Australia - AI Policy Update
DTA AI Policy Update - Impact Assessment Tool and Procurement Guidance
Australia
RAI-AU-NA-DAUIAXX-2025The Digital Transformation Agency (DTA) updated the Policy for the responsible use of AI in government (v2.0) and published a new AI Impact Assessment Tool plus Guidance on AI procurement. The update mandates use-case-level impact assessments, strengthens accountability requirements, and provides procurement steps, checklists and contract-clause guidance to support safe, ethical and transparent AI adoption across the Australian Public Service (APS).
Summary
Overview
In December 2025 the Digital Transformation Agency (DTA) published a significant update to the Australian Government’s AI policy framework: an updated "Policy for the responsible use of AI in government" (v2.0), a new AI Impact Assessment Tool with supporting guidance, and new Guidance on AI procurement in government. The policy update, delivered as part of the broader "APS AI Plan 2025" program, places clearer and stronger obligations on non-corporate Commonwealth entities to identify, evaluate and manage AI-specific risks while retaining space for experimentation and innovation.
Core policy changes
The update introduces, among other elements, mandatory requirements that each in‑scope AI use case have a clearly designated accountable officer and be recorded in an internal register. Critically, agencies must complete an AI use-case impact assessment using the DTA’s AI Impact Assessment Tool for all AI use cases that fall within the policy’s scope. The policy v2.0 took effect on 15 December 2025, and agencies were provided staged implementation timeframes for operational actions (including a stated deadline for impact assessment implementation by 15 December 2026 for in-scope use cases).
AI impact assessment tool
The DTA’s AI Impact Assessment Tool is a structured, 12-section template (fillable Word template) aligned to Australia’s AI Ethics Principles (fairness, reliability & safety, privacy & security, transparency, contestability, human-centred values, accountability etc.). The tool is accompanied by a detailed guidance document which explains how to complete each section, provides risk-rating guidance, and clarifies when a use case triggers higher levels of assurance and referrals to oversight arrangements (for example the forthcoming AI Review Committee).
Procurement guidance and buyer supports
Complementing the tool, the DTA published Guidance on AI procurement in government and an AI procurement checklist. These resources embed AI-specific considerations into the Digital Sourcing Lifecycle (Plan, Source, Manage): they instruct buyers to define outcome-focused objectives, undertake legal and policy reviews (privacy, security, ethics), assemble multidisciplinary procurement teams, assess data and infrastructure readiness, require appropriate reporting/transparency from suppliers, and use model contractual clauses and templates to capture obligations about data handling, IP, explainability, monitoring and incident management. The APS AI Plan and the DTA guidance also signal actions to create procurement categories and marketplace arrangements that make it easier to find vendors with demonstrated capabilities.
Governance, oversight and tools ecosystem
The update aligns with a broader set of DTA standards and APSC/Finance-led APS actions: a technical standard for AI use across the government lifecycle, a Standard for AI accountability and a Standard for AI transparency statements. The APS AI Plan assigns deliverables across Finance, DTA and APSC (including Chief AI Officers, GovAI platforms and GovAI Chat rollout) and foresees a central register of generative AI assessments and a standing AI Review Committee for high-risk cases.
Scope and applicability
The policy applies to non-corporate Commonwealth entities; some national security, defence and intelligence activities are treated separately. Agencies remain responsible for ensuring compliance with existing laws (Privacy Act, protective security frameworks, procurement law) and for integrating the DTA resources into their broader risk-management and ICT investment oversight processes.
Practical impact
Agencies are required to integrate the impact assessment into project governance, maintain internal registers, designate accountable officials, publish transparency statements for public-facing AI use, and adopt procurement clauses and due diligence steps when buying AI-enabled goods and services. While the DTA guidance is not primary legislation, failure to meet policy standards can lead to internal administrative and accountability measures, impact procurement eligibility, and raise oversight concerns through Finance, APSC and parliamentary scrutiny.
Sources
Primary official sources for the update include the DTA media release (2 December 2025), the Policy for the responsible use of AI in government (v2.0, effective 15 December 2025), the AI Impact Assessment Tool and Guidance (Published 1 December 2025), and the DTA Guidance on AI procurement in government. These are published on the DTA and digital.gov.au portals and cross-referenced in the APS AI Plan 2025 and Department of Finance announcements.
Overall, the DTA update formalises risk‑based, use‑case level governance for AI across the APS; provides a standardised assessment instrument and step‑by‑step procurement guidance; and sits inside a wider program (APS AI Plan, GovAI, technical standards) designed to accelerate safe, capable and ethically aligned AI adoption across Commonwealth agencies.
Full article
Read full text ↗Overview
The Digital Transformation Agency announced an update to the Australian Government's AI policy framework in December 2025, delivering three interlinked products: an updated Policy for the responsible use of AI in government (v2.0), a new AI Impact Assessment Tool with supporting guidance, and Guidance on AI procurement in government. Policy v2.0 came into effect on 15 December 2025 and establishes mandatory accountability and impact assessment requirements for in-scope AI use cases within non-corporate Commonwealth entities.
Definitions
The update relies on a set of working definitions consistent with DTA resources: an "AI use case" is an activity where an AI system (or model-based automation) materially affects government decision-making, service delivery, or interactions with the public. The policy references Australia’s AI Ethics Principles and distinguishes between in-scope use cases (which require assessments and accountability) and out-of-scope activities (local, low-risk or excluded national security/intelligence contexts). The AI Impact Assessment Tool further defines key concepts (fairness, reliability, contestability, explainability, human oversight) used throughout the assessment template.
Governance and Institutional Framework
The DTA is the lead agency coordinating whole-of-government AI guidance, supported by the Department of Finance and the Australian Public Service Commission (APSC). The updated policy mandates that agencies designate accountable official(s) for AI strategy and for each in-scope use case, maintain an internal use-case register, and produce AI transparency statements under the Standard for AI accountability and Standard for AI transparency statements. The APS AI Plan (2025) coordinates additional institutional measures, including appointing Chief AI Officers, establishing an AI Review Committee, and providing shared GovAI infrastructure to reduce duplication and support secure adoption.
Key Focus Areas
The policy update and supporting materials focus on: (1) strengthened accountability (clear accountable officers for use cases, internal registers); (2) mandatory AI use-case impact assessment, using the DTA’s 12-section assessment tool aligned to Australia’s AI Ethics Principles; (3) procurement safeguards—guidance and checklists that embed AI-specific considerations into the Digital Sourcing Lifecycle; (4) transparency—requirements for publishing AI transparency statements where public-facing or materially impactful AI is used; (5) technical assurance—linkage to the DTA’s Technical Standard for AI and to existing cyber/security frameworks; and (6) capability uplift—training, Chief AI Officers, and GovAI services to support government adoption.
Implementation Framework
Implementation is staged: policy v2.0 is effective from 15 December 2025 but agencies are given structured time to operationalise new requirements (the DTA guidance clarifies implementation timetables and transitional arrangements). The AI Impact Assessment Tool (fillable Word template) and detailed guidance (PDF) are provided to help agencies incorporate assessments into existing governance and investment assurance processes. Procurement guidance maps AI considerations to each phase of the Digital Sourcing Lifecycle (Plan, Source, Manage) and recommends multidisciplinary procurement teams, supplier due diligence, contract clauses, data readiness checks and alignment with existing legislative obligations.
Monitoring and Evaluation
The DTA and Finance will monitor uptake across the APS, supported by the APS AI Plan governance structures. Agencies must maintain internal registers and transparency statements, producing evidence that assessments have been completed and accountability assigned. The DTA has piloted earlier versions of the tool (September–November 2024) and published pilot findings; ongoing monitoring will include aggregation of lessons learned, reuse via a central register on GovAI, and review by the proposed AI Review Committee for higher-risk use cases.
Penalties, Liability, and Appeals
The DTA policy is a mandatory APS policy instrument for non-corporate Commonwealth entities; enforcement relies on APS accountability, administrative remedies and oversight by agency heads, Finance and the APSC rather than new criminal penalties in the policy itself. Non-compliance can have administrative consequences (internal disciplinary or procurement ineligibility), reputational impacts, and may expose agencies to regulatory or legal risks under existing legislation (Privacy Act, protective security laws, procurement rules). The policy highlights alignment with existing legal frameworks rather than creating standalone statutory sanctions.
Relationship to Other Instruments
The policy update complements and references existing instruments: the APS AI Plan 2025, the Technical standard for government’s use of artificial intelligence, the Standard for AI accountability and the Standard for AI transparency statements. Agencies must also continue to satisfy obligations under the Privacy Act, the Protective Security Policy Framework and procurement legislation; the DTA materials are expressly designed to integrate with these frameworks and not to duplicate them.
International Alignment
The DTA materials and the APS AI Plan reference international best practice and standards (for example OECD AI principles and cross-jurisdictional technical guidance). The approach emphasises risk-based, use-case level assessment and alignment with common international themes—transparency, accountability, human oversight and safety—while preserving flexibility to adapt to domestic legal obligations and sector-specific regulatory regimes.
Implementation Timeline
| Event | Date |
|---|---|
| DTA media release announcing policy update, tool and procurement guidance | 2025-12-02 |
| AI Impact Assessment Tool and Guidance published (digital.gov.au) | 2025-12-01 |
| Policy for the responsible use of AI in government (v2.0) takes effect | 2025-12-15 |
| Deadline for agencies to implement mandatory AI impact assessment for in-scope use cases | 2026-12-15 |
| Pilot of early assurance framework (21 volunteer agencies) | 2024-09 to 2024-11 |
Sources and References
Requirements for a company
What an organisation has to do under Australia - AI Policy Update, at a glance. Not legal advice — the table below gives the provision and deadline for each item.
Must do
9- Complete a mandatory AI impact assessment for all in-scope use cases.Non-corporate Commonwealth entities using in-scope AI systems.
- Designate accountable official(s) for AI strategy and each in-scope use case.Non-corporate Commonwealth entities.
- Maintain an internal register of AI use cases, accountable officers, and assessment outcomes.Non-corporate Commonwealth entities.
- Publish AI transparency statements where public-facing or materially impactful AI is used.Non-corporate Commonwealth entities using public-facing AI.
- Comply with existing Privacy Act, protective security, and procurement legislation.Non-corporate Commonwealth entities.
- Apply DTA procurement guidance, checklists, and contract clauses for AI systems.Non-corporate Commonwealth entities procuring AI systems.
- +3 more in the table below
Must not do
0Nothing in this category.
Should do
0Nothing in this category.
Should not do
0Nothing in this category.
Who must do what
The obligations under Australia - AI Policy Update, most serious first. Not legal advice — verify against the official text before relying on it.
| # | Who | Requirement | By when | Where | Severity |
|---|---|---|---|---|---|
| 1 | Non-corporate Commonwealth entities using in-scope AI systems. | Complete a mandatory AI impact assessment for all in-scope use cases. “Deadline for agencies to implement mandatory AI impact assessment for in-scope use cases” | Dec 15, 2026 | Implementation Timeline | Critical |
| 2 | Non-corporate Commonwealth entities. | Designate accountable official(s) for AI strategy and each in-scope use case. “The updated policy mandates that agencies designate accountable official(s) for AI strategy and for each in-scope use case” | — | Governance and Institutional Framework | Critical |
| 3 | Non-corporate Commonwealth entities. | Maintain an internal register of AI use cases, accountable officers, and assessment outcomes. “agencies... maintain an internal use-case register” | — | Governance and Institutional Framework | Critical |
| 4 | Non-corporate Commonwealth entities using public-facing AI. | Publish AI transparency statements where public-facing or materially impactful AI is used. “produce AI transparency statements under the Standard for AI transparency statements.” | — | Governance and Institutional Framework | Critical |
| 5 | Non-corporate Commonwealth entities. | Comply with existing Privacy Act, protective security, and procurement legislation. “Non-compliance... may expose agencies to regulatory or legal risks under existing legislation (Privacy Act, protective security laws, procurement rules).” | — | Penalties, Liability, and Appeals | Critical |
| 6 | Non-corporate Commonwealth entities procuring AI systems. | Apply DTA procurement guidance, checklists, and contract clauses for AI systems. “procurement safeguards—guidance and checklists that embed AI-specific considerations into the Digital Sourcing Lifecycle” | — | Key Focus Areas | Important |
| 7 | Non-corporate Commonwealth entities. | Incorporate AI impact assessments into existing governance and investment assurance processes. “help agencies incorporate assessments into existing governance and investment assurance processes.” | — | Implementation Framework | Important |
| 8 | Non-corporate Commonwealth entities procuring AI systems. | Conduct supplier due diligence, including data readiness checks, for AI procurement. “recommends multidisciplinary procurement teams, supplier due diligence, contract clauses, data readiness checks” | — | Implementation Framework | Important |
| 9 | Non-corporate Commonwealth entities using AI systems. | Ensure AI systems align with the DTA’s Technical Standard for AI. “technical assurance—linkage to the DTA’s Technical Standard for AI” | — | Key Focus Areas | Important |
Related Regulations
Policy for the responsible use of AI in government
Australia96% similar
National Framework for the Assurance of Artificial Intelligence in Government
Australia93% similar
New South Wales AI Assurance Framework
Australia93% similar
Safe and Responsible AI in Australia — Government Interim Response to Consultation
Australia92% similar
Guidance for the use of artificial intelligence in Tasmanian Government
Australia92% similar
© Regulations.AI · updated on 13-Jun-2026