Insights

Notes from the regulated frontier.

Writing on AI decisioning, cloud, change and delivery in the industries where trust is the product.

Explaining a decline: the reason is the policy, not your model Regulators in Singapore, Australia and New Zealand all want automated decisions explained to the customer. Most systems answer with the model output. Our view is the explanation that satisfies a regulator and a customer is the policy rule that fired, and what would change the outcome. Four regulators, one artefact: the decision record The audit log usually gets bolted on after the decision engine is chosen, sized to whatever the last review asked for. Our view is that is backwards. The record of a single decision is the most useful thing the system produces, and four regulators are now asking for it in different words. The Privacy Act 2020 and AI: what NZ organisations can actually do with customer data New Zealand has no automated decision-making law like Australia's. It has the Privacy Act 2020, thirteen principles written before generative AI existed, and a Privacy Commissioner applying them to it anyway. APRA and ASIC: frontier AI risk has moved from awareness to action A joint APRA and ASIC statement warns that frontier AI is accelerating cyber threats to the financial system, and calls on boards to move from awareness to action. Decision engine or rules engine? The difference your auditor cares about Rules engines are not automatically safer than models, and models are not automatically riskier than rules. What your auditor actually checks is governance, not architecture. Australia's Privacy Act reforms: what changes for personalisation From 10 December 2026, Australian organisations must disclose automated decision-making in their privacy policies. If you personalise offers, prices or treatments with personal information, that is probably you. What CPS 230 means for automated customer decisions APRA's CPS 230 has been in force since July 2025. If a system makes customer decisions, it now sits inside the operational resilience regime: tolerance levels, provider registers and incident clocks included. MAS FEAT in practice: making AI credit decisions explainable Singapore's FEAT principles have guided AI in financial services since 2018. In 2026 MAS is turning them into supervisory expectations. Here is what explainable credit decisioning actually requires. The EU AI Act's high-risk deadline just moved. Your commercial deadline didn't. The EU has pushed the AI Act Annex III obligations to December 2027. Regulated buyers are not waiting, and neither should anyone selling AI into banks, insurers or utilities.

Let's talk about what you're trying to change.

A 30 minute call. No deck, no discovery workshop. Just the problem and whether we can help.

Book a call