Skip to main content

12 July 2026

AI Governance

AI Governance for Australian Business: A Practical Framework

A practical AI governance framework for Australian business: what the National AI Plan, the Voluntary AI Safety Standard and ISO 42001 mean, and how to comply.

AI Governance for Australian Business: A Practical Framework, AI Governance, Compliance analysis by Amjid Ali.

Every week another Australian business asks me the same thing: “Do we need to worry about AI regulation, or is that a European problem?” The honest answer is that Australia has taken a different road to Brussels, and that road puts more of the burden on you, not less.

AI governance for an Australian business means putting in place the accountability, policies, records and human checks that let you use AI safely and prove you did so, drawing on existing laws plus voluntary standards rather than a single AI Act. It is not a legal department problem you can park. It is an operating discipline, and the businesses that get it right will move faster, not slower, because they will not be second-guessing every deployment.

Here is the framework I use with clients, grounded in where Australian policy actually landed as of mid-2026.

Does Australia have an AI law?

No. Australia has deliberately chosen not to pass a standalone AI Act, and the December 2025 National AI Plan made that official.

The National AI Plan set out the government’s approach: build on the legal and regulatory frameworks we already have, and lift them where gaps appear, rather than write one omnibus statute in the mould of the EU AI Act. The plan pulls together more than A$460 million in existing funding across three goals: capture the opportunity, spread the benefits, and keep Australians safe.

For most business owners the takeaway is counter-intuitive. “No AI Act” does not mean “no obligations”. It means your AI obligations are scattered across laws you already have to follow:

  • The Privacy Act 1988, which already governs how you handle personal information and is being tightened.
  • Australian Consumer Law, which bites if an AI system misleads customers or produces unfair outcomes.
  • Anti-discrimination law, which applies squarely to a biased model that screens job applicants or prices a service.
  • Sector rules in health, finance and other regulated fields.

The government itself acknowledged the gaps: generative AI, deepfakes, synthetic training data, systemic algorithmic bias and autonomous decision-making are areas where existing law strains. Expect incremental amendments to the Privacy Act, Consumer Law and Online Safety Act rather than one big bang.

The single most concrete obligation is already on the calendar. From 10 December 2026, new automated decision-making transparency rules under the Privacy Act require organisations that use personal information in a computer program to make decisions significantly affecting people to disclose this in their privacy policy. The OAIC is preparing detailed guidance and has signalled a broad reading. Critically, it applies even when a human stays in the loop. I have written a fuller breakdown in the Privacy Act automated-decisions guide.

There is also the Scams Prevention Framework, which places mandatory prevent, detect, report and respond duties on banks, telcos and digital platforms. AI sits on both sides of that fight, so if you operate in those sectors, governance is not optional.

What is the Voluntary AI Safety Standard?

The Voluntary AI Safety Standard is the Australian government’s practical playbook: 10 guardrails that any organisation can adopt to use AI safely, and it is the closest thing we have to a national baseline.

Published by the Department of Industry, Science and Resources, the Voluntary AI Safety Standard is voluntary, but I treat it as the reference every Australian board should measure itself against. It was designed to be consistent with the international ISO/IEC 42001 standard and the US NIST AI Risk Management Framework, so adopting it is not a dead end. The National AI Centre has since built on it with the October 2025 Guidance for AI Adoption, which distils the same thinking into six essential practices for organisations starting out.

Here are the 10 guardrails in plain terms, with what each one actually asks of you.

#GuardrailWhat it means in practice
1AccountabilityName an owner, build internal capability, have a compliance strategy, and publish it
2Risk managementRun a repeatable process to identify and mitigate AI risks before and during use
3Data governanceProtect the systems and manage data quality, security and provenance
4TestingEvaluate model performance before launch and monitor it once live
5Human oversightMake sure a person can intervene in or control the system meaningfully
6Transparency to usersTell people when they are dealing with AI or AI-generated content
7ContestabilityGive affected people a way to challenge an AI decision or outcome
8Supply-chain transparencyShare model and data information with partners so they can manage risk
9RecordsKeep documentation good enough for a third party to assess your compliance
10Stakeholder engagementConsider the people affected, with a focus on safety, fairness and inclusion

If you do nothing else this quarter, read these 10 lines and score yourself honestly against each. Most businesses I assess are strong on testing and weak on accountability, records and contestability. Those three gaps are exactly what a regulator or an angry customer will probe first.

Where does ISO/IEC 42001 fit in?

ISO/IEC 42001 is the international, certifiable version of what the guardrails describe: an AI management system you can be audited against and hold up as proof.

The difference is one of weight. The Voluntary AI Safety Standard is free guidance you can adopt in an afternoon. ISO/IEC 42001:2023 is a formal management-system standard, in the same family as ISO 9001 for quality and ISO 27001 for information security, that an external auditor can certify. Because the guardrails were mapped to it deliberately, the work you do on the guardrails is not wasted if you later pursue certification.

Who should reach for 42001? If you sell to enterprise or government, if AI is core to your product, or if you already run other ISO management systems, certification becomes a commercial asset rather than a compliance cost. I have written more on how that plays out for teams already certified in ISO 9001 and AI governance. For a small services firm using off-the-shelf tools, the guardrails alone are plenty for now.

How do I write an AI policy and governance framework?

Build the smallest governance framework that actually changes behaviour: an AI policy, a use register, risk tiering, human-in-the-loop rules, and vendor and data checks. Right-size it, then grow it.

Academic frameworks fail because nobody reads them. Here is the practical version I put in place, and it fits most mid-sized Australian businesses.

1. A one-page AI policy. Name the accountable owner. List approved tools and banned ones. Set clear rules for confidential and personal data (no client data into consumer chatbots without approval). Require staff to disclose AI-generated content and to keep a human sign-off on anything that affects a person. Short enough that people read it beats thorough enough that they do not.

2. A live AI use register. A single spreadsheet or table listing every AI system in use, its owner, what data it touches, and its risk tier. You cannot govern what you cannot see, and guardrail 9 effectively demands this record anyway.

3. Risk tiering. Not every use needs the same scrutiny. Sort uses into three tiers:

TierExampleGovernance
LowDrafting internal emails, summarising notesPolicy and training only
MediumCustomer-facing chatbot, marketing copyHuman review, disclosure, testing
HighDecisions on hiring, credit, eligibility, healthFormal risk assessment, human sign-off, records, contestability path

Anything that significantly affects a person is high tier, and that is precisely where the December 2026 Privacy Act rules land.

4. Human-in-the-loop by design. For every high-tier use, a named person owns the final decision and can override the model. Document who, and document that they actually looked.

5. Vendor and data checks. Before you adopt a tool, ask where the data goes, whether it is used to train the vendor’s models, where it is hosted, and what the vendor will tell you about the model. If you would not put it in a customer email, do not put it in an unvetted tool. My longer take on tool selection sits in is ChatGPT safe for Australian business.

Governance is not a document you file. It is the register you keep current, the sign-offs you actually collect, and the tool requests you actually say no to.

What is changing, and what should I do now?

The direction of travel is clear. Australia set up an AI Safety Institute, backed by A$29.9 million and standing up through early 2026, to test high-risk systems and feed insight to government and the National AI Centre. Expect the voluntary guardrails to harden into targeted obligations for high-risk settings over time, and expect the existing laws to keep tightening.

The businesses that win will not be the ones that waited for a law. They will be the ones that adopted the guardrails early, built the register, and made governance a habit before it became a requirement. Start with the 10 guardrails, tier your uses, and get your privacy policy ready for December 2026. That is a fortnight of work that saves you a very bad quarter later. If you want the full sequence, from policy to production, my 7-phase AI transformation roadmap lays it out.

I help Australian leaders build AI governance frameworks that enable delivery instead of blocking it. If that is where your business is, get in touch.

Frequently asked.

Does Australia have an AI law that businesses have to comply with in 2026?
No. Australia has no standalone AI Act. The December 2025 National AI Plan confirmed the government will lift existing laws (privacy, consumer, anti-discrimination) rather than pass one statute. So AI obligations reach you through those existing laws, including new Privacy Act automated-decision transparency rules that commence in December 2026.
What is the Voluntary AI Safety Standard and is it mandatory for my business?
The Voluntary AI Safety Standard is a set of 10 practical guardrails published by the Department of Industry, Science and Resources. It is not mandatory. It gives Australian organisations a ready framework for accountability, risk management, data governance, testing, human oversight and record keeping, and it aligns with the international ISO/IEC 42001 standard.
How do I write an AI policy for a small or medium Australian business?
Start with a one-page policy that names an accountable owner, lists approved and banned tools, sets rules for confidential and personal data, requires human sign-off on decisions that affect people, and mandates disclosure of AI-generated content. Pair it with a live AI use register. Keep it short enough that staff actually read it.
What is the difference between the Voluntary AI Safety Standard and ISO/IEC 42001?
The Voluntary AI Safety Standard is free Australian government guidance you can adopt in an afternoon. ISO/IEC 42001 is a certifiable international management-system standard you can be independently audited against. The 10 guardrails map closely to ISO 42001, so starting with the guardrails is a sensible first step toward certification later.
What are the Privacy Act automated decision-making rules starting in December 2026?
From 10 December 2026, organisations that use personal information in computer programs to make decisions significantly affecting people must disclose this in their privacy policy. It covers the kinds of information used and decisions made, and applies even when a human stays in the loop. The OAIC is publishing detailed guidance ahead of the deadline.

Picked by shared topic. The through-line is agentic AI shipped into production, not the pilot theatre.

Read another.