Queensland’s Department of Transport and Main Roads says it has put AI-powered résumé ranking into production and intends to run 15 AI projects by Christmas 2026, followed by another 15. For an agency already using Microsoft 365 Copilot and operating a transport portfolio with thousands of staff, the significant development is not the number of pilots: it is that TMR is moving AI into processes that can affect employment decisions while still rebuilding the governance controls an independent audit found lacking last year.

iTnews first reported the plans from comments by Paul Hesford at an SAP customer event in Sydney. Hesford said Director-General Sally Stannard has made AI adoption a leader-led effort, including sharing how she uses Copilot in internal messages, while Chief Finance Officer Nick Shaw has pressed for broader access to AI tools. TMR’s public organisational chart confirms Stannard remains Director-General and Shaw is the department’s CFO.

The report offers an unusually clear picture of the executive sponsorship behind a government agency’s AI push. It offers far less detail on the systems themselves: TMR has not publicly identified the 15 projects expected to be live by December, their suppliers, whether they will use generative AI or conventional machine learning, which ones will process personal data, or how staff and members of the public can challenge an AI-assisted outcome.

That missing detail matters most for the new résumé-ranking system. TMR says it has gone live, but neither the department nor iTnews has disclosed the software platform, what inputs are evaluated, whether candidates are filtered out automatically, how rankings are tested for bias, or whether applicants are told that an AI system has participated in the screening process.

Business professionals review analytics dashboards and cloud security systems in a modern waterfront office.A rollout plan arrives after a warning on oversight​

TMR is not starting its AI work from scratch. Its 2024–25 annual report documented a Microsoft 365 update pilot involving 350 participants, including Copilot, that recorded 2,100 task-completion hours saved across 28 days. The department also identified data and AI as a workforce capability priority, participated in Queensland Government’s Microsoft 365 Copilot and QChat pilots, and said it was developing an AI strategy.

But the Queensland Audit Office’s September 2025 review found that TMR did not yet have comprehensive department-wide arrangements to oversee AI ethical risks. The audit focused on TMR’s QChat generative AI service and its Mobile Phone and Seatbelt Technology image-recognition program. It found the department lacked a central inventory covering AI systems in use or under development, had not completed full ethical-risk assessments for the audited tools, and needed stronger monitoring and assurance mechanisms.

TMR accepted the audit’s recommendations and said it was progressing changes. The audit also noted that the department was developing an AI Strategic Roadmap for 2025–28. That is important context for the new target: the department’s public commitment is no longer a limited productivity trial or a roadmap exercise. It is a plan to put 30 AI projects into production, beginning with 15 before the end of 2026.

A fast-growing project portfolio makes a central register, common approval gates and repeatable risk assessments more important, not less. Without them, an agency cannot reliably answer basic operational questions: which models are deployed, who owns them, what data they handle, which decisions they influence, when they were last tested, and what happens if an output is wrong.

For enterprise IT teams, this is the difference between encouraging tool use and running an AI service portfolio. Executive enthusiasm can clear the cultural obstacle that often blocks adoption. It does not substitute for asset management, access controls, records retention, evaluation, incident reporting, procurement scrutiny and independent assurance.


Copilot use is expanding from drafting into finance work​

Hesford told iTnews that TMR uses Microsoft Copilot to assist with work tied to its $10 billion budget, including ministerial submissions, case studies and annual-report material. He also said Copilot was used to draft an ethical assessment related to the department’s SAP platform adoption.

These are plausible productivity uses, but they deserve more careful separation than a single “Copilot” label permits. Drafting an internal case study, helping summarise material and shaping a document outline are one category of task. Preparing material associated with budget management or ministerial submissions is another, because errors, omissions, confidentiality breaches and weak source traceability can have more serious consequences.

Queensland Government guidance on the use of generative AI makes public servants responsible for content they create, share or use. It also advises staff to review AI-generated outputs, keep appropriate records of information used to generate and apply an output, and conduct risk assessments before using commercial generative-AI tools. In its examples, the guidance treats the use of financial and project-risk information in a commercial tool as potentially inconsistent with information-security and usage policies.

That does not establish that TMR has mishandled financial information or ministerial documents. It does show why a department should explain the controls around such use before presenting Copilot adoption as a simple productivity story. The public record does not say whether TMR’s Copilot deployment uses tenant controls, sensitivity labels, data-loss-prevention rules, restricted connector access, prompt logging policies, or mandatory review and sign-off for financial and ministerial material.

For Windows and Microsoft 365 administrators, the practical lesson is straightforward: a leadership-driven Copilot rollout needs a workload-by-workload operating model. A tenant licence and a broad training campaign do not determine whether a user should be able to ground prompts in financial files, SharePoint sites, mailbox content or project repositories. Permissions, classification and review practices do.

Résumé ranking is the point where governance becomes visible​

The department’s new résumé-ranking use case is more consequential than the drafting examples because it sits at the front of a public-sector recruitment process. Hesford told iTnews that the business had raised ethical concerns, and described the approach as human-controlled AI rather than the more familiar “human in the loop” model.

The phrase is useful only if it describes concrete controls. A human being who merely receives a ranked list and accepts it under time pressure is technically in the loop, but may not be exercising meaningful control. A genuinely human-controlled process would require that the responsible recruiter understands what the system is doing, can override it, has sufficient information to identify unreasonable results, and records why a recommendation was accepted or rejected.

TMR has not yet publicly described those controls. It has not said whether the system scores applications against selection criteria, extracts skills, groups candidates, ranks them against a job description, identifies missing requirements, or performs some combination of those functions. It has not disclosed whether the output is advisory only, whether a human reviews every application before anyone is excluded, or whether it measures different outcomes across demographic groups and employment histories.

Those omissions are not semantic details. Résumé ranking can amplify historical patterns in training data, penalise candidates whose experience is expressed differently, and create a false impression of precision from a score that is ultimately dependent on the job criteria, data quality and model configuration. In public-sector hiring, the department must also be able to account for its process if a candidate seeks an explanation or challenges an outcome.

The Queensland Audit Office’s earlier findings make the need for disclosure sharper. The audit did not examine TMR’s résumé-ranking system, and it should not be read as evidence of a problem with that particular deployment. But it did establish that, at the department-wide level, TMR needed stronger visibility, ethical-risk assessment and assurance for AI. A recruitment tool is precisely the kind of project that should demonstrate whether those gaps have been closed.

SAP migration adds another AI decision layer​

Alongside Microsoft Copilot, TMR is migrating to SAP S/4HANA and using Syniti, an SAP-certified extension, to condition data and make recommendations. Hesford told iTnews that the system had generated 200 recommendations so far.

That work belongs in the same governance conversation even though it is different from résumé ranking or generative drafting. Data-quality recommendations in an ERP migration can influence how information is mapped, corrected, classified or carried into a new finance platform. Their quality therefore affects downstream reporting, auditability and operational decisions long after the migration project ends.

TMR has not publicly said what the 200 recommendations concerned, how many were accepted, which staff validate them, or whether changes are independently reviewed before they reach the S/4HANA environment. These are standard migration-control questions, not an indictment of the technology. They become more relevant when an agency presents AI-generated recommendations as part of a broader productivity and modernisation program.

The department’s public reporting gives TMR a stronger foundation than many organisations attempting to deploy generative AI: it has already run Microsoft 365 pilots, established staff-learning programs and begun an AI strategic roadmap. Its senior leadership is also visibly engaged, rather than leaving adoption to a small digital team.

The immediate test is whether TMR will publish the operating details behind its production deployments before the project count rises. By December 2026, the useful measure will not be whether the department reaches 15 AI projects. It will be whether each project has a named owner, defined human authority, tested controls, an auditable record of its use and a clear path for correcting an AI-assisted decision.