Every week another Australian business asks me the same thing: “Do we need to worry about AI regulation, or is that a European problem?” The honest answer is that Australia has taken a different road to Brussels, and that road puts more of the burden on you, not less.
AI governance for an Australian business means putting in place the accountability, policies, records and human checks that let you use AI safely and prove you did so, drawing on existing laws plus voluntary standards rather than a single AI Act. It is not a legal department problem you can park. It is an operating discipline, and the businesses that get it right will move faster, not slower, because they will not be second-guessing every deployment.
Here is the framework I use with clients, grounded in where Australian policy actually landed as of mid-2026.
Does Australia have an AI law?
No. Australia has deliberately chosen not to pass a standalone AI Act, and the December 2025 National AI Plan made that official.
The National AI Plan set out the government’s approach: build on the legal and regulatory frameworks we already have, and lift them where gaps appear, rather than write one omnibus statute in the mould of the EU AI Act. The plan pulls together more than A$460 million in existing funding across three goals: capture the opportunity, spread the benefits, and keep Australians safe.
For most business owners the takeaway is counter-intuitive. “No AI Act” does not mean “no obligations”. It means your AI obligations are scattered across laws you already have to follow:
- The Privacy Act 1988, which already governs how you handle personal information and is being tightened.
- Australian Consumer Law, which bites if an AI system misleads customers or produces unfair outcomes.
- Anti-discrimination law, which applies squarely to a biased model that screens job applicants or prices a service.
- Sector rules in health, finance and other regulated fields.
The government itself acknowledged the gaps: generative AI, deepfakes, synthetic training data, systemic algorithmic bias and autonomous decision-making are areas where existing law strains. Expect incremental amendments to the Privacy Act, Consumer Law and Online Safety Act rather than one big bang.
The single most concrete obligation is already on the calendar. From 10 December 2026, new automated decision-making transparency rules under the Privacy Act require organisations that use personal information in a computer program to make decisions significantly affecting people to disclose this in their privacy policy. The OAIC is preparing detailed guidance and has signalled a broad reading. Critically, it applies even when a human stays in the loop. I have written a fuller breakdown in the Privacy Act automated-decisions guide.
There is also the Scams Prevention Framework, which places mandatory prevent, detect, report and respond duties on banks, telcos and digital platforms. AI sits on both sides of that fight, so if you operate in those sectors, governance is not optional.
What is the Voluntary AI Safety Standard?
The Voluntary AI Safety Standard is the Australian government’s practical playbook: 10 guardrails that any organisation can adopt to use AI safely, and it is the closest thing we have to a national baseline.
Published by the Department of Industry, Science and Resources, the Voluntary AI Safety Standard is voluntary, but I treat it as the reference every Australian board should measure itself against. It was designed to be consistent with the international ISO/IEC 42001 standard and the US NIST AI Risk Management Framework, so adopting it is not a dead end. The National AI Centre has since built on it with the October 2025 Guidance for AI Adoption, which distils the same thinking into six essential practices for organisations starting out.
Here are the 10 guardrails in plain terms, with what each one actually asks of you.
| # | Guardrail | What it means in practice |
|---|---|---|
| 1 | Accountability | Name an owner, build internal capability, have a compliance strategy, and publish it |
| 2 | Risk management | Run a repeatable process to identify and mitigate AI risks before and during use |
| 3 | Data governance | Protect the systems and manage data quality, security and provenance |
| 4 | Testing | Evaluate model performance before launch and monitor it once live |
| 5 | Human oversight | Make sure a person can intervene in or control the system meaningfully |
| 6 | Transparency to users | Tell people when they are dealing with AI or AI-generated content |
| 7 | Contestability | Give affected people a way to challenge an AI decision or outcome |
| 8 | Supply-chain transparency | Share model and data information with partners so they can manage risk |
| 9 | Records | Keep documentation good enough for a third party to assess your compliance |
| 10 | Stakeholder engagement | Consider the people affected, with a focus on safety, fairness and inclusion |
If you do nothing else this quarter, read these 10 lines and score yourself honestly against each. Most businesses I assess are strong on testing and weak on accountability, records and contestability. Those three gaps are exactly what a regulator or an angry customer will probe first.
Where does ISO/IEC 42001 fit in?
ISO/IEC 42001 is the international, certifiable version of what the guardrails describe: an AI management system you can be audited against and hold up as proof.
The difference is one of weight. The Voluntary AI Safety Standard is free guidance you can adopt in an afternoon. ISO/IEC 42001:2023 is a formal management-system standard, in the same family as ISO 9001 for quality and ISO 27001 for information security, that an external auditor can certify. Because the guardrails were mapped to it deliberately, the work you do on the guardrails is not wasted if you later pursue certification.
Who should reach for 42001? If you sell to enterprise or government, if AI is core to your product, or if you already run other ISO management systems, certification becomes a commercial asset rather than a compliance cost. I have written more on how that plays out for teams already certified in ISO 9001 and AI governance. For a small services firm using off-the-shelf tools, the guardrails alone are plenty for now.
How do I write an AI policy and governance framework?
Build the smallest governance framework that actually changes behaviour: an AI policy, a use register, risk tiering, human-in-the-loop rules, and vendor and data checks. Right-size it, then grow it.
Academic frameworks fail because nobody reads them. Here is the practical version I put in place, and it fits most mid-sized Australian businesses.
1. A one-page AI policy. Name the accountable owner. List approved tools and banned ones. Set clear rules for confidential and personal data (no client data into consumer chatbots without approval). Require staff to disclose AI-generated content and to keep a human sign-off on anything that affects a person. Short enough that people read it beats thorough enough that they do not.
2. A live AI use register. A single spreadsheet or table listing every AI system in use, its owner, what data it touches, and its risk tier. You cannot govern what you cannot see, and guardrail 9 effectively demands this record anyway.
3. Risk tiering. Not every use needs the same scrutiny. Sort uses into three tiers:
| Tier | Example | Governance |
|---|---|---|
| Low | Drafting internal emails, summarising notes | Policy and training only |
| Medium | Customer-facing chatbot, marketing copy | Human review, disclosure, testing |
| High | Decisions on hiring, credit, eligibility, health | Formal risk assessment, human sign-off, records, contestability path |
Anything that significantly affects a person is high tier, and that is precisely where the December 2026 Privacy Act rules land.
4. Human-in-the-loop by design. For every high-tier use, a named person owns the final decision and can override the model. Document who, and document that they actually looked.
5. Vendor and data checks. Before you adopt a tool, ask where the data goes, whether it is used to train the vendor’s models, where it is hosted, and what the vendor will tell you about the model. If you would not put it in a customer email, do not put it in an unvetted tool. My longer take on tool selection sits in is ChatGPT safe for Australian business.
Governance is not a document you file. It is the register you keep current, the sign-offs you actually collect, and the tool requests you actually say no to.
What is changing, and what should I do now?
The direction of travel is clear. Australia set up an AI Safety Institute, backed by A$29.9 million and standing up through early 2026, to test high-risk systems and feed insight to government and the National AI Centre. Expect the voluntary guardrails to harden into targeted obligations for high-risk settings over time, and expect the existing laws to keep tightening.
The businesses that win will not be the ones that waited for a law. They will be the ones that adopted the guardrails early, built the register, and made governance a habit before it became a requirement. Start with the 10 guardrails, tier your uses, and get your privacy policy ready for December 2026. That is a fortnight of work that saves you a very bad quarter later. If you want the full sequence, from policy to production, my 7-phase AI transformation roadmap lays it out.
I help Australian leaders build AI governance frameworks that enable delivery instead of blocking it. If that is where your business is, get in touch.