


An AI assistant that prepares a draft is useful. An AI agent that can also update records, send messages or operate software needs a clearly defined job and boundaries. For Australian business leaders, the next step in AI adoption is deciding which work to delegate, how to supervise it and what evidence will show that it is working.
On 28 September 2026, the National AI Centre published findings from its industry discussions on agentic AI and risk, updated on 29 September. Participants highlighted the importance of the authority organisations give agents and the people who remain accountable. They also questioned whether a human approval step is meaningful without enough training, time and power to intervene.
These are findings informing resources still being developed, rather than a newly finalised compliance standard. Our practical takeaway is to put operating boundaries alongside the business case before a pilot starts.
Earlier in September, ASD released its Agentic AI Harnesses guidance. A harness is the software around an AI model that connects it to data and tools and controls how actions run. ASD explains why permissions, integrations and oversight need attention alongside the model itself.
Choose one recurring task with a clear starting point and a result someone can check. For example, a hypothetical pilot could prepare a weekly summary from approved, non-sensitive service information. Define the intended readers, the required source links and what counts as an unacceptable error. Keep distribution with a person during the trial.
Measure the whole job. Count review and correction time as well as drafting time, and include software usage costs. A fast first draft is not a successful outcome if staff spend longer fixing it. Agree in advance what would justify continuing, changing or stopping the pilot.
ASD’s broader Careful adoption of agentic AI services guidance recommends low-risk, non-sensitive tasks and considering other ways to simplify repetitive work. Use an agent where its ability to handle the task is needed; a simpler workflow may be sufficient.
Ask your IT team to document the exact folders, applications and actions the pilot needs. Reading a document, changing it and sharing it externally are separate permissions. Avoid giving an agent a staff member’s broad access merely because that makes setup easier.
ASD warns that prompt injection can arise when an AI system treats material in documents, web pages or emails as instructions. Instructions telling an agent to behave safely are therefore only part of the design. Restrict available tools and enforce access limits in the surrounding systems.
For the summary pilot, a useful acceptance test is whether the agent can reach an unrelated folder or send the result itself. If either action is outside its job, the test should show it is blocked. Record the result before expanding the trial.
Name a business owner and a reviewer, including cover when that person is away. Define the decisions that stay with people. A request to approve should show the proposed action, affected records or recipients, and enough supporting information to judge it.
Design for a busy working day. If the reviewer cannot establish why a change is proposed, the workflow should pause and ask for clarification. An approval queue that everyone routinely clears without inspection provides little assurance. Test the refusal and escalation paths as carefully as the happy path.
Use a controlled environment and representative, non-sensitive test material. Include missing information, conflicting instructions and a tool that is unavailable. Confirm that the agent reports uncertainty or failure instead of treating an incomplete task as finished.
Decide who can suspend the workflow, how access is revoked and how staff continue the work manually. Keep appropriate activity and approval records, with access and retention controls. Review them after changes to the model, connected software or permissions.
These steps support the phased deployment, validation and monitoring described in ASD’s guidance. They should connect with your existing ICT change and incident processes so the team knows where an AI issue belongs.
Before committing to a wider rollout, bring the business owner and IT team together to review the pilot’s actual results. Identify which errors were caught, which controls worked and what ongoing support will cost. Expand only when the evidence supports the next step.
Zarbtech’s Managed AI services bring together Leadership, Strategy, Software and Hardware. We can help define ownership and success measures, assess suitable workflows, plan a scoped pilot and review the software and infrastructure it needs. For implementation planning, explore our IT project services.
Foundation, our direction for a governed AI workforce, is currently in development. Specific capabilities and availability are assessed for each engagement.
Book a free consultation to discuss a useful first AI workflow and the boundaries it needs.