Skip to content

Government & Public Institutions

Purpose: Preserve public authority, essential services and strategic options as AI capabilities change
Audience: Australian ministers, public service leaders, regulators, agencies and local councils | Time: 20–25 minutes

This page focuses on strategic preparedness for advanced AI systems and possible AGI. It complements—not replaces—current public-sector AI policy, legislation, assurance and operational risk management. National Security remains a separate specialist page for defence, intelligence and security contexts.


Preserving public authority under uncertainty

Australia may experience the consequences of advanced systems developed and controlled elsewhere. What cannot be imported or delegated is public authority: deciding what may be used in essential services, protecting rights, responding to evidence of danger and maintaining public institutions when external systems fail.

Governance is the connecting task—turning technical evidence into lawful decisions, oversight and coordination. Resilience is the part most firmly within domestic control: essential services, institutional expertise and trusted public communication should be able to continue through overseas or provider disruption. Containment and Alignment also matter, but depend more heavily on specialist technical institutions, providers and international cooperation.

Preserve options, not predictions

The practical test is whether government can recognise a change, decide who has authority, act proportionately and keep functioning. Waiting for agreement on an AGI definition or arrival date would defer capabilities that take years to build.


Five decisions that cannot wait for certainty

1. Which options should Australia prepare before they are needed?

Forecasts are useful inputs, but they cannot remove deep uncertainty about advanced AI. A more practical strategy is to compare options, not odds.

This framing, drawn from Joel Predd's reflections on work at RAND's Center for the Geopolitics of AGI, separates action into three categories:

Category Purpose Australian examples
No-regret options Strengthen capability across many plausible futures. Independent evaluation expertise, regulator capability, cyber resilience, dependency mapping, incident learning and exercised service continuity.
Break-glass plans Prepare lawful contingency measures that may be unnecessary or disproportionate under normal conditions. Protocols for coordinated isolation, emergency procurement, continuity of essential services, rapid technical assessment and trusted public communication.
Signposts Define evidence that should trigger review or activation of a contingency. Systems defeating established evaluations, rapidly expanding autonomous access, serious loss-of-control incidents, dangerous capabilities appearing in widely available systems or concentrated dependencies becoming critical.

Break-glass plans should be developed with legal authority, proportionality, time limits, oversight and review designed in—not improvised during a crisis. Signposts need named owners, monitoring sources and a decision process; a watchlist with no activation pathway does not preserve an option.

2. Where should stronger thresholds apply?

Avoid one approval process for every system. Define thresholds using capability, access, autonomy, affected rights, reversibility and the criticality of the function.

Decision context Questions to settle before deployment or wider access
AI assisting routine internal work Is the purpose clear, information handled appropriately, use recorded and a person accountable?
AI influencing benefits, justice, health, education, policing or other high-impact decisions Does a responsible human retain decision authority? Are reasons, records, review and effective contestability preserved?
AI operating in critical infrastructure or essential public services Has it been independently tested? Can it be isolated safely? Is a non-AI fallback exercised and adequately resourced?
A broadly capable or agentic system receiving sensitive access or authority What new failure pathways arise from tools, autonomy and scale? Which body can require further evidence or stop deployment?
Capabilities that may exceed meaningful human supervision Is there a presumption against deployment until assurance, control and emergency arrangements are proportionate to the consequences?

Thresholds should connect evidence to action. Government needs to know which technical result changes a procurement decision, a regulator's posture, an agency deployment or a whole-of-government response.

3. How will technical evidence become an accountable decision?

Australia's AI Safety Institute, within the Department of Industry, Science and Resources, analyses and tests emerging AI capabilities and supports regulators and agencies responding to risks. Its role strengthens the evidence available to government; it does not remove the need for clear authority across the wider institutional system.

Leaders should clarify the connections between:

  • the AI Safety Institute's technical analysis and testing;
  • sector regulators with domain expertise and statutory powers;
  • agencies and public institutions accountable for their own deployments;
  • central coordination and crisis-management bodies; and
  • ministers, parliaments, courts and independent oversight bodies.

For each high-consequence issue, document who assesses evidence, who decides, who can challenge the decision, who can act urgently and who reviews the outcome. Build protected channels for sensitive findings without making secrecy the default for decisions that require public accountability.

Coordination cannot substitute for capability. Sector regulators and agencies need enough internal expertise to interrogate evidence, recruit and retain specialists and preserve institutional memory; otherwise practical authority can migrate to consultants, providers or a central body that lacks the relevant sector context.

4. How will responsibilities connect across Australia?

Advanced AI crosses portfolios and jurisdictions. Commonwealth institutions influence national policy, competition, international engagement and many regulatory settings. States and territories operate major health, education, justice, transport and emergency-management systems. Local councils provide community-facing services, manage local assets and maintain relationships that matter during disruption.

Coordination should provide:

  • clear divisions of responsibility and escalation paths;
  • compatible incident reporting and shared situational awareness;
  • access to scarce technical expertise across jurisdictions;
  • exercises involving policy, operational, regulatory and community participants;
  • liaison between civilian, national security and emergency-management functions; and
  • international exchange of evaluation methods, emerging-risk evidence and incident lessons.

National consistency is valuable where systems and harms cross borders, while local knowledge remains essential for understanding consequences and maintaining trusted services. Coordination should make these perspectives usable together rather than treating one as a substitute for the other.

5. Can government retain control of essential functions?

Map where public functions depend on the same providers, model families, cloud infrastructure, data sources or specialist workforce. Concentration can turn one provider decision, system defect, cyber incident or geopolitical restriction into a multi-agency failure.

Use procurement to require evidence and preserve options, including:

  • disclosure of relevant system and hosting dependencies;
  • notice and testing of material model changes;
  • access to necessary records, logs and evaluation results;
  • incident notification and cooperation;
  • portability of public data and critical workflows;
  • safe isolation, shutdown and recovery arrangements; and
  • credible exit support before dependence becomes difficult to reverse.

Assess total cost of ownership—including switching, exit and capability-loss costs—and use staged pilots where alternatives could reduce concentration without placing critical services at unnecessary risk.

Continuity exercises should test unavailable and untrusted modes. A system may remain online while its outputs become unreliable, manipulated or impossible to verify. Public institutions should retain the people, information, authority and communication channels needed to operate safely in that condition.


Scenarios to exercise

Use the SafeAI-Aus scenarios to expose assumptions and decision gaps. They are planning tools, not forecasts.

Scenario Government questions to test
Power Concentration & Governance Failure Which public decisions or capabilities have become dependent on a small number of providers? What leverage and democratic oversight remain?
Gradual Disempowerment Are institutions retaining expertise and authority, or merely approving recommendations they can no longer challenge?
Critical Infrastructure Which failures cross agencies, jurisdictions or sectors? Who coordinates continuity and public communication?
Information Ecosystems How would government maintain trusted communication, electoral integrity and public participation during widespread synthetic influence or fraud?
Catastrophic Misuse Which capabilities, access pathways and warning indicators require coordinated prevention and response?
Loss of Control Who can recognise, escalate and act when a highly capable system behaves outside meaningful supervision?

Every exercise should end with named decisions: an owner, threshold, capability investment, contingency, legal question or follow-up test.


Questions for your next planning discussion

Use these prompts to explore institutional readiness

  • Which public functions would face materially different risks if an AI system gained greater autonomy, access or scale?

  • Which body has the lawful authority and technical capability to review, restrict or stop the relevant deployment?

  • What evidence or signposts would justify reconsidering a policy, procurement or operational decision?

  • Where do responsibility and dependencies cross Commonwealth, state, territory, local or private-sector boundaries?

  • Could an essential service continue if an AI system remained online but its outputs could not be trusted?


Current operational guidance

Use current Australian policy and SafeAI-Aus core content for present-day implementation:

For connected strategic guidance, return to the Sector Guidance overview, the C·A·G·R framework or the specialist National Security page.


Sources & further reading