AIRiskAware
What Is...
Core Concept

What Is Generative AI?

Generative AI refers to AI systems that produce new content — text, images, code, audio, or video — by learning patterns from training data, rather than following explicitly programmed rules. It is the technology behind the most widely deployed AI tools of 2024–26, and the category most immediately relevant to enterprise governance.

How it differs from earlier AI

Earlier AI systems were largely discriminative — they classified inputs into categories, such as spam detection, credit scoring, or image recognition. Generative AI goes further: it creates outputs that did not previously exist. A text generation model does not retrieve a stored answer; it constructs a new one, word by word, based on learned patterns. This distinction is significant for governance because generative outputs are inherently variable, cannot be pre-approved, and carry risks that discriminative models do not.

Types of generative AI and their risks

TypeCommon toolsPrimary governance risks
Text generationChatGPT, Claude, Gemini, CopilotHallucination, bias, professional liability, confidentiality breach
Image generationMidjourney, DALL-E, Stable DiffusionCopyright infringement, deepfakes, reputational harm, consent issues
Code generationGitHub Copilot, Cursor, Gemini CodeSecurity vulnerabilities, copyright in training data, incorrect logic
Audio / voice synthesisElevenLabs, Suno, voice cloning toolsImpersonation fraud, consent violations, reputational damage
Video generationSora, Runway, KlingDeepfake harm, non-consensual content, disinformation

The regulatory picture

The EU AI Act creates a specific category — General Purpose AI (GPAI) — to address the most capable generative AI models. These are subject to transparency requirements, copyright compliance obligations, and for the most capable systems, additional safety obligations including adversarial testing and incident reporting, in force from August 2025.

In Australia, generative AI is not specifically regulated but existing laws apply. The Privacy Act governs how personal information is processed by AI. Australian Consumer Law applies to AI-generated product claims. Professional conduct standards from AHPRA, Law Societies, and accounting bodies apply to AI-assisted professional work. And the AI6 framework establishes governance expectations for organisations deploying generative AI tools.

What is an LLM? Building your AI controls register