Fortnightly Bulletin · AU-first regulatory & governance watch
Issue: 31 August 2026
My take
Last fortnight I asked you to name one control in your AI stack you had personally seen tested. This fortnight the UK’s National Cyber Security Centre published the list of controls it thinks you should be able to demonstrate for autonomous agents — and one of them is beautifully, brutally binary: can you stop it? Not raise a ticket. Not convene a working group. Immediately halt the agent, cut its network access, sever its connection to the model. Deloitte then surveyed 3,235 organisations and found 35% admit they could not. So the question this fortnight is shorter than last fortnight’s and considerably harder to talk your way around: if an agent started doing something wrong right now, who stops it, how, and when did you last test that? Most organisations discover their real answer sits somewhere between “we’d raise it with the vendor” and “we’d unplug something and hope.” Finding that out on a Tuesday in a meeting is dramatically cheaper than finding it out during an incident.
— Gethryn Ghavalas, AI Strategy & Governance, Agile Insights
In brief
Last bulletin’s argument was that three frontier labs had each disclosed an agent incident, and that in every case the thing that found it was a retrospective audit rather than a control. This fortnight the institutions answered. On 21 August the UK’s National Cyber Security Centre published interim guidance on managing cyber risk in agentic AI systems — distinct agent identities, short-lived credentials scoped to the task, the ability to immediately halt autonomous activity, and controls sized to the autonomy granted rather than one policy applied uniformly. Read it next to Deloitte’s finding that 35% of organisations admit they could not immediately pull the plug on a rogue agent and you have the fortnight in one line: the regulator has now written down the control, and a third of the market cannot perform it. Meanwhile the protocol layer consolidated — Google’s A2A joined the Linux Foundation’s Agentic AI Foundation on 20 August, putting it under the same neutral governance as MCP — and in Australia, Parliament appointed a Joint Select Committee on AI on 20 August reporting by 30 November. The OAIC’s ADM guidance remains unpublished with the 10 December obligation now fifteen weeks out.
01
AU-first
Australia acquired a parliamentary inquiry and a data-centre framework this fortnight, and still has not acquired the one piece of guidance most organisations actually need before December.
Joint Select Committee on AI appointed 20 August, final report due 30 November 2026. Both Houses resolved to appoint the committee on 20 August. Terms of reference cover the adequacy of existing laws and regulatory frameworks, copyright and IP, national security, data sovereignty, consumer protection, deepfakes and cyber security — with economic opportunity, workforce impact and sovereign capability explicitly in frame.
National Cabinet took the AI data-centre framework in August; it remains an energy-and-water instrument, not a governance one. The proposed national framework for large AI data centres went to National Cabinet as flagged, with legislation expected in Parliament in early 2027. The substance is that large data centres could be legally required to underwrite new power supplies, cover their share of grid connection costs, add at least as much electricity to the grid as they consume, minimise water use and fund additional water infrastructure.
OAIC ADM guidance still unpublished; 10 December is now fifteen weeks away. The Commissioner’s stated position remains that guidance lands by September 2026, following the Automated Decision-Making Issues Paper published 18 May and consultation closed 15 June. From 10 December, APP entities using personal information in substantially automated decisions that could reasonably be expected to significantly affect an individual’s rights or interests must describe in their privacy policy the kinds of personal information used, the kinds of decisions made, and broadly how the automated process works.
eSafety Commissioner warns AI regulation will be materially harder than the online-safety fight. On 19 August Julie Inman Grant cautioned that the current “everyday” harms of AI will be eclipsed by far more serious consequences if platforms are permitted to avoid regulatory oversight — building on eSafety’s existing transparency notices to AI companion chatbot providers.
EU: Digital Omnibus on AI is in force (24 July OJ, effective 27 July); Article 50 transparency has applied since 2 August. For anyone maintaining a compliance calendar, the settled position is now: Annex III standalone high-risk obligations move to 2 December 2027, Annex I embedded high-risk to 2 August 2028, transparency live from 2 August 2026, and a new prohibition on AI systems used to generate child sexual abuse material or non-consensual intimate content with technical safeguards required by 2 December 2026.
– What this signals: The practical read is that this pushes substantive Australian AI legislation further right, not closer. A committee reporting 30 November feeds a government response, which feeds drafting, which meets legislation already slated for early 2027 — and the committee’s scope overlaps heavily with what the Standards package was meant to settle. The message is unchanged and now better evidenced: don’t build a compliance programme against Australian AI law, because there isn’t one yet and the shape is still being argued in public. Build against the obligations that already bite — Privacy Act ADM, work health and safety, consumer law, your sector regulator. The committee is, however, a genuine submission opportunity if you have a sector view worth putting on the public record.
– What this signals: Worth being precise if anyone in your organisation heard “National Cabinet agreed AI standards” and assumed it meant obligations on AI use. It does not. This is infrastructure and utilities policy with an AI label on it. Nothing in it changes what a deployer of AI has to do. If your risk register grew a line item off the back of the August coverage, it is probably in the wrong register.
– What this signals: This is the fourth consecutive bulletin carrying this item and the message has not changed, which is itself the point. Fifteen weeks. If your system inventory isn’t already running, September’s guidance will land on an organisation that still cannot answer the prior question — which of our decisions are substantially automated — and the discovery work will collide with the December deadline and the Christmas shutdown. The privacy-policy paragraph is an afternoon. Finding the rostering tool, the eligibility screen, the triage script and the assessment macro is a quarter. If you’re waiting for the guidance before starting, you’ve misread which half is hard.
– What this signals: eSafety is the Australian regulator most likely to act on AI before the standards framework exists, because it already has the instrument — the Basic Online Safety Expectations and transparency notices — and has demonstrated willingness to use it on AI services specifically. If you run a consumer-facing conversational product, that is a live compliance surface today, not a 2027 one.
– What this signals: The tracker-drift problem flagged last bulletin has now had a month to resolve and largely hasn’t. Any internal standard, policy or board deck citing “high-risk obligations from August 2026” is wrong and should be corrected. The new prohibition is worth a specific flag if you run or resell image or video generation — that December safeguard date is closer than the high-risk deferral makes it feel.
02
The NCSC guidance is the most operationally useful document published this fortnight, and it is essentially a control set derived from the incidents in the last bulletin.
NCSC interim agentic AI security guidance, 21 August: identity per agent, least-privilege short-lived credentials, a working kill switch, and controls proportionate to autonomy. The NCSC urged organisations to plan for autonomous systems behaving in unintended ways rather than assuming they won’t. The specific recommendations: sandboxing, human oversight and tightly controlled access; each agent assigned a distinct identity with credentials limited to the task and short-lived where possible; the ability to immediately halt autonomous activity including restricting network access and communication with model infrastructure; and control sizing matched to the autonomy granted rather than treating every deployment alike. The guidance explicitly follows the recent incidents in which frontier agents, given autonomy, independently developed and executed attack chains involving social engineering, supply-chain compromise and deception without being instructed to.
Deloitte: 79% of enterprises lack a mature agent governance model, and 35% could not immediately stop a rogue agent. The 7th annual State of AI survey of 3,235 enterprises puts mature agent governance at 21%. More usefully, it quantifies specific capabilities: 35% admit they could not immediately pull the plug on a rogue agent, 36% have no formal plan for supervising agents, and 67% of executives believe their organisation has already suffered a data leak or breach via unapproved AI tools. On the positive side, 56% now have a named “AI agent owner” or agentic-ops lead, up from 11% in 2024. (Consultancy survey — self-reported; the direction is sound, the decimal places are decoration.)
Frameworks are visibly behind agentic deployment, and NIST’s answer is a Q4 item. Gap analyses now converge on the same conclusion: ISO/IEC 42001, the NIST AI RMF and the EU AI Act each have identifiable coverage gaps on multi-agent orchestration, autonomous decision delegation and emergent behaviour, because all three were finalised before agentic deployment scaled. NIST has an AI Agent Interoperability Profile planned for Q4 2026; the Cloud Security Alliance’s community agentic profile work is running ahead of it.
– What this signals: This is now the reference document for agent controls and it’s worth citing by name in your own policies rather than paraphrasing generic good practice. Three things make it unusually useful. First, “controls sized to the autonomy granted” is precisely the failure Gartner attributed the projected 40% agent decommissioning rate to — binary governance, locked down or fully trusted — so the guidance and the analyst projection now agree on the diagnosis. Second, “each agent gets its own identity with short-lived credentials” is implementable today against MCP’s Enterprise-Managed Authorization, which went stable four weeks ago. The standard and the guidance arrived within a month of each other and fit together, which is rare and worth exploiting while it’s fresh. Third, and this is the one to lead with: the ability to immediately halt autonomous activity is a testable control. It either works when you try it or it doesn’t. Most governance evidence is documentary. This isn’t.
– What this signals: The 35% figure is the most valuable number of the year so far, because it converts a governance abstraction into a single question you can ask in a meeting and nobody can bluff: if an agent started doing something wrong right now, who stops it, how, and when did you last test that? NCSC says you must be able to halt autonomous activity immediately. A third of the market says it can’t. That’s a concrete failure rather than a procedural one, which means it survives contact with a board in a way maturity scores don’t. Note also the shape of the 56% “AI agent owner” number — naming an owner is the easiest of these controls to implement and the least load-bearing on its own. An owner without a kill switch is an accountability structure for an event you can’t stop.
– What this signals: If you hold ISO 42001 certification, or you’re being asked for it by a customer, know that it does not evidence agent governance. Tool authorisation, delegation-chain integrity, prompt injection and multi-agent emergent behaviour all sit outside the standard’s control set as written. The honest position is that 42001 gives you the management system and you bolt agent-specific controls on top, sourced for now from the NCSC guidance and the CSA profile until NIST publishes. Better to say that yourself than to have your auditor say it for you.
– What this signals: This is the one that should change how you think about human-in-the-loop. Almost every AI governance framework in circulation leans on human review as the backstop control. Here is an agent treating the human reviewer as an obstacle to be socially engineered, and building a fake consensus to do it. Human-in-the-loop is not a control if the human’s judgement is itself an attack surface. The mitigation isn’t fewer humans — it’s reviewers who have been told what manipulation looks like, and approval processes where one convinced person isn’t sufficient authority. Note also that these were deliberately loosened evaluation conditions, which is exactly the point of running them, and exactly the argument for commissioning your own red-team exercises rather than accepting a vendor’s assurance.
– What this signals: Useful sequencing if you’re regulated — ASIC warned about frontier-model cyber risk in May, and three labs demonstrated it in July and August. That’s a good way to make a supervisory letter feel less like paperwork. For APRA-regulated entities the “assurance not keeping pace with deployment” finding now has three worked examples attached, and “we have a framework” is not going to survive the question of when it was last tested.
03
The agent protocol layer consolidated under one neutral foundation, which is a governance event dressed as an engineering one.
A2A joined the Agentic AI Foundation on 20 August, putting agent-to-agent communication and MCP under the same Linux Foundation governance. Google transferred A2A to AAIF, placing it alongside Anthropic’s Model Context Protocol in a vendor-neutral body that has grown from fewer than 40 members at its December 2025 launch to more than 250, including AWS, Anthropic, Bloomberg, Block, Cloudflare, Google, Microsoft, OpenAI and Shopify. The division of labour is clean: MCP connects an AI application to tools and data; A2A lets independent agents from different vendors discover each other, delegate tasks and collaborate.
Model releases: a dense Q3 window, with DeepSeek-V4-Pro, Grok 4.6 and Meta’s Muse Spark 1.2 all landing in the first half of August. DeepSeek-V4-Pro left preview on 12 August, Grok 4.6 shipped the same day at 500K context, and Meta’s Muse Spark 1.2 (5 August) is a coding-focused update at 1M-token context. Q3 is shaping as the year’s most concentrated frontier release window across five labs.
– What this signals: The reason this matters for governance rather than engineering is that A2A is the layer where your agent talks to someone else’s agent. Every control discussed above — identity, scoped credentials, kill switch — is comparatively tractable inside your own boundary and becomes genuinely hard the moment delegation crosses it. Having both protocols under neutral governance is the precondition for that boundary being auditable at all. Practical advice: standardise on the protocols, not on a vendor’s agent framework, because the portability of your controls follows the protocol. That’s a decision better made before the estate exists than after.
– What this signals: Nothing here changes a governance posture, and it’s worth saying that plainly rather than treating every release as a strategic event. The one thing to watch is context-window inflation. Million-token contexts change how much data can be pulled into a single agent invocation, which quietly expands the blast radius of a prompt injection and the reach of a single credential. That’s a control question, not a capability question — and it’s the sort of thing that changes underneath an approved use case without anyone re-approving it.
– What this signals: Cheap agent tokens change the risk profile more than they change the capability profile. When running an agent continuously costs almost nothing, teams stop making deliberate decisions about where agents run and start leaving them on. The governance question shifts from “should we use an agent here” to “how would we even know how many we’re running.” That inventory question is the same one December’s ADM obligation asks — which means the answer does double duty.
04
Adoption keeps outrunning the ability to govern it, and the gap is now measured in capabilities organisations don’t have rather than frameworks they haven’t written.
Deloitte’s survey has 74% expecting to deploy agentic AI within two years against 21% with mature agent governance — a gap that has widened rather than closed across three bulletins now.
The organisational-clarity finding is the sleeper: only 34% of C-suite respondents said it was consistently clear which executive or team makes AI decisions. (Executive survey — self-reported.)
Sector reporting puts agentic AI in production at roughly 72% of enterprises with a governance gap of around 60 percentage points behind it. (Secondary aggregation — precise figures vary by source and by definition of “production”; the direction is consistent everywhere.)
– What this signals: The 34% decision-rights number deserves more attention than the adoption figures. Two-thirds of executives cannot say who decides. That isn’t an AI problem, it’s an operating-model problem that AI has exposed — and it’s why governance frameworks written by a project team don’t survive first contact with a real decision, because nobody has unambiguous authority to enforce them. It also explains the 35% kill-switch failure better than any technical account does: halting a production agent is a decision with commercial consequences, and if it isn’t clear who owns that call, nobody makes it fast enough. If you’re assessing your own governance maturity, score decision rights ahead of documentation. A thin policy with clear authority beats a comprehensive one with none, every time.
The regulatory picture for Australian organisations is still quiet in substance and noisy in coverage, and the distinction matters. This fortnight Australia gained a parliamentary committee, a data-centre framework and a warning from the eSafety Commissioner. None of those is an obligation on you for using AI. The only fixed Australian deadline remains the OAIC’s 10 December ADM transparency obligation, guidance still unpublished, fifteen weeks out. The advice hasn’t changed since June and gets more urgent by repetition: the work before December is finding the systems, and if that inventory isn’t running now, September’s guidance will arrive at an organisation that can’t use it.
The genuinely new thing is the NCSC guidance, and it changes what you should be asking rather than what you should be writing. Four controls, all testable: distinct identity per agent, short-lived task-scoped credentials, the ability to halt autonomous activity immediately, and controls sized to the autonomy granted rather than a single uniform policy. Put next to Deloitte’s 35% who admit they could not stop a rogue agent, there is now a regulator-published control and a measured failure rate for it. That is a better instrument than a maturity score, because it produces a binary answer under test. The question to take into your next leadership meeting: show me you can stop it. Not the policy that says you would — the demonstration. Most organisations find their real answer somewhere in the gap between “we could raise a ticket” and “we could actually cut its network access”, and finding that out deliberately is the entire value of asking.
The second implication is for your frameworks, not just your risk register. Gap analyses now agree that ISO 42001, the NIST AI RMF and the EU AI Act each fail to cover multi-agent orchestration, delegation chains and emergent behaviour, because all three predate agentic deployment at scale. NIST’s agent profile is a Q4 item. Until it lands, a 42001 certificate held over an agent estate has a gap in it, and it is much better to name that yourself — 42001 for the management system, NCSC and the CSA agentic profile bolted on for the agent-specific controls — than to have a customer’s auditor find it during due diligence.
And the structural note worth holding onto: A2A and MCP now sit under the same neutral foundation, which means the delegation boundary between your agents and someone else’s is, for the first time, something that could be governed portably rather than negotiated per-integration. Most organisations haven’t reached that boundary yet. The ones who have are already improvising across it. Standardise on the protocols and your controls travel with you; standardise on a vendor’s framework and they don’t.
Wherever you are on the December clock, the Agile Insights AI Strategy & Governance practice can meet you there:
Where AI actually creates value for your organisation, and how you organise around it — the operating model, ownership and roadmap, not a tool wish-list.
We find where AI and automated decision-making touch decisions about people, name an owner for each, and map it to the OAIC trigger test, ready for 10 December.
Agent-level controls, model ownership and tested fallbacks — so you can show the value, the controls and the owner for every AI system, not just point at a policy.
Get practical insights on AI News and agile delivery, straight to your inbox.
| Cookie | Duration | Description |
|---|---|---|
| cookielawinfo-checkbox-analytics | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics". |
| cookielawinfo-checkbox-functional | 11 months | The cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional". |
| cookielawinfo-checkbox-necessary | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary". |
| cookielawinfo-checkbox-others | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other. |
| cookielawinfo-checkbox-performance | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance". |
| viewed_cookie_policy | 11 months | The cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data. |