It was a pleasure to join the panel on “Integrating and Upholding Secure, Responsible and Resilient Data and AI Systems” at the Government Innovation Showcase New South Wales 2026, alongside Sonia Minutillo, Privacy Commissioner at the Information and Privacy Commission NSW, and Anne McDonald, Executive Director, Regulatory Transformation at Transport for NSW.
One point I emphasised is that AI is changing what we mean by data governance.
Traditionally, data governance focused on datasets: collecting, cleaning and managing them before they were used. But AI systems operate on continuous streams of information. Users upload arbitrary content, AI generates new data, and information is constantly moving between people, models and enterprise systems.
In this world, governance needs to move closer to the point of use.
Rather than relying primarily on processes around datasets, organisations should embed governance into technical control points throughout the AI system: automatically checking inputs, enforcing policies during processing, validating outputs, and monitoring behaviour at runtime.
Privacy-enhancing technologies provide a good example. Sensitive information can be automatically redacted before data is sent to an AI model and reinserted afterwards, allowing organisations to maximise the value of AI while maintaining privacy and security obligations.
As AI adoption scales, governance itself needs to become increasingly operational and automated. The challenge is no longer writing principles. It is translating them into technical controls that work continuously, consistently and at scale.


Leave a Reply