All 10 NSW government agencies examined for their use of artificial intelligence keep an AI register. But only four of them record the AI they have formally assessed. The rest of their AI use sits outside any inventory.
The finding comes from Internal controls and governance 2026: grants, consultants, purchasing cards and technology. The report analyses internal controls at the 26 largest NSW agencies, which account for about 91 per cent of the state's 2025-26 budgeted expenditure. Technology governance was examined at 10 agencies with more significant AI use, alongside grants administration, consultants and purchasing cards. https://www.audit.nsw.gov.au/
The audit found AI adoption running ahead of the arrangements meant to control it. Only half the selected agencies have a formal AI strategy. Only half have an agency-level AI policy, with the remainder relying on the whole-of-government ethics principles or still drafting their own.
Half have not fully embedded AI-specific risks into existing governance frameworks. Of the 10 agencies, five had reviewed their risk management framework for AI and four had revised IT policies and procedures. Just one had considered AI in procurement documentation and contracting.
Cost visibility is similarly thin. Most agencies do not centrally track AI spending or set budgets for it. The report notes that AI pricing is shifting from per-user licensing to consumption models driven by token usage. Token prices and volumes can be volatile. Agencies without central tracking may not see the bill coming.
Assessment framework applied unevenly
Of 15 AI projects reviewed, 13 had been assessed under the NSW AI Assessment Framework. Two were not, because the framework did not exist when the solution was implemented. Four had no cyber risk assessment.
Retrospective assessment is not required, but current guidance expects the framework to be applied across the whole solution lifecycle. The Audit Office says existing AI solutions therefore need to be assessed against current guidance. It states that the gaps reduce confidence that agencies have adequately tested the tools they have deployed.
Agencies also flagged their own barriers. They include data classification and privacy difficulties, low AI literacy among staff, use of unauthorised generative AI tools, and integration with fragmented legacy systems.
The report recommends that by 30 June 2027 agencies assess all required AI solutions against the NSW AI Assurance Framework. It says the framework should then guide lifecycle management. That echoes the 2025 report, which recommended agencies create a central AI inventory and establish an AI policy.
The report includes a case study of Transport for NSW's automated enforcement of seatbelt offences. It was one of the first projects reviewed by the AI Review Committee. Most images are never seen by a human, images without offences are deleted promptly, and escalated images are cropped and pixelated. At least three human decision-makers review every potential offence before an infringement issues.
The Audit Office draws a general lesson from it. "The principles for governing AI are also features of good public administration," the report states.
"The presence of AI may increase the need for discipline, but the underlying principles apply to any program that affects people's rights, obligations or access to services."
Cyber compliance still short
Analysis of 2024-25 reporting by the 71 agencies that report to Cyber Security NSW found most did not comply with the Cyber Security Policy. More than half have not implemented the mandatory 'govern and identify' and 'protect' requirements. Some remediation plans are at least four years from achieving compliance.
Thirty-three agencies reported 128 significant, high and extreme residual cyber security risks. Of the 10 agencies examined in detail, three had not formally assessed the risks attached to each legacy system. Two had not implemented compensating controls for systems that can no longer be patched.