Insight,

Lessons from the Digital Future Summit 2026: How to harness change for strategic advantage

AU | EN
Current site :    AU   |   EN
Australia
Singapore

For our sixth annual Mallesons Digital Future Summit, we focussed on Harnessing Change for strategic advantage in a world defined by technological disruption and geopolitical uncertainty. 

Revisit the key messages from each Digital Future Summit session and catch up on any you missed by watching or listening to the conversations on-demand. Want the high-level snapshot? Scroll down for our takeaways.

Session 1 | Quantum and Australia’s advantage: Capturing value in the next tech revolution

'Quantum actually has an opportunity to save the planet and possibly the Australian economy - it is so important. It's going to have a lot to do with you.' - Dr Cathy Foley

Speaker: Dr Cathy Foley AO PSM, Executive Chair, Sydney Quantum Academy, former Chief Scientist of Australia

Moderator: Rachael Lewis, Mallesons Partner

With world-leading research, fast-growing companies and strong investment, Australia could take a leading role in quantum. But it will require sustained commitment, the right policy settings and deep collaboration across industry, government and academia.

Australia's former chief scientist Dr Foley explained how early movers will shape the market, the benefits of organisational literacy, and the urgent need for cyber resilience and strong governance (especially to guard against the threat of 'harvest now, decrypt later').

Key takeaways

  1. Understand what it means for your organisation - now. From sensing and navigation to secure communications, know what’s coming and how quantum will reshape your sector and affect your organisation(without becoming a physicist).
  2. Financial services and energy carry some of the clearest near-term use cases. Banks are exploring applications for investment decisions and fraud detection, while energy companies are looking at grid optimisation and infrastructure security.
  3. Get serious about cyber risk and build governance frameworks. Every board should have quantum on its risk register, given the live threat of 'harvest now, decrypt later' (data stolen today can be decrypted later). The Australian Signals Directorate expects plans in place by the end of 2026 and transition arrangements by 2028.
  4. Collaborate, don’t go it alone. Partner across industry, government and academia. No single organisation can capture this opportunity in isolation.
  5. We can combine AI and quantum for growth. Quantum systems can generate better, more secure training data for AI, and AI can help optimise quantum systems. Australia has an opportunity to combine the technologies for productivity growth across the economy.

Session 2 | The ACCC’s digital enforcement agenda

'We want compliance by design, not as an afterthought.' - ACCC Commissioner Luke Woodward

Speaker: Commissioner Luke Woodward, Australian Competition and Consumer Commission

Moderators: Tamara Hunter and Jennifer Barron, Mallesons Partners

Speed and scale are what make digital markets valuable. They can also magnify harm.

That was the thread running through ACCC Commissioner Luke Woodward’s remarks, as he set out the regulator’s enforcement agenda for digital and data-enabled markets.

Commissioner Woodward described the ACCC’s mindset as 'proactive, practical and outcome focused' and encouraged business to adopt a compliance by design approach. The ACCC’s integrated approach spans enforcement under the existing Australian Consumer Law and competition provisions, the new unfair trading practices prohibition commencing 1 July 2027, and advocacy for a targeted ex ante digital competition regime, considering current and emerging consumer and competition risks in dynamic digital markets, including in relation to AI.

Key takeaways

  1. The ACCC is actively enforcing existing laws. It is prioritising manipulative practices that distort consumer choice, unsafe consumer goods, and the undermining of consumer guarantees. Commissioner Woodward noted that the ACCC will look beyond specific contraventions to the totality of a business’s conduct, including senior leadership accountability and compliance systems. This echoes themes in the Chair’s enforcement priority speech in early 2026.
  2. Compliance by design is the practical ask. The Commissioner’s central message to business is to build lawful conduct into digital customer journeys from the outset, rather than assembling a compliance case after the fact.
  3. Manipulative digital design is a target under the unfair trading practices prohibition. Conduct in the frame includes creating a false sense of value, such as through deceptive discount promotions, designing customer journeys that circumvent consumers’ natural caution, and deploying online hard-sell tactics such as countdown clocks and 'buy now' signals.
  4. Australia’s proposed ex ante digital competition regime will be calibrated, not general. Designed to prevent competition problems before they occur, the model favoured by the ACCC would be developed on a service-by-service basis through consultative processes. In contrast to the EU’s broader DMA approach and Japan’s narrow focus on smartphone software, the Australian regime will likely sit'somewhere in the middle'.
  5. AI will require a rapid evolution, but not a revolution. Commissioner Woodward rejected the idea that AI requires a fundamentally different regulatory approach, noting there is no longer a distinction between the digital and non-digital economy. It is now just 'the economy'. The more immediate risks are on the consumer side: AI amplifying manipulative design practices, facilitating scams, collecting data without consent, and raising questions of legal accountability. Emerging competition risks, such as tying up data inputs and algorithmic collusion, will also be closely monitored.

Session 3 | Online safety and accountability: What businesses need to know

'We want compliance by design, not as an afterthought.' - ACCC Commissioner Luke Woodward

Speaker: Julie Inman Grant, eSafety Commissioner

Moderators: Michael Swinson and Bryony Evans, Mallesons Partners

Australia’s eSafety Commissioner, Julie Inman Grant, discussed the importance of safety by design, establishing normative and cultural change through the social media minimum age framework, and how Australia is leading the global charge towards online safety.

There are no expectations that it will be an 'overnight success', given that we're unwinding about 20 years of social media being entrenched in our lives. But one thing is clear: the future of online safety is 'safety by design'.

Key takeaways

  1. Cooperation can deliver more durable outcomes. While there will always be tension between companies and regulators, shared objectives and cooperation often lead to meaningful change and more durable outcomes than adversarial enforcement alone. By way of analogy, car manufacturers now compete on safety standards,asa point of innovation. 
  2. Make safety a core governance concern. Like security and privacy before it, safety must be embedded as a core governance concern rather than treated as a compliance exercise. The proposed digital duty of care positions safety by design as the primary scaffolding for platform accountability.
  3. Technology will always outpace policy. Proactive 'future casting' and systemic change are essential. However, anticipatory regulation will demand significant government investment in resources and technical capability. We should have applied important lessons learned from the social media ageto AI, which is moving faster and could bring more potentially catastrophic harms.
  4. The social media minimum age legislation is about sustained cultural change. Rather than immediate results, the long-term objective is to shift community norms around children’s access to social media, the role and responsibility of platforms, and the conversations we have with young people on social media.It's not about trying to prevent kids from accessing social media, but social media from accessing kids.
  5. Global regulators are focused on coherence. Different legislative frameworks, political imperatives and cultural traditions complicate that goal. International engagement and structured forums like the Global Online Safety Regulators Network are key to bridging those gaps.

Session 4 | Data breaches, privacy and class actions

'For any major breach, litigation is certainly, in my opinion, on the cards... There are no shortcuts to compliance on this.' – Nicholas De Young  

Speakers: The Honourable Justice Kate Richardson, Supreme Court of New South Wales; Nicholas De Young KC, Barrister

Moderators: Peta Stevenson and James Russell, Mallesons Partners

Data breaches have become an almost inevitable feature of doing business in the modern world. Litigation is likely to flow from these incidents, and it is more important than ever for companies to be prepared.

New legislative changes have also made it easier for individuals and groups to pursue claims for privacy breaches through the courts, including a new statutory tort for serious invasions of privacy, and a new provision in the Privacy Act (s 80UA). This provision gives a direct right to compensation following the finding of a breach of a civil penalty provision. Companies should take careful steps in the aftermath of a cyber incident and should ensure their plans and processes are well formulated to respond.

Key takeaways

  1. Major data breaches should now be expected to result in litigation from multiple fronts. The Federal Court has taken the approach of case-managing these overlapping proceedings together, which presents significant complexity for respondents.
  2. Section 80UA (civil penalty in the Privacy Act) is a 'radical change'. It provides a quasi-direct right to compensation once the Commissioner establishes a contravention in civil penalty proceedings, sidestepping the difficulties that plaintiffs traditionally face in proving breach of contract or negligence.
  3. Keep operational investigations separate from legal investigations. Public relations messaging must be carefully managed to avoid inadvertent waiver of claims for legal professional privilege.
  4. Proactive preparation is essential. Data breaches are inevitable, but good governance reduces exposure. Organisations should critically assess how much data they are retaining, properly resource IT and risk departments, and have a clear incident response plan that identifies how operational, PR and legal workstreams will be managed if an incident occurs.

Session 5 | AI, judgment and strategic decision-making

'People that do work with agents don't talk in terms of efficiency. They talk in terms of enlargement, enablement, the capability to reach higher, go further.' - Professor Anthea Roberts  

Speaker: Professor Anthea Roberts, Founder and CEO, Dragonfly Thinking; Professor, School of Regulation and Global Governance, Australian National University

Moderator: Bryony Evans, Mallesons Partner

Much of the current conversation on AI’s return on investment is centred around efficiency gains: doing the same work faster and at lower cost. However, in this session, Professor Roberts discussed how AI’s greatest value comes from augmenting human judgement and enabling better decision-making in complex, uncertain environments.

Professor Roberts highlighted that professionals who develop deep AI fluency alongside domain expertise will direct, coach and edit AI outputs rather than be displaced by them, and that organisations which invest in that shift now will shape the market rather than merely reacting to it.

Key takeaways

  1. Move from automation to augmentation. The real opportunity with AI is in enlargement and enablement rather than just efficiency. Those who develop fluency with AI agents report being able to reach into new domains, hold greater complexity, and produce work they could not have done alone, rather than simply doing existing tasks faster.
  2. Become the director of AI. As AI agents take on more of the primary execution work, professionals shift up a level into being directors of AI. The task becomes one of coaching AI iteratively when it goes off course and editing its outputs to ensure accuracy and voice. This transition also requires a new set of managerial skills to lead blended teams of people and AI agents.
  3. AI enables 'dragonfly thinking' for complex decisions. Using a case study of the evolution of Australia and China’s relationship, we demonstrate how AI can map multiple actors, drivers, system dynamics and scenarios across contested environments in ways that surpass any individual’s cognitive capacity. The benefits include enhanced situational awareness, scenario planning, identification of early warning indicators, and the ability to update analysis dynamically as events unfold.
  4. Law is the 'gateway drug' for AI diffusion into other sectors. Legal work is text-dense and pattern-rich, yet ultimately still depends on human judgement. This combination positions law as an early and influential adopter of AI, and as a testing ground for the judgement-intensive, human-AI collaboration model likely to spread across all professional services.
  5. Invest in the next generation of professionals. AI can do much of the work traditionally done by junior professionals, but without the corresponding investment in their growth and development. As seen with outsourcing in the era of globalisation, short-term efficiency gains come at the risk of undermining long-term institutional capability. Organisations should rethink how they build professional judgement through coaching, simulation and deliberate exposure to AI-assisted workflows.

Session 6 | AI and the future of work

'Human judgement, human empathy, human creativity, human adaptability... those are the things that are going to become ever more important in the workplace.' - Professor Toby Walsh

Speaker: Scientia Professor Toby Walsh, Chief Scientist, UNSW.ai; Scientia Professor of Artificial Intelligence, UNSW Sydney 

Moderator: Cilla Robinson, Mallesons Partner 

AI is not just changing the tools we use – it is reshaping how work is designed, how people are developed and how organisations are led. Unlike previous industrial revolutions that unfolded over decades, AI is scaling overnight, and the friction is human, not technical.

Professor Walsh explained that the imperative for leaders is to treat AI as a leadership issue, not solely a technology project. That means investing in people even when AI could do the task faster, protecting the talent pipeline that builds expertise, and designing AI adoption so it augments human judgement rather than replacing the effort that develops it.

Key takeaways

  1. Treat AI as a leadership issue. Accountability, transparency, skills, workforce design and safety are decisions for boards and senior leaders, not IT departments. Organisations need an enterprise-wide view of AI adoption that addresses governance, risk and people strategy together. 
  2. Protect the talent pipeline. AI tools can perform many tasks previously done by junior professionals, but if those entry-level roles disappear, organisations lose the pathway through which people develop expertise. Businesses may need to absorb the cost of having humans do work that AI could do more cheaply, to ensure the next generation of professionals builds the judgement required for senior roles, including the capability to supervise the AI performing the entry-level tasks.
  3. Keep humans at the centre – deliberately. Design AI adoption so that it augments human decision-making rather than replacing the skills that underpin it. The most effective outcomes emerge when AI and humans work together. As Professor Walsh noted, the gold standard in radiology is now one AI and one human, because their strengths are complementary. Human judgement, empathy and creativity will become more valuable, not less.
  4. Transparency matters, but it is not enough on its own. Organisations should be clear about where and how AI is used, in customer interactions, in decision-making and in the workplace. Transparency can help employees, customers and regulators have greater confidence. Transparency without good governance, however, can simply shine a light on bad decisions. The real ask is to build systems that are both transparent and well governed.
  5. AI won’t take your job, but someone who knows how to use AI might. Professor Walsh’s advice is to get familiar with the tools now: understand their capabilities, recognise their limitations, and learn how they can help. The organisations and individuals who engage early and thoughtfully will be best placed to harness the change rather than be disrupted by it.

Session 7 | Building resilience in the AI era

'What you depend on and what you will increasingly depend on can be taken away because of a contest that has nothing to do with you. We cannot rely on a strategy of hope and trust anymore.' - Dr Merriden Varrall

Speakers: Dr Stephen King, Commissioner, Productivity Commission
Dr Merriden Varrall, CEO, VantageGeopol  
Cameron Mitchell, Head of Geopolitical Risk, ANZ  

Moderator: Annabel Griffin, Mallesons Partner

Capturing the significant opportunities that AI and emerging technologies present for Australia depends as much on geopolitics as on technology, with governments around the world treating AI as a tool of national power and strategic advantage.  

The panel discussed Australia’s regulatory positioning and how the risks of dependency on foreign-controlled technology are among key factors businesses and boards must understand and consider, to make critical decisions ahead of regulation.

Key takeaways

  1. The liberal international order, and the rules and norms underpinning it, is being shaken apart. AI is a powerful technology arriving in a profoundly unstable geopolitical moment.
  2. Hope is not an effective strategy. US restrictions on foreign access to frontier AI models show that Australia cannot assume ongoing access to technology is assured. A bifurcation is occurring in global AI governance, with US-led and China-led blocs forming. Like-minded countries may consider aligning on AI policy to harness their collective power.
  3. Boards need to be proactive. Given the pace of change, boards will increasingly have to make decisions before the comfort of regulation is in place. Boards must question and interrogate existing assumptions and think deeply about geopolitical issues.
  4. Businesses need a fallback plan. Organisations that depend on a single source for critical technology inputs are vulnerable. Businesses need to consider the impact of geopolitics and supply chain risk, including in relation to AI, and need to have a plan B if access to critical inputs or technologies is disrupted.
  5. Predictable volatility. The geopolitical landscape appears chaotic, but the drivers behind policy decisions are structural, meaning volatility is more predictable than people may initially anticipate. Businesses must keep on top of volatility and attendant risk.

Session 8 | Cyber resilience: Preparing for what comes next

'There is an uplift required across the entire economy. And given the discussion we've just had on AI, that speed of which change is happening, the speed of the response needs to be commensurate with that.' - Hamish Hansford

Speakers: Hamish Hansford, Head of National Security, Department of Home Affairs   
Leah Pinto, Director, Cyber Intelligence, CyberCX  

Moderators: Michael Swinson, Mallesons Partner;  Cheng Lim, Mallesons Head of Cyber Practice and Senior Consultant

'Resilience isn’t about getting back to where you were before the cyber incident... it’s about moving forward after the incident.' – Leah Pinto

Organisations should assume they will experience a cyber incident at some point, and focus on preparing, responding and recovering effectively.

The pace of change is only increasing, but leaders do have choices, and good governance and clear judgement have never been more important.

The speakers also discussed the Government’s proposed reforms to the Security of Critical Infrastructure Act, aimed at ensuring that Australia’s critical infrastructure is as secure and resilient as possible. Importantly, the Department flagged that the reforms were also intended to support an intention to focus on enforcement of the SOCI Act moving forward.

Key takeaways

  1. Get the basics right. Most attacks still begin with unpatched vulnerabilities, weak credentials, legacy systems, poor segmentation and poor cyber hygiene.
  2. Building cyber resilience starts with people. Technical controls remain important, but organisations that invest in education, awareness and a culture where employees feel empowered to discuss cyber risks will be better positioned to respond to emerging threats. Cyber is human issue now, not just an IT one.
  3. Understand third-party risk. Third-party providers remain a major vector for cyber attacks. Organisations need to understand their critical suppliers, dependencies and concentration risks, particularly as AI and cloud services become embedded in operations.
  4. Board accountability and engagement are expected. With increasing regulatory scrutiny and a shift from education to enforcement, directors should challenge assumptions, ask questions and ensure they genuinely understand cyber risks.
  5. Prepare for faster, more sophisticated attacks. Organisations will likely see increasing sophistication of attacks, particularly as threat actors start leveraging AI. They must appreciate how quickly attack capabilities are evolving, alongside the growing convergence of cyber crime, nation-state activity and ideologically motivated actors, making the threat landscape increasingly difficult to assess.

 

How are organisations such as SEEK and Microsoft approaching AI and workplace transformation? Our AI Now podcast series brings together leading experts to discuss AI opportunities, risks and legal developments. Explore the full series on our Artificial Intelligence page and subscribe via our Preference Centre to receive new episodes and tech insights.

Latest Thinking
Insight
This is a significant decision for businesses that include arbitration clauses in their standard form consumer contracts, particularly in the financial services sector.

18 September 2026

Insight
The 2026-27 Federal Budget delivered a tax reform trio that is reshaping the investment landscape: changes to negative gearing, a return to CGT indexation (see CGT amendments: A blast from the past and a new minimum tax), and a minimum tax on discretionary trust distributions (see Discretionary Trusts - Limited time offer for relief from minimum tax). This alert unpacks the negative gearing reforms, which have now become law with the Treasury Laws Amendment (Tax Reform No. 1) Act 2026 (the Act).

18 September 2026

Insight
On 10 September 2026, the Treasury Laws Amendment (Strengthening Accountability for Tax Adviser Misconduct and Other Measures) Bill 2026 (Cth) (Bill) was passed by Parliament, which implements material changes to the ACCC’s mandatory notification regime.

18 September 2026