So I Guess We're Lobbyists Now
Why we published the missing pieces of Australia's AI standards, in the open - and what that makes us.
On 15 July 2026 the Government announced it would build Australian standards for AI. An Office of AI inside the Prime Minister's department, an AI Safety Institute already testing frontier models, existing regulators handed strengthened powers, legislation flagged for early 2027, and a consumer safety priorities statement due within weeks. We watched the announcement the way anyone in this line of work watches these things - reading the releases, opening the speeches in tabs, and starting, more or less involuntarily, to map it.
The map is in the kit if you want the working: what already existed, what the act will almost certainly assemble from the voluntary stack given teeth, and where the gaps are. Nothing in the predicted act is new. It is the pieces that have been sitting on the table since 2024, finally picked up. That is not a criticism. It is the normal way a framework gets built, and it is a good sign that it is being built at all.
But mapping it produced a second, less comfortable thought, and this post exists because of it.
Before any of the detail
Before any of the detail, take stock of where we actually are. Right now, as routine and not as hypothesis, doctors, lawyers, engineers, public servants, defence operators and more than a few politicians are using a chat window for decision support on matters with real consequences. And the position we have all somehow accepted is this: no audit trail worth the name. No traceability from a conclusion back to what produced it. No structural guarantee that only deliberate actions are taken. No way to state which capabilities a system is authorised to exercise, for whom, until when. And the data of all of it handed across to a handful of firms that have taken enormous financial risks - and at times acted recklessly - with no means of requiring them to attest to the security or behaviour of the systems we are feeding.
Say it out loud and it is bizarre. Every professional in that list is individually licensed, examined, insured and answerable for their decisions. The system now sitting in the middle of their decisions is none of those things. We would not accept this arrangement from a drug, a vehicle, or a bridge - we would not accept it from a junior employee - and we have accepted it here mostly because it arrived quickly and the controls sounded like someone else's job.
The measures the standards will need are not exotic. Audit, traceability, deliberate action, authorised capability, attested systems - these are the boring, adult controls every other consequential industry already runs. It is a ridiculous position we are in, once you look at it squarely. We can do better, and most of the doing is already written down.
What we did instead of booking meetings
The ordinary response to a consultation window is to book meetings. Get in early, get in the room, put a view. We are a small firm without an established government relationship, which is one reason we did something else, and we give the other reason later in this post.
What we did was write the missing pieces and publish them. All of them, dated and attributed, before any consultation opened:
- A defined-terms glossary, written to be lifted into drafting instructions and standards - the terms named by their mechanisms, so an obligation drafted with them has something an auditor can point to.
- A model instrument for data governance and consent - draft legislative text, not a wish-list, with a running reference implementation behind the parts marked as running.
- A conformity test procedure, a schema annex, an explanatory companion and a drafting-instructions template - the machinery that turns a good idea into an assessable one.
- Pages on sovereign capability and civic compute, a comparison against the other jurisdictions, a short list of things doable without legislation at all, and a reader's guide so none of it needs a phone call to navigate.
Each piece is also its own page, versioned and dated. Two links do the heaviest lifting. The first is our capability-licensing research, published before the 15 July speech and before this campaign existed - which is the strongest answer we can give to "who wrote this and why". The work is a standing programme, not a response manufactured to chase a policy window. The second is the provenance page on determination authorship, where the single most reusable idea in the kit already runs as software: every determination has an author, recorded as a first-class fact, with the machine-generated conclusion held structurally distinct from the human decision. The whole policy stack - human oversight, contestability, the automated-decision reform agenda, the findings of the Robodebt Royal Commission - converges on that one requirement, and no published document had yet specified it as a schema. So we specified it, built it, and deployed it.
If this looks familiar, it should. A map of the policy terrain, a mock act, model instruments, an explanatory companion, talking points in the format the office already uses - this is, almost exactly, the work product a consulting firm or a government-relations shop assembles for a paying client. The difference is where it normally goes. That version arrives privately, after the meeting, after the golf, with the client's logo on the cover and the sources left off. We did the same work and put it on the internet - dated, attributed, and free for anyone, including the people it argues with.
How text actually gets into law
Here is the part that made the title unavoidable.
Legislation is not written the way people imagine. The operative words in an Australian act are drafted by the Office of Parliamentary Counsel from instructions, not from clauses handed over by outsiders. But standards, schedules and the instruments beneath an act are a different story: industry associations draft codes, model instruments travel from submissions into drafting instructions almost intact, and exposure drafts are the one moment external text meets official text in public. There is nothing improper about this. The Online Safety Act's industry codes work exactly this way. Externally drafted model standards are the design, not a loophole.
Put plainly, what we are doing is: working the layer where outside text survives into law. That is lobbying, in the plain sense, even if the federal Register of Lobbyists - which covers third-party lobbyists acting for clients, not an organisation publishing its own views - would not have us. 1
The difference we are betting on is not that we are above the process. It is the direction we face while we work it. Publishing everything, attributed, before consultation opens is cover, and it is the one move the better-resourced participants in this process cannot match. The same accountability question our software answers about a determination - who decided - is the question a drafting process is now under pressure to answer about its own text. So we applied the discipline to ourselves first.
Where we think you'll object, and what we'd do about it
We have tried to write the objections better than we expect to receive them. If we have missed yours, the contact page works. The way out matters more than the rebuttal - so each of these keeps your concern intact rather than asking you to concede it.
"You're a vendor arguing for your own architecture." True, and the reason everything here is published rather than pitched. The pattern is separable from us: the definitions, the schemas, the model instrument and the research are all open, and the reference implementation can be adopted, forked or reimplemented without a single conversation with us. If the work is only persuasive when we are in the room, it should not persuade you.
"The cryptographic machinery is research-grade, not procurement-grade." Parts of it are, and our own research pages say which parts, including the negative results. The way through: standards should require the property, not the mechanism. Write "provenance records must be verifiable by a party that does not trust the record-keeper" and "revocation must actually stop further use", and let conformity recognise a maturity ladder - declarative records as the floor today, attested implementations as they mature. The standard names the destination; it should not mandate this year's road.
"A general data-grant instrument cuts across the Privacy Act reforms." It would, drafted as new primary rights. Draft it instead as a record schema in a standard - what a well-formed consent is as a record: who, what data, what purpose, until when, revoked how - with an interface clause to the Privacy Act. It does not create new rights; it makes existing consents inspectable objects instead of collection-time rituals.
"A never-automate list is undraftable." The list is short precisely because it is drawn by decision type, not technology: decisions over liberty, the use of force, the exercise of mercy, and the framing of law itself. Parliament already accepts that some decisions are non-delegable. Put the list in an instrument with a statutory floor, review it on the act's three-year cycle, and the chilling-effect concern becomes a maintenance task rather than a reason to have no list.
"Citizens revoking access would break tax, courts and policing." The design concedes this, structurally. Consensual services, where the person holds an enforceable veto; coercive functions, where they do not, and where the trade is due process instead - compelled access warranted, scoped, logged, and provable after the fact if abused. That is not a constraint on lawful compulsion; it is what makes lawful compulsion demonstrably lawful.
"Cryptographic erasure conflicts with record-keeping obligations." It does, which is why erasure is the top rung of a ladder, not the default. Advisory revocation, access-gated revocation, erasure - a standard chooses the rung per context, and where retention is mandated, the access-gated rung with audit applies. The hard question of escrow and break-glass for the erasure rung remains open, and we would rather it be settled in your consultation than in our repo.
"Compliance cost lands on small deployers." Under the auditor-and-paperwork model, always. That is the model to avoid. An open reference implementation makes compliance the cheap path, and machine-verifiable conformity replaces recurring audit fees with a certificate check. The organisations that should fear this framework are the ones whose compliance currently exists only as paperwork.
"A member-owned data union is a new institution, and new institutions get captured." Australia has run collective rights administration for decades - collecting societies under declared-scheme recognition are settled law. The union is that form with the membership inverted and non-capturability as a design requirement: member-governed, unable to read member data, quorum-controlled destructive operations. Start it as a declared scheme under machinery that already exists.
"You can't regulate a plume of smoke"
There is a fatalism worth answering, because it does more quiet damage than any lobby. This week a former minister compared regulating AI to regulating a plume of smoke - not something he was sure was even possible, so why try. 2 It is a comfortable thing to say and a reckless thing to believe. We legislate weapons, medicines, vehicles and financial advice knowing full well the rules will be broken - the purpose of a law was never to make the prohibited thing impossible, it is to make it accountable and to give everyone else a standard to hold. Nobody argues we should repeal the firearms laws because criminals still get guns.
And a plume of smoke is the wrong picture anyway. Smoke cannot be licensed, audited or revoked. A system can: it runs on hardware someone owns, from weights someone holds, producing records someone can sign. "You can't regulate it" is not a finding about the technology. It is a decision to hand the drafting to whoever is least troubled by being regulated - and it tells every citizen there is nothing to be done, which is both untrue and precisely what the best-resourced participant in this process would like them to believe. Giving up before the first draft is not realism. It is the most useful thing you could possibly do for the people hoping you will.
The other lobbyists
We are not the only ones who understand that the fight moves to the instruments. The difference is that the platforms will attend the standards consultations with more staff and better access, and the public record already shows the shape of the case they will make.
It is worth citing, because the force here comes entirely from what has already been said. The Tech Council of Australia told ministers, in a brief released under FOI, that the current regulatory system is sufficient for AI. The Business Software Alliance opposed mandatory licensing in its copyright submission and argued for a text-and-data-mining exception. Treasury briefing material weighed a claimed $21.6 billion in investment against a request for legal certainty on training liability, and concluded the fair-use question is "not settled". And the creator sector has already named the pattern, with APRA AMCOS demanding licensing negotiations rather than "further rounds of tech sector avoidance".
The creator sector is the clearest ally in that record, and the pattern extends to it directly. The same licensed-capability model this kit is built from - grant, scope, revoke, verify - applies as cleanly to a song, a film or an image as to a determination. An artist can licence a finished work, or the method behind it if they choose to, and revoke that licence in a way that actually bites, rather than one merely asserted in a terms-of-service page nobody can enforce. That is the machinery APRA AMCOS is asking for, described in the same language as the rest of this hub, and building it out for music, video and images is where our own work goes next.
The Prime Minister has already answered the trade: unlicensed training is "theft", and Australia must not be "subcontracting our national sovereignty and security to the control of foreign monopolies". The strongest lines available here are the Government's own.
So the counters we would build are not arguments to be won at a podium - they are properties to put in the instruments, so the defence does not depend on any minister's stamina. A provenance requirement for the standards themselves: all submissions published, all meetings logged, adopted text attributed to its source. The same discipline this hub applies to itself, made mandatory for everyone - the single strongest anti-capture mechanism available, and a cheap one. A testability rule for definitions, because a definition no examiner can apply serves only the party hoping not to be examined. Automatic conversion dates on any voluntary pathway. An attestation rung named against each obligation, so self-assessment cannot quietly become the ceiling. And, in the letter that accompanies this post, one plain ask: that secondments and paid advisory relationships into a weeks-old Office appear in its first annual report. Certainty is what the framework provides. Certainty about weaker rules is a different product, and it is not for sale here.
The disclosure we owe
There is a conflict in this post, and the credible way to handle it is to name it before anyone else does.
One of the companies in that record is one whose models this platform is built on. We are, separately, courting its safety-research community, and a Commonwealth department has a signed memorandum of understanding with the same company. So: we build on frontier models including theirs, we are seeking a relationship with their safety-research people, and we still say the training-consent concession should not be granted - to them, or to anyone. Arguing against the commercial interest of a company we depend on and court is either the strongest evidence of independence in this whole hub or a live conflict, and which one it is depends entirely on whether we said it first. We would rather say it first.
To the ministers, who have already said the words
The Prime Minister has said unlicensed training is theft. The Attorney-General has ruled out the exception twice. The Assistant Minister has promised faster rules, not fewer. These are the strongest statements any G20 government has made on this ground, and they were the easy part. Between now and early 2027 sits a consultation process that the best-resourced lobbying operations on earth will attend in numbers, proposing text. Some of it will be good text. The test of this framework is not the speech at Sydney University; it is whether the instruments registered in 2027 still say what the speech said. We have published everything we propose, attributed, in advance, and we invite every other participant in this process - including the platforms - to do the same. A government confident of its position should make that disclosure mandatory.
Ministers: you have said the words. Keep them in the instruments.
- The federal Register of Lobbyists covers third-party lobbyists acting for clients. An organisation publishing its own views is not registrable lobbying, so the title is a joke that is also technically false - which felt like the right note to open on, given the rest of this. ↩
- Christopher Pyne, on radio, comparing the task to regulating a plume of smoke and doubting it was possible. ↩
Written with model assistance. Read and edited by a human - though I'm not an editor, so tell me what I've missed: get in touch. Parts of this were generated; all of it was read, checked and meant. Feedback is welcome and gets used.