Overview
It is one thing to have an AI policy. It is another thing entirely to get your organisation to live and breathe it. AI policy is no longer a box to tick, it is an urgent operational priority.
This course is not another AI awareness session, and it is not Policy Writing 101. It is about the practical work of turning a policy document into daily practice: the levers agencies can pull to drive uptake, the guardrails that keep implementation safe, and the metrics that prove the policy is actually being lived.
Key implementation deadlines are now in effect. Under Australia's updated Policy for the Responsible Use of AI in Government, mandatory requirements are being introduced in stages, with major milestones on 15 June 2026 and 15 December 2026 covering governance, accountability, AI impact assessments, transparency, AI registers and workforce capability.
AI is already inside government. OECD 2026 data show AI is now used in at least one area of government in 97% of OECD countries, while 83% have established an institution responsible for governing AI in the public sector. The shift from experimentation to formal governance is well underway.
The opportunity is significant. Generative AI could contribute AUD $45 to $115 billion annually to Australia's economy by 2030 through productivity gains and workforce augmentation. Realising that value depends on effective governance, disciplined implementation, and strong organisational capability.
New Zealand is also advancing responsible AI adoption. Its AI Strategy, Investing with Confidence, sets out a vision for accelerating AI uptake while helping organisations address privacy, security, workforce capability and value realisation.
Waiting creates more than compliance risk. As agencies increasingly adopt staff AI tools, pilot projects and vendor platforms before appropriate governance is in place, shadow AI, fragmented practices and vendor dependency can become embedded, making future remediation significantly more difficult and costly.
Many agencies now understand why AI matters. What they need is practical guidance on how to make policy stick: how to embed it into existing workflows, how to build the adoption pathways that drive uptake, and how to measure whether the policy is genuinely being lived across the organisation.
This course provides a practical blueprint. Participants will leave with a lever map, an uptake measurement approach, and a staged roadmap grounded in real public sector case studies, templates and reusable artefacts.
Who Should Attend?
Designed for public sector teams that already know AI policy matters and now need to operationalise it.
Policy and strategy teams responsible for agency AI policy scope
Governance, risk and assurance leaders
Program and project leaders responsible for implementing AI initiatives
Digital, data, ICT, cyber security and innovation teams
Operational leaders assessing AI use cases and service impacts
Internal communications and change leaders driving adoption
Also relevant for: Legal and privacy teams, Procurement and supplier management, Board, ARC, executive reporting and enterprise risk stakeholders, HR, workforce planning and capability leaders, CIO / CDO / CEO office stakeholders needing senior visibility on AI, opportunity and risk
Learning Outcomes
By the end of this course, you will be able to:
Break down the mandate: the Commonwealth AI Policy obligations, timeframes and compliance steps, and the artefacts that evidence them
Design a policy people will actually use: written for the operational reader, embedded in existing workflows, and owned at executive level
Choose and sequence the levers that get policy lived: sponsorship, embedding, approved-tool pathways, champions, comms, literacy, attestations and feedback loops
Measure uptake, not just outputs: coverage, capability, behaviour, flow, assurance and sentiment metrics your executive and ARC will actually read
Triage AI use cases for purpose, relevance, benefit, data quality, bias, risk tier and public value before deciding to proceed, pause, redesign or reject
Manage the hard implementation risks: privacy, cyber, shadow AI, sovereignty, vendor dependency, continuity and exit
Prove ROI and public value, even where cost to serve is unclear, and link value evidence back to uptake
Build a staged roadmap that starts small, sequences the levers (not just the tech), and learns from what other agencies are doing
Online Training
AI Policy Implementation
Session details
- Move from policy on paper to policy in practice. Leave with the levers, the metrics and the sequencing to make it real.
- Beat the 2026 deadlines with confidence. Arrive with obligations, leave with a compliance-ready plan of attack.
- Stop drowning in "why," start delivering "how." Convert policy intent into artefacts, registers and adoption pathways your agency can actually run.
- Prove AI's value. Build a defensible ROI and public value case, even where cost to serve is unclear.
- De-risk your rollout. Spot and manage privacy, cyber, bias, sovereignty, vendor and shadow AI risks before they bite.
- Save months of guesswork. Adapt ready-to-use templates instead of building from scratch.
- Learn from peers, not theory. Real public sector case studies and a cross-cohort community of practice you keep after the course.
- Bring your whole team. One shared language across policy, risk, digital, legal, procurement and operational leaders.
Some familiarity with topic is recommended
Key Sessions
Understand the practical requirements, timeframes, and compliance obligations for implementing AI policy inside a public sector agency.
Define the scope of an agency-specific AI policy or framework, so it is specific, usable on the ground, and aligned to the agency’s AI ambitions, risk profile and operating context.
Concept Briefing
Unpacking June/December 2026 mandatory requirements, OECD benchmarks, and three AI maturity stages — experimenting, scaling, and embedding. Introducing the DTA AI impact assessment tool as a mandatory compliance obligation: what it is (a structured 12-section risk and impact assessment), what it produces (an inherent risk rating of low, medium, or high for each use case), and the 15 December 2026 implementation deadline. The tool is the diagnostic input that feeds accountability, prioritisation, and oversight decisions covered in Modules 2, 3, and 4.
Expert Debrief
Unpacking Robodebt’s failure: why automating processes to remove human cost strips away vital governance safeguards and why getting accountability structures right must come before deploying AI. Connecting the DTA tool: a completed impact assessment would have flagged the risks, but without a named person accountable for outcomes, the assessment would have been filed and ignored.
Personal Canvas Update
Attendees map their department’s maturity stage, identify which of their agency’s active or planned AI use cases are in scope of the DTA mandatory impact assessment requirement, and establish initial policy safeguards.
Module Learning Outcome:
Identify the governance artefacts needed for implementation, including AI registers, reporting lines, roles, accountabilities, escalation pathways, assurance checkpoints and evidence trails.
Concept Briefing
The role of committee oversight and its limitations. Establishing a single named executive who owns the outcome — not a committee, not a shared responsibility, but one person whose name is on the decision. Introducing AI policy structures: accountability organised around services or outcomes (not internal divisions), centralised vs decentralised decision-making, accountability layers from the team delivering the work up to the executive owning the portfolio, and rapid escalation pathways.
Connecting the DTA tool’s risk ratings to the accountability structure. The risk rating determines which level owns the decision: low-risk use cases are governed at the team level within existing authority; medium-risk use cases are owned by a named person at the product level who engages directly with the CISO, privacy team, and legal as subject matter inputs; high-risk use cases are owned at the portfolio level because they implicate agency-wide standards — PSPF, APP, the AI policy itself.
Group Breakout
Small groups analyse Scenario 2 and answer accountability mapping questions. Where time permits, Scenario 5 (reserve) is also used.
Expert Debrief
AI failure modes and the cost of slow decisions — how committee-based governance inflates the time between identifying a risk and acting on it. Where Scenario 5 has been used: how a single named person at the product level engages directly with the portfolio-level owner of cross-cutting standards (privacy, PSPF, AI policy) rather than routing through a working group, and how operating rules written into contracts and instruction sets enforce those standards at the point of execution.
Personal Canvas Update
Attendees assign a single named person accountable for outcomes on active departmental AI initiatives. For each initiative, map the DTA risk rating (low, medium, or high) to the accountability level that should own it — team, product, or portfolio.
Module Learning Outcome:
Assess AI use cases through a practical purpose, relevance, benefit, risk, data quality, ROI and public value lens before deciding whether to proceed, pause, redesign or reject.
Concept Briefing
The DTA impact assessment tool answers “have we identified the risks” — it does not answer “should we do this” or “is this delivering value.” This module covers the value question. Measuring outcomes, not just outputs — using Evidence-Based Management (EBM) to assess whether AI investments are delivering real value. Structuring a four-sentence investment case that includes a pre-committed decision rule (what you will do if results come in above or below threshold). Sequencing execution based on the cost of waiting — the value lost every week in a high-value initiative sits in the queue. The DTA risk rating acts as a pre-filter: use cases rated at high inherent risk require additional governance actions under the AI policy before they enter the economic prioritisation queue.
Group Breakout
Small groups review Scenario 3 to size proposals and calculate a value-per-week prioritisation score (Cost of Delay Divided by Duration, or CD3).
Group Playback
Tables present their investment cases, outcome measurement findings, and sequencing decisions.
Expert Debrief
Deconstructing sunk-cost fallacy and implementing decision rules agreed before the pilot starts — Pivot (change direction), Pause (wait for more data), Persevere (continue as planned), or Pull (stop and reallocate).
Personal Canvas Update
Attendees draft four-sentence investment cases for two active agency proposals. For each, confirm the DTA risk rating is complete and note the additional governance actions required if rated high.
Module Learning Outcomes:
Recognise and manage key AI implementation risks, including privacy, cyber security, data management, bias, false positives, supplier risk, sovereignty, ethical use, human oversight and public trust.
Develop a step-by-step AI policy implementation roadmap that starts small, uses case studies and proof points, supports culture change, and balances compliance with responsible AI uptake.
Concept Briefing
Push decisions down to the team — except where the action can’t be undone. The DTA tool’s risk rating determines where the irreversibility boundary sits. For low-risk use cases, the boundary is far downstream and the team governs through its own instruction sets. For medium-risk use cases, the product-level owner defines which specific actions require human sign-off before execution — data leaving the jurisdiction, retention period expiry, model retraining on citizen data. For high-risk use cases, the portfolio-level owner sets the boundary and certain actions may require executive sign-off. Governing what AI agents are and aren’t allowed to do through version-controlled instruction sets that encode the irreversibility boundary. Learning that questions the system design, not just the results — and the three-step structural sequence: diagnose the accountability gap, assign nmed ownership, then pilot under observation.
Group Breakout
Small groups unpack Scenario 4 to isolate technical failure points.
Group Playback
Tables outline their human oversight thresholds and instruction set revisions.
Expert Debrief
Establishing "Start Small and Public" pilots — visible, low-risk, time-limited — and safeguarding the professional capability pipeline so junior staff continue building judgement as routine tasks automate. Human change beyond “communications and training” — why adoption fails when agencies treat change as a broadcast problem rather than a capability, identity, and workflow redesign problem, and what the 90-day pilot needs to include to bring people along rather than drag them forward.
Personal Canvas Update
Attendees finalise their 90-day pilot roadmap and canvas actions. For each pilot, confirm the irreversibility boundary placement based on the DTA risk rating and name the person accountable for enforcing it.
Meet Your Facilitator
Matthew Hodgson
CEO, Zen Ex Machina
Matthew Hodgson is CEO of Zen Ex Machina, which has worked with Australian federal agencies including the ATO, ABS, AUSTRAC, CER and Home Affairs on operating model transformation for over 15 years. He is the author of Evolve: The Operating Model AI Demands (2026) and co-authors the Empiricism at Machine Speed whitepaper series with Dave West, CEO of Scrum.org. Matt leads a hybrid human-agentic team that has provided twelve months of operational evidence on governing AI agents using existing governance frameworks.
Register Today
Join this training for professionals working within the Public Sector
Early Bird
Ends 16 Oct
$A 995
per person + tax $A 200 savingRegular
Ends 30 Nov
$A 1195
per person + taxFor group or payment enquiries or custom training solutions, please contact [email protected]
Can't see what you need?
Download our training catalogue to review all available topics