Source basis
Official source basis
Last reviewed on 2026-09-08.
This profile is grounded in official laws, policy documents, regulator guidance, standards, and public-sector source materials listed below.
- National AI Plan
- Mandatory guardrails for AI in high-risk settings — consultation and status
- Policy for the Responsible Use of AI in Government v2.0
- Australian AI Safety Institute
- APP 1 guidance on automated-decision transparency
- OAIC consultation on transparency in automated decision-making
- National AI Plan
- Mandatory guardrails for high-risk AI — consultation and policy status
Executive summary
Australia does not currently have a single horizontal AI Act or a general mandatory high-risk AI regime. The current architecture combines the National AI Plan, mandatory Policy for the Responsible Use of AI in Government, existing privacy and consumer protections, the Australian AI Safety Institute, and sector-specific regulatory work. For public bodies, the Commonwealth policy creates mandatory internal controls for responsible AI use within its scope. For private enterprises, the main near-term legal development is the enacted privacy transparency requirement for certain automated decisions, which is scheduled to commence on 10 December 2026. The proposed mandatory guardrails consultation has closed without the government proceeding with that broad regime at this time; it should therefore remain a closed or deferred policy pathway, not current law. Australia’s governance signal is consequently implementation-led and adaptive. Enterprise readiness should focus on privacy, transparency, record-keeping, consumer protection, sector obligations, safety testing, procurement controls, and monitoring of future legislative or regulator action.
Governance architecture
Australia’s AI governance architecture is layered across Commonwealth administrative policy, privacy and consumer law, sector regulation, safety and evaluation infrastructure, and national strategy. The Policy for the Responsible Use of AI in Government is a mandatory Commonwealth public-sector control within scope. The National AI Plan is strategic rather than binding, the Australian AI Safety Institute provides capability and testing infrastructure rather than general regulatory authority, and the scheduled Privacy Act transparency amendments create a targeted legal requirement for certain automated decisions. The previous mandatory high-risk guardrails pathway is not an enacted regime.
Major policies and frameworks
| Policy | Issuer | Year | Status | Summary |
|---|---|---|---|---|
| National AI Plan | Australian Government / Department of Industry, Science and Resources | 2025 | National strategy | National strategy for AI capability, adoption, safety, investment, skills and public benefit. It is strategic policy, not a standalone source of binding AI duties. |
| Mandatory guardrails for high-risk AI — consultation and policy status | Australian Government / Department of Industry, Science and Resources | 2024–2026 | Closed policy pathway — government not proceeding with broad mandatory guardrails at this time | The official consultation and status page records the policy process for proposed mandatory high-risk AI guardrails. The proposal is not current binding law and should not be treated as an enacted regime. |
| Policy for the Responsible Use of AI in Government v2.0 | Australian Government / Digital Transformation Agency | 2025 | Mandatory Commonwealth public-sector policy within scope | Mandatory policy controls for Commonwealth government use of AI, including responsible use, risk management, accountability, transparency and assurance expectations. |
| Australian AI Safety Institute | Australian Government / Department of Industry, Science and Resources | 2025–2026 | AI safety and evaluation institution | Government capability for AI safety research, evaluation, testing, standards and international collaboration; it is not a general AI regulator. |
| Privacy Act automated-decision transparency amendments | Office of the Australian Information Commissioner / Australian Government | 2025–2026 | Enacted privacy-law amendments — scheduled to commence 2026-12-10 | Targeted privacy transparency requirements for certain substantially automated decisions with legal or similarly significant effects. The obligations are enacted but are not yet applicable before the scheduled commencement date. |
Policy timeline
2025-12-02
National AI Plan published
Australia set national priorities for AI capability, adoption, safety, skills and public benefit.
2025-12-15
Policy for the Responsible Use of AI in Government v2.0 applied
Commonwealth public-sector AI use is governed by a mandatory responsible-use policy within scope.
2026
Government does not proceed with broad mandatory high-risk guardrails at this stage
The mandatory-guardrails consultation pathway is closed/deferred and does not create current binding AI law.
2026-09-08
Observatory initial Australia profile review
Initial profile created from official Australian government, DTA, OAIC and AI Safety Institute sources.
2026-12-10
Scheduled commencement of automated-decision transparency obligations
Enacted Privacy Act transparency requirements for certain significant automated decisions are scheduled to commence.
Enterprise implications
Enterprises should not treat the closed mandatory-guardrails consultation as current law. Near-term controls should focus on existing privacy, consumer, sector and security obligations; transparency and record-keeping for significant automated decisions ahead of 10 December 2026; model and data documentation; human review and escalation; testing and assurance; procurement and vendor controls; and monitoring for future Commonwealth or sector-specific rules.
Observatory interpretation
Australia is an implementation-led and adaptive jurisdiction. Its binding AI-specific signal is currently strongest in Commonwealth public-sector policy and targeted privacy transparency, while the National AI Plan and Australian AI Safety Institute build capability and direction. The absence of a broad enacted high-risk guardrail regime is itself material and should be recorded as a policy status, not silently converted into a regulatory gap or an assumed future law.
Official resources
| Resource | Source | Type | Date | Legal force | Why it matters |
|---|---|---|---|---|---|
| National AI Plan | Australian Government / Department of Industry, Science and Resources | Strategy | 2025-12-02 | Not applicable | Sets Australia’s strategic direction for AI capability, safety, adoption and workforce development without creating standalone binding duties. |
| Mandatory guardrails for AI in high-risk settings — consultation and status | Australian Government / Department of Industry, Science and Resources | Guidance | 2024–2026 | Not applicable | Must be read as a closed/deferred proposal pathway, not as enacted regulation. |
| Policy for the Responsible Use of AI in Government v2.0 | Australian Government / Digital Transformation Agency | Public-sector rule | 2025 | Binding | Provides the clearest current mandatory operational controls for Australian government AI use. |
| Australian AI Safety Institute | Australian Government / Department of Industry, Science and Resources | Framework | 2025–2026 | Not applicable | Tracks national safety-testing and evaluation capacity without implying general regulatory authority. |
| APP 1 guidance on automated-decision transparency | Office of the Australian Information Commissioner | Law | 2025–2026 | Binding | Adds a targeted binding privacy-law development while preserving the fact that the obligations are not yet applicable before commencement. |
| OAIC consultation on transparency in automated decision-making | Office of the Australian Information Commissioner | Guidance | 2025–2026 | Guidance | Signals likely implementation expectations but is not itself binding regulation. |
Update log
2026-09-08: Initial published profile created and reviewed from official Australian government, Digital Transformation Agency, OAIC and Australian AI Safety Institute sources. The mandatory high-risk guardrails pathway is classified as closed/deferred rather than enacted law; Commonwealth public-sector policy is binding within scope; and Privacy Act automated-decision transparency amendments are enacted but scheduled to commence on 2026-12-10.
