AI Regulation in Australia: What Businesses Need to Know in 2026
A practical, plain-language guide to how Australia regulates AI in 2026 — what is voluntary, what is already law, and what is still only proposed — for businesses that use AI.
Australia does not have a single, dedicated AI law. Instead, businesses using AI in Australia must comply with existing laws — the Privacy Act, the Australian Consumer Law, anti-discrimination law, and sector-specific rules — plus a set of voluntary safety guardrails published by the federal government. Understanding which obligations are mandatory today and which are still proposed is the key to staying compliant without over-reacting.
The centrepiece of the government's current approach is the Voluntary AI Safety Standard, published by the Department of Industry, Science and Resources (DISR) in September 2024, which sets out 10 practical guardrails organisations can adopt now. Alongside it, the government released a proposals paper on mandatory guardrails for AI in high-risk settings — but as of mid-2026 those mandatory rules have not been legislated.
This guide explains the actual state of AI regulation in Australia as of July 2026: what the law requires, what is voluntary best practice, and what businesses should do now to reduce legal and reputational risk. It is written for small and medium businesses adopting AI tools, not for AI developers building frontier models. It is general information, not legal advice — for decisions about your specific situation, consult a qualified Australian lawyer.
Does Australia have an AI law?
No. As of July 2026, Australia has no single, dedicated AI Act. Unlike the European Union, Australia has not passed a standalone, cross-economy law that regulates artificial intelligence by name. Instead, AI use is governed by existing, technology-neutral laws that already apply to how businesses collect data, make decisions, sell products, and treat people.
This means an Australian business using AI must still comply with the Privacy Act 1988, the Australian Consumer Law (which prohibits misleading or deceptive conduct), anti-discrimination laws, work health and safety obligations, and any rules specific to its sector (for example, financial services regulation overseen by ASIC). AI does not create an exemption from these laws — it applies them to a new technology.
The federal government has signalled it may introduce targeted, mandatory obligations for AI used in high-risk settings, and released a proposals paper on this in September 2024. But that framework has not been enacted. Businesses should plan for a future of more specific AI rules while recognising that, today, compliance means applying existing law well and voluntarily adopting recognised safety guardrails.
Not sure how the Voluntary AI Safety Standard and Privacy Act apply to your AI tools? Layer3 Labs will map it out for you.
Book a ConsultationWhat is the Voluntary AI Safety Standard?
The Voluntary AI Safety Standard is a set of 10 practical guardrails that the Department of Industry, Science and Resources (DISR) published in September 2024 to help organisations use and deploy AI safely and responsibly. It is voluntary — adopting it is not legally required — but it reflects what the government considers good practice and previews the shape of possible future mandatory rules.
The standard applies across the AI supply chain, to both organisations that develop AI and those that merely deploy or use it. For most small and medium businesses, the relevant role is "deployer" or "user": you are buying and applying commercial AI tools rather than building your own models. The guardrails are designed to be adopted incrementally.
In October 2025, DISR published a simplified companion, the Guidance for AI Adoption, which distils the approach into a smaller number of essential practices for organisations getting started. The 10 guardrails remain the fuller reference framework.
- Guardrail 1: Establish, implement and publish an accountability process, including governance, internal capability and a strategy for regulatory compliance.
- Guardrail 2: Establish and implement a risk management process to identify and mitigate risks.
- Guardrail 3: Protect AI systems, and implement data governance measures to manage data quality and provenance.
- Guardrail 4: Test AI models and systems to evaluate model performance and monitor the system once deployed.
- Guardrail 5: Enable human control or intervention in an AI system to achieve meaningful human oversight across the life cycle.
- Guardrail 6: Inform end users about AI-enabled decisions, interactions with AI and AI-generated content.
- Guardrail 7: Establish processes for people impacted by AI systems to challenge use or outcomes.
- Guardrail 8: Be transparent with other organisations across the AI supply chain about data, models and systems so they can address risks.
- Guardrail 9: Keep and maintain records to allow third parties to assess compliance with the guardrails.
- Guardrail 10: Engage stakeholders and evaluate their needs and circumstances, with a focus on safety, diversity, inclusion and fairness.
Are there mandatory guardrails for high-risk AI?
Not yet. In September 2024 the government released a proposals paper, "Introducing mandatory guardrails for AI in high-risk settings," which set out a risk-based approach: certain AI uses judged to be high-risk would face binding obligations, while lower-risk uses would not. Public consultation on that paper closed in October 2024.
The proposals paper canvassed several possible ways to make guardrails mandatory — such as adapting existing sector-specific laws, creating framework legislation that coordinates existing regulators, or introducing a standalone cross-economy AI Act. The proposed mandatory guardrails broadly mirror the voluntary ones, with added emphasis on conformity assessments for high-risk systems.
As of July 2026, the government has not legislated mandatory guardrails, and their final form and timing remain uncertain. Businesses should treat the high-risk framework as a strong indication of direction rather than current law. Because the proposed mandatory guardrails closely resemble the voluntary standard, organisations that adopt the 10 voluntary guardrails now will be well-positioned if binding rules arrive.
How does the Privacy Act apply to AI?
The Privacy Act 1988 applies to AI whenever your business handles personal information — and the OAIC has confirmed this covers data you put into an AI tool and personal information the AI generates. The Australian Privacy Principles (APPs) govern how personal information is collected, used, disclosed, kept accurate, and secured, and they apply regardless of whether a human or an AI system does the processing.
In its guidance on using commercially available AI products, the Office of the Australian Information Commissioner (OAIC) highlights several obligations: entities should be transparent in their privacy policy about AI use (APP 1 and APP 5), only use personal information for the purpose it was collected or a reasonably expected secondary purpose (APP 6), take reasonable steps to ensure AI-generated personal information is accurate (APP 10), and be cautious about entering personal or sensitive information into public AI tools. The OAIC notes generative AI carries inherent accuracy risks such as hallucination and bias.
The Privacy and Other Legislation Amendment Act 2024, which received Royal Assent on 10 December 2024, adds a new transparency requirement for automated decision-making (ADM). From 10 December 2026, organisations that use personal information in computer programs to make, or substantially and directly help make, decisions that could significantly affect an individual's rights or interests must disclose this in their privacy policy. The OAIC is expected to publish detailed guidance on the new ADM obligations during 2026.
- Update your privacy policy to disclose how and where you use AI (APP 1, APP 5).
- Avoid entering personal or sensitive information into public AI tools unless you have a lawful basis and appropriate safeguards.
- Take reasonable steps to keep AI-generated personal information accurate before relying on it (APP 10).
- Prepare for the automated decision-making transparency requirement that starts 10 December 2026 if AI helps make decisions affecting people.
Which other regulators oversee AI in Australia?
Several existing regulators enforce laws that apply to AI within their remit, even without a dedicated AI statute. This "existing regulators" approach means the agency responsible for your sector or activity is generally the one that will hold you accountable for AI-related conduct.
The Australian Competition and Consumer Commission (ACCC) enforces the Australian Consumer Law, which prohibits misleading or deceptive conduct — relevant if AI outputs, chatbots, or AI-generated marketing mislead customers. The Australian Securities and Investments Commission (ASIC) has stated that existing financial services and directors' duties obligations apply to firms using AI, and has scrutinised AI governance in regulated entities. The eSafety Commissioner administers the Online Safety Act and industry codes that address AI-generated harmful content, including deepfakes and synthetic child sexual abuse material.
Anti-discrimination laws, enforced through bodies such as the Australian Human Rights Commission, apply where AI systems produce discriminatory outcomes in areas like hiring or credit. The practical takeaway: identify which regulators already govern your industry, because they are the ones whose rules your AI use must satisfy.
What should businesses do now to stay compliant?
Start by treating AI as a governed business activity rather than an informal experiment. Because Australia's rules flow from existing laws plus voluntary guardrails, the most effective compliance step is to build a light-touch AI governance process that maps your AI uses to the obligations that already apply — privacy, consumer law, and fair treatment of people.
The checklist below is drawn from the Voluntary AI Safety Standard and the Privacy Act. None of it requires legal expertise to begin, and adopting it now prepares you for both the automated decision-making rules starting in December 2026 and any future mandatory high-risk guardrails.
This is general information, not legal advice. For high-stakes uses — such as AI that influences hiring, credit, or other significant decisions about individuals — get advice from a qualified Australian lawyer before you deploy.
- Inventory your AI: list every AI tool in use, who owns it, and what data it touches.
- Name an accountable owner and set a simple internal AI use policy (Guardrail 1).
- Do a basic risk assessment for each use, flagging anything that affects people's rights or safety (Guardrail 2).
- Keep a human in the loop for consequential decisions, with a way for people to query or challenge outcomes (Guardrails 5 and 7).
- Update your privacy policy to disclose AI use and, where relevant, automated decision-making (Privacy Act; ready before 10 December 2026).
- Avoid putting personal, sensitive, or confidential data into public AI tools without safeguards.
- Tell users when they are interacting with AI or seeing AI-generated content (Guardrail 6).
- Keep records of your AI decisions and testing so you can show what you did (Guardrails 4 and 9).
How does Australia compare to the EU AI Act?
Australia's approach is far lighter and less prescriptive than the European Union's. The EU AI Act is a comprehensive, binding law that classifies AI systems by risk tier — prohibited, high-risk, limited-risk, and minimal-risk — and imposes detailed, enforceable obligations with significant penalties, phased in from 2025 onward. Australia has no equivalent statute in force.
Where the EU legislates mandatory requirements across the economy, Australia currently relies on voluntary guardrails plus existing laws, and has only proposed (not enacted) mandatory rules for high-risk settings. Notably, Australia's proposed high-risk approach borrows the EU's risk-based logic, so the two frameworks share a common philosophy even though only the EU's is binding today.
For Australian businesses, the practical implication is a lower immediate compliance burden than an EU counterpart faces — but not zero obligation. If your business sells into the EU or handles EU residents' data, the EU AI Act and GDPR may apply to you directly regardless of Australian law, so map your obligations by market, not just by where you are based.
Frequently Asked Questions
- No. As of July 2026 Australia has no single, dedicated AI Act. AI use is governed by existing laws — including the Privacy Act 1988, the Australian Consumer Law, and anti-discrimination law — plus the government's Voluntary AI Safety Standard. The Department of Industry, Science and Resources (DISR) has proposed, but not enacted, mandatory guardrails for high-risk AI.
- It is a set of 10 practical guardrails published by DISR in September 2024 to help organisations use and deploy AI safely and responsibly. It is voluntary and not legally binding, but it reflects government-endorsed good practice and closely mirrors the obligations proposed for high-risk AI, per the DISR standard.
- No. The 10 guardrails in the Voluntary AI Safety Standard are voluntary. The government released a separate proposals paper in September 2024 on making guardrails mandatory for high-risk AI settings, but as of July 2026 those mandatory rules have not been legislated, according to DISR.
- The Privacy Act 1988 applies whenever your business handles personal information, including data entered into AI tools and personal information the AI generates. The OAIC's guidance on commercially available AI products says the Australian Privacy Principles require transparency about AI use, purpose limits on use and disclosure, and reasonable steps to keep AI-generated personal information accurate.
- From 10 December 2026, under the Privacy and Other Legislation Amendment Act 2024 (Royal Assent 10 December 2024), organisations must disclose in their privacy policy where they use personal information in automated decision-making that could significantly affect an individual's rights or interests. The OAIC is expected to publish detailed guidance on this in 2026.
- The Voluntary AI Safety Standard applies across the AI supply chain, including organisations that only deploy or use AI rather than build it, per DISR. As a user of commercial AI tools you are not legally required to follow the guardrails, but they are the recommended way to manage risk, and the Privacy Act still applies to any personal information you handle.
- Australia uses existing regulators rather than a single AI regulator. The ACCC enforces consumer law, ASIC oversees AI use in financial services, the eSafety Commissioner addresses AI-generated online harms, and the OAIC enforces privacy obligations. Anti-discrimination bodies apply where AI produces discriminatory outcomes.
- The EU AI Act is a comprehensive, binding law with risk tiers and enforceable penalties, phased in from 2025. Australia has no equivalent statute in force and relies on voluntary guardrails plus existing laws, with only proposed mandatory rules for high-risk settings, per DISR. The two frameworks share a risk-based philosophy but only the EU's is currently binding.
- Start by creating an inventory of the AI tools you use, naming an accountable owner, writing a short internal AI use policy, and updating your privacy policy to disclose AI use. These steps align with the Voluntary AI Safety Standard and the Privacy Act and cover most near-term risk. For high-stakes uses, seek qualified legal advice.
- No. This is general information about AI regulation in Australia as of July 2026, not legal advice. Laws and government positions can change, and how they apply depends on your specific circumstances. For decisions about your business, consult a qualified Australian lawyer.
Adopt AI in Australia without the compliance guesswork
Layer3 Labs helps small and medium businesses adopt AI within their compliance obligations — mapping your AI uses to the Voluntary AI Safety Standard and Privacy Act, setting up practical governance, and getting a human-in-the-loop process in place before the 2026 automated decision-making rules take effect. Start with a free AI workflow audit and get a clear, prioritised action list.
Get your free AI workflow audit