Back
Information Technology
Katonic AI

Katonic AI urges Canberra to write a Control Disclosure into Australia's AI Standards

Katonic AI

The four controls in Katonic AI's proposed Control Disclosure: keys, models, evidence and switch-off. Source: Katonic AI submission to the Office of AI, October 2026.
The four controls in Katonic AI's proposed Control Disclosure: keys, models, evidence and switch-off. Source: Katonic AI submission to the Office of AI, October 2026.
Key Facts:
  • Katonic AI lodged its submission to the Office of AI consultation on 2 October 2026; the consultation closes 5 pm AEDT Friday 9 October.
  • The submission proposes a one-page Control Disclosure for every AI service supplied to a Commonwealth entity or a critical infrastructure operator, wherever hosted.
  • Four controls: who holds the keys, who chooses the models, who keeps the evidence, who can switch it off. Each answer names a party and the law it sits under.
  • Every party in the chain answers, including the cloud underneath. Katonic's own platform would have to answer too.

SYDNEY, Wednesday 7 October 2026: Katonic AI, an Australian enterprise AI platform company, has lodged a submission to the Office of AI's consultation "Getting it right: Building AI infrastructure that works for Australia", proposing that Australia's AI Standards require a one-page Control Disclosure naming who controls the AI systems the new infrastructure will run. The full submission is attached to this release.

The consultation, run by the Office of AI in the Department of the Prime Minister and Cabinet, closes at 5 pm AEDT on Friday 9 October. Its paper proposes mandatory minimum requirements for data centres of 30 megawatts or more, covering energy, water, costs to consumers, community engagement, location and skills, and conditions for frontier AI training, covering security, local capability and Australian creators. The responses will inform Australia's AI Standards, which the Prime Minister announced on 15 July.

The paper's questions cover the buildings, the grid, the water and the labs that will train models here. None asks who holds the keys to, chooses the models for, or can switch off the AI systems that Australian organisations will run on that infrastructure. The paper itself says sovereign AI capability "relies on secure, onshore data centre infrastructure". Katonic's submission argues that location is necessary but does not settle control, and proposes that every supplier of an AI service to a Commonwealth entity or a critical infrastructure operator, wherever the service is hosted, answer four questions on one page:

  • Keys: who holds the keys to the data, and can any supplier obtain a copy?
  • Models: who chooses which models run, and who decides when they change?
  • Evidence: when the system acts, what record is kept, where, and who can read it?
  • Switch-off: who can stop the system, and does it keep running if a supplier's service or licence ends?

Each answer names a party, not an assurance, and every party in the chain answers, including the cloud underneath. The disclosure is neutral on location. An insurer running AI in its own tenancy on a public cloud, holding its own keys and its own records, answers "the insurer" four times. A subscription in a certified Sydney data centre that the vendor can end answers "the vendor" four times. Katonic's own installed software stops when its licence ends, and the submission says so.

The submission builds on Frontier AI Cyber Threat Considerations for Boards of Directors, published in August by the Australian Signals Directorate and the Australian Institute of Company Directors, which tells boards to "assess the risk of relying on AI providers, including cyber supply chain risks and concerns about foreign ownership, control and influence".

"Look, a postcode is not a policy," said Prem Naraindas, founder and CEO of Katonic AI. "The Standards will rightly measure how much power and water a data centre uses. They should also ask who can switch off what runs inside it, because that is the question a board, a regulator or a customer will ask the day something goes wrong."

"We are not a hyperscaler, so we don't get to define sovereignty by press release," Naraindas said. "That is why the submission asks for a disclosure anyone can fail, including us. Four questions, answered on one page, for every AI service that matters. The energy and water standards will look after the buildings. This looks after what runs inside them."

The four questions draw on the Control Test set out in Own Your AI: The Sovereign Stack Playbook for Nations and Enterprises, which Naraindas co-wrote.


About us:

Katonic AI is an Australian enterprise AI platform company, founded in Sydney in 2020, with offices in Sydney, Mumbai and Dubai, where its founder is based. Its platform lets governments and enterprises run their own AI under their own governance, deployed inside the customer's own environment: their data centre, their own tenancy on a public cloud, or a sovereign or partner cloud. Katonic develops no models of its own. It serves organisations in 11 countries, including Pilipinas AI, the sovereign AI service run with ePLDT in the Philippines, and MODON, the Saudi industrial cities authority. Katonic is certified to ISO/IEC 27001:2022. www.katonic.ai


Contact details:

Prem Naraindas, Founder and CEO, Katonic AI
[email protected]
Prem Naraindas is available for interview on 7 and 8 October (Sydney business hours).

Images

OFFICE-OF-AI-four-controls-graphic-2026-10-02.png

The four controls in Katonic AI's proposed Control Disclosure: keys, models, evidence and switch-off. Source: Katonic AI submission to the Office of AI, October 2026.
Download
Attachments

KATONIC-SUBMISSION-OFFICE-OF-AI-FINAL-editorial-2026-10-02.pdf

Download