Key takeaways

  • ✓No single law bans AI in Australian government, but multiple frameworks apply at once: the APS AI Policy, the Privacy Act 1988, agency-specific security classifications, and the Australian Government's Automated Decision-Making (ADM) guidance.

  • ✓Routine, low-risk uses (drafting, summarisation, research assistance) are generally permitted today, provided staff understand what the tool does with their data before they paste anything in.

  • ✓Sovereign data handling is the most common blocker. Many commercial AI tools route data through offshore infrastructure, which can breach data residency requirements for PROTECTED and above information.

  • ✓Automated decisions that affect individuals, such as benefit eligibility or compliance action, carry legal and ethical obligations that most off-the-shelf AI tools are not designed to satisfy on their own.

  • ✓Building genuine AI capability inside government requires structured training, not just policy. Staff need to understand both how to use AI tools and where the guardrails sit.

What rules actually govern AI use in Australian government?

Four overlapping frameworks shape what Australian public sector agencies can and cannot do with AI. None of them is a single "AI law", and that is exactly what makes the picture complicated.

The APS Artificial Intelligence Policy (published by the Department of Finance) is the most direct instrument. It requires agencies to complete an AI assessment record before deploying any AI tool in a business process, publish their use of AI in annual reports, and nominate an accountable official for each deployment. The policy applies to non-corporate Commonwealth entities and sits above internal IT policies in the governance hierarchy.

The Australian Government's Voluntary AI Safety Standard sets out ten guardrails covering transparency, human oversight, and testing for harmful outputs. It is voluntary in name, but APS agencies treating it as optional are taking a risk. The Office of the Australian Information Commissioner and the broader public accountability environment mean "voluntary" carries less weight in government than it does in the private sector.

The Privacy Act 1988 remains the primary constraint on how agencies handle personal information. Automated decision-making that affects individuals, such as benefit assessments or compliance flags, must meet the Australian Privacy Principles. Where an AI system produces a decision or a recommendation that feeds directly into a decision, agencies need to be able to explain that outcome to the individual affected.

The Information Security Manual (ISM), maintained by the Australian Signals Directorate, governs how data is handled across PROTECTED, OFFICIAL: Sensitive, and OFFICIAL classification levels. Most commercial AI tools, including the major large language models (LLMs), are not cleared for PROTECTED data unless accessed through a specifically accredited environment. This is not a grey area. Sending classified content to an unaccredited cloud service is a breach regardless of how useful the output might be.

Four frameworks, one decision

Before deploying any AI tool, an agency needs to satisfy the APS AI Policy, the Privacy Act, the ISM, and ideally the Voluntary AI Safety Standard. No single tick-box covers all four.

These frameworks do not operate in isolation. An AI assessment record under the APS policy should reference ISM data classification, identify any Privacy Act obligations, and document how the Voluntary AI Safety Standard guardrails have been considered. In practice, many agencies are still building the internal processes to connect these dots consistently.

Which AI use cases are clearly permitted?

Several categories of AI use are well-established in Australian government and carry low regulatory risk when handled with reasonable care. They share a common trait: they assist staff rather than replace human judgement on decisions that affect individual rights or entitlements.

Document drafting and summarisation. Agencies are using AI tools to draft internal briefing notes, summarise long policy documents, and produce first-draft correspondence. Staff review and approve the final output. Because no automated decision reaches a citizen, the legal exposure is minimal. The Australian Public Service Commission's guidance on AI use explicitly contemplates this kind of productivity tool.

Internal knowledge retrieval. A number of agencies have deployed AI assistants trained on their own policy libraries, legislation summaries, and procedure manuals. A staff member asks a question in plain English and gets a referenced answer drawn from approved internal documents. Think of it as a smarter search tool. The key safeguard is that the underlying documents are controlled by the agency and the system is not exposed to the public.

Data analysis and reporting. Turning large operational datasets into readable summaries, identifying trends in service demand, or flagging anomalies in procurement spend are all tasks AI handles well. The outputs inform decisions made by humans; they do not constitute the decision itself. This distinction matters under the Administrative Decisions (Judicial Review) Act 1977, which requires that reviewable decisions be made by an authorised person.

Transcription and meeting notes. Automated transcription of meetings, workshops, and stakeholder consultations is in widespread use across the APS. The practical rule most agencies apply is to notify participants that transcription is occurring, which satisfies obligations under the Privacy Act 1988, and to store recordings and transcripts on government-managed infrastructure rather than vendor cloud environments.

The common thread in low-risk AI use

These use cases keep a human in the decision loop and keep sensitive data within environments the agency controls. Both conditions matter. Drop either one and the risk profile changes.

Accessibility and translation tools. AI-powered captioning, text-to-speech, and plain-language translation tools help agencies meet their obligations under the Disability Discrimination Act 1992 and improve service access for Australians from non-English-speaking backgrounds. Adoption here has been straightforward because the tools directly support compliance goals rather than creating new compliance questions.

What these permitted uses have in common is that they are assistive rather than determinative. The AI governance frameworks that work best in the public sector are built around that distinction from the start, before tools are selected and before pilots are launched.

Where does it get complicated?

The permitted use cases above share a common trait: the AI handles internal content, and a human reviews the output before anything consequential happens. Complexity arrives the moment citizen data enters the picture, a decision carries legal weight, or the model itself sits outside Australian jurisdiction.

Generative AI and citizen data

Most commercially available generative AI tools (Microsoft Copilot, Google Gemini, ChatGPT Enterprise) process prompts on infrastructure that may span multiple countries, even when a vendor offers an Australian data residency option for stored files. The distinction matters. Data residency tells you where your documents sit at rest. It does not always tell you where inference happens, where prompts are logged, or where fine-tuning data flows.

For agencies handling personal information under the Privacy Act 1988, this creates a real problem. Feeding a citizen's Medicare details, visa application, or welfare history into a general-purpose AI tool is not straightforwardly compliant, even if the vendor's marketing says "your data stays in Australia." The Australian Privacy Principles require agencies to understand how personal information is handled, not just where it is stored.

The practical guidance here is narrow: keep identified citizen data out of AI tools unless you have completed a Privacy Impact Assessment (PIA), confirmed the contractual data handling terms in writing, and obtained legal sign-off. That is not a bureaucratic hurdle for its own sake. A breach involving citizen welfare data or immigration records would carry significant political and legal consequences.

Automated decision-making

The APS AI Ethics Principles are clear that humans must remain accountable for consequential decisions. What they do not do is define "consequential" precisely, which is where agencies get into trouble.

Consider a few scenarios. An AI tool that drafts a grant rejection letter, which an officer then reads and approves, is almost certainly fine. An AI tool that scores welfare eligibility applications and routes low-risk approvals through automatically, with officers only reviewing exceptions, sits in much greyer territory. The decision is still technically reviewed, but the practical reality is that the AI determines outcomes for the majority of cases.

Australia does not yet have specific legislation governing automated administrative decisions, unlike the European Union's AI Act, which mandates human oversight for high-risk categories. That absence does not mean automation is permissible by default. The Administrative Decisions (Judicial Review) Act 1977 and the broader principle of procedural fairness still apply. If a citizen can challenge a government decision, that decision needs to be explainable by a person, not a model.

The explainability test

If a senior officer could not explain to an affected citizen exactly how their case was assessed and why a particular outcome was reached, the process probably relies too heavily on AI. Explainability is not optional in public administration.

Agencies experimenting with automated triage or routing should document the decision logic, set clear thresholds for human review, and run the approach past their legal team before any citizen is affected.

Procurement and vendor lock-in

A less-discussed complication is what happens when an agency builds workflows around a specific AI platform and that platform changes its terms, pricing, or data handling practices. This is not hypothetical. Several major AI vendors have updated their enterprise terms multiple times in the past two years, sometimes in ways that affected how customer data could be used for model improvement.

Agencies investing in AI capability need to treat vendor agreements with the same scrutiny applied to any critical infrastructure contract. The AI procurement for government article covers this in more detail, but the headline point is this: lock-in risk is an AI governance issue, not just a commercial one. If your agency's core service delivery depends on a single vendor's model, you have a continuity and sovereignty exposure that no data residency clause fully resolves.

What does data sovereignty mean for your agency?

Data sovereignty, in plain terms, means that your data remains subject to Australian law and accessible to Australian authorities, regardless of where it physically sits. For AI tools, that creates a specific set of questions most vendors are not quick to answer.

The Australian Signals Directorate's Information Security Manual (ISM) sets the cloud security controls that Commonwealth agencies must meet. For PROTECTED-level data, that means using cloud services that hold a current IRAP (Infosec Registered Assessors Program) assessment at the relevant classification level. Many popular AI platforms have not completed that assessment, which effectively puts them out of reach for anything above OFFICIAL: Sensitive.

IRAP assessment is not the same as general security certification

A vendor can hold ISO 27001, SOC 2, and a dozen other certifications and still not be cleared for PROTECTED workloads. The IRAP assessment is specific to Australian government requirements. Check the ASD Certified Cloud Services List before assuming a tool qualifies.

Even below the PROTECTED threshold, sovereignty questions surface. If an AI tool sends query data to a model hosted offshore for inference, that data has left Australian jurisdiction, even temporarily. Whether that matters depends on the sensitivity of what you are querying. A planning team drafting public consultation summaries faces a different risk profile from a policy team working with cabinet-in-confidence material. Many agencies are still working through exactly where their data goes when staff use commercial AI tools, which is reason enough to map that before you roll anything out widely.

There is also the question of training data. Some AI platforms, particularly consumer-grade tools, use customer inputs to improve their models by default. Enterprise agreements typically allow you to opt out of this, but the default setting matters if staff have already been using a tool without a formal agreement in place.

For agencies with a Microsoft 365 environment, Microsoft Copilot for Microsoft 365 is one of the more straightforward options at OFFICIAL: Sensitive, because Microsoft's data boundary commitments and the existing enterprise agreement provide a starting point. That does not mean it is automatically compliant for all use cases; it means the compliance conversation is more tractable. For agencies exploring other platforms, the procurement and data governance groundwork is more substantial.

This intersects closely with AI procurement decisions and with broader questions about data sovereignty for Australian government agencies. Both deserve dedicated analysis before a tool reaches your staff, not after.

How should agencies build AI governance?

Governance does not need to be a 200-page policy document before a single tool gets used. Most agencies are better served by a lightweight, iterative framework that grows as AI use expands. The core components are the same regardless of agency size.

Start with risk classification

Not every AI use case carries the same risk. A tool that drafts internal briefing notes sits in a very different category from one that recommends welfare payment eligibility. Before deploying anything, classify each use case by the consequence of an error and the degree to which the output affects citizens directly.

A simple two-axis approach works: how severe is the potential harm, and how automated is the decision pathway? High-harm, high-automation combinations require the most scrutiny. Low-harm, human-reviewed outputs can move faster with lighter controls. The Australian Government's Responsible AI framework uses similar logic, and aligning your internal classification to it makes external audit conversations considerably easier.

Define human-in-the-loop requirements explicitly

"A human reviews the output" is not a governance control unless you specify who, at what point, and with what authority to reject the recommendation. Vague human oversight tends to become rubber-stamping under workload pressure.

For each use case, document the review step as a named role, a described action, and a record. A grants assessment officer reviewing an AI-generated summary should know they are accountable for the final determination, not just the summary. That accountability needs to be in writing, in the workflow design, not just in a policy footnote.

The review step only counts if it's real

Human oversight is a governance control when it is documented, assigned to a named role, and recorded. A process that says "humans are in the loop" but does not specify who and when will not hold up under an FOI request or a complaint to the Ombudsman.

Keep records that can survive scrutiny

The Freedom of Information Act and administrative law principles both assume government decisions are explainable. If an AI system influenced a decision, that influence needs to be traceable. At minimum, record which AI tool was used, what version, what input was provided, and what the output was. Many agencies are adding this to their existing records management systems rather than building separate infrastructure.

For higher-risk applications, you also want to record when the AI output was overridden and why. That data is not just a compliance asset; it tells you whether the model is actually useful or whether staff are routinely ignoring it.

Assign accountability to a person, not a team

Shared accountability is diffused accountability. Agencies that are managing AI governance well tend to have a named individual, often a deputy secretary or equivalent SES officer, who owns the agency's AI risk register and signs off on new deployments above a defined risk threshold. That person does not need to be a data scientist. They need enough technical literacy to ask the right questions and enough seniority to say no.

If your agency does not yet have that role filled, the five roles every enterprise AI initiative actually needs is worth reading alongside this. The titles differ in government contexts, but the functions are the same.

Build staff capability into the governance plan

Governance frameworks fail when the people expected to apply them do not understand what they are approving. A reviewing officer who cannot distinguish between a deterministic rule-based output and a probabilistic language model output is not equipped to provide meaningful oversight. That is not a criticism of the officer; it is a design gap.

Training is a governance control. Agencies that treat it as an optional add-on tend to discover the gap after an incident. Factoring AI literacy for non-technical teams into the governance rollout, rather than after it, closes that gap before it matters.

Frequently asked questions

Is there a law that prohibits Australian government agencies from using AI?

There is no single law that bans AI use in the public sector. What exists is a framework of obligations: the Privacy Act 1988, the Australian Privacy Principles, agency-specific legislation, and guidance from the Australian Government's Mandatory Guardrails for AI in Government. Taken together, these set out how AI can be used responsibly rather than whether it can be used at all. The practical constraints come from data classification, consent requirements, and whether a particular tool processes data offshore.

Can federal agencies use commercial AI tools like Microsoft Copilot or Google Gemini?

Yes, but with conditions that vary by agency and data sensitivity. Many agencies are already deploying Microsoft Copilot through Microsoft 365 Government tenancies that meet Australian data residency requirements. Google Workspace with Gemini is similarly available in configurations designed for government. The sticking point is almost always data classification: tools deployed against OFFICIAL or OFFICIAL: Sensitive data need to meet controls that most consumer-grade versions of these products do not satisfy. Procurement teams should request a current copy of each vendor's IRAP assessment before committing.

What is an IRAP assessment and does every AI tool need one?

IRAP stands for Infosec Registered Assessors Program, administered by the Australian Signals Directorate. An IRAP assessment evaluates whether a cloud or software product meets the controls in the Australian Government Information Security Manual. Not every AI tool requires a full IRAP assessment, but any tool that will process government data above the UNOFFICIAL classification needs to demonstrate compliance with the relevant ISM controls, and an IRAP assessment is the standard way vendors do that. Agencies should check the ASD's cloud services certification register before procurement, and consult their Chief Information Security Officer if the tool will handle anything classified PROTECTED or above.

Do agencies need to tell citizens when AI is involved in a decision that affects them?

The Australian Government's AI Ethics Principles include transparency as a core requirement, and the Mandatory Guardrails published in 2024 explicitly require agencies to be transparent about consequential AI use. For decisions that carry legal or significant practical effect on an individual, transparency is not optional. What "transparency" looks like in practice ranges from a note in a letter to a formal explanation of how an automated system contributed to an outcome. If your agency is using AI in any process that touches individual entitlements, appeals, or compliance decisions, your legal team should assess notification obligations before you go live.

How is AI governance in government different from the private sector?

The accountability standard is higher and the risk of harm is different in character. A private company that misuses AI faces reputational and regulatory consequences. A government agency that does so can breach citizens' legal rights, undermine public trust in institutions, or compromise national security. Public sector AI governance also has to contend with public records obligations, ministerial accountability, freedom of information requirements, and the principle that administrative decisions must be explainable and contestable. The governance framework principles that work for a mid-sized enterprise are a reasonable starting point, but they need to be adapted significantly for a government context.

Ready to build AI capability across your agency?

Understanding what is permitted is the starting point. Building the capability to act on it is the work that follows.

Better People works with Australian government agencies to design and deliver AI training that fits the actual constraints you operate under: APS Values, data classification requirements, procurement rules, and the realities of mixed-tenure workforces. That means practical programs for policy staff, service delivery teams, and senior executives, not generic workshops repackaged for government.

Explore our government training programs to see how we work with agencies, or get in touch to talk through what your team needs.