AI security & governance · for Australian boards & regulated industries

High-stakes change does not fail
because of the strategy.
It fails because the network
beneath it is not ready to carry it.

The Mycelium Group is an AI security and governance practice for Australian boards and regulated industries — built on three decades of diagnostic work on the network beneath high-stakes change. Three connected practices: Board AI Readiness (free 30-minute diagnostic), AI Security Health Check (4-week, board-ready scorecard), and Managed AI Agents (purpose-built departmental builds).

network hub isolated

We help leaders determine whether further AI investment will convert into adoption — or whether the operating conditions beneath the program need to be fixed first.

Assess
Restore
Roll out

The org chart shows authority.
The network shows whether change will move.

Most organisations respond to stalled AI adoption with more: more tools, more training, more mandate. That response treats the symptom. If the operating conditions beneath the program are weak, additional investment does not solve the problem — it scales the waste. The network beneath the structure is the cause. In every sector. At every scale.

Weak operating conditions
Decisions take months for issues that feel straightforward
Talented people stay quiet in meetings
The same problems recur after every restructure
AI programs stall despite deployment, training, and mandate
Leadership is surprised by what they didn't know
The best people leave — gradually, quietly
Strong operating conditions
Problems surface early — when they are still manageable
People bring their real thinking. Ideas get raised
Change lands. The network was ready to carry it
AI adoption becomes genuine, not performative
Accurate signals reach leadership intact
People stay. The system lets them do their best work

Five conditions.
Each measurable.
Each addressable.

AI programs fail when five organisational conditions are absent. These are not cultural attitudes — they are structural operating conditions. The diagnostic scores your organisation across all five using executive interviews, frontline input, governance review, and artefact analysis — mapping precisely where adoption will fail and why, before further investment is committed.

01
Psychological Safety

People feel safe to experiment, fail, and report honestly before issues become political.

Determines whether delivery risk is visible early — or hidden until cost, delay, and adoption failure are already locked in.

02
Lateral Learning Flow

What works in one team reaches other teams before adoption fragments.

Determines whether the organisation scales what works — or rebuilds the same solutions in isolation at ongoing cost.

03
Distributed Authority

Frontline teams can adapt AI tools to how they actually work, within clear governance boundaries.

Determines whether the program reaches operational reality — or stays a compliance exercise that bypasses real work.

04
Incentive Alignment

People are rewarded for genuine use and outcomes, not reported activity.

Determines whether adoption data reflects reality — or reflects what people know leadership wants to see.

05
Honest Signal Flow

Leadership receives accurate data on what is and is not working, early enough to act.

Determines whether leadership can intervene before failure is locked in — or learns of adoption collapse after the spend is committed.

The gap between what leadership perceives and what the frontline experiences is not a people problem. It is a network health problem. It is precisely measurable — and it is the most reliable predictor of whether an AI program will hold.

95%

of corporate AI pilots fail to create measurable value

MIT Sloan, 2025

60%

of organisations generate no material AI value despite significant investment

BCG, 2025

51 pts

gap between executive and frontline perception of AI readiness — in the same organisations

BCG / Columbia, 2025

If adoption conditions are weak, additional AI spend does not solve the problem. It scales the waste.

Before committing further spend,
test whether the organisation can convert it.

The standard response to a stalled AI program is more: more tools, more licences, more training, more mandate. That response assumes the problem is insufficient input. It is usually insufficient operating conditions.

The diagnostic tests whether the next tranche of AI investment will convert into genuine adoption — or add to the sunk cost. It is designed as a decision gate, not a consulting engagement.

Three diagnostics.
One build practice.
Diagnostic-led.

Every engagement begins with a diagnostic. No engagement proceeds without one. If the diagnostic does not support further work, we say so before a proposal is written.

The Organisational Ecology Model is the methodology under both diagnostics. The five conditions assessed are constant. The application is calibrated to each specialism.

Front Door · Start Here

Board AI Readiness

Where every Mycelium engagement begins. A diagnostic, a workshop, an assessment — for boards now formally accountable for AI.

  • 10-question Boardroom AI Diagnostic — free, 2-page PDF, self-scored RAG
  • 3-hour facilitated boardroom workshop with chair, company secretary and directors
  • 3-week Board AI Readiness Assessment with structured director interviews
  • Sector-tuned editions: Banking & Mutuals, Energy & Utilities, Master
  • Boards enter at the lightest rung and step up only on what the previous rung surfaces.
For boards now formally accountable for AI under AICD director-duty guidance, APRA CPS 230 and AS ISO/IEC 42001 — but unsure where their organisation actually stands.
30 min — 3 weeks Free entry · tier-based
Specialism 01 · Govern

AI Security Health Check

Where does your AI risk actually sit? A four-week board-ready diagnostic.

  • 14 dimensions across 4 pillars — Govern, Protect, Operate, Enable
  • RAG-scored against the Mycelium AI Security Framework
  • Mapped to APRA CPS 230, CPS 234, AS ISO/IEC 42001 and AICD director-duty guidance
  • Two deliverables: Executive Scorecard (1 page) and Detailed Findings Report (10–15 pages)
  • Board-ready output. Defensible to the regulator, the auditor, and the board.
For organisations that need a defensible picture of their AI security and governance posture before a deadline, an audit, or a board moment.
4 weeks AUD $80,000–$180,000
Specialism 02 · Build

AI Agent Discovery

Mission alignment, workflow mapping, build feasibility. The front door to every Mycelium agent build.

  • A two-week diagnostic before any agent build is commissioned
  • Mission Alignment Document — what the function exists to do, and what the agent must never do
  • Workflow map — how the work actually happens, observed not assumed
  • Build specification and executive sign-off path
  • Outputs into Phase 02–05 of the agent build, or stands alone
For organisations ready to build a purpose-built AI agent and willing to commission the work the right way — mission first, build second.
2 weeks AUD $18,000–$35,000
Build Phase · Following Discovery

AI Agent Build

Departmental agents, built against the mission, governed by the people who use them.

  • Five phases: Mission Alignment, Workflow Mapping, Build, Departmental Review, Executive Release
  • No off-the-shelf compromise — built against the department’s actual workflow
  • Three sign-offs required before broader release
  • Five named agents now live — Banking & Finance Ops, Project Management, Legal Intake, Supplier Assurance & Onboarding, Energy Operations
8–18 weeks per agent AUD $35,000–$180,000 tiered
The Mycelium Journey

Diagnose. Govern. Enable. Operate.

Every Mycelium engagement begins with a diagnostic. Where the findings support further work, governance, enablement, and operation follow — in that order.

Diagnose
AI Security
Health Check
4 weeks · Fixed price
Board-ready output
Start Here
Govern
AI Governance
Framework
Following Health Check.
Scoped to findings.
Enable
AI Enablement
& Literacy
Role-specific.
Board literacy support.
Operate
Intelligent
Agent Deployment
Departmental AI agents.
Begins with Discovery.

Before the organisation, diagnose the board.

See Board AI Readiness →
AICD Director-Duty Guidance APRA CPS 230 AS ISO/IEC 42001 Free 10-Question Diagnostic

Australian boards are now formally accountable for AI in a way they were not eighteen months ago. AICD and HTI have published five major pieces of director-duty guidance. APRA CPS 230 is in force. AS ISO/IEC 42001 has been adopted as an Australian standard. The board's exposure has changed.

Board AI Readiness is the front door to every Mycelium engagement. A free 10-question diagnostic, a 3-hour facilitated workshop, and a 3-week readiness assessment — with each rung funding the discovery for the next. Most boards never need to go past rung two.

Before the program, diagnose the AI risk.

See the security practice →
14 Dimensions 4 Pillars 4-Week Diagnostic Privacy Act 2026

A four-week AI Security Health Check across 14 structured dimensions — Govern, Protect, Operate, Enable. Aligned to the Australian Government's six Essential AI Practices, plus eight additional control areas regulators are likely to formalise next.

Two deliverables. One clear picture. An Executive Scorecard ready to table at your next board meeting, and a Detailed Findings Report with a prioritised remediation roadmap. Board-ready before 10 December 2026.

Once the network is ready, here's what we build.

See the agent practice →
Banking & Finance Project Management Legal Intake

Three purpose-built AI agents are available to commission now. Each is built against a department's specific mission, governed by the people who use it, and released only after executive sign-off. No off-the-shelf compromise.

Phase 1 demos are available for all three — a working prototype on synthetic data, no production access required, in 4 weeks. The right way to show leadership what's possible before a full build is commissioned.

Two scales.
One problem.

Organisations engage when major initiatives are failing at implementation — where strategy is clear at the top and dissolves before it reaches the front line. The operating conditions beneath the structure are the cause. In every sector. At every scale.

Mid-Market · 100–500 People

Organisations that have scaled past what personal leadership can hold together.

Coherence is fracturing. The operating conditions that worked at 80 people no longer function at 300. The diagnostic shows where they need to be deliberately rebuilt — before the next growth phase, acquisition, or strategic shift.

Large Enterprise · 1,000+ People

Organisations where major initiatives keep failing at implementation.

Strategy is sound. Investment is committed. The program is not landing. Stage 1 identifies precisely where the operating conditions are failing to carry the change — and what it will take to restore them before further spend is made.

Sector
Government & Public Sector
Sector
Critical Infrastructure
Sector
Financial Services
Sector
Enterprise Technology

Four
entry points.

Organisations engage at different stages of the same problem. The diagnostic conversation is the same regardless of where you are — it determines what is causing the issue, which stage applies, and whether we are the right firm to address it.

Before Launch

You want to know if your organisation is ready before committing the budget.

Stage 1 confirms readiness before capital is allocated. If conditions are not present, you will know precisely what it will take to create them — and what it will cost to proceed without doing so.

Assess whether the organisation can carry the investment before it is committed. Request a Diagnostic Conversation →

During Stall

Your AI program has plateaued despite deployment, training, and mandate.

The program is live, the technology is deployed, adoption is not following. Stage 1 identifies the specific operating conditions responsible. Most stalls are diagnosable within weeks.

Diagnose why adoption is not holding before investing in more tools or mandate. Request a Diagnostic Conversation →

After Failure

An AI program failed. You need to understand why before trying again.

Repeating the program without changing the conditions produces the same result. Stage 1 determines what failed and why. Stages 2 and 3 are offered only when findings support a viable path forward.

Determine what broke and whether the conditions exist to restart. Request a Diagnostic Conversation →

Before Further Spend

More tools, licences, or training is being considered. Stage 1 first.

Additional investment in an unready network extends the loss. Stage 1 confirms whether the next tranche of spend will produce genuine use — or add to the sunk cost.

Test whether additional spend will convert to adoption or compound the problem. Request a Diagnostic Conversation →

The first conversation
is diagnostic.

Sixty minutes. We assess the presenting problem, determine the right entry point, and establish whether our approach is the right one for your situation.

No pitch. No proposal until it makes sense.

The diagnostic reduces the risk of

Funding AI programs the organisation cannot absorb

Scaling low adoption with further spend

Receiving false-positive program status from filtered reporting

Discovering adoption failure after the investment is committed

Request a Diagnostic Conversation
Location Southbank, Melbourne VIC
Experience 30 years across government, critical infrastructure, financial services, and enterprise technology.
Engagement Each stage stands alone. Stage 1: AUD $35,000–$65,000.