Most organisations don't have an AI problem — they have a visibility problem. We bring the guardrails, evidence, and decision ownership that turn AI from a risk conversation into a confident yes.
Staff are already using AI — often invisibly. Boards are asked to approve AI they can't assess. Regulators are moving: enforcement is up, new obligations have fixed dates, and health information sits at the centre of it. Blanket bans push usage underground; blind adoption creates the incidents that end up in penalty proceedings.
Governance is not the brake. Done properly, it's the reason you can move: every AI use case visible, every decision owned, every claim evidenced.
From fear and chaos → clarity, control, confident action.
Independent evaluation of your AI systems — does the tool actually do what the vendor claims, safely, on your population?
Structured adversarial testing of AI applications before your residents' data depends on them.
The frameworks, policies, and decision rights that let leadership approve AI — and prove it to an auditor.
Your facility scored across 8 governance dimensions in 5 business days. Guaranteed to reveal gaps you didn't know you had, or your money back.
Verified against the Australian landscape as at August 2026 — what's in force, what has a fixed date, and what's coming.
Individuals can now sue directly for serious invasions of privacy — raising the stakes of any AI misuse of resident data.
Rights-based Act and seven strengthened Standards. Standard 2 (governance & information systems) and Standard 5 (clinical care) are where AI deployments meet your accreditation.
Civil penalty proceedings live against major providers; a $5.8M penalty in the health sector for security failures. Health information is the enforcement epicentre.
Privacy policies must disclose automated decisions that significantly affect individuals. If AI touches admissions, care planning, or rostering decisions — you have a deadline.
Announced July 2026 with a new Office of AI — legislation expected from 2027. Providers who implement the National AI Centre's 6 essential practices now will already be positioned.
Where AI processing happens is a legal question, not a technical detail. We design AI architectures that keep Australian health data where it belongs.
My Health Record data must not be held, processed, or handled outside Australia. Any AI touching MHR-derived data must be onshore. No exceptions worth testing.
Victoria (HPP 9) and NSW (HPP 14) restrict sending health information outside the jurisdiction without equivalent protections — plus APP 8 accountability for cross-border disclosure.
Frontier models can now run with inference pinned to Sydney (e.g. Claude on AWS Bedrock ap-southeast-2). Enterprise-grade, in-country AI is achievable — consumer AI tools with identifiable health data are not defensible.
For government-adjacent workloads: IRAP-assessed environments and the Hosting Certification Framework. We architect to the standard your data classification demands.
We apply our own governance to our own AI. Every assessment is framework-mapped, every claim carries a receipt, and escalation logic is deterministic — the model can add a warning, never remove one.
AI usage inventory — including the shadow AI nobody put on a register.
Risk assessment across 8 governance dimensions, mapped to the frameworks your auditors recognise.
Guardrails, policies, and decision ownership — governance designed to enable, not block.
Evals, monitoring, and review cadence so approval isn't a one-off event.
GVRN-AI is led by Nathan Bhasker — a healthcare ICT professional with 10+ years across clinical systems, aged-care telehealth operations, and enterprise AI delivery. Everything we recommend, we've built and evaluated ourselves: clinical triage systems with deterministic safety gates, agent systems with published eval results, and governance frameworks running in production.
AI governance is the set of rules, checks, and responsibilities that let an organisation use AI safely. It answers three questions: what AI is being used, who is accountable for it, and how do we know it is working safely. It is not about blocking AI — it is about being able to say yes with evidence.
Yes. Bans rarely work — staff use AI on personal devices instead, which is harder to see and riskier. Sector surveys consistently find a majority of care staff have used AI tools at work. Governance makes usage visible and safe rather than hidden.
A scored assessment of your facility across 8 governance dimensions, a prioritised list of gaps, a board-ready summary, and a 45-minute debrief — delivered within 5 business days. If it reveals nothing you didn't already know, you get your money back.
It depends on the tool. My Health Record data must never leave Australia by law (My Health Records Act s 77). Consumer AI tools generally process data offshore and are not defensible for identifiable health information. Enterprise AI can now run entirely in Sydney — we design architectures that keep Australian health data onshore.
In force today: the Aged Care Act 2024 and strengthened Quality Standards (from 1 November 2025), the Privacy Act including the new statutory privacy tort, and state health records laws. Coming: automated decision-making transparency in privacy policies from 10 December 2026, and legislated Australian Standards for AI expected from 2027.
The AI Risk Assessment takes 5 business days. Governance implementation typically runs 4–8 weeks depending on facility size. Advisory support is ongoing month-to-month — no lock-in contracts.
A 30-minute discovery call. No pitch — just an honest conversation about your AI exposure and what visibility would take.
Book a discovery call