Constitutional governance audit
Auditable AI governance for Australian businesses.
Three voices weigh each AI-assisted decision; a human authorises it; the outcome is sealed into an append-only record you can produce later.
A person authorises every governed step. Nothing is recorded without sign-off.
Auditable authorisation policy · tamper-evident governance audit · human-in-the-loop gates.
10 DEC 2026
APP 1.7–1.9 take effect
From 10 December 2026, your privacy policy must say when a computer system makes or helps make decisions about people. You need to write this down before that date.
EU AI ACT
Article 50: transparency obligations
If your AI systems reach people in the EU, providers and deployers must tell them when they are dealing with AI, and AI-made content must be marked. Australian firms with EU customers can be in scope.
EVIDENCE
What you'll need to show
A written authorisation policy, a record of who approved each AI-assisted decision, and the disclosure wording you actually published. Kept so a reviewer can read it later.
How it works
ONE LIGHT · THREE VOICES
Three voices, one record.
The beam splits once. Each colour is a distinct duty, and each leaves its own line of evidence.
- 01 · VISION
Deliberate
A three-spectrum council examines the decision from distinct viewpoints.
- 02 · INTEGRITY
Gate
Nothing proceeds past a governance check without authorisation; a human decides.
- 03 · ADVOCATE
Record
Every step lands in an append-only Truth Ledger you can produce as evidence.
Evidence
The ledger is the deliverable.
One row per governed step: what was asked, which gate applied, who authorised it, a hash over the row’s own contents, and a server signature over that hash.
truth_ledger · row shape
ts 2026-12-10T09:14:02+10:30 actor h.reid action disclosure.publish gate integrity / authorisation decision authorised — reviewed 2 min policy app-1.7-disclosure v1.0 row_hash 2676a8f5b0a88a94553062bc738ec9b5… signature nL9tZty9DmPy+4byyJuH…
Written once. Readable forever. Never overwritten.
Append-only · human sign-off · rows hashed and server-signed on write · configured, not serving
For accountants, lawyers and MSPs.
Your clients will ask what to write in their privacy policy before 10 December 2026. The audit gives you a structured way to answer: a short engagement, a written authorisation policy, and a ledger extract your client can keep on file.
Governance notes.
What changed in Australian and EU AI rules, in plain language.
Email only, at most one message a month, unsubscribe any time.
Signing up happens on Beehiiv, our newsletter provider — this link leaves sovereignnexus.ai, and your address is entered there, not here. A confirmation email follows before anything is sent.