Home / AI & Agentic Readiness / AI & Agent Operating Model
AI & Agent Operating Model Design
The control design an AI or agentic system needs ahead of go-live — accountable ownership, permitted actions, data boundaries, approval thresholds, escalation, and a shutdown that works.
Operating-model design, applied to agents.
Authority lands inside a process built to grant authority to people. Afterwards, nobody can explain what the system was permitted to do, or why.
The pattern repeats: ownership sits nowhere, permitted actions were never written down, the approval threshold was set by whoever configured it, the escalation path assumes a role that has since changed, and the rollback was never tested. Every one of these is an operating-model question.
So we start where value is created or lost — the decisions, the decision rights, and the handovers between them — and design the agent into that structure.
Where we start
Eighty-four per cent of Australian firms have already rolled back or shut down a customer-facing agent. Boards are asking what happens when an agent has to be pulled, and whether the reason stands up afterwards.
This mirrors the Commonwealth's agentic AI technical guidance, which names intervention and shutdown mechanisms as one of five domains agencies are expected to apply.
The control set
Eleven things, written down, owned, and specific enough for someone outside the room to test.
The design maps to the instrument that governs you, so the output doubles as evidence.
Published June 2026 as an addendum to the Australian Government AI technical standard, covering governance and controls, data and memory management, evaluation against defined outcomes, human oversight and real-time monitoring, and intervention and shutdown. Agencies are expected to apply it, and it is what an internal auditor or the ANAO will reach for.
Sets expectations across governance and board AI literacy, information security including prompt injection and manipulation of autonomous agents, lifecycle management and AI inventory, supply-chain visibility to fourth parties, and continuous assurance. APRA states plainly that assurance practice is falling behind.
Core cyber risks now expressly include the deployment or hostile use of advanced, novel or emerging technology including AI, covering both your own deployment and AI used against you. The design feeds directly into the risk management program and the annual board-approved report.
The design is expressed so it maps cleanly onto an AI management system and onto the NIST functions — the two frameworks Australian regulators name. Accredited bodies issue certification; we handle readiness and evidence design.
Retained afterwards through the Value Realisation Office, where the portfolio is reviewed monthly, new use cases are assessed, and the benefit is tracked to the ledger.
Most engagements begin with the Agent-Ready X-ray, because the design works better from a measured process. Where you already hold that evidence, we can start here.