A practical enterprise framework for governing information as an organisational asset, strengthening accountability and building the foundations required for AI, privacy, cyber security and trusted decision-making. InfoGovANZ has published its Enterprise Information Governance Framework to help organisations build a coordinated enterprise approach to governing information. The Framework responds to […]
Frontier AI, agentic systems and the changing cyber threat environment
Recent incidents show why advanced AI agents require technical containment, least privilege, monitoring and effective human control. Four disclosures between 24 July and 6 August 2026 have brought the cyber risks of increasingly capable AI agents into sharper focus. On 21 July, OpenAI disclosed that a combination of its […]
The Qantas Data Breach: lessons in regulatory defensibility
What organisations can learn from the Privacy Commissioner’s decision to conclude preliminary inquiries without further action. The Privacy Commissioner has completed preliminary inquiries into the 2025 Qantas data incident, which affected approximately 5.12 million Australians following a social-engineering attack on an overseas third-party contact centre provider. After almost a […]
Data Breach Report and OAIC Guidance
Australia’s latest data breach figures reinforce the need for stronger cyber resilience, third-party oversight and breach readiness across organisations holding sensitive and identity-rich information. The OAIC’s latest complete dataset records 1,205 notifiable data breaches during calendar year 2025, an increase of 8 per cent on 2024 and the highest […]
AI in Australia’s Interests Announcement
Australia’s national-interest approach is emerging as other major jurisdictions recalibrate AI security, innovation and regulation. On 15 July 2026, Prime Minister Anthony Albanese announced(opens in new tab) that the Australian Government would establish an Office of AI within the Department of the Prime Minister and Cabinet and develop a […]
US: Frontier AI security reviews without comprehensive regulation
The United States is prioritising frontier-model security review and national-security cooperation while continuing to resist comprehensive national AI regulation. The United States has directed the development of a voluntary pre-release security review framework for certain proprietary models with advanced cyber capabilities. Under Executive Order 14409, developers would be able […]
China: rapid AI development within a comprehensive regulatory framework
China is combining rapid AI capability development with detailed rules governing public-facing services, personal information, user safety and vulnerable groups. China continues to combine rapid AI capability development with detailed regulation of public-facing AI services and personal information. Its Interim Measures for Artificial Intelligence Anthropomorphic Interaction Services commenced on […]
EU: AI transparency enforcement begins as requirements are simplified
The European Union is commencing key AI Act transparency requirements while simplifying and extending parts of its high-risk regulatory regime. The European Union is simultaneously implementing and modifying its AI framework. From 2 August 2026, Article 50 of the AI Act applies to providers and deployers of specified AI […]
Agentic AI Guidance: IG, Risk and Practical Controls
InfoGovANZ has released new guidance on Agentic AI: Information Governance, Risk and Practical Controls. It is intended for information governance, privacy, cybersecurity, records, legal, risk, procurement, technology, audit and business leaders assessing or deploying agentic AI. Agentic AI differs from conventional generative AI in that it can go beyond producing a […]
Australian Government releases technical guidance for Agentic AI
The Digital Transformation Agency has released an Agentic AI addendum to the AI Technical Standard for Australian Government. The addendum supplements the existing technical standard and should be read with the broader Australian Government AI policy and assurance framework. While the addendum is directed to Australian Government agencies, its treatment […]
Cybersecurity: AI in cyber defence
The Australian Signals Directorate’s Australian Cyber Security Centre has published Opportunities for AI in cyber defence. The guidance explains how organisations can use AI to strengthen cyber-security functions while managing risks introduced by AI-enabled systems. It frames AI use against the Information Security Manual cybersecurity functions of Govern, Identify, Protect, […]
Cybersecurity: Quantum sensing and emerging risk
ASD’s ACSC has released Quantum technology primer: Sensing. Quantum sensing uses quantum phenomena to make highly sensitive observations of the physical world, including time, pressure, gravity and magnetic fields. For information governance and risk leaders, the immediate relevance is not adoption: it is understanding how more precise sensing could change […]
National Archives Check-up 2025: progress, but gaps remain
The National Archives of Australia has released its Check-up 2025 Whole-of-Government Summary Report. The report is based on the 2025 self-assessment responses of 175 Australian Government agencies and provides the final stocktake against the original timeframe of the Building trust in the public record policy, which has now been extended […]
WA’s Privacy and Responsible Information Sharing Act commences
The substantive privacy and information-sharing provisions of Western Australia’s Privacy and Responsible Information Sharing Act 2024 commenced on 1 July 2026. The framework introduces clear principles and standards for how Western Australian government agencies collect, use, store and share personal information, together with a responsible information-sharing framework. The commencement matters […]
EU’s Digital Omnibus on AI
On 29 June 2026, the Council of the European Union gave final approval to the regulation simplifying aspects of the implementation of the EU AI Act, commonly described as the Digital Omnibus on AI. The measure forms part of the EU’s wider ‘Omnibus VII’ simplification package. The application of […]
FOI under scrutiny: ANAO report identifies administration weaknesses
The Australian National Audit Office has released its performance audit report, Administration of the Freedom of Information Act 1982 by Selected Entities, Auditor-General Report No. 32 of 2025-26 (ANAO FOI Report). The audit examined whether selected entities’ administration of FOI requests was effective at providing the community with access to […]
Privacy enforcement: Insider access and the American Express report
The Privacy Commissioner has found that American Express Australia Limited (Amex) interfered with an individual’s privacy by failing to take reasonable steps to protect personal information from unauthorised employee access, in breach of APP 11.1. The decision is a significant reminder that insider access is not a peripheral cyber-security issue. […]
Privacy enforcement: tracking pixels and sensitive health information
The Australian Privacy Commissioner has found that Medmate Australia and Monash IVF interfered with individuals’ privacy by using third-party tracking pixels on websites that provide telehealth and fertility services. The determinations found that tracking pixels collected sensitive information and enabled subsequent targeting of individuals through social media advertising. The decisions […]
A Bookish Coda: Mona Opens
From information governance to the pleasure of information itself: Mona in Hobart has opened Phrontisterion, a subterranean library more than a decade in the making and built at a cost of just over $100 million. It houses David Walsh’s growing collection of books, rare volumes, maps and manuscripts, with around […]
New Zealand welfare automation: modernisation, safeguards and the Robodebt warning
On 28 May 2026, New Zealand’s government passed the Social Security (Modernisation) Amendment Bill, enabling automated electronic systems to be used in social security administration, including to make decisions on behalf of the Ministry of Social Development about people’s benefits. Government messaging has emphasised modernisation, reduced delays, error reduction and […]


















