JavaScript is required
DOMESTIC BUILDING INSURANCE now managed by the Building and Plumbing Commission
Visit BPC
Health Sector Cyber Security Assessments - header

CISO insights (December 2025)

AI - friend or foe?

In this commentary, VMIA Chief Information Security Officer, Ian Pham, shares his top 10 recommendations drawn from his own experience to guide responsible adoption, ensuring risk management and governance safeguards evolve as rapidly as emerging AI capabilities.

Artificial Intelligence (AI) is rapidly weaving itself into the fabric of every public sector agency, offering unprecedented pathways to efficiency and data-driven insights. Yet before we embrace any new tool, we must ensure that our safeguards, particularly those relating to risk management and governance, evolve just as quickly.

In the Victorian Government, we have the advantage of pursuing public value rather than shareholder returns. This means we can afford to, and are expected to, adopt AI responsibly, not recklessly.

Ian Pham at CyberCon 2025
Ian Pham, one of the speakers at CyberCon Melbourne 2025

Embracing new technology

Each new AI capability is a double-edged sword, creating valuable opportunities while introducing fresh exposures. We cannot shy away from these benefits. History shows that truly transformative technologies become part of our daily lives regardless of whether we feel ready.

I still remember driving through Melbourne with a worn-out Melway tucked behind the passenger seat, surrounded by old tissues and crumbs. When the street signs disappeared and the roads were unfamiliar, I would pull over, fumble through the pages and try to work out where on earth I was. The first time a GPS unit appeared on my dashboard, I did not trust it."

The voice instructions felt robotic and, to be honest, occasionally wrong. Yet within a few short years, I stopped questioning it at all. It has become indispensable. That experience reminds me that while AI follows a similar path, its growth is much faster and far less predictable. Controls we finalise this month may well be outdated by next quarter.

We all have a responsibility to reconsider how we design, review and refresh our policies. The real challenge is no longer “how do we control AI?”, but rather how we can build adaptive safeguards that can evolve as quickly as the technology itself.

Below are some recommendations, in chronological order, that have helped govern my AI journey.

Top 10 AI governance recommendations

Speak to your organisation’s AI specialists to better understand the below recommendations and risks.

VMIA Top 10 AI Recommendations
PDF 162.39 KB
(opens in a new window)

AI can be a powerful ally, but only if we all manage it with intention and vigilance. The real challenge isn’t whether AI is friend or foe. It is whether we are ready to take responsibility for how we use it.

Be it Melway or GPS, the tools may change but the goal remains the same – to ensure we arrive safely.

Updated