Responsible AI has produced a large volume of principles documents and a much smaller volume of operational practice. The principles are not wrong. They are just not, on their own, enough to build a system a regulator or an affected citizen can trust. What is missing is the translation from principle to practice, expressed in terms an engineering team can actually implement and an assurance function can actually verify.
The seven pillars below are that translation. They are drawn from real programmes across Australian federal and state government, financial services, health and critical infrastructure. Each pillar is stated in operational terms, with the evidence a mature programme should be able to produce on request.
## 1. Purpose
Every AI system in production has a written, specific statement of the decisions it is intended to influence, the population it is intended to serve, and the outcomes it is expected to improve. Purpose is not the model. Purpose is what the model is for. Systems without a written purpose statement drift into use cases they were not designed or evaluated for, and become uncontrollable.
Evidence: a purpose statement, dated and signed by the accountable executive, referenced from the model card and the assurance plan.
## 2. Provenance
The data used to train, tune and evaluate the model is documented, with source, lawful basis, sensitivity, and any known limitations of representativeness. Third party model dependencies are treated as suppliers and their provenance is captured in the same register.
Evidence: a data and model provenance register, updated on every material change, and reconciled against the production artifacts quarterly.
## 3. Performance
Performance is measured against a use case specific evaluation set, not a public benchmark. The evaluation set is representative of the populations and edge cases the system will actually see, is refreshed on a defined cadence, and includes adversarial and failure mode cases explicitly. Performance is monitored continuously in production and reported against the same metrics used at launch.
Evidence: an evaluation harness, versioned test sets, and a monitoring dashboard that any executive can read.
## 4. People
Every consequential decision has a defined human role and a defined mechanism for that human to intervene. Fully automated decisions are permitted only where the consequence is low, the population is well characterised, and the reversibility is high. The competencies required of the humans in the loop are documented, and training is auditable.
Evidence: a human in the loop design document per use case, and a training record for the roles named in it.
## 5. Protection
The system is designed against the threats it will actually face, which for AI systems include prompt injection, data exfiltration through model outputs, training data poisoning, and misuse by legitimate users. Standard cyber security controls apply, and AI specific controls are added on top, not instead.
Evidence: a threat model that names the AI specific threats explicitly, tested by exercise at least annually.
## 6. Participation
The people affected by the system, and their representatives, have a defined path to raise concerns, correct errors and understand how decisions about them were made. In regulated Australian environments this is not optional. In unregulated environments it is still the right thing to do, and cheaper to build in than to retrofit under pressure.
Evidence: a published redress mechanism, and a log of matters raised through it with outcomes.
## 7. Post market surveillance
The system is treated as a product that continues to evolve after launch. Behavioural change is expected, monitored, and responded to. Incidents are captured with the same rigour as any other production incident, and the lessons are fed back into the evaluation and design of the next release.
Evidence: an incident register, a change log tied to model, prompt and retrieval versions, and a periodic assurance report.
## What this changes
The seven pillars are not a maturity model to admire. They are a set of artifacts a functioning programme actually produces. If you cannot put the evidence for each pillar on the table today for one of your production AI systems, you do not yet have responsible AI for that system. You have a policy that names it.
The good news is that none of the seven pillars is exotic. Each is achievable with the engineering, security and governance capability that most Australian enterprises already have. The work is in aligning those capabilities around AI specifically, and in accepting that responsible AI is an operating discipline, not a one time certification.



