Insights · Compliance
AI governance for founders.
Notes from EO Melbourne's AI in Action session, and why governance is the thing that lets a founder move faster on AI rather than the thing that slows them down.
On 8 April 2026, EO Melbourne ran a session called AI in Action: Real AI Use Cases from EO Members. It was not a panel about what AI might do. Matt Butterworth walked through custom GPTs and agents already running inside his business. Andre Lang had shipped a live product without a developer background. Allan Dib described building a "second brain" to sharpen his own decisions. Vince Lebon moderated. Every example was in production.
I spoke about the layer underneath all of it: data strategy, governance, and platforms that hold up when usage grows. EO's write-up summarised my segment in one line — "Strong governance is what keeps opportunity from becoming risk." That is a fair summary, and it is also the sentence most likely to be misread, so it is worth unpacking properly.
Governance is not the brake.
The consistent message across the room was: do not wait for the perfect AI strategy, start. Governance usually gets heard as the opposite of that — a committee, a policy, a delay. At founder scale it is neither.
The reason a founder can move quickly on AI is that they already know which data the tools may touch, what happens to the output, and who is accountable when it is wrong. That is all governance is. Without it, you move fast right up until the first serious incident, and then everything stops — usually for longer than the governance would have taken.
What actually goes wrong at this size.
Not the failure modes in the newspaper. These four, over and over, in businesses between ten and three hundred people:
- Company knowledge leaves through the prompt box. Someone pastes a client contract, a pricing sheet or a customer list into a personal AI account to get a fast answer. There is no record of what left, and no way to get it back.
- The tool nobody owns. One person builds a genuinely useful custom GPT or agent. They change roles or leave. Nobody knows what it is connected to, what it was told, or whether it is still correct.
- Confident wrong answers reaching customers. The output reads well, so it goes out. The failure is not that the model was wrong, it is that nothing sat between wrong and the customer.
- No test at all. "It seems good" is the entire evaluation. When the model provider updates something under you, nobody notices the quality moved.
None of these need a policy document. They need decisions, made once, written down where people can find them.
Five decisions instead of a framework.
This is the founder-scale version. It should fit on one page, and it should be finished this week rather than scoped this quarter.
01
Name the data that never gets pasted
One explicit list. Customer personal information, signed contracts, unreleased financials, anything under an NDA. Short enough that people remember it.
02
Give every AI tool an owner
A named person per tool or agent, in a one-page register: what it does, what it connects to, who to ask. Unowned tools are how knowledge walks out the door.
03
Decide where a human signs
Anything that reaches a customer, a regulator or money gets a human in the loop. Everything else does not need one. Draw the line deliberately, not by default.
04
Keep the evidence
Retain prompts, outputs and the corrections people make. It is your audit trail if anyone asks, and it is the most valuable training material you will ever have.
05
Test before you trust
Twenty real questions with known-good answers. Re-run them whenever the prompt, the model or the data source changes. Twenty is enough to catch a regression.
That is the whole thing. It grows into a real framework when the business needs one, and nothing in it has to be undone later.
Why the platform question sat next to the governance one.
Data strategy and scalable platforms were in my segment for a reason. Most AI disappointment at this scale is not a model problem. It is that the data the model needs is spread across five systems that each define "customer" differently, so the only way anyone can get an answer is to copy something into a chat window and hope.
Governance and platform are the same job seen from two ends. One decides what is allowed and who is accountable. The other makes the right data reachable, so people are not improvising. Do the first without the second and you have written rules nobody can follow.
What the room actually told me.
I went in expecting to make the case for starting. I did not need to — the room was already running things in production. The gap was not ambition. It was that in most of these businesses, nobody had yet written down who owned the AI that was already working. Governance was the missing half hour, not the missing quarter.
It gets less optional from here. Australia's Voluntary AI Safety Standard sets out the same basic expectations — accountability, records, human oversight, testing — and if you sell to enterprise or government, their procurement questionnaires are already asking. Founders who made these five decisions early will answer those in an afternoon. The rest will answer them during a deal, under time pressure, which is the expensive way.
We do this work with Australian businesses as AI governance consulting, usually alongside data governance so the rules land on a platform that can follow them. If you want to know where you stand before deciding anything, the AI readiness assessment is the fastest way to find out, and our Melbourne AI consulting team runs these sessions with founder groups regularly.
Source: AI in Action: Real AI Use Cases from EO Members — EO Melbourne's write-up of the session, 8 April 2026.
General information only, not legal or regulatory advice. Current as at August 2026.