Australian SMBs operate under a lot of law. Tax law, employment law, privacy law, consumer law, cyber law, financial-services law. Getting one of them wrong is the kind of event that reshapes a quarter. Getting the wrong one wrong because the AI didn't check is the kind that reshapes a year.
XGVS is the answer to that problem. 356+ gates. 6 verification stages. 34+ compliance frameworks. Every AI action passes every gate that applies — or the action halts and tells you which framework it violated, which gate caught it, and what rollback point was captured before it started.
This is a deep-dive on the 34+ frameworks, grouped into 7 categories, plus three real scenarios where compliance failure surfaced on an AU SMB — and how XGVS catches that exact pattern.
The 7 categories
34+ frameworks. 7 categories. Every one maps to a gate.
Tax & ATO
Every lodgement, every BAS, every super contribution, every PAYG withholding — cross-checked against live ATO rules before the action reaches your books.
Employment & Workplace
Every pay run, every shift, every overtime calculation — cross-verified against the right modern award, the right super fund, the right workplace standard before wages hit employee accounts.
Privacy & Data
Every AI action that touches personal information checked against APP obligations, NDB reporting triggers, and CDR consent boundaries — before an email draft, a data export, or a portal update is allowed to proceed.
Consumer & Commercial
Every customer-facing claim, every quote, every marketing message checked against Australian Consumer Law — no misleading representations, no unsubstantiated guarantees.
Cyber & Security
Every system access, every credential flow, every piece of data at rest and in transit measured against the Australian Cyber Security Centre’s Essential 8 plus international security standards recognised by AU enterprise buyers.
Financial Services & AML
Every transaction above the reporting threshold, every suspicious pattern, every financial advice action checked against AFSL requirements and AUSTRAC rules before logging or export.
E-invoicing & Industry Standards
Every invoice, every reporting format, every interchange pattern aligned with the e-invoicing network Australia is standardising on for B2B + government payments.
The 22 frameworks listed above are publicly documented. The remaining 12 cover specialised industry regulations (healthcare, childcare, transport, real estate, legal, construction) and are verified on industry-tagged AI actions only.
When compliance fails
Three real failure patterns. Three gates that would have caught them.
Marketing copy that breached ACL §18.
AI generated a promotional email line claiming "guaranteed 40 % cost reduction" to a cohort of 380 SMB prospects. Two complaints later, the ACCC wrote. The agent could not cite a substantiation. The company paid for legal counsel and a consent-order remediation.
Essential 8 blind spot on admin credentials.
AI exported a customer dataset to a private bucket for "admin review" — bypassing MFA, missing application-control logging, exceeding the application patch age threshold. The breach wasn’t malicious. The AI was helpful. The controls were not.
Super contribution calendar out of date by 12 weeks.
AI payroll agent prepared super contributions on the quarterly cadence it was trained on — but the Payday Super transition had moved the reporting cadence to weekly. Twelve weeks of super was under-remitted. Each employee got a late-payment SGC notice.
Scenarios composed from common AU SMB incident patterns. Names and identifying details generalised.
How XGVS runs on every AI action.
Every AI action in XIntelliSync passes through six verification stages before it reaches your books. Code-level checks, not LLM calls — which means the evaluation runs in the tens of milliseconds, not seconds. The penalty for verification is visibility, not speed.
- Stage 0 · Static code gates — the action meets the code contract.
- Stage 1 · Cross-file consistency — the action aligns with related records (invoices, customers, employees).
- Stage 2 · Live integration — the action matches live database state before write.
- Stage 3 · Agent behaviour (XAVS) — the agent producing the action is V1-certified on 10+ dimensions.
- Stage 4 · End-to-end workflow — the action composes correctly with adjacent operations (approval, audit, rollback).
- Stage 5 · Runtime monitoring — Horizon observes the live execution for drift, anomaly, and degradation.
356+ gates fire across those six stages. Each gate maps to one or more of the 34+ compliance frameworks. One gate fails, the action halts — and the system tells you which framework it violated, which gate caught it, and what rollback point was captured before it started.
If the gate fails, we both lose.
If the ATO asks why your BAS under-reported GST and the answer is "the AI got it wrong," we both lose. If Fair Work catches an award underpayment our payroll agent missed, we both lose. If the ACCC opens a misleading conduct file on a marketing line our AI drafted, we both lose. If a Privacy Act breach traces back to an under-verified agent accessing customer records, we both lose.
Every gate in XGVS exists because one of those outcomes would otherwise be possible. The gate is the answer to the question "what stops this from happening?" — codified, run on every action, logged, auditable.
The verification engine runs 24/7 across every AI action, every write, every API call. You don't watch it work. You watch your numbers be right.
Key takeaways
- 356+ gates evaluate every AI action across 34+ compliance frameworks before the action reaches your books.
- Gate failures halt the action and explain which framework it violated — no silent failures.
- The 34+ frameworks span tax (ATO DSP, STP Phase 2, BAS, GST, Payday Super), employment (Fair Work 121+ awards), privacy (Privacy Act APPs, NDB, CDR), consumer law (ACL §18, §29), cyber (Essential 8, OWASP, PCI-DSS, SOC 2, ISO 27001), financial services (AFSL, AUSTRAC), and e-invoicing (Peppol).
- XGVS runs on every tier — Starter, Growth, Enterprise. The verification engine is the foundation, not an add-on.
- Every AI write creates a 24-hour rollback point before the gate evaluation. Undo is one click.
XGVS + 34+ frameworks — questions answered.
What is XGVS and how does it verify AI actions?+
How many compliance frameworks does XGVS verify against?+
Does XGVS slow AI actions down?+
What happens when a framework gate fails at runtime?+
Is XGVS verification available on every tier?+
Can I see the full verification trace for a specific action?+
Is XIntelliSync a registered ATO Digital Service Provider?+
Keep reading
Deeper on the Trust Stack.
Pillar page
AI Verification — the full overview
All four Trust Stack systems in one place — Omega, Horizon, XAVS, XGVS — and how they compose into a single verification engine.
Read pillarSpoke · Risk
Why AI Hallucinations Break Financial Data
Three real hallucination patterns that cost AU SMBs at BAS, payroll, and audit — and how the Trust Stack catches them.
Read spokeTrust Centre
Security, privacy, and AI governance
Four-system architecture, 34+ compliance frameworks, data sovereignty, incident response.
See Trust CentreFounder
Why I built the verification engine
Two years of work before you ever logged in. 29+ layers · 388+ phases · 356+ gates · 34+ frameworks. One operator, end-to-end.
Read founder356+ gates. 34+ frameworks. Every action. Every plan.
From $97/month AUD. The verification engine is the foundation, not the feature. Built in Australia. Built for what's next.