5 min readAI, Governance
Regulate the record, not the model
Australia is writing its AI rules. The useful ones will not be about how big a model is. They will be about what a deployer can show afterwards.
By Dave Tormey
Australia is in the middle of deciding how to regulate AI. Having built systems for government under existing security regimes, and with my own submission to the parliamentary inquiry nearly finished, here is the argument in plain words.
Model rules age badly
Rules written about the model itself, its size, its training data, its benchmark scores, are out of date before they are printed. The models change every few months. The organisations deploying them cannot see inside them and mostly should not have to.
What does not change is what an organisation can be asked to show after the fact. That is where useful rules live.
Four things a deployer should always be able to show
Whatever the system, whoever built it, the organisation running it should be able to produce, from a log rather than a policy document:
- What the AI accessed. Which data, which systems.
- What rules it followed. Which policies were applied at the point of execution, not described in a PDF.
- What evidence supports each output. Where each finding came from, or an honest "not found".
- Who approved the result before it took effect.
Call that the evidence record. If a deployer can produce it, an auditor, a regulator or a court has something to work with. If they cannot, no amount of model certification helps, because nobody can say what the model actually did in the case in front of them.
Why this is the practical option
It is technology-neutral. It applies equally to a chatbot, a coding agent and a claims pipeline, and it will still apply to whatever arrives next year.
It is checkable. An auditor does not need to understand transformers to read a record of what was accessed and who signed off.
It is already how we regulate other consequential systems. Aviation does not certify pilots' judgement; it requires the black box and the checklist. Financial services do not regulate traders' intuition; they require the audit trail.
And government has the lever already in hand. Commonwealth procurement can require an evidence record and a human approval gate on consequential decisions from any supplier, today, without waiting for legislation. Buyers set standards faster than parliaments do.
Two things that would make it work better
First, a common definition of a serious AI incident, so that when something goes wrong everyone agrees it counts and reports it the same way. Europe has one under Article 73 of its AI Act; ours should be interoperable with it, because Australian companies will be selling into both.
Second, a machine-readable format for the evidence record, so that regulators and the AI Safety Institute can read records from many deployers without a bespoke integration each time. Standardise the record, not the model.
What this asks of vendors
It asks them to build the controls into the software: permissions enforced at execution, evidence attached to outputs, approval gates on anything that matters, a log of everything. Some will say that is expensive. It is less expensive than the alternative, which is deploying systems nobody can explain and finding out in front of a committee.
I have watched an experienced estimator check thirteen values from an AI system against his own drawings, every one either cited or handed back as a question, and sign it off himself. That is what an evidence record looks like in practice. It is not exotic. It is just what we should expect.