What a Fractional CTO Actually Is — And Why Australian Mid-Market Firms Have Until 10 December

Updated September 2026

On 10 December 2026, new transparency obligations under the Privacy Act commence. From that date, if your organisation uses a computer program to make decisions about people, or to score, rank or categorise them in a way that materially shapes a human decision, your privacy policy has to say so, in specific terms.

That is under four months away.

Most Australian organisations under 100 staff will not be ready. Not through carelessness. The obligation lands in a gap: too technical for the leadership team to have registered, too strategic for anyone in IT to have authority over. Nobody’s job description contains the words “notice this”.

That gap is the entire argument for a fractional executive.

What a fractional executive actually is

A fractional CTO is a senior technology executive engaged on a part-time, ongoing retainer, typically one day a week, or two days a month, who holds real accountability for an organisation’s technical direction, rather than delivering a report and leaving.

A fractional CAIO (Chief AI Officer) is the same arrangement applied to artificial intelligence: ownership of AI strategy, governance, tooling, vendor selection, staff capability and risk posture.

Three things distinguish this from consulting.

  • Continuity. A consultant produces an artefact. A fractional executive carries the consequences of last quarter’s decision into this quarter’s.
  • Accountability. The name goes on the recommendation. It also goes on the incident review.
  • Authority. They sit in the leadership meeting, not outside it waiting to be briefed.

It is not a contractor with a grander title. It is a seat at the table, sized to what the organisation can actually use.

Fractional CTO

Why the mid-market keeps getting this wrong

A competent full-time CTO in Australia commands a package most organisations under 100 staff cannot justify. So they don’t hire one. What happens instead is predictable, and we see it constantly.

The best developer gets promoted. They are excellent at the thing they were hired for and have never made an architecture bet with a five-year blast radius. They have never negotiated with a vendor who knows more about the contract than they do. They have never had to tell a board that the cheap option is the expensive option.

Or the decision goes upward, to a managing director evaluating a platform migration on the strength of a sales deck.

Or, most often, the decision doesn’t get made at all. The organisation defaults into its incumbent supplier’s roadmap and calls it a strategy.

None of these are failures of intelligence. They are failures of pattern exposure. Someone who has personally watched thirty of these decisions play out prices risk differently to someone facing their first. That exposure is the product. You do not need to buy it forty hours a week.

What you are actually accountable for now

The Australian regulatory picture changed in a way most people have read backwards.

In December 2025 the federal government released the National AI Plan and declined to introduce a dedicated AI Act, or the mandatory guardrails proposed the year before. Plenty of people took that as a reprieve.

It was the opposite. The decision was that AI would be governed by the law that already exists, privacy, consumer protection, anti-discrimination, copyright, work health and safety, and whatever your sector regulator already expects. There is no separate AI compliance regime arriving to give you a clean start and a generous transition period. There is your existing obligation surface, now with AI running through it.

Four things follow.

The December deadline is broader than it sounds. Australian Privacy Principles 1.7 to 1.9 require you to disclose the kinds of personal information your automated systems use, and the kinds of decisions those systems make or substantially inform. The threshold is not “fully automated”. A tool that scores, shortlists or categorises people is captured if a human materially relies on the output. OAIC guidance is expected around September.

Most organisations that say they don’t use AI, do. Your applicant tracking system ranks candidates. Your CRM scores leads. Your helpdesk routes tickets by predicted priority. Your accounting platform flags anomalies. None of it was procured as “AI” and all of it may be disclosable.

Your vendors’ decisions are your obligation. The duty sits with the entity handling the personal information, not with the software company. If a third-party tool in your stack performs automated decision-making and cannot tell you how, that is now your problem to resolve, commercially, in a contract, before December.

More is coming, and it is not the part people expect. In July the Prime Minister announced a national AI framework and an Office of AI within Prime Minister and Cabinet, with legislation flagged for 2027. In the meantime the National AI Centre’s Guidance for AI Adoption, the six practices known as AI6, is the practical baseline. It is voluntary. It is also what a regulator, an insurer, or an enterprise customer’s procurement team will measure you against.

None of this is exotic. It simply requires someone to hold it, quarter after quarter, with the standing to make a call.

Why Ey3

Ey3 is a Brisbane consultancy operating across cybersecurity, managed hosting, custom development and applied AI. Our principal, Luke Elin, has spent more than thirty-five years in database architecture, web engineering and security, offensive and defensive, and most recently served as a Generative AI Engineer with the Queensland Government, building adoption frameworks inside government departments subject to precisely the obligations described above.

That combination matters more than it sounds. Most AI advisers have never run an incident. We maintain a fleet of production infrastructure, we have handled live compromises with month-long dwell times, and we have written the remediation as well as the post-mortem. When we assess your AI exposure, we assess it as people who know what an actual breach looks like at three in the morning, not as people who have read about one.

We also don’t sell fear. Most AI risk in Australian SMEs is mundane, cheap to fix and unglamorous. We would rather tell you that and be useful than tell you the sky is falling and be expensive.

Start with an hour

We offer an initial conversation at no cost, and we will tell you honestly if you don’t need us. Sometimes the answer is a two-page policy and a staff briefing. Sometimes it’s a genuine architectural problem. Either way you’ll know which one you have.

Next step

Contact Ey3, Brisbane, servicing Australia-wide.

Call 1300 856 393

Common questions

What is a fractional CTO?
A part-time senior technology executive on an ongoing retainer, typically one day a week or two days a month, who holds real accountability for technical direction and sits at the leadership table rather than advising from outside.
What happens on 10 December 2026 under the Privacy Act?
New transparency obligations commence requiring organisations that use computer programs to make, or substantially inform, decisions about people to disclose this in their privacy policies. It covers systems that score, rank or categorise people, not only fully automated decisions.
Why might a business not realise it needs to comply?
Many use AI-powered tools such as applicant tracking, lead scoring or helpdesk routing without recognising these as automated decision-making. Responsibility stays with the business even when a third-party vendor supplies the tool.