By Graham Solling, Technical Consulting Lead
AT A GLANCE
- Start with the problem, not the AI. AI should only be used when it is the most appropriate solution to the business need.
- AI introduces unique risks including bias, transparency issues, model drift, data sensitivity, and evolving risk profiles.
- PMOs play a critical governance role by balancing innovation with security, oversight, accountability, and risk management.
- Not all AI projects require the same level of control. A tiered governance model helps match oversight to risk and impact.
- AI governance must continue beyond go-live through ongoing monitoring, review, and reporting as use and risks evolve.
Government agencies are experiencing increasing pressure to adopt Artificial Intelligence (AI) due to its potential to increase productivity, accelerate decision-making, improve service delivery, and provide solutions that fulfil the needs of both citizens and government.
The Australian Public Service (APS) has acknowledged this opportunity. The APS AI Plan 2025 establishes a clear direction for AI adoption, emphasising trust, workforce capability, and appropriate tools. The current priority is to ensure that AI is implemented safely, effectively, and at scale across the public sector. As AI adoption increases, the role of Project Management Offices (PMOs) is growing increasingly critical.
Agencies are now focused on managing innovation with risk and translating policy into measurable outcomes.
PMOs are central to effective AI governance. They ensure that risks and key decisions remain transparent throughout the project lifecycle, and they provide essential support for executive reporting on AI initiatives. Rather than acting as gatekeepers, PMOs help guide AI projects from initial concept through to successful, organisation-wide delivery. Their focus is on enabling progress while maintaining oversight, making them facilitators of both innovation and accountability.
AI is a tool, not the goal
With AI, there is a risk of bias in how we frame the work. People often ask:
What is the way we can use AI for this problem?
Instead of:
What problem are we trying to solve?
AI technology is not always required. In some cases, process improvement, workflow automation, enhanced data quality, clarified business rules, or improved information access may provide more effective solutions.
AI may be appropriate in certain circumstances, but not in others. This consideration is not new in technology projects, and PMOs must stay alert in assessing AI’s suitability during project tracking and review.
When social media became popular, many groups felt pressure to join every platform because others did. Some found real value and built strong ties with their audience. Others kept accounts that added little value beyond saying they were there.
The key lesson is that new technology alone does not constitute a strategy. The primary concentration should remain on addressing the underlying problem.
For PMOs, governance processes should include an assessment of whether AI represents the most appropriate tool to address the specific problem the project tries to resolve.
Why AI creates a different kind of risk
While AI is a technological tool, it introduces risks that differ from those associated with traditional technology projects.
Traditional systems act in more predictable ways. Business rules lead to expected results, testing checks behaviour, and change is usually controlled.
AI introduces further uncertainty. Outputs from large language models may change over time due to model drift. Inadequate design can result in decisions that lack transparency. Furthermore, risk may arise from user interactions with the tool, not solely from its initial development.
For example, utilising generative AI for internal drafting may present a low-risk profile. However, if such drafts are used to inform significant decisions without appropriate review, and the underlying model evolves over time, the associated risk can increase rapidly.
While the tool itself may remain unchanged, the risk profile can evolve. Consequently, AI governance requires regular review of project risks throughout the entire project lifecycle.
Managing innovation risk and security risk
AI governance continues to prioritise security and compliance, which remain essential considerations.
Poorly governed AI can lead to:
- Exposure of sensitive information
- Improper use of agency data
- Biased or poor outputs
- Reputation damage
- Loss of public trust
However, excessively restrictive governance can result in agencies remaining in pilot phases, thereby delaying productivity gains, missing cost-reduction opportunities, and limiting service improvements.
The primary challenge for PMOs is to support both innovation and security. This requires applying an AI risk management framework that enables low-risk experimentation while increasing oversight for higher-risk initiatives.
The APS AI plan has raised the bar
The APS AI Plan provides practical guidance for governance, capability development, accountability, support, and oversight. This includes enhanced policy direction, establishment of AI Review Committees, targeted training, leadership accountability, and support mechanisms to ensure safe and responsible AI adoption by agencies.
The current challenge is effective implementation. Agencies must determine how to apply government guidance consistently across multiple projects with varying objectives, stakeholders, and risk profiles.
PMOs are essential in operationalising the APS AI Plan by translating its principles into repeatable, fit-for-purpose project delivery approaches.
This approach underpins responsible AI implementation within government.
From AI experiments to AI portfolio management
A key theme of the APS AI Plan is the transition from isolated pilot projects to scalable, enterprise-wide AI adoption across government.
Many agencies are already trying AI through:
- Internal productivity tools
- Knowledge discovery work
- Business process improvements
- Service delivery pilots
- Business decision support tools
Individually, these initiatives are manageable; collectively, they constitute a growing portfolio of AI projects that require robust oversight, governance, and risk management.
Standard PMO capabilities remain highly relevant, as established governance practices continue to be critical for effective portfolio management.
However, AI-related projects introduce additional requirements, including enhanced clarity, accountability, transparency, human oversight, and management of data sensitivity.
AI does not replace traditional governance frameworks; rather, it necessitates the evolution and adaptation of governance practices.
A practical AI governance model for PMOs
AI projects present varying levels of risk; therefore, governance and oversight should be proportionate to each project’s specific risk profile.
A tiered governance model enables the application of appropriate controls commensurate with project risk.
This is a simple AI risk management framework.
Tier 1: Productivity and admin support
Examples include projects that use it for:
- Meeting summaries
- Internal document drafting
- Knowledge discovery
- Content generation
These applications typically support testing and productivity and can be managed through streamlined controls.
Tier 2: Business decision support
Examples include projects that use it for:
- Recommendations
- Task order
- Case management support
- Live help
These projects require additional review, as their outcomes may influence business decisions. It is essential that the rationale for these decisions is transparent.
Tier 3: Human impact and public outcomes
Examples include projects that use it for:
- Access decisions
- Compliance assessments
- Citizen-facing decisions
- Activities that affect individuals
These projects require the highest level of control, executive oversight, and continuous monitoring.
What can PMOs do today?
Build AI-specific risk registers
Traditional project registers focus on schedule, cost, scope, and delivery risk.
AI projects should explicitly document AI-specific risks, including whether AI is utilised and the areas of potential impact, such as:
- Data sensitivity
- Human monitoring needs
- Clarity
- Third-party dependencies
- Model ownership
- Ongoing monitoring duties
These risks should remain visible and be actively managed throughout the entire project lifecycle.
Introduce meaningful governance gates
Not all AI pilot projects require extensive approval processes.
The APS AI Plan encourages agencies to test, learn, and build AI skills safely and responsibly. Low-risk tests should be supported when safeguards are in place, and impacts are clear.
However, transitioning from pilot testing to live implementation should involve increased review. Governance processes must be substantive and not merely procedural.
For AI projects, the quality of governance decisions is as important as the governance process itself. Given the evolving nature of AI, decision-makers require an appropriate level of expertise.
Decision-makers need enough understanding of:
- The current and future use case
- The AI tools being used and how they may change
- The data involved
- The risks and assumptions found
- The controls being used
- The possible effects of failure
For PMOs, this is where they add value. Good governance steps build trust that risks are found, understood, questioned, and accepted by the right people before wider rollout.
Monitor beyond go-live
AI governance extends beyond go-live; however, PMO involvement frequently concludes at this stage.
Usage patterns, model evolution, and data changes can alter the risk profile over time. A use case initially assessed as low risk may become higher risk as utilisation and reliance increase.
Ongoing governance should be integrated into every AI project, including regular monitoring, periodic review, and transparent reporting on AI usage and outcomes.
Final thoughts
The future of AI in government is not about whether to use it. That decision has already been made.
The challenge is to deploy AI where it delivers tangible value, while maintaining the trust, transparency, and accountability expected of government services. Not all projects require AI, nor do all AI initiatives present the same level of risk or require identical oversight. PMOs are well positioned to support this balance.
The APS AI Plan provides a clear framework for effective AI adoption. PMOs operationalise this framework by developing practical approaches to project delivery and governance across an expanding portfolio.
This involves supporting organisations to progress beyond experimental and pilot phases, ensuring visibility of AI usage across all projects, maintaining comprehensive risk management throughout the project lifecycle, and providing decision-makers with the necessary information.
Ultimately, effective AI governance should not impede innovation or introduce unnecessary administrative burden. It should ensure that organisations consistently consider key questions regarding AI implementation:
- Are we solving the right problem?
- Is AI the right tool for the job?
- Do we understand and accept the risks involved?
If PMOs help organisations answer these questions often, they will play a key role in turning AI from scattered tests into trusted, scalable, and useful results for government.
Balancing innovation with governance isn’t something PMOs need to figure out alone. Sensei’s Altus platform is built to give government agencies the visibility, risk tracking, and reporting they need to manage AI initiatives confidently at scale. If you’d like to talk through how a tiered governance model could work for your agency’s project portfolio, get in touch with the Sensei team.
Q&A
Q: Why should PMOs be involved in AI governance rather than leaving it only to technical or security teams?
A: PMOs provide visibility of AI initiatives across the entire project portfolio, rather than within individual teams. They track AI usage, ensure that risks are reported to leadership, and support consistent governance. Their role is to facilitate the transition from small-scale pilots to trusted, scalable delivery, not to impede innovation.
Q: How can agencies decide whether an AI project needs light or heavy governance?
A: Governance should be proportionate to the level of risk and impact. Low-risk productivity applications, such as meeting summaries or internal drafting, may require only basic controls. Business decision support tools require additional review due to their influence on organisational decisions. AI initiatives that affect citizens, access, compliance, or public outcomes necessitate the highest level of oversight, controls, and ongoing monitoring.
Q: Why is it important to ask whether AI is the right tool before starting an AI project?
A: AI should solve a real problem, not be used just because it is new or popular. Sometimes better processes, better data, clearer rules, workflow automation, or better access to information work better. PMOs can help keep the focus on the problem, not on the tool.
Q: Why does AI risk need to be reviewed after go-live?
A: AI risk profiles can change over time as usage increases, models evolve, data changes, or reliance on outputs grows. A use case initially assessed as low risk may become higher risk if it begins to inform significant decisions without adequate review. Therefore, AI projects require ongoing monitoring, review, and transparent reporting following delivery.
Q: What should an AI-specific risk register include?
A: In addition to standard project risks such as schedule, cost, scope, and delivery, an AI-specific risk register should record whether AI is utilised and track factors including data sensitivity, human oversight requirements, clarity, third-party dependencies, model ownership, and ongoing monitoring responsibilities. These risks should remain visible and be managed throughout the project lifecycle.
About the author
Graham Solling is a Technical Consulting Lead at Sensei. With extensive experience delivering Microsoft-based solutions, Graham plays a key role in leading technical delivery within Sensei’s public sector practice. He combines deep expertise in Power Platform and Azure DevOps with a focus on governance and scalable solutions, helping organisations modernise project delivery and portfolio management.