Australia

Runtime authority for Australian sovereign AI.

When APRA asks for the operational-risk control trail under CPS 230, when the AI Guardrails ask who was accountable and how a decision was reached, when the OAIC asks about an automated decision under the Privacy Act 1988 — KYE Protocol answers from a record sealed at the moment of action. Replayable from the publishing tenant's JWKS alone. No vendor dependency in the audit path.

Australian frameworks mapped to KYE

Per-requirement bijection — not a slide deck.

APRA CPS 230

Prudential Standard CPS 230 — Operational Risk Management (effective 1 July 2025). The Risk Engine + Decision Engine bind each governed action to a contemporaneous risk assessment, and the Resilience Loop replays the life cycle of every operation an AI agent performed — the operational-risk control trail APRA wants.

Mandatory AI Guardrails (DISR 2024)

The 10 mandatory AI guardrails for high-risk settings. Guardrails 1-9 map directly to KYE primitives: accountability (Purpose Permission), human oversight (GovernedUI), transparency (Decision Map), contestability (Replay-Proof) and record-keeping (WORM audit). Each guardrail is a per-requirement bijection row.

Privacy Act 1988 — ADM reform

The 2024 automated-decision-making transparency reform plus Australian Privacy Principles 1 and 11. The Decision Map records the kinds of personal information used in a substantially automated decision, and Replay-Proof reconstructs the explanation the reform contemplates.

ASD Essential Eight + ASD AI guidance

Restrict-administrative-privileges and MFA map to Authority Resolution + WebAuthn step-up; tamper-evident monitoring maps to the Streaming Logs Contract + WORM audit. ASD's 'Engaging with Artificial Intelligence' supply-chain guidance maps to the Authority Register.

AUSTRAC · TGA (acknowledged)

AUSTRAC AML/CTF obligations and TGA medical-device regulation are acknowledged Australian regulators on the coverage registry; their per-requirement bijection maps are staged for the next coverage wave alongside the active four above.

Australian-sovereign deployment

Australian data, Australian keys, Australian control.

  • Data residency — deploy to Australian-region edge runtime resources; per-tenant configurable; structured datastore + object store pinned to Australia.
  • Customer KMS — signing keys live in the customer's HSM or sovereign-cloud KMS; KYE never has access to the private key material.
  • Open verifier — APRA examiners, the OAIC, AUSTRAC and the customer's own auditors can replay an Evidence Pack using only the publisher's JWKS. No vendor dependency in the audit path.
  • Apache 2.0 schemas + vocabulary — the contracts the customer relies on are open. The patent-track runtime construction is paid; the proof formats are not.
Australian pilot · 6 weeks

KYE Australian Readiness Pilot™.

Australian banks, insurers, superannuation trustees and AI-deploying enterprises: a 6-week shadow-mode engagement producing APRA CPS 230 operational-risk control mapping per assertion, AI Guardrails accountability coverage, signed Evidence Packs per decision, and an APRA-ready executive summary with a residual-risk register.

{BLOCK} {BLOCK}

Independent — no government affiliation. KYE Protocol™ is an independent protocol and is not affiliated with, endorsed by, or part of any government, regulator, or official “Sovereign AI” programme. References to regulators and frameworks describe the requirements KYE™ helps you evidence — not any official relationship.