AGL and Suncorp on building AI that’s worse than ChatGPT

Published on the 01/10/2026 | Written by Heather Wright


Trust and governance trump flashy AI experiences…

Suncorp’s Jonathan Rutter is blunt: “It can give a less than ChatGPT experience for the user,” he says of a Suncorp AI assistant. “But that’s important because we cannot have it giving the wrong information.”

While consumer AI tools compete to be more conversational and creative, businesses are clear that accuracy, governance and trust often matter more then delivering a flashy user experience.

Speaking at Gartner’s IT Symposium/Xpo on the Gold Coast recently, Rutter – who is executive manager, programs and systems within Enterprise Risk at Suncorp – and AGL head of architecture – security and corporate technology Yaso Addanki, shared how they are embedding AI into their businesses, moving away from AI experimentation towards practical business applications designed to solve specific operational problems.

Stopping the bottleneck

At AGL, AI agents were built not as part of a grand transformation strategy, but because security reviews were slowing projects down. As AI initiatives multiplied across the business, security architects found themselves reviewing a growing number of projects, each requiring assessments, threat modelling and architecture reviews before work could proceed.

“We were thinking how do we not become a bottleneck and actually help the organisation move faster with deploying their initiatives?,” Addanki says.

“We had internal discussions and thought ‘how much time are we taking to turn around a security architecture review and how can we make it better and faster?’”

The discussions evolved into the development of an AI agent which uses threat modelling frameworks to generate security review documentation, providing architects with an initial draft they can refine, rather than creating assessments from scratch.

Initially deployed within the security architecture team, the agent was designed to reduce turnaround times and free specialists from routine work. But AGL sees a bigger opportunity ahead.

Rather than waiting for projects to reach security teams, the company is exploring how the technology could be made available directly to solution architects, allowing controls to be incorporated much earlier in the design process. The goal is to improve the organisation’s overall security posture while helping delivery teams move faster.

The project reflects a broader approach to AI across AGL. Addanki says the company is focusing on three key areas: Building enterprise AI and data platforms, leveraging AI capabilities already embedded in existing tech tools and orchestrating those capabilities into agents that support business workflows.

Customer service has been one of the beneficiaries. Within one AGL subsidiary, AI is used to generate summaries of customer interactions, recommend relevant knowledge articles, draft email responses and deliver more consistent service across teams. By removing the need for staff to manually document every interaction, customer service representatives can spend more time focusing on customers rather than admin.

Teaching AI to speak governance

Suncorp has taken a similar approach, focusing on solving specific business problems within risk management.

“We started with business problems first,” Rutter says. “Things that we would have looked to provide an enhancement solution for pre-AI. So these things were areas that we were going to address regardless.”

“We’ve got three areas we like to tackle: UX, efficiency and then the data quality,” Rutter says.

One project focused on incident reporting. Whenever an operational risk incident occurs, information needs to be captured accurately so teams can investigate causes, resolve issues and prevent similar incidents in future. While reports are usually submitted by risk specialists they can also be submitted by frontline employees who don’t have experience in lodging incident reports.

Suncorp’s AI-assisted incident process guides users through submissions, prompting them for missing information and helping categorise incidents correctly.

“If you haven’t provided enough, it’ll prompt you for what you’ve missed and it’ll categorise it and help it flow through our process effectively.”

The result is improved data quality from the outset, Rutter says, making downstream investigations and reporting more effective. “It’s [an area] where we will get efficiencies, but data quality is the driver.”

The company is also using AI to tackle another common enterprise problem: Dense policy documentation.

Risk and governance documents are often lengthy, technical and difficult for employees to navigate. Suncorp is using AI to simplify the language, reduce duplication and then serve that information up in a chatbot-style interface that enables staff to ask questions directly, rather than searching through extensive document libraries.

A third initiative applies AI to control testing and governance activities, helping automate administrative tasks that would otherwise consume significant amounts of specialist time. Again, the objective is not workforce reduction, but enabling experts to focus on work that requires human judgement.

Why enterprise AI can’t act like ChatGPT

Despite the growing use of AI, both organisations say the path hasn’t been without challenges – including the issue of trust. And here’s where Rutter’s comment’s about being a ‘less than ChatGPT experience’ come in.

“In the example of the policy consumption, one of the biggest risks we’ve got is the accuracy of information. It somebody has asked our assistant for support and it doesn’t give them the right answer back, we’re in a bad position.”

The company has built guardrails into its systems, including source references, hyperlinks back to supporting material and explanations showing how answers were generated. Inbuilt guardrails behind the scenes ensure the chatbot won’t hallucinate or go off topic.

The approach may create a more constrained experience than employees get from tools such as ChatGPT, but it ensures there’s no providing of wrong information.

“Something we’ve learned along the way is people will expect that [ChatGPT experience] and we’ve had to educate them that this is serving a specific purpose and there are controls in place.”

At AGL, meanwhile, security teams face a different challenge: Keeping pace with rapidly evolving models and vendor offerings. Understanding where models are deployed, where data is stored, whether information is used for training and what controls are needed around those environments has become an increasingly important part of AI governance, Addanki says.

“Sometimes it could become a black box because we don’t understand and some vendors might not be able to kind of reveal some of those details to us,” she says.

She notes that could see contractual controls becoming required.

Winning buy-in

Both organisations also highlighted the importance of proving value early. At Suncorp, proof-of-concept projects have played a key role in building stakeholder support and demonstrating how AI can address real business pain points. AGL similarly started by solving problems within its own security function before expanding further.

For both, success has come from applying AI to specific operational challenges, removing administrative burden and helping specialists focus on the work that matters most. As Richie Paul, IBM generative AI practice lead, who hosted the session, summed up: “Yasso and Jonathan give us insight into this idea of having multiple programs going in parallel and really, a thousand flowers truly will bloom, which will be the marker of enterprise-wide organisational change.”

Post a comment or question...

Your email address will not be published.

This site uses Akismet to reduce spam. Learn how your comment data is processed.

MORE NEWS:

Processing...
Thank you! Your subscription has been confirmed. You'll hear from us soon.
Follow iStart to keep up to date with the latest news and views...
ErrorHere