NAI

Draft for discussion

Draft governance statement

How we intend NAI to be governed, set out so it can be examined and challenged before the company exists. This is a draft for discussion, not a legal document, and every part of it is subject to legal advice and to what we learn from government and other partners.

Version
0.1, 25 September 2026
Applies to
NAI, once it is formed
Comments
hi@wearenai.au
01

Settled principles

Four principles are settled. Everything else on this page is a way of upholding them: the mechanisms may change as we take advice, the principles will not.

  • Australian control. NAI is controlled in Australia, by Australians, and cannot pass into foreign control.
  • Meaningful independent oversight. People outside management, including government where appropriate, can see how NAI operates and act on what they find.
  • Rapid incident reporting. Affected parties and government hear about incidents quickly, without waiting for a finished investigation.
  • Protection of the mission. The mission cannot be quietly traded away as NAI grows or raises capital.
02

Mission and its protection

NAI’s mission is to build Australian-controlled foundation models and AI-native cyber security that help protect Australian government, critical infrastructure and the systems Australians depend on.

  • The mission would be written into NAI’s constitution, and directors would be required to pursue it. Maximising shareholder value is not the objective.
  • Changing the mission would take more than an ordinary shareholder vote. Options we are considering include a special resolution that also needs the independent directors’ consent, or a special share held by a public-interest trustee or the Commonwealth.
03

Ownership and control

  • NAI would be incorporated and headquartered in Australia, with its board and senior management based here.
  • We intend to cap the voting power any foreign person, alone or with associates, can hold, and to keep a majority of voting rights with Australians. Thresholds will be set with legal advice, on top of any approvals Australia’s foreign investment laws require.
  • A change of control, or a transfer of core assets such as model weights, would need the independent directors’ consent and advance notice to government.
04

Board and oversight

  • A majority of directors would be Australian citizens living in Australia.
  • Independent directors, with expertise in security, AI safety or public administration, would oversee the mission, security and incident reporting, and could commission independent reviews.
  • We are open to a government observer on the board, or to specific government rights such as a veto over changes to the mission or the foreign-control limits. The right form depends on the relationship that develops and on legal advice.
  • Directors and staff would declare conflicts of interest, recorded in a register the board reviews.
05

Audit, inspection and evaluation

  • Government-nominated assessors, for example from ASD or the AI Safety Institute where appropriate, could inspect NAI’s systems, security controls and logs, and how it handles model weights and Australian data.
  • Inspections would normally be scheduled. After a significant incident they could happen at short notice.
  • NAI would respond to findings in writing and fix material issues within agreed timeframes.
  • Before a model or security system is used in a government or critical-infrastructure environment, it would be independently evaluated for security and behaviour, including by Australian evaluators. Summaries of the results would be published where that is safe.
06

Data, infrastructure and dependencies

  • Australian government and customer data would be stored and processed in Australia.
  • Infrastructure, administrative access and cryptographic keys would be controlled by NAI in Australia, with staff access vetted to the level each environment requires.
  • Foreign suppliers would have no access to Australian data or model weights without consent, and any access would be logged.
  • Dependencies on external suppliers, licences, hardware and capital would be kept in a register, reviewed by the board and summarised in the annual report.
07

Autonomous testing

  • Autonomous defensive testing would happen only with written authorisation from the system owner, inside network, credential and tool-access restrictions that are tested independently before use.
  • Detection, triage and analysis can run automatically. High-impact actions, such as exploiting a vulnerability or changing a system, need a named person’s approval first.
  • Operators can halt a run and revoke its credentials at any time. Halting does not undo completed actions, so tool calls, network activity, approvals and outcomes are logged with tamper evidence and reviewed after each engagement.
08

Incident reporting

  • Scope. Incidents involving NAI’s systems or activities, including the actions of its own agents, that affect or could affect Australian government or critical systems.
  • Timing. Within 12 hours of becoming aware of an incident with significant impact, and within 72 hours for other relevant incidents.
  • Recipients. The affected system owner, ASD’s ACSC and NAI’s independent directors.
  • Content. What is known, what is not yet known and what has been done to contain it, followed by updates. Reports would not wait for an investigation to finish.
  • Disclosure. Public disclosure would follow once it is operationally safe, after consulting the affected party.
  • Status. A voluntary policy, separate from and in addition to any legal obligations that apply.
09

Funding and transparency

  • We intend to fund NAI primarily with private capital. Investors’ rights would not extend to the mission, the foreign-control limits, the security commitments or incident reporting, and investment would not give anyone access to Australian data, model weights or security details.
  • NAI may take on paid government work under normal contracts. Our first request of government is a technical discussion about a useful design partnership.
  • NAI would publish an annual report covering ownership, the board, disclosed incidents, evaluations, supplier dependencies and any changes to this statement.
  • This statement would be versioned. Material changes would be published with reasons, and changes that weaken the principles would need the independent directors’ consent.

Comments are welcome, particularly from people working in government, security and governance: hi@wearenai.au.