Skip to main content

Governance and GenAI in the public service

Clear oversight and governance of agency use of GenAI can ensure not just responsible spending and timely delivery, but can enable safe, responsible, ethical and effective use.

AI Governance and assurance

Governance and assurance are closely related activities. Understanding the relationship between assurance and governance is important. As some of the existing guidance refers to governance, it’s important in this context to understand the inter relationship between the 2 concepts of governance and assurance.

There’s no single agreed definition of governance. But broadly it involves setting the goals, allocation of resource to achieve those goals, establishment of systems to track progress and management of risk. Assurance is an independent assessment of governance, risk management, and control processes to achieve a specified aim.

What this means is that good governance will establish assurance mechanisms to support the delivery of an outcome for the task or area of responsibility of the governance group. But it’s also possible to have an assurance process that sits above this, which is an assurance system that independently reviews aspects of the work that is governed or sufficiency of governance.

Commit to good governance of GenAI

Agencies should publicly develop and share their GenAI policies and standards to guide its use of AI. Working together will help agencies lift their capability on using emerging technologies like GenAI.

Designate a responsible official to lead adoption of GenAI

Conduct appropriate impact assessments for applications of GenAI

Have human oversight of GenAI use

Transparency and accountability

What to publish about your agency’s GenAI use

AI Governance scenario

Example scenario of governance and GenAI

You’re the responsible official for your agency’s GenAI use. You’re reviewing a proposed use of GenAI based on a risk assessment.

Recognising a likely risk of a privacy breach with potential major severity, you consider this system a high-risk use of GenAI. You ask the staff proposing this AI system to conduct a privacy impact assessment, suggest mitigations, and test it internally before proceeding. These mitigations address the risks assessed, and give you confidence in the benefits and risks of using the proposed GenAI system to proceed.

Related guidance

Utility links and page information

Was this page helpful?
Thanks, do you want to tell us more?

Do not enter personal information. All fields are optional.

Last updated