tasmaniaaustraliaartificial intelligencepublic sectorai governance

Tasmania’s Government AI Guidance Turns Two: What to Know

Regulations.ai (AI-assisted)

Two years ago today, on September 13, 2024, the Tasmanian Government Secretaries Board formally approved the Guidance for the use of artificial intelligence in Tasmanian Government. Marking its two-year anniversary in active operation, this operational framework continues to govern how public sector bodies across the state integrate automation and machine learning into daily government services.

What's changing — substance

While the document was designed as a non-binding guideline rather than a statutory law, its expectations have been binding administrative policy across state agencies since late 2024. The guidance provides clear parameters for adopting AI technologies, ranging from enterprise productivity software like Microsoft Copilot to complex algorithmic decision-support tools.

Rather than imposing a blanket prohibition or a single technical standard, the instrument focuses on risk management, accountability, and compliance with existing legal obligations. Key requirements established under the framework include:

  • Risk-Based Assessments: Agencies must evaluate every proposed AI project against their specific organizational risk tolerance. High-impact applications—particularly those touching administrative decisions, public entitlements, or sensitive records—demand thorough risk reviews prior to launch.
  • Continuous Human Oversight: Human accountability is mandatory. Automated systems cannot serve as autonomous final decision-makers for statutory, administrative, or policy outcomes; ultimate legal and administrative responsibility remains with designated public servants.
  • Data Protection and Privacy Compliance: Every AI initiative must strictly protect state records and personal information. Aligning deployments with existing state cybersecurity frameworks and the Personal Information Protection Act 2004 is required.
  • No Automatic Pre-Approvals: Commercial off-the-shelf platforms and general generative AI tools are not automatically pre-approved for routine administrative work. Entering sensitive, classified, or personal state records into unvetted platforms directly breaches state data management standards.

Because this guidance is a non-binding policy framework rather than legislation, it creates no independent penalties, liability regimes, or standalone administrative appeal mechanisms. However, this does not mean agencies operate without risk. Data breaches, privacy violations, or administrative errors resulting from AI deployments remain fully subject to enforcement and legal consequences under pre-existing state laws.

Who is affected — jurisdictions, sectors, sizes

This guidance applies directly to all public sector bodies operating within the Tasmanian state government. This includes departments, statutory authorities, state-owned corporations, and administrative units across the state, regardless of their operational size or technical capacity.

While central governance leads overarching whole-of-government policy, individual agency heads and project leads hold direct responsibility for local compliance. The guidance explicitly emphasizes that departments cannot rely solely on this high-level state instrument. Each agency is required to formulate its own tailored internal policies, build internal team capabilities, and update procurement screening processes before deploying third-party AI systems in live operational environments.

Three things to do this week

If your team manages, procures, or uses automated systems within a Tasmanian government body, use this two-year milestone to review your operational posture:

  1. Audit Bespoke Internal Agency Policies: Verify whether your agency has drafted and published its own specific internal rules for AI usage. Relying exclusively on the overarching 2024 state guidance without local operational procedures creates compliance gaps.
  2. Re-Issue Data Guardrails to Staff: Clarify across your organization that standard consumer AI models and web tools are not pre-approved for official business. Ensure staff understand that inputting confidential, personal, or state-classified records into unvetted platforms risks violating the Personal Information Protection Act 2004.
  3. Review Vendor Procurement Workflows: Examine active software vendor contracts and procurement pipelines. Ensure that external vendors delivering embedded AI features are subject to explicit risk screening, data lineage checks, and state cyber security standards before contract execution.

Related context

Tasmania’s state-level framework sits alongside broader governance efforts across Australia to manage emerging technology in the public sector. At the federal level, the Policy for the responsible use of AI in government (/regulations/RAI-AU-NA-RUAGXXX-2024) outlines binding expectations for Commonwealth entities. State-level frameworks such as the New South Wales AI Assurance Framework (/regulations/RAI-AU-NS-NSWAAXX-2022) and the Northern Territory AI Assurance Framework (/regulations/RAI-AU-NT-NTAAXXX-2024) provide parallel benchmarks for structured risk management and ethical AI oversight in public administration.

Note: this article was drafted by AI - Google Gemini