On 1 September, The Mandarin published a piece by Datacom containing a claim that is easy to skim straight past: since July, every federal government department and agency has been required to appoint a Chief AI Officer. It is very nearly true. The “very nearly” turns out to be the most interesting part — and so does what happened in the two weeks before the deadline.
We went and checked the whole thing: the policy documents, the Department of Finance’s own compliance numbers, and the two occasions where the Auditor-General has actually audited AI governance inside a Commonwealth agency. What emerges is a genuinely impressive piece of public administration, sitting directly on top of a gap that every private-sector board about to copy this move should look at first.
The mandateWhat was actually required, and of whom
The requirement comes from the AI Plan for the Australian Public Service 2025, released in November 2025 with a foreword from Finance Minister Senator the Hon Katy Gallagher. The plan lists four blunt “actions to drive adoption”: everyone in the APS completing training on the fundamentals of AI use; all public servants having access to generative AI tools; all agencies tracking and reporting their AI use; and each agency and department appointing a senior executive as Chief AI Officer. The milestone attached to that first tranche was July 2026.
The scope is narrower than the shorthand suggests, and the difference matters. The underlying Policy for the responsible use of AI in government applies to all non-corporate Commonwealth entities, with exceptions for the defence portfolio and the national intelligence community. Corporate Commonwealth entities are encouraged to apply it, not compelled. That put 106 entities under the CAIO obligation. Of the 74 corporate Commonwealth entities outside it, 18 — around 24% — nominated a CAIO anyway. Commonwealth companies, a group that includes NBN Co and Snowy Hydro, notified Finance of none.
The second piece of precision is the one most commentary loses entirely. A Chief AI Officer is not the agency’s AI risk owner. Every one of these agencies already had an AI Accountable Official, focused on monitoring risk and governance. The CAIO was designed as the deliberate counterweight. Finance’s own November 2025 information pack for agencies described CAIOs as “people whose primary job is pushing opportunity, working alongside those with more cautionary approaches and concerns”.
AI Accountable Official
Pre-existing role. Monitors risk and governance, and enables the agency to adopt AI responsibly by providing governance frameworks. Required under the AI in government policy since 2024.
Chief AI Officer
New role, deadline July 2026. Identifies opportunities, drives adoption and cultural change. Not required to be a technical expert. Attracts no additional pay.
Smaller agencies were permitted to give both roles to the same person, though government preferred them separate. Where they are combined, Finance told agencies the officeholder “need[s] to manage any tensions arising from being both advocate and guardian”, and that expectations and strategies for handling that should be “made explicitly clear”. In June, an ANAO audit revealed that IP Australia had appointed its deputy director general to both roles, precisely because it did not want to create “a dichotomy between driving adoption and engagement with AI and being accountable for governance and risk of AI use”.
A deadline that moved 57 agencies in two weeks
Here is the number that should hold your attention. According to figures published by the Department of Finance, 56 Australian Public Service agencies and corporate entities had appointed a CAIO as at 15 June 2026. By 29 June that number had more than doubled to 113. Of the 106 entities actually mandated, only two had not appointed by 1 July: the Inspector-General of Taxation, expected to confirm shortly after, and the National Environmental Protection Agency, which was only established as an agency on 1 July itself.
Compliance velocity: CAIO appointments across the APS
Read generously, that is a deadline doing exactly what deadlines are for. Minister Gallagher had told Senate Estimates in late May that AI leadership across agencies had been “patchy”, and that the CAIO requirement sought to “drive that leadership and attention to AI, which was apparent in some agencies – but not all”. She was explicit about the standard she had in mind: “You have to treat this like your CIO or your COO, and we need senior people to take it on.” On the measure set, it worked. Near-total compliance across 106 entities is not a trivial administrative achievement.
Read carefully, though, a doubling in fourteen days tells you something else as well. It tells you that for roughly half the affected entities this was a deadline met at the deadline — and that the appointment, not the capability behind it, was what the clock was measuring. Two further details from the same reporting sharpen the point. As of early July, the Digital Transformation Agency had held meetings with AI Accountable Officials but had not yet begun holding meetings with the newly appointed CAIOs, despite having been expected to start earlier in the year. And there is precedent: dozens of agencies missed a February 2025 deadline to publish transparency statements about their use of AI, before the DTA’s Lucy Poole confirmed that all relevant agencies had since complied, with a further 21 agencies publishing voluntarily.
None of that makes the mandate a paper exercise. More than 100,000 of Australia’s almost 200,000 public servants have now completed mandatory AI foundation training, according to Information Age. But the pattern — a bunching at the line, then a lag before the machinery behind the requirement starts turning — is the same pattern that shows up when the auditors arrive.
What the auditors foundTwo audits, one uncomfortable sentence
The Australian National Audit Office has now examined AI governance inside two Commonwealth agencies, and the findings are the most useful evidence available anywhere in this debate — because unlike a survey, an audit involves someone going and looking.
The first, Governance of Artificial Intelligence at the Australian Taxation Office (Auditor-General Report No. 26 of 2024–25, February 2025), found the ATO had partly effective arrangements to support its adoption of AI, across governance, design and deployment, and monitoring, evaluation and reporting. At the time of the audit the ATO had 43 of its own AI models in production. The number that travelled furthest, and deserved to:
The second audit is, if anything, more instructive — because the agency passed. Artificial Intelligence Use in IP Australia (Auditor-General Report No. 43 of 2025–26, published 29 June 2026) found IP Australia’s use of AI in the patent rights process was largely effective. This is an agency that deployed its first AI tool into patent examination in 2018, now runs four AI tools in that process, and whose governance the ANAO explicitly credits as having “matured over time to meet the changing environment”.
And still, the finding: “Strategic oversight of the implementation and associated benefits of AI is not yet fully established.” One of the two recommendations was aimed squarely at improving that strategic oversight. IP Australia agreed to both.
That is the sentence to sit with, because it describes something a new appointment does not fix by itself. Both agencies had governance. Both had accountable people. What the ANAO could not find was a clear line of sight from the AI deployed to the benefits claimed. If the best-audited early adopter in the Commonwealth has not fully established that line of sight after eight years, an executive named in the last fortnight of June has not established it either.
The spilloverThe private sector is copying the homework
Datacom’s report The Emerging Role of the Chief AI Officer in Australia: Building Leadership for Transformation, based on a survey of 507 Australian business and IT leaders, is the research the Mandarin article was built around, and it is worth reading on its own terms. It found 42% of Australian organisations already have a CAIO or equivalent, with a further 21% expecting to appoint one within the next year — almost two-thirds with dedicated AI leadership by 2027. Some 93% expect the role to become a permanent part of executive teams.
Critically, the mandate is doing work well beyond the agencies it binds: 73% of respondents said the government requirement has shaped their own organisation’s approach to AI leadership. As Datacom’s Director of AI, Lou Compagnone, put it: “While many assume government lags on technology, the public sector is taking a leadership role in AI governance. The way departments approach the CAIO role today will shape expectations for AI leadership across both the public and private sectors in the years ahead.”
That is the part that should concentrate the mind. Australian organisations are importing a governance structure from a sector that has not yet demonstrated the structure produces measurable outcomes. And the same survey shows they are importing it into a fairly unpromising starting position.
Australian organisations: the leadership, and the gap behind it
Just 3% of Australian organisations are not using AI at all, and more than four in ten are already scaling it across business functions. Yet fewer than half have embedded AI into an organisational strategy, and 55% describe themselves as cautious or highly risk-averse. Asked to name the biggest barrier to stronger AI leadership, the largest single group — 22% — named risk and governance concerns.
Encouragingly, the role is not being defined as a technology job. Respondents ranked developing an organisation-wide AI strategy and roadmap as the CAIO’s top responsibility (60%), followed by responsible AI governance (50%). Managing vendors and platforms was named by just 9%. Compagnone frames the distinction that follows from that: “Adoption is about introducing AI into existing ways of working. Adaptation challenges organisations to rethink how they deliver services, how decisions are made, how work flows across functions and how value is created.”
We would put it more bluntly. Appointing a Chief AI Officer is an adoption move. Everything hard about the role is an adaptation problem.
The real deadlineWhy December 2026, not July 2026, is the test
In December 2025 the DTA overhauled the Policy for the responsible use of AI in government, and this is where the CAIO role stops being a title and starts being a workload. The updated policy introduces formal governance requirements for individual AI use cases. Agencies must maintain an internal register of all in-scope use cases and assign an accountable owner to each one. Before deployment, agencies must complete an AI impact assessment for every in-scope use case, considering fairness, safety, privacy, transparency, security and human-centred values. Foundational AI training becomes mandatory for all APS staff. Agencies must have a process to address AI incidents, and a pathway for staff and the public to report AI safety concerns.
The DTA’s Deputy CEO for Strategy, Planning and Performance, Lucy Poole, framed the intent precisely: “Strong governance and capability must advance together to be effective in practice.” The commencement is staged: the first new mandatory requirement began on 15 June 2026, with all remaining requirements coming into effect in December 2026.
The four dates that define this
The plan lands
The APS AI Plan 2025 is released, setting the CAIO requirement and a July 2026 milestone. In December, the National AI Plan follows, backed by a $29.9m commitment to establish an AI Safety Institute in early 2026.
First requirement bites
The first new mandatory requirement of the revised AI in government policy commences. On this date, 56 APS agencies and corporate entities have a CAIO.
The naming deadline
104 of 106 mandated entities have appointed a Chief AI Officer. The DTA has not yet begun convening them.
The auditable one
All remaining mandatory requirements take effect: a register of every in-scope use case, an accountable owner for each, and a completed AI impact assessment before deployment.
A named executive is not an auditable artefact. A register of every AI use case, each with a named owner and a completed impact assessment, is. December is the first date on which an outside party can tell the difference between an agency that appointed a Chief AI Officer and an agency that gave one a job.
Why accountability is being mandated at all
Two findings explain the urgency, and we’d ask you to read both with their methods in view rather than as slogans.
MIT’s Project NANDA report The GenAI Divide: State of AI in Business 2025 concluded that around 95% of generative AI pilots were delivering no measurable P&L return, and located the cause not in the technology but in the approach — a failure of learning, integration and contextual adaptation. That headline has travelled a very long way; the study behind it rests on a review of more than 300 publicly disclosed AI initiatives, 52 structured interviews and 153 survey responses. It is directional evidence, not a census, and it deserves to be cited that way.
Gartner, in June 2025, predicted that more than 40% of agentic AI projects will be cancelled by the end of 2027, attributing it to escalating costs, unclear business value or inadequate risk controls. Note what all three of those causes have in common: none of them is a model problem. All three are governance problems.
Set against that, the upside the policy is chasing is real and officially estimated. The Productivity Commission’s August 2025 interim report Harnessing data and digital technology assessed that broader AI adoption could drive up to 4.3% labour productivity growth over the next decade in the market sector — around $116 billion in GDP. The APS AI Plan cites that figure directly, alongside an estimate that by 2030 AI adoption could lift public sector gross value added by 13%, delivering $19 billion in annual value.
Australia is also not alone in reaching for this particular lever. In the United States, OMB Memorandum M-25-21, issued 3 April 2025, requires federal agencies to designate a Chief AI Officer, publish an AI strategy, maintain an AI use-case inventory and apply minimum risk-management practices to high-impact AI uses. What makes the Australian design distinctive is the deliberate split described at the top of this article: an advocate and a guardian, named separately wherever an agency can afford two people.
Our viewWhat separates a CAIO who works from a CAIO who exists
Everything above is sourced. What follows is ours — the pattern we see repeatedly when an organisation creates a senior role to own something the operating model does not yet support. Treat it as practitioner opinion, not research findings.
Six things to get right in the next quarter
- Give the role decision rights, not just a name. A CAIO who can only recommend will spend the year in other people’s steering committees. Write down the decisions this person makes alone, the ones they can veto, and the ones on which they merely advise.
- Build the use-case register as a management instrument, not a compliance artefact. December forces a register with named owners onto the APS, and the private sector will follow the pattern. Build it once, properly, so that it answers “what should we stop?” as readily as it answers “what do we have?” A register that only satisfies an auditor is pure cost.
- State the expected benefit before deployment, not just the harm. The mandated impact assessment covers fairness, safety, privacy, transparency, security and human-centred values. It does not compel you to write down the benefit you expect and go back later to check it. That omission is precisely the gap the ANAO found at IP Australia. Add the benefit statement yourself.
- Keep advocate and guardian separate where you can afford it. Where you cannot, do what Finance told agencies to do: make the tension explicit, and write down how it gets resolved, before it is tested by a live decision.
- Measure adaptation, not adoption. Licence counts, usage dashboards and training completions are activity metrics. They are worth having and they prove nothing. The question that matters is which decisions, workflows or services actually changed shape.
- Publish internally, on a cadence. The transparency statement regime eventually worked because non-compliance became visible. Apply the same mechanic to your own AI portfolio: a standing, circulated report on what is live, who owns it, and what it returned.
The Chief AI Officer Summit in Canberra on 17 September will put many of these questions to the people now holding the role — among them Monita Lal, First Assistant Secretary and Finance CAIO; Samantha Yorke, Chief AI Officer at the Australian Communications and Media Authority; DTA chief executive Chris Fechner; and Tech Council of Australia CEO Dr Kate Cornick. Its afternoon workshop on shaping a future training and capability blueprint for Australian CAIOs is a tell in itself: the role was mandated first, and the definition of competence in it is still being written.
That is not a criticism of the policy. It is a fair description of where we are. Australia has done the hard, unglamorous thing of putting names against AI accountability across an entire public service, faster than almost anyone expected, and the private sector is following. The naming is done. The next eighteen months decide whether it was an org chart change or an operating model change.
Sources, in full
This article was prompted by Datacom’s partner-content piece in The Mandarin, then independently verified against primary sources. Every statistic above is attributed to the organisation that produced it and linked below. The compliance figures come from the Department of Finance via ACS Information Age; the audit findings are the Auditor-General’s; the survey data is Datacom’s. The interpretation, the framing of December 2026 as the decisive date, and the six recommendations are ours alone, and should not be read as the views of any source.
A note on one figure: the training-completion number (more than 100,000 of almost 200,000 public servants) is reported by Information Age as its own understanding rather than as a figure confirmed on the record by the Department of Finance, and is presented here on that basis.
You’ve named someone. Now give them an operating model.
We help Australian organisations turn AI accountability into AI capability — use-case portfolios with real owners, benefit cases that actually get checked, and governance that speeds delivery up rather than slowing it down.
Start a Conversation