Australian governments spent 2024 and 2025 building AI assurance machinery. A national framework was agreed by the Data and Digital Ministers Meeting in June 2024, and the states built their own policies on top of it. What almost nobody has done is check whether the machinery is working. Two auditors-general did, in the same season, and their reports read as a pair even though neither mentions the other.
Queensland: the framework is sound, the visibility is not
Queensland introduced an AI governance policy in September 2024. The Audit Office assessed
it and was broadly positive: The Queensland Government’s AI governance framework is
effectively designed to support entities with managing the ethical risks of AI systems, with
some opportunities for improvement.
The policy and its supporting materials align to
national and international frameworks.
The problem is what happens after the policy is written. The department responsible for it,
Customer Services, Open Data and Small and Family Business, is described in flat terms:
CDSB has limited visibility across the Queensland Government on AI use and emerging ethical
risks. This affects its ability to assess how well entities manage these risks.
The Audit
Office made four recommendations to that department, including monitoring
whole-of-government AI use and risks.
The audit then tested the policy against one department in practice, Transport and Main
Roads, and the picture is uneven rather than bad. TMR has not yet established department-wide
AI governance
and has not yet undertaken dedicated ethical risk assessments for the MPST
program or the QChat AI systems
. Two more recommendations went to TMR.
The contrast between TMR’s two systems is the most useful thing in the report for
anyone running AI anywhere. The Mobile Phone and Seatbelt Technology program
uses image recognition AI to detect driving offences
, and TMR has implemented controls
including human review to support accuracy, privacy and fairness, plus
monitoring of the external vendor that runs it. On the other system, a chat assistant, the
finding is blunt: TMR does not have adequate safeguards to manage ethical risks for
QChat.
The system that decides whether a driver gets a fine is the one with the human in the loop. The general-purpose chat tool, the sort of thing that spreads through an organisation without a procurement decision, is the one without the safeguards. That ordering is not surprising, and it is exactly the pattern a central agency with no visibility would fail to catch.
NSW: the same gap, counted
NSW answered the same question by counting. Its Auditor-General’s internal controls report, tabled 29 October 2025, audited the 26 largest agencies and found 21 of them running 357 AI tools between them, with only 38 per cent holding a formal AI policy and 15 of the 21 keeping a central inventory of what they run. We went through that audit in July.
Put the two side by side and the methods could not be more different. Queensland assessed the framework and drilled into one department. NSW counted tools across a whole tier of government. Queensland described the gap; NSW measured it. Neither auditor could tell you, from the centre, what the state as a whole is running.
The obvious fix is the one that already failed
Reading Queensland’s report on its own, the natural conclusion is that the tools
should be mandatory. Queensland’s AI governance policy is mandated: it
requires agencies to use a consistent and evidence-based process which incorporates an
ethical framework
. But the specific instrument the state built for that job, the
Foundational Artificial Intelligence Risk Assessment, is published as
non-mandated. Mandate the tool, the argument goes, and consistency follows.
NSW is the test of that argument, and it does not support it. In NSW the assessment framework itself is mandatory, through a 2024 circular, with registration required above a $5 million threshold. NSW still ended up with 357 tools, a minority of agencies holding a formal policy, and a third of the audited group keeping no central inventory. A mandatory instrument produced better compliance on the transactions it covers and did not, by itself, produce a picture of the estate.
That is the useful finding from reading both. Visibility is not a by-product of an assurance framework, however good the framework is. An assessment tool is aimed at a decision about one system at one moment. Knowing what an entire government is running is a different job, needing an inventory, and neither state has finished building one.
Our view
Both audits are more encouraging than a summary of their findings suggests. Two states commissioned genuine scrutiny of their own AI governance and published the results while the policies were young enough to change, which is close to best case. Queensland’s auditor called the framework well designed and then said plainly what it cannot do.
The gap they share is worth naming precisely, because it is fixable and cheap relative to the machinery already built. Both states can tell you what an agency is supposed to do before it deploys an AI system. Neither can tell you what is deployed right now. Every other question worth asking about public sector AI, whether the safeguards on a driver-fining system are typical, how many chat assistants are running without a risk assessment, sits downstream of that one.
Queensland’s Audit Office says it will follow up on its recommendations, and NSW has a dedicated performance audit of AI and automation governance scheduled for 2026-27. Those are the two documents to read next, and we will.
How we sourced this
The Queensland findings are transcribed from the Audit Office’s report to parliament, Managing the ethical risks of artificial intelligence (Report 2: 2025-26), tabled 24 September 2025, downloaded and read on 19 August 2026. The mandated and non-mandated status of Queensland’s policy and its FAIRA instrument come from the Queensland Government Enterprise Architecture pages for each document, which publish that status as a field. The NSW figures come from the NSW Auditor-General’s internal controls report as read for our July piece. The national framework date comes from the framework itself.
What we have not done. We have not audited either auditor, and every finding here is reported as theirs and attributed. We have not spoken to either department. We have not read the Queensland report’s appendices, which carry the detailed entity responses, so the departments’ own replies are not represented here beyond what the report summarises. Nothing here is a claim about any individual public servant.
Sources
- Queensland Audit Office, Managing the ethical risks of artificial intelligence (Report 2: 2025-26) (tabled 24 September 2025; PDF downloaded and read 19 August 2026): every Queensland finding and quotation above, the four recommendations to CDSB and two to TMR, and the contrast between the MPST and QChat systems.
- Queensland Government Enterprise Architecture, Artificial intelligence governance policy and FAIRA framework (both read 19 August 2026): that the policy is published as Mandated and effective September 2024, that FAIRA is published as Non-mandated, and the wording of the policy requirement quoted above.
- Department of Finance, National framework for the assurance of artificial intelligence in government (dated 21 June 2024, PDF read 19 August 2026): that the national framework was agreed through the Data and Digital Ministers Meeting and is the anchor the state policies align to.
- Our own analysis of the NSW Auditor-General’s internal controls report (11 July 2026): the 357 tools across 21 of 26 agencies, the 38 per cent with a formal AI policy, the 15 of 21 keeping a central inventory, and the mandatory NSW circular with its $5 million registration threshold.
Work in public sector AI governance, or read these audits differently? The correction form is on our tips page; we check every correction against the published reports and log the outcome here.