Key takeaways

  • ✓Australia does not yet have a dedicated AI law, but that is changing. The federal government has signalled mandatory guardrails for high-risk AI applications, with consultation underway and obligations expected to crystallise through 2025 and 2026.

  • ✓Existing laws already apply. The Privacy Act, anti-discrimination legislation, and Australian Consumer Law create real compliance exposure for organisations using AI today, regardless of what new rules arrive.

  • ✓"High-risk AI" in the Australian context broadly means systems that make or inform consequential decisions about people, including hiring, credit, healthcare, and law enforcement.

  • ✓Board-level accountability is the direction of travel. Regulators are increasingly clear that AI governance is a leadership responsibility, not something that can be delegated entirely to IT or legal.

  • ✓The window to act is now. Organisations that build internal governance, training, and documentation practices ahead of mandatory requirements will find compliance far less disruptive than those scrambling after the fact.

What is the current state of Australian AI regulation?

Australia does not yet have a dedicated AI law. As of 2026, the federal government's approach remains largely voluntary, built around principles-based frameworks rather than enforceable rules.

The centrepiece is the Australian Government's Voluntary AI Safety Standard, released by the Department of Industry, Science and Resources in late 2024. It sets out ten guardrails covering accountability, transparency, human oversight and risk management. Organisations are encouraged to adopt them. There is no penalty for ignoring them.

Alongside that, the National AI Centre and the Digital Transformation Agency have published guidance for public sector AI use. The AI Ethics Framework, first released in 2019, still shapes much of the conversation. These are genuinely useful documents. They are not law.

Where Australia sits right now

Voluntary frameworks set the direction, but compliance is optional. The legal exposure for most organisations currently comes from existing laws applied to AI, not from AI-specific legislation.

How does this compare with the EU AI Act?

The contrast with Europe is sharp. The EU AI Act, which came into force in August 2024, is binding legislation. It classifies AI systems by risk level, prohibits certain uses outright, and carries fines of up to 35 million euros or 7% of global annual turnover for the most serious breaches. Australian organisations that sell into or operate within the EU market are already subject to it.

Australia is not following that model directly, at least not yet. The federal government has signalled a preference for a sector-by-sector approach rather than a single horizontal AI law. In practice, that means the obligations currently sit inside existing regulators: the OAIC for privacy, ASIC and APRA for financial services, the Fair Work Commission for employment matters.

Which way is the policy heading?

The direction is toward harder rules. The government's 2023 Safe and Responsible AI consultation drew significant industry response, and subsequent releases have pointed toward mandatory guardrails for high-risk applications. A targeted, risk-based mandatory framework is the working model being developed, broadly consistent with international approaches but calibrated for Australia's regulatory environment.

How quickly that becomes law is less certain. Expect continued consultation through 2025 and 2026, with the realistic prospect of binding obligations for specific sectors or use cases within that window. Organisations that treat the voluntary guardrails as a dry run for what is coming are better positioned than those waiting for a final text.

Which existing laws already apply to AI?

Waiting for new legislation is not a safe strategy. Several existing frameworks already reach AI-powered tools and decisions, and regulators are beginning to apply them.

The Privacy Act 1988

The Privacy Act governs how organisations collect, use and disclose personal information. AI systems routinely do all three. A customer-service chatbot trained on interaction histories, a recruitment tool that scores CVs, a fraud-detection model that profiles transactions: each of these touches personal information and must satisfy the Australian Privacy Principles (APPs).

Two principles deserve particular attention. APP 1 requires organisations to have a clearly expressed, up-to-date privacy policy that covers how automated systems handle personal data. APP 3 limits collection to information that is reasonably necessary. If your AI tool vacuums up more data than the task requires, that is a compliance problem today, not a future one. The Privacy Act and AI is a topic covered in more detail in a companion article in this series, but the short version is: review your privacy notices and data flows before you deploy, not after.

Anti-discrimination law

Federal and state anti-discrimination legislation prohibits decisions that disadvantage people because of protected attributes: race, sex, age, disability and others. The law does not care whether the decision was made by a person or an algorithm. An AI hiring tool that systematically filters out candidates over fifty, or a lending model that produces racially disparate outcomes, can expose an organisation to complaints under the Age Discrimination Act 2004, the Racial Discrimination Act 1975, or equivalent state instruments.

The practical difficulty is that many models produce discriminatory outputs without anyone intending them to. Bias can enter through training data, through proxy variables, or through feedback loops that reinforce historical patterns. That is not a defence; it is a liability. AI in HR and recruitment sits at the centre of this risk for many organisations.

Australian Consumer Law

The Australian Consumer Law (ACL), administered by the ACCC, prohibits misleading and deceptive conduct. If your marketing uses AI-generated claims you cannot substantiate, or if a recommendation engine steers customers toward products that do not suit them while implying objectivity, the ACL is engaged. The ACCC has signalled active interest in AI-driven consumer harms, and its enforcement posture is hardening.

Sector-specific obligations

Several regulated industries carry additional layers of obligation that sit on top of general law.

  • Financial services. ASIC's guidance on automated advice (RG 255) and responsible lending obligations mean that AI used in financial product recommendations or credit decisions must meet standards around suitability, disclosure and record-keeping. APRA's prudential standards also apply to model risk in banks and insurers.

  • Healthcare. The Therapeutic Goods Administration (TGA) regulates AI tools that meet the definition of a medical device, including some diagnostic software. Deployment without the appropriate registration is a regulatory offence.

  • Government agencies. Commonwealth and state agencies are subject to the APS AI Policy, the Digital Service Standard, and Freedom of Information obligations that affect how automated decisions are recorded and reviewed.

The compliance gap most organisations miss

Existing law already applies to AI in your organisation. The question is not whether regulation has arrived; it is whether your governance, contracts and training have caught up with what is already on the books.

If your organisation is deploying AI tools that touch personal information, hiring, customer offers or financial decisions, a compliance gap is more likely than not. The place to start is understanding what data your tools are actually processing, which is harder than it sounds when shadow AI is in play.

What mandatory obligations are coming?

The Australian Government has proposed a set of mandatory guardrails that would apply to organisations developing or deploying AI in high-risk settings. These are not law yet, but the direction is clear enough that waiting for royal assent before preparing is not a sensible posture.

The Department of Industry, Science and Resources released its proposals following the 2023 discussion paper on safe and responsible AI. The current framework centres on ten mandatory guardrails for high-risk AI, which include:

  • Establishing accountability for AI outcomes at an appropriate level of seniority

  • Assessing and documenting risks before deployment, not after

  • Being transparent with affected people that AI is involved in decisions about them

  • Maintaining human oversight over AI-driven decisions that carry significant consequences

  • Keeping records sufficient to allow audit and review

  • Testing AI systems for bias and accuracy before and after deployment

These guardrails are deliberately principle-based rather than prescriptive. That is useful for flexibility, but it also means your organisation will need to interpret how each one applies to your specific use cases. A lender using AI in credit decisions faces different specifics than a hospital using AI for triage support, even if the underlying obligation to document and test is the same.

The direction is settled, even if the detail is not

The Australian Government has signalled clearly that mandatory requirements are coming for high-risk AI. Organisations that treat this as a distant policy conversation are building future compliance debt into systems they are deploying today.

What sectors should expect the most scrutiny

The government's framing of "high-risk" aligns broadly with use cases where an AI-driven outcome materially affects a person's rights, finances, health, or employment. That puts financial services, healthcare, government services, recruitment, and insurance at the front of the queue. If your organisation operates in any of these areas, the guardrails effectively describe a floor for what your AI governance documentation should already contain.

Organisations in other sectors should not assume they are out of scope. The Privacy Act already creates obligations around automated decision-making that touches personal information, and the ACCC has made clear that misleading or deceptive conduct rules apply to AI-generated content. Sector-specific regulation layered on top is the likely direction, not a replacement for those existing obligations.

Consultation timelines

The government's consultation process has been iterative. The most recent round closed in 2024, and while a final regulatory model has not been legislated, Treasury and DISR have both signalled that voluntary frameworks will transition to mandatory requirements. The timeline most commonly discussed in policy circles points to legislative exposure drafts in 2025, with obligations potentially taking effect through 2026 and 2027 depending on the risk tier and sector.

That timeline is tight when you consider that designing a governance framework, training staff, updating procurement processes, and documenting existing AI systems all take real time. Organisations waiting for a final Act before they start are likely to find themselves retrofitting compliance into systems that were never built with it in mind, which is considerably harder than building it in from the start.

If you are currently evaluating or deploying AI tools and want a baseline for what good procurement looks like from a governance perspective, this checklist of questions to filter AI vendors is a practical starting point.

What does 'high-risk AI' mean in the Australian context?

Australia has not yet legislated a formal risk tier system the way the EU AI Act has, but the government's voluntary frameworks and the proposed mandatory guardrails both use risk-level thinking. The practical definition being applied is this: an AI system is high-risk when a failure, bias, or error in its outputs could cause serious harm to individuals, or when it makes consequential decisions about people with limited human oversight.

The Department of Industry, Science and Resources has identified several domains where that threshold is most likely to be crossed. HR and employment decisions sit near the top of that list.

HR and recruitment

An AI tool that screens job applications, scores candidates, or recommends termination is making decisions with direct financial and reputational consequences for real people. The bias and compliance traps in AI-assisted hiring are significant: models trained on historical data can encode past patterns of discrimination, and neither the organisation nor the candidate may realise it has happened. Under Australian consumer and anti-discrimination law, the organisation deploying the tool bears responsibility for the outcome, regardless of what the vendor claims.

Finance and credit

AI used to assess creditworthiness, approve or decline transactions, or flag accounts for fraud review is high-risk by almost any definition. These systems affect access to financial products. Errors compound quickly, and the people most affected are often the least equipped to contest an automated decision. The Australian Securities and Investments Commission (ASIC) has been explicit that responsible lending obligations do not disappear because a model made the call.

Health and welfare

Clinical decision support tools, triage assistants, and automated mental health screening products are subject to the Therapeutic Goods Administration (TGA) framework where they qualify as medical devices. The risk bar here is rightly high. Delayed, missed, or incorrect outputs can cause direct physical harm, and "the AI suggested it" is not a clinical defence.

Customer-facing AI in regulated industries

A chatbot handling insurance claims, superannuation queries, or financial advice is operating in regulated territory even if the underlying product looks like an off-the-shelf AI assistant. The Australian Prudential Regulation Authority (APRA) and ASIC have both signalled that existing prudential and conduct obligations extend to AI-mediated customer interactions. If your AI is telling customers things about their policy or their account, it is giving information that carries legal weight.

The risk is in the use case, not the technology

The same large language model can be low-risk in one context and high-risk in another. A model summarising internal meeting notes carries little regulatory exposure. The same model reviewing a job application or explaining a customer's insurance entitlements sits in a very different category. Categorise by what the output does to a person, not by what technology sits underneath.

What 'meaningful human oversight' actually means

Both the voluntary AI Ethics Principles and the proposed mandatory guardrails use phrases like "human oversight" and "contestability". In practice, regulators appear to be drawing a distinction between oversight that is genuine and oversight that is nominal. A human who rubber-stamps five hundred AI decisions per day without the time, information, or authority to override them is not providing meaningful review. Boards and executives should be asking whether their current human-in-the-loop arrangements would withstand scrutiny, not just whether they exist on paper.

How should leaders respond right now?

Australia's AI governance framework is still forming, but "wait and see" is not a neutral position. Organisations that start building governance habits now will find compliance far less disruptive when mandatory obligations arrive. Those that don't will be retrofitting controls onto live systems under time pressure.

Four practical steps are worth prioritising.

Build an AI register. You cannot govern what you have not catalogued. An AI register is a living document that records every AI tool in use, who owns it, what decisions it informs or makes, what data it touches, and what the failure mode looks like. This is also the foundation for identifying which systems would qualify as high-risk under any future Australian mandatory framework. If you suspect your register will turn up more tools than you expect, start with shadow AI discovery before you build the formal list.

Put an acceptable use policy in place. Most Australian organisations still lack a written policy governing how staff may use AI, what data they may share with external tools, and who is accountable when something goes wrong. A policy does not need to be long to be effective, but it does need to be specific about the scenarios your teams actually face. It should address generative AI tools in particular, given the data-sharing risks those tools carry.

Treat training as a compliance obligation, not a nicety. The Privacy Act already requires staff who handle personal information to understand their obligations. Where AI tools process that data, training needs to cover how those tools work, what can go wrong, and what to do when it does. For teams in finance, HR, or legal, the bar is higher. AI scam awareness training deserves a place on the compliance calendar alongside data handling and workplace safety.

Apply procurement due diligence to every AI vendor. Before any new tool goes into production, ask the vendor for its data processing agreement, its sub-processor list, and evidence of how the model was trained. Where the tool makes or informs consequential decisions, ask how outputs can be explained and challenged. The questions you ask at procurement are far easier to enforce than trying to renegotiate terms once a tool is embedded in operations. A structured approach to AI procurement will surface the gaps that informal evaluation misses.

The governance gap is a liability gap

Regulators and courts do not require perfection, but they do look for evidence of reasonable care. An AI register, a use policy, documented training, and disciplined procurement are the artefacts that demonstrate it.

None of this requires a large team or a significant budget to start. What it requires is a decision to treat AI governance as an operational responsibility, owned by leadership, rather than an IT problem to be solved later.

Frequently asked questions

Is there a single Australian AI law we need to comply with right now?

There is no single Australian AI Act in force as of 2026. Compliance obligations come from a patchwork of existing legislation: the Privacy Act 1988, the Anti-Discrimination Act in relevant states and territories, the Australian Consumer Law, and sector-specific rules from regulators such as APRA and ASIC. The federal government's AI governance work is ongoing, and mandatory obligations are expected to be introduced progressively, starting with high-risk applications.

What counts as 'high-risk AI' under Australian guidelines?

The Australian government has aligned broadly with international frameworks, identifying high-risk AI as systems that make or substantially influence decisions affecting individual rights, safety, or access to services. Practical examples include automated hiring tools, credit-scoring models, fraud-detection systems that flag customers, and any AI used in healthcare triage or welfare eligibility. If your system produces a consequential outcome for a person and a human does not meaningfully review it before it takes effect, treat it as high-risk until you have assessed it properly.

Does the Privacy Act already cover AI systems that process personal data?

Yes. If an AI system ingests, analyses, or generates outputs based on personal information about Australians, the Privacy Act applies today. That includes third-party AI tools your staff use through a browser, not just systems you have built. The Australian Privacy Principles require you to have a lawful basis for collection, to tell individuals how their data is used, and to take reasonable steps to protect it. Using an unapproved AI tool that sends employee or customer data to an offshore model is a potential breach, not a grey area.

When will mandatory AI obligations actually come into force?

The federal government has signalled a staged approach. Voluntary commitments from high-risk AI developers were sought in 2024, and mandatory guardrails for the highest-risk applications are expected to follow through a combination of new regulation and amendments to existing laws. Precise dates are not yet legislated, which is itself a reason to act now: organisations that treat current voluntary frameworks as the floor will be better positioned than those waiting for a compliance deadline.

What should our board minute to demonstrate we are taking AI governance seriously?

Board minutes should record that the organisation has identified where AI is in use, assessed which systems carry meaningful risk, assigned accountability for AI oversight, and reviewed policies for acceptable use and third-party AI procurement. Documenting that the board has received a briefing on the four AI risks every board should be asking about and has approved a roadmap to address gaps is a defensible starting point. Regulators in other jurisdictions have treated board-level inaction as an aggravating factor; there is no reason to assume Australian regulators will be different.

Is your organisation ready for what's coming?

Australian AI regulation is moving from voluntary guidance to enforceable obligations. The organisations that will handle that transition well are the ones building governance muscle now, before compliance deadlines force rushed, surface-level responses.

That means more than updating a policy document. It means ensuring your leadership team understands what high-risk AI actually looks like in your operations, that your people know how to use AI tools within boundaries that protect the organisation, and that someone owns the governance function rather than assuming someone else does.

Better People works with Australian enterprises and government agencies to build exactly that capability, through custom programs, practical workshops, and AI implementation support that connects regulatory requirements to real workflows. If your board is asking the four AI risks questions and your team cannot yet answer them confidently, that is the gap worth closing first.

Where does your organisation sit on AI governance readiness?

href="/contact" button="Book a 30-minute discovery call" We can map your current AI use against existing obligations and the incoming mandatory guardrails, and identify the highest-priority gaps to address this year.

Book a 30-minute discovery call →

The regulatory window is narrowing. Audit trails, human oversight mechanisms, bias assessments and staff training are not things you want to build under pressure. Starting now means your organisation shapes its own governance approach rather than having one imposed on it.