The Governance Gap: What the Safety Report Doesn't Tell Boards
8 July 2026 · 11:12 am–11:17 am · Cullen
The International AI Safety Report sets the risk landscape. But between frontier risk research and safe AI deployment sits an unaddressed layer — organisational governance. Most boards of mid-size organisations are making AI adoption decisions today, without the oversight structures the report implicitly assumes exist. This talk focuses on that gap with a practitioner's lens.
Recording
Audience Q&A
Ask a question or upvote others.
Loading questions…
Transcript
Hi everyone. My name is Bernadette Harkin. I'm going to talk to you about something completely different to the previous two presenters that were absolutely fascinating. So thank you for that. I have an advisory business. I work with boards and leadership teams on AI governance, and whilst that might seem like a bit of a boring topic, it's really important because everything that we're discussing here at the AI Safety Forum ends up in the humble Australian organisation and needs to be implemented, and that's where I belong. What I'd like to talk to you about is Minding the Gap.
And if you've ever stood on a platform waiting for a train, you know that phrase. It's a warning about the space between you and where we are and where we need to be. I want to talk to you about a different gap, one I discuss almost every day — the space between choosing an AI governance framework and actually governing AI. Because here's the thing: choosing a framework shouldn't feel like picking a side. But for a lot of boards right now, that's exactly what it feels like.
As examples, there's the National AI Centre's AI six guidelines, OECD principles, a technology risk lens and other industry body recommendations. Just for starters. And that's before you even get to the sector-specific standards and the international instruments and things like the AI Safety Report. Each one's credible, each one's asking for attention, and none of them quite fit together out of the box. The question I hear most often isn't, should we govern AI? The question is, how should we do it? And which framework should we actually use?
And that question on its own is a trap. Let me bring in some context. The International AI Safety Report sets out the risk landscape we are all operating in. It's substantial and it's evolving. For larger organisations with dedicated risk and technology practices, understanding it and acting on it is within reach. But for mid-size organisations — and there are a lot of you in the room who influence those organisations and provide recommendations to them — the question becomes, how do I move forward in this age of frontier technologies with the resources I actually have?
So if you think about organisations like the size of Bendigo Bank, for example, how do they actually move forward with what's on top of them right now? The report raises something fundamental. Organisations are at the mercy of how these models are trained and how they reason. They're also at the mercy of how some of the bigger software platform providers, the SaaS providers, are actually embedding AI agents into their systems now. So there's a lot of third-party risk out there for them as well. That creates real questions about reliability and consistency, which makes deployment high risk if performance isn't properly controlled and observed.
And the competitive pressure — the report actually notes that it suggests models could potentially provide research-level performance across specialised scientific domains within the next few years. Imagine that in the hands of your competitor — that's a serious threat to any organisation right now. And if they don't move forward, identify the risks, work on the mitigations. The report identifies misuse, malfunction, systemic risk, and they're not going away. And traditional risk management processes weren't built to capture them. So where does this leave a mid-size organisation or a mid-sized board?
If not choosing a framework off the shelf, it leaves you needing to hold several things at once — and they're fundamental to how you operate. Now it comes back to who you are. Your core values, your mission, your purpose — not reducing any of that down to an assessment of what a particular AI model might do. Your organisational purpose, your mission, actually requires a view which no external framework can define. Your stakeholders — what do they actually expect from you? So the potential solution is not to set
just against those frameworks I mentioned earlier. It's to blend them. You take the guidance, the principles, the technology risk lens, whatever applies to your sector and you read them through your purpose. What's your reason for being? That's what turns a generic framework into something that actually fits your organisation. That's the work — not compliance in one document, but interpretation across all of them. Applied to your organisation specifically, done well, it produces something very valuable — a balanced, restrained approach to deployment, not paralysis and not recklessness.
I believe that most organisations need professional support to do that, not to hand a board a framework and say, go ahead. And we need those skills here in Australia to maintain our competitive advantage and our organisational culture, and not become a cookie-cutter version of somewhere else. The AI Safety Forum and legislators around the world are continuing to do vital work trying to tie these models down to make them more predictable, observable, and responsible. I welcome that work and it needs to continue. But let's be honest about where we are today, on a journey that's already left the station — until I find a better descriptor.
The frameworks are not the gap. The gap is what happens after you read them. So mind it. Thank you.
