to happen. Where an award or agreement requires consultation and the employer fails to do it, there cannot be a genuine redundancy at all.

Source: [AI Can Build the Redundancy. It Cannot Decide It](https://theaicommand.com/hr/ai-redundancy-restructure-consultation-selection-2026#faq-3)

### When does the consultation clock start?

At the definite decision, not at go-live. The model term requires the employer to consult as soon as practicable after making its decision, and clause 38 of the Clerks-Private Sector Award 2020 requires discussions to commence as soon as practicable after a definite decision has been made. Signing the contract, approving the budget or locking the rollout date can each be the moment the clock starts. Consultation that begins after implementation is not consultation.

Source: [Your AI Rollout Triggers a Clause You Already Signed](https://theaicommand.com/hr/ai-rollout-triggers-your-consultation-clause#faq-3)

### When does the new automated decision-making privacy obligation start?

It commences on 10 December 2026 through new APP 1.7 to 1.9, inserted by the Privacy and Other Legislation Amendment Act 2024. From that date, where AI significantly affects a worker decision, your privacy policy must disclose the kinds of personal information used and the kinds of automated decisions made.

Source: [AI Worker Monitoring in Australia: What HR Can and Cannot Do](https://theaicommand.com/hr/ai-workplace-monitoring-australia#faq-2)

### Where does the consultation obligation actually come from?

It is a term of the industrial instrument that applies to you, not a standalone AI law. Section 205 of the Fair Work Act requires an enterprise agreement to contain a consultation term for major workplace change, and if if the agreement has none or the one it has does not meet the Act, the model consultation term is taken to be a term of the agreement, and the current model term is the one set out in the Fair Work (Model Terms) Determination 2025, the model term in the Fair Work (Model Terms) Determination 2025 is taken to be a term of the agreement. Award-covered employers have their duty in the award's own major change clause, for example clause 38 of the Clerks-Private Sector Award 2020. Read the wording of the award that covers you.

Source: [Your AI Rollout Triggers a Clause You Already Signed](https://theaicommand.com/hr/ai-rollout-triggers-your-consultation-clause#faq-2)

### Who bears the burden of proving an AI tool was not discriminatory?

The employer. Under section 7C of the Sex Discrimination Act, once a candidate shows a condition or practice had a disadvantaging effect, the burden of proving it was reasonable falls on the person who imposed it. For an AI tool, that means producing bias testing, a business rationale and evidence of less-discriminatory alternatives considered.

Source: [AI Hiring and Performance Tools Under Australia's Positive Duty: What HR Must Control](https://theaicommand.com/hr/ai-positive-duty-hiring-performance#faq-3)

### Who is accountable if an AI background check is wrong?

The employer. An AI summary can be confidently wrong, mix up two people, or rely on stale data, but the hiring decision and its consequences sit with the organisation, not the vendor. That is why the referee's own words, the candidate's right to respond to adverse information, and the final call all stay with a person.

Source: [AI in Reference and Background Checks: Verify Facts, Not Character](https://theaicommand.com/hr/ai-reference-and-background-checks#faq-5)

### Why has AI made hiring harder?

Because the written application used to be a signal. Tailoring, clear writing and a well-structured CV suggested effort and communication skill. Now a candidate can produce all of that with a model in minutes, so the signal is gone. Robert Half's Australian data shows more than a third of hiring managers say AI-generated CVs make it harder to assess candidate quality accurately, because uniform, polished applications blur the differences between people.

Source: [Every Application Now Reads Perfectly. Assess the Person.](https://theaicommand.com/hr/ai-generated-applications-assess-the-person#faq-1)

### Why is a meeting transcript a privacy risk?

A transcript is not a fleeting set of notes. It is a durable, searchable, copyable record that lives somewhere after the meeting, can be forwarded, and can be produced later in a dispute or an information-access request. When the meeting is a grievance or a medical conversation, you have automatically manufactured a sensitive document, often without deciding where it sits, how long it is kept, or who can open it.

Source: [AI Note-Takers in HR Meetings: Consent Before the Transcript](https://theaicommand.com/hr/ai-note-takers-in-hr-meetings#faq-4)

### Why is AI-generated performance documentation a legal risk?

Because generative AI invents plausible detail. The Fair Work Commission has reported documents citing cases and awards that do not exist. If a warning or improvement plan contains an incident that did not happen, a misquoted policy or a date that is wrong, it undermines the valid reason and the procedural fairness a dismissal must show under the Fair Work Act. An inaccurate paper trail is worse than a thin one.

Source: [AI Can Draft the Warning. It Cannot Fake the Facts.](https://theaicommand.com/hr/ai-performance-management-documents-procedural-fairness#faq-2)

### Why is an AI tool unreliable for penalty rates and classifications?

A language model is most confident about exactly the things it gets wrong, including penalty rates, classification levels, overtime thresholds and allowance amounts. It paraphrases training data that may be months out of date, so a model trained before the Annual Wage Review does not know award minimums rose on 1 July and will give last year's rate with full confidence.

Source: [AI Can Read the Award. It Cannot Set the Pay.](https://theaicommand.com/hr/ai-can-read-the-award-not-set-the-pay#faq-2)

### Why is the People at Work survey being replaced and what does that mean for AI tools?

The free, government-backed People at Work psychosocial survey is being decommissioned through 2026, with reports accessible only until 2 October 2026, because legislation and research revealed gaps. As it leaves, commercial AI-powered survey products are moving in, often promising individual-level insight that careful HR teams should question.

Source: [AI Can Analyse Your Engagement Survey Without Surveilling Your People](https://theaicommand.com/hr/ai-engagement-survey-analysis-without-surveillance#faq-3)

### Why set a minimum group size when reporting survey results?

A minimum group size, commonly five or ten responses, sets a floor below which you do not report a result for any team or segment. If only three people answered, their feedback rolls up to the next level. This single rule prevents the most common re-identification accident: a team result that is really one person's words.

Source: [AI Can Analyse Your Engagement Survey Without Surveilling Your People](https://theaicommand.com/hr/ai-engagement-survey-analysis-without-surveillance#faq-5)

## Work health and safety

WHS duties, psychosocial risk, and AI in safety systems.

### Can AI complete a psychosocial risk assessment for me?

No. AI may assist with three tasks only: identifying candidate hazards, synthesising de-identified survey data into themes, and drafting the written assessment with rating fields left blank. Under Australian WHS law a competent person must determine the risk rating, select the controls, and sign off. The model never rates or signs.

Source: [AI-Assisted Psychosocial Risk Assessment: A WHS Governance Workflow That Keeps the Sign-Off Human](https://theaicommand.com/whs/ai-assisted-psychosocial-risk-assessment#faq-1)

### Can AI create WHS training material?

Yes, as a drafting tool using verified sources. AI can structure objectives, scenarios, questions, facilitator notes and plain-language explanations. A competent person must check the content against the current work, risks, controls, equipment, jurisdiction and workforce before delivery.

Source: [AI Can Draft WHS Training. It Cannot Verify Competence.](https://theaicommand.com/whs/ai-drafted-whs-training-human-competence-verification#faq-1)

### Can AI decide that refresher training is enough after an incident?

No. The incident may reveal a control, supervision, equipment or system-of-work failure rather than a knowledge gap. A competent person investigates, consults workers, reviews controls and decides what training, instruction, supervision or other action is required.

Source: [AI Can Draft WHS Training. It Cannot Verify Competence.](https://theaicommand.com/whs/ai-drafted-whs-training-human-competence-verification#faq-4)

### Can AI decide whether a workplace incident is notifiable?

No. AI must never auto-classify whether an event is notifiable under sections 35 to 39 of the model WHS Act. The notification duty is immediate and strict, so an automated recommendation can reliably produce a breach. The safe pattern is the inverse: AI prepares the facts so a named competent person decides faster, leaving the decision field blank.

Source: [AI for Incident Analysis and Leading Indicators: A Human-in-the-Loop WHS Playbook](https://theaicommand.com/whs/ai-for-incident-analysis-and-leading-indicators#faq-2)

### Can AI determine whether an emergency plan complies with regulation 43?

No. AI can compare supplied text and flag gaps for review, but it lacks the full workplace context and cannot make a legal or professional determination. A competent person must assess the plan against the current law, the hazards, the workforce, the location and regulator guidance.

Source: [AI Can Stress-Test an Emergency Plan. It Cannot Run the Drill.](https://theaicommand.com/whs/ai-stress-test-emergency-plan-drill#faq-1)

### Can AI do the WHS work for me?

AI can draft the consultation plan, structure the risk assessment, and turn workshop notes into a tidy first draft. It cannot consult, because consultation is a two-way exchange with the people who do the work. It cannot set the risk rating or decide which controls are reasonably practicable, and it cannot sign off or carry the accountability. Those stay with a competent person.

Source: [Rolling Out AI Is a Workplace Change: Consult and Risk-Assess First](https://theaicommand.com/whs/ai-rollout-is-a-whs-change#faq-5)

### Can AI write a compliant SWMS for high-risk construction work?

No. AI can produce a formatted first draft, but a SWMS for high-risk construction work must take account of the actual workplace under regulation 299(3) and be built in consultation with the workers who will do the work. A model has never seen your site and cannot hold the toolbox talk, so the draft is not yet lawful until a competent person makes it true.

Source: [AI Can Draft a SWMS in Seconds. The Site Walk and the Consultation Cannot Be Automated.](https://theaicommand.com/whs/ai-swms-without-the-generic-trap#faq-1)

### Can an AI safety control also create a psychosocial hazard?

Yes. A camera trained on a person, a cab-facing fatigue camera, or a body-tracking wearable is a form of monitoring, and Comcare lists intrusive surveillance among the psychosocial hazards a PCBU must manage under regulations 55A to 55D. Because health in the WHS Act means physical and psychological health, the same primary duty covers it, supported by consultation.

Source: [An AI Safety Control Is Still Just a Control. The Duty to Verify It Stays With You.](https://theaicommand.com/whs/ai-safety-controls-and-the-duty-to-verify#faq-4)

### Do I have to consult workers before switching on an AI tool?

Yes, where the tool changes how people are allocated work, measured, or monitored. The consultation is not a launch email. It is a genuine opportunity for affected workers and their health and safety representatives to influence the decision before it is made, as required by the model framework consultation provisions in sections 47 to 49.

Source: [Rolling Out AI Is a Workplace Change: Consult and Risk-Assess First](https://theaicommand.com/whs/ai-rollout-is-a-whs-change#faq-3)

### Do we have to consult workers before deploying a work-allocation tool?

Yes, so far as is reasonably practicable. Sections 47 to 49 of the WHS Act require consultation with directly affected workers when identifying hazards, deciding on controls, and proposing changes affecting health or safety. Consultation must occur before the decision is finalised, not after deployment, so worker views can shape the design.

Source: [AI Work Allocation and Psychosocial Risk: The WHS Duty NSW Teams Already Hold](https://theaicommand.com/whs/nsw-digital-work-systems-whs-duty#faq-3)

### Does a tabletop exercise count as testing the emergency procedures?

A tabletop can test decision logic and expose assumptions, but it may not test physical evacuation, alarm audibility, equipment, access or worker behaviour. The appropriate testing program depends on the workplace and is set by a competent person using current jurisdictional guidance, and regulation 43 requires the plan to state the frequency of testing.

Source: [AI Can Stress-Test an Emergency Plan. It Cannot Run the Drill.](https://theaicommand.com/whs/ai-stress-test-emergency-plan-drill#faq-2)

### Does buying an AI safety camera discharge my WHS duty?

No. An AI safety system is a control measure, not a transfer of duty. Safe Work Australia is explicit that a PCBU cannot contract out of their responsibility and a duty cannot be transferred to another person. The vendor has its own upstream duty over the product, but that sits alongside yours. Verifying the system works on your site is you discharging your duty.

Source: [An AI Safety Control Is Still Just a Control. The Duty to Verify It Stays With You.](https://theaicommand.com/whs/ai-safety-controls-and-the-duty-to-verify#faq-1)

### Does passing an AI-generated quiz prove competence?

No. A quiz can provide evidence of knowledge or recall. Competence may require practical demonstration, observation, formal assessment, licence evidence or supervised performance appropriate to the task. A competent person selects the method and decides whether the evidence is sufficient.

Source: [AI Can Draft WHS Training. It Cannot Verify Competence.](https://theaicommand.com/whs/ai-drafted-whs-training-human-competence-verification#faq-2)

### Does the WHS primary duty really cover psychological harm from software?

Yes. Section 19 of the WHS Act 2011 (NSW) defines health to include psychological health and requires safe systems of work. An AI tool that allocates, paces or monitors work is a system of work, so the duty applies to the psychosocial risks it creates, the same as any other aspect of work design.

Source: [AI Work Allocation and Psychosocial Risk: The WHS Duty NSW Teams Already Hold](https://theaicommand.com/whs/nsw-digital-work-systems-whs-duty#faq-1)

### Has the NSW Digital Work Systems duty commenced?

No. NSW Parliament passed an amendment introducing an express digital work systems duty, but its operative provisions commence on a day to be appointed by proclamation, which has not yet occurred. Until then, manage AI-related psychosocial risk under the existing duties in the WHS Act and the WHS Regulation, which already apply.

Source: [AI Work Allocation and Psychosocial Risk: The WHS Duty NSW Teams Already Hold](https://theaicommand.com/whs/nsw-digital-work-systems-whs-duty#faq-5)

### How can AI help analyse workplace incident data safely?

AI reads across many de-identified incident records and proposes patterns a human would take hours to assemble. Three supported uses hold up: de-identified trend and leading-indicator analysis, ICAM-style causal support for a single incident, and drafting investigation summaries with blanks. The output is a hypothesis, never a finding, and a competent person tests and decides.

Source: [AI for Incident Analysis and Leading Indicators: A Human-in-the-Loop WHS Playbook](https://theaicommand.com/whs/ai-for-incident-analysis-and-leading-indicators#faq-1)

### How do I stop an AI tool from assigning a risk rating?

Set the boundary in writing in your project instructions and prompts so every rating field returns blank, marked competent person to determine. If the drafting tool ever returns a populated risk-level column, treat that as a prompt defect, delete it, and put the rating back in human hands. The competent person rates and signs.

Source: [AI-Assisted Psychosocial Risk Assessment: A WHS Governance Workflow That Keeps the Sign-Off Human](https://theaicommand.com/whs/ai-assisted-psychosocial-risk-assessment#faq-4)

### How do I verify an AI safety control before I rely on it?

Test it against your own site conditions, not the vendor demo footage, and probe two failures in opposite directions. The false negative is the dangerous miss, the worker in the zone the system did not flag. The false positive is the nuisance alert that trains everyone to ignore it. Vendor accuracy figures do not close this out. Your own test on your own site does.

Source: [An AI Safety Control Is Still Just a Control. The Duty to Verify It Stays With You.](https://theaicommand.com/whs/ai-safety-controls-and-the-duty-to-verify#faq-3)

### How does ICAM-style support work with AI in an investigation?

AI proposes candidate contributing factors at the four ICAM levels for a single de-identified incident: absent or failed defences, individual or team actions, task or environmental conditions, and organisational factors. The investigator then tests each factor against the evidence, discards weak ones, and adds what the model missed. The model widens the search; the competent investigator decides what is true.

Source: [AI for Incident Analysis and Leading Indicators: A Human-in-the-Loop WHS Playbook](https://theaicommand.com/whs/ai-for-incident-analysis-and-leading-indicators#faq-5)

### How should a team measure whether this workflow helped?

Measure the quality of the exercise and action closure, not the number of scenarios generated. Useful measures include new dependencies identified, participation across shifts, actions supported by evidence, time to close actions and successful verification at the next test.

Source: [AI Can Stress-Test an Emergency Plan. It Cannot Run the Drill.](https://theaicommand.com/whs/ai-stress-test-emergency-plan-drill#faq-5)

### How should I de-identify incident data before using AI?

Never paste real personal, claim, health or incident data into a model that is not an approved enterprise instance, and public consumer chatbots do not qualify. Before any export leaves your safety system, strip names, employee IDs, claim numbers, exact dates, and re-identifying free text, replacing them with placeholder tokens such as [EMPLOYEE_NAME], [CLAIM_NUMBER] and [SITE].

Source: [AI for Incident Analysis and Leading Indicators: A Human-in-the-Loop WHS Playbook](https://theaicommand.com/whs/ai-for-incident-analysis-and-leading-indicators#faq-4)

### Is rolling out an AI tool a work health and safety matter?

Yes. Introducing a system that changes how work is allocated, paced, measured, monitored, or decided is a change to the work. The primary duty of care and the duty to consult workers, which include psychological health, already cover it. NSW has now made the AI case express in statute, and the model WHS jurisdictions, Victoria, and the Comcare scheme reach it through existing duties.

Source: [Rolling Out AI Is a Workplace Change: Consult and Risk-Assess First](https://theaicommand.com/whs/ai-rollout-is-a-whs-change#faq-1)

### Is the SafeWork NSW Code of Practice legally binding?

An approved code under section 274 of the WHS Act is not a standalone offence, but it is admissible in court as evidence of known hazards and reasonably practicable controls. Following the Code is the most defensible position. Departing from it shifts the burden to you to prove your alternative approach was at least as effective.

Source: [AI Work Allocation and Psychosocial Risk: The WHS Duty NSW Teams Already Hold](https://theaicommand.com/whs/nsw-digital-work-systems-whs-duty#faq-4)

### What data do I need to de-identify before using AI for psychosocial work?

Strip all personal, claim, health, and incident data to placeholder tokens such as EMPLOYEE_NAME, CLAIM_NUMBER, INCIDENT_ID, TEAM, ROLE, SITE, and DATE before anything reaches the model. Aggregate into themes and counts where possible. De-identification is a control you apply at source, not a step the model performs for you.

Source: [AI-Assisted Psychosocial Risk Assessment: A WHS Governance Workflow That Keeps the Sign-Off Human](https://theaicommand.com/whs/ai-assisted-psychosocial-risk-assessment#faq-2)

### What data should be excluded from the AI training workflow?

Exclude real employee, incident, client, medical and witness information unless the tool and data pathway are specifically approved. Use placeholders such as [EMPLOYEE_NAME], [TEAM], [SITE], [TASK], [HAZARD], [CONTROL] and [INCIDENT_ID], and de-identify before upload, not after.

Source: [AI Can Draft WHS Training. It Cannot Verify Competence.](https://theaicommand.com/whs/ai-drafted-whs-training-human-competence-verification#faq-5)

### What data should I never paste into a public AI tool when drafting a SWMS?

Do not paste anything that identifies people, the client, or commercially sensitive site detail into a public AI tool while drafting. A SWMS is about the work and the controls, and it does not need names to do its job. Strip identifiers to placeholder tokens before anything reaches the model.

Source: [AI Can Draft a SWMS in Seconds. The Site Walk and the Consultation Cannot Be Automated.](https://theaicommand.com/whs/ai-swms-without-the-generic-trap#faq-5)

### What does regulation 39 require?

For the Commonwealth jurisdiction, regulation 39 of the Work Health and Safety Regulations 2011 requires information, training and instruction provided to a worker to be suitable and adequate having regard to the nature of the work, the risks associated with the work at the time, and the control measures implemented. So far as is reasonably practicable, it must also be provided in a way that is readily understandable. Check the equivalent provision in your own jurisdiction.

Source: [AI Can Draft WHS Training. It Cannot Verify Competence.](https://theaicommand.com/whs/ai-drafted-whs-training-human-competence-verification#faq-3)

### What does the NSW Digital Work Systems Act require?

The Work Health and Safety Amendment (Digital Work Systems) Act 2026, assented on 18 February 2026, defines a digital work system as an algorithm, artificial intelligence, automation, or online platform. It extends the primary duty and adds a new section 21A requiring a PCBU to consider whether work allocation creates excessive workloads, unreasonable performance metrics, excessive monitoring or surveillance, or discriminatory decisions.

Source: [Rolling Out AI Is a Workplace Change: Consult and Risk-Assess First](https://theaicommand.com/whs/ai-rollout-is-a-whs-change#faq-2)

### What does this AI workflow actually buy a WHS function?

It saves time and adds consistency on the mechanical work: synthesising free-text, mapping to categories, and producing a structured first draft. The auditable trail from de-identified data to a drafted assessment with blank ratings is a governance asset. It does not shortcut the duty, which still rests on the organisation and competent people.

Source: [AI-Assisted Psychosocial Risk Assessment: A WHS Governance Workflow That Keeps the Sign-Off Human](https://theaicommand.com/whs/ai-assisted-psychosocial-risk-assessment#faq-5)

### What information should stay out of the AI tool?

Keep out names, contact details, health or disability information, security credentials, detailed access data and sensitive floor plans unless an approved environment and clear authority exist. Use role and site placeholders such as [SITE] and [WARDEN_ROLE] wherever possible, and de-identify before anything enters the model.

Source: [AI Can Stress-Test an Emergency Plan. It Cannot Run the Drill.](https://theaicommand.com/whs/ai-stress-test-emergency-plan-drill#faq-3)

### What is a leading indicator in WHS incident analysis?

A leading indicator is a signal that predicts harm before it happens, such as a rising rate of near-misses of a particular type, rather than a lagging indicator like a lost-time injury that records harm after the fact. AI can surface candidate leading indicators across de-identified data for a human analyst to confirm against further evidence.

Source: [AI for Incident Analysis and Leading Indicators: A Human-in-the-Loop WHS Playbook](https://theaicommand.com/whs/ai-for-incident-analysis-and-leading-indicators#faq-3)

### What part of an AI safety control must always stay human?

The model can watch, detect and flag tirelessly. It cannot decide what to control, choose where the control sits in the hierarchy, verify it works in your conditions, weigh the surveillance it creates against the harm it prevents, respond to what it flags, or carry the duty when it misses. Those are judgements the law puts on a person and an organisation, not on a sensor.

Source: [An AI Safety Control Is Still Just a Control. The Duty to Verify It Stays With You.](https://theaicommand.com/whs/ai-safety-controls-and-the-duty-to-verify#faq-5)

### What parts of a SWMS can AI safely help with?

AI is genuinely useful for the blank page: laying out the required format, listing standard hazards for a task type so you are less likely to miss one, surfacing candidate controls, and rewriting dense safety language into plain English, which is what regulation 299(3)(b) asks for. Used as a drafting assistant against your own template and site knowledge, it removes the slow part and leaves the judgement to you.

Source: [AI Can Draft a SWMS in Seconds. The Site Walk and the Consultation Cannot Be Automated.](https://theaicommand.com/whs/ai-swms-without-the-generic-trap#faq-3)

### What stays human in an AI-assisted SWMS?

The site walk, the consultation, the judgement that a control is adequate, the decision to proceed or stop work under regulation 300, and the signature of the person who carries the duty. AI cannot hold the primary duty of care. That responsibility rests with the person conducting a business or undertaking and its officers, and it does not move to a tool because the tool produced the first draft.

Source: [AI Can Draft a SWMS in Seconds. The Site Walk and the Consultation Cannot Be Automated.](https://theaicommand.com/whs/ai-swms-without-the-generic-trap#faq-4)

### Where does an AI safety system sit in the hierarchy of controls?

Almost every detect-and-alert AI safety product is an administrative control. It does not remove, isolate or engineer out the hazard, it watches and relies on a human noticing the alert and acting in time. Safe Work Australia ranks administrative controls and PPE as the least effective because they rely on human behaviour and supervision, so the tool sits near the bottom where reliability is lowest.

Source: [An AI Safety Control Is Still Just a Control. The Duty to Verify It Stays With You.](https://theaicommand.com/whs/ai-safety-controls-and-the-duty-to-verify#faq-2)

### Which Australian laws govern psychosocial risk assessment?

The Safe Work Australia model Code of Practice (July 2022) is the practical method, sitting over model WHS Regulations 55A to 55D and the section 19 primary duty in the model WHS Act. Adoption varies: NSW took effect 28 May 2021, Comcare covers Commonwealth employers, and Victoria and Western Australia run distinct arrangements.

Source: [AI-Assisted Psychosocial Risk Assessment: A WHS Governance Workflow That Keeps the Sign-Off Human](https://theaicommand.com/whs/ai-assisted-psychosocial-risk-assessment#faq-3)

### Which WHS Regulation provisions apply to AI-driven psychosocial risk?

Clauses 55A to 55D of the WHS Regulation 2025 (NSW) define psychosocial hazards and risks and require PCBUs to manage them using the hierarchy of controls in clause 36. Clause 55D lists the matters to weigh, including exposure duration and severity, how hazards combine, and the design and systems of work.

Source: [AI Work Allocation and Psychosocial Risk: The WHS Duty NSW Teams Already Hold](https://theaicommand.com/whs/nsw-digital-work-systems-whs-duty#faq-2)

### Who should review AI-generated emergency scenarios?

The review group should include the competent WHS lead and the people who understand the work, including workers, health and safety representatives, wardens, facilities, shared-site duty holders and emergency services where appropriate. Consultation with workers and HSRs when making and reviewing emergency plans is part of the duty.

Source: [AI Can Stress-Test an Emergency Plan. It Cannot Run the Drill.](https://theaicommand.com/whs/ai-stress-test-emergency-plan-drill#faq-4)

### Why is a generic AI-generated SWMS a problem?

Regulation 299(3) requires a SWMS to be prepared taking into account circumstances at the workplace and to be readily understandable to the people who use it. A document built from a task description and a training corpus has taken account of no workplace at all. SafeWork NSW states a SWMS must be site-specific, so a generic AI draft is non-compliant by construction until reviewed and amended for the actual site.

Source: [AI Can Draft a SWMS in Seconds. The Site Walk and the Consultation Cannot Be Automated.](https://theaicommand.com/whs/ai-swms-without-the-generic-trap#faq-2)

### Why is an AI rollout a psychosocial risk and not just a privacy matter?

Because the harms from a badly introduced AI system are mostly psychological, and psychological health is inside the duty. The four risks NSW names map onto recognised psychosocial hazards: workload onto job demands, metrics onto job control, surveillance onto intrusive surveillance, and discriminatory decisions onto organisational justice. Poor change management is itself a recognised hazard.

Source: [Rolling Out AI Is a Workplace Change: Consult and Risk-Assess First](https://theaicommand.com/whs/ai-rollout-is-a-whs-change#faq-4)

## Leading with AI

Delegation, decision rights, and team capability.

### Are prompt counts ever useful?

Yes. They can help monitor adoption, cost, training needs and unusual use, and they can flag a workflow worth examining more closely. They are diagnostic telemetry, not a productivity outcome, and they never earn a green status on their own.

Source: [Stop Counting Prompts. Measure the Work That Improved](https://theaicommand.com/leadership/stop-counting-prompts-measure-work-improved#faq-1)

### Can employees really tell when a manager uses AI to write a message?

Often, yes, and perception is what matters. In the Coman and Cardon study of 1,100 professionals, employees who sensed heavy AI assistance rated the same supervisor messages as far less sincere. Messages that arrive suspiciously fast, unusually polished and slightly off the leader's normal register read as low effort. Even when nobody is certain, the doubt itself does the damage on relationship-bearing messages like praise and feedback.

Source: [Don't Let AI Write the Messages That Build Trust](https://theaicommand.com/leadership/ai-leadership-communication-trust-triage#faq-1)

### Does AI make the decision in a pre-mortem?

No. AI surfaces the case against. The leader makes the call and carries it, and accountability does not transfer to a tool. A model told to argue will manufacture some thin objections, and a fluent objection is not a correct one, so you weigh what it raises rather than obey it.

Source: [Make AI Disagree With You Before You Decide](https://theaicommand.com/leadership/make-ai-disagree-before-you-decide#faq-4)

### Does stopping work mean cutting jobs?

No. The immediate goal is to remove low-value activity and redirect capacity to work that changes an outcome. Workforce changes are a separate decision that carries its own consultation, legal review and accountable sign-off. Using a work-kill review to reverse-engineer a predetermined headcount answer corrupts the method and the trust it depends on.

Source: [Use AI to Kill Work Before You Accelerate It](https://theaicommand.com/leadership/use-ai-kill-work-before-accelerate#faq-2)

### Does this mean leaders should read the raw material themselves?

Not generally. Reading everything is the problem compression was introduced to solve, and reverting relocates the cost rather than removing it. The practical position is selective: accept compression for the routine, demand the source and a second reading for the consequential, and keep at least one recurring channel that nothing summarises.

Source: [The Summary Kept the Number and Lost the Caveat](https://theaicommand.com/leadership/the-summary-lost-the-caveat#faq-4)

### Does this mean my team should stop using AI for ideas?

No, and the research does not say that. It says where AI enters matters. Writing in MIT Sloan Management Review in July 2026, Boussioux, Doshi, Hauser and Hosanagar report that AI in idea generation consistently reduced diversity, while AI in idea selection preserved variety at levels comparable to human-only work. Wharton's Human-AI Research group, where Hosanagar sits, makes the same point. So the move is sequencing, not restriction. Let people diverge first, then bring AI in to pressure-test, cost and choose. Nobody gives up the tool.

Source: [AI Is Narrowing Your Team's Idea Pool. Only You Can See It.](https://theaicommand.com/leadership/ai-narrows-your-teams-idea-pool#faq-2)

### Does using AI to think make leaders lazy or worse at judgement?

It can, if the leader consumes AI output instead of evaluating it. The risk is rubber-stamping a confident answer. It sharpens judgement when the leader uses AI for breadth and speed, then does the harder human work of questioning the output, weighing it against values and context the model lacks, and owning the decision. The discipline is to stay the evaluator, not become the audience.

Source: [You Are No Longer the Smartest Person in the Room](https://theaicommand.com/leadership/not-the-smartest-person-in-the-room#faq-3)

### How can a leader tell whether a step is a control?

Ask what risk the step addresses, who owns that risk, what evidence the step creates and whether the control is required by law, policy, contract or professional standard. A step that annoys the team may still be protecting a legal, safety, financial or customer outcome. Involve the qualified risk owner before removing it, and record the decision.

Source: [Use AI to Kill Work Before You Accelerate It](https://theaicommand.com/leadership/use-ai-kill-work-before-accelerate#faq-3)

### How can a manager safely model AI use with team data?

Never paste real personal, claim, health or incident data into a model that is not an approved enterprise instance. Use placeholder tokens such as [TEAM], [ROLE], [SITE] and [DATE], or fill them with non-sensitive descriptors only. In financial services, use your organisation's approved enterprise tool, not a personal account, for anything touching the business.

Source: [Set the AI Norm: Your Team Copies How You Use It](https://theaicommand.com/leadership/set-your-teams-ai-norm#faq-4)

### How can a team measure the quality of AI-assisted work?

Use a rubric defined before the trial, source verification, human sampling, defect or correction rates and severity levels. Keep the standard independent of the model producing the work, and track severity as well as frequency, because one material error can outweigh fifty clean drafts.

Source: [Stop Counting Prompts. Measure the Work That Improved](https://theaicommand.com/leadership/stop-counting-prompts-measure-work-improved#faq-5)

### How do I assign a review tier to an AI workflow?

Ask two questions per workflow: how bad is it if this goes out wrong, and can you take it back. Low harm and easily reversed is spot-check. Real harm or hard to reverse is full human review. Severe, regulated or irreversible is two-person or named sign-off. Write the answer down.

Source: [The Review Tax: AI Adoption Is Done, Now Design the Checking](https://theaicommand.com/leadership/the-ai-review-tax#faq-2)

### How do I map decision rights across my team?

Run a five-step method this week. List your team's recurring decisions, usually ten to thirty. Name a specific role that decides each. Place AI on the ladder at inform, recommend or act within bounds. Engineer override and escalation paths for anything AI recommends or acts on. Write it on one page and revisit it.

Source: [Decision Rights Are the Leadership Job AI Just Made Urgent](https://theaicommand.com/leadership/decision-rights-in-ai-enabled-teams#faq-2)

### How do I prepare the conversation without an AI writing it for me?

Use AI to prepare, never to deliver. Draft your own three lists (what is changing, what you can commit to, what you cannot promise), have ChatGPT, Claude or equivalent turn them into plain talking points, then run a red-team pass that attacks every overpromise and buzzword. You say the words in person. The tool never appears in front of your team.

Source: [Talk to Your Team About AI Before the Rumours Do](https://theaicommand.com/leadership/talking-to-your-team-about-ai-and-jobs#faq-3)

### How do I run the fifteen-minute rehearsal?

Four steps in order. Brief the role and stance, never a real person. Tell the model not to be agreeable or concede quickly. Run your real opening line three ways, against a defensive, a withdrawn and an agrees-too-fast reaction. Then type STOP to switch the model from counterpart to coach for a short debrief.

Source: [Rehearse the Hard Conversation Before You Have It](https://theaicommand.com/leadership/rehearse-the-hard-conversation-with-ai#faq-2)

### How do I set the AI norm for my team this week?

Make four behaviours visible, starting at your next meeting. Model your own AI use in the open, including the errors you fixed. Set the norm explicitly: what is encouraged, what is off-limits, what good looks like. Make space to experiment without penalty. Hold the quality bar so the standard does not drop.

Source: [Set the AI Norm: Your Team Copies How You Use It](https://theaicommand.com/leadership/set-your-teams-ai-norm#faq-2)

### How does a leader decide what to keep human?

Ask one question of each recurring task: does doing this build a capability we need to protect? Most tasks fail that test and should be accelerated with AI. A few pass it, the analysis a junior needs to reason through to become senior, the judgement calls that keep an expert sharp, and those you deliberately keep human, or structure so the person does the thinking and AI does the support. Name which tasks are development reps, protect them, and make the trade-off explicit rather than letting efficiency quietly decide it.

Source: [Protect the Reps: Lead So AI Does Not Deskill Your Team](https://theaicommand.com/leadership/protect-the-reps-ai-deskilling#faq-3)

### How does AI adoption overload middle managers?

A 2026 Harvard Business Review study found that when organisations roll out AI, middle managers absorb three new responsibilities on top of unchanged delivery pressure: validating and checking AI outputs, coaching their teams to use the tools, and managing the organisational change. Because the rollout is framed as a technology project, none of that work is planned, resourced or acknowledged, so it lands as invisible overload on the manager layer.

Source: [Your AI Rollout Landed on Your Managers. Resource It.](https://theaicommand.com/leadership/ai-overload-on-middle-managers#faq-1)

### How does AI change what leaders are for?

It removes the knowledge advantage. When anyone can get a competent synthesis of a market, a competitor or an option in seconds, being the most informed person in the room stops being the source of a leader's value. A 2026 Journal of Business Research study argues the shift is human rather than technological: leadership moves from holding information to framing the real question, judging what is right, and taking responsibility for the outcome, which AI cannot do.

Source: [You Are No Longer the Smartest Person in the Room](https://theaicommand.com/leadership/not-the-smartest-person-in-the-room#faq-1)

### How is a charter different from a decision-rights map?

A decision-rights map answers who decides, placing AI on a ladder of inform, recommend or act. A delegation charter answers which recurring tasks the team hands to AI and which stay human. One is about authority over decisions, the other about the work itself. They complement each other; a task on the charter may still have its decisions governed by the map.

Source: [The AI Delegation Charter Your Team Actually Needs](https://theaicommand.com/leadership/your-teams-ai-delegation-charter#faq-2)

### How long should an AI trial run?

Long enough to capture normal variation and meaningful exceptions. Four to eight weeks may suit a frequent workflow, while lower-volume or seasonal work may need longer. Set the period in the measurement contract before the trial starts, not after the results arrive.

Source: [Stop Counting Prompts. Measure the Work That Improved](https://theaicommand.com/leadership/stop-counting-prompts-measure-work-improved#faq-3)

### How often should the charter be revisited?

Set a quarterly review at the latest, and give each line an event trigger that forces an earlier look: a new tool, a new regulation, or a near-miss. A charter that never changes is a poster. A charter that gets revisited on a cadence and on real events is a practice, and it is the only version worth building.

Source: [The AI Delegation Charter Your Team Actually Needs](https://theaicommand.com/leadership/your-teams-ai-delegation-charter#faq-4)

### How solid is the evidence?

Mixed, and worth knowing precisely. Doshi and Hauser is peer-reviewed, published in Science Advances in July 2024. Boussioux and colleagues is peer-reviewed, published in Organization Science in 2024. Hosanagar and Ahn is an arXiv preprint from December 2024 and has not been peer-reviewed. All of it comes from lab and crowdsourcing experiments on short stories, cartoon captions and business-idea challenges, run with crowdworkers and solvers, not from leadership teams doing real planning work. Applying it to your planning cycle is a reasoned extrapolation, not a measured finding.

Source: [AI Is Narrowing Your Team's Idea Pool. Only You Can See It.](https://theaicommand.com/leadership/ai-narrows-your-teams-idea-pool#faq-4)

### Is AI a fast track to reducing management headcount?

That assumption is where the trouble starts. Framing AI as a headcount saving ignores that the technology creates significant new supervisory and coaching work in the near term, and that work concentrates on managers. A leader who cuts the layer that is absorbing the transition can lose the very capacity that makes the adoption succeed. In the short run AI expands the manager's job before it shrinks anything.

Source: [Your AI Rollout Landed on Your Managers. Resource It.](https://theaicommand.com/leadership/ai-overload-on-middle-managers#faq-4)

### Is it acceptable for a leader to use AI for any team communication?

Yes, for most of it. Informational messages such as status updates, logistics and policy reminders exist to be clear and correct, and AI drafts them well. Messages carrying decisions benefit from AI pressure-testing, provided the leader stays the author of the judgement. The line sits at relationship-bearing messages, meaning recognition, personal feedback and apologies. The research points at those as the messages where perceived AI involvement collapses trust.

Source: [Don't Let AI Write the Messages That Build Trust](https://theaicommand.com/leadership/ai-leadership-communication-trust-triage#faq-2)

### Is it safe to put real names or records into the prompt?

No. You rehearse against a described archetype only, never a real person's name, performance notes or medical information. In Australia, restructure and performance conversations engage a duty to manage psychosocial hazards, so keeping real personal data out of the prompt is both a privacy reflex and a safety practice.

Source: [Rehearse the Hard Conversation Before You Have It](https://theaicommand.com/leadership/rehearse-the-hard-conversation-with-ai#faq-3)

### Is this just resistance to a productivity tool?

No. The point is not to slow AI down, it is to keep building the capability the organisation runs on. Harvard Business Review has warned that leaning on AI to the generic standard can strip an organisation's distinctive judgement, leaving it more efficient yet less legitimate, and California Management Review argues the tacit knowledge in your people's judgement is the real competitive moat. Protecting the reps is a capability investment, not a brake. Most work can and should be accelerated. The leader's job is to protect the small share that builds the expertise you will need later.

Source: [Protect the Reps: Lead So AI Does Not Deskill Your Team](https://theaicommand.com/leadership/protect-the-reps-ai-deskilling#faq-2)

### Is this the same problem as AI hallucination?

No, and that is why it is harder to catch. A hallucination introduces something that is not in the source, so a check against the source finds it. Decontextualisation keeps only what is in the source. Every sentence verifies. The distortion sits in what is absent, and absence does not trigger a fact check.

Source: [The Summary Kept the Number and Lost the Caveat](https://theaicommand.com/leadership/the-summary-lost-the-caveat#faq-2)

### Is unclear accountability a work health and safety issue in Australia?

It bears on one. Safe Work Australia's model Code of Practice on managing psychosocial hazards at work, published in July 2022, names lack of role clarity as a psychosocial hazard, defined as uncertainty, frequent changes, conflicting roles or ambiguous responsibilities and expectations. It separately names poor support, which includes inadequate training, tools and resources for a task. Making a person answerable for checking work they were never given the time or standard to check sits inside both descriptions. This is general information, not legal advice, and duties vary by jurisdiction.

Source: [When the AI Gets It Wrong, Who Carries It?](https://theaicommand.com/leadership/who-carries-it-when-ai-gets-it-wrong#faq-4)

### Should a free-trial deadline drive a team-wide AI adoption decision?

No. A promotional deadline is information about the vendor's pricing calendar, not evidence that your team is ready. Deciding to beat a deadline front-loads the cost of getting governance or fit wrong. Decide on real need, switching cost and governance readiness, and let the window close if those are not settled.

Source: [A Deadline Is Not a Decision: Greenlighting AI Before the Free Window Closes](https://theaicommand.com/leadership/a-deadline-is-not-a-decision#faq-2)

### Should I tell my team where I use AI in my communication?

Yes. Declaring the boundary is itself a trust signal. Telling your team you use AI for updates and logistics but never for recognition or feedback shows the relationship is taken seriously, and it removes the guessing game the research shows employees are already playing. The boundary becomes part of how you lead rather than a secret you are keeping.

Source: [Don't Let AI Write the Messages That Build Trust](https://theaicommand.com/leadership/ai-leadership-communication-trust-triage#faq-4)

### Should managers compare individual AI usage?

Generally avoid usage quotas or rankings. They reward low-value activity, punish people who have no suitable use case or who are protecting sensitive data, and create privacy and employment risks. Compare workflow outcomes instead, and discuss individual support in context.

Source: [Stop Counting Prompts. Measure the Work That Improved](https://theaicommand.com/leadership/stop-counting-prompts-measure-work-improved#faq-4)

### What are common mistakes leaders make when introducing AI to their team?

Three patterns undo progress. The absent sponsor announces AI matters then never engages, leaving a vacuum. The secret user uses AI privately, so all the modelling value is lost. The enforcer mandates use and sets targets, producing compliance and resentment rather than absorption. The lever is permission and example, not a quota.

Source: [Set the AI Norm: Your Team Copies How You Use It](https://theaicommand.com/leadership/set-your-teams-ai-norm#faq-5)

### What are decision rights and why has AI made them urgent?

Decision rights define who decides, who is consulted and who is merely informed, and on what basis. AI has made them urgent because it now moves from informing to recommending to acting inside the decision flow. Where no explicit rule exists, the system fills the gap and quietly assumes the right itself.

Source: [Decision Rights Are the Leadership Job AI Just Made Urgent](https://theaicommand.com/leadership/decision-rights-in-ai-enabled-teams#faq-1)

### What are the three review tiers for AI output?

Spot-check, for low-stakes internal work the reviewer samples rather than reads in full. Full human review before it leaves the team, for client-facing work, numbers, or anything where the raised bar bites. Two-person or named sign-off, for regulated, legal, financial, safety-critical or irreversible output.

Source: [The Review Tax: AI Adoption Is Done, Now Design the Checking](https://theaicommand.com/leadership/the-ai-review-tax#faq-3)

### What are the two ways leaders get AI decision rights wrong?

Over-trust, where a busy leader lets AI climb the ladder unchecked until recommendations become decisions and bounds disappear. Under-use, where a wary leader keeps everything at inform, redoes every suggestion by hand, and mistakes the drag for prudence. A decision-rights map steers between both by forcing a deliberate rung for each decision.

Source: [Decision Rights Are the Leadership Job AI Just Made Urgent](https://theaicommand.com/leadership/decision-rights-in-ai-enabled-teams#faq-5)

### What are workspace agents and how do they differ from custom GPTs?

Workspace agents are OpenAI's evolution of custom GPTs. Powered by Codex, they run in the cloud, can be shared across a team, connect to apps such as Slack, Google Drive, Salesforce and Notion, and can run on a schedule or via an API. OpenAI has said it will deprecate the organisation custom GPT standard and require teams to move to workspace agents.

Source: [A Deadline Is Not a Decision: Greenlighting AI Before the Free Window Closes](https://theaicommand.com/leadership/a-deadline-is-not-a-decision#faq-3)

### What can AI never own in a decision?

AI cannot own the why: the choice of goal, the weighing of values, and the judgement about what the organisation is for. It cannot own accountability when a decision affects livelihoods, customers or integrity, since a named human must answer for it. It cannot own the decisions that define a team's culture.

Source: [Decision Rights Are the Leadership Job AI Just Made Urgent](https://theaicommand.com/leadership/decision-rights-in-ai-enabled-teams#faq-4)

### What can AI not do in a leadership decision?

Three things. It cannot decide which problem is the real one to solve, because that requires context and priorities it does not hold. It cannot decide what is right, because that requires values and accountability. And it cannot own the outcome, because responsibility cannot sit with a model. AI can illuminate what is possible. Deciding what to do with that, and answering for it, stays with the leader.

Source: [You Are No Longer the Smartest Person in the Room](https://theaicommand.com/leadership/not-the-smartest-person-in-the-room#faq-4)

### What closes on 6 July 2026 for ChatGPT's workspace agents?

OpenAI's free access period for workspace agents ends on 6 July 2026. From that date, agent runs invoked inside ChatGPT move to credit-based pricing on the Business, Enterprise, Edu and Teachers plans. The free period was originally set to end on 6 May and was extended to 6 July when the feature reached general availability.

Source: [A Deadline Is Not a Decision: Greenlighting AI Before the Free Window Closes](https://theaicommand.com/leadership/a-deadline-is-not-a-decision#faq-1)

### What does a leader still own that AI cannot?

The duty of care to real people, accountability for decisions about roles, and trust. AI can change what work gets done, but it cannot decide who is affected, cannot take responsibility for the human consequences, and cannot extend or repair the trust a team places in its leader. Those stay with the person in charge.

Source: [Talk to Your Team About AI Before the Rumours Do](https://theaicommand.com/leadership/talking-to-your-team-about-ai-and-jobs#faq-4)

### What does deskilling from AI actually mean?

It means losing the skills you no longer practise because AI now does the task. People build expertise by doing the reps, the drafting, the analysis, the wrestling with a hard problem and the checking of the answer. When AI does those steps, the output still appears, but the learning that used to come with it does not. A Microsoft and Carnegie Mellon study found higher confidence in AI is associated with less critical thinking, and an MIT study found sustained AI use left people under-engaged and less able to recall their own output. The skill atrophies quietly, and you notice only when you need it.

Source: [Protect the Reps: Lead So AI Does Not Deskill Your Team](https://theaicommand.com/leadership/protect-the-reps-ai-deskilling#faq-1)

### What does it mean that AI reduces collective diversity?

It means the ideas get better one by one and more alike as a set. In a Science Advances study published in July 2024, Anil Doshi and Oliver Hauser had 293 writers produce short stories with no AI, with one GPT-4 idea, or with five. Novelty rose 5.4% with one idea and 8.1% with five. At the same time the stories converged, by 8.9% of the total range in the five-idea condition. The authors concluded that individual creativity rises while collective novelty is at risk. Nothing goes wrong for any individual. The loss only exists in the set.

Source: [AI Is Narrowing Your Team's Idea Pool. Only You Can See It.](https://theaicommand.com/leadership/ai-narrows-your-teams-idea-pool#faq-1)

### What does the model never get to own?

The decision behind the conversation, the duty of care in the room, the formal written record and the relationship the morning after. The model can play the counterpart and critique your framing. It does not get a vote on the message itself.

Source: [Rehearse the Hard Conversation Before You Have It](https://theaicommand.com/leadership/rehearse-the-hard-conversation-with-ai#faq-4)

### What governance should be in place before greenlighting workspace agents?

Name an admin owner, decide who may build, run, publish and connect agents, scope which connectors can touch sensitive systems, and confirm you can monitor and suspend agents through the compliance controls. If a connector would reach real customer or employee data before those rules exist, you are not ready to greenlight, deadline or not.

Source: [A Deadline Is Not a Decision: Greenlighting AI Before the Free Window Closes](https://theaicommand.com/leadership/a-deadline-is-not-a-decision#faq-4)

### What if I cannot promise no one will lose their job?

Then do not promise it. Credibility is the whole asset here, and a promise you cannot keep destroys it the first time reality contradicts you. Be honest about the uncertainty, be specific about what you can commit to (genuine consultation, notice, reskilling support, how decisions will be made), and be clear about what is not on the table. Honesty about uncertainty beats false comfort.

Source: [Talk to Your Team About AI Before the Rumours Do](https://theaicommand.com/leadership/talking-to-your-team-about-ai-and-jobs#faq-2)

### What if the AI creates more review work than it saves?

Measure total effort and rework across the whole workflow, not generation speed. AI often moves effort from creation to checking. If the checking burden exceeds the benefit, narrow the use case, improve the source material, change the review tier or stop the trial. A trial that gets stopped on evidence is a success of the method, not a failure.

Source: [Use AI to Kill Work Before You Accelerate It](https://theaicommand.com/leadership/use-ai-kill-work-before-accelerate#faq-5)

### What is a moral crumple zone?

It is a concept introduced by Madeleine Clare Elish in Engaging Science, Technology, and Society in 2019, describing how responsibility for an action may be misattributed to a human actor who had limited control over the behaviour of an automated system. Her comparison is to the crumple zone in a car, which absorbs the force of an impact. The difference is that a car's crumple zone protects the driver, while the moral crumple zone protects the integrity of the technological system at the expense of the nearest human operator. Elish was writing about aviation and nuclear accidents in an American context, but the shape travels to any workplace where a person is the last step before an automated output goes out.

Source: [When the AI Gets It Wrong, Who Carries It?](https://theaicommand.com/leadership/who-carries-it-when-ai-gets-it-wrong#faq-1)

### What is a strategic co-thinker?

It is one of four AI-driven leadership skills identified in the Bevilacqua and colleagues study: using AI as a genuine partner in thinking rather than an answer machine. A strategic co-thinker frames the real problem so the model solves that and not the obvious one, then treats the output as a draft to interrogate, asking what is flawed or missing, before applying their own judgement to decide.

Source: [You Are No Longer the Smartest Person in the Room](https://theaicommand.com/leadership/not-the-smartest-person-in-the-room#faq-2)

### What is an AI delegation charter?

It is a one-page, living record of your team's recurring tasks that names, for each one, the current owner, the role AI plays (none, draft, assist or do-and-check), the part that stays human, and when the line gets reviewed. The team writes it together, so AI becomes something they decide on rather than something done to them.

Source: [The AI Delegation Charter Your Team Actually Needs](https://theaicommand.com/leadership/your-teams-ai-delegation-charter#faq-1)

### What is an AI-assisted decision pre-mortem?

A pre-mortem imagines the plan has already failed, then lists the reasons it did. The method comes from Gary Klein's 2007 Harvard Business Review work. AI makes it available to a single leader in fifteen minutes on any decision. You instruct the model to act as a sceptic, run the failure scenario, develop the strongest objection, and audit the assumptions, then you decide.

Source: [Make AI Disagree With You Before You Decide](https://theaicommand.com/leadership/make-ai-disagree-before-you-decide#faq-2)

### What is the actual failure mode in AI summaries for decision makers?

A June 2026 preprint on compressing financial filings and earnings-call transcripts frames it as information fidelity, where compression loses fidelity when it changes the decision induced by the source. The authors name two diagnostic patterns: decontextualisation, where salient evidence is retained but separated from the caveats and contextual qualifiers needed for correct interpretation, and model dependency, where different compressors expose different views of the same source.

Source: [The Summary Kept the Number and Lost the Caveat](https://theaicommand.com/leadership/the-summary-lost-the-caveat#faq-1)

### What is the AI review tax?

It is when the time AI saves at the drafting stage leaks straight back out at the review stage. AI produces a fast first draft, but someone must check it, the bar for what passes has risen, and nobody has said what to do with the recovered time, so it dissipates into more checking.

Source: [The Review Tax: AI Adoption Is Done, Now Design the Checking](https://theaicommand.com/leadership/the-ai-review-tax#faq-1)

### What is the autonomy ladder for placing AI on a decision?

It has three rungs. At inform, AI gathers and summarises while a human decides. At recommend, AI proposes a specific option and a human approves or rejects it. At act within bounds, AI executes inside a defined envelope, like sending a routine response, with a human notified who can reverse it.

Source: [Decision Rights Are the Leadership Job AI Just Made Urgent](https://theaicommand.com/leadership/decision-rights-in-ai-enabled-teams#faq-3)

### What is the best single AI productivity measure?

There is no universal measure. Choose the closest credible outcome for the specific workflow, such as resolution rate, decision cycle time or usable first-pass quality, then pair it with quality, rework and risk guardrails so a gain in one place cannot hide a loss in another.

Source: [Stop Counting Prompts. Measure the Work That Improved](https://theaicommand.com/leadership/stop-counting-prompts-measure-work-improved#faq-2)

### What is the difference between AI adoption and AI absorption?

Adoption is people using the tools, a licence-utilisation number you can put on a dashboard. Absorption is the organisation redesigning how it works to capture value, an actual result. You can buy adoption, but absorption only comes when people change how they work, which happens when their manager makes it safe, expected and normal.

Source: [Set the AI Norm: Your Team Copies How You Use It](https://theaicommand.com/leadership/set-your-teams-ai-norm#faq-3)

### What is the Inform, Coordinate, Connect triage?

A one-time sort of every recurring message a leader sends. Inform covers facts and logistics, where AI can draft freely. Coordinate covers decisions and plans, where AI can structure and pressure-test while the leader authors the reasoning. Connect covers recognition, feedback and apologies, which the leader writes personally, with AI limited to flagging typos and unclear sentences. Each lane gets a one-line AI rule, written down once and applied on autopilot.

Source: [Don't Let AI Write the Messages That Build Trust](https://theaicommand.com/leadership/ai-leadership-communication-trust-triage#faq-3)

### What is the single highest-value thing a leader can change?

Require a what-was-left-out line on any paper that supports a consequential decision: the caveats, the dissent and the range that did not make the summary. It costs the author two minutes, it is impossible to write without re-reading the source, and it converts an invisible omission into a visible choice someone has signed.

Source: [The Summary Kept the Number and Lost the Caveat](https://theaicommand.com/leadership/the-summary-lost-the-caveat#faq-3)

### What matters more for AI adoption, individual training or manager behaviour?

Manager behaviour and the surrounding environment matter far more. Microsoft's 2026 Work Trend Index found organisational factors like culture, manager support and talent practices account for more than twice the reported AI impact of individual factors like mindset, at 67 per cent versus 32 per cent.

Source: [Set the AI Norm: Your Team Copies How You Use It](https://theaicommand.com/leadership/set-your-teams-ai-norm#faq-1)

### What should a leader do in the first hour after an AI-assisted failure?

Take the public accountability yourself, by name, before anyone asks who did it. Then separate the process question from the person question and run them on different clocks. Ask what the standard said the check was, whether the check was actually done, and whether the time and access to do it properly existed. Do not open with who approved this, because that question ends the inquiry at the nearest human and leaves the workflow that produced the failure completely untouched.

Source: [When the AI Gets It Wrong, Who Carries It?](https://theaicommand.com/leadership/who-carries-it-when-ai-gets-it-wrong#faq-3)

### What should I do if I have already sent AI-written praise?

Change the pattern rather than confessing. The next time someone genuinely earns recognition, write it yourself, name the specific thing they did, and send it the same day. Specificity is the tell that a human was paying attention, and it is the one thing a model cannot fake, because it was not in the room. One concrete hand-written acknowledgement rebuilds more signal than a month of polished generic praise.

Source: [Don't Let AI Write the Messages That Build Trust](https://theaicommand.com/leadership/ai-leadership-communication-trust-triage#faq-5)

### What should leaders do with the time AI saves?

Name where the saved time goes and protect it. If AI takes a two-hour task to thirty minutes, say out loud what the recovered ninety minutes is for, deeper client work, a stalled priority, or thinking time. Saved time that is not claimed gets reabsorbed into busywork and double-checking.

Source: [The Review Tax: AI Adoption Is Done, Now Design the Checking](https://theaicommand.com/leadership/the-ai-review-tax#faq-5)

### What should never be set to full delegation on the charter?

Anything where a wrong result could reach a customer, harm a person or corrupt the record before a human sees it, and any task that is really how someone builds a skill. The judgement, the relationship, the sign-off and the accountability stay human. The charter names those explicitly so the boundary is a decision, not an accident.

Source: [The AI Delegation Charter Your Team Actually Needs](https://theaicommand.com/leadership/your-teams-ai-delegation-charter#faq-5)

### What should senior leaders do about manager overload from AI?

Treat AI adoption as an operating-model change, not just a software rollout. Name the new work the rollout creates for managers, subtract something from their load to make room for it, resource the coaching and validation with time and training, and close the gap between how executives and managers experience AI by getting into the real workflow. The sustainability of the manager layer is a leadership responsibility, not something to delegate to the tool.

Source: [Your AI Rollout Landed on Your Managers. Resource It.](https://theaicommand.com/leadership/ai-overload-on-middle-managers#faq-3)

### What should you keep out of the prompt?

Keep real personal, claimant or commercially sensitive information out of the prompt unless the tool is sanctioned for it. The model is a thinking aid, not a system of record, and it should not become a back door for sensitive data.

Source: [Make AI Disagree With You Before You Decide](https://theaicommand.com/leadership/make-ai-disagree-before-you-decide#faq-5)

### When is the right time to have this conversation?

Before the rumours, not after. The moment AI is visibly changing work in your team, or a rollout is coming, is the moment to talk, while you can still shape the narrative. Waiting until people are already anxious or a change is already decided means you are managing damage instead of building trust.

Source: [Talk to Your Team About AI Before the Rumours Do](https://theaicommand.com/leadership/talking-to-your-team-about-ai-and-jobs#faq-5)

### When should a leader use this technique?

Reserve it for decisions that are hard to reverse, expensive to get wrong, or the ones you feel most certain about, because certainty is usually the signal that you have stopped looking for problems. You do not need to run it on every call. A thinking partner earns its place on exactly those high-stakes decisions.

Source: [Make AI Disagree With You Before You Decide](https://theaicommand.com/leadership/make-ai-disagree-before-you-decide#faq-3)

### When should I not use this?

Run it only for conversations that carry weight, like a restructure, serious feedback or a negotiation you cannot afford to fumble. Run it for everything and it becomes avoidance with extra steps. The signal you are using it well is walking in slightly bored by your own opening, because you have already heard it land badly once and fixed it.

Source: [Rehearse the Hard Conversation Before You Have It](https://theaicommand.com/leadership/rehearse-the-hard-conversation-with-ai#faq-5)

### When should work be automated rather than augmented?

Automate where inputs, rules, quality thresholds and exceptions are well understood and the consequences of an error are contained, with monitoring and an exception path in place. Augment where context, judgement or accountability remains material, keeping a human as the author of the decision and AI in a preparation or checking role.

Source: [Use AI to Kill Work Before You Accelerate It](https://theaicommand.com/leadership/use-ai-kill-work-before-accelerate#faq-4)

### Which work should be reviewed first?

Start with high-volume recurring work that has a visible recipient and low safety or legal consequence. Monthly reporting, project approvals and coordination meetings are good candidates. Avoid beginning with a politically sensitive workflow or a poorly understood critical control, because the first review should build the habit, not test the organisation's appetite for conflict.

Source: [Use AI to Kill Work Before You Accelerate It](https://theaicommand.com/leadership/use-ai-kill-work-before-accelerate#faq-1)

### Whose job is this?

The leader's, and it cannot be delegated to the technology team. McKinsey's research points to leaders, not employees, as the main brake on getting value from AI, and the deskilling risk is the same shape: it is a workforce-capability decision, not a tooling one. Deciding which work stays human for development reasons, and holding that line against short-term output pressure, is a leadership judgement about the future capability of the team.

Source: [Protect the Reps: Lead So AI Does Not Deskill Your Team](https://theaicommand.com/leadership/protect-the-reps-ai-deskilling#faq-4)

### Why build the charter with the team rather than for them?

Because most of the anxiety about AI is about things being decided about people without them. A charter the team co-writes turns AI from a threat into a shared choice, and it draws on the people who actually know which parts of a task carry judgement and which are safe to hand over. A charter imposed from above rebuilds the very fear the conversation was meant to settle.

Source: [The AI Delegation Charter Your Team Actually Needs](https://theaicommand.com/leadership/your-teams-ai-delegation-charter#faq-3)

### Why can't AI handle its own review?

AI cannot decide its own review tier, because the stakes are a judgement about the business, not something the model reads off the text. It cannot certify that its output clears a human standard, and it cannot carry accountability for what ships. Responsibility sits with a person.

Source: [The Review Tax: AI Adoption Is Done, Now Design the Checking](https://theaicommand.com/leadership/the-ai-review-tax#faq-4)

### Why do AI assistants tend to agree with you?

The training method behind most assistants, reinforcement learning from human feedback, can reward responses that match user beliefs over truthful ones. OpenAI rolled back a 2025 update for being overly flattering, and Anthropic's research found five leading assistants all exhibit sycophancy. People often rate the agreeable answer above the correct one, which is how the behaviour got trained in.

Source: [Make AI Disagree With You Before You Decide](https://theaicommand.com/leadership/make-ai-disagree-before-you-decide#faq-1)

### Why do executives miss the burden on managers?

Because they experience AI differently. Research shows executives tend to see AI as a strategic advantage viewed from above, while managers meet its flaws inside real workflows, under real constraints, without enough time or support. The C-suite sees the promise and the potential headcount saving; the manager sees the messy reality of making it work. That perception gap is why the burden goes unseen and unfunded.

Source: [Your AI Rollout Landed on Your Managers. Resource It.](https://theaicommand.com/leadership/ai-overload-on-middle-managers#faq-2)

### Why does blame land on the most junior person in the chain?

Because proximity is the easiest answer available, and because that person is the only party the organisation can actually sanction. The vendor is not in the room, the model cannot be performance managed, and the decision to deploy the tool was made somewhere above the failure. Elish's account of Three Mile Island is precise on the mechanism: the operators knew the system was malfunctioning, but they did not have sufficient information or authority to take corrective actions. Someone can be answerable for an output without ever having had the control, the information or the time to prevent it going wrong.

Source: [When the AI Gets It Wrong, Who Carries It?](https://theaicommand.com/leadership/who-carries-it-when-ai-gets-it-wrong#faq-2)

### Why is this a leadership problem rather than an individual one?

Because no individual has any reason to fix it. Doshi and Hauser name it as a social dilemma: if writers learn their AI-assisted work is rated as more creative, they have an incentive to use AI more, and collective novelty may fall further. Each person is correctly optimising the thing they can see, which is their own output, and each is succeeding. The narrowing is only visible to whoever holds the full set of options. That vantage point is the leader's, which makes the remedy structural rather than personal.

Source: [AI Is Narrowing Your Team's Idea Pool. Only You Can See It.](https://theaicommand.com/leadership/ai-narrows-your-teams-idea-pool#faq-3)

### Why rehearse a conversation with AI instead of just drafting it?

Drafting the message is the low-value use of AI here. A hard conversation rarely fails on the words you planned. It fails on your reaction to the response you did not. Rehearsing lets you feel the resistance before it is real, so you spend your composure in practice and arrive with it intact.

Source: [Rehearse the Hard Conversation Before You Have It](https://theaicommand.com/leadership/rehearse-the-hard-conversation-with-ai#faq-1)

### Why should a leader raise AI and job security proactively?

Because the anxiety is already there. Around 30 per cent of Australian workers are worried AI will replace their job, per Finder's April 2026 survey. If leaders say nothing, the silence does not read as reassurance; it reads as bad news being withheld, and rumour fills the vacuum. A leader who raises it first shapes an honest conversation instead of managing a panic.

Source: [Talk to Your Team About AI Before the Rumours Do](https://theaicommand.com/leadership/talking-to-your-team-about-ai-and-jobs#faq-1)

## AI news and analysis

What shipped, what it changes, and what it means for regulated work.

### Are GPT-5.6's benchmark claims trustworthy?

Treat them cautiously. The benchmarks are all OpenAI's own, run on a preview and not independently verified. The claim that Sol is competitive with Mythos Preview using only about a third of the output tokens is a vendor figure on a vendor benchmark. Because the preview is closed, you cannot test any of it against your own tasks yet.

Source: [GPT-5.6 Sol Lands. The Frontier Just Got Gated.](https://theaicommand.com/ai-news/gpt-5-6-sol-and-the-gated-frontier#faq-5)

### Are multi-agent systems better than a single AI agent?

Not by default. Anthropic reports that multi-agent systems use about 15 times the tokens of a chat interaction and add rapid coordination complexity, with early agents duplicating each other's work and failing to divide labour. Multiple agents help when a task genuinely splits into independent parallel parts and its value is high enough to pay for the extra cost. For most tasks, one capable agent is cheaper, simpler and easier to govern.

Source: [More Agents Is Not More Intelligence. Govern the Coordination.](https://theaicommand.com/ai-news/more-agents-is-not-more-intelligence#faq-2)

### Are young Australian graduates being hit by AI?

Not on this data. Unlike some US findings, employment for Australians aged 20 to 24 grew slightly faster than for those 25 and over since ChatGPT arrived. Young graduate unemployment sits at 5.4 per cent, lower than any point in the five years before COVID, and the share of young graduates in degree-level jobs rose from 51.1 to 52.2 per cent.

Source: [Canberra Just Measured What AI Is Doing to Jobs. It Found 2%.](https://theaicommand.com/ai-news/dewr-ai-employment-australia-report#faq-4)

### Can an AI summary count as medical evidence in a workers compensation claim?

No. Liability and medical questions are decided on medical evidence from qualified practitioners, not a chatbot summary. AI can help a claimant prepare for an appointment or explain a term, but it cannot be the appointment and it is not evidence. A delegated decision maker must review and own the outcome.

Source: [ChatGPT Just Got Better at Health. Mind the Boundary.](https://theaicommand.com/ai-news/chatgpt-health-intelligence-and-the-boundary#faq-3)

### Can an employee use GPT-Live to record a workplace meeting?

Technical capability is not permission. Workplace surveillance and listening-device rules in Australia are state and territory based, for example the Workplace Surveillance Act 2005 (NSW) and the Surveillance Devices Act 1999 (Vic), and personal and sensitive information may also engage the Privacy Act 1988 and the Australian Privacy Principles. An organisation should obtain legal and privacy advice for its setting and establish notice, authority, purpose, access and retention rules before recording real meetings.

Source: [GPT-Live Makes Voice a Work Interface. Check What Gets Recorded](https://theaicommand.com/ai-news/gpt-live-voice-workplace-recording-controls#faq-3)

### Can Australian users still access Claude models?

Australian readers are foreign nationals under the directive, so Fable 5 and Mythos 5 are unavailable to them, as they are to everyone. Every other Anthropic model is unaffected. Claude Opus 4.8 is now the most capable model available, and Claude Sonnet 4.6 and Claude Haiku 4.5 remain online.

Source: [AI Week in Review, 8-14 June 2026: A Frontier Model Pulled by Government Order](https://theaicommand.com/ai-news/ai-week-in-review-8-14-june-2026#faq-2)

### Can HR use AI in recruitment in Australia?

Yes. AI can reduce administrative load by helping screen applications, summarise resumes, prepare interview questions and communicate with candidates. The better question is where AI should support hiring, where it should not decide, and what evidence shows the process stayed fair, private and human-led. Used poorly, it turns a people decision into poorly documented automation.

Source: [AI in Hiring Needs Human Review Before It Needs Another Tool](https://theaicommand.com/ai-news/ai-in-hiring-needs-human-review#faq-1)

### Can I put a claimant's or employee's health details into ChatGPT?

No. Under the Privacy Act 1988 health information is sensitive information, and the OAIC sets a higher consent bar and generally expects express consent. A consumer chatbot is not the place for a diagnosis or medical history. De-identify first, and only use an approved enterprise instance for any real material.

Source: [ChatGPT Just Got Better at Health. Mind the Boundary.](https://theaicommand.com/ai-news/chatgpt-health-intelligence-and-the-boundary#faq-2)

### Can I use a model to decide whether an arrangement is material under CPS 230?

A model can make the triage repeatable but cannot make the call. It takes the facts, walks them against published CPS 230 criteria, and hands a structured first pass that a named risk owner accepts, amends or rejects. The aim is consistency before sign-off, never an unreviewed classification entering the register.

Source: [AI Is Moving Into the Core Systems of Regulated Work](https://theaicommand.com/ai-news/ai-in-regulated-core-systems#faq-4)

### Can I use GPT-5.6 right now?

No. OpenAI previewed GPT-5.6 on 26 June but, at the US government's request, started with a limited preview for a small group of trusted partners. During the preview the models are reachable only through the API and Codex, by that select group. General availability is planned for the coming weeks.

Source: [GPT-5.6 Sol Lands. The Frontier Just Got Gated.](https://theaicommand.com/ai-news/gpt-5-6-sol-and-the-gated-frontier#faq-1)

### Can you delete a single record from a fine-tuned model?

Not reliably. Machine unlearning is an active research field precisely because full retraining is the fallback everyone wants to avoid, and the surveys close on open challenges rather than a settled method. Microsoft's own documentation lists it as a limitation, noting that fine-tuning may need to be repeated whenever the data is updated or an updated base model is released. Retraining from a corrected dataset works, but it is a project and it does not produce evidence that the old artefact forgot anything.

Source: [Fine-Tuning Writes Your Data Into the Model](https://theaicommand.com/ai-news/fine-tuning-writes-your-data-into-the-model#faq-2)

### Do heavier AI delegators really feel more optimistic about their careers?

In the survey, yes. Across all six job-quality dimensions measured, pay, job security, finding a new job, meaning, autonomy and human interaction, people with a higher share of automated sessions were more optimistic about AI's effect on their work next year. This is a correlation, not proof of cause, and Anthropic is candid about that.

Source: [What 9,700 Real Users Actually Do With Claude](https://theaicommand.com/ai-news/what-9700-real-users-do-with-claude#faq-3)

### Do structured outputs make the model more accurate?

No, and this is the point teams most often miss. Structured outputs guarantee the shape of the answer, not the truth of it. Google's documentation is explicit that even when output is syntactically correct JSON you should always validate the values, and warns to handle schema-compliant but semantically incorrect outputs. The schema kills format and parsing errors. It does not kill a wrong number in the right field. A confidently wrong value that fits the schema is arguably more dangerous, because it looks clean.

Source: [Structured Outputs: Make Your AI Return Data You Can Audit](https://theaicommand.com/ai-news/structured-outputs-schema-enforced-ai-regulated-work#faq-2)

### Do these North American numbers apply to Australian audit teams?

Treat them as a mirror, not a local statistic. The value is the self-assessment: hold your own function against the same two questions, whether you have genuinely embedded AI in a completed audit, and whether you are ready for AI-enabled fraud. Internal audit's obligations under prudential standards such as CPS 230 make an unevidenced "we adopted AI" a gap worth closing.

Source: [Internal Audit's AI Say-Do Gap Now Has Numbers](https://theaicommand.com/ai-news/internal-audit-ai-say-do-gap#faq-3)

### Does a 2 million token context window mean I can stop using RAG?

No. Long multimodal context complements RAG rather than replacing it, because the two answer different questions. Long context suits a small number of large, complex documents needing holistic reasoning. For high-volume, freshness-sensitive or cost-sensitive workloads, well-built RAG remains faster, cheaper and more current.

Source: [2M-Token Multimodal Contexts: Where They Actually Pay Off](https://theaicommand.com/ai-news/multimodal-context-windows-real-workflows#faq-1)

### Does a Content Credential prove that content is true?

No. OpenAI's own guidance on its verification tool states that it only confirms whether an image was generated by OpenAI, and does not confirm that the image is accurate, unedited, legally owned or presented in the correct context. Provenance answers where something came from and how it was handled. Accuracy remains a separate judgement made by a person.

Source: [Stop Detecting AI. Start Checking Provenance.](https://theaicommand.com/ai-news/stop-detecting-ai-check-provenance#faq-3)

### Does a smaller AI model mean lower risk?

No. Smaller does not automatically mean safer. A small model in a sensitive process can create more risk than a large model used for low-stakes drafting. Context matters more than model size: decision influence, data sensitivity, automation level, stakeholder impact, transparency and vendor dependency all drive the real risk.

Source: [Small Models, Edge AI and the Next Governance Blind Spot](https://theaicommand.com/ai-news/small-models-edge-ai-governance#faq-2)

### Does adopting MCP make AI integration secure?

No. MCP standardises integration but does not secure it. In April 2025 researchers found outstanding issues including prompt injection and poisoned tools enabling data exfiltration. Because a model can be steered by content it reads, a malicious document or compromised connector can instruct it to misuse other connected tools.

Source: [Model Context Protocol: The Standard Wiring AI Into Your Tools](https://theaicommand.com/ai-news/model-context-protocol-govern-the-connectors#faq-3)

### Does AI observability give me an audit trail by default?

No. The OpenTelemetry project states that by default no prompt content or tool arguments are captured with GenAI telemetry, and only metadata like model names, token counts and durations are included. That metadata is genuinely useful for cost and reliability, but it cannot answer why a model produced a particular output, because the prompt and the completion are not recorded. An audit trail requires deliberately opting in to content capture, which is a separate decision with its own privacy consequences.

Source: [Your AI Logs the Tokens. Not the Decision.](https://theaicommand.com/ai-news/trace-the-decision-not-just-the-tokens#faq-1)

### Does any of this apply to models below the frontier?

The trigger is capability. GPT-5.6 drew review because its system card rates all three models High in both cybersecurity and biological and chemical risk. A general productivity model your team uses for drafting is unlikely to attract a government gate. Score exposure by the capability tier and the lab's jurisdiction, not by the vendor's name.

Source: [A Government Now Vets Who Gets the Model. File It as a Vendor Risk.](https://theaicommand.com/ai-news/gated-model-access-is-a-vendor-risk#faq-5)

### Does ChatGPT store GPT-Live audio?

OpenAI says audio clips from Live and Advanced Voice conversations are stored with the transcript in chat history and retained for 30 days. Deleting a chat triggers deletion of associated clips within 30 days, unless OpenAI needs to keep them for security, safety or legal reasons. Archiving is not deletion.

Source: [GPT-Live Makes Voice a Work Interface. Check What Gets Recorded](https://theaicommand.com/ai-news/gpt-live-voice-workplace-recording-controls#faq-2)

### Does grounding replace human sign-off?

No. Grounding raises the reliability of the input, but a person still checks the quoted words against the source, confirms the context matches, and makes the decision. For regulated work the rule holds that AI assists and the accountable person decides. Grounding makes that sign-off faster and more defensible because there is a traceable source behind the answer.

Source: [Ground the Model, Do Not Trust Its Memory](https://theaicommand.com/ai-news/grounding-beats-model-memory#faq-5)

### Does more AI demand automatically mean higher household electricity prices?

No. That outcome depends on how projects connect, who pays for network upgrades, whether new supply and storage are added, and how flexible the load can be. The government's expectations explicitly say new facilities should avoid upward price pressure and cover their share of connection costs. Whether individual projects deliver that result requires evidence.

Source: [AI's Next Constraint Is Power. Australia Has Started Writing the Rules](https://theaicommand.com/ai-news/ai-power-australia-grid-rules#faq-5)

### Does on-device AI remove the need for human review on regulated tasks?

No. On-device models still hallucinate, and privacy on the inference path does not equal accuracy on the output. The human-in-the-loop review gate that applies to any AI-assisted regulated workflow applies just as firmly to on-device output. Privacy gains do not lower the verification bar.

Source: [On-Device AI at Work: Apple Intelligence and Pixel Gemini Nano](https://theaicommand.com/ai-news/on-device-ai-pixel-and-apple-at-work#faq-4)

### Does prompt caching close the cost gap between long context and RAG?

Sometimes. Anthropic and OpenAI prompt caching cut repeat-context query costs by 75 to 90 percent. Asking many questions of one long document in a session lands cached long context close to RAG on cost. One query each against many different documents gets no benefit, so RAG wins clearly. Access pattern decides.

Source: [2M-Token Multimodal Contexts: Where They Actually Pay Off](https://theaicommand.com/ai-news/multimodal-context-windows-real-workflows#faq-4)

### Does the evaluation mean ChatGPT is now better than my doctor?

No. A doctor panel rated GPT-5.5 Instant's written answers higher than physician-written answers, but that is a written-response evaluation, not a clinical trial. Scoring well on written questions is not assessing a patient with examination and history. OpenAI does not claim the model is better than your doctor.

Source: [ChatGPT Just Got Better at Health. Mind the Boundary.](https://theaicommand.com/ai-news/chatgpt-health-intelligence-and-the-boundary#faq-4)

### Does the Privacy Act apply to what an AI agent remembers?

Treat it that way. A memory store that accumulates customer or claimant detail is a record of personal information, and the agent remembering it is still collection and retention by your organisation. Purpose, minimisation, correction and deletion obligations follow, and APRA-regulated entities also need to know where the store lives and who can access it. The agent remembered it is not a defence.

Source: [Your AI Agent Can Remember Now. Govern What It Keeps.](https://theaicommand.com/ai-news/govern-ai-agent-memory#faq-4)

### Does this affect vendors other than Anthropic?

Yes. The pattern generalises. For the second time in a month a frontier model's availability moved on government action, and any major vendor can change a model's behaviour under you to close a risk. Read the Fable 5 specifics as a template for OpenAI, Google and the rest, and treat access as a live variable rather than a settled fact.

Source: [Fable 5 Returns With a Jailbreak Severity Framework](https://theaicommand.com/ai-news/fable-5-returns-jailbreak-severity-framework#faq-5)

### Has Australia introduced binding electricity rules specifically for AI data centres?

Not yet in the form described by the March 2026 AEMC proposal. The Package 2 standards remain a draft, with a final determination scheduled for 29 October 2026. Separate Australian Government expectations already guide how new or expanded data-centre and AI infrastructure projects may be prioritised in Commonwealth assessments, but those expectations do not replace existing law.

Source: [AI's Next Constraint Is Power. Australia Has Started Writing the Rules](https://theaicommand.com/ai-news/ai-power-australia-grid-rules#faq-1)

### Has open-source AI actually caught up with closed models?

Partly. On benchmark numbers the gap is small, but on production reliability, tool-use accuracy and long-context coherence the gap is still meaningful. GPT-5 and Claude Opus 4.7 remain the right answer for the most demanding workloads. For the bulk of enterprise workloads, open is now good enough.

Source: [The Open-Source Frontier in April 2026: Llama 4, DeepSeek R2, Mistral Sovereign](https://theaicommand.com/ai-news/open-source-frontier-april-2026#faq-4)

### How can I tell if I have a grounding problem?

Run the same question three or four times. If the answers drift, you have a grounding problem, not a prompt problem, and the fix is a tighter source rather than cleverer wording. A second signal is an answer you cannot trace back to specific words in a named source. If nothing anchors the output, treat it as a draft, not a finding.

Source: [Ground the Model, Do Not Trust Its Memory](https://theaicommand.com/ai-news/grounding-beats-model-memory#faq-4)

### How can someone start applying context engineering this week?

Three moves work for anyone. Audit what you load into projects, workspaces or agents and cut anything that is not high signal. Retrieve relevant material on demand rather than dumping everything. Treat a misbehaving workflow as a context problem first, asking whether the model has too much, too little, or the wrong information before rewording.

Source: [Context Engineering: What the Model Is Allowed to See](https://theaicommand.com/ai-news/context-engineering-what-the-model-sees#faq-5)

### How do AI tools change workplace privacy risk?

AI widens the data surface beyond traditional records like personnel files and payroll. Transcription tools collect voice and sensitive discussion, summarisation assistants process performance or health information, productivity tools infer patterns from emails and calendars, and HR chatbots log questions about leave, grievances or entitlements, touching personal and sensitive categories indirectly.

Source: [Workplace AI and Privacy: The Trust Test HR Cannot Outsource](https://theaicommand.com/ai-news/workplace-ai-and-the-privacy-trust-test#faq-1)

### How do I build a private evaluation Project to test an AI tool?

Create a dedicated Project in ChatGPT or Claude with fixed standing instructions. Upload a task set of ten to thirty de-identified real tasks, a scoring rubric, known-good answers kept separate, and a source pack of public documents, so every candidate is briefed and tested identically without the test drifting.

Source: [Stop Trusting the Leaderboard: Evaluate AI on Your Own Work](https://theaicommand.com/ai-news/evaluate-ai-tool-before-you-buy#faq-2)

### How do I get value from GPT-5 in the enterprise?

Build a clear taxonomy of your workloads and match each to the right model. Measure task-level cost including retries and human review, not just per-token price. Instrument tool-call success rates and log tool-use traces from day one, so you can debug failures and prove you are getting the main benefit.

Source: [GPT-5 in the Enterprise: 60-Day Debrief](https://theaicommand.com/ai-news/gpt-5-enterprise-rollout-debrief#faq-5)

### How do I ground a model in a rule or award rather than trusting its memory?

Open the authoritative source in full, start a fresh chat in ChatGPT, Claude or equivalent, and paste the exact text in or attach the document. Ask your question with an instruction to answer only from the pasted source and to quote the words it relies on. The model becomes the reader and the instrument stays the authority.

Source: [Ground the Model, Do Not Trust Its Memory](https://theaicommand.com/ai-news/grounding-beats-model-memory#faq-3)

### How do you actually build one?

Define a JSON schema for the data you want, mark every field as required, and set additionalProperties to false so the model cannot invent fields. Vendor implementations have limits worth respecting, for example a ceiling of around 100 object properties and roughly five levels of nesting, so keep schemas flat and focused. Handle the edge cases the docs name: a model can still fail to match the schema if it refuses on safety grounds, so detect refusals via the stop reason rather than assuming every response is parseable. Then validate the values, because the schema does not.

Source: [Structured Outputs: Make Your AI Return Data You Can Audit](https://theaicommand.com/ai-news/structured-outputs-schema-enforced-ai-regulated-work#faq-4)

### How do you close the gap without just buying more tools?

The surveys name skills, standards and time, not more software, as the binding constraints. Turn one stalled pilot into embedded practice: write a standard for when AI output can support a finding, train at least one auditor to use the tool inside real testing, and pilot one AI-enabled fraud detection procedure. Adoption becomes real when it produces evidence, not when a licence is bought.

Source: [Internal Audit's AI Say-Do Gap Now Has Numbers](https://theaicommand.com/ai-news/internal-audit-ai-say-do-gap#faq-4)

### How does cheaper AI affect privacy and governance in Australia?

For years cost quietly acted as a governance control, keeping AI with a few power users. The falling cost curve removes that fence, so AI spreads into more documents, inboxes and case notes by default. Your use-and-disclosure decisions under the Australian Privacy Principles now apply to a much larger surface.

Source: [OpenAI Built Its Own Chip. The Real Story Is the Cost of Intelligence.](https://theaicommand.com/ai-news/openai-custom-chip-and-the-ai-cost-curve#faq-3)

### How does Claude Fable 5 retention affect Australian privacy and APRA obligations?

The mandatory 30-day retention makes any zero-retention control description in an APP 11 assessment inaccurate, so the assessment needs reopening and the data flow re-mapping. For APRA-regulated entities, this unilateral change triggers CPS 230 material service provider review and CPS 234 information security reassessment.

Source: [Claude Fable 5: Frontier Capability, With Conditions Attached](https://theaicommand.com/ai-news/claude-fable-5-in-practice#faq-2)

### How does CPS 230 apply when an integrator embeds AI in my platform?

Once an integrator embeds a model into your claims or lending platform, you take on a material service arrangement. APRA's CPS 230, in force since 1 July 2025, pulls it into scope where it supports a critical operation, with obligations to assess it, monitor it and be able to exit it.

Source: [AI Is Moving Into the Core Systems of Regulated Work](https://theaicommand.com/ai-news/ai-in-regulated-core-systems#faq-3)

### How does MCP connector governance map to Australian regulatory obligations?

A connector wiring AI into a core system is part of your information security surface, squarely within what APRA's CPS 234 expects. Where it reaches a system the business depends on, it resembles the material service arrangements CPS 230 asks you to identify and manage. Treat a connector as third-party access deserving inventory, scoping and review.

Source: [Model Context Protocol: The Standard Wiring AI Into Your Tools](https://theaicommand.com/ai-news/model-context-protocol-govern-the-connectors#faq-5)

### How does the AI Credits billing change affect Copilot costs?

GitHub Copilot moved to usage-based token billing called AI Credits on 1 June 2026, the same week as the model swap. Cost becomes a function of behaviour rather than headcount, so per-seat assumptions no longer hold and any FY2026-27 budget built on them is wrong on day one.

Source: [Microsoft's Seven MAI Models: The In-House Bet Under Copilot](https://theaicommand.com/ai-news/microsoft-mai-models-copilot#faq-4)

### How does the OWASP agentic list relate to APRA CPS 234 and CPS 230?

For APRA-regulated entities, agents sit within existing obligations. CPS 234 Information Security reaches an agent as an information asset and access path. CPS 230 Operational Risk Management, live since 1 July 2025, brings the agent's third-party stack into scope where it feeds critical operations, so agents belong in access reviews and risk registers.

Source: [The OWASP Agentic Top 10: A Defence Playbook for the Agents You Are Deploying](https://theaicommand.com/ai-news/owasp-agentic-top-10-defence-playbook#faq-5)

### How does this affect Workers Compensation and claims professionals?

De-identification obligations do not change because the model became more capable, but an agentic default raises the stakes of casual use. A model that can act on uploaded content is a worse place for an unredacted document than one that can only summarise it. De-identify before anything touches a consumer tool.

Source: [Gemini 3.5 Flash: Google Makes the Agent the Default](https://theaicommand.com/ai-news/gemini-3-5-flash-agent-default#faq-4)

### How important is manager behaviour and culture to AI adoption at scale?

Culture, manager support and talent practices reportedly account for twice the AI impact of individual effort alone. Managers shape outcomes by checking quality not just volume, supporting disclosure of AI use, and asking better questions about sources, errors, judgement and risk. Power users cannot compensate for unclear expectations or weak standards.

Source: [The AI Pilot-to-Scale Gap Is an Operating Model Problem](https://theaicommand.com/ai-news/the-ai-pilot-to-scale-gap#faq-5)

### How is agent memory different from a bigger context window?

The context window is what the model sees at the moment it answers, and it resets. Memory is information the agent writes down and reads back in later sessions, stored outside the window on your infrastructure. Anthropic's documentation describes memory files that persist between sessions. That persistence is what makes memory a separate governance problem, because a single entry shapes behaviour long after the session that wrote it.

Source: [Your AI Agent Can Remember Now. Govern What It Keeps.](https://theaicommand.com/ai-news/govern-ai-agent-memory#faq-1)

### How is this different from the Anthropic Fable 5 suspension?

The mechanism differs. Fable 5 was disabled under an export-control directive that cut off foreign nationals, a switch-off. GPT-5.6 was restricted at launch to a vetted list, a gate on who gets in. One removes access you had, the other withholds access you never got. Both belong in your vendor file, but they create different continuity risks.

Source: [A Government Now Vets Who Gets the Model. File It as a Vendor Risk.](https://theaicommand.com/ai-news/gated-model-access-is-a-vendor-risk#faq-3)

### How long do AI agents now run?

By May 2026, 80.6 per cent of sampled individual Codex users had set a task estimated to exceed 30 minutes of human work, 70.2 per cent one exceeding an hour, and 25.6 per cent one exceeding eight hours. OpenAI reports its heaviest users run many agents in parallel, generating more than 60 hours of agent turns in a single day.

Source: [AI Agents Just Went From Minutes to Hours. The Control Point Is Where They Run.](https://theaicommand.com/ai-news/long-running-ai-agents-govern-where-they-run#faq-2)

### How much Australian electricity do data centres use?

AEMO reported in June 2026 that 162 operating Australian data centres accounted for about 2 per cent of grid-supplied electricity. Its 2025 assumptions projected about 12 terawatt hours, or around 6 per cent, by 2030 and about 34 terawatt hours, or around 12 per cent, by 2050. These are data-centre scenarios, not AI-only measurements.

Source: [AI's Next Constraint Is Power. Australia Has Started Writing the Rules](https://theaicommand.com/ai-news/ai-power-australia-grid-rules#faq-2)

### How much does GPT-5 cost compared to GPT-4o?

GPT-5 Standard runs at USD 8 per million input tokens and USD 24 output. GPT-5 Reasoning runs at USD 12 input and USD 48 output. GPT-4o sits at USD 5 and USD 15. Higher per-token rates can still mean lower task cost when retries drop, so measure cost per completed task.

Source: [GPT-5 in the Enterprise: 60-Day Debrief](https://theaicommand.com/ai-news/gpt-5-enterprise-rollout-debrief#faq-2)

### How much money can tuning reasoning budgets actually save?

One team found 78 per cent of traffic could run with zero reasoning budget, saving roughly 40 per cent of spend. Tightening ceilings on long-running requests cut tail-end cost by 30 to 60 per cent. Routing requests by complexity to different models and caps lowered total cost by 35 to 50 per cent.

Source: [Reasoning Budgets in Production: How Teams Are Spending Them](https://theaicommand.com/ai-news/anthropic-reasoning-budgets-in-production#faq-2)

### How reliable is agentic browsing in production right now?

Reliability is roughly 60 to 75 per cent on real-world tasks. Benchmark numbers are 73 per cent for Computer Use 2.0, 67 per cent for Operator and 64 per cent for Manus on AGENT-Bench. Narrow, repetitive tasks reach the high 80s to low 90s, while novel multi-step tasks drop to the 50s and 60s.

Source: [Agentic Browsing: What Actually Shipped This Month](https://theaicommand.com/ai-news/agentic-browsing-what-shipped-in-april#faq-2)

### How reliable is Genie One based on the reported benchmark?

Databricks reports Genie answered 84.5 per cent of questions correctly on the first attempt on its own 28-question suite, against 52.4 per cent for the strongest competitor tested. That is a vendor-run internal result, and 84.5 per cent still means roughly one answer in six is wrong before anyone checks it.

Source: [Business Teams Can Now Build Their Own AI Agents](https://theaicommand.com/ai-news/business-teams-building-their-own-ai-agents#faq-4)

### How should a regulated business govern multi-agent AI?

Treat each agent as a named actor, not a feature. Give every agent its own identity, scope its access to least privilege, define an explicit division of labour so agents do not duplicate or contradict each other, log every agent-to-agent message, and bound the blast radius with human checkpoints on consequential actions. For Australian regulated work this is existing practice, mapped to CPS 234 information security, CPS 230 operational resilience and the Privacy Act, not a new legal regime.

Source: [More Agents Is Not More Intelligence. Govern the Coordination.](https://theaicommand.com/ai-news/more-agents-is-not-more-intelligence#faq-4)

### How should a team start building guardrails?

Start with the highest-consequence path in one workflow. Run a gap review against the four rails, then add an input rail that redacts sensitive data and rejects obvious injection, ground the model in your authoritative source, validate the output before anything downstream trusts it, and put a human gate in front of any irreversible action. Log every rail decision so you can prove the control worked.

Source: [AI Guardrails: The Safety Layer No Vendor Can Ship for You](https://theaicommand.com/ai-news/ai-guardrails-the-layer-around-the-model#faq-5)

### How should AI be used in security work?

Copy the gate OpenAI used. Expert human review before any AI finding is acted on or disclosed, authorisation discipline so you test only systems you own or are permitted to test, and a standing rule that the model proposes while a qualified person decides.

Source: [AI Cyber Defence Just Scaled Up. Mind Your Open-Source Dependencies.](https://theaicommand.com/ai-news/ai-cyber-defence-and-your-open-source-dependencies#faq-5)

### How should an organisation govern its MCP connectors?

Treat each connector as third-party access. Inventory every connector your AI tools use, scope each to least privilege, manage authorisation centrally through your identity provider using the Enterprise-Managed Authorization capability, and review where each tool comes from before approving it, the same way you assess any third party.

Source: [Model Context Protocol: The Standard Wiring AI Into Your Tools](https://theaicommand.com/ai-news/model-context-protocol-govern-the-connectors#faq-4)

### How should governance be structured so it enables AI rather than smothering it?

Use a tiered approach that matches governance depth to risk. Low-risk drafting needs approved tools, training and data rules. Medium-risk workflow support needs use-case registration, testing and manager review. High-risk decision support or sensitive data should trigger formal risk assessment, testing, human oversight and audit evidence.

Source: [The AI Pilot-to-Scale Gap Is an Operating Model Problem](https://theaicommand.com/ai-news/the-ai-pilot-to-scale-gap#faq-3)

### How should HR approach role redesign for AI?

Start with tasks, not titles. Avoid predicting which jobs will disappear and instead map tasks within a role: candidates for AI support, tasks needing human judgement, sensitive or high-risk tasks, and tasks that should not be automated. This task-level view is more useful than broad claims that a profession is safe or unsafe.

Source: [AI Upskilling Will Fail If HR Does Not Redesign the Work](https://theaicommand.com/ai-news/ai-upskilling-needs-work-redesign#faq-2)

### How should HR be transparent with candidates about AI?

Transparency means telling candidates enough to understand how their information may be used and where humans remain accountable, not overwhelming them with technical detail. A practical notice explains what AI is used for, what it is not used for, whether personal information is processed by a third party, whether outputs are human-reviewed, and who to contact with concerns.

Source: [AI in Hiring Needs Human Review Before It Needs Another Tool](https://theaicommand.com/ai-news/ai-in-hiring-needs-human-review#faq-5)

### How should I compare the cost of long context against RAG?

Use cost per useful answer, meaning dollars per accepted answer, not per-token rate cards. In the worked example, the long-context route reached about USD 12.60 per useful answer versus about USD 0.20 for RAG. Score the workload by error cost, not query volume, since rare cross-reference catches sometimes justify the spend.

Source: [2M-Token Multimodal Contexts: Where They Actually Pay Off](https://theaicommand.com/ai-news/multimodal-context-windows-real-workflows#faq-3)

### How should I filter AI news before acting on it?

Give each item one of five labels: ignore, monitor, test, brief or adopt. Score it against credibility, workflow relevance, risk, effort and governance impact, then place it. The label is a decision, and ignore is often correct. This stops you treating every announcement as urgent while still catching the consequential ones.

Source: [AI Week in Review, 8-14 June 2026: A Frontier Model Pulled by Government Order](https://theaicommand.com/ai-news/ai-week-in-review-8-14-june-2026#faq-4)

### How should I respond to GPT-5.6 this week?

Three moves. Read the system card, not the launch thread, for the capability ratings and limits. Put one line in your AI plan that frontier access is a policy variable, and name a fallback model you can actually reach. When it opens, treat it as new and re-run your own evaluation before relying on it.

Source: [GPT-5.6 Sol Lands. The Frontier Just Got Gated.](https://theaicommand.com/ai-news/gpt-5-6-sol-and-the-gated-frontier#faq-4)

### How should I score and reject AI tools during evaluation?

Score each candidate task-by-task on accuracy, format, tone and failure behaviour, weighting failure behaviour highest on high-damage tasks. Apply kill criteria set in advance: reject any candidate that fabricates a citation on a high-damage task or scores zero on failure behaviour, no matter how fluent it is.

Source: [Stop Trusting the Leaderboard: Evaluate AI on Your Own Work](https://theaicommand.com/ai-news/evaluate-ai-tool-before-you-buy#faq-3)

### How should I set agent permissions to reduce risk?

Start with least privilege. Give the agent only the data access and tool permissions the approved use case needs. Make permissions time-limited where possible, separated by environment and logged. Allow read-only tools before write or execute tools, and require a second factor of human approval for sensitive actions.

Source: [AI Agents Need Approval Gates Before They Need Autonomy](https://theaicommand.com/ai-news/ai-agents-need-approval-gates#faq-3)

### How should I set reasoning budgets for my workload?

Run a one-day experiment: pull last week's traffic, tag 100 requests by complexity, and re-run them at ceilings of 0, 4,000 and 12,000, comparing quality scores. If still on defaults, set an explicit cap now, around 8,000 for Sonnet and 16,000 for Opus, then tune from there.

Source: [Reasoning Budgets in Production: How Teams Are Spending Them](https://theaicommand.com/ai-news/anthropic-reasoning-budgets-in-production#faq-4)

### How should my team approach GLM-5.2 this week?

Split the model from the channel and treat using GLM-5.2 and calling the Z.ai API as two separate approvals. Keep regulated and personal data off convenience APIs. If you want the capability for sensitive work, scope the self-host path. Run your own evaluation on real tasks before trusting the published benchmarks.

Source: [The Strongest Open Model Is Now Chinese. Mind Where Your Data Goes.](https://theaicommand.com/ai-news/glm-5-2-open-weights-and-data-sovereignty#faq-4)

### How should organisations begin deploying AI agents safely?

Begin with constrained autonomy rather than choosing between no agents and fully autonomous ones. Let an agent read approved sources, draft a response, prepare a checklist or open a ticket, but not send, close, approve or update without human review. Over time, low-risk steps with strong evidence can receive more automation.

Source: [AI Agents Need Approval Gates Before They Need Autonomy](https://theaicommand.com/ai-news/ai-agents-need-approval-gates#faq-5)

### How should procurement help control embedded AI risk?

Procurement becomes a key control point because AI is often enabled by default or added after signing. An AI intake process should ask whether the product contains AI, whether features can be disabled, what data is processed, how outputs are logged, how model changes are communicated, and which subcontractors support the feature.

Source: [Small Models, Edge AI and the Next Governance Blind Spot](https://theaicommand.com/ai-news/small-models-edge-ai-governance#faq-3)

### How should regulated entities treat Claude Tag under APRA standards?

A standing AI presence with access to your systems and data is a material service arrangement that CPS 230 expects you to assess and manage rather than switch on channel by channel. CPS 234 puts the security of that arrangement on the board, raising the bar for regulated entities.

Source: [Your AI Assistant Just Became a Shared Teammate. Govern the Channel.](https://theaicommand.com/ai-news/claude-tag-and-the-shared-ai-teammate#faq-3)

### How should teams defend the AI agents they deploy?

Scope the agent like a service account with least-privilege, short-lived tokens, separate instructions from retrieved content, put approval gates on high-blast-radius actions, allowlist and constrain tools, practise memory hygiene, red-team against the OWASP list before production, and log every action as reversible, auditable evidence.

Source: [The OWASP Agentic Top 10: A Defence Playbook for the Agents You Are Deploying](https://theaicommand.com/ai-news/owasp-agentic-top-10-defence-playbook#faq-4)

### How should you govern a long-running AI agent?

Treat it as a change, not a feature. Pin the execution boundary and prefer running inside your own cloud account. Scope least privilege and time-box credentials. Log every action and review the trail. Bound the blast radius with spend caps and a kill switch. Keep human checkpoints on the consequential steps.

Source: [AI Agents Just Went From Minutes to Hours. The Control Point Is Where They Run.](https://theaicommand.com/ai-news/long-running-ai-agents-govern-where-they-run#faq-5)

### How were the servers actually attacked?

Security researchers at Trend Micro reported an active campaign that weaponised the flaw within about 20 hours of the advisory, before any public proof-of-concept existed. Attackers scanned for internet-exposed Langflow instances, ran code through the vulnerable endpoint, and installed a customised XMRig miner to mine Monero, switching off local security controls along the way.

Source: [A Real CVE in Your Agent-Building Tools](https://theaicommand.com/ai-news/a-real-cve-in-your-agent-building-tools#faq-2)

### If a file has no Content Credential, was it faked?

No, and treating absence as evidence is the most common error. Metadata can be stripped by ordinary processing, uploads, screenshots and format conversions. OpenAI lists exactly these reasons for a missing signal. Absence means you learned nothing and must fall back on the checks you would have run anyway.

Source: [Stop Detecting AI. Start Checking Provenance.](https://theaicommand.com/ai-news/stop-detecting-ai-check-provenance#faq-4)

### Is AI causing job losses in Australia?

The report says the evidence does not show that. The 2 per cent estimate is a shortfall against trend, not a fall in jobs, and it disappears under two alternative exposure measures and under a different statistical method. DEWR describes the result as justification for ongoing monitoring rather than clear evidence that AI has reduced employment.

Source: [Canberra Just Measured What AI Is Doing to Jobs. It Found 2%.](https://theaicommand.com/ai-news/dewr-ai-employment-australia-report#faq-2)

### Is an open-weight model cheaper than a closed model like GPT-5?

Yes, substantially. Self-hosted Llama 4 70B runs at roughly USD 0.40 per million tokens, DeepSeek R2 at USD 0.50, and Mistral Sovereign around USD 1.20, compared with GPT-5 enterprise at USD 8 per million input. Open-weight has crossed the cost-effectiveness threshold for any sustained workload.

Source: [The Open-Source Frontier in April 2026: Llama 4, DeepSeek R2, Mistral Sovereign](https://theaicommand.com/ai-news/open-source-frontier-april-2026#faq-2)

### Is Claude Tag really a virtual employee replacing staff?

No. The virtual employee framing oversells it. Claude Tag is a shared assistant, not a colleague. It holds no accountability, owns no decision, and cannot be the name on a determination, customer outcome or board paper. Its async autonomy means a person must stay the decision-maker for anything carrying a consequence.

Source: [Your AI Assistant Just Became a Shared Teammate. Govern the Channel.](https://theaicommand.com/ai-news/claude-tag-and-the-shared-ai-teammate#faq-5)

### Is data in a fine-tuned model actually recoverable?

Sometimes, and that is enough to matter. Research on production models showed extractable memorization at scale and concluded that current alignment techniques do not eliminate memorization. Work published in January 2026 focused specifically on fine-tuned models, probing personal information that appeared only in inputs rather than training targets, and concluded on the persistent challenge of memorization in fine-tuned LLMs. The honest claim is not that your data will come out. It is that nobody can certify it will not.

Source: [Fine-Tuning Writes Your Data Into the Model](https://theaicommand.com/ai-news/fine-tuning-writes-your-data-into-the-model#faq-3)

### Is Gemini 3.5 Pro cancelled?

No. It was unveiled at Google I/O in May 2026 and remains in a limited enterprise preview, but general availability has slipped repeatedly and, as this publishes, is unconfirmed. Google is reportedly holding the model back over quality rather than shipping it to meet a date. A delay is not a cancellation, and it is not a verdict on the finished product either.

Source: [Google Missed Its Own Release Date, and That Is the Story](https://theaicommand.com/ai-news/google-missed-its-own-release-date#faq-1)

### Is GPT-5 worth migrating to from GPT-4o for enterprise?

It depends on the workload. GPT-5 wins on tool-heavy agentic and long-context document tasks, where tool-call success improves markedly. Routine drafting and summarisation can stay on GPT-4o or Claude Sonnet for cost. Teams that swept everything to GPT-5 are now reverting selectively rather than migrating wholesale.

Source: [GPT-5 in the Enterprise: 60-Day Debrief](https://theaicommand.com/ai-news/gpt-5-enterprise-rollout-debrief#faq-1)

### Is GPT-5.5-Cyber available to everyone?

No. It is distributed through Trusted Access for Cyber, an identity and trust-based framework with three tiers: standard GPT-5.5 for everyone, GPT-5.5 with Trusted Access for vetted defenders, and GPT-5.5-Cyber for authorised red teaming and penetration testing. Australia is named as a partner in the access scheme.

Source: [AI Cyber Defence Just Scaled Up. Mind Your Open-Source Dependencies.](https://theaicommand.com/ai-news/ai-cyber-defence-and-your-open-source-dependencies#faq-2)

### Is GPT-Live available to ChatGPT Enterprise users?

Not at launch. OpenAI's current help page says Live is rolling out across consumer plans and is not available in Business, Enterprise or Edu workspaces at launch. Those workspaces can continue using the voice options already available to them.

Source: [GPT-Live Makes Voice a Work Interface. Check What Gets Recorded](https://theaicommand.com/ai-news/gpt-live-voice-workplace-recording-controls#faq-1)

### Is it true that 95 per cent of enterprise AI still runs on frontier models?

That figure is an industry estimate reported by CNBC and attributed to Glean chief executive Arvind Jain, not a number CNBC measured itself. Treat it as directional. Most enterprise usage still defaults to frontier models even for simple tasks, which is why finance teams see room to cut, and why the shift to routing is a turn in sentiment rather than a finished migration.

Source: [Model Routing Cuts AI Bills. It Also Moves Your Data.](https://theaicommand.com/ai-news/match-the-model-to-the-task#faq-2)

### Is MCP widely adopted across the industry?

Yes. OpenAI adopted MCP across its products in March 2025, Google followed in April 2025, and Microsoft and Cloudflare built it in. Anthropic donated MCP to the Agentic AI Foundation under the Linux Foundation in December 2025, and the registry reported more than 10,000 public servers.

Source: [Model Context Protocol: The Standard Wiring AI Into Your Tools](https://theaicommand.com/ai-news/model-context-protocol-govern-the-connectors#faq-2)

### Is on-device AI like Apple Intelligence or Pixel Gemini Nano ready for enterprise use?

Yes, but only for specific workflows. As of April 2026 both are genuinely enterprise-deployable for short summarisation, live transcription and translation, offline contexts, and high-sensitivity quick tasks. Neither substitutes for frontier cloud models on long-form drafting, reasoning over documents, or agentic tool use, which are not production-ready.

Source: [On-Device AI at Work: Apple Intelligence and Pixel Gemini Nano](https://theaicommand.com/ai-news/on-device-ai-pixel-and-apple-at-work#faq-1)

### Is the $234 billion figure revenue that will disappear?

No. Gartner's figure is enterprise application spend exposed to agentic arbitrage between now and 2030, roughly 20 per cent of SaaS spend by then. Gartner itself calls the shift less an apocalypse and more of a metamorphosis, and separately predicts more than 40 per cent of agentic AI projects will be cancelled by the end of 2027. Treat it as a repricing signal, not a countdown.

Source: [You Are Now Buying Software for Agents, Not People](https://theaicommand.com/ai-news/agentic-arbitrage-buying-software-for-agents#faq-2)

### Is the GPT-5 2 million token context window actually useful?

It is technically real but situational. Large document review teams, such as legal services loading entire matter files, see genuine value. Ordinary chat assistants do not, and longer context can introduce attention dilution. For most production workloads, well-built RAG with a 200K context still outperforms loading everything in.

Source: [GPT-5 in the Enterprise: 60-Day Debrief](https://theaicommand.com/ai-news/gpt-5-enterprise-rollout-debrief#faq-3)

### Is the Jalapeño chip a strike at Nvidia that changes things now?

No. The strike-at-Nvidia and full-stack headlines mean little for you this week. OpenAI is still measuring final performance, the technical report is months away, and first deployment is at gigawatt scale from the end of 2026. It changes nothing about what your AI can do today.

Source: [OpenAI Built Its Own Chip. The Real Story Is the Cost of Intelligence.](https://theaicommand.com/ai-news/openai-custom-chip-and-the-ai-cost-curve#faq-5)

### Is the model's built-in safety enough?

No. Model providers ship moderation, refusal training and safety classifiers, but those are tuned to protect the provider's platform and its general reputation, not your specific application, data and obligations. Your risks, leaking a customer's data, acting on a prompt injection, passing an unvalidated output to a downstream system, are yours to guard, and only you know your policy well enough to enforce it.

Source: [AI Guardrails: The Safety Layer No Vendor Can Ship for You](https://theaicommand.com/ai-news/ai-guardrails-the-layer-around-the-model#faq-2)

### Is the open-weights version actually safe to use?

Open weights solve a data-residency problem, not model-behaviour problems, the need for human review, or evaluation discipline. Running it yourself means you also own the security, patching and monitoring a hosted vendor would otherwise carry. It is also not the best model overall, trailing Claude Opus 4.8 on most published coding benchmarks. Sovereignty is a trade, not a free win.

Source: [The Strongest Open Model Is Now Chinese. Mind Where Your Data Goes.](https://theaicommand.com/ai-news/glm-5-2-open-weights-and-data-sovereignty#faq-5)

### Is trace sampling on by default?

No, and practitioners routinely get this backwards. The OpenTelemetry SDK default sampler is parentbased_always_on, which keeps everything. Ratio sampling, using traceidratio or parentbased_traceidratio, is something a team switches on deliberately, usually to control a cloud bill. That matters because if sampling is enabled, the trace of the one request that went wrong may never have been kept at all. A decision made about spend quietly decided which AI decisions remain reconstructable.

Source: [Your AI Logs the Tokens. Not the Decision.](https://theaicommand.com/ai-news/trace-the-decision-not-just-the-tokens#faq-4)

### Should AI decide which candidates progress?

No, unless the organisation has strong legal, ethical and assurance justification. Hiring is a human accountability process. AI may assist preparation, search, summarisation and productivity, but it should not quietly become the decision-maker. The safest rule: use AI to prepare, organise and draft, and do not let it decide who gets opportunity.

Source: [AI in Hiring Needs Human Review Before It Needs Another Tool](https://theaicommand.com/ai-news/ai-in-hiring-needs-human-review#faq-3)

### Should I wait for Gemini 3.5 Pro or adopt what I have now?

Neither the launch nor the delay should decide it. The question is whether a given model does your specific job, on your real work, measurably better than what you run today. That answer is the same whether the model shipped early, on time or months late. Decouple your decision from the vendor release calendar entirely.

Source: [Google Missed Its Own Release Date, and That Is the Story](https://theaicommand.com/ai-news/google-missed-its-own-release-date#faq-3)

### Should I worry about the model or about where my data goes?

Focus on where the data goes. The open weights and the hosted API are two different governance propositions. Self-hosting the MIT weights inside your own network is data-sovereign because nothing leaves your boundary. Calling the China-hosted API sends your prompts and documents offshore, which is the riskier channel for sensitive information.

Source: [The Strongest Open Model Is Now Chinese. Mind Where Your Data Goes.](https://theaicommand.com/ai-news/glm-5-2-open-weights-and-data-sovereignty#faq-2)

### What agentic browsing tools shipped in April 2026?

Three platforms shipped meaningful updates. Anthropic released Computer Use 2.0 on 8 April with vision-grounded action selection. OpenAI moved Operator to general availability on 11 April for ChatGPT Pro and Enterprise. Manus released v3 with multi-agent planner-executor orchestration on 16 April. All three automate planning, clicking, form-filling and extraction.

Source: [Agentic Browsing: What Actually Shipped This Month](https://theaicommand.com/ai-news/agentic-browsing-what-shipped-in-april#faq-1)

### What AI capabilities should appear in capability frameworks?

Quality control should become core. Frameworks should cover prompt framing, source checking, risk judgement, human authorship, recordkeeping and escalation. Employees need to verify output, identify unsupported claims, check sources, protect confidential information, recognise bias and decide when not to use AI. These belong in job descriptions, performance conversations and learning pathways, not informal tips.

Source: [AI Upskilling Will Fail If HR Does Not Redesign the Work](https://theaicommand.com/ai-news/ai-upskilling-needs-work-redesign#faq-3)

### What are AI guardrails?

Guardrails are the controls you place around a language model to keep its inputs and outputs safe and on-policy. The common layers are input rails that validate requests, redact sensitive data and detect prompt injection, grounding that limits the model to retrieved authoritative context, output rails that validate and sanitise the response before anything acts on it, and action gates that require human approval for consequential actions. Open toolkits such as NVIDIA NeMo Guardrails implement input and output rails.

Source: [AI Guardrails: The Safety Layer No Vendor Can Ship for You](https://theaicommand.com/ai-news/ai-guardrails-the-layer-around-the-model#faq-1)

### What are Claude reasoning budgets and what do they do?

Reasoning budgets, shipped for Sonnet 4.6 and Opus 4.7 on 27 March 2026, let developers cap how many tokens a model spends on extended thinking before answering. They expose the model's internal thinking bound as an explicit per-request ceiling, turning an opaque cost lever into one teams can control directly.

Source: [Reasoning Budgets in Production: How Teams Are Spending Them](https://theaicommand.com/ai-news/anthropic-reasoning-budgets-in-production#faq-1)

### What are Microsoft's seven MAI models and where are they being used?

Microsoft launched MAI-Thinking-1, MAI-Code-1-Flash, MAI-Image-2.5, MAI-Image-2.5-Flash, MAI-Transcribe-1.5, MAI-Voice-2 and MAI-Voice-2-Flash at Build 2026. They are being substituted into GitHub Copilot and the Microsoft 365 stack, landing across coding, productivity, image, transcription and voice surfaces.

Source: [Microsoft's Seven MAI Models: The In-House Bet Under Copilot](https://theaicommand.com/ai-news/microsoft-mai-models-copilot#faq-1)

### What are structured outputs?

Structured outputs are a feature that forces a model's response to match a JSON schema you supply. OpenAI describes it as ensuring the model will always generate responses that adhere to your supplied JSON Schema, and Anthropic describes it as guaranteeing the response matches the exact structure you define. Under the hood, the schema is compiled into a grammar that constrains the model's output, a technique called constrained decoding, so the model cannot produce tokens that would break the structure. It is the evolution of the older JSON mode, which produced valid JSON but could not guarantee it matched your specific schema.

Source: [Structured Outputs: Make Your AI Return Data You Can Audit](https://theaicommand.com/ai-news/structured-outputs-schema-enforced-ai-regulated-work#faq-1)

### What are the Australian privacy and regulatory implications of using GLM-5.2?

Sending personal information to Z.ai's overseas API is a cross-border disclosure under Australian Privacy Principle 8 of the Privacy Act 1988, and you remain accountable for the data offshore. For regulated entities, APRA's CPS 234 puts information security on the board, and CPS 230 treats the provider as a material service relationship to assess and manage.

Source: [The Strongest Open Model Is Now Chinese. Mind Where Your Data Goes.](https://theaicommand.com/ai-news/glm-5-2-open-weights-and-data-sovereignty#faq-3)

### What are the five parts of an AI operating model for scaling?

A useful operating model answers five questions: who is accountable, which use cases are prioritised, what controls apply at each risk level, how people learn and change work practices, and how value is measured after deployment. The article maps these to accountability, portfolio, controls, adoption and measurement elements.

Source: [The AI Pilot-to-Scale Gap Is an Operating Model Problem](https://theaicommand.com/ai-news/the-ai-pilot-to-scale-gap#faq-2)

### What are the three actions to take this week?

First, record the default-model change in your AI inventory. Second, if you run Google Workspace, review the Gemini Enterprise Agent Platform, confirm secure boundary defaults and decide which connectors are in scope. Third, re-run the cost model on any agent pilot you parked for budget reasons.

Source: [Gemini 3.5 Flash: Google Makes the Agent the Default](https://theaicommand.com/ai-news/gemini-3-5-flash-agent-default#faq-5)

### What are the three conditions attached to using Claude Fable 5?

First, a safety classifier silently reroutes cybersecurity, biology, chemistry and model-distillation requests to Claude Opus 4.8. Second, a mandatory 30-day data retention policy applies even to enterprises with prior zero-retention agreements. Third, from 23 June the model leaves subscription plans and requires usage credits to access.

Source: [Claude Fable 5: Frontier Capability, With Conditions Attached](https://theaicommand.com/ai-news/claude-fable-5-in-practice#faq-1)

### What changed in the C2PA specification in 2026?

Version 2.4, dated April 2026, introduced a new AI Disclosure assertion for machine-readable AI transparency information, added support for embedding manifests into HTML documents and into structured text formats such as source code, YAML, Markdown and AsciiDoc, and added a new JSON-based serialisation. The practical effect is that provenance now reaches documents and text, not only photographs and video.

Source: [Stop Detecting AI. Start Checking Provenance.](https://theaicommand.com/ai-news/stop-detecting-ai-check-provenance#faq-2)

### What contract clauses matter when agents will use the software?

Three carry the weight: agent access, meaning the licence expressly permits an autonomous agent to act on your behalf; autonomy scope, meaning what the agent may do is defined per system rather than inherited from a human user's permissions; and learning ownership, meaning you retain control of what the vendor learns from your workflows. Add API change notice and API-based exit as supporting clauses.

Source: [You Are Now Buying Software for Agents, Not People](https://theaicommand.com/ai-news/agentic-arbitrage-buying-software-for-agents#faq-4)

### What controls should govern an AI agent's memory store?

Five, across the memory lifecycle: rules on what may be written, validation that strips sensitive data before it lands, per-tenant isolation with path validation on every file operation, provenance and audit logging so every entry traces to an agent and session, and expiry windows backed by tested rollback. The most important control sits at the write, not the read.

Source: [Your AI Agent Can Remember Now. Govern What It Keeps.](https://theaicommand.com/ai-news/govern-ai-agent-memory#faq-3)

### What data should I never put into an AI tool I am still evaluating?

Never paste real personal, claim, health or incident data into a tool that is not an approved enterprise instance, because the tool you are evaluating is by definition not yet approved. De-identify every task using placeholder tokens, and prefer public source material such as a published regulator release or annual report.

Source: [Stop Trusting the Leaderboard: Evaluate AI on Your Own Work](https://theaicommand.com/ai-news/evaluate-ai-tool-before-you-buy#faq-4)

### What did DXC and TCS actually announce this week?

On 11 June, DXC announced a multi-year global alliance with Anthropic to bring Claude into the systems it runs for banks, airlines, insurers and government. A day later, TCS announced a global premier partnership to deploy Claude across financial services, insurance, healthcare and the public sector.

Source: [AI Is Moving Into the Core Systems of Regulated Work](https://theaicommand.com/ai-news/ai-in-regulated-core-systems#faq-1)

### What did Google actually announce about Gemini 3.5 Flash?

At I/O 2026 on 19 May, Google shipped Gemini 3.5 Flash as generally available and made it the default model in the Gemini app and AI Mode in Search worldwide, including Australia. It also reached Google Antigravity, the Gemini API, Android Studio and the Gemini Enterprise Agent Platform.

Source: [Gemini 3.5 Flash: Google Makes the Agent the Default](https://theaicommand.com/ai-news/gemini-3-5-flash-agent-default#faq-1)

### What did Google say caused the delay?

Google has not published an official explanation. Reporting across the tech press attributes the first slip to token efficiency, coding performance and long-task reasoning falling short of the bar set at I/O, and a later delay to a decision to rebuild the model. Treat those specifics as reported rather than confirmed, and do not build a decision on them.

Source: [Google Missed Its Own Release Date, and That Is the Story](https://theaicommand.com/ai-news/google-missed-its-own-release-date#faq-4)

### What did OpenAI actually announce about ChatGPT health on 18 June?

OpenAI announced a substantial step up in ChatGPT's health intelligence, driven by its free GPT-5.5 Instant model. On the hardest health evaluations it now performs comparably to frontier Thinking models, and the rate of responses with a flagged factuality issue has fallen 71 per cent over two months.

Source: [ChatGPT Just Got Better at Health. Mind the Boundary.](https://theaicommand.com/ai-news/chatgpt-health-intelligence-and-the-boundary#faq-1)

### What did OpenAI announce in June 2026 about AI agents?

On 11 June 2026 OpenAI announced it would acquire Ona, the cloud company formerly known as Gitpod, to give its Codex agents secure, persistent places to run. On 25 June it published economic research showing the unit of AI work has moved from quick interactions to delegated tasks that run for hours.

Source: [AI Agents Just Went From Minutes to Hours. The Control Point Is Where They Run.](https://theaicommand.com/ai-news/long-running-ai-agents-govern-where-they-run#faq-1)

### What did OpenAI announce on 22 June 2026?

OpenAI launched a defensive cybersecurity programme called Daybreak. It released the full GPT-5.5-Cyber, its most capable security model, and a second initiative, Patch the Planet, that pointed that model at critical open-source software. The early work surfaced hundreds of real security issues and merged dozens of fixes within days.

Source: [AI Cyber Defence Just Scaled Up. Mind Your Open-Source Dependencies.](https://theaicommand.com/ai-news/ai-cyber-defence-and-your-open-source-dependencies#faq-1)

### What did the DEWR report find about AI and jobs in Australia?

The July 2026 report finds no broad AI-driven labour market upheaval. Overall conditions remain strong, with unemployment at 4.2 per cent. But the most AI-exposed fifth of occupations grew 5.6 per cent between November 2022 and February 2026, against 9.5 per cent for the least exposed, and DEWR's model implies employment in highly exposed occupations is about 2 per cent below its pre-ChatGPT trend.

Source: [Canberra Just Measured What AI Is Doing to Jobs. It Found 2%.](https://theaicommand.com/ai-news/dewr-ai-employment-australia-report#faq-1)

### What did the IIA and AuditBoard find about AI-enabled fraud?

Their report, released on 17 February 2026 and based on more than 370 senior internal audit leaders in North America, found 85 per cent consider AI-enabled fraud a moderate-to-high risk, but fewer than 40 per cent feel their function is adequately prepared to detect it. The top barriers were a lack of appropriate tools (57 per cent) and too few skilled staff (55 per cent).

Source: [Internal Audit's AI Say-Do Gap Now Has Numbers](https://theaicommand.com/ai-news/internal-audit-ai-say-do-gap#faq-2)

### What do Microsoft's clean data lineage claims actually answer?

They answer where training data came from (commercially licensed), whether models inherit behaviour from other labs (zero distillation), and whether documentation exists. They do not say which model serves your tenant on a given day, how substitutions are notified, what parity evidence supports your workloads, or what rollback looks like.

Source: [Microsoft's Seven MAI Models: The In-House Bet Under Copilot](https://theaicommand.com/ai-news/microsoft-mai-models-copilot#faq-3)

### What does 93% producing an artefact actually mean?

Anthropic's classifier found that 93% of conversations produced a recognisable output, an explanation, a document or report, a piece of code, guidance, and so on. The most common were explanations at 17%, documents and reports at 15%, and guidance at 11%. The practical read is that committed use is production, not idle chat.

Source: [What 9,700 Real Users Actually Do With Claude](https://theaicommand.com/ai-news/what-9700-real-users-do-with-claude#faq-2)

### What does Claude Fable 5 cost in Australian dollars?

At current exchange rates, US$10 and US$50 per million input and output tokens translate to roughly A$15 and A$77. A plausible day of autonomous work running 20 million input and 2 million output tokens costs about US$300, around A$460. The cost that matters is per completed task against the human alternative.

Source: [Claude Fable 5: Frontier Capability, With Conditions Attached](https://theaicommand.com/ai-news/claude-fable-5-in-practice#faq-5)

### What does grounding an AI model actually mean?

Grounding means wiring the model to the authoritative source and a reliable path to query it, so the answer comes from the record rather than from the model's impression of the record. It is not a better prompt or a bigger model. In practice it means pasting in the exact rule, rate, section or standard, or connecting the model to that source, rather than asking it to recall the fact from memory.

Source: [Ground the Model, Do Not Trust Its Memory](https://theaicommand.com/ai-news/grounding-beats-model-memory#faq-1)

### What does on-device AI mean for regulated workplaces under CPS 234 and privacy obligations?

For APRA-regulated entities, financial services and Comcare-aligned teams, on-device AI is the first credible answer to data-residency concerns. Sensitive drafting can stay on the device with no cloud transit, CPS 234 and APP 11 conversations get easier with no third-party processor, and audit trails tighten because inference logs locally.

Source: [On-Device AI at Work: Apple Intelligence and Pixel Gemini Nano](https://theaicommand.com/ai-news/on-device-ai-pixel-and-apple-at-work#faq-3)

### What does the GPT-5.6 gate mean for Australian professionals?

When the recent US directive cut off Anthropic's Fable 5 and Mythos 5, it targeted foreign nationals, which in Sydney and Melbourne means you. Treat frontier-model access like any dependency you do not control: assume it can change, do not build around it, and have a fallback you can reach.

Source: [GPT-5.6 Sol Lands. The Frontier Just Got Gated.](https://theaicommand.com/ai-news/gpt-5-6-sol-and-the-gated-frontier#faq-3)

### What does the one million token context window change?

Sonnet 5 carries a native one million token context window, on by default and billed at standard rates. Far more can now be pasted, uploaded or ingested into a single request, including material that should not be there. What enters a context window is a decision under the Australian Privacy Principles and, for anything that could become evidence, a records decision. The bigger window is capacity, not permission.

Source: [Claude Sonnet 5 Became the Default. That Is a Change Event.](https://theaicommand.com/ai-news/claude-sonnet-5-your-default-just-changed#faq-4)

### What does this mean for APRA-regulated Australian work?

A long-running agent in production is a change-management and supplier-risk question, not an IT convenience. APRA's 30 April 2026 letter set expectations across cyber and information security, governance, supplier risk, and change management. CPS 230, with amendments effective 1 July 2026, requires resilience, critical-operation continuity and service-provider risk management.

Source: [AI Agents Just Went From Minutes to Hours. The Control Point Is Where They Run.](https://theaicommand.com/ai-news/long-running-ai-agents-govern-where-they-run#faq-4)

### What does this mean for regulated Australian organisations?

When an agent bypasses an application's screens, you lose that application's controls and inherit the agent's, so treat the swap as a change, not a convenience. Under APRA CPS 230 an arrangement supporting a critical operation is material, so it belongs in your change and supplier-risk process with a tested fallback. Learning ownership also raises Privacy Act APP 6 use and disclosure questions, and APP 8 questions if processing sits offshore.

Source: [You Are Now Buying Software for Agents, Not People](https://theaicommand.com/ai-news/agentic-arbitrage-buying-software-for-agents#faq-5)

### What does tiered governance for embedded AI look like?

Blocking every feature is unrealistic. A tiered model fits the risk: low-risk embedded AI proceeds with standard data-handling guidance, medium-risk use needs registration, an owner, source checking and review sampling, and high-risk use needs formal risk assessment, testing, human oversight and a challenge pathway. Governance stays lightweight but persistent, with periodic review and change triggers.

Source: [Small Models, Edge AI and the Next Governance Blind Spot](https://theaicommand.com/ai-news/small-models-edge-ai-governance#faq-5)

### What does turning content capture on actually cost me?

It converts your observability backend into a repository of personal information. Under APP 11, an entity holds personal information if it has possession or control of a record containing it, which reaches a third-party monitoring vendor. That triggers an obligation to take reasonable steps to protect it, and APP 11.2 requires destruction or de-identification once it is no longer needed. Trace retention stops being a cost setting and becomes a privacy control you have to justify.

Source: [Your AI Logs the Tokens. Not the Decision.](https://theaicommand.com/ai-news/trace-the-decision-not-just-the-tokens#faq-3)

### What exactly did OpenAI do with GPT-5.6?

On 26 June 2026 OpenAI previewed GPT-5.6 (Sol, Terra and Luna) but, at the US government's request, released it to roughly 20 individually vetted organisations only, through the API and Codex, with no public waitlist. The government signed off customer by customer. As of early July the model is still gated, with broad availability promised in the coming weeks.

Source: [A Government Now Vets Who Gets the Model. File It as a Vendor Risk.](https://theaicommand.com/ai-news/gated-model-access-is-a-vendor-risk#faq-1)

### What failure modes appear with very long contexts?

Three surface above 500K tokens. Attention degradation drops recall on middle-of-context facts by 20 to 30 percent. Latency climbs, with a 1.8M-token GPT-5 request taking 90 to 180 seconds to first token. Hallucination rises, and verification effort scales with context length because the assertion surface grows.

Source: [2M-Token Multimodal Contexts: Where They Actually Pay Off](https://theaicommand.com/ai-news/multimodal-context-windows-real-workflows#faq-5)

### What is a Content Credential in plain terms?

It is a set of statements about an asset, called assertions, wrapped into a claim that is digitally signed and bound to the file. The specification describes assertions as trust signals that a human can use to improve their view of the trustworthiness of an asset. Binding is either hard, using cryptographic hashes of the content, or soft, using a fingerprint or an invisible watermark that allows the credential to be found again if it is separated from the file.

Source: [Stop Detecting AI. Start Checking Provenance.](https://theaicommand.com/ai-news/stop-detecting-ai-check-provenance#faq-1)

### What is a safe first workplace use of GPT-Live?

Use fictional or non-sensitive material for rehearsal, language practice or brainstorming in an approved account. Do not include names, live customer information, health information, employee matters, confidential documents or another person's voice. A human verifies anything that informs work.

Source: [GPT-Live Makes Voice a Work Interface. Check What Gets Recorded](https://theaicommand.com/ai-news/gpt-live-voice-workplace-recording-controls#faq-4)

### What is a software bill of materials and why do I need one?

A software bill of materials is a current inventory of the open-source components and versions your software depends on. You cannot patch, or even reason about, what you cannot see. It is the unglamorous prerequisite for everything else, and you should ask the same of your suppliers.

Source: [AI Cyber Defence Just Scaled Up. Mind Your Open-Source Dependencies.](https://theaicommand.com/ai-news/ai-cyber-defence-and-your-open-source-dependencies#faq-4)

### What is agentic arbitrage?

Agentic arbitrage is Gartner's term for what happens when an AI agent completes a task across several systems through their APIs, so people no longer open each application and click through its screens. The software still does the processing, but it becomes invisible to the user, which breaks the link between per-seat licensing and the value the software delivers.

Source: [You Are Now Buying Software for Agents, Not People](https://theaicommand.com/ai-news/agentic-arbitrage-buying-software-for-agents#faq-1)

### What is an approval gate for an AI agent?

An approval gate is a point in a workflow where the agent must stop and obtain human confirmation before proceeding. Gates should be based on risk, not inconvenience. Low-risk actions may be automated, medium-risk actions may need sampled or manager review, and high-risk actions should require explicit human approval every time.

Source: [AI Agents Need Approval Gates Before They Need Autonomy](https://theaicommand.com/ai-news/ai-agents-need-approval-gates#faq-2)

### What is Claude Sonnet 5 and when was it released?

Claude Sonnet 5 is Anthropic's newest mid-tier Claude model, released on 30 June 2026. Anthropic calls it the most agentic Sonnet yet, able to plan, use tools such as browsers and terminals, and run multi-step tasks. On the SWE-bench Pro coding benchmark it scores 63.2 per cent against 69.2 per cent for the more expensive Opus 4.8, positioning it close to Opus performance at lower cost.

Source: [Claude Sonnet 5 Became the Default. That Is a Change Event.](https://theaicommand.com/ai-news/claude-sonnet-5-your-default-just-changed#faq-1)

### What is Claude Tag and how does it differ from a normal AI chatbot?

Claude Tag is a single shared Claude that runs inside a Slack workspace, with one Claude per channel interacting with everyone. Unlike a private session that forgets you when you close the tab, it has channel memory and admin-scoped access, making it a standing presence rather than a chatbot you open and close.

Source: [Your AI Assistant Just Became a Shared Teammate. Govern the Channel.](https://theaicommand.com/ai-news/claude-tag-and-the-shared-ai-teammate#faq-1)

### What is continuous evaluation?

Continuous evaluation is the practice of measuring an AI system's quality on an ongoing basis in production, not just once at launch. In practice it means keeping a fixed evaluation set that represents the real task, logging production inputs and outputs, scoring them against the eval set, alerting when inputs drift or scores drop, converting every real failure into a regression test, and gating changes through a pipeline so a bad update is caught before it ships.

Source: [Your AI Passed the Pilot. Production Is a Different Test.](https://theaicommand.com/ai-news/ai-passed-the-pilot-govern-the-drift#faq-3)

### What is CVE-2026-33017?

CVE-2026-33017 is a critical, unauthenticated remote code execution vulnerability in Langflow, an open-source low-code platform for building AI agents and workflows. GitHub's advisory rates it 9.3 under CVSS 4.0. It affects Langflow 1.8.2 and earlier, and is fixed in version 1.9.0.

Source: [A Real CVE in Your Agent-Building Tools](https://theaicommand.com/ai-news/a-real-cve-in-your-agent-building-tools#faq-1)

### What is Databricks Genie One and who is it for?

Genie One is an agentic AI coworker Databricks launched on 16 June 2026, pitched at marketing, finance and sales teams rather than engineers. It orchestrates work across structured and unstructured data, connects to more than 50 apps including Slack, Jira and SharePoint, and is generally available now.

Source: [Business Teams Can Now Build Their Own AI Agents](https://theaicommand.com/ai-news/business-teams-building-their-own-ai-agents#faq-1)

### What is GLM-5.2 and why does it matter?

GLM-5.2 is Z.ai's flagship model, released on 16 June under an MIT licence with no regional limits and a one-million-token context window. On the coding benchmarks Z.ai published it is the highest-ranked open model. It matters because the strongest openly downloadable model now sits under Chinese rules.

Source: [The Strongest Open Model Is Now Chinese. Mind Where Your Data Goes.](https://theaicommand.com/ai-news/glm-5-2-open-weights-and-data-sovereignty#faq-1)

### What is internal audit's AI "say-do gap"?

It is the distance between stated AI adoption and actual embedded use. Gartner's January 2026 survey found 83 per cent of audit functions piloting or using AI, up from 41 per cent using or planning to in 2024, yet only a small number of chief audit executives feel confident they can effectively embed the technology in real audit workflows. Interest has raced ahead of capability.

Source: [Internal Audit's AI Say-Do Gap Now Has Numbers](https://theaicommand.com/ai-news/internal-audit-ai-say-do-gap#faq-1)

### What is MCP tool poisoning?

It is an attack that changes the natural-language description of an MCP tool, the metadata an agent reads to decide when and how to call it, to smuggle in hidden instructions. The tool's name and code stay the same, so the agent treats the poisoned description as a legitimate instruction and acts on it using the user's own permissions.

Source: [Someone Poisoned the Tool Description. The Agent Did the Rest.](https://theaicommand.com/ai-news/mcp-tool-poisoning-least-agency#faq-1)

### What is memory poisoning, and how serious is it?

Memory poisoning is when a malicious or corrupted entry is written into an agent's persistent memory and then shapes future sessions. The OWASP Top 10 for Agentic Applications lists it as ASI06, Memory and Context Poisoning. Research on arXiv reports over 95 per cent injection success under idealised conditions, but effectiveness drops sharply when the store already holds legitimate memories. Design against it rather than panicking about it.

Source: [Your AI Agent Can Remember Now. Govern What It Keeps.](https://theaicommand.com/ai-news/govern-ai-agent-memory#faq-2)

### What is model drift?

Drift is the gradual or sudden divergence between the conditions a system was validated under and the conditions it now runs in. Data drift is when the inputs shift away from what you tested. Behaviour change is when the underlying model is updated by the provider. Quality regression is when outputs get measurably worse. Any of the three can degrade an AI system that passed its pilot, without anyone changing your own code.

Source: [Your AI Passed the Pilot. Production Is a Different Test.](https://theaicommand.com/ai-news/ai-passed-the-pilot-govern-the-drift#faq-2)

### What is model routing, and why is it in the news?

Model routing sends each task to the model that fits it, hard problems to expensive frontier models and easy, high-volume work to cheaper, faster alternatives. CNBC reported in June 2026 that chief financial officers and boards are cracking down on AI bills, so buyers are moving away from defaulting every task to the most powerful model, a habit the market nicknamed tokenmaxxing.

Source: [Model Routing Cuts AI Bills. It Also Moves Your Data.](https://theaicommand.com/ai-news/match-the-model-to-the-task#faq-1)

### What is OpenAI's Jalapeño chip and should I care about it?

Jalapeño is OpenAI's first custom inference chip, unveiled with Broadcom on 24 June, built from scratch to run large language models. You will never touch it, as it runs inside OpenAI's data centres. The chip is not the point; the falling cost of intelligence it confirms is.

Source: [OpenAI Built Its Own Chip. The Real Story Is the Cost of Intelligence.](https://theaicommand.com/ai-news/openai-custom-chip-and-the-ai-cost-curve#faq-1)

### What is prompt injection and how do guardrails help?

OWASP defines prompt injection (LLM01:2025) as user prompts altering the model's behaviour in unintended ways, including indirect injection where malicious instructions arrive inside a document or web page the model reads. Guardrails help by constraining the model's role in the system prompt, filtering inputs and outputs, scoping the model's privileges, and requiring human approval for privileged actions, though no single control fully solves it.

Source: [AI Guardrails: The Safety Layer No Vendor Can Ship for You](https://theaicommand.com/ai-news/ai-guardrails-the-layer-around-the-model#faq-3)

### What is the Agentic AI Foundation?

The Agentic AI Foundation is a directed fund under the Linux Foundation, announced on 9 December 2025 and co-founded by Anthropic, Block and OpenAI, with supporting members including Google, Microsoft, AWS, Cloudflare and Bloomberg. Anthropic donated the Model Context Protocol to it. The foundation exists to steward open standards for AI agents so that agents built by different vendors can connect to tools and to each other without proprietary lock-in.

Source: [More Agents Is Not More Intelligence. Govern the Coordination.](https://theaicommand.com/ai-news/more-agents-is-not-more-intelligence#faq-3)

### What is the Anthropic Cadences report?

Cadences is the latest Anthropic Economic Index, published on 26 June 2026. It combines hourly usage sampling, a classifier that labels the main output of each conversation, and a survey of about 9,700 Claude users whose answers were linked to their real activity through a privacy-preserving system. The usage data covers chat and Cowork conversations sampled between 10 April and 10 June 2026.

Source: [What 9,700 Real Users Actually Do With Claude](https://theaicommand.com/ai-news/what-9700-real-users-do-with-claude#faq-1)

### What is the API-parity test?

It asks one question of any system you are renewing or buying: can an agent do through the documented API everything your people do through the screens? List the top ten actions your team performs, check each against the vendor's API documentation, and mark it API-complete, partial or UI-only. The result changes what a renewal is worth and what an agent project can safely include.

Source: [You Are Now Buying Software for Agents, Not People](https://theaicommand.com/ai-news/agentic-arbitrage-buying-software-for-agents#faq-3)

### What is the Australian Voluntary AI Safety Standard and when did it launch?

It is Australia's voluntary framework of ten guardrails covering accountability, risk management, data governance, testing, transparency, contestability, supply chain, training, records and engagement. It launched on 4 September 2024, framed as voluntary, with a clear signal that mandatory guardrails would follow for high-risk settings.

Source: [Australian AI Safety Standard: 18-Month Review](https://theaicommand.com/ai-news/australian-ai-safety-standard-18-month-review#faq-1)

### What is the default reasoning budget and why is it a problem?

The default ceiling is 16,000 reasoning tokens on Sonnet and 32,000 on Opus. For most production tasks both numbers are too high. Teams on defaults leave money on the table, because a handful of requests spend 12,000 to 14,000 tokens on work that only needed about 4,000.

Source: [Reasoning Budgets in Production: How Teams Are Spending Them](https://theaicommand.com/ai-news/anthropic-reasoning-budgets-in-production#faq-3)

### What is the difference between automation and augmentation here?

Automation is when a user hands over a whole task with little further input. Augmentation is the more collaborative, back-and-forth style where the person works on the task together with the model. The report links a higher automation share to more career optimism and to people feeling their skills are growing more valuable.

Source: [What 9,700 Real Users Actually Do With Claude](https://theaicommand.com/ai-news/what-9700-real-users-do-with-claude#faq-4)

### What is the difference between context engineering and prompt engineering?

Prompt engineering is about writing good instructions, which is one slice of what the model sees. Context engineering is broader: it covers the whole context window, including instructions, system prompt, tool definitions, retrieved documents, prior turns and action outputs. It curates what fills that window, recognising it shapes answer quality as much as wording.

Source: [Context Engineering: What the Model Is Allowed to See](https://theaicommand.com/ai-news/context-engineering-what-the-model-sees#faq-1)

### What is the difference between least privilege and least agency?

Least privilege limits what an identity can reach. Least agency limits what an agent is allowed to do on its own before a human is in the loop. A poisoned tool can act entirely within the permissions you granted, so scoping access is not enough. You also have to gate which actions the agent may take without approval.

Source: [Someone Poisoned the Tool Description. The Agent Did the Rest.](https://theaicommand.com/ai-news/mcp-tool-poisoning-least-agency#faq-3)

### What is the difference between MCP and A2A?

They govern two different connections. The Model Context Protocol (MCP) defines how a single agent connects to tools and data sources. The Agent2Agent protocol (A2A) defines how agents discover, communicate and coordinate with each other across different frameworks, vendors and organisational boundaries. MCP is agent-to-tools. A2A is agent-to-agent. Both are now hosted under the Linux Foundation, so the connectivity layer is largely settled and the design and governance layer is where the work moves.

Source: [More Agents Is Not More Intelligence. Govern the Coordination.](https://theaicommand.com/ai-news/more-agents-is-not-more-intelligence#faq-1)

### What is the difference between workforce insight and employee monitoring?

Workforce insight uses aggregated, proportionate data to improve systems of work. Employee monitoring tracks individuals in ways that can affect performance, discipline, rostering, promotion or job security. Analytical insight can quietly become behavioural surveillance if managers flag employees for sending fewer messages or appearing less active, without any formal policy change.

Source: [Workplace AI and Privacy: The Trust Test HR Cannot Outsource](https://theaicommand.com/ai-news/workplace-ai-and-the-privacy-trust-test#faq-2)

### What is the four-dimension jailbreak-severity framework?

It is a proposed way to rate how serious an AI jailbreak is, across four dimensions: how much capability an attacker gains beyond existing tools, how broad that gain is across offensive tasks, how easy the technique is to weaponise, and how discoverable it already is. Anthropic is developing it with Amazon, Microsoft, Google and other partners through its Glasswing program. It is proposed, not yet an adopted standard.

Source: [Fable 5 Returns With a Jailbreak Severity Framework](https://theaicommand.com/ai-news/fable-5-returns-jailbreak-severity-framework#faq-2)

### What is the Model Context Protocol and what problem does it solve?

MCP is a standard Anthropic introduced on 25 November 2024 for connecting AI assistants to the systems where data lives. It replaces bespoke, brittle custom integrations with one protocol, so any AI client that speaks MCP can reach any system exposing an MCP server without a fresh build.

Source: [Model Context Protocol: The Standard Wiring AI Into Your Tools](https://theaicommand.com/ai-news/model-context-protocol-govern-the-connectors#faq-1)

### What is the OWASP Top 10 for Agentic Applications 2026?

It is a security list the OWASP GenAI Security Project published in December 2025, built with more than 100 contributors. It is the first widely adopted list treating the agent, not the model, as the unit of risk, listing ten risks coded ASI01 to ASI10 for organisations deploying AI agents.

Source: [The OWASP Agentic Top 10: A Defence Playbook for the Agents You Are Deploying](https://theaicommand.com/ai-news/owasp-agentic-top-10-defence-playbook#faq-1)

### What is the real difference between retrieval and fine-tuning?

Where your data ends up. With retrieval, the authoritative copy stays in a store you run, and passages are fetched into the request at query time, so deleting a record deletes what the model can see. With fine-tuning, the data is used to adjust the model's weights, which is why OpenAI describes the benefit as training on proprietary or sensitive data without having to include it via examples in every request. The data no longer needs to be sent because a version of it is now inside the artefact.

Source: [Fine-Tuning Writes Your Data Into the Model](https://theaicommand.com/ai-news/fine-tuning-writes-your-data-into-the-model#faq-1)

### What is the safety-utility trade-off in the Fable 5 fix?

The return shipped with a new cybersecurity classifier that Anthropic says blocks the reported jailbreak in more than 99 per cent of cases, but at the cost of flagging benign requests more often during routine coding and debugging. Legitimate developers will hit more false positives on ordinary work. Treat the update as a change event and re-test your key workflows after it.

Source: [Fable 5 Returns With a Jailbreak Severity Framework](https://theaicommand.com/ai-news/fable-5-returns-jailbreak-severity-framework#faq-3)

### What is the trust test for workplace AI?

Before deploying workplace AI, HR asks whether the organisation would be comfortable explaining the data use to employees in plain English. If the answer is no, the design may be wrong, not just the communications. A transparent explanation covers what data is collected, why, who sees it, retention, third parties, and how to raise concerns.

Source: [Workplace AI and Privacy: The Trust Test HR Cannot Outsource](https://theaicommand.com/ai-news/workplace-ai-and-the-privacy-trust-test#faq-4)

### What new habits do managers need for AI-assisted work?

Managers should ask whether AI was used, what source material was checked, what risks were considered and what human judgement changed. They must avoid punishing transparency, because if employees fear disclosing AI use, governance will fail. Manager training should include scenarios, such as reviewing reports with confident but unsupported claims, to build practical judgement.

Source: [AI Upskilling Will Fail If HR Does Not Redesign the Work](https://theaicommand.com/ai-news/ai-upskilling-needs-work-redesign#faq-4)

### What practical moves make up context engineering?

Named strategies include writing system instructions at the right altitude, keeping tools lean and non-overlapping, just-in-time retrieval that pulls information on demand, compaction that summarises long runs and reinitialises, structured note-taking or memory tooling, and sub-agents that split work so each context window stays focused and passes forward conclusions.

Source: [Context Engineering: What the Model Is Allowed to See](https://theaicommand.com/ai-news/context-engineering-what-the-model-sees#faq-3)

### What privacy obligations does Claude Tag trigger for Australian organisations?

Putting a shared AI member into a channel carrying customer details, case notes or personal and health data, or connecting it to such data, is a use-and-disclosure decision under the Privacy Act 1988 and the Australian Privacy Principles. Accountability for that decision sits with your organisation, not the tool.

Source: [Your AI Assistant Just Became a Shared Teammate. Govern the Channel.](https://theaicommand.com/ai-news/claude-tag-and-the-shared-ai-teammate#faq-2)

### What privacy risks come with AI hiring tools?

Recruitment data is often richer than people realise. Resumes can reveal age, location, career breaks, caring responsibilities, visa history, disability adjustments, union activity or health gaps. Uploading this into a tool without understanding retention, training use, access controls and third-party processing creates immediate privacy risk. The trust standard should sit higher than the minimum legal threshold.

Source: [AI in Hiring Needs Human Review Before It Needs Another Tool](https://theaicommand.com/ai-news/ai-in-hiring-needs-human-review#faq-4)

### What separates teams getting value from agentic browsing?

Three patterns. Scope discipline: one well-tested workflow on one site, not a general web assistant. Observability: logging every action with a screenshot, the planner's reasoning and the action taken. Human-in-the-loop where stakes are high, with a person approving each meaningful step on workflows touching customer data or regulated systems.

Source: [Agentic Browsing: What Actually Shipped This Month](https://theaicommand.com/ai-news/agentic-browsing-what-shipped-in-april#faq-5)

### What should a people leader do differently because of this?

Build upskilling around delegation done well, not tool familiarity for its own sake. Teach people to choose which tasks to hand over whole, brief the model properly, and verify what comes back. Run a short usage audit, redesign one recurring task for clean delegation with a human check, and measure the result before scaling.

Source: [What 9,700 Real Users Actually Do With Claude](https://theaicommand.com/ai-news/what-9700-real-users-do-with-claude#faq-5)

### What should a team do first?

List your recurring AI tasks and attach a data class to each before you attach a model. Set an allow-list of acceptable models per class, ask the smallest, cheapest model that clears each task reliably, and govern any automated routing layer like a control. Keep one register line per task recording the task, model, data class and why that pairing is acceptable.

Source: [Model Routing Cuts AI Bills. It Also Moves Your Data.](https://theaicommand.com/ai-news/match-the-model-to-the-task#faq-5)

### What should a workplace AI privacy policy actually cover?

A broad responsible-use statement is not enough. A useful policy answers six questions: which tools are approved, what information must not be entered, what logs are kept, who can access them, how long information is retained, and whether AI output can be used in employment decisions. It should separate employee use from employer use.

Source: [Workplace AI and Privacy: The Trust Test HR Cannot Outsource](https://theaicommand.com/ai-news/workplace-ai-and-the-privacy-trust-test#faq-3)

### What should an AI agent evidence trail capture?

Treat evidence trails as part of product design. A useful trail records the initiating user, system instructions, user prompt, retrieved sources, tool calls, data accessed, outputs generated, approvals obtained, actions taken, timestamps and errors. This supports quality review, incident response, audit and continuous improvement when something goes wrong.

Source: [AI Agents Need Approval Gates Before They Need Autonomy](https://theaicommand.com/ai-news/ai-agents-need-approval-gates#faq-4)

### What should an AI buyer ask a vendor about power?

Ask where the service runs, which infrastructure dependencies are concentrated, whether workloads can move regions, what additional clean generation or storage supports growth, how demand is managed during constraints, how water and emissions claims are calculated, and what continuity arrangements exist if a facility or region is unavailable.

Source: [AI's Next Constraint Is Power. Australia Has Started Writing the Rules](https://theaicommand.com/ai-news/ai-power-australia-grid-rules#faq-4)

### What should an AI inventory include to avoid gaps?

An inventory should pull from many sources, not just tools employees nominate: procurement records, software asset registers, cloud logs, browser extensions, vendor roadmaps, data connectors and business process maps. It should also record whether the AI is visible to users, since hidden AI needs stronger transparency controls. An incomplete inventory undermines every later control.

Source: [Small Models, Edge AI and the Next Governance Blind Spot](https://theaicommand.com/ai-news/small-models-edge-ai-governance#faq-4)

### What should an Australian due-diligence questionnaire now ask?

Add a section on government-imposed access conditions. Ask which government can restrict or revoke access, whether you would be inside or outside a vetted list, what notice and continuity commitment applies, and what the fallback is. Score the answers, record them in the vendor register, and treat a vendor who cannot answer as having answered.

Source: [A Government Now Vets Who Gets the Model. File It as a Vendor Risk.](https://theaicommand.com/ai-news/gated-model-access-is-a-vendor-risk#faq-4)

### What should an Australian regulated team do first?

Inventory your MCP servers and tools, baseline every tool description at deployment, and make any later change to that description trigger review before the tool is used again in a sensitive workflow. Then turn off allow-all tool access and put a human approval gate on high-impact actions.

Source: [Someone Poisoned the Tool Description. The Agent Did the Rest.](https://theaicommand.com/ai-news/mcp-tool-poisoning-least-agency#faq-5)

### What should an Australian team do right now?

Inventory every low-code or no-code agent-building tool in use, confirm none is reachable from the public internet, patch Langflow to 1.9.0 or later, and rotate any credentials on a host that was exposed. Then write a short governance rule for how these tools are deployed and who may expose one.

Source: [A Real CVE in Your Agent-Building Tools](https://theaicommand.com/ai-news/a-real-cve-in-your-agent-building-tools#faq-5)

### What should Australian GRC teams do about it?

Add jailbreak and misuse severity to your third-party AI due diligence under the Voluntary AI Safety Standard and APRA CPS 234, asking how a provider rates severity and responds to a serious finding. Treat safety patches as material changes under CPS 230, re-testing key workflows and logging what shifted. Keep a named fallback model, because access can move on government action.

Source: [Fable 5 Returns With a Jailbreak Severity Framework](https://theaicommand.com/ai-news/fable-5-returns-jailbreak-severity-framework#faq-4)

### What should GRC professionals do about the default-model change?

GRC teams have an inventory integrity problem. Most registers record tools and vendors, not which model sits behind each tool, and few would capture a same-day worldwide default change to an agentic model. Log the 19 May change and review Gemini Enterprise Agent Platform connector scopes before staff wire in SharePoint or ServiceNow.

Source: [Gemini 3.5 Flash: Google Makes the Agent the Default](https://theaicommand.com/ai-news/gemini-3-5-flash-agent-default#faq-3)

### What should GRC teams do about GPT-5 rollouts?

Update your vendor risk file now, because GPT-5 sits behind more agentic workflows, changing your control surface. Treat tool-use logs as material evidence under a CPS 230 lens. Specify retention and review obligations in your service contract, and confirm where tool-use logs sit before your next operational resilience review.

Source: [GPT-5 in the Enterprise: 60-Day Debrief](https://theaicommand.com/ai-news/gpt-5-enterprise-rollout-debrief#faq-4)

### What should GRC teams require before approving agentic browsing?

GRC should treat agentic browsing as a high-risk category. Specify access controls, audit logs and human-in-the-loop requirements before any agent touches customer data, financial transactions or regulated systems. Ask the failure rate by workflow, what logs are retained and for how long, and where the documented human checkpoint sits.

Source: [Agentic Browsing: What Actually Shipped This Month](https://theaicommand.com/ai-news/agentic-browsing-what-shipped-in-april#faq-4)

### What should I check before deploying on-device AI as an enterprise tool?

Verify five things: MDM coverage for on-device-only enforcement on your actual OS version, a model-selection policy enforced at org level, escalation behaviour for cloud handoffs sitting inside your residency posture, retention and analytics opt-outs at the MDM level, and training-data warranties written into your contract rather than just marketing.

Source: [On-Device AI at Work: Apple Intelligence and Pixel Gemini Nano](https://theaicommand.com/ai-news/on-device-ai-pixel-and-apple-at-work#faq-5)

### What should I do if a workflow depends on one named AI model?

Treat single-model dependence as a logged continuity scenario, not a hypothetical. If any pilot or production workflow relies on one named model, write down a fallback model and the steps to switch to it. A vendor's flagship can be withdrawn by a foreign government order with no notice and no restoration date.

Source: [AI Week in Review, 8-14 June 2026: A Frontier Model Pulled by Government Order](https://theaicommand.com/ai-news/ai-week-in-review-8-14-june-2026#faq-3)

### What should I do this week about self-serve AI agents?

You do not need to ban them, you need to see them. Ask whether any self-serve agent is already live, confirm agents inherit catalog permissions, name an accountable owner for any agent touching regulated data, draw a bright line on autonomous action, and stand up a fast control-summary intake for every new agent.

Source: [Business Teams Can Now Build Their Own AI Agents](https://theaicommand.com/ai-news/business-teams-building-their-own-ai-agents#faq-5)

### What should I do this week in response to OpenAI's chip announcement?

Make three adjustments. Reopen business cases you killed on cost, because the maths has probably changed. Design for abundance, deciding deliberately what AI is allowed to touch and where a person stays the decision-maker. And ignore the chip itself; treat it as a signal about where cost is heading.

Source: [OpenAI Built Its Own Chip. The Real Story Is the Cost of Intelligence.](https://theaicommand.com/ai-news/openai-custom-chip-and-the-ai-cost-curve#faq-4)

### What should I do this week to evaluate open-weight models?

Set up a one-week pilot. Pick the workload you spend most on commercially and run it on Llama 4 70B as a baseline. If sovereignty is on your risk register, request a demo from Mistral Sovereign through their partner network. Treat this as workload triage, not a model beauty contest.

Source: [The Open-Source Frontier in April 2026: Llama 4, DeepSeek R2, Mistral Sovereign](https://theaicommand.com/ai-news/open-source-frontier-april-2026#faq-5)

### What should my organisation do about this in the next week?

Set the data line so no identifiable health or claimant detail enters consumer AI tools. Name where AI health information is welcome, such as preparing questions, and where it is not, such as decisions or evidence. Brief the front line to route decisions to the qualified person, and recheck existing guardrails.

Source: [ChatGPT Just Got Better at Health. Mind the Boundary.](https://theaicommand.com/ai-news/chatgpt-health-intelligence-and-the-boundary#faq-5)

### What should my organisation do this week about the Standard?

If you have not mapped your AI policy to the ten guardrails, do that now, as it is a one-day exercise for most teams. If you sit in procurement, add a guardrail-compliance question to your AI vendor questionnaire. If you operate in a high-risk category, start asking vendors for evidence on guardrails 1, 2, 4 and 9.

Source: [Australian AI Safety Standard: 18-Month Review](https://theaicommand.com/ai-news/australian-ai-safety-standard-18-month-review#faq-5)

### What should organisations do this week about the MAI substitution?

Ask the Microsoft account team or message centre which Copilot surfaces now run MAI models and how future swaps are notified, then record it in the AI register. Model last quarter's usage against AI Credits pricing for the budget. Add a model substitution clause with notification, evaluation evidence and rollback before renewal.

Source: [Microsoft's Seven MAI Models: The In-House Bet Under Copilot](https://theaicommand.com/ai-news/microsoft-mai-models-copilot#faq-5)

### What should regulated organisations do about embedded AI this week?

Ask procurement whether any integrator contract now includes an embedded model, then triage whether each is a material service arrangement and record it with a named owner. Write down the human-decision boundary for regulated decisions, and confirm you can extract a full audit trail of the model's actions and inputs.

Source: [AI Is Moving Into the Core Systems of Regulated Work](https://theaicommand.com/ai-news/ai-in-regulated-core-systems#faq-5)

### What should teams do this week about Claude Sonnet 5?

Map where the default is now in play, pin the model version wherever a workflow has been validated, re-run a small eval set of real de-identified tasks before trusting it on regulated work, write a data-class rule for what may enter the one million token window, and log the swap in your AI or change register with the date and what you re-tested.

Source: [Claude Sonnet 5 Became the Default. That Is a Change Event.](https://theaicommand.com/ai-news/claude-sonnet-5-your-default-just-changed#faq-5)

### What should vendor-risk teams do about Claude Fable 5 this week?

Pull your Anthropic agreement and compare the retention clause against the new policy, logging any zero-retention variance and reopening the APP 11 assessment. Set your 23 June billing position and tell finance before 22 June. If using Bedrock, ask AWS how the 30-day retention operates for Sydney-region workloads.

Source: [Claude Fable 5: Frontier Capability, With Conditions Attached](https://theaicommand.com/ai-news/claude-fable-5-in-practice#faq-4)

### What should we ask a vendor before buying an agent with memory?

Where is memory stored and in which jurisdiction, can we see and export it, how is it isolated between customers, what controls exist on what gets written, how does expiry work, and how do we delete or roll back an entry. A vendor with no answer to those has not built an enterprise-ready memory feature, however good the demo looks.

Source: [Your AI Agent Can Remember Now. Govern What It Keeps.](https://theaicommand.com/ai-news/govern-ai-agent-memory#faq-5)

### What tasks should I keep on-device versus sending to a cloud AI model?

Keep short summaries, message previews, voice memo transcriptions, multilingual transcription, offline field work, and high-sensitivity 200-word notes on-device. Send long-form drafting, structured reasoning over documents, and agentic workflows to frontier cloud models. The right question is which tasks belong on which tier, and whether your MDM can enforce that routing.

Source: [On-Device AI at Work: Apple Intelligence and Pixel Gemini Nano](https://theaicommand.com/ai-news/on-device-ai-pixel-and-apple-at-work#faq-2)

### What three decisions should I make before deploying Claude Tag?

Decide which channels it can join, defaulting to keeping it out of sensitive ones. Scope its access tightly to the tools and data a defined job needs, nothing more. Gate consequential actions, treating anything that sends, commits or decides as needing a human checkpoint. Make these decisions before it is live.

Source: [Your AI Assistant Just Became a Shared Teammate. Govern the Channel.](https://theaicommand.com/ai-news/claude-tag-and-the-shared-ai-teammate#faq-4)

### What was the EchoLeak vulnerability?

EchoLeak, tracked as CVE-2025-32711, was a zero-click vulnerability in Microsoft 365 Copilot rated 9.3 on CVSS. A single ordinary-looking email contained hidden instructions that caused Copilot to gather data from the user's OneDrive, SharePoint and Teams and route it out through an allowed channel, using the user's own access.

Source: [The OWASP Agentic Top 10: A Defence Playbook for the Agents You Are Deploying](https://theaicommand.com/ai-news/owasp-agentic-top-10-defence-playbook#faq-3)

### What were the other AI developments to watch this week?

OpenAI filed a confidential draft S-1 for an IPO, Apple unveiled a Gemini-powered Siri at WWDC, Google removed the Gemini 3.5 Flash opt-out, ChatGPT replaced named models with effort tiers, Codex gained Computer Use on Windows, and ChatGPT can now draft and send email in chat.

Source: [AI Week in Review, 8-14 June 2026: A Frontier Model Pulled by Government Order](https://theaicommand.com/ai-news/ai-week-in-review-8-14-june-2026#faq-5)

### What were the VirBench numbers, and do they apply to my work?

On Anthropic's VirBench benchmark of 120 factual retrieval queries, frontier models answering from memory ran a mean accuracy of 16.9% to 91.3%, with answers drifting between runs. Once given a deterministic tool over the real database, every agent cleared 90% and the top reached 99.7%. The exact percentages belong to a biology task and do not transfer to your domain. The pattern does.

Source: [Ground the Model, Do Not Trust Its Memory](https://theaicommand.com/ai-news/grounding-beats-model-memory#faq-2)

### What worked and what did not work after 18 months?

Two things worked: the ten-guardrail taxonomy proved the right shape for boards, procurement and regulators, and procurement leverage drove vendor self-certification. Two did not: voluntary framing capped SME adoption at 4 per cent implementation, and guardrail 10, stakeholder engagement, remained weak and often token in practice.

Source: [Australian AI Safety Standard: 18-Month Review](https://theaicommand.com/ai-news/australian-ai-safety-standard-18-month-review#faq-2)

### When does Claude Fable 5 come back, and why was it suspended?

Claude Fable 5 returns globally from 1 July 2026, on the Claude Platform, Claude.ai, Claude Code and Claude Cowork. It was suspended on 12 June after a US government directive to block access for foreign nationals, over a concern the model could be jailbroken to unlock cybersecurity capability. The US Department of Commerce lifted the controls on 30 June after its Center for AI Standards and Innovation tested the safeguards.

Source: [Fable 5 Returns With a Jailbreak Severity Framework](https://theaicommand.com/ai-news/fable-5-returns-jailbreak-severity-framework#faq-1)

### When does long context actually pay off over RAG?

It pays off on a small number of large, complex documents needing holistic reasoning where cost per query is not the dominant constraint. Examples include complex contract review across hundreds of cross-references, hour-long video evidence review, and reasoning over an entire large codebase that fragmentary retrieval would miss.

Source: [2M-Token Multimodal Contexts: Where They Actually Pay Off](https://theaicommand.com/ai-news/multimodal-context-windows-real-workflows#faq-2)

### When is fine-tuning the right answer?

When you want changed form or behaviour rather than new facts. OpenAI's supervised fine-tuning is aimed at classification, nuanced translation, generating content in a specific format and correcting instruction following failures, with preference optimisation used for tone and style. Microsoft names modifying style and tone, generating outputs in specific formats or schemas, enhancing tool usage and distilling a large model into a smaller cheaper one. Shorter prompts, lower latency and cost at volume are genuine wins. Knowing a fact you told it last week is not.

Source: [Fine-Tuning Writes Your Data Into the Model](https://theaicommand.com/ai-news/fine-tuning-writes-your-data-into-the-model#faq-4)

### When should agentic browsing be used instead of an API?

Where an API exists, the API is still the right answer: cheaper, faster, more reliable and more auditable. Agentic browsing does not replace APIs. It is the right choice only when no API exists and you cannot obtain the data otherwise, and it suits narrow, repetitive, internal tasks where failure is recoverable.

Source: [Agentic Browsing: What Actually Shipped This Month](https://theaicommand.com/ai-news/agentic-browsing-what-shipped-in-april#faq-3)

### When will the DEWR monitoring framework be updated?

Not until late 2026. The ABS has retired occupation-level employment data under the ANZSCO classification and is moving to the new OSCA classification, so February 2026 was the final quarter DEWR could analyse. The report is a frozen snapshot taken just as the negative signal was strengthening.

Source: [Canberra Just Measured What AI Is Doing to Jobs. It Found 2%.](https://theaicommand.com/ai-news/dewr-ai-employment-australia-report#faq-5)

### Where has Claude Sonnet 5 become the default model?

It became the default in Claude Code on 1 July 2026 (version 2.1.197) and is the default for Free and Pro users on Claude.ai. It is also available through the API as claude-sonnet-5, on Max, Team and Enterprise plans, and on Amazon Bedrock and Microsoft Foundry, with Google Vertex listed as coming soon. It is not the API default, where Anthropic still points agentic work at Opus 4.8.

Source: [Claude Sonnet 5 Became the Default. That Is a Change Event.](https://theaicommand.com/ai-news/claude-sonnet-5-your-default-just-changed#faq-2)

### Where is AI safest to use in hiring?

AI is most defensible supporting low-risk administrative work: drafting interview guides from an approved position description, converting selection criteria into scorecard language, summarising policy documents for panels, preparing candidate communication templates and checking advertisement language. Remove personal information first, keep prompts to role content rather than candidate content, and have a human reviewer check all outputs.

Source: [AI in Hiring Needs Human Review Before It Needs Another Tool](https://theaicommand.com/ai-news/ai-in-hiring-needs-human-review#faq-2)

### Which Australian regulations apply when a business team builds an AI agent?

An agent touching personal or claims data is your organisation's responsibility under the Privacy Act 1988 and Australian Privacy Principle 11. For APRA-regulated entities, CPS 234 reaches the agent as an access path into your data, and CPS 230 applies once a team depends on it for a real process.

Source: [Business Teams Can Now Build Their Own AI Agents](https://theaicommand.com/ai-news/business-teams-building-their-own-ai-agents#faq-3)

### Which Australian rules apply to where a task is routed?

Under the Privacy Act, which model handles personal information is a use and disclosure question under APP 6, and once the model sits offshore it becomes a cross-border disclosure question under APP 8. For APRA-regulated entities, a material model provider also sits inside CPS 234 information security and CPS 230 service provider obligations. A routing layer tuned only for price satisfies none of that.

Source: [Model Routing Cuts AI Bills. It Also Moves Your Data.](https://theaicommand.com/ai-news/match-the-model-to-the-task#faq-4)

### Which guardrails are moving towards mandatory and by when?

Based on public consultation responses, guardrails 1, 2, 4 and 9 are set to become mandatory for defined high-risk uses by mid-2027. The remaining guardrails would stay voluntary but continue to be referenced in sector regulation. The legislative vehicle has not yet been confirmed.

Source: [Australian AI Safety Standard: 18-Month Review](https://theaicommand.com/ai-news/australian-ai-safety-standard-18-month-review#faq-3)

### Which occupations are most exposed to AI in Australia?

Routine cognitive occupations. The largest in the most exposed fifth include General Clerks, Retail Managers, Software and Applications Programmers, Accountants, Receptionists, Accounting Clerks, Solicitors and Finance Managers. The least exposed are manual and care roles such as electricians, truck drivers and aged and disabled carers.

Source: [Canberra Just Measured What AI Is Doing to Jobs. It Found 2%.](https://theaicommand.com/ai-news/dewr-ai-employment-australia-report#faq-3)

### Which open model should I use for data sovereignty and cross-border concerns?

Mistral Sovereign 220B is purpose-built for this, hosted in EU and AU regions through partners including Outscale, OVHCloud and AUCloud with contractual data residency guarantees. Self-hosted Llama 4 in an Australian region is also a legitimate answer to APP 8 cross-border concerns. DeepSeek R2 carries supply-chain restrictions.

Source: [The Open-Source Frontier in April 2026: Llama 4, DeepSeek R2, Mistral Sovereign](https://theaicommand.com/ai-news/open-source-frontier-april-2026#faq-3)

### Which open-source AI model is best for enterprise in April 2026?

There is no single best model. DeepSeek R2 leads on reasoning and code benchmarks, Llama 4 wins on ecosystem and tooling, and Mistral Sovereign wins on sovereign deployment. Match models to workloads rather than choosing one answer for everything, because each carves out a defensible enterprise niche.

Source: [The Open-Source Frontier in April 2026: Llama 4, DeepSeek R2, Mistral Sovereign](https://theaicommand.com/ai-news/open-source-frontier-april-2026#faq-1)

### Which OWASP agentic risk does this map to?

It maps to ASI05 Unexpected Code Execution in the OWASP Top 10 for Agentic Applications, where externally influenced code runs when it should not. The standing control is the same one the framework recommends: constrain what can execute, do not expose the builder, and run it with least privilege.

Source: [A Real CVE in Your Agent-Building Tools](https://theaicommand.com/ai-news/a-real-cve-in-your-agent-building-tools#faq-4)

### Which OWASP agentic risks does this map to?

Two. ASI02 Tool Misuse, where a legitimate tool is bent to a harmful end, and ASI04 Agentic Supply Chain Vulnerabilities, the runtime poisoning of MCP and agent-to-agent ecosystems. Both sit in the OWASP Top 10 for Agentic Applications 2026, the framework this site already uses to govern agents.

Source: [Someone Poisoned the Tool Description. The Agent Did the Rest.](https://theaicommand.com/ai-news/mcp-tool-poisoning-least-agency#faq-4)

### Why are small and embedded models a governance blind spot?

Most AI policies were built around public chatbots, telling staff not to enter sensitive data and to review outputs. They do not cover AI arriving through procurement, software updates, vendor add-ons or device features. Embedded models quietly classify, rank, flag or summarise, so the risk is missed entirely.

Source: [Small Models, Edge AI and the Next Governance Blind Spot](https://theaicommand.com/ai-news/small-models-edge-ai-governance#faq-1)

### Why can a data centre affect power-system security?

Large data centres can behave as inverter-based loads. The AEMC says poor disturbance response, including many facilities disconnecting together after a voltage event, could increase instability. Its draft rule would create clearer performance and ride-through standards proportionate to a load's potential system-security impact.

Source: [AI's Next Constraint Is Power. Australia Has Started Writing the Rules](https://theaicommand.com/ai-news/ai-power-australia-grid-rules#faq-3)

### Why did Anthropic suspend Claude Fable 5 and Mythos 5?

On 12 June 2026 Anthropic received a US export-control directive citing national security authorities. It suspends access by any foreign national, inside or outside the United States. Because Anthropic cannot filter foreign nationals from US users in real time, it disabled both models for every customer rather than only the affected group.

Source: [AI Week in Review, 8-14 June 2026: A Frontier Model Pulled by Government Order](https://theaicommand.com/ai-news/ai-week-in-review-8-14-june-2026#faq-1)

### Why do AI agents break the old security model?

Traditional security assumes a clear line between trusted code and untrusted data. Large language models erase that line, treating everything in the context window as language to act on. So text in a web page, calendar invite or email can read as an instruction, which is prompt injection, and the agent can then take actions.

Source: [The OWASP Agentic Top 10: A Defence Playbook for the Agents You Are Deploying](https://theaicommand.com/ai-news/owasp-agentic-top-10-defence-playbook#faq-2)

### Why do AI agents need stronger controls than chatbots?

A chatbot answers questions, but an agent can plan steps, use tools, call APIs, write files, send messages and trigger workflows. That shifts the risk from whether the output is good to whether the system should be allowed to act, adding action risk such as emailing the wrong person or updating the wrong record.

Source: [AI Agents Need Approval Gates Before They Need Autonomy](https://theaicommand.com/ai-news/ai-agents-need-approval-gates#faq-1)

### Why do AI pilots stall before reaching enterprise scale?

Pilots stall because the limiting factor is the operating model, not access to a model. Pilots can rely on enthusiastic users, selected examples, manual checks and non-sensitive data. Normal operations bring messy inputs, privacy constraints, vendor limits, audit questions, incident management and accountability that a pilot can skip but a scaled system cannot.

Source: [The AI Pilot-to-Scale Gap Is an Operating Model Problem](https://theaicommand.com/ai-news/the-ai-pilot-to-scale-gap#faq-1)

### Why do guardrails matter for regulated Australian work?

Because the guardrail layer is where a written policy becomes an enforced control and where you can produce evidence that it operated. A rule that says de-identify before sending to a model is only real if an input rail enforces it, and an obligation to keep a human in the loop is only real if an action gate stops the model acting alone. That maps directly to privacy, CPS 234 and CPS 230 style expectations.

Source: [AI Guardrails: The Safety Layer No Vendor Can Ship for You](https://theaicommand.com/ai-news/ai-guardrails-the-layer-around-the-model#faq-4)

### Why do structured outputs matter for regulated work?

Because they turn an AI step from prose a person eyeballs into structured data a system can check and log. If you extract fields from a claim, a determination or a compliance register into a defined schema, you can enforce rules on each field, record exactly what came out, and audit the pipeline. That auditability is what regulated work needs. It also sharpens where the human belongs: the Privacy Act's APP 10 requires reasonable steps to keep personal information accurate, and the OAIC says a human should verify the accuracy of information obtained through AI, so the person checks the values while the schema handles the format.

Source: [Structured Outputs: Make Your AI Return Data You Can Audit](https://theaicommand.com/ai-news/structured-outputs-schema-enforced-ai-regulated-work#faq-3)

### Why does a default model change matter for regulated work?

Almost nobody chooses a model deliberately; they use whatever the tool opens with. When the default changes, a workflow you validated earlier can behave differently even though nothing in your own setup changed. For Australian regulated work, a material change to a service you depend on is a change event under APRA CPS 230, and a third-party AI change worth noticing under CPS 234 and the Voluntary AI Safety Standard.

Source: [Claude Sonnet 5 Became the Default. That Is a Change Event.](https://theaicommand.com/ai-news/claude-sonnet-5-your-default-just-changed#faq-3)

### Why does a model that works for days change how managers supervise AI?

When output arrives after three days of unattended work, reviewing each step as it lands is no longer possible. Control moves to the front: define acceptance criteria before the run and audit the result after, managing it like a contractor. Most AI usage policies do not yet cover unattended overnight runs.

Source: [Claude Fable 5: Frontier Capability, With Conditions Attached](https://theaicommand.com/ai-news/claude-fable-5-in-practice#faq-3)

### Why does adding more context make an AI model perform worse?

Models have a limited attention budget, like human working memory. Spend it on noise and less remains for what matters. As the context window fills, the model's ability to accurately recall information decreases, a phenomenon nicknamed context rot. Burying the relevant paragraph among many tokens makes the signal harder to find.

Source: [Context Engineering: What the Model Is Allowed to See](https://theaicommand.com/ai-news/context-engineering-what-the-model-sees#faq-2)

### Why does context engineering matter for regulated Australian work?

What enters the context window is a decision about what data the model handles, possibly through a third-party service or into logs. Curating to the smallest high-signal set mirrors privacy practice: collect and use only what is necessary. It lets practitioners apply de-identification and minimisation before data reaches the model, producing better answers and a defensible position.

Source: [Context Engineering: What the Model Is Allowed to See](https://theaicommand.com/ai-news/context-engineering-what-the-model-sees#faq-4)

### Why does embedding AI in core systems matter more than a chatbot pilot?

A copilot is a tool an individual chooses to open or ignore. Systems integrators build and run the core systems that move money, adjudicate claims and keep aircraft scheduled. Wiring a frontier model into that layer moves AI from a tool a person uses to a dependency the whole organisation runs on.

Source: [AI Is Moving Into the Core Systems of Regulated Work](https://theaicommand.com/ai-news/ai-in-regulated-core-systems#faq-2)

### Why does it matter that the flaw was in Langflow and not a model?

Most AI security attention goes to models and prompts. This flaw was in the plumbing, the low-code tool teams use to assemble agents. An exposed builder with a code-execution bug hands a server to anyone who finds it, no model involved. It is a reminder to govern agent-building tooling like production infrastructure.

Source: [A Real CVE in Your Agent-Building Tools](https://theaicommand.com/ai-news/a-real-cve-in-your-agent-building-tools#faq-3)

### Why does measurement matter more than time saved when scaling AI?

Measurement is often the weakest element. Time saved is useful but insufficient, because a faster draft may be inaccurate, a polished summary may omit caveats and a structured recommendation may hide bias. Organisations need measures of both value and trust, covering quality, judgement, risk and stakeholder outcomes, not just speed.

Source: [The AI Pilot-to-Scale Gap Is an Operating Model Problem](https://theaicommand.com/ai-news/the-ai-pilot-to-scale-gap#faq-4)

### Why does normal monitoring miss it?

Because nothing that usually trips an alert changes. There is no exploit code, no new credential, no altered system prompt. In setups where a description update does not force re-approval, the poisoned metadata simply goes live, and the agent's actions look like ordinary tool calls made with access it already had.

Source: [Someone Poisoned the Tool Description. The Agent Did the Rest.](https://theaicommand.com/ai-news/mcp-tool-poisoning-least-agency#faq-2)

### Why does OpenAI building its own chip matter for my AI decisions?

OpenAI's stated reason for the chip is making compute more affordable and lowering the cost of running its models. Every serious lab is vertically integrating for the same reason. That trajectory means the cost of useful AI keeps falling, which is what you plan around, not the silicon.

Source: [OpenAI Built Its Own Chip. The Real Story Is the Cost of Intelligence.](https://theaicommand.com/ai-news/openai-custom-chip-and-the-ai-cost-curve#faq-2)

### Why does regulated work need continuous AI evaluation most?

Because in regulated settings a silent quality drop is a compliance event, not just a product bug. Frameworks like NIST's AI Risk Management Framework treat measurement and ongoing monitoring as core, and APRA's CPS 230 treats a material change to a service, including a model version change, as a change to manage. If you cannot detect that your AI has drifted, you cannot evidence that it still meets the obligation it was deployed under.

Source: [Your AI Passed the Pilot. Production Is a Different Test.](https://theaicommand.com/ai-news/ai-passed-the-pilot-govern-the-drift#faq-4)

### Why does self-serve agent-building change governance for my organisation?

When a business user builds an agent from a prompt, two things change. The pool of people creating autonomous software grows by an order of magnitude, and the control point moves from an IT approval gate to whatever your data-governance layer enforces. A patchy governance layer does not wait for you to fix it.

Source: [Business Teams Can Now Build Their Own AI Agents](https://theaicommand.com/ai-news/business-teams-building-their-own-ai-agents#faq-2)

### Why does testing on my own work matter more in regulated environments?

In regulated work you must care whether a tool fails safely: whether it refuses what it should, leaks across boundaries, or fabricates a citation or clause confidently. These behaviours rarely show on a capability leaderboard. Build tests that probe your risk, because a safety card describes intent while your evaluation measures behaviour.

Source: [Stop Trusting the Leaderboard: Evaluate AI on Your Own Work](https://theaicommand.com/ai-news/evaluate-ai-tool-before-you-buy#faq-5)

### Why does the AI control point move from the prompt to the environment?

When an agent answers in seconds you supervise by reading the answer. When it works unattended for hours, taking hundreds of small actions, reading the final output is not supervision. Control has to move upstream to the environment: where the agent runs, what it can reach, how credentials are scoped, what it logs, and how the work is reviewed.

Source: [AI Agents Just Went From Minutes to Hours. The Control Point Is Where They Run.](https://theaicommand.com/ai-news/long-running-ai-agents-govern-where-they-run#faq-3)

### Why does the Flash-first sequencing matter?

Frontier launches normally lead with the flagship, then cheaper tiers follow. Google inverted this: the executor, Flash, shipped first worldwide as the default, while Pro, positioned as the orchestrator, ships next month. That order signals the product is now an orchestrator-plus-subagent architecture, not a single model.

Source: [Gemini 3.5 Flash: Google Makes the Agent the Default](https://theaicommand.com/ai-news/gemini-3-5-flash-agent-default#faq-2)

### Why does the MAI model swap matter for GRC and vendor risk teams?

The substitution is a third-party risk change that arrives without a procurement trigger. The invoice, product name and contract do not change, but the model underneath does. AI register entries naming the old model are now stale, and registers must be specific enough to detect this class of change.

Source: [Microsoft's Seven MAI Models: The In-House Bet Under Copilot](https://theaicommand.com/ai-news/microsoft-mai-models-copilot#faq-2)

### Why does this matter for Australian organisations?

Even if you never use GPT-5.5-Cyber, the same capability that helps defenders find flaws helps attackers find them in your software. Australia is a named partner in the access scheme. The practical response is to know your open-source dependencies, treat patch velocity as a frontline control, and read your security vendors as material relationships.

Source: [AI Cyber Defence Just Scaled Up. Mind Your Open-Source Dependencies.](https://theaicommand.com/ai-news/ai-cyber-defence-and-your-open-source-dependencies#faq-3)

### Why is a government access list a procurement issue and not just a policy story?

Because it is repeatable. A vetted access list is a mechanism a government can use again on the next capable model. That turns government-imposed access conditions into a standing vendor-risk category, the kind of thing your due diligence and vendor register have to name and score, rather than a one-off headline you read and move past.

Source: [A Government Now Vets Who Gets the Model. File It as a Vendor Risk.](https://theaicommand.com/ai-news/gated-model-access-is-a-vendor-risk#faq-2)

### Why is a successful AI pilot not enough?

A pilot measures the system once, against a snapshot of data, on a particular version of a model. In production, all three move. The provider can swap the default model version underneath you, the real-world inputs drift away from your test data, and users find new ways to use the tool. A pilot proves the AI can work, not that it keeps working, so treating the pilot as sign-off leaves you blind to the moment it stops.

Source: [Your AI Passed the Pilot. Production Is a Different Test.](https://theaicommand.com/ai-news/ai-passed-the-pilot-govern-the-drift#faq-1)

### Why is AI training on its own not enough for adoption?

Training assumes the job stays the same and the employee simply works faster. In practice AI changes the sequence of work, so HR must also redesign roles, expectations, capability frameworks and quality controls. Without this, AI can create hidden capability gaps and people may appear productive while becoming less able to explain their reasoning.

Source: [AI Upskilling Will Fail If HR Does Not Redesign the Work](https://theaicommand.com/ai-news/ai-upskilling-needs-work-redesign#faq-1)

### Why is model routing a governance issue and not just a cost one?

Because a cheaper model is usually a different model, from a different provider, in a different place, with different data handling. CNBC's reporting notes companies steering high-volume work to cheaper open-source models out of China or elsewhere. The model behind a task decides where the data goes, who can see it, and whether it is retained or used for training.

Source: [Model Routing Cuts AI Bills. It Also Moves Your Data.](https://theaicommand.com/ai-news/match-the-model-to-the-task#faq-3)

### Why is prompt and response content switched off by default?

Because it is likely to be personal information. The GenAI semantic conventions The GenAI semantic conventions warn that the input and output message attributes are likely to contain sensitive information including user or PII data, and flag other content attributes, including system instructions and memory records, as ones that may contain sensitive information., including input messages, output messages and system instructions: the attribute is likely to contain sensitive information including user or PII data. Instrumentations are told they should not capture it by default and that capture should be gated behind an explicit user opt-in. The default is a privacy protection, chosen on purpose, not a gap someone forgot to close.

Source: [Your AI Logs the Tokens. Not the Decision.](https://theaicommand.com/ai-news/trace-the-decision-not-just-the-tokens#faq-2)

### Why must HR own the people impact of workplace AI?

Adoption is often led by technology, transformation or procurement, with HR invited late after the vendor is chosen. That sequence is backwards when employee data is involved. HR need not own every technical decision, but it must own the people impact assessment covering personal information, employment influence, notice, monitoring capability and misuse risk.

Source: [Workplace AI and Privacy: The Trust Test HR Cannot Outsource](https://theaicommand.com/ai-news/workplace-ai-and-the-privacy-trust-test#faq-5)

### Why must workforce planning include governance capacity?

Access can scale faster than governance capacity. As adoption grows, organisations need people who can review outputs, maintain knowledge bases, test workflows, manage change, handle incidents, update policies and train others. Useful roles include AI champions, quality reviewers, knowledge stewards, risk partners and learning designers, many sitting in operations, HR, risk, legal and line management.

Source: [AI Upskilling Will Fail If HR Does Not Redesign the Work](https://theaicommand.com/ai-news/ai-upskilling-needs-work-redesign#faq-5)

### Why should a missed release date matter to me as a buyer?

Because it tells you how a vendor behaves under pressure, which a benchmark score never will. A lab that eats a delay rather than ship a model it does not trust is showing you one kind of judgement. The deeper lesson is that a release calendar is a marketing artefact. It should not set the timing of your own adoption decision.

Source: [Google Missed Its Own Release Date, and That Is the Story](https://theaicommand.com/ai-news/google-missed-its-own-release-date#faq-2)

### Why should finance, GRC or procurement teams care about reasoning budgets?

Default budgets are the equivalent of an unbounded invoice, so reasoning ceilings should be a line item in the AI vendor risk register. Sponsors should ask engineering teams what ceilings are set per workflow and what evidence supports them. Specifying ceilings as operational governance is now standard practice.

Source: [Reasoning Budgets in Production: How Teams Are Spending Them](https://theaicommand.com/ai-news/anthropic-reasoning-budgets-in-production#faq-5)

### Why should GRC and workers compensation professionals care about the Standard now?

For GRC, the Standard is a regulator-aligned baseline, and internal AI policies that do not map to the ten guardrails are out of step with Comcare, ASIC and APRA. For workers compensation, Comcare's April 2026 guidance references guardrails 4 and 9, so de-identification, prompt logging and a no-go list flow directly from them.

Source: [Australian AI Safety Standard: 18-Month Review](https://theaicommand.com/ai-news/australian-ai-safety-standard-18-month-review#faq-4)

### Why should I not trust AI benchmarks when choosing a tool?

A review of 445 benchmarks found almost all carried a methodological weakness, with 27 per cent relying on convenience sampling and only 16 per cent using statistical tests. Benchmarks are also contaminated when test questions sit in training data, and scores are measured under conditions that are not yours.

Source: [Stop Trusting the Leaderboard: Evaluate AI on Your Own Work](https://theaicommand.com/ai-news/evaluate-ai-tool-before-you-buy#faq-1)

### Why was GPT-5.6 launched gated by the US government?

The GPT-5.6 Preview System Card rates all three models High capability in both Cybersecurity and Biological and Chemical risk under OpenAI's Preparedness Framework. Sol is OpenAI's most capable cyber model yet. High capability is what a government takes an interest in, and that interest now sits in the release path.

Source: [GPT-5.6 Sol Lands. The Frontier Just Got Gated.](https://theaicommand.com/ai-news/gpt-5-6-sol-and-the-gated-frontier#faq-2)

## Learning hub

How the tools work and how to set them up properly.

### Can a safety card tell me how a model will perform in my own workflow?

No. The card describes the model in lab conditions, while your work is field conditions, and the two never match perfectly. Reading the card is the start of evaluation, not the end. It narrows the questions you ask in your own pilot, but it does not answer them.

Source: [How to Read an AI Tool Safety Card and Spot the Red Flags](https://theaicommand.com/learning-hub/reading-an-ai-tool-safety-card#faq-4)

### Can a team share one Custom Project?

Yes. In the team and enterprise tiers of Claude and ChatGPT, Projects can be shared, so a whole team works from the same system prompt and files for consistent output. Name an owner to keep the prompt current, reviewed once a quarter, and reference the team's documented AI policy in a house rules line.

Source: [Custom Projects vs Raw Chats: When to Graduate Your AI Workflow](https://theaicommand.com/learning-hub/custom-projects-vs-raw-chats#faq-5)

### Can an AI model grade its own outputs?

It can assist with repeatable rubric scoring, but its grades need validation against human judgements. Keep deterministic checks for exact requirements and qualified human review for meaning, risk and fairness.

Source: [Build a Golden Test Set Before You Trust an AI Workflow](https://theaicommand.com/learning-hub/build-golden-test-set-ai-workflow#faq-3)

### Can I paste real names and board papers into the chatbot to rehearse?

No. Do not paste real names, performance histories or board papers into a consumer chatbot. De-identify with placeholders like a senior direct report or a project name, use your organisation's enterprise tenancy where one exists, and check the AI use policy first. The rehearsal works just as well with placeholders.

Source: [AI as a Leadership Thinking Partner: Make It Attack Your Plan](https://theaicommand.com/learning-hub/ai-as-a-leadership-thinking-partner#faq-5)

### Can I see and delete what a Project remembers?

Yes. You can open the Project's saved memory, edit it, and tell Claude to update or forget specific things. Claude keeps the memory as a plain, readable file inside the Project, so treat it as a record you own and curate, not a black box.

Source: [What Your AI Workspace Actually Remembers, and What It Doesn't](https://theaicommand.com/learning-hub/what-your-ai-workspace-remembers#faq-5)

### Can I use AI to write my team's performance reviews?

You can use AI to draft feedback from a de-identified evidence log, then check every line. Drafting is a low-risk aid. Deciding is not. Scoring, ranking or recommending ratings is automated decision-making with its own obligations. The rating, calibration position and conversation stay human and carry your name.

Source: [AI in Performance Reviews: Draft the Words, Keep the Judgement](https://theaicommand.com/learning-hub/ai-in-performance-management#faq-1)

### Can I use the AI red team as accountability cover for a decision?

No. Do not use AI to launder accountability. The AI challenged it is not a defence, sign-off or substitute for judgement. The model produces input; the leader produces the decision and owns the consequences. A red team is legitimate cover only when it changes something or is consciously overruled with recorded reasoning.

Source: [AI as a Red Team for Leaders: How to Challenge Thinking Without Surrendering Judgement](https://theaicommand.com/learning-hub/ai-as-a-red-team-for-leaders#faq-5)

### Does a shared AI identity keep separate teams' information separate?

It can, if you scope it. In Claude Tag, memories and access stay scoped to the channels an administrator defines. Anthropic's own example is that an identity set up for sales will not pass its memories to one set up for engineering, and will not give engineers sales data or tools. The separation only holds if someone sets it up that way.

Source: [Your Team's First Shared AI Identity Is a Decision, Not a Toggle](https://theaicommand.com/learning-hub/the-shared-ai-identity-decision#faq-3)

### Does a valid schema make the content accurate?

No. A response can contain the required date field and still place an unsupported date inside it. Validate field values against source evidence and keep material decisions with an authorised person.

Source: [Structured Outputs: Get the Same Shape Every Time](https://theaicommand.com/learning-hub/structured-outputs-same-shape-every-time#faq-3)

### Does every case need an exact expected answer?

No. Generative wording can vary. Define expected properties, required fields, forbidden claims and scoring criteria. Use exact answers only where the task itself has one correct result.

Source: [Build a Golden Test Set Before You Trust an AI Workflow](https://theaicommand.com/learning-hub/build-golden-test-set-ai-workflow#faq-2)

### Does using AI in performance reviews break Australian privacy or employment law?

The employee records exemption is narrower than assumed and may not follow data sent to third-party tools. New APP 1.7 transparency obligations arrive on 10 December 2026. Under the Fair Work Act, the employer stays liable even if an algorithm decided. This is general information only, not legal advice; obtain advice for your scenario.

Source: [AI in Performance Reviews: Draft the Words, Keep the Judgement](https://theaicommand.com/learning-hub/ai-in-performance-management#faq-4)

### How can I read an AI safety card in 20 minutes?

Skim the executive summary, then read intended use carefully. Note the training data cut-off and licensing. Skim eval results for tasks relevant to your work. Read known limitations twice. Read the safety evaluations, focusing on named red teams and refusal rates. Finally note the versioning policy. Total: 20 minutes.

Source: [How to Read an AI Tool Safety Card and Spot the Red Flags](https://theaicommand.com/learning-hub/reading-an-ai-tool-safety-card#faq-5)

### How do I audit my AI tools for after-hours contact risk?

Conduct a comprehensive audit of every AI-enabled tool, listing all notifications, alerts, escalations, chatbots and summaries that can reach employees outside standard hours. Use a classification checklist recording contact type, trigger, time sent, urgency, whether automated or manager-triggered, and reasonableness notes.

Source: [The Right to Disconnect Changes How Teams Should Configure AI Workflow Tools](https://theaicommand.com/learning-hub/right-to-disconnect-ai-workflow-tools#faq-3)

### How do I build a voice profile without staring at a blank page?

Treat it as an interview, not a document. Paste samples you like and dislike, then have Claude ask up to eight questions one at a time to pin down tone, sentence length, structures, banned phrases, spelling and citation style. Claude drafts the file, you correct it, and it captures rules in minutes.

Source: [Gold Standard Claude Workspace Setup](https://theaicommand.com/learning-hub/gold-standard-claude-workspace-setup#faq-3)

### How do I build an AI workflow without any coding tools?

Pick a recurring text-heavy task with a defined input and output. Stitch three prompts together in a chat tool you already have: Extract, Transform, Polish. Run them as three separate prompts in the same chat for the first month. You need no n8n, Zapier or developer, only about 30 minutes to design it once.

Source: [Your First AI Workflow Without a Single Line of Code](https://theaicommand.com/learning-hub/first-ai-workflow-without-code#faq-1)

### How do I build ChatGPT Project instructions without staring at a blank page?

Use an interview, not a blank document. Paste samples the team likes and dislikes, then prompt the model to ask up to eight questions, one at a time, pinning down purpose, audience, tone, structures, banned phrases, citation rules and privacy limits. It then drafts instructions, a review checklist and before-and-after rewrites, marking anything inferred.

Source: [Gold Standard ChatGPT and Codex Setup](https://theaicommand.com/learning-hub/gold-standard-chatgpt-and-codex-setup#faq-2)

### How do I calibrate the challenge level to the decision?

Match the intensity to the stakes. Use mild challenge, which checks clarity, for routine reversible decisions. Use moderate challenge, which tests assumptions and stakeholders, as the default for most management decisions. Use severe challenge, a full pre-mortem attacking the strongest argument, only for irreversible or high-consequence calls.

Source: [AI as a Red Team for Leaders: How to Challenge Thinking Without Surrendering Judgement](https://theaicommand.com/learning-hub/ai-as-a-red-team-for-leaders#faq-3)

### How do I choose which Claude model to use for regulated GRC, WC or HR work?

Route by capability tier, not by model name. Decide which tier a task needs based on its consequence, ambiguity, sensitivity and the review it triggers. Pick the lightest tier that does the work safely, then pair it with a named review owner. The routing decision comes before you write the prompt.

Source: [Claude Model Routing for Regulated Work: Which Model to Use for GRC, WC and HR Tasks](https://theaicommand.com/learning-hub/claude-model-routing-for-regulated-work#faq-1)

### How do I improve the quality of AI outputs at work?

Three patterns reliably help: negative instructions telling the model what not to do, reasoning steps that ask it to think before answering on analytical tasks, and worked examples showing the tone or format you want. One example usually fixes tone; two or three usually fix format.

Source: [Prompt Engineering Fundamentals: The 2026 Update for Working Professionals](https://theaicommand.com/learning-hub/prompt-engineering-fundamentals-2026#faq-2)

### How do I keep worker control when using AI scheduling?

Let workers influence or override AI assignments and reasonably refuse or negotiate generated schedules or tasks. Embed a human review step before escalations to supervisors so legitimate reasons are considered. Respect the right to disconnect outside working hours, and ensure AI assists cognitive work rather than dictating decisions.

Source: [AI Work Allocation Needs Psychosocial Risk Controls](https://theaicommand.com/learning-hub/ai-work-allocation-psychosocial-risk-controls#faq-3)

### How do I know if my knowledge spine is actually working?

Score the pilot on five measures: specificity, source traceability, reviewer rework, missing-question quality and safe handling, judging on the contextual output rather than the longer one. If a pack only produced a longer answer, the spine is not working. If it named the right controls and asked better questions, the architecture is paying off.

Source: [Build the Knowledge Spine That Stops Generic AI Output](https://theaicommand.com/learning-hub/enterprise-knowledge-spine#faq-5)

### How do I know my AI setup has decayed back into a pile of chats?

Watch for familiar symptoms: every task starts from scratch, feedback disappears after one conversation, Codex changes files without a clear diff, or Custom GPTs multiply faster than anyone can maintain them. These signal no memory, no boundary or no review loop. Fix the operating system, prune monthly, and run a fuller quarterly reset.

Source: [Gold Standard ChatGPT and Codex Setup](https://theaicommand.com/learning-hub/gold-standard-chatgpt-and-codex-setup#faq-5)

### How do I measure whether AI adoption is actually working?

Track four practical signals. Quality covers improved accuracy, fewer errors and better decision support. Speed covers faster workflows and shorter cycle times. Risk covers identifying and mitigating new risks and meeting privacy and compliance standards. Learning covers the team gaining AI skills and sharing knowledge, collected consistently within the operating rhythm.

Source: [Managers Need an AI Operating Rhythm, Not More Pilots](https://theaicommand.com/learning-hub/ai-operating-rhythm-for-managers#faq-3)

### How do I pick an AI tool without getting fooled by the marketing?

Ignore launch posts. Run the same real task on each tool you can access for two weeks, read working-professional reports published a few weeks after a launch rather than week-one hype, and check whether your organisation already holds an enterprise contract, which is often the right starting point.

Source: [Choosing Claude, ChatGPT, Gemini or Copilot for Your Job](https://theaicommand.com/learning-hub/choosing-claude-chatgpt-gemini-copilot-for-your-job#faq-3)

### How do I run an AI pre-mortem on a decision?

Assume the plan has already failed twelve months on and ask the model to write the post-mortem. Have it list the most plausible failure reasons ranked by likelihood times damage, name the earliest warning sign for each, and surface causes nobody inside the plan would say aloud. Paste a de-identified plan summary.

Source: [AI as a Leadership Thinking Partner: Make It Attack Your Plan](https://theaicommand.com/learning-hub/ai-as-a-leadership-thinking-partner#faq-2)

### How do I save an AI workflow so I do not rebuild it each week?

Open a plain document, title it with the workflow name, and paste the three prompts in order. Add one line noting the weekly input and expected output. Save it where you will find it next Monday. That document is the recipe. If your tool supports Custom Projects, promote it once it runs cleanly twice.

Source: [Your First AI Workflow Without a Single Line of Code](https://theaicommand.com/learning-hub/first-ai-workflow-without-code#faq-4)

### How do I score a task before routing it to a Claude model?

Score the task one to five on four dimensions: consequence of error, ambiguity, sensitivity and review effort. Let the highest-risk dimension pull the routing upward. Low totals route to the fast tier with a spot check, medium to the reasoning tier, and high consequence or ambiguity to the highest available reasoning or frontier tier with expert review.

Source: [Claude Model Routing for Regulated Work: Which Model to Use for GRC, WC and HR Tasks](https://theaicommand.com/learning-hub/claude-model-routing-for-regulated-work#faq-3)

### How do I stop AI fabricating or just agreeing with my preferred option?

Guard against sycophancy and fabrication with a hard workflow rule: verify every AI-supplied fact, figure, citation or quote against the source before it enters the memo. If it cannot be traced to a real source, it goes in the gap list, not the recommendation. Ask the model to flag claims it introduced.

Source: [AI Decision Memos for Leaders: Sharpen the Thinking Without Outsourcing the Decision](https://theaicommand.com/learning-hub/ai-for-leadership-decision-memos#faq-3)

### How do I stop AI from just defending the option I prefer?

Do not state your preference, because models mirror stated views. Present the options neutrally, ask for the strongest case against each, ask what a sceptical CFO, regulator or board member would challenge first, and ask separately for disconfirming evidence. If the model knows your favourite, you are commissioning a defence, not a stress-test.

Source: [AI as a Leadership Thinking Partner: Make It Attack Your Plan](https://theaicommand.com/learning-hub/ai-as-a-leadership-thinking-partner#faq-3)

### How do I stop AI-drafted feedback from being biased?

Do not ask the model to de-bias its own work; Textio tested this and the feedback got less clear, not less biased. Instead, run a human screen for the three markers: personality comments, hedging, and non-actionable language with no example and no next step. The screen is the control, not self-debiasing.

Source: [AI in Performance Reviews: Draft the Words, Keep the Judgement](https://theaicommand.com/learning-hub/ai-in-performance-management#faq-3)

### How do I turn a Teams meeting transcript into a controlled HR SOP?

Treat the transcript as raw evidence, not the approved process. Run a staged prompt stack: first extract process facts plus a gap log marking uncertain points, then have humans confirm each fact before the model drafts. The published SOP needs a named owner, version history, validation trail and a scheduled review date.

Source: [Turn a Teams Transcript Into a Controlled HR SOP](https://theaicommand.com/learning-hub/teams-transcript-to-controlled-sop#faq-1)

### How do the major AI vendors differ on safety-card quality?

Anthropic publishes the most detailed system cards, structured by capability thresholds and named red teams. OpenAI's specs have grown more rigorous since GPT-5. Google's cards are technically thorough but corporately framed. Microsoft Copilot's is a Responsible AI Impact Assessment focused on integration controls rather than the underlying model's behaviour.

Source: [How to Read an AI Tool Safety Card and Spot the Red Flags](https://theaicommand.com/learning-hub/reading-an-ai-tool-safety-card#faq-3)

### How does a RAG system actually work step by step?

A RAG system does three things. It indexes documents once by splitting them into chunks, converting each into an embedding, and storing them in a vector database. For each question it retrieves the closest chunks, typically the top three to ten. It then generates an answer grounded in those retrieved chunks.

Source: [RAG Explained for Non-Engineers: How AI Reads Your Documents](https://theaicommand.com/learning-hub/rag-explained-for-non-engineers#faq-1)

### How does model routing connect to AI governance frameworks?

A written routing table with owners and review lanes is a recognised governance control. It maps to the NIST AI Risk Management Framework functions: govern by setting policy, map by classifying the task, measure by logging error rates per route, and manage by changing the route. ISO/IEC 42001 expects documented, auditable AI controls of exactly this kind.

Source: [Claude Model Routing for Regulated Work: Which Model to Use for GRC, WC and HR Tasks](https://theaicommand.com/learning-hub/claude-model-routing-for-regulated-work#faq-5)

### How long does it take to build a Custom Project?

About 10 minutes once your recipe is written. Click New Project and name it after the workflow, paste a one-paragraph system prompt, attach two or three small files, run the workflow once inside a new conversation, tweak anything generic or wrong, then save. It saves 60 to 90 seconds every later run.

Source: [Custom Projects vs Raw Chats: When to Graduate Your AI Workflow](https://theaicommand.com/learning-hub/custom-projects-vs-raw-chats#faq-3)

### How many cases should a golden test set contain?

Start with about 12 well-chosen cases across normal, difficult and boundary conditions. Add cases when real failures reveal a missing condition. Coverage matters more than an impressive row count.

Source: [Build a Golden Test Set Before You Trust an AI Workflow](https://theaicommand.com/learning-hub/build-golden-test-set-ai-workflow#faq-1)

### How often should my team review AI use?

Set three cadences. A 30-minute weekly team check-in shares wins, surfaces risks and updates use case status. A monthly cross-team review analyses adoption signals and plans training. A quarterly governance meeting evaluates the AI portfolio, updates risk controls and aligns AI use with business goals and compliance.

Source: [Managers Need an AI Operating Rhythm, Not More Pilots](https://theaicommand.com/learning-hub/ai-operating-rhythm-for-managers#faq-2)

### How should I control what each AI prompt is allowed to retrieve?

Retrieval boundaries are the single most important design decision. Not every interaction needs every note. An HR prompt may need employment-process context but not claim-level medical detail. Treat personal, medical, claim-level or confidential audit content as excluded by default unless a named owner approves it for that specific prompt type.

Source: [Build the Knowledge Spine That Stops Generic AI Output](https://theaicommand.com/learning-hub/enterprise-knowledge-spine#faq-4)

### How should I embed verification into my team's daily AI work?

Require team members to identify the source of AI outputs and check them against official records, policies or expert advice. Have them question inconsistent or unexpected results rather than relying blindly, and document the verification steps and any changes made before finalising work. This creates an audit trail and supports accountability.

Source: [AI Literacy Is a Management Skill, Not a Training Module](https://theaicommand.com/learning-hub/ai-literacy-verification-management-skill#faq-2)

### How should I prompt AI to draft review feedback without inventing examples?

Instruct it to use only the evidence notes, not invent examples, not infer personality traits, and not inflate or soften. Anchor every claim to a specific note and date, and write "insufficient evidence" where the log is thin. Then fact-check each line against the log and decide the rating yourself.

Source: [AI in Performance Reviews: Draft the Words, Keep the Judgement](https://theaicommand.com/learning-hub/ai-in-performance-management#faq-5)

### How should I prompt for high-stakes professional work?

Use two extra patterns. Ask the model to self-critique, acting as a senior reviewer that lists weaknesses and proposes fixes before you accept the draft. Then run a two-model check: the same prompt on a second model. Agreement raises confidence; divergence flags a real ambiguity worth examining yourself.

Source: [Prompt Engineering Fundamentals: The 2026 Update for Working Professionals](https://theaicommand.com/learning-hub/prompt-engineering-fundamentals-2026#faq-5)

### How should I use AI for a leadership decision memo without outsourcing the decision?

Treat AI as a structure engine, a critique partner and a drafting accelerator. Let it sharpen the question, generate options, sort evidence and run the pre-mortem. Keep the source evidence, the professional judgement and the accountable approval with named people. The leader decides; the model only prepares the thinking.

Source: [AI Decision Memos for Leaders: Sharpen the Thinking Without Outsourcing the Decision](https://theaicommand.com/learning-hub/ai-for-leadership-decision-memos#faq-1)

### Is a shared AI identity a replacement for a team member?

No. A shared identity is a shared assistant, not a colleague. It holds no accountability and owns no decision. It can draft, organise and follow up, but a named person stays responsible for anything it produces. Treat it as a capable tool the whole team can reach, not as a headcount.

Source: [Your Team's First Shared AI Identity Is a Decision, Not a Toggle](https://theaicommand.com/learning-hub/the-shared-ai-identity-decision#faq-5)

### Is asking for a table a structured output?

It is a prompted structure. It can be highly useful for human-reviewed work, but it does not provide the same machine-level guarantee as a supported API using a defined schema.

Source: [Structured Outputs: Get the Same Shape Every Time](https://theaicommand.com/learning-hub/structured-outputs-same-shape-every-time#faq-1)

### Is Cowork Project memory the same as Claude's chat memory?

No. They are separate stores. The memory Claude builds from your ordinary claude.ai conversations does not flow into a Cowork Project, and a Project's memory does not flow back into your chats. A Project only knows what you have done or saved inside it.

Source: [What Your AI Workspace Actually Remembers, and What It Doesn't](https://theaicommand.com/learning-hub/what-your-ai-workspace-remembers#faq-2)

### Is de-identifying a document enough to make a consumer AI tool safe for regulated work?

No. De-identification is necessary but not sufficient. It does not remove re-identification risk in small populations with rare attributes, residual confidential business information, or aggregate patterns across many cases. Tier 2 or Tier 3 deployment, plus de-identification where appropriate, is the working position for serious regulated work.

Source: [Privacy-Safe AI for Regulated Work: A Working Practitioner's Guide](https://theaicommand.com/learning-hub/privacy-safe-ai-for-regulated-work#faq-3)

### Is it worth switching AI tools once I am fluent in one?

Usually not. Tool fluency compounds and switching carries a real relearning cost, so a marginal improvement rarely justifies six weeks of relearning. Switch when the work shifts, for example moving into a regulated role or joining a Microsoft 365 enterprise that just deployed Copilot. Otherwise, stay and deepen your fluency.

Source: [Choosing Claude, ChatGPT, Gemini or Copilot for Your Job](https://theaicommand.com/learning-hub/choosing-claude-chatgpt-gemini-copilot-for-your-job#faq-5)

### Should every AI response use JSON?

No. Use it when another system needs to parse the output or when stable fields materially improve review. Natural language remains better for many exploratory and explanatory tasks.

Source: [Structured Outputs: Get the Same Shape Every Time](https://theaicommand.com/learning-hub/structured-outputs-same-shape-every-time#faq-4)

### Should I use just one AI tool or more than one?

For most professionals, owning two tools beats one. Run a primary tool for daily work and a secondary tool to sanity check high-stakes outputs like board papers, determination letters or risk register entries. Where the two models agree, you can be more confident. Where they disagree, you have flagged something worth examining yourself.

Source: [Choosing Claude, ChatGPT, Gemini or Copilot for Your Job](https://theaicommand.com/learning-hub/choosing-claude-chatgpt-gemini-copilot-for-your-job#faq-4)

### Should my team build a RAG system or buy one?

In 2026 the honest answer is buy first, build only if buy does not fit. Vendor products from Microsoft, Glean, Notion and Elastic have matured fast and handle chunking, embeddings, retrieval, permission mirroring and audit logs. Build only when your corpus has unusual structure or your governance posture requires controls vendors do not offer.

Source: [RAG Explained for Non-Engineers: How AI Reads Your Documents](https://theaicommand.com/learning-hub/rag-explained-for-non-engineers#faq-5)

### What are the five AI literacy behaviours managers should reinforce?

The five behaviours are prompting, verification, privacy hygiene, escalation and review. Prompting means clear, context-aware inputs. Verification checks outputs against reliable sources. Privacy hygiene controls what data enters AI tools. Escalation refers high-risk outputs to experts. Review regularly assesses AI use and outcomes for continuous improvement.

Source: [AI Literacy Is a Management Skill, Not a Training Module](https://theaicommand.com/learning-hub/ai-literacy-verification-management-skill#faq-1)

### What are the five steps in the privacy assessment before using AI on regulated data?

Answer five questions before any workflow touching sensitive data: the data classification, who the data subject is and what consent applies, which jurisdiction governs the data, the worst-case downstream use if it leaks, and the documented justification for using AI. If you cannot answer all five, do not proceed.

Source: [Privacy-Safe AI for Regulated Work: A Working Practitioner's Guide](https://theaicommand.com/learning-hub/privacy-safe-ai-for-regulated-work#faq-1)

### What are the main ways a RAG system fails?

There are four predictable failure modes. Retrieval misses pull back chunks that lack the answer. A stale index returns yesterday's policy when you needed today's. Generation drift sees the model fall back to general knowledge. A permission leak retrieves a document the user should not see, the most consequential failure in regulated work.

Source: [RAG Explained for Non-Engineers: How AI Reads Your Documents](https://theaicommand.com/learning-hub/rag-explained-for-non-engineers#faq-3)

### What are the most common prompting mistakes?

Treating the chat box like a search engine and underprompting, asking five questions in one prompt instead of a focused sequence, accepting the first answer rather than following up, and not defining what success looks like. A model treats good as a statistical average unless you tell it what good means for you.

Source: [Prompt Engineering Fundamentals: The 2026 Update for Working Professionals](https://theaicommand.com/learning-hub/prompt-engineering-fundamentals-2026#faq-4)

### What are the six modes of the AI red team for leaders?

The six modes are assumption challenge, evidence challenge, stakeholder challenge, downside challenge, timing challenge and narrative challenge. Each is a different move with a defined question, a specific output to request, and a specific human action, so requesting a named mode converts a vague chat into a focused method.

Source: [AI as a Red Team for Leaders: How to Challenge Thinking Without Surrendering Judgement](https://theaicommand.com/learning-hub/ai-as-a-red-team-for-leaders#faq-1)

### What are the three Claude capability tiers and what is each one for?

The fast tier suits high-volume, low-ambiguity work a human can check at a glance. The reasoning tier handles analysis, structured drafting and exception handling that mixes judgement with structure. The frontier tier covers the most demanding reasoning and long-horizon agentic work. Route to tiers so lineup changes do not break your workflow.

Source: [Claude Model Routing for Regulated Work: Which Model to Use for GRC, WC and HR Tasks](https://theaicommand.com/learning-hub/claude-model-routing-for-regulated-work#faq-2)

### What Australian rules apply when recording an HR meeting for an SOP?

Consent to record varies by state and territory, so confirm your jurisdiction's surveillance laws and tell attendees clearly. Employee records carry privacy obligations under the Australian Privacy Principles, including APP 11 security. Under the Fair Work Act and Regulations, certain employee records must be kept for seven years, so treat the transcript as a record.

Source: [Turn a Teams Transcript Into a Controlled HR SOP](https://theaicommand.com/learning-hub/teams-transcript-to-controlled-sop#faq-4)

### What changed about prompting on 2026 frontier models?

Three things shifted. Reasoning budgets now let you control how long a model thinks, helping multi-step analytical work. Long context windows reward direct citation, so name the exact sections to draw from. System prompts in Custom Projects are an under-used lever that shapes every conversation inside them.

Source: [Prompt Engineering Fundamentals: The 2026 Update for Working Professionals](https://theaicommand.com/learning-hub/prompt-engineering-fundamentals-2026#faq-3)

### What configuration changes help comply with the right to disconnect?

Suppress low-urgency notifications outside working hours and batch them into a morning summary, require manager approval before any after-hours escalation, use less intrusive channels for optional notifications, and let employees set preferred contact times and methods. Log all after-hours contacts with reasons and approvals.

Source: [The Right to Disconnect Changes How Teams Should Configure AI Workflow Tools](https://theaicommand.com/learning-hub/right-to-disconnect-ai-workflow-tools#faq-4)

### What decisions should a team make before enabling a shared AI identity?

Settle five things first. Which channels it lives in, what tools and data it can reach, what it is allowed to remember, who owns it and its token limit, and whether it acts unprompted. Each is a deliberate choice, not a default to accept. Write the answers down before the identity goes live.

Source: [Your Team's First Shared AI Identity Is a Decision, Not a Toggle](https://theaicommand.com/learning-hub/the-shared-ai-identity-decision#faq-2)

### What do Australian regulators expect for AI use on regulated information?

Existing law applies. The OAIC confirms the Privacy Act 1988 and Australian Privacy Principles cover AI processing, expecting a privacy impact assessment first. APRA brings AI within operational and model risk under CPS 230. Comcare emphasises de-identification, documented decision-making, and that statutory determinations remain with the delegate, not the model.

Source: [Privacy-Safe AI for Regulated Work: A Working Practitioner's Guide](https://theaicommand.com/learning-hub/privacy-safe-ai-for-regulated-work#faq-5)

### What does a Claude Cowork Project remember across sessions?

It remembers context from the tasks you run inside that Project, plus anything you explicitly ask it to save, and applies it to future tasks in the same Project. So you stop re-explaining the same background. It also carries the Project's standing instructions and attached files into every task.

Source: [What Your AI Workspace Actually Remembers, and What It Doesn't](https://theaicommand.com/learning-hub/what-your-ai-workspace-remembers#faq-1)

### What does a Project not remember?

What you did in a different Project, what you did in a standalone Cowork session outside any Project, and what you told Claude in an ordinary chat. Incognito chats are never saved to memory at all. Memory is scoped, not global.

Source: [What Your AI Workspace Actually Remembers, and What It Doesn't](https://theaicommand.com/learning-hub/what-your-ai-workspace-remembers#faq-3)

### What does good privacy hygiene look like when teams use AI tools?

Train teams on what data can and cannot be entered, keeping personal identifiers, sensitive health information and confidential business data out of AI tools without explicit consent and safeguards. Monitor prompts, chat logs and outputs for privacy risks, and ensure tools comply with organisational privacy policies and legal requirements such as the Privacy Act.

Source: [AI Literacy Is a Management Skill, Not a Training Module](https://theaicommand.com/learning-hub/ai-literacy-verification-management-skill#faq-5)

### What does the NSW Digital Work Systems Act 2026 require for AI work allocation?

It requires PCBUs to consider whether AI-driven work allocation produces excessive or unreasonable workloads or metrics, monitor systems for discriminatory or unlawful practices, and keep records to assist WHS inspectors reviewing digital work systems. The reforms treat AI as part of work design needing health and safety assessment.

Source: [AI Work Allocation Needs Psychosocial Risk Controls](https://theaicommand.com/learning-hub/ai-work-allocation-psychosocial-risk-controls#faq-4)

### What employee information can I safely paste into ChatGPT or Claude?

De-identify before anything touches the tool. The OAIC recommends not entering personal, particularly sensitive, information into publicly available generative AI. Replace names with placeholders like [EMPLOYEE], and strip anything identifying by inference. An approved enterprise tool changes the calculus, but check your AI policy first.

Source: [AI in Performance Reviews: Draft the Words, Keep the Judgement](https://theaicommand.com/learning-hub/ai-in-performance-management#faq-2)

### What files make up a gold standard Claude workspace?

The core set covers a project brief, voice profile, writing styles, source rules, domain packs, examples, ideas, lessons, a CLAUDE.md and a rules folder. Each file has one job. Coding rules and writing voice stay separate because they load into different surfaces and update on different triggers.

Source: [Gold Standard Claude Workspace Setup](https://theaicommand.com/learning-hub/gold-standard-claude-workspace-setup#faq-2)

### What five actions should every red team critique become?

Every surviving challenge must become one of five concrete actions: verify a piece of evidence, consult an uncertain stakeholder, adjust the decision in response to a genuine weakness, control a risk with a mitigation or early-warning signal, or rewrite the communication. If a critique maps to none, it is noise and gets discarded.

Source: [AI as a Red Team for Leaders: How to Challenge Thinking Without Surrendering Judgement](https://theaicommand.com/learning-hub/ai-as-a-red-team-for-leaders#faq-4)

### What framework should HR use before deploying AI allocation tools?

Use a structured assessment across five dimensions: job demands, worker control, support, organisational justice and change management. Audit AI rules, allow human review and overrides, train managers, keep decisions transparent and contestable, and consult workers early. Treat AI allocation as a work design issue, not only a technology procurement matter.

Source: [AI Work Allocation Needs Psychosocial Risk Controls](https://theaicommand.com/learning-hub/ai-work-allocation-psychosocial-risk-controls#faq-2)

### What goes into a Custom Project in Claude or ChatGPT?

Three things. A system prompt covering role, style, constraints and house rules, which is always included. Files such as a style guide, glossary or worked example, which are optional but valuable. And optionally a saved starting message you tweak each time rather than beginning from a blank page.

Source: [Custom Projects vs Raw Chats: When to Graduate Your AI Workflow](https://theaicommand.com/learning-hub/custom-projects-vs-raw-chats#faq-2)

### What information should never be pasted into ChatGPT or Codex?

Classify information into four levels and decide destinations in advance. Never paste secrets, credentials, API keys, tokens or live personal data into any prompt, Project, GPT or repository file. Sensitive records should be de-identified first or kept in local files under access control. Public material can go on any surface, including shared ones.

Source: [Gold Standard ChatGPT and Codex Setup](https://theaicommand.com/learning-hub/gold-standard-chatgpt-and-codex-setup#faq-3)

### What is a domain pack and what should it contain?

A domain pack is the unit you actually build: a curated bundle for one business area holding its notes, policies, approved examples, decision rules, lessons and prompt patterns, plus metadata and a retrieval boundary. A good pack has a named owner, sensitivity classification, permitted uses, excluded content, readable formats, backlinks and a review cadence.

Source: [Build the Knowledge Spine That Stops Generic AI Output](https://theaicommand.com/learning-hub/enterprise-knowledge-spine#faq-3)

### What is a knowledge spine and how is it different from a data swamp?

A data swamp is the accumulated sediment of near-duplicate versions, contradictory decks and tacit knowledge, searchable in theory and unusable in practice. A knowledge spine is the opposite: a deliberately curated, owned and governed body of knowledge an AI workflow may draw on. It is the small, trusted core, not the whole organisation digitised.

Source: [Build the Knowledge Spine That Stops Generic AI Output](https://theaicommand.com/learning-hub/enterprise-knowledge-spine#faq-2)

### What is a safe first use case to trial a shared team AI?

Pick a channel that carries low-sensitivity, high-repetition work, such as an internal operations or project-coordination channel with no customer, health or claim data. Give the identity a narrow job, keep proactive mode off at first, and review what it remembered after a week before widening its scope.

Source: [Your Team's First Shared AI Identity Is a Decision, Not a Toggle](https://theaicommand.com/learning-hub/the-shared-ai-identity-decision#faq-4)

### What is a shared AI identity, and how is it different from a normal AI chat?

A shared AI identity is one AI that a whole team channel uses together, with its own memory of that channel and its own admin-scoped access to tools and data. Anthropic's Claude Tag is the clearest example. Unlike a private chat that forgets you when you close it, a shared identity remembers, is visible to everyone in the channel, and can act between your messages.

Source: [Your Team's First Shared AI Identity Is a Decision, Not a Toggle](https://theaicommand.com/learning-hub/the-shared-ai-identity-decision#faq-1)

### What is an AI operating rhythm for managers?

An operating rhythm is the regular set of meetings, decisions, measures and review habits that turn AI strategy into repeatable work. For AI adoption it means weekly team check-ins, monthly cross-team reviews and quarterly governance, so isolated pilots become consistent routines that improve quality, speed and safety across the team.

Source: [Managers Need an AI Operating Rhythm, Not More Pilots](https://theaicommand.com/learning-hub/ai-operating-rhythm-for-managers#faq-1)

### What is an AI safety card and which sections should I focus on?

An AI safety card is the vendor document describing a model's design, evaluations, limitations and mitigations. Most run 30 to 80 pages, but the substance sits in seven sections: capabilities and intended use, training data summary, evaluation results, safety and red-team results, known limitations, mitigations and policies, and versioning.

Source: [How to Read an AI Tool Safety Card and Spot the Red Flags](https://theaicommand.com/learning-hub/reading-an-ai-tool-safety-card#faq-1)

### What is safe to put in shared Project knowledge?

Stable, cleared material is safe: brand and voice guidance, approved templates, published policy extracts and de-identified examples. Records with personal information, confidential material and live source data are not safe by default. Project knowledge is shared context, so de-identify first and keep live records in their governing system.

Source: [Gold Standard Claude Workspace Setup](https://theaicommand.com/learning-hub/gold-standard-claude-workspace-setup#faq-4)

### What is the difference between a ChatGPT Project, a Custom GPT and Codex?

A Project organises chats, files and instructions around one goal for repeated thinking work. A Custom GPT is a reusable assistant for one narrow task done the same way every time. Codex is OpenAI's coding agent that reads repository instructions and acts on files. Local files hold canonical or sensitive material under your own control.

Source: [Gold Standard ChatGPT and Codex Setup](https://theaicommand.com/learning-hub/gold-standard-chatgpt-and-codex-setup#faq-1)

### What is the difference between JSON mode and Structured Outputs?

JSON mode aims to return valid JSON. Schema-constrained Structured Outputs aim to return JSON that also matches specified fields, types and rules. Provider implementations and supported features vary, so check current documentation before building.

Source: [Structured Outputs: Get the Same Shape Every Time](https://theaicommand.com/learning-hub/structured-outputs-same-shape-every-time#faq-2)

### What is the RCTF prompting pattern?

RCTF stands for Role, Context, Task and Format. Tell the model who it is, give it the situation and constraints, state what you want using a precise verb like summarise or draft, and specify the output structure. Every professional prompt should hit all four beats, because skipping any one drops quality.

Source: [Prompt Engineering Fundamentals: The 2026 Update for Working Professionals](https://theaicommand.com/learning-hub/prompt-engineering-fundamentals-2026#faq-1)

### What is the right to disconnect in Australia?

Since 26 August 2024, Australian employees outside small business have a statutory right to refuse to monitor, read or respond to work-related contact outside their agreed working hours, unless that refusal is unreasonable. The Fair Work Ombudsman sets out factors that influence what is reasonable.

Source: [The Right to Disconnect Changes How Teams Should Configure AI Workflow Tools](https://theaicommand.com/learning-hub/right-to-disconnect-ai-workflow-tools#faq-1)

### What is the three-step pattern for a first AI workflow?

Almost every useful first workflow fits Extract, Transform, Polish. Extract pulls structured information from the raw input. Transform turns it into the shape your audience needs. Polish tightens the output to your voice and constraints. Run them as three prompts at first, then fold them into one once you know the pattern.

Source: [Your First AI Workflow Without a Single Line of Code](https://theaicommand.com/learning-hub/first-ai-workflow-without-code#faq-2)

### What mistakes should I avoid with Custom Projects?

Do not stuff everything into the system prompt; keep it to one or two short paragraphs and push detail into files. Do not forget to update it as workflows evolve. Do not treat a Project as a document library; five files is comfortable, fifty is too many. Do not paste confidential data into a consumer-tier Project.

Source: [Custom Projects vs Raw Chats: When to Graduate Your AI Workflow](https://theaicommand.com/learning-hub/custom-projects-vs-raw-chats#faq-4)

### What must be true before a transcript becomes a publishable SOP?

It must clear three gates. The capture gate checks the meeting was lawfully recorded, attendees were told and sensitive examples de-identified. The convert gate checks the model produced a gap log, not a fluent guess, with uncertain points flagged. The control gate checks a human owner confirmed each fact, with privacy, retention and approval authority all checked.

Source: [Turn a Teams Transcript Into a Controlled HR SOP](https://theaicommand.com/learning-hub/teams-transcript-to-controlled-sop#faq-5)

### What psychosocial hazards can AI work allocation create?

AI scheduling, monitoring and scoring can create excessive or unreasonable workloads, reduce worker control over pace and methods, weaken support, and damage perceptions of fairness or organisational justice. Systems may penalise workers for taking lawful breaks or following safe procedures, encouraging unsafe behaviour such as rushing deliveries or care tasks.

Source: [AI Work Allocation Needs Psychosocial Risk Controls](https://theaicommand.com/learning-hub/ai-work-allocation-psychosocial-risk-controls#faq-1)

### What questions should I ask a vendor pitching a chat with your documents product?

Ask three things. Show me the retrieval, not just the answer, so the system is auditable. What happens when the answer is not in the documents, since a good one says it does not have that. How do you handle confidential or restricted documents, because retrieval must mirror your access control model.

Source: [RAG Explained for Non-Engineers: How AI Reads Your Documents](https://theaicommand.com/learning-hub/rag-explained-for-non-engineers#faq-4)

### What red flags should I watch for when reading a model card?

Watch for three red flags. Marketing prose where evidence should sit, such as vague expert claims with no named experts or methodology. No acknowledged failure modes, since every model has them. And benchmarks chosen by the vendor with no public counterpart, which means the claim is not falsifiable.

Source: [How to Read an AI Tool Safety Card and Spot the Red Flags](https://theaicommand.com/learning-hub/reading-an-ai-tool-safety-card#faq-2)

### What roles keep a transcript-to-SOP workflow accountable?

Appoint three roles. The domain owner confirms the SOP describes reality. The AI workflow owner maintains the prompts, transcript files, naming conventions and tool behaviour for consistency. The reviewer checks outputs are grounded, proportionate and safe, watching privacy, retention and the line between manager action and HR escalation. Small teams can combine but should still name the hats.

Source: [Turn a Teams Transcript Into a Controlled HR SOP](https://theaicommand.com/learning-hub/teams-transcript-to-controlled-sop#faq-3)

### What should a 30-minute weekly AI rhythm review cover?

Schedule a 30-minute meeting focused on AI use. Ask what AI tools or features saved time or improved quality this week, identify any new risks, errors or user frustrations, discuss what should be standardised or stopped, and assign follow-up actions for training or process changes. This builds a habit of regular reflection.

Source: [Managers Need an AI Operating Rhythm, Not More Pilots](https://theaicommand.com/learning-hub/ai-operating-rhythm-for-managers#faq-5)

### What should I document for an AI workflow that touches regulated data?

Document the bounded purpose, the data classification and subjects, the tool, tier and contractual basis, any de-identification step, retention and deletion expectations, the named human review step, the escalation path, and the owner, reviewer and review cadence. This becomes part of your AI register and is what you hand to a regulator or auditor.

Source: [Privacy-Safe AI for Regulated Work: A Working Practitioner's Guide](https://theaicommand.com/learning-hub/privacy-safe-ai-for-regulated-work#faq-4)

### What steps does the decision memo method follow from start to finish?

Six deliberate steps: clarify the decision question, list real options separate from your preference, map evidence by quality, test the assumptions, run a pre-mortem, then draft the memo and name the review trigger. Each step narrows the task before the next builds on it, so weak evidence is not buried in smooth prose.

Source: [AI Decision Memos for Leaders: Sharpen the Thinking Without Outsourcing the Decision](https://theaicommand.com/learning-hub/ai-for-leadership-decision-memos#faq-2)

### What steps should managers follow when introducing AI work allocation?

Follow six review steps: plan by identifying systems and psychosocial risks; consult workers and representatives early; train staff on tools and controls; implement with human oversight and support; monitor outputs, feedback and health indicators regularly; and adjust parameters and controls based on monitoring and ongoing consultation.

Source: [AI Work Allocation Needs Psychosocial Risk Controls](https://theaicommand.com/learning-hub/ai-work-allocation-psychosocial-risk-controls#faq-5)

### When does AI sharpen leadership judgement and when does it flatten it?

AI sharpens judgement by widening the options and risks you can see, but flattens it through automation bias and polish-induced complacency. The capability frontier is jagged, and fluent output never tells you which side a task sits on. Use AI to widen inputs and risks, and keep the decision itself human.

Source: [AI as a Leadership Thinking Partner: Make It Attack Your Plan](https://theaicommand.com/learning-hub/ai-as-a-leadership-thinking-partner#faq-4)

### When should an AI workflow have more than three steps?

Three steps is the floor and the right starting point for everyday workflows. Add an Analyse step between Extract and Transform when the task involves judgement like ranking risks or scoring evidence. Add a Critique step after Polish to have the model review its own draft. Add steps only when the work demands it.

Source: [Your First AI Workflow Without a Single Line of Code](https://theaicommand.com/learning-hub/first-ai-workflow-without-code#faq-5)

### When should I choose Microsoft 365 Copilot over Claude or ChatGPT?

Choose Copilot when your organisation has deployed Microsoft 365 and you want work that touches tenant data: email, calendar, Teams, Outlook drafting, Excel help and SharePoint search. It is the only one shipping with enterprise grounding to your tenant by default. For thinking work, layer in Claude or ChatGPT.

Source: [Choosing Claude, ChatGPT, Gemini or Copilot for Your Job](https://theaicommand.com/learning-hub/choosing-claude-chatgpt-gemini-copilot-for-your-job#faq-2)

### When should I move a workflow from a raw chat into a Custom Project?

Use the two-week rule. If you have run the same kind of task more than two or three times in two weeks, it is ready to graduate. Pasting the same setup paragraph into a fresh chat every Monday is a tax a Project removes. Genuinely one-off work stays in raw chat.

Source: [Custom Projects vs Raw Chats: When to Graduate Your AI Workflow](https://theaicommand.com/learning-hub/custom-projects-vs-raw-chats#faq-1)

### When should I use RAG instead of a simpler approach?

RAG fits when you have a defined corpus, it changes more often than weekly, answers must cite the source, and the corpus is too big for a context window. If three or four are true, RAG is likely right. For a single document under 100 pages or a stable base under 500 pages, simpler approaches usually win.

Source: [RAG Explained for Non-Engineers: How AI Reads Your Documents](https://theaicommand.com/learning-hub/rag-explained-for-non-engineers#faq-2)

### When should my team escalate an AI output instead of verifying it themselves?

Escalate when outputs carry potential legal, compliance or safety risks, when AI results conflict with known facts or expert advice, or when cases involve sensitive personal or organisational data needing specialist handling. Managers should define clear escalation paths so uncertain or high-risk outputs reach people with the right authority or expertise.

Source: [AI Literacy Is a Management Skill, Not a Training Module](https://theaicommand.com/learning-hub/ai-literacy-verification-management-skill#faq-3)

### When should the test set be rerun?

Run it after material changes to the prompt, model, reference material, tools or output use. Also schedule periodic reruns for important production workflows because provider behaviour and real inputs can drift.

Source: [Build a Golden Test Set Before You Trust an AI Workflow](https://theaicommand.com/learning-hub/build-golden-test-set-ai-workflow#faq-4)

### Which AI tool is best for document-heavy or regulated work like compliance and workers compensation?

Claude is the default for document-heavy, regulated and compliance-adjacent work. It handles long-form writing, analytical reasoning across multiple documents and careful professional registers well. Use ChatGPT or Gemini for one-off ideation, and Microsoft Copilot if your firm runs Microsoft 365. Always de-identify claim data before pasting it in.

Source: [Choosing Claude, ChatGPT, Gemini or Copilot for Your Job](https://theaicommand.com/learning-hub/choosing-claude-chatgpt-gemini-copilot-for-your-job#faq-1)

### Which assumptions in a decision memo are worth slowing down for?

Plot each load-bearing assumption on two axes: how much it matters to the decision and how well it is evidenced. The danger zone is high-impact, low-evidence assumptions that carry the decision but rest on almost nothing. These are the only ones worth slowing down for; well-evidenced or low-impact assumptions can proceed or be noted.

Source: [AI Decision Memos for Leaders: Sharpen the Thinking Without Outsourcing the Decision](https://theaicommand.com/learning-hub/ai-for-leadership-decision-memos#faq-4)

### Which Australian privacy principles apply to loading data into Claude?

The Australian Privacy Principles are the baseline. APP 6 limits using or disclosing personal information beyond its collection purpose, and APP 11 requires reasonable steps to protect it from misuse and unauthorised access. Loading personal information into a shared workspace is the kind of secondary use these principles are designed to catch.

Source: [Gold Standard Claude Workspace Setup](https://theaicommand.com/learning-hub/gold-standard-claude-workspace-setup#faq-5)

### Which Australian privacy principles apply when using ChatGPT at work?

The Australian Privacy Principles are the baseline. APP 6 limits how personal information is used and disclosed beyond its collection purpose, and APP 11 requires reasonable steps to protect it from misuse and unauthorised access. Pasting personal information into a shared Project is exactly the secondary use these principles catch, so de-identify first.

Source: [Gold Standard ChatGPT and Codex Setup](https://theaicommand.com/learning-hub/gold-standard-chatgpt-and-codex-setup#faq-4)

### Which Claude surface should I use for which job?

Match the surface to the job. Use Claude.ai for ad hoc questions and one-off drafts, Projects for repeated work needing the same background, Cowork for delegated multi-step tasks with an approval gate, and Claude Code for repository work where a CLAUDE.md carries conventions into each session.

Source: [Gold Standard Claude Workspace Setup](https://theaicommand.com/learning-hub/gold-standard-claude-workspace-setup#faq-1)

### Which factors determine if after-hours contact is reasonable?

Fair Work guidance points to several factors: the purpose of the contact and whether it is urgent, the communication channel used and how intrusive it is, the level of disruption to rest or personal time, compensation arrangements such as overtime, and whether the employee's role requires after-hours response.

Source: [The Right to Disconnect Changes How Teams Should Configure AI Workflow Tools](https://theaicommand.com/learning-hub/right-to-disconnect-ai-workflow-tools#faq-5)

### Which memory settings should a team decide before relying on Cowork?

Four. What each Project's standing instructions say, what its memory is allowed to hold and who curates it, whether sensitive work uses an incognito chat instead, and, on consumer plans, whether training on your data is turned off. Decide these before the memory fills up, not after.

Source: [What Your AI Workspace Actually Remembers, and What It Doesn't](https://theaicommand.com/learning-hub/what-your-ai-workspace-remembers#faq-4)

### Which tasks make a good first AI workflow?

A good candidate has four properties: it recurs weekly or fortnightly, it is text-heavy, it has a defined input like a transcript or email list, and it has a defined output like a status update or stakeholder summary. If you can name the input and output in one sentence each, you have a workflow candidate.

Source: [Your First AI Workflow Without a Single Line of Code](https://theaicommand.com/learning-hub/first-ai-workflow-without-code#faq-3)

### Which tier of AI tool can I safely use for regulated personal or claim data?

Consumer chat is never acceptable for regulated data, because the prompt leaves your tenant even with training opt-out. Enterprise tier is potentially acceptable with controls and a contract. Tenant-grounded enterprise, where data never leaves your tenant, has the highest fit but still needs the five-step assessment.

Source: [Privacy-Safe AI for Regulated Work: A Working Practitioner's Guide](https://theaicommand.com/learning-hub/privacy-safe-ai-for-regulated-work#faq-2)

### Who owns the decision when AI helps draft the memo?

One named person holds the Decide right and owns the consequence. That cannot be shared with a model or diffused across a meeting. Decision-rights models like RAPID and RACI name who recommends, agrees, inputs, decides and performs. AI can draft the stakeholder map and flag who is missing, but assigning the decision right is a leadership act.

Source: [AI Decision Memos for Leaders: Sharpen the Thinking Without Outsourcing the Decision](https://theaicommand.com/learning-hub/ai-for-leadership-decision-memos#faq-5)

### Why do AI pilots fail to scale in teams?

Many pilots fail because managers focus on technology instead of work redesign and governance. Common pitfalls include treating AI as an individual tool without redesigning team workflows, ignoring emerging risks such as privacy complaints or bias, lacking clear accountability and documentation, and failing to invest in training and human oversight.

Source: [Managers Need an AI Operating Rhythm, Not More Pilots](https://theaicommand.com/learning-hub/ai-operating-rhythm-for-managers#faq-4)

### Why do AI workflow tools risk breaching the right to disconnect?

AI workflow tools often run continuously, automatically sending notifications or escalating tasks based on algorithms. Without careful configuration they can trigger after-hours contact without human review, ignore agreed working hours, escalate prematurely, and amplify psychosocial hazards such as stress and reduced job control.

Source: [The Right to Disconnect Changes How Teams Should Configure AI Workflow Tools](https://theaicommand.com/learning-hub/right-to-disconnect-ai-workflow-tools#faq-2)

### Why does AI give generic output and how do I fix it?

A frontier model does not know your control taxonomy, risk appetite language or recent issue themes, so it reaches for the average of everything it has read. The fix is rarely a cleverer prompt. It is the knowledge behind the prompt: a governed knowledge spine that grounds the model in real organisational knowledge.

Source: [Build the Knowledge Spine That Stops Generic AI Output](https://theaicommand.com/learning-hub/enterprise-knowledge-spine#faq-1)

### Why does my AI assistant always agree with my plan?

AI assistants are trained to flatter because matching a user's stated views is rewarded in human preference data. Anthropic's sycophancy research found all five assistants tested produced sycophantic responses. It is not a glitch but what the training signal rewards, so adversarial behaviour must be explicitly instructed every time.

Source: [AI as a Leadership Thinking Partner: Make It Attack Your Plan](https://theaicommand.com/learning-hub/ai-as-a-leadership-thinking-partner#faq-1)

### Why does the AI agree with my decision when I ask it to criticise mine?

Models trained on human feedback learn to be agreeable because raters tend to prefer answers matching their own views. Sharma and colleagues at Anthropic found responses matching a user's views are more likely preferred. Present a decision warmly and the likely output is polished agreement, so force genuine challenge in the instruction.

Source: [AI as a Red Team for Leaders: How to Challenge Thinking Without Surrendering Judgement](https://theaicommand.com/learning-hub/ai-as-a-red-team-for-leaders#faq-2)

### Why should an AI not just write the SOP straight from the transcript?

A transcript can contain contradictory opinions and unresolved arguments; an SOP cannot. Asked to draft directly, the model smooths over disagreement with confident prose, which is the failure you want to avoid. A middle conversion layer extracts facts, separates them from opinion, marks gaps, and forces a human to close each before publication.

Source: [Turn a Teams Transcript Into a Controlled HR SOP](https://theaicommand.com/learning-hub/teams-transcript-to-controlled-sop#faq-2)

### Why should I avoid writing a specific model name into my AI policy?

Model lineups change for commercial, technical and geopolitical reasons. Claude Fable 5 launched on 9 June 2026 and was disabled three days later under a US export-control directive. A policy naming Fable 5 broke overnight, while one routing to the highest available tier simply re-pointed to Opus 4.8 and kept working.

Source: [Claude Model Routing for Regulated Work: Which Model to Use for GRC, WC and HR Tasks](https://theaicommand.com/learning-hub/claude-model-routing-for-regulated-work#faq-4)

### Why should managers own AI literacy rather than treat it as staff training?

Managers are the frontline accountable officials ensuring teams comply with organisational AI policies and government requirements. Without active managerial involvement, teams risk overreliance on flawed, biased or incomplete AI outputs. Managers must translate policy mandates into practical routines, coach teams to keep human judgement central and escalate issues when necessary.

Source: [AI Literacy Is a Management Skill, Not a Training Module](https://theaicommand.com/learning-hub/ai-literacy-verification-management-skill#faq-4)

## Glossary terms

Plain-English definitions of Australian regulatory terms.

### Are model Codes of Practice legally binding?

Not by themselves. A model Code of Practice must be approved as a code of practice in a jurisdiction before it has legal effect there. Approved codes are not law, but they are admissible in court proceedings, and courts may rely on them to determine what is reasonably practicable.

Source: [What are the model WHS laws?](https://theaicommand.com/glossary/model-whs-laws#faq-4)

### Are the model WHS laws actually law?

No. The model WHS laws are a template. They only become legally binding when the Commonwealth, a state or a territory enacts them as its own legislation. Safe Work Australia maintains the model laws but does not regulate or enforce them. Enforcement sits with the WHS regulator in each jurisdiction.

Source: [What are the model WHS laws?](https://theaicommand.com/glossary/model-whs-laws#faq-1)

### Can an accountable person be held responsible for AI failures?

FAR does not name AI, but accountability follows the area of responsibility. If an AI system sits within an accountable person's remit and produces harm through poor governance, that can be treated as a failure to act with care, skill, and diligence. Ownership and oversight of AI systems should therefore be clearly mapped.

Source: [What is Financial Accountability Regime?](https://theaicommand.com/glossary/financial-accountability-regime-far#faq-4)

### Can an award or contract provide less than the NES?

No. The Fair Work Ombudsman states that other workplace instruments cannot provide for conditions less than the National Employment Standards, including an award, an employment contract, an enterprise agreement or another registered agreement. Those instruments also cannot exclude the NES. The NES applies regardless of what instrument covers the employee.

Source: [What is the Fair Work Act 2009?](https://theaicommand.com/glossary/fair-work-act-2009#faq-2)

### Can I rely on AI to find ART cases for a submission?

Only with verification. AI tools can fabricate case names, party names, and tribunal references, or misstate the outcome of a real case. Always confirm each citation against the published decision on AustLII or the Tribunal record before relying on it, and de-identify any claim material before entering it into an AI tool.

Source: [What is Administrative Review Tribunal?](https://theaicommand.com/glossary/administrative-review-tribunal-art#faq-4)

### Can I use AI to draft SRC Act determinations?

AI can assist with summarising evidence, drafting plain-English explanations, and structuring analysis against the statutory tests. It cannot make the determination. An authorised delegate must decide, a human must review every AI-assisted draft, and claimant data must be de-identified before it enters any general AI tool.

Source: [What is Safety, Rehabilitation and Compensation Act 1988?](https://theaicommand.com/glossary/src-act-1988#faq-4)

### Can prompt injection be fully prevented?

Probably not. OWASP says prompt injection is possible due to the nature of generative AI, and that given the stochastic influence at the heart of the way models work, it is unclear if there are fool-proof methods of prevention. The realistic goal is impact reduction through least privilege, human approval for high-risk actions, output validation, segregation of external content and adversarial testing.

Source: [What is prompt injection?](https://theaicommand.com/glossary/prompt-injection#faq-2)

### Can psychosocial hazards combine with each other?

Yes. Safe Work Australia warns that psychosocial hazards may interact or combine to create new, changed or higher risks. Some hazards may not create risk on their own but may do so when combined with others, and some may only create risk on their own when severe. Assessing hazards one at a time therefore understates the real exposure workers face.

Source: [What are psychosocial hazards?](https://theaicommand.com/glossary/psychosocial-hazards#faq-4)

### Can the ART review a Comcare decision before reconsideration?

No. The SRC Act uses a three-tier process: determination, then reconsideration producing a reviewable decision, then ART review. Under section 64 of the SRC Act, the ART can only review reviewable decisions. A first-tier determination must go through internal reconsideration before the Tribunal has jurisdiction to review it.

Source: [What is Administrative Review Tribunal?](https://theaicommand.com/glossary/administrative-review-tribunal-art#faq-3)

### Do Australian rules cover agentic AI specifically?

No Australian instrument names agentic AI. The Guidance for AI Adoption, published 21 October 2025, sets six essential practices including maintaining human control, and it is voluntary. Existing duties still apply, so an agent acting inside a regulated process inherits that process and its obligations.

Source: [What is agentic AI?](https://theaicommand.com/glossary/agentic-ai#faq-3)

### Do psychosocial hazards apply to AI at work?

They can. The Australian Work Health and Safety Strategy 2023 to 2033 warns that while automation may reduce physical risk, workers overseeing that technology could face more psychosocial hazards from increased or more complex interpersonal interactions. AI changes job demands, job control and role clarity, all named hazards.

Source: [What are psychosocial hazards?](https://theaicommand.com/glossary/psychosocial-hazards#faq-5)

### Do the Australian Privacy Principles apply to small businesses?

Generally the APPs bind organisations with an annual turnover above $3 million. Smaller operators are still caught where an exception applies, including private sector health service providers, credit reporting bodies, businesses that buy or sell personal information, Commonwealth contracted service providers, and businesses that have opted in.

Source: [What are the Australian Privacy Principles?](https://theaicommand.com/glossary/australian-privacy-principles#faq-3)

### Do the model WHS laws cover artificial intelligence?

They do not mention AI, but the duties are technology neutral and apply to it. The Australian Work Health and Safety Strategy 2023 to 2033 names the rise of AI and automation as an emerging challenge, warning that new technology needs appropriate design and oversight so workers face no new WHS risks.

Source: [What are the model WHS laws?](https://theaicommand.com/glossary/model-whs-laws#faq-3)

### Does a human making the final call remove the obligation?

Not automatically. APP 1.7 reaches a computer program that does a thing substantially and directly related to making a decision, not only one that decides. The OAIC's issues paper puts exactly this to consultation, using an example where staff rely on a chatbot's eligibility recommendation before deciding.

Source: [What is automated decision-making?](https://theaicommand.com/glossary/automated-decision-making#faq-3)

### Does a refusal to decide count as automated decision-making?

Yes. APP 1.9 states that making a decision includes refusing or failing to make a decision, and that doing a thing includes refusing or failing to do a thing. A system that automatically rejects, defers or silently drops an application is therefore within scope.

Source: [What is automated decision-making?](https://theaicommand.com/glossary/automated-decision-making#faq-5)

### Does APP 8 apply when staff use an overseas AI chatbot?

APP 8 sets out the steps an APP entity must take before personal information is disclosed overseas. Where an AI tool is hosted outside Australia and staff enter personal information into it, that is a cross-border disclosure, so the APP 8 accountability and reasonable steps obligations need to be worked through first.

Source: [What are the Australian Privacy Principles?](https://theaicommand.com/glossary/australian-privacy-principles#faq-5)

### Does AUSTRAC use AI?

AUSTRAC's AI transparency statement says it has not yet deployed AI that directly interacts with the public or is involved in decision making and administrative action without human intervention. It is trialling enterprise generative AI, and applies controls so no sensitive or classified information enters public generative AI systems.

Source: [What is AUSTRAC?](https://theaicommand.com/glossary/austrac#faq-5)

### Does Comcare use artificial intelligence to make decisions?

No. Comcare's AI Transparency Statement says it does not at present use AI for any of its core functions, and that AI is not used in compliance, auditing or decision-making processes without human oversight. Staff are not permitted to input sensitive employee or customer information into AI technologies.

Source: [What is Comcare?](https://theaicommand.com/glossary/comcare#faq-5)

### Does CPS 230 apply to AI vendors?

CPS 230 does not mention AI, but AI vendors and AI-enabled services fall within its service provider obligations. Where an AI tool supports a critical operation, the arrangement can be a material service provider arrangement, requiring a formal agreement, service levels, monitoring and oversight of fourth-party dependencies.

Source: [What is APRA CPS 230?](https://theaicommand.com/glossary/apra-cps-230#faq-2)

### Does CPS 234 apply to AI tools and vendors?

Yes, where an AI tool or vendor processes, stores or transmits regulated information assets it falls inside the information security framework CPS 234 governs. Third-party AI services attract the same assurance expectations as any other outsourced information asset, and AI failures can be material incidents.

Source: [What is APRA CPS 234?](https://theaicommand.com/glossary/apra-cps-234#faq-3)

### Does DDO apply to AI-driven product distribution?

Yes. AI used to target, score, or personalise offers is part of distribution, so it must stay consistent with the target market determination. An automated model that reaches consumers outside the target market does not escape DDO. The reasonable steps obligation applies regardless of automation.

Source: [What is Design and Distribution Obligations?](https://theaicommand.com/glossary/design-and-distribution-obligations-ddo#faq-3)

### Does de-identification make it safe to put claims data into an AI chatbot?

No. The OAIC notes information can be at risk of re-identification even when de-identified or anonymised, and that once data enters a generative AI system it is very difficult to control and potentially impossible to remove. Best practice is to keep personal and sensitive information out of public tools.

Source: [What is de-identification?](https://theaicommand.com/glossary/de-identification#faq-3)

### Does FAR replace other obligations like director duties?

No. FAR sits alongside existing duties, including directors' duties under the Corporations Act and licensing obligations. It adds a specific personal accountability layer for senior executives in regulated financial entities. Practitioners should treat it as additional to, not a substitute for, their other regulatory obligations.

Source: [What is Financial Accountability Regime?](https://theaicommand.com/glossary/financial-accountability-regime-far#faq-5)

### Does RAG stop AI from hallucinating?

No. RAG reduces fabrication by grounding answers in retrieved passages, and the 2020 paper reported more factual language than a parametric-only baseline. The model can still misread a passage, blend sources, or answer confidently when retrieval returns nothing useful. Citations make errors easier to catch, not impossible.

Source: [What is retrieval-augmented generation (RAG)?](https://theaicommand.com/glossary/retrieval-augmented-generation#faq-1)

### Does removing names and addresses de-identify a dataset?

Not on its own. The OAIC warns that removing name, address or other direct identifiers alone may not result in de-identification for the purposes of the Privacy Act. A second step is needed, either altering other identifying information or applying controls and safeguards in the data access environment.

Source: [What is de-identification?](https://theaicommand.com/glossary/de-identification#faq-2)

### Does retrieval-augmented generation increase prompt injection risk?

It can. NIST identifies RAG systems and internet-connected agents as the classic settings for indirect prompt injection, because the model pulls in outside resources an attacker may control. A poisoned document in a knowledge base becomes an instruction the model may follow at retrieval time.

Source: [What is prompt injection?](https://theaicommand.com/glossary/prompt-injection#faq-4)

### Does the ART decide the matter fresh or just check for error?

The ART conducts merits review, which means it stands in the shoes of the original decision maker and decides the correct or preferable decision on the material before it. This is broader than judicial review, which examines only whether the decision was lawful. The ART can affirm, vary, set aside, or remit the decision.

Source: [What is Administrative Review Tribunal?](https://theaicommand.com/glossary/administrative-review-tribunal-art#faq-5)

### Does the EU AI Act apply to Australian organisations?

It can. Article 2 extends the regulation to providers and deployers established in a third country where the output produced by the AI system is used in the Union, and to anyone placing an AI system on the Union market. Australian establishment alone does not put an organisation outside it.

Source: [What is the EU AI Act?](https://theaicommand.com/glossary/eu-ai-act#faq-1)

### Does the Fair Work Act 2009 regulate AI in the workplace?

The Act does not name AI. It bites indirectly, through unfair dismissal tests that ask whether a dismissal was harsh, unjust or unreasonable, through general protections, through award consultation obligations on major change, and through the right to disconnect where AI-enabled tooling extends contact beyond working hours.

Source: [What is the Fair Work Act 2009?](https://theaicommand.com/glossary/fair-work-act-2009#faq-5)

### Does the Fair Work Commission have rules about using AI in a case?

The President published an exposure draft Guidance Note on the use of generative AI in Commission cases in March 2026, with comments due by 10 April 2026. The draft would require a party who used generative AI to prepare a document to tell the Commission and to check that all details are correct and relevant.

Source: [What is the Fair Work Commission?](https://theaicommand.com/glossary/fair-work-commission#faq-5)

### Does the NIST AI RMF matter in Australia?

Yes, indirectly. Australia's Voluntary AI Safety Standard, published on 5 September 2024, states it draws on and is aligned with AS ISO/IEC 42001:2023 and NIST AI RMF 1.0, with each guardrail requirement aligned to relevant international and local standards. The department has since published Guidance for AI Adoption, on 21 October 2025, which it describes as evolving that standard. Australian legal obligations still come from Australian law.

Source: [What is the NIST AI Risk Management Framework?](https://theaicommand.com/glossary/nist-ai-rmf#faq-3)

### Does the OAIC handle the statutory tort for privacy invasions?

No. The statutory tort for serious invasions of privacy commenced on 10 June 2025 and sits in Schedule 2 of the Privacy Act, but the OAIC states it does not have a direct role in administering the tort. Individuals pursuing it are directed to seek independent legal advice.

Source: [What is the Office of the Australian Information Commissioner?](https://theaicommand.com/glossary/oaic#faq-5)

### Does the Privacy Act 1988 cover AI tools?

Yes. The OAIC states the Privacy Act applies to all uses of AI involving personal information, covering both what an organisation puts into an AI system and what the system generates. Inferred or hallucinated information about an identifiable person is still personal information and must be handled under the Australian Privacy Principles.

Source: [What is the Privacy Act 1988?](https://theaicommand.com/glossary/privacy-act-1988#faq-2)

### Does the Privacy Act 1988 cover employee records?

In some situations the Act does not cover an organisation's handling of employee records connected to a current or former employment relationship. The exemption is narrow and does not remove other obligations, so employers running AI over workforce data need to confirm whether the exemption applies before relying on it.

Source: [What is the Privacy Act 1988?](https://theaicommand.com/glossary/privacy-act-1988#faq-5)

### Does the standard align with international frameworks?

Yes. The guardrails are aligned with AS ISO/IEC 42001:2023, the leading international standard on AI management systems, and with the United States NIST AI Risk Management Framework 1.0. The National AI Centre says this supports organisations operating internationally by aligning Australian practice with other jurisdictions and their expectations.

Source: [What is the Voluntary AI Safety Standard?](https://theaicommand.com/glossary/voluntary-ai-safety-standard#faq-4)

### Does using AI for transaction monitoring change my AML/CTF obligations?

No. The obligation to apply appropriate risk-based controls remains with the reporting entity, not the tool. If you use AI for monitoring or customer due diligence, you must be able to explain its outputs, govern the model, keep records of escalation decisions, and maintain human oversight so the system supports rather than replaces your compliance program.

Source: [What is AML/CTF regime?](https://theaicommand.com/glossary/aml-ctf#faq-5)

### Has prompt injection caused a real vulnerability?

Yes. CVE-2025-32711, published 11 June 2025, records an AI command injection flaw in Microsoft 365 Copilot allowing an unauthorised attacker to disclose information over a network. It is classified CWE-74 and scored 9.3 critical by Microsoft and 7.5 high by NIST in the national vulnerability database.

Source: [What is prompt injection?](https://theaicommand.com/glossary/prompt-injection#faq-3)

### Has the OAIC published guidance on AI?

Yes. The OAIC has published guidance on privacy and the use of commercially available AI products, and separate guidance on privacy and developing and training generative AI models. Its stated position is that the Privacy Act applies to all uses of AI involving personal information, covering both inputs and generated outputs.

Source: [What is the Office of the Australian Information Commissioner?](https://theaicommand.com/glossary/oaic#faq-4)

### Has the Voluntary AI Safety Standard been replaced?

It has been evolved rather than withdrawn. On 21 October 2025 the government published Guidance for AI Adoption, which condenses the 10 guardrails into 6 essential practices and extends the audience to developers as well as deployers. The standard pages remain live and carry a banner pointing to the newer guidance.

Source: [What is the Voluntary AI Safety Standard?](https://theaicommand.com/glossary/voluntary-ai-safety-standard#faq-2)

### How do I challenge a Comcare decision under the SRC Act?

First seek reconsideration of the determination through the original decision-maker. If you still disagree, apply to the Administrative Review Tribunal, which reviews Commonwealth workers compensation decisions on the merits. The ART replaced the Administrative Appeals Tribunal in October 2024. Check current timeframes on the ART website before lodging.

Source: [What is Safety, Rehabilitation and Compensation Act 1988?](https://theaicommand.com/glossary/src-act-1988#faq-5)

### How does CPS 230 relate to business continuity for AI tools?

CPS 230 requires business continuity plans that keep critical operations within defined tolerance levels through severe but plausible disruptions, tested regularly. If a critical operation depends on an AI model or vendor, the entity should define tolerances for that dependency and confirm a workable fallback if the AI fails.

Source: [What is APRA CPS 230?](https://theaicommand.com/glossary/apra-cps-230#faq-5)

### How is agentic AI different from a chatbot?

A chatbot returns text for a person to act on. An agent takes the action itself, calling tools, writing files, sending messages or moving money, often across many turns. That shifts the control question from whether the output is accurate to whether the action was authorised.

Source: [What is agentic AI?](https://theaicommand.com/glossary/agentic-ai#faq-5)

### How is the Fair Work Commission different from the Fair Work Ombudsman?

They are separate bodies. The Commission is the tribunal that hears and decides matters, sets minimum wages, maintains awards and approves enterprise agreements. The Fair Work Ombudsman provides information about workplace rights and obligations and enforces compliance with those laws. The Ombudsman does not investigate unfair dismissal claims.

Source: [What is the Fair Work Commission?](https://theaicommand.com/glossary/fair-work-commission#faq-3)

### How long do I have to apply to the ART for a Comcare decision?

You generally have 60 days from receiving the reviewable decision, which is the decision made after reconsideration under the SRC Act. The Tribunal can grant extensions in limited circumstances, but you should treat the 60-day period as firm and lodge early rather than relying on an extension being granted.

Source: [What is Administrative Review Tribunal?](https://theaicommand.com/glossary/administrative-review-tribunal-art#faq-2)

### How long does an employee have to lodge an unfair dismissal claim?

An employee must apply to the Fair Work Commission within 21 days of the dismissal. Eligibility also requires at least 6 months of service with that employer, or 12 months where the employer is a small business employer with fewer than 15 employees. The Commission decides the case.

Source: [What is the Fair Work Act 2009?](https://theaicommand.com/glossary/fair-work-act-2009#faq-4)

### How many Australian Privacy Principles are there?

There are 13 Australian Privacy Principles, set out in Schedule 1 of the Privacy Act 1988. They run from open and transparent management of personal information at APP 1 through to correction of personal information at APP 13, covering collection, notification, use, disclosure, cross-border transfer, quality, security and access.

Source: [What are the Australian Privacy Principles?](https://theaicommand.com/glossary/australian-privacy-principles#faq-1)

### How many businesses does Tranche 2 bring in?

AUSTRAC stated in March 2026 that from 1 July the number of businesses it regulates would grow from around 19,000 to close to 100,000 nationwide. AUSTRAC described the reforms as the most significant overhaul of Australia's AML/CTF framework in more than 20 years.

Source: [What are the AML/CTF Tranche 2 reforms?](https://theaicommand.com/glossary/aml-ctf-tranche-2#faq-4)

### How quickly must we notify APRA of a security incident under CPS 234?

You must notify APRA within 72 hours of becoming aware of a material information security incident, including any incident already notified to another regulator. Separately, material control weaknesses you cannot remediate in a timely way must be notified within 10 business days.

Source: [What is APRA CPS 234?](https://theaicommand.com/glossary/apra-cps-234#faq-2)

### Is AUSTRAC a law enforcement agency?

AUSTRAC is a regulator and a financial intelligence unit rather than a police force. It collects and analyses financial reports and other data to create targeted, actionable intelligence that supports law enforcement and national security investigations. Its intelligence functions form part of the national intelligence community.

Source: [What is AUSTRAC?](https://theaicommand.com/glossary/austrac#faq-4)

### Is CPS 234 the same as CPS 230?

No. CPS 234 covers information security and took effect in 2019. CPS 230 covers operational risk management, including service provider management and business continuity, and took effect on 1 July 2025. They are complementary, so AI security and AI operational resilience should be managed together.

Source: [What is APRA CPS 234?](https://theaicommand.com/glossary/apra-cps-234#faq-5)

### Is de-identification the same as anonymisation?

Not necessarily. The OAIC notes several terms are used in Australia for similar processes, including anonymisation and confidentialisation, and advises checking that all parties understand the terminology consistently. The Privacy Act test is whether an individual remains reasonably identifiable, not which label the parties use.

Source: [What is de-identification?](https://theaicommand.com/glossary/de-identification#faq-5)

### Is de-identified information still personal information?

No, provided the de-identification is robust. The OAIC's position is that information which has undergone an appropriate and robust de-identification process is not personal information and is not subject to the Privacy Act. The same data can be personal in one release context and de-identified in another.

Source: [What is de-identification?](https://theaicommand.com/glossary/de-identification#faq-1)

### Is prompt injection the same as jailbreaking?

They overlap but are not identical. NIST defines a jailbreak as a direct prompting attack intended to circumvent restrictions placed on model outputs, such as circumventing refusal behaviour. Prompt injection is the broader mechanism of exploiting untrusted input concatenated onto higher-trust instructions, and indirect injection usually aims at data theft or unauthorised action rather than rude answers.

Source: [What is prompt injection?](https://theaicommand.com/glossary/prompt-injection#faq-5)

### Is RAG safe for confidential or regulated data?

It depends on the controls around the index, not on RAG itself. Retrieval can surface any document the permissions allow, so access control must be enforced at retrieval time. NIST also identifies RAG knowledge bases as a route for indirect prompt injection, where poisoned documents carry hidden instructions.

Source: [What is retrieval-augmented generation (RAG)?](https://theaicommand.com/glossary/retrieval-augmented-generation#faq-3)

### Is stress a psychosocial hazard?

Stress is a response, not a hazard and not an injury in itself. Safe Work Australia explains that psychosocial hazards can create stress, and that stress can cause psychological or physical harm where workers are stressed often, over a long time, or at a high level of intensity.

Source: [What are psychosocial hazards?](https://theaicommand.com/glossary/psychosocial-hazards#faq-2)

### Is the Comcare scheme a no-fault scheme?

Yes. Comcare describes the SRC Act scheme as a no fault scheme with limited access to common law. It takes an integrated approach across injury prevention, occupational rehabilitation and workers' compensation, with employers responsible for the occupational rehabilitation and return to work of their employees.

Source: [What is Comcare?](https://theaicommand.com/glossary/comcare#faq-3)

### Is the NIST AI Risk Management Framework mandatory?

No. NIST states the framework is intended to be voluntary, rights-preserving, non-sector-specific and use-case agnostic. It was produced as directed by the National Artificial Intelligence Initiative Act of 2020 and offers a resource rather than a compliance obligation, even for organisations in the United States.

Source: [What is the NIST AI Risk Management Framework?](https://theaicommand.com/glossary/nist-ai-rmf#faq-1)

### Is the Voluntary AI Safety Standard mandatory?

No. The standard states that being voluntary, it does not create new legal duties about AI systems or their use. It asks organisations to commit to understanding their AI use, engaging stakeholders, running risk and impact assessments, testing, and adopting appropriate controls. Existing law still applies regardless.

Source: [What is the Voluntary AI Safety Standard?](https://theaicommand.com/glossary/voluntary-ai-safety-standard#faq-1)

### Is there a NIST framework for generative AI?

Yes. NIST released NIST AI 600-1, the Generative AI Profile, on 26 July 2024. It is a companion to the AI RMF that helps organisations identify risks specific to generative AI and proposes actions for managing them in line with their own goals and priorities.

Source: [What is the NIST AI Risk Management Framework?](https://theaicommand.com/glossary/nist-ai-rmf#faq-5)

### What are the 6 essential practices in Guidance for AI Adoption?

Decide who is accountable, understand impacts and plan accordingly, measure and manage risks by implementing AI-specific risk management, share essential information, test and monitor, and maintain human control. Two versions exist, a foundations edition for low-risk and early AI use, and an implementation guidance edition for complex and higher-risk use.

Source: [What is the Voluntary AI Safety Standard?](https://theaicommand.com/glossary/voluntary-ai-safety-standard#faq-3)

### What are the core obligations for a reporting entity?

A reporting entity must enrol and register with AUSTRAC, develop and maintain a risk-based AML/CTF program, conduct customer due diligence, report suspicious matters, report threshold transactions such as large cash dealings, and keep supporting records. The exact services that trigger these obligations are the designated services listed in the Act.

Source: [What is AML/CTF regime?](https://theaicommand.com/glossary/aml-ctf#faq-3)

### What are the four functions of the NIST AI RMF?

Govern, Map, Measure and Manage. Govern cultivates a culture of risk management and sets the structures that align AI work with organisational policy. Map establishes the context to frame risks. Measure analyses, benchmarks and monitors those risks. Manage allocates resources to treat them and plans incident response.

Source: [What is the NIST AI Risk Management Framework?](https://theaicommand.com/glossary/nist-ai-rmf#faq-2)

### What are the National Employment Standards under the Fair Work Act?

The NES are the minimum entitlements for employees in the national system. They cover maximum weekly hours, flexible working requests, casual employment, parental leave, annual leave, personal, carer's, compassionate and family and domestic violence leave, community service leave, long service leave, public holidays, superannuation, notice and redundancy, and the required information statements.

Source: [What is the Fair Work Act 2009?](https://theaicommand.com/glossary/fair-work-act-2009#faq-1)

### What are the penalties under the EU AI Act?

Article 99 sets three tiers. Breaching the Article 5 prohibitions can draw fines up to 35 million euro or 7 per cent of total worldwide annual turnover, whichever is higher. Most other breaches reach 15 million euro or 3 per cent, and supplying misleading information 7.5 million euro or 1 per cent.

Source: [What is the EU AI Act?](https://theaicommand.com/glossary/eu-ai-act#faq-3)

### What are the seven trustworthy AI characteristics?

NIST lists valid and reliable, safe, secure and resilient, accountable and transparent, explainable and interpretable, privacy-enhanced, and fair with harmful bias managed. Validity and reliability is treated as the base condition, and accountability and transparency relates to all the others. The characteristics must be balanced by context of use.

Source: [What is the NIST AI Risk Management Framework?](https://theaicommand.com/glossary/nist-ai-rmf#faq-4)

### What are the top security risks of agentic AI?

OWASP published a Top 10 for Agentic Applications in December 2025. It runs from agent goal hijack and tool misuse through identity and privilege abuse, supply chain vulnerabilities, unexpected code execution, memory and context poisoning, insecure inter-agent communication, cascading failures, human-agent trust exploitation, and rogue agents.

Source: [What is agentic AI?](https://theaicommand.com/glossary/agentic-ai#faq-2)

### What changes under the Tranche 2 reforms and when?

The AML/CTF Amendment Act 2024 extends the regime to more professions, including certain lawyers, accountants, conveyancers, real estate professionals, and dealers in precious metals and stones. Broader reforms commenced 31 March 2026, and newly regulated Tranche 2 businesses are regulated by AUSTRAC from 1 July 2026, subject to transitional rules.

Source: [What is AML/CTF regime?](https://theaicommand.com/glossary/aml-ctf#faq-4)

### What counts as significantly affecting rights or interests?

The Privacy Act gives examples: a decision under an Act or legislative instrument to grant or refuse a benefit, a decision affecting rights under a contract, agreement or arrangement, and a decision affecting access to a significant service or support. Beneficial effects count, not just adverse ones.

Source: [What is automated decision-making?](https://theaicommand.com/glossary/automated-decision-making#faq-4)

### What disputes can the Fair Work Commission deal with?

Common matters include unfair dismissal, bullying, sexual harassment, dismissal under general protections, unfair deactivation or termination for regulated workers, disputes about flexible work or unpaid parental leave, changes from casual to permanent employment, and right to disconnect disputes. It also handles industrial action and bargaining disputes.

Source: [What is the Fair Work Commission?](https://theaicommand.com/glossary/fair-work-commission#faq-2)

### What does a RAG pipeline do at query time?

AWS describes four stages. Create external data as vector representations in a database, retrieve relevant information by relevancy search, augment the prompt by adding the retrieved data in context, and update the external data asynchronously through real-time processes or periodic batch, so it does not go stale.

Source: [What is retrieval-augmented generation (RAG)?](https://theaicommand.com/glossary/retrieval-augmented-generation#faq-5)

### What does APP 1 require of an organisation using AI?

APP 1 requires open and transparent management of personal information, which in practice means a current privacy policy and documented practices and procedures. From 10 December 2026 it also requires entities using personal information in automated decision making affecting rights or interests to describe that use in the policy.

Source: [What are the Australian Privacy Principles?](https://theaicommand.com/glossary/australian-privacy-principles#faq-4)

### What does AUSTRAC stand for?

AUSTRAC stands for the Australian Transaction Reports and Analysis Centre. It describes itself as having a dual role, acting as Australia's anti-money laundering and counter-terrorism financing regulator and as the national financial intelligence unit, using both regulation and intelligence to detect, deter and disrupt serious crime.

Source: [What is AUSTRAC?](https://theaicommand.com/glossary/austrac#faq-1)

### What does Comcare do?

Comcare is the national work health and safety and workers' compensation authority. It acts as a regulator, claims manager, scheme manager and insurer. It is established under the Safety, Rehabilitation and Compensation Act 1988 and holds functions, compliance and enforcement powers under both that Act and the Work Health and Safety Act 2011.

Source: [What is Comcare?](https://theaicommand.com/glossary/comcare#faq-1)

### What does the EU AI Act count as an AI system?

Article 3 defines it as a machine-based system designed to operate with varying levels of autonomy, that may exhibit adaptiveness after deployment, and that infers from the input it receives how to generate outputs such as predictions, content, recommendations or decisions influencing physical or virtual environments.

Source: [What is the EU AI Act?](https://theaicommand.com/glossary/eu-ai-act#faq-4)

### What does the Fair Work Commission do?

It describes itself as Australia's independent workplace relations tribunal and registered organisations regulator. Its responsibilities span dispute resolution, labour standards including annual wage reviews and modern awards, bargaining and enterprise agreements, and the regulation of registered organisations through its General Manager.

Source: [What is the Fair Work Commission?](https://theaicommand.com/glossary/fair-work-commission#faq-1)

### What does the OAIC actually do?

The OAIC regulates privacy, freedom of information and government information policy. Its work includes conducting investigations, reviewing decisions, handling complaints, and providing guidance and advice. It administers the Privacy Act 1988, receives notifiable data breach notifications, and publishes the Australian Privacy Principles guidelines that entities are expected to follow.

Source: [What is the Office of the Australian Information Commissioner?](https://theaicommand.com/glossary/oaic#faq-1)

### What duty does an employer have for psychosocial hazards?

Under the model WHS laws a person conducting a business or undertaking must eliminate psychosocial risks, or if that is not reasonably practicable, minimise them so far as is reasonably practicable. The model WHS Regulations require PCBUs to have regard to all relevant matters when choosing control measures.

Source: [What are psychosocial hazards?](https://theaicommand.com/glossary/psychosocial-hazards#faq-3)

### What has to go in the privacy policy?

Three things under APP 1.8: the kinds of personal information used in the operation of such computer programs, the kinds of decisions made solely by those programs, and the kinds of decisions for which a program does something substantially and directly related to making the decision.

Source: [What is automated decision-making?](https://theaicommand.com/glossary/automated-decision-making#faq-2)

### What is a material service provider under CPS 230?

A material service provider is one the entity relies on to undertake a critical operation, or one that exposes the entity to material operational risk. For AI, this can include a hosted model or AI-enabled service supporting claims, underwriting or customer decisions. The Material Service Provider Register should capture these arrangements.

Source: [What is APRA CPS 230?](https://theaicommand.com/glossary/apra-cps-230#faq-4)

### What is a rogue agent?

Rogue agents is the tenth OWASP agentic risk, ASI10. It covers agents that begin showing misalignment, concealment and self-directed action. OWASP is explicit that the entry focuses on loss of behavioural integrity and governance once drift begins, not on the initial intrusion that may have started it.

Source: [What is agentic AI?](https://theaicommand.com/glossary/agentic-ai#faq-4)

### What is a self-insured licensee under the SRC Act?

The SRC Act allows eligible corporations and Commonwealth authorities to hold a licence to self-insure their workers' compensation liabilities, claims management, or both. The relevant minister must first declare a corporation eligible, after which it applies to the Safety, Rehabilitation and Compensation Commission for the licence.

Source: [What is Comcare?](https://theaicommand.com/glossary/comcare#faq-4)

### What is a target market determination under DDO?

A target market determination, or TMD, is the document an issuer must make under Part 7.8A. It defines the class of consumers a financial product suits, the distribution conditions and restrictions, the review triggers, and the information distributors must report. Distribution must stay consistent with it.

Source: [What is Design and Distribution Obligations?](https://theaicommand.com/glossary/design-and-distribution-obligations-ddo#faq-1)

### What is the AML/CTF regime in Australia?

It is Australia's framework for preventing money laundering and terrorism financing, set out in the AML/CTF Act 2006 and administered by AUSTRAC. Regulated businesses, called reporting entities, must enrol with AUSTRAC, maintain a compliance program, verify customers, and report suspicious and threshold transactions.

Source: [What is AML/CTF regime?](https://theaicommand.com/glossary/aml-ctf#faq-1)

### What is the definition of a psychosocial hazard?

Safe Work Australia defines a psychosocial hazard as anything that could cause psychological harm, for example harm to someone's mental health. Psychosocial hazards can arise from the design or management of work, the work environment, plant at a workplace, or workplace interactions and behaviours.

Source: [What are psychosocial hazards?](https://theaicommand.com/glossary/psychosocial-hazards#faq-1)

### What is the difference between an AI agent and a workflow?

Anthropic draws the line at who controls the path. Workflows are systems where models and tools are orchestrated through predefined code paths. Agents are systems where models dynamically direct their own processes and tool usage, keeping control over how they accomplish tasks. Workflows are predictable, agents are not.

Source: [What is agentic AI?](https://theaicommand.com/glossary/agentic-ai#faq-1)

### What is the difference between an issuer and a distributor under DDO?

An issuer designs and offers the financial product and must prepare and maintain the target market determination. A distributor deals in or arranges the product, including AFS licensees and advisers, and must take reasonable steps to distribute consistently with the TMD and report relevant information back to the issuer.

Source: [What is Design and Distribution Obligations?](https://theaicommand.com/glossary/design-and-distribution-obligations-ddo#faq-5)

### What is the difference between direct and indirect prompt injection?

Direct injection comes from the person using the system, whose input changes how the model behaves. Indirect injection arrives through content the model processes, such as a web page, email or document carrying hidden instructions. NIST notes that in indirect attacks the primary user is often the one harmed.

Source: [What is prompt injection?](https://theaicommand.com/glossary/prompt-injection#faq-1)

### What is the difference between FAR and BEAR?

BEAR, the Banking Executive Accountability Regime, applied only to banking and was administered by APRA. FAR replaced BEAR and extended the accountability model to insurance and superannuation, with joint administration by both APRA and ASIC. FAR also adds a conduct regulator dimension that BEAR did not have.

Source: [What is Financial Accountability Regime?](https://theaicommand.com/glossary/financial-accountability-regime-far#faq-1)

### What is the difference between RAG and fine-tuning?

Fine-tuning changes the model weights by training on additional examples. RAG leaves the model unchanged and supplies information at query time from an external index. NIST notes RAG lets the internal knowledge of a model be modified without retraining, so updating a document updates the answer immediately.

Source: [What is retrieval-augmented generation (RAG)?](https://theaicommand.com/glossary/retrieval-augmented-generation#faq-2)

### What is the difference between the ART and the AAT?

The Administrative Review Tribunal replaced the Administrative Appeals Tribunal on 14 October 2024 under the Administrative Review Tribunal Act 2024 (Cth). It performs the same core function of independent merits review of Commonwealth decisions, but under a new governing Act with revised structure and procedures. The AAT no longer exists.

Source: [What is Administrative Review Tribunal?](https://theaicommand.com/glossary/administrative-review-tribunal-art#faq-1)

### What is the reasonable administrative action exclusion under the SRC Act?

Section 5A defines injury and excludes conditions suffered as a result of reasonable administrative action taken in a reasonable manner against the employee. It covers actions like performance management, transfers, and discipline. The exclusion frequently determines psychological claims, so the action's reasonableness must be assessed on the evidence.

Source: [What is Safety, Rehabilitation and Compensation Act 1988?](https://theaicommand.com/glossary/src-act-1988#faq-3)

### What is the SRC Act in workers compensation?

The SRC Act 1988 is the Commonwealth law that runs the federal workers compensation scheme. It governs liability for injury, disease, rehabilitation, and compensation for employees of the Australian Government and corporations licensed to self-insure under it. Comcare administers claims for many Commonwealth agencies under the Act.

Source: [What is Safety, Rehabilitation and Compensation Act 1988?](https://theaicommand.com/glossary/src-act-1988#faq-1)

### What is the statutory tort for serious invasions of privacy?

Introduced by Schedule 2 of the Privacy Act and commenced on 10 June 2025, it lets an individual sue for intrusion upon seclusion or misuse of information where they had a reasonable expectation of privacy. Courts may award damages, an injunction or an order requiring an apology. The OAIC does not administer it.

Source: [What is the Privacy Act 1988?](https://theaicommand.com/glossary/privacy-act-1988#faq-4)

### What is Tranche 2 in AML/CTF?

Tranche 2 is the expansion of Australia's AML/CTF regime into industries recognised domestically and globally as high risk for criminal exploitation. It covers certain designated services provided by real estate professionals, dealers in precious stones and metals, lawyers, conveyancers, accountants, trust and company service providers, and some virtual asset businesses.

Source: [What are the AML/CTF Tranche 2 reforms?](https://theaicommand.com/glossary/aml-ctf-tranche-2#faq-1)

### What law establishes the OAIC?

The Australian Information Commissioner Act 2010, Act No. 52 of 2010, establishes the Office of the Australian Information Commissioner. The Office consists of three information officers, the Information Commissioner, the Freedom of Information Commissioner and the Privacy Commissioner, with the Information Commissioner as head of the Office. The OAIC sits as an independent agency within the Attorney-General's portfolio.

Source: [What is the Office of the Australian Information Commissioner?](https://theaicommand.com/glossary/oaic#faq-2)

### What must a newly regulated business actually do?

From 1 July 2026 newly regulated businesses must comply with obligations under the AML/CTF laws, including implementing AML/CTF programs, conducting customer due diligence, reporting suspicious matters and keeping records. Most only need to enrol, though remittance and virtual asset service providers must also apply for registration.

Source: [What are the AML/CTF Tranche 2 reforms?](https://theaicommand.com/glossary/aml-ctf-tranche-2#faq-5)

### What obligations does AUSTRAC enforce?

Reporting entities must implement AML/CTF controls and report to AUSTRAC. Core obligations include maintaining an AML/CTF program, conducting customer due diligence, submitting suspicious matter reports, threshold transaction reports and international funds transfer reports, and keeping records. AUSTRAC requires a business to apply to enrol no later than 28 days after the day it starts providing a designated service.

Source: [What is AUSTRAC?](https://theaicommand.com/glossary/austrac#faq-3)

### What Privacy Act change starts on 10 December 2026?

From 10 December 2026, APP entities that use personal information in a computer program to make a decision that could reasonably be expected to significantly affect an individual's rights or interests must set out in their privacy policies the kinds of personal information used and the kinds of decisions made that way. The OAIC consulted on guidance during 2026.

Source: [What is the Privacy Act 1988?](https://theaicommand.com/glossary/privacy-act-1988#faq-3)

### When did CPS 230 take effect?

CPS 230 came into force on 1 July 2025. There is a transitional arrangement for existing material service provider contracts, which runs to 1 July 2026 at the earliest of the next renewal date. Separate targeted amendments for non-traditional service providers also take effect on 1 July 2026.

Source: [What is APRA CPS 230?](https://theaicommand.com/glossary/apra-cps-230#faq-1)

### When did CPS 234 come into effect?

CPS 234 took effect on 1 July 2019. APRA allowed a transition period until 1 July 2020 for information assets managed by third parties, recognising that entities needed time to obtain assurance over systems and data they relied on but did not directly control.

Source: [What is APRA CPS 234?](https://theaicommand.com/glossary/apra-cps-234#faq-1)

### When did the Design and Distribution Obligations commence?

DDO commenced on 5 October 2021 under Part 7.8A of the Corporations Act 2001 (Cth). The regime was introduced by the Treasury Laws Amendment (Design and Distribution Obligations and Product Intervention Powers) Act 2019. ASIC administers it and published Regulatory Guide 274 to set out its expectations.

Source: [What is Design and Distribution Obligations?](https://theaicommand.com/glossary/design-and-distribution-obligations-ddo#faq-2)

### When did the Financial Accountability Regime start?

FAR commenced in two stages. It applied to the banking sector, including authorised deposit-taking institutions, from 15 March 2024. It then applied to the insurance and superannuation sectors from 15 March 2025. The underlying Act received Royal Assent on 14 September 2023.

Source: [What is Financial Accountability Regime?](https://theaicommand.com/glossary/financial-accountability-regime-far#faq-2)

### When did the right to disconnect start?

The right to disconnect applied from 26 August 2024 for employees of non-small business employers, and from 26 August 2025 for employees of small business employers, meaning those with fewer than 15 employees. It lets employees refuse to monitor, read or respond to out of hours contact unless refusing is unreasonable.

Source: [What is the Fair Work Act 2009?](https://theaicommand.com/glossary/fair-work-act-2009#faq-3)

### When did the Tranche 2 reforms start?

Parliament passed the AML/CTF Amendment Bill 2024 on 29 November 2024, amending the Anti-Money Laundering and Counter-Terrorism Financing Act 2006. Newly regulated businesses could enrol with AUSTRAC from 31 March 2026 and became subject to obligations from 1 July 2026. Changes for existing reporting entities started 31 March 2026.

Source: [What are the AML/CTF Tranche 2 reforms?](https://theaicommand.com/glossary/aml-ctf-tranche-2#faq-2)

### When do the EU AI Act's high-risk rules apply?

Later than originally legislated. Regulation (EU) 2026/1744, the Digital Omnibus on AI adopted on 8 July 2026, moved the high-risk obligations for standalone Annex III systems to 2 December 2027 and for AI embedded in regulated products under Annex I to 2 August 2028.

Source: [What is the EU AI Act?](https://theaicommand.com/glossary/eu-ai-act#faq-2)

### When do you have to notify the OAIC of a data breach?

Under the notifiable data breaches scheme, an entity covered by the Privacy Act must notify affected individuals and the OAIC when a data breach involving personal information is likely to result in serious harm. The notification to individuals must include recommendations about the steps they should take in response.

Source: [What is the Office of the Australian Information Commissioner?](https://theaicommand.com/glossary/oaic#faq-3)

### When does the automated decision-making privacy obligation start?

The obligation commences on 10 December 2026. It was introduced by the Privacy and Other Legislation Amendment Act 2024 and sits in Australian Privacy Principle 1. The OAIC published an issues paper on 18 May 2026 to inform its guidance, with submissions closing on 15 June 2026.

Source: [What is automated decision-making?](https://theaicommand.com/glossary/automated-decision-making#faq-1)

### When does the Privacy Act require de-identification?

APP 11.2 requires an entity that no longer needs personal information for any permitted purpose to take reasonable steps to destroy or de-identify it. That obligation does not apply where the information sits in a Commonwealth record, or where an Australian law or a court or tribunal order requires the entity to retain it. APP 4.3 and APP 6.4 also refer to de-identification.

Source: [What is de-identification?](https://theaicommand.com/glossary/de-identification#faq-4)

### Where did the term RAG come from?

From a paper submitted in May 2020, Retrieval-Augmented Generation for Knowledge-Intensive NLP Tasks, by Patrick Lewis and colleagues. It described models that combine pre-trained parametric memory, a sequence-to-sequence model, with non-parametric memory, a dense vector index of Wikipedia accessed by a neural retriever.

Source: [What is retrieval-augmented generation (RAG)?](https://theaicommand.com/glossary/retrieval-augmented-generation#faq-4)

### Which Australian Privacy Principles matter most for AI?

APP 3 governs collection, and the OAIC treats AI-generated or inferred personal information as a collection. APP 6 limits use and disclosure to the primary purpose unless consent or reasonable expectation applies. APP 8 covers overseas disclosure, which most hosted AI triggers. APP 11 requires reasonable security steps.

Source: [What are the Australian Privacy Principles?](https://theaicommand.com/glossary/australian-privacy-principles#faq-2)

### Which businesses does AUSTRAC regulate?

AUSTRAC regulates reporting entities across accountants, banks, casinos, conveyancers, dealers in precious stones, metals and products, financial service providers, legal professionals, pubs, clubs and bookmakers, real estate, remittance service providers, superannuation providers and virtual asset service providers. Regulation follows the designated service provided, rather than the industry label a business uses.

Source: [What is AUSTRAC?](https://theaicommand.com/glossary/austrac#faq-2)

### Which entities does CPS 234 apply to?

It applies to all APRA-regulated entities across five industries: authorised deposit-taking institutions, general insurers, life companies and friendly societies, private health insurers, and superannuation RSE licensees. It also reaches information assets managed on their behalf by related parties and third parties.

Source: [What is APRA CPS 234?](https://theaicommand.com/glossary/apra-cps-234#faq-4)

### Which EU AI Act rules already apply?

The prohibitions on unacceptable-risk practices and the AI literacy duty applied from 2 February 2025. Obligations for general-purpose AI models, governance arrangements, notified bodies and penalties applied from 2 August 2025. The regulation itself entered into force on 1 August 2024.

Source: [What is the EU AI Act?](https://theaicommand.com/glossary/eu-ai-act#faq-5)

### Which jurisdictions have adopted the model WHS laws?

Safe Work Australia states that the model WHS laws have been implemented in all jurisdictions except Victoria. Some jurisdictions have made variations, often to stay consistent with their own drafting protocols and other laws. The model WHS Act Cross-Comparison Table published by Safe Work Australia summarises those differences.

Source: [What are the model WHS laws?](https://theaicommand.com/glossary/model-whs-laws#faq-2)

### Who administers the SRC Act?

Comcare administers the SRC Act for the Australian Government and many of its agencies. Corporations holding a self-insurance licence under the Act determine their own claims. Both apply the same legislation. State schemes use separate workers compensation laws, so always confirm which scheme a claim falls under first.

Source: [What is Safety, Rehabilitation and Compensation Act 1988?](https://theaicommand.com/glossary/src-act-1988#faq-2)

### Who are the members of the Fair Work Commission?

The Commission is led by a President, who under section 629A of the Fair Work Act has the same status as a Judge of the Federal Court, supported by Vice Presidents, Deputy Presidents and Commissioners based in Adelaide, Brisbane, Canberra, Hobart, Melbourne, Newcastle, Perth and Sydney. Expert Panel Members are appointed part-time for periods of not more than five years, and some state industrial tribunal members hold dual appointments.

Source: [What is the Fair Work Commission?](https://theaicommand.com/glossary/fair-work-commission#faq-4)

### Who does the Privacy Act 1988 apply to?

It applies to most Australian Government agencies and to private sector organisations with an annual turnover of more than $3 million, together called APP entities. Some smaller operators are also covered, including private health service providers, credit reporting bodies, businesses that buy or sell personal information, and Commonwealth contracted service providers.

Source: [What is the Privacy Act 1988?](https://theaicommand.com/glossary/privacy-act-1988#faq-1)

### Who does the Voluntary AI Safety Standard apply to?

All organisations across the AI supply chain, though the first version focuses on AI deployers rather than developers. A deployer is an individual or organisation that supplies or uses an AI system to provide a product or service, whether the deployment is internal to the organisation or external.

Source: [What is the Voluntary AI Safety Standard?](https://theaicommand.com/glossary/voluntary-ai-safety-standard#faq-5)

### Who enforces DDO and what are the consequences?

ASIC enforces DDO. It can issue stop orders that halt distribution of a product where the target market determination is deficient or distribution is inconsistent with it, and it has commenced litigation. ASIC has issued multiple DDO stop orders since the regime began in October 2021.

Source: [What is Design and Distribution Obligations?](https://theaicommand.com/glossary/design-and-distribution-obligations-ddo#faq-4)

### Who enforces the model WHS laws?

The Commonwealth, state and territory regulators enforce WHS laws in their own jurisdictions, supported by the National Compliance and Enforcement Policy. Safe Work Australia is not a regulator and cannot advise on workplace WHS issues. In the Commonwealth jurisdiction the regulator is Comcare, which administers the Work Health and Safety Act 2011.

Source: [What are the model WHS laws?](https://theaicommand.com/glossary/model-whs-laws#faq-5)

### Who has to comply with CPS 230?

All APRA-regulated entities must comply. That covers authorised deposit-taking institutions (banks), general insurers, life insurers, private health insurers, and superannuation trustees. The standard sits within the existing risk management framework under CPS 220 and SPS 220.

Source: [What is APRA CPS 230?](https://theaicommand.com/glossary/apra-cps-230#faq-3)

### Who is an accountable person under FAR?

An accountable person is an individual who holds a position of senior executive responsibility within an accountable entity, such as a CEO, a senior risk or compliance executive, or a head of a major business line. Their specific responsibilities must be set out in the entity's accountability statements and accountability map.

Source: [What is Financial Accountability Regime?](https://theaicommand.com/glossary/financial-accountability-regime-far#faq-3)

### Who is covered by the Comcare scheme?

The Safety, Rehabilitation and Compensation Act 1988 covers employees of the Australian Government, of Australian Government authorities and corporations, and of corporations holding a licence to self-insure under that Act. A separate Parliamentary Injury Compensation Scheme covers parliamentarians and the Prime Minister's spouse.

Source: [What is Comcare?](https://theaicommand.com/glossary/comcare#faq-2)

### Who is newly regulated under Tranche 2?

AUSTRAC names real estate professionals, dealers in precious stones, metals and products, lawyers, conveyancers, accountants, trust and company service providers, and businesses providing certain virtual asset services beyond the previously regulated digital to fiat currency exchange services. Regulation attaches to the designated service provided, not the profession.

Source: [What are the AML/CTF Tranche 2 reforms?](https://theaicommand.com/glossary/aml-ctf-tranche-2#faq-3)

### Who regulates AML/CTF compliance in Australia?

AUSTRAC, the Australian Transaction Reports and Analysis Centre, is the regulator. It is both Australia's financial intelligence unit and the supervisor of reporting entities. AUSTRAC publishes the AML/CTF Rules, guidance, and program starter kits, and it takes enforcement action against businesses that fail to meet their obligations.

Source: [What is AML/CTF regime?](https://theaicommand.com/glossary/aml-ctf#faq-2)
