When AI Companies Cheer for Regulation, Ask Who Wrote the Rules
Australian boards welcoming the federal government’s move toward AI regulation should be careful about treating compliance as protection, for reasons sitting in plain view.
The Guardian’s recent piece notes that OpenAI and Anthropic have been actively supportive of Australian AI regulation, and draws a comparison to SpaceX, a company that embraced regulatory engagement on the path to an $86 billion listing and a $2.1 trillion valuation. That comparison is doing the real work in the article. Nobody is cheering for Australian rules out of concern for Australian outcomes. They are cheering because a stable, compliant jurisdiction they helped design reads well to institutional investors ahead of a public offering.
Being used as a test market for regulatory legitimacy is a different proposition from being protected by regulation built for local conditions.
The Commercial Logic Behind the Applause
When a company with a dominant market position supports regulation in a relatively small market, the obvious question is: what does the regulation look like, and who shaped it?
Regulatory capture does not require corruption. It requires asymmetric expertise and access. OpenAI and Anthropic have both in abundance. They have policy teams, legal resources, and years of experience shaping narratives about AI risk. Australian regulators — working with limited budgets and under political pressure to remain “open for business” — are in a structurally weaker position at the negotiating table.
Rules produced under that dynamic tend to reflect the risk tolerance of the companies being regulated. The language will sound protective — safety frameworks, transparency obligations, accountability mechanisms — and it will be calibrated to remain survivable for the organisations writing the submissions. There is nothing conspiratorial in saying so. It is how industry-friendly regulation has worked in financial services, telecommunications and pharmaceuticals for forty years.
The difference here is velocity. AI capability is moving faster than any previous technology wave, which means the window for regulatory design to be genuinely independent is narrow, and that window may already be closing.
What Australian Boards Are Relying On
Australian organisations operating AI systems face real legal obligations that exist entirely outside whatever framework OpenAI and Anthropic are helping to design. The Privacy Act reform process is underway. SOCI Act obligations apply to critical infrastructure operators regardless of what vendor a system is purchased from. APRA CPS 234 already requires that information security controls — including those governing third-party technology — meet a standard commensurate with the threat. None of these are satisfied by virtue of a vendor achieving compliance with a nationally designed AI framework.
The boardroom pattern is nonetheless forming already: regulation arrives, a compliance checkbox is created, and the checkbox becomes the proxy for governance. We watched this happen with the original Privacy Act notification requirements, when organisations began treating the existence of a breach response plan as evidence of privacy maturity. It was not evidence of much then, and it will not be here.
If an Australian bank, hospital, or energy operator deploys an AI system that causes material harm — to a customer, to critical infrastructure, or to the integrity of a business process — the question the regulator, the court, and the board will face is whether the organisation exercised adequate judgement. The answer to that question will not be “yes, because the vendor was compliant with the Australian AI framework.” The answer will need to account for what the organisation actually knew about the system’s behaviour, its limitations, and its failure modes.
Compliance with a standard designed to serve a global IPO narrative does not answer that question. It may not even be relevant to it.
The Sovereignty Illusion
There is a broader problem with how Australian government stakeholders are framing this moment. The language around AI regulation frequently invokes sovereignty — the idea that Australia is taking control of how AI is deployed within its borders. That framing is politically useful and analytically wrong.
The systems in question are built, trained, maintained and updated offshore. Model weights, training data, fine-tuning infrastructure: none of it sits under Australian jurisdiction in any operational sense. What sits here is the deployment layer — the interface, the enterprise wrapper, sometimes local inference. Regulating that layer while the capability underneath stays entirely outside Australian control produces the appearance of sovereignty and very little of the substance.
This matters because boards are making procurement and risk decisions based partly on the assumption that regulatory approval or compliance implies some level of national oversight over the technology. It does not. An AI system that passes every test in an Australian framework can still behave in ways that were never anticipated, never audited, and never disclosed — because the disclosures required by the framework were written by the people with the most to lose from full transparency.
What Should Change
Australian boards need to separate two questions that are currently being conflated: whether a vendor is compliant with emerging AI regulation, and whether deploying that vendor’s system is prudent given the organisation’s specific risk profile, legal obligations, and operational context.
The first question will eventually have a relatively straightforward answer. The second question requires the board to actually understand what they are deploying — not at a technical level, but at a governance level. What decisions is this system making or influencing? What are the consequences of a systematic error? Who is accountable when it fails? What contractual rights does the organisation have when the model is updated in ways that change its behaviour?
No regulation is going to answer those on your behalf. Boards are already obliged to ask them under frameworks that exist today, and most are asking with nothing like the rigour the exposure warrants.
An AI-specific framework may well make that worse, by supplying a compliance narrative to stand behind at precisely the moment independent scrutiny would be most useful.
Watch how the framework develops and pay attention to who shaped it. The judgement it appears to relieve you of is still, entirely, yours.