The Australian Institute of Company Directors updated its guidance for boards in June 2026, with the Human Technology Institute at UTS. Buried in the summary is a sentence that should stop a board meeting.
Board-level oversight of AI and its associated risks forms part of directors’ existing duties.
No new duty was created. Nobody is waiting on legislation. The duties already on your shoulders reached this technology the moment your organisation started using it, which for most was some time ago and without a decision being made.
So what actually changes about leading?
Four things, none of them technical. Accountability that cannot be handed to a tool. Deciding what stays human. Governing the thing without strangling it. And knowing adoption from theatre.
Before you accept the numbers
Somebody will put a number in front of you this quarter. Odds are good it is 95%.
It comes from a July 2025 paper by Project NANDA at MIT: 95% of enterprise AI pilots deliver no measurable return. The paper calls itself preliminary findings and was not peer reviewed. The 5% sits inside one funnel chart describing a single narrow category, and success was defined so tightly that a tool delivering modest real returns counted as a failure. R. Scott Raynovich of Futuriom put it best: pulling a 95% failure rate out of that chart is like saying 95% of drivers failed at driving when 80% of them do not own a car. NANDA also builds agent infrastructure, and a finding that current deployments fail happens to support what they sell.
The other number is about jobs. There, the Department of Employment and Workplace Relations reported in July 2026, on ABS Labour Force Survey data, no evidence to date of broad AI-driven upheaval in the Australian labour market.
Neither is a reason to relax. Both are a reason to stop deciding off numbers that will not survive a director Googling them.
The Australian numbers that do hold up
66% of Australian workers already use at least one AI tool regularly at work. 56% of them are on tools their employer has not approved. 9% say AI is embedded in how they work day to day. That is Salesforce and YouGov, a nationally representative sample of 1,293 Australians, fielded 18 to 22 May 2026.
Sit with the gap between 66 and 9.
Employment Hero’s AI Paradox at Work, fielded with Focaldata across 1,634 Australian workers and 1,008 business leaders between 23 April and 7 May 2026, found 34% using AI at work without their employer knowing, and 51% picking up their AI skills from social media rather than any employer training.
The AICD names the same pattern, describing employees using AI on a shadow basis without formal oversight, and notes that relatively few organisations have moved past the pilot phase.
So your people have adopted it, mostly without you. Your directors are worried. And almost nobody has it embedded in the work.
That gap is a set of decisions nobody has made yet.
The accountability a board cannot delegate
Australia’s current national reference is the Guidance for AI Adoption, published by the National AI Centre on 21 October 2025, setting out six essential practices. It replaced the 2024 Voluntary AI Safety Standard, condensing ten guardrails into six practices. On this site we shorten it to AI6, but that is our shorthand rather than an official name, so search for it by its real title. If your policy still cites the Voluntary AI Safety Standard as current, that is a tidy-up worth doing this month.
The first of the six practices is deciding who is accountable. Named responsibility. Not a committee. Not “the AI working group”. A person, with the authority to match.
Worth knowing what the guidance itself suggests you do first under that practice: create an AI policy. Not a committee, not a pilot. A written statement of what is and is not allowed.
The AICD arrives at the same place from the other direction, telling boards to map AI-related responsibilities across the organisation. Mapping responsibility is what most organisations skip, because it is slower than buying something.
That map is what HUMAN is for. It is the accountability map I built to sit across the four GIST pillars, at five levels.
- H, Habit. The individual. What guardrails do I personally need to use AI safely?
- U, Unit. The team. What do we agree on so one person’s AI use does not create risk for the others?
- M, Macro. The organisation. What policies and risk settings need to be in place, and who owns them?
- A, Audience. Clients and suppliers. What protects their data, and what do they need to understand about how we use AI?
- N, Neighbourhood. The community. What is our ethical responsibility in how we use this?
Most leadership teams can answer the Macro row. Almost none can answer the Habit row, which is where the risk actually lives, because that is where the 56% and the pasted client data are.
The question I ask boards: which cell are you most quietly worried about?
Deciding what stays human
Nobody hands you a template for this, and it is the part of the job that cannot be outsourced to a policy.
Some work should not be automated even when it can be. The apology to a client who has been let down. The decision that ends someone’s employment. The conversation where the point was never the information, it was that a person turned up to have it.
Draw that line deliberately, write it down, and say why. If you do not, it gets drawn for you by whoever is quickest with a prompt, one small convenience at a time, and you will not notice until a client does.
This sits with leadership, not a working group, because it is a values decision wearing an operational hat. What your organisation refuses to automate says more about it than any strategy document, and staff read it accurately within a week.
Call it sentimentality if you like. It is also where your differentiation sits, because anyone can buy the same model you did. The AICD puts it in governance language, telling boards to keep close oversight of the human impacts of AI on employees, customers and the community.
Decide it now, while it is cheap. Deciding it after an incident is a very different meeting.
Governing AI without strangling it
The fear I hear most from executives is that governing AI will slow everything to a crawl. Fair concern, and badly done it does exactly that. A forty page policy nobody reads is not governance, it is paperwork with a compliance smell.
Reassuringly, the AICD says the same. Dedicated AI governance structures may not be necessary for every organisation. What matters is that the board can see how AI is managed, monitored and governed, with enough AI literacy at board level to ask a decent question.
You do not need a new committee. You need four answers.
GIST is the methodology I use with boards and leadership teams. Guardrails, Intent, Strategy, Practical Training.
Guardrails. What protects us? Define what stays in-house and what goes to AI. Set the rules before your team sets their own, because on current numbers they already have.
Intent. Why are we using AI? Skip this and your strategy becomes a shopping list.
Strategy. What is the plan? Build it from the intelligence already in the room, sequenced for your team and your timeline. Not one lifted from a vendor deck.
Practical Training. What must we learn? Half your people picked up their AI skills from social media, and whatever they learned there is now your default practice.
The sequence carries the weight. Guardrails first, because every other pillar sits on sand without them. Practical Training last, because a team trained on a tool before its purpose is clear will do the wrong thing beautifully.
If your board met tomorrow, which pillar would you fail on first?
Where leaders come unstuck
Delegating it entirely to IT. They own the systems. They cannot own what the work should look like, or which parts of it stay human.
Governing for the pilot, not the organisation. Guardrails written for a controlled trial fall apart the moment three hundred people have access.
Announcing before deciding. A launch email lands, nothing changes underneath, and staff learn that AI is theatre. Expensive to unteach.
What to do on Monday morning
If you run the organisation, four moves, none needing budget approval.
- Name the accountable person. Out loud, in the minutes, with the authority attached.
- Ask your executives what they personally used AI for last week. That answer beats any audit.
- Write down three things that stay human, and circulate them.
- Pick one guardrail you can state in a sentence and put it in front of everyone this week. Client data is the place to begin.
If you sit on the board, you cannot do those things. You can ask four questions.
- Who is accountable for AI here, by name?
- What are our people using that we have not approved, and how do we know?
- What have we decided stays human, and who decided it?
- What did our last AI investment change about how the work gets done?
If management cannot answer the second one, that is the answer.
The short version
AI does not change what leadership is. It changes how quickly the gaps show.
An organisation with fuzzy accountability finds AI makes it fuzzier, faster. One that never decided what its people are for finds the tools deciding instead.
66% of your people are using it. 9% of workplaces have it embedded in the work. Closing that distance is a leadership job, and no model release will do it for you.
Human-led. AI-leveraged. The Augmented Workforce.
The positioning is a statement about who stays responsible. The technology was always the easy part.
The four answers, worked through with your board.
Guardrails, Intent, Strategy and Practical Training, sequenced for your organisation rather than lifted from a vendor deck. That is the work I do with boards and leadership teams.
Work with me →Questions people ask
Do directors have a legal duty to oversee AI?
Board-level oversight of AI and its associated risks forms part of directors’ existing duties, according to A Director’s Guide to AI Governance Version 2, published by the AICD with the Human Technology Institute at UTS in June 2026. No AI-specific duty was created. Organisations are expected to govern AI within existing obligations covering privacy, consumer protection, discrimination, work health and safety, copyright and cyber security.
Who should own AI in our organisation?
A named person at executive level, with authority to make decisions and a direct line to the board. The National AI Centre’s Guidance for AI Adoption puts accountability first for a reason. Shared ownership across a working group tends to mean nobody is answerable when something goes wrong.
Do we need a separate AI governance committee?
Not necessarily. The AICD’s guidance says dedicated AI governance structures may not be necessary for every organisation. What matters is that the board has visibility of how AI is managed, monitored and governed, underpinned by enough AI literacy at board level to ask useful questions.
Do we need an AI policy before we let people use AI?
Your people are already using AI. Australian research from May 2026 puts workplace use at 66%, with 56% of those users on tools their employer has not approved. A policy arriving after two years of unmonitored use is a documentation exercise, not protection. Start with one or two guardrails you can state in a sentence, publish them this week, then build the fuller policy with the people who will live under it.
Is the Voluntary AI Safety Standard still the current Australian reference?
No. The National AI Centre published the Guidance for AI Adoption on 21 October 2025, consolidating and replacing the 2024 Voluntary AI Safety Standard. It sets out six essential practices in two layers: foundations for organisations getting started, and implementation guidance for those with mature governance or higher-risk uses. Work already done against the ten guardrails still counts — the National AI Centre published a crosswalk mapping them across.
Is AI costing Australian jobs?
Not so far, on the available evidence. The Department of Employment and Workplace Relations reported in July 2026 that there is no evidence to date of broad AI-driven upheaval in the Australian labour market, drawing on ABS Labour Force Survey data. That is a monitoring finding, not a forecast, and it says nothing about how individual roles will change.
What is the GIST framework?
GIST is a four-part AI governance methodology created by Tracy Sheen: Guardrails, Intent, Strategy and Practical Training. It sets out the four questions a leadership team has to answer to adopt AI well, in that order, and pairs with the HUMAN accountability map across five levels: Habit, Unit, Macro, Audience and Neighbourhood.
Human-led. AI-leveraged. My philosophy, my business, this article. The Augmented Workforce in action.
Drafted with Ada, my AI collaborator. Reviewed, shaped and signed off by me. How I work with AI· Tracy Sheen CSP

