2026-07-23OPINION · AIGOVERNANCE · CYBERRISK · BOARDROOMACCOUNTABILITY · AIREGULATION · TECHPOLICY5 MIN READ READ
FILED UNDER

OpenAI Supports Australian Regulation Because It Helped Write It

The companies celebrating Australian AI oversight have more to gain from it than Australian organisations do.

When AI Companies Cheer for Regulation, Ask Who Wrote the Rules

Australian boards and executives celebrating the federal government’s move toward AI regulation should pause before treating compliance as protection. It is not. And the reason it will not be is hiding in plain sight.

The Guardian’s recent piece notes that OpenAI and Anthropic have been actively supportive of Australian AI regulation. The comparison drawn is to SpaceX — a company that embraced regulatory engagement as part of a pathway to an $86 billion public listing and a $2.1 trillion valuation. That comparison is not incidental. It is the entire point. These companies are not cheering for Australian rules because they care about Australian outcomes. They are cheering because a compliant, stable regulatory jurisdiction — one they helped design — looks good to institutional investors ahead of a public offering.

Australia is being used as a test market for regulatory legitimacy. That is a fundamentally different thing from being protected by regulation designed for Australian conditions.

The Commercial Logic Behind the Applause

When a company with a dominant market position supports regulation in a relatively small market, the obvious question is: what does the regulation look like, and who shaped it?

Regulatory capture does not require corruption. It requires asymmetric expertise and access. OpenAI and Anthropic have both in abundance. They have policy teams, legal resources, and years of experience shaping narratives about AI risk. Australian regulators — working with limited budgets and under political pressure to remain “open for business” — are in a structurally weaker position at the negotiating table.

The rules that emerge from this dynamic will reflect the risk tolerance and commercial interests of the companies being regulated. They will be framed in language that sounds protective — safety frameworks, transparency obligations, accountability mechanisms — but they will be calibrated to be survivable by the companies writing the submissions. That is not a conspiracy theory. It is how industry-friendly regulation has worked in financial services, telecommunications, and pharmaceuticals for decades.

The difference here is velocity. AI capability is moving faster than any previous technology wave, which means the window for regulatory design to be genuinely independent is narrow, and that window may already be closing.

What Australian Boards Are Actually Relying On

Australian organisations operating AI systems face real legal obligations that exist entirely outside whatever framework OpenAI and Anthropic are helping to design. The Privacy Act reform process is underway. SOCI Act obligations apply to critical infrastructure operators regardless of what vendor a system is purchased from. APRA CPS 234 already requires that information security controls — including those governing third-party technology — meet a standard commensurate with the threat. None of these are satisfied by virtue of a vendor achieving compliance with a nationally designed AI framework.

Yet the pattern in Australian boardrooms is already forming: a new regulation arrives, a compliance checkbox is created, and the checkbox becomes the proxy for adequate governance. This is exactly what happened with the original Privacy Act notification requirements, where organisations treated the existence of a breach response plan as evidence of privacy maturity. It was not then. It will not be now.

If an Australian bank, hospital, or energy operator deploys an AI system that causes material harm — to a customer, to critical infrastructure, or to the integrity of a business process — the question the regulator, the court, and the board will face is whether the organisation exercised adequate judgement. The answer to that question will not be “yes, because the vendor was compliant with the Australian AI framework.” The answer will need to account for what the organisation actually knew about the system’s behaviour, its limitations, and its failure modes.

Compliance with a standard designed to serve a global IPO narrative does not answer that question. It may not even be relevant to it.

The Sovereignty Illusion

There is a broader problem with how Australian government stakeholders are framing this moment. The language around AI regulation frequently invokes sovereignty — the idea that Australia is taking control of how AI is deployed within its borders. That framing is politically useful and analytically wrong.

The systems being regulated are built, trained, maintained, and updated offshore. The model weights, the training data, the fine-tuning infrastructure — none of it sits under Australian jurisdiction in any meaningful operational sense. What sits in Australia is the deployment layer: the interface, the enterprise wrapper, occasionally some locally hosted inference. Regulating that layer while the underlying capability remains entirely outside Australian control is not sovereignty. It is the appearance of sovereignty.

This matters because boards are making procurement and risk decisions based partly on the assumption that regulatory approval or compliance implies some level of national oversight over the technology. It does not. An AI system that passes every test in an Australian framework can still behave in ways that were never anticipated, never audited, and never disclosed — because the disclosures required by the framework were written by the people with the most to lose from full transparency.

What Should Change

Australian boards need to separate two questions that are currently being conflated: whether a vendor is compliant with emerging AI regulation, and whether deploying that vendor’s system is prudent given the organisation’s specific risk profile, legal obligations, and operational context.

The first question will eventually have a relatively straightforward answer. The second question requires the board to actually understand what they are deploying — not at a technical level, but at a governance level. What decisions is this system making or influencing? What are the consequences of a systematic error? Who is accountable when it fails? What contractual rights does the organisation have when the model is updated in ways that change its behaviour?

These are not questions that regulation will answer on your behalf. They are questions that boards are already obligated to ask under existing frameworks, and most are not asking them with anything like the rigour the risk warrants.

The arrival of an AI-specific regulatory framework will, if anything, make this worse — because it will give boards a compliance narrative to hide behind at exactly the moment when genuine scrutiny is most needed.

Watch how the framework develops. Notice who shaped it. And do not let the existence of a checkbox substitute for the judgement that is still, entirely, yours.

Next dossier
Did Your Board Know HR Bought an AI Surveillance Tool? →
Engage the author
Stephen Betros is currently taking on briefs for FY26.
Brief Stephen
Share