Responsible AI

Control is part of the product.

Responsible AI should help an organisation move—not turn every pilot into a compliance program. The right controls are practical, documented and proportionate to what the system can affect.

Graymatter adapts Australia’s current AI adoption guidance to the job, the organisation and the stage of the work.

Six essential practices

From guidance to working controls.

The National AI Centre provides a foundations version for organisations early in AI adoption and detailed implementation guidance for more complex or higher-risk use.

01

Decide who is accountable

Name the executive owner, workflow owner, system owner and the people responsible for review, intervention and improvement.

02

Understand impacts

Identify users and affected people, how the workflow may help or harm them, and how they can question or correct an outcome.

03

Measure and manage risks

Assess risk for the specific use—not AI in general. Define acceptable use, prohibited use, controls and escalation.

04

Share essential information

Tell users what the system does, where information comes from, its important limits and when they are dealing with AI.

05

Test and monitor

Test representative and difficult cases before launch. Watch quality, exceptions, misuse and change after launch.

06

Maintain human control

Match oversight to consequence. Give people clear pause, override, rollback and shutdown paths.

Source framework: National AI Centre, Guidance for AI adoption: foundations ↗

What appears in the build

A control set you can inspect.

The exact depth changes with risk. These are the practical elements we expect to discuss in a serious pilot.

OWNER

Named accountability

Business outcome, system operation, review and escalation each have an owner with authority.

RECORD

AI system entry

Purpose, users, provider, model, data, limits, risk and current status are recorded.

DATA

Approved information path

Only needed and permitted information is used. Access, retention and third-party handling are understood.

TEST

Evaluation set

Common, difficult, unsafe and incomplete-input cases are tested against explicit criteria.

GATE

Human intervention

Consequential decisions and external actions have clear review, override and stop points.

WATCH

Monitoring and review

Quality, exceptions, complaints, usage, change and cost are reviewed at an agreed cadence.

DISCLOSE

Useful transparency

People know when AI is involved and receive the information they need to understand or contest its role.

FALLBACK

Safe manual path

Critical work can continue when the service is unavailable, uncertain or withdrawn.

Privacy and data

Start with less data, not every data source.

The OAIC says the Privacy Act applies to AI uses involving personal information. The specific purpose, collection notice, disclosure, accuracy, security and cross-border handling may all matter.

  • Use representative, minimised or de-identified information where it can answer the question.
  • Do not place personal or confidential information into public AI tools without an approved basis.
  • Understand provider access, training use, location, retention and deletion settings.
  • Make AI-related collection and use transparent where required.
  • Involve privacy, legal and security specialists where the use warrants it.
Read the OAIC guidance

An important boundary

Graymatter builds responsible working practice. It does not replace specialist advice.

We help identify issues, create records, design controls and bring the right stakeholders into the work. We are not your legal, privacy, cybersecurity, employment or regulatory adviser.

Where an engagement raises material obligations or specialised risk, we will recommend that you obtain appropriate advice and incorporate it into the design.

A practical first conversation

Make the first pilot safe enough to learn from.

Tell us the workflow, the information involved and who could be affected. We’ll help define a proportionate first boundary.

Start with the workflow