– 21 July 2026
Lucy Poole - Deputy CEO, Strategy, Planning and Performance Division – delivered the following address to the ANAO Audit Committee Chairs Forum.
NOTE: This speech was delivered on Friday 17 July 2026. Check against delivery.
Thank you, Ms Jago. And thank you to the ANAO for inviting me to speak.
I want to talk about artificial intelligence through a practical lens: how we keep public trust when the technology is moving quickly, the language can be slippery, and the accountability still sits with us.
AI does not change the basic responsibilities of government: reliable delivery, explainable decisions and administration that people can see is worthy of their confidence.
What AI changes is the practical job of giving assurance. It can put more distance between policy intent and what happens in delivery, and create new dependencies across technology, suppliers and staff.
The story in the committee paper can sound sensible, and the pilot can look promising. But assurance has to test what is really happening underneath.
One risk I will keep coming back to is the illusion that accountability can be outsourced. We can buy impressive capability from third parties, but we cannot buy our way out of public responsibility for how those systems are used.
That is the thread I want to pull through this discussion: assurance has to look past the polished committee paper.
With that in mind, I’ll cover 3 things: where agencies are now; how the strategic position requirement can sharpen scrutiny; and what agentic AI will mean when systems start to act across government workflows.
So, let me start with where we are now.
From the DTA's whole-of-government view, the APS has moved beyond curiosity. AI is already part of government work.
The Prime Minister’s address this week sent a clear signal: AI is no longer a narrow technology issue. It is starting to shape almost every sector — from the economy to energy, infrastructure and public services.
For audit and risk leaders, that means moving past the hype and making sure the internal controls are real.
Public trust changes the stakes.
The OECD's most recent trust survey found Australians' trust in the federal government has risen and now sits above the OECD average. But trust can be built slowly and lost quickly.
A single high-profile AI failure can make the public wonder whether reliability was assumed rather than assured. Researchers call Australia's pattern "sceptical adoption": high use of AI, but limited trust in it.
Government may be more trusted than AI in general, but that trust is not a blank cheque. It’s credit we have to keep earning in the way we adopt AI in practice.
One sign of that shift is the first meeting of the cross-service AI Review Committee. Administered by the DTA, it provides independent, non-binding advice before the most sensitive or high-risk AI applications move into production.
But central mechanisms can only take us so far. The real test is whether whole-of-government direction shows up in agency governance and control. Across the Commonwealth, agencies are starting from very different levels of readiness, and much early use is still tactical.
The ANAO's performance audit of AI governance at the Australian Taxation Office makes the point concrete. The audit found the ATO had only partly effective arrangements across the AI lifecycle, and the ATO agreed to all 7 recommendations.
This isn’t a story about an agency doing AI badly. In many ways, the ATO was ahead of most agencies because it had arrangements mature enough to audit. The lesson is the gap between having a framework and having evidence that the framework is working.
That’s the gap an ARC needs to close.
The same split shows up in the workforce. Some employees are cautious, while others are already pulling AI into day-to-day work ahead of formal training or clear guidance.
That is where shadow AI often appears: staff under pressure using consumer-grade tools because official options are too slow, too limited or unavailable.
All of this changes the assurance task.
A point-in-time check before deployment will not be enough. Committees need a live view of what is in use, who owns the risk, and whether the agency can detect drift over time.
In practice, agencies need to turn scattered activity into deliberate choices.
That is the role of the strategic position now required under the AI Policy: to make those choices explicit, and to give Audit and Risk Committees something concrete to test.
Under the AI Policy, the strategic position is where each agency makes those choices visible: what it is scaling, what risk it is carrying, and what capability it is building for the long term.
At its best, it is not a compliance artefact. It is leadership clarity: a chance for management to explain how AI connects to the agency's mission, where it adds value, and how staff move from experimentation to adoption.
For Audit and Risk Committees, the value is in the conversation the strategic position enables. It gives you a basis to test whether management's view of AI is grounded in the agency's mandate and risk appetite, and whether it reflects the practical realities of how the agency works.
There is deliberately no single model for doing this well. The form matters less than whether the position gives staff clarity and gives the ARC enough detail to test whether management's choices are proportionate.
A useful strategic position reveals management's judgement about where AI belongs in the agency's work: individual productivity, safe experimentation, enterprise capability or scaled adoption.
If it reads like it could belong to any agency, it probably has not said enough about this agency.
It should drive a better conversation with management. Not simply: can you show us some pilots? But: can you explain the path from current use to considered adoption?
It also opens a line of sight to whether the foundations are keeping pace with the AI use cases being pursued.
The strongest approaches will use existing governance arrangements and bring in the right expertise, so management has a clear way to experiment safely, choose the right tools and show that progress is real.
That gives the ARC a practical test: does the agency's ambition match its capability, and does management know when experimentation should scale, change course or stop?
I want to name one dimension explicitly, because it's easy for it to disappear inside all this talk of governance and capability: cost.
AI is often costed once, at the pilot stage, and then not costed properly again. A business case may cover the licence, integration and initial training, but not the ongoing costs of monitoring, maintenance, escalation and eventual retirement. We would expect that discipline for any other investment. AI should not be treated differently.
The ANAO's audit of the ATO is instructive here too. It found the ATO had no arrangements in place to measure the effectiveness of its automation and AI strategy. That is a value-for-money problem as much as a governance one.
There is also the cost of failure. If an agentic system is compromised, or a poorly governed model produces a wrong or unfair decision at scale, the cost of fixing it can be much larger than the cost of building it. That belongs in the risk appetite conversation, not just the IT budget.
Behind these practical questions is a bigger point.
AI may change how bureaucracies work: less like a neat hierarchy of boxes, and more like a network of people, systems and automated actions. We can already see early signs — work moving across organisational boundaries, decisions being shaped outside the traditional chain of command, and authority being exercised through tools as well as people.
For ARCs, assurance can no longer only follow the organisation chart. It needs to follow the workflow — from the source of the data, through the point of judgement, to where the system acts and accountability lands.
Handled well, the strategic position requirement shifts the conversation from "are we adopting AI?" to "are we adopting it deliberately, proportionately and in a way that fits the work of this agency?"
And that takes us to the next assurance challenge: what happens when AI systems begin not only to generate outputs, but to act across workflows?
That is the heart of agentic AI — systems that can take action across tools, workflows and services.
For assurance, the key question is plain: what authority has been delegated to the system? How is that authority limited? And can the agency reconstruct what happened if it is later challenged?
At Innovation 2026 in London, the recurring international question was how governance keeps pace with systems that do more than generate advice.
With agentic AI, the risk is not only what a system produces. It is what the system is allowed to do.
The connection to automated decision-making and administrative law needs care. Where a system uses personal information or affects the public, safeguards need to be designed in from the start: human judgement, contestability and proper records.
Cyber risk shows why this matters. Five Eyes cyber security agencies have warned that agentic AI creates new risks as systems become more autonomous and interconnected.
Think of a procurement agent with access to contracts, supplier information and payment authority. If a lower-risk tool connected to that workflow is compromised, an attacker may inherit permissions they should never have had. The agent does not need to be attacked directly. It just needs to be trusted by something that was.
Even clean audit logs can obscure risk when actions are taken through a trusted agent identity.
A real case shows how this can play out. In late 2025, Anthropic disclosed that a state-sponsored threat actor had manipulated one of its agentic coding tools into attempting to infiltrate around thirty organisations worldwide, including government agencies. It succeeded in a small number of cases.
The method was not a classic technical exploit. The operators convinced the system it was working for a legitimate cybersecurity firm, then broke the attack into small, harmless-looking tasks. Once that trust was established, the system carried out most of the operation independently.
That is worth pausing on. An agent may have legitimate authority and stay within the rules it has been given. But if the trust underneath that authority is manipulated, it can still be turned against the organisation.
The audit log may simply show a trusted identity doing what it was allowed to do.
That is why access, identity and permissions need to be treated as core governance questions — not technical details. A capable system may look trustworthy before anyone has really tested how it behaves under pressure.
The benefits are real, especially where government processes are complex, repetitive or hard to navigate. But if control does not keep pace with capability, agencies may be left retrofitting evidence and accountability after agentic systems are already embedded.
So agentic AI is not just a new technology category. It is a shift in how authority is exercised — and it brings us to the final practical question: what capability does an ARC need around the table?
For the most sensitive or high-risk use cases, management should be able to explain whether APS AI Review Committee advice is needed. If it is, the advice should be sought early enough to shape the design and safeguards — not just endorse them at the end.
That advice is valuable, but it does not transfer accountability away from agencies. Internal thresholds still need to identify the use cases that warrant extra scrutiny while design choices can still be adjusted.
This is the same accountability point from the start: advice can be sought, capability can be bought, but public responsibility cannot be outsourced.
That is also why an ARC's own capability is part of the assurance environment. The useful question is whether members can understand what management is proposing, test the evidence base, and recognise when deeper inquiry is needed.
If AI is used in service delivery, compliance or fraud detection, the Committee should test whether safeguards are working: are decisions fair, explainable and properly overseen?
And if staff are using public generative AI tools, does management know whether the guidance is being followed?
If that capability isn't yet available, Chairs can build or borrow it through specialist advisors, small external groups or targeted expert sessions.
That capability also needs to be cross-disciplinary. AI is not just a technology problem for the IT branch. The Committee's value is in bringing perspectives together, so assurance follows the real workflow rather than a single organisational view.
But a committee that only turns up at the end is not practising independence. It is practising absence. If engaging with the ARC feels like friction rather than judgement to be sought, management may bring things later, frame them more narrowly, or go around the committee altogether.
The alternative is not for ARCs to become cheerleaders. It is to be present earlier and more often: to understand the agency's AI direction while it is forming, see things demonstrated before a decision point, and build enough fluency that proposals do not arrive as a foreign language.
Put simply, ARCs do not need to adopt AI for management, and they should not simply resist it from the sidelines. They need to be actively engaged in the journey — informed, curious and hard to surprise.
Let me bring this back to a few practical questions you can put to management directly.
They are not technical questions.
They are assurance questions: can the agency see the risk, own it, escalate it and build the capability to manage it?
The first is about whether management has a live view of AI use — not just the projects that have gone through formal approval, but the tools that are actually shaping day-to-day work.
The second is about strategy: whether the agency’s position on AI is specific enough to its mission, risk appetite and operating environment to support real decisions.
The third is about agentic AI, where the question becomes less “what does the system say?” and more “what has it been authorised to do?”
And the final questions are for committees themselves. Are you seeing these issues early enough to shape the conversation, and do you have the right mix of perspectives around the table to test what management is telling you?
If these questions do nothing else, I hope they help move the discussion from reassurance to evidence — and from approval at the end to better judgement earlier in the process.
Let me close by returning to the main point. AI does not change the principles of public administration; it changes the environment in which those principles have to be applied.
It does not change what earns public trust: reliable delivery, explainable decisions and administration people can see is worthy of their confidence.
It changes how hard those things are to demonstrate.
So, the enduring task for ARC Chairs is to test whether assurance is keeping pace: whether human oversight is built in, staff guidance is usable, and the Committee can help shape the journey rather than judge it at the end.
The DTA can support agencies through guidance, forums and practical advice. But independent assurance sits with Audit and Risk Committees themselves. It remains one of the most important ways the public service protects public trust.
Thank you.
The Digital Transformation Agency is the Australian Government's adviser for the development, delivery, and monitoring of whole-of-government strategies, policies, and standards for digital and ICT investments, including ICT procurement.
For media enquiries email us at media@dta.gov.au
For other enquiries email us at info@dta.gov.au