Constitutional governance audit

Auditable AI governance for Australian businesses.

Three voices weigh each AI-assisted decision; a human authorises it; the outcome is sealed into an append-only record you can produce later.

A person authorises every governed step. Nothing is recorded without sign-off.

Auditable authorisation policy · tamper-evident governance audit · human-in-the-loop gates.

10 DEC 2026

APP 1.7–1.9 take effect

From 10 December 2026, your privacy policy must say when a computer system makes or helps make decisions about people. You need to write this down before that date.

EU AI ACT

Article 50: transparency obligations

If your AI systems reach people in the EU, providers and deployers must tell them when they are dealing with AI, and AI-made content must be marked. Australian firms with EU customers can be in scope.

EVIDENCE

What you'll need to show

A written authorisation policy, a record of who approved each AI-assisted decision, and the disclosure wording you actually published. Kept so a reviewer can read it later.

How it works

ONE LIGHT · THREE VOICES

Three voices, one record.

The beam splits once. Each colour is a distinct duty, and each leaves its own line of evidence.

  1. 01 · VISION

    Deliberate

    A three-spectrum council examines the decision from distinct viewpoints.

  2. 02 · INTEGRITY

    Gate

    Nothing proceeds past a governance check without authorisation; a human decides.

  3. 03 · ADVOCATE

    Record

    Every step lands in an append-only Truth Ledger you can produce as evidence.

Evidence

The ledger is the deliverable.

One row per governed step: what was asked, which gate applied, who authorised it, a hash over the row’s own contents, and a server signature over that hash.

truth_ledger · row shape

ts         2026-12-10T09:14:02+10:30
actor      h.reid
action     disclosure.publish
gate       integrity / authorisation
decision   authorised — reviewed 2 min
policy     app-1.7-disclosure v1.0
row_hash   2676a8f5b0a88a94553062bc738ec9b5…
signature  nL9tZty9DmPy+4byyJuH…

Written once. Readable forever. Never overwritten.

Append-only · human sign-off · rows hashed and server-signed on write · configured, not serving

For accountants, lawyers and MSPs.

Your clients will ask what to write in their privacy policy before 10 December 2026. The audit gives you a structured way to answer: a short engagement, a written authorisation policy, and a ledger extract your client can keep on file.

Governance notes.

What changed in Australian and EU AI rules, in plain language.

Subscribe on Beehiiv

Email only, at most one message a month, unsubscribe any time.

Signing up happens on Beehiiv, our newsletter provider — this link leaves sovereignnexus.ai, and your address is entered there, not here. A confirmation email follows before anything is sent.