CountryInitial profile

AI Governance Profile

Australia AI Governance Profile

Initial Observatory profile for Australia AI governance, covering Commonwealth public-sector controls, the National AI Plan, AI safety capacity, privacy transparency rules for automated decisions, and the status of proposed high-risk guardrails.

Last reviewed 2026-09-08
Australia flag

Profile at a glance

Executive overview

Key signals for Australia AI governance, structured for quick institutional review before the full profile analysis below.

Region

Asia-Pacific

Governance model

Innovation-led governance

Regulatory maturity

Developing

Enterprise impact

Medium

Public-sector readiness

Advanced

Enforcement maturity

Developing

Major policy and regulatory signals

  • National AI Plan
  • Mandatory guardrails for high-risk AI — consultation and policy status
  • Policy for the Responsible Use of AI in Government v2.0
  • Australian AI Safety Institute
  • Privacy Act automated-decision transparency amendments

Enterprise implications

Enterprises should not treat the closed mandatory-guardrails consultation as current law.

Last updated

2026-09-08

Key institutions

  • Department of Industry, Science and Resources
  • Digital Transformation Agency
  • Office of the Australian Information Commissioner
  • Australian AI Safety Institute
  • Australian Competition and Consumer Commission
  • Sector regulators and Commonwealth departments

Watchlist

  • Commencement and regulator guidance for the Privacy Act automated-decision transparency amendments on 2026-12-10
  • Whether the government revisits mandatory high-risk AI guardrails or sector-specific mandatory rules
  • Implementation updates to the Policy for the Responsible Use of AI in Government
  • Australian AI Safety Institute testing, evaluation and standards outputs
  • OAIC guidance and enforcement concerning AI, transparency, privacy and automated decision-making
  • ACCC and sector-regulator action involving AI-enabled consumer, competition, health, finance or employment practices
  • National AI Plan implementation, workforce capability and public-sector procurement signals

Executive summary

Australia does not currently have a single horizontal AI Act or a general mandatory high-risk AI regime. The current architecture combines the National AI Plan, mandatory Policy for the Responsible Use of AI in Government, existing privacy and consumer protections, the Australian AI Safety Institute, and sector-specific regulatory work. For public bodies, the Commonwealth policy creates mandatory internal controls for responsible AI use within its scope. For private enterprises, the main near-term legal development is the enacted privacy transparency requirement for certain automated decisions, which is scheduled to commence on 10 December 2026. The proposed mandatory guardrails consultation has closed without the government proceeding with that broad regime at this time; it should therefore remain a closed or deferred policy pathway, not current law. Australia’s governance signal is consequently implementation-led and adaptive. Enterprise readiness should focus on privacy, transparency, record-keeping, consumer protection, sector obligations, safety testing, procurement controls, and monitoring of future legislative or regulator action.

Governance architecture

Australia’s AI governance architecture is layered across Commonwealth administrative policy, privacy and consumer law, sector regulation, safety and evaluation infrastructure, and national strategy. The Policy for the Responsible Use of AI in Government is a mandatory Commonwealth public-sector control within scope. The National AI Plan is strategic rather than binding, the Australian AI Safety Institute provides capability and testing infrastructure rather than general regulatory authority, and the scheduled Privacy Act transparency amendments create a targeted legal requirement for certain automated decisions. The previous mandatory high-risk guardrails pathway is not an enacted regime.

Major policies and frameworks

PolicyIssuerYearStatusSummary
National AI PlanAustralian Government / Department of Industry, Science and Resources2025National strategyNational strategy for AI capability, adoption, safety, investment, skills and public benefit. It is strategic policy, not a standalone source of binding AI duties.
Mandatory guardrails for high-risk AI — consultation and policy statusAustralian Government / Department of Industry, Science and Resources2024–2026Closed policy pathway — government not proceeding with broad mandatory guardrails at this timeThe official consultation and status page records the policy process for proposed mandatory high-risk AI guardrails. The proposal is not current binding law and should not be treated as an enacted regime.
Policy for the Responsible Use of AI in Government v2.0Australian Government / Digital Transformation Agency2025Mandatory Commonwealth public-sector policy within scopeMandatory policy controls for Commonwealth government use of AI, including responsible use, risk management, accountability, transparency and assurance expectations.
Australian AI Safety InstituteAustralian Government / Department of Industry, Science and Resources2025–2026AI safety and evaluation institutionGovernment capability for AI safety research, evaluation, testing, standards and international collaboration; it is not a general AI regulator.
Privacy Act automated-decision transparency amendmentsOffice of the Australian Information Commissioner / Australian Government2025–2026Enacted privacy-law amendments — scheduled to commence 2026-12-10Targeted privacy transparency requirements for certain substantially automated decisions with legal or similarly significant effects. The obligations are enacted but are not yet applicable before the scheduled commencement date.

Policy timeline

2025-12-02

National AI Plan published

Australia set national priorities for AI capability, adoption, safety, skills and public benefit.

2025-12-15

Policy for the Responsible Use of AI in Government v2.0 applied

Commonwealth public-sector AI use is governed by a mandatory responsible-use policy within scope.

2026

Government does not proceed with broad mandatory high-risk guardrails at this stage

The mandatory-guardrails consultation pathway is closed/deferred and does not create current binding AI law.

2026-09-08

Observatory initial Australia profile review

Initial profile created from official Australian government, DTA, OAIC and AI Safety Institute sources.

2026-12-10

Scheduled commencement of automated-decision transparency obligations

Enacted Privacy Act transparency requirements for certain significant automated decisions are scheduled to commence.

Enterprise implications

Enterprises should not treat the closed mandatory-guardrails consultation as current law. Near-term controls should focus on existing privacy, consumer, sector and security obligations; transparency and record-keeping for significant automated decisions ahead of 10 December 2026; model and data documentation; human review and escalation; testing and assurance; procurement and vendor controls; and monitoring for future Commonwealth or sector-specific rules.

Observatory interpretation

Australia is an implementation-led and adaptive jurisdiction. Its binding AI-specific signal is currently strongest in Commonwealth public-sector policy and targeted privacy transparency, while the National AI Plan and Australian AI Safety Institute build capability and direction. The absence of a broad enacted high-risk guardrail regime is itself material and should be recorded as a policy status, not silently converted into a regulatory gap or an assumed future law.

Official resources

ResourceSourceTypeDateLegal forceWhy it matters
National AI PlanAustralian Government / Department of Industry, Science and ResourcesStrategy2025-12-02Not applicableSets Australia’s strategic direction for AI capability, safety, adoption and workforce development without creating standalone binding duties.
Mandatory guardrails for AI in high-risk settings — consultation and statusAustralian Government / Department of Industry, Science and ResourcesGuidance2024–2026Not applicableMust be read as a closed/deferred proposal pathway, not as enacted regulation.
Policy for the Responsible Use of AI in Government v2.0Australian Government / Digital Transformation AgencyPublic-sector rule2025BindingProvides the clearest current mandatory operational controls for Australian government AI use.
Australian AI Safety InstituteAustralian Government / Department of Industry, Science and ResourcesFramework2025–2026Not applicableTracks national safety-testing and evaluation capacity without implying general regulatory authority.
APP 1 guidance on automated-decision transparencyOffice of the Australian Information CommissionerLaw2025–2026BindingAdds a targeted binding privacy-law development while preserving the fact that the obligations are not yet applicable before commencement.
OAIC consultation on transparency in automated decision-makingOffice of the Australian Information CommissionerGuidance2025–2026GuidanceSignals likely implementation expectations but is not itself binding regulation.

Update log

2026-09-08: Initial published profile created and reviewed from official Australian government, Digital Transformation Agency, OAIC and Australian AI Safety Institute sources. The mandatory high-risk guardrails pathway is classified as closed/deferred rather than enacted law; Commonwealth public-sector policy is binding within scope; and Privacy Act automated-decision transparency amendments are enacted but scheduled to commence on 2026-12-10.