Home · About

An AI governance firm
built for Australian boards.

Mycelium is an AI security, governance and agents practice for regulated industries. Diagnostic-led. Evidence-graded. Built to defend.

01 · Principal

Who’s behind it.

SS
Founder & principal consultant · Mycelium

Sara Shakib

Sara Shakib founded Mycelium to make AI governable for Australian boards and regulated industries. Thirty years across government, critical infrastructure, financial services and enterprise technology — building the diagnostic-led practice that turns AI risk into evidence boards can table, regulators can audit, and operators can use.

She authored the Mycelium 14-Dimension AI Security Framework — the operating model behind every Health Check, every agent build, and every board briefing.

Diagnostic-led. Evidence-graded. Built to defend.

02 · How we work

Three principles. One discipline.

  1. 01

    Diagnostic-led.

    Every engagement begins with a diagnostic. No engagement proceeds without one. If the diagnostic does not support further work, we say so before a proposal is written.

  2. 02

    Evidence-graded.

    Every finding maps to a control, a standard and a piece of evidence. Board-ready. Auditor-defensible. Regulator-ready. No abstractions, no slideware.

  3. 03

    Built to defend.

    Whether it’s a Health Check, a Framework or an Agent build, the output is designed to hold up in front of the people who matter most — your board, your regulator, your auditor.

03 · Sectors

Where we work.

Sectors where AI governance and board accountability are formally regulated — or about to be.

SECTOR · 01
Financial Services
SECTOR · 02
Banking & Mutuals
SECTOR · 03
Energy & Utilities
SECTOR · 04
Critical Infrastructure
SECTOR · 05
Government & Public Sector
SECTOR · 06
Enterprise Technology
SECTOR · 07
Insurance
SECTOR · 08
Health & Aged Care
CPS 230 · CPS 234 · AS ISO/IEC 42001 · ASD ISM · NIST AI RMF · AICD · Privacy Act 1988 (ADM 2026)
04 · Standards we map to

Frameworks behind the work.

Every Mycelium deliverable maps explicitly to the standards your board, auditor and regulator are reading.

  1. 01

    APRA CPS 230 · Operational Risk Management

    In force. Names AI as material technology requiring board oversight and risk management.

  2. 02

    APRA CPS 234 · Information Security

    In force. Establishes board accountability for information security capabilities, including AI systems.

  3. 03

    AS ISO/IEC 42001 · AI Management System

    Now an Australian standard. Defines management-system requirements for organisations using AI.

  4. 04

    AICD Director-Duty Guidance on AI

    Five major publications. Directly ties director duties of care and diligence to AI literacy and governance.

  5. 05

    Privacy Act 1988 (ADM 2026) · AI provisions

    Expands obligations around automated decision-making, model transparency and consumer rights.

05 · Start here

The first call is diagnostic.

Thirty minutes. No pitch. No proposal until it makes sense.

Book a diagnostic
30-MINUTE DIAGNOSTIC CALL · VIDEO OR MELBOURNE · BOOK DIRECTLY
Or download the Boardroom Diagnostic (PDF, 2 pages) ↗