A dated list is a promise you can audit

Appendix A of the APS AI Plan sets out deliverables in three groups, matching the Plan’s own trust, people and tools structure, with a column headed Expected timeframe. That column is the reason the appendix is worth more than the Plan around it. Fifteen initiatives carry a date or a season, and two of them the government has already marked Completed.

Appendix A deliverables and their stated timeframes, as published
InitiativeExpected timeframe, abbreviated
AI in government policy and guidance updatesFor publication in December 2025
AI Review CommitteeMid 2026 establish; late 2026 operationalise; late 2026 to early 2027 full maturity
Clear expectations of external service providersBy end 2025 MAS and People Panel; early 2026 Commonwealth Contracting Suite and Clausebank
AI strategic communicationsEarly 2026 communications plan and CAIO cohort operationalised; mid 2026 integration into standard reporting
Foundational learningMandatory AI literacy training by end 2025, agencies then have 12 months to implement
Staff consultation and engagementEnd of 2025 or early 2026, subject to consultation on a Circular
AI delivery and enablementEarly 2026 CAIO meetings commence; mid 2026 adoption strategy and published research
Chief AI OfficersAll agencies expected to appoint in 2026
GovAI centrally hosted AI servicesLate 2026 for foundational capabilities
GovAI ChatMid 2026 for a beta trial
Guidance on public and enterprise AI servicesCompleted
Support for AI tool procurementProcurement guidance by December 2025; broader changes late 2025 to early 2026
Re-using intellectual propertyEarly to mid 2026 design and consultation; late 2026 launch
Central register of generative AI assessmentsMid 2026
New whole-of-government cloud policyCompleted

Be careful what you conclude from a table like this, and we will be explicit about it below. Most of these are internal deliverables. An adoption strategy, a cohort of Chief AI Officers meeting, a communications plan: none of those necessarily leaves a public trace, so a member of the public cannot tell from outside whether they happened on time. What can be checked from outside is whether a promised artefact exists.

The committee exists, and the membership is not decorative

The AI Review Committee has a page, and it names five people, each in their public role:

AI Review Committee membership, as published on the committee page
MemberRole as stated
Chris Fechner, ChairChief Executive Officer, Digital Transformation Agency
Dr Kate ConroyGeneral Manager, AI Governance, Department of Industry, Science and Resources, and General Manager of the AI Safety Institute
Carly KindPrivacy Commissioner
Jo TalbotActing Deputy Commissioner, Workplace Relations, Integrity and Enabling Services, Australian Public Service Commission
Andrew WatsonDeputy Commissioner Smarter Data Program and Chief Data Officer, Australian Taxation Office

That is a serious room. The privacy regulator, the AI Safety Institute, the employer of the public service and the agency that runs some of the largest automated decision systems in the country, chaired by the body that writes the policy. If you were designing a committee to catch a bad government AI deployment before it shipped, you would want roughly these people in it.

What it is allowed to do

Here is the sentence the page leads with. The committee provides expert and non-binding advice on AI use cases with a residual high-risk rating and use cases that agencies determine to be highly sensitive, novel or complex. It helps agencies consider whether proposed AI controls, safeguards and governance arrangements are appropriate before deployment. It can also review agency responses to serious AI incidents after the agency has completed its incident response, to identify lessons and strengthen practices across government.

And then, in case anyone was in doubt: the committee does not replace agency accountability or duplicate existing governance processes. Agencies remain responsible for identifying, assessing, managing and monitoring AI use case risks.

So the sequence for a high-risk use case is that an agency may bring it, the committee may advise, and the agency decides. On incidents, the committee looks after the agency has finished responding. Nothing on the page describes a power to require, to halt, or to publish a dissent.

Why this is the same finding again, one layer up

Yesterday we set out that of the four documents governing Commonwealth AI use, only the Policy for the responsible use of AI in government binds anybody. The Plan, the technical standard and the agentic addendum are direction and best practice. The pattern in that story was about instruments.

This is the same pattern at the level of institutions. The instruments are mostly advisory, and now the body created to oversee the riskiest uses is advisory too, and says so on its own front page. That is not a gotcha: non-binding expert advice is a real and often effective governance tool, especially inside a public service where a committee of these five people expressing concern is not a small thing for an agency to ignore.

Our view, labelled as such: the honest way to read this is that Australia has chosen soft power over hard power at every layer of its public sector AI governance, deliberately and consistently. That is a defensible choice while nothing goes badly wrong. The question it leaves open is the one nobody has had to answer yet, which is what happens the first time an agency proceeds with a high-risk deployment after this committee advises against it. Nothing published says the advice would become public, and that, rather than the absence of a veto, is the thing worth watching.

What we could not check

We are not reporting that the other deliverables were or were not met. Most of them are internal and leave no public artefact, and the government has not published a status update against the appendix that we could find. Two items carry the word Completed in the appendix itself, and that is the government’s marking rather than our finding. The absence of a public progress report against a public dated list is itself the gap here, and it is a small and easily fixed one.

How we did this

Every fact above comes from two pages on digital.gov.au read in full on 26 August 2026: the AI Plan’s deliverables appendix and the AI Review Committee page. The timeframe column is quoted as published and abbreviated in our table only where a cell ran to several milestones; nothing was reordered or re-dated. Member names and roles are transcribed from the committee page, and each person is named in their public role from an official government source.

A note for anyone repeating this. The deliverables appendix is not where its own link suggests. Hrefs on the digital.gov.au AI pages resolve against a different base than the page carrying them, so the appendix sits at the site root rather than under the AI plan path, and the obvious guesses return 404. We found it by reading the addendum page’s links and testing each candidate rather than assuming.

We have not asked the Digital Transformation Agency for comment, and this piece makes no claim about any individual member beyond the role the department publishes for them.

Sources

  1. Digital Transformation Agency, AI Plan for the Australian Public Service 2025, Appendix A: Plan deliverables, read in full 26 August 2026. All 15 initiatives and their expected timeframes, including the two marked Completed, and the mid 2026 establishment date for the AI Review Committee.
  2. Digital Transformation Agency, AI Review Committee, read in full 26 August 2026. The committee's stated function, the non-binding character of its advice, its role on residual high-risk and highly sensitive, novel or complex use cases, its after-the-fact incident review role, the statement that it does not replace agency accountability, and the five members with their stated roles.
  3. Digital Transformation Agency, APS AI Plan 2025, read 26 August 2026, for the Plan's trust, people and tools structure that Appendix A is organised against.

Spotted an error? Tell us and we will check it against the sources above and publish the outcome.