australiaai governancepublic sectorrisk managementdata privacyethics

Australia's AI Assurance Framework Now In Force for Government

Regulations.ai (AI-assisted)

A significant milestone for responsible AI governance in Australia has been reached: the National Framework for the Assurance of Artificial Intelligence in Government officially moved to an 'In Force' status on June 21, 2024. This change marks a critical moment for all Australian government agencies, establishing a clear, consistent roadmap for ensuring that AI systems are deployed safely, ethically, and effectively across the public sector.

What's changing

The National Framework for the Assurance of Artificial Intelligence in Government isn't a new law with fresh penalties, but rather a comprehensive, principles-based guideline that sets a strong expectation for how government entities should manage AI. Its core purpose is to ensure that any AI system developed, procured, or used by Australian federal, state, or territory governments is safe, lawful, and fit for its intended purpose. This framework directly aligns with Australia’s broader AI Ethics Principles, embedding those ethical considerations into practical operational requirements.

At its heart, the framework mandates a shift in how government agencies approach AI. It requires them to adapt their existing governance structures to include clear executive ownership for AI initiatives, establish cross-functional expert teams, and define specific roles and responsibilities for managing AI throughout its entire lifecycle—from conception to decommissioning. This isn't a 'set and forget' model; it demands continuous oversight and adaptation.

A cornerstone of the framework is the adoption of a risk-proportionate approach. This means agencies must actively identify all AI uses, then classify them based on their potential impact to individuals' rights, safety, or wellbeing. Once classified, assurance activities—such as rigorous testing for performance, bias, and safety—must be tailored to the identified risk level. A low-risk internal tool might require less stringent checks than an AI system influencing public services or critical infrastructure.

Data governance is also a major focus. Agencies are obligated to ensure strong data quality and provenance, understanding where the data comes from and how it has been processed. Crucially, the framework emphasizes embedding privacy-by-design principles from the outset of any AI project and implementing robust security controls to protect sensitive information. Transparency is another key pillar, requiring public disclosures about significant AI uses, maintaining registers of these systems, and providing clear pathways for human oversight and for individuals to challenge AI-influenced decisions.

Furthermore, when government agencies procure AI systems from third-party suppliers, they are now expected to demand comprehensive assurance evidence. This shifts some of the burden of proof onto vendors, ensuring that the AI solutions brought into government operations meet the same high standards.

It's important to reiterate that while the framework is non-binding, its recommendations carry significant weight. Non-compliance, particularly concerning issues like data breaches or discriminatory outcomes, could lead to liabilities under existing laws such as the Privacy Act 1988, anti-discrimination legislation, or consumer protection regulations. The framework provides the 'how-to' guide to avoid falling foul of these existing legal obligations.

Who is affected

This framework has a broad reach, impacting virtually every corner of Australian government. It applies to:

  • All Australian federal, state, and territory government agencies: This includes departments, statutory authorities, and other public sector bodies at all levels of government.
  • Public sector systems that develop, procure, or use artificial intelligence: Whether an agency is building its own AI tools, buying them off the shelf, or integrating AI capabilities into existing systems, the framework applies.

This comprehensive scope means that a vast array of government functions, from healthcare and social services to infrastructure management and defense, will need to align with the framework's principles. While the framework provides a national standard, its implementation is devolved. This means each jurisdiction (federal, state, and territory) will develop its own operational policies and guidelines to put the framework into practice. This devolved approach allows for flexibility to address specific local contexts and needs but may also lead to variations in the precise requirements and enforcement mechanisms across different parts of the country.

Three things to do this week

For product managers, team leads, and government officials involved with AI, the 'In Force' status means it's time to act. Here are three concrete steps to take this week:

  1. Review and Adapt Governance Structures: Immediately assess your agency's current governance for AI projects. Identify who holds executive ownership, whether cross-functional expert teams are in place, and if roles for managing AI throughout its lifecycle are clearly defined. Begin the process of formalizing these structures to align with the framework's expectations. This might involve updating internal policies, creating new committees, or assigning specific AI governance responsibilities to existing roles.
  2. Prioritize Privacy-by-Design and Data Governance: Given that implementing privacy-by-design principles and adhering to the Privacy Act 1988 is a critical compliance item, this should be a top priority. For all new and existing AI initiatives, ensure that privacy considerations are embedded from the earliest design stages. Conduct thorough data quality and provenance checks for all datasets used in AI systems, verifying their source, accuracy, and appropriate usage. If your agency hasn't already, establish clear protocols for data handling specific to AI applications.
  3. Initiate AI Use Identification and Risk Classification: Start a comprehensive inventory of all AI systems currently in use or under development within your agency. For each identified AI use, begin the process of classifying it based on its potential impact to individuals' rights, safety, or wellbeing. This classification will be the foundation for applying a risk-proportionate approach to assurance. Even a preliminary classification can help identify high-risk areas that require immediate attention and more rigorous assurance planning.

Related context

The National Framework for the Assurance of Artificial Intelligence in Government is a cornerstone of Australia's evolving approach to AI governance, but it doesn't exist in isolation. It complements and interacts with a broader landscape of policies and frameworks designed to ensure responsible AI use.

For instance, specific state and territory governments have also developed their own localized assurance frameworks, reflecting the devolved implementation approach. Examples include the New South Wales AI Assurance Framework and the Northern Territory AI Assurance Framework. These jurisdictional frameworks provide more granular guidance tailored to their specific operational contexts, while still aligning with the national principles.

Additionally, the framework works in concert with other national-level guidance, such as the Policy for the responsible use of AI in government. While the National Framework focuses on the 'assurance' aspect—how to verify that AI systems are safe and fit for purpose—the Policy for the responsible use of AI in government provides broader principles and expectations for ethical and responsible AI deployment across the public sector. Together, these documents create a robust ecosystem for governing AI in Australia's public service, aiming to foster innovation while mitigating potential harms.

Note: this article was drafted by AI - Google Gemini