Australia - AI Guardrails in High-Risk Settings

Proposals Paper for Introducing Mandatory Guardrails for AI in High-Risk Settings

Australia

RAI-AU-NA-PPIMGXA-2024
Withdrawn(Failed, vetoed or pulled)
PolicyGovernance and OversightRisk ManagementConformity Assessment and Registration
Export PDF

The Australian Government published a Proposals Paper on 5 September 2024 outlining proposed mandatory guardrails for AI systems used in high-risk settings. The paper proposes a risk-based approach (including a definition of high-risk AI), ten proposed mandatory guardrails, and three regulatory implementation options for consultation.

Summary

On 5 September 2024 the Australian Government (Department of Industry, Science and Resources) published the "Proposals Paper for Introducing Mandatory Guardrails for AI in High-Risk Settings" to consult on a framework of mandatory obligations for AI used in high-risk contexts. The Paper sets out a risk-based approach to identifying high-risk AI systems (based on potential harms to individuals, groups and public interests) and proposes ten high-level guardrails intended to apply across the AI supply chain and throughout the AI lifecycle. The proposed guardrails include obligations around testing and evaluation before and after deployment, transparency and labelling of AI interactions and outputs, data governance and privacy protections, accountability and documentation, human oversight, incident reporting and remediation, cybersecurity, conformity and registration requirements, third-party supply-chain management, and measures to protect fundamental rights and reduce bias and discrimination.

The Proposals Paper also outlines three regulatory pathways to mandate these guardrails: (1) embedding guardrails into existing sectoral regulatory frameworks where appropriate; (2) a framework approach that uplifts and coordinates powers across existing regulators; and (3) a standalone cross-economy AI Act and dedicated regulator. The consultation sought stakeholder feedback on the definition of high-risk AI, the content of each guardrail, and the preferable regulatory approach. The government released the consultation for four weeks (5 September to 4 October 2024) and published the Paper and associated Voluntary AI Safety Standard for immediate guidance.

Submissions from existing regulators (including the Office of the Australian Information Commissioner) and industry generally support the need for mandatory, interoperable, human-rights-informed guardrails while cautioning against regulatory duplication. The Proposals Paper emphasises alignment with international developments (notably the EU AI Act and Canadian approaches) and the need for coordination between regulators such as the OAIC, ACCC, ACMA, eSafety Commissioner and sectoral regulators (e.g., TGA and APRA) to ensure consistent enforcement and conformity assessment. The Paper is positioned as a policy step toward legislative and regulatory reform to manage AI risks while enabling innovation in Australia.

Full article

Read full text ↗

Overview

The Australian Government published the "Proposals Paper for Introducing Mandatory Guardrails for AI in High-Risk Settings" on 5 September 2024 to seek views on a set of ten proposed mandatory guardrails, a proposed definition of high-risk AI, and three regulatory options for mandating guardrails. The consultation materials, including the Proposals Paper (PDF) and an accompanying Voluntary AI Safety Standard, are available on the Department of Industry, Science and Resources consultation portal. The Paper takes a risk-based, lifecycle approach that aims to prevent and mitigate harms arising from AI systems used in contexts where failures could materially affect safety, human rights, economic wellbeing or public trust. The Paper emphasises cross-regulatory coordination, alignment with international instruments, and the need for clarity for businesses and regulators to enable safe uptake of AI across sectors. Key references include the Department consultation page and the Proposals Paper itself (Introducing mandatory guardrails for AI in high-risk settings: proposals paper) and the official PDF of the Paper (Proposals Paper (PDF)).

Definitions

The Paper proposes a definition of "high-risk AI" grounded in potential for material harm to individuals or public interests. A high-risk AI system is described by a combination of (1) the severity and likelihood of potential harms arising from its outputs or decisions, (2) the scale of affected persons or systems, and (3) the context of deployment (e.g., safety-critical systems, decisions that materially affect legal rights, access to services, health outcomes, or essential economic functions). The Paper distinguishes between AI as a component of a broader system and stand-alone AI products and applies the definition across the AI lifecycle (development, testing, deployment, monitoring, decommissioning). The Paper also defines terms used across the guardrails such as "developer", "deploying entity", "supply chain", "human oversight", "conformity assessment" and "materially adverse outcome" to support regulatory clarity.

Governance and Institutional Framework

The Proposals Paper outlines three institutional options for implementing mandatory guardrails: (1) embedding guardrails in sector-specific regulatory frameworks; (2) a framework approach that uses existing regulators but elevates consistent mandatory requirements and coordination mechanisms across regulators; and (3) a new cross-economy AI Act supported by a dedicated regulator. The Paper recommends assessing trade-offs between regulatory coherence, speed of implementation, and the risk of duplication. It highlights coordination roles for the Department of Industry, Science and Resources as policy lead and identifies other regulators that would play operational roles, including the Office of the Australian Information Commissioner (OAIC), the Australian Competition and Consumer Commission (ACCC), the Australian Communications and Media Authority (ACMA), the eSafety Commissioner (eSafety), and sectoral regulators such as the Therapeutic Goods Administration (TGA) and the Australian Prudential Regulation Authority (APRA). The Paper stresses the need for governance structures that enable coordinated market surveillance, conformity assessment pathways, clear enforcement powers, and specialist technical capability within regulators.

Key Focus Areas

The Paper proposes ten high-level mandatory guardrails meant to be applied where AI is assessed as high-risk. These focus areas are: (1) risk assessment and management across the AI lifecycle; (2) pre-deployment safety testing and ongoing evaluation (including post-deployment monitoring); (3) transparency, labelling and notification of AI interactions and AI-generated content to affected persons; (4) data governance, quality and privacy protections; (5) human oversight and human-in-the-loop measures for critical decisions; (6) documentation and technical records (model cards, data lineage, audit logs) to support accountability; (7) conformity assessment, registration and independent testing for selected classes of systems; (8) incident reporting, breach notification and remediation obligations; (9) cybersecurity requirements and model integrity protections; and (10) measures addressing bias, discrimination, and protection of fundamental rights. Collectively these guardrails are designed to reduce likelihood and severity of harms, increase transparency and trust, and provide clear remediation pathways when harms occur. The Paper also canvasses how obligations might be apportioned across developers, deployers and third-party suppliers in the AI supply chain.

Implementation Framework

The Paper outlines an implementation framework that pairs the substantive guardrails with a staged compliance pathway. Key elements include: mandatory obligations for entities developing or deploying high-risk AI to undertake risk classification and document decisions; requirements to undertake pre-deployment testing (including technical and social impact testing) and to publish summary results or certifications; mandatory maintenance of auditable documentation across the lifecycle; registration or conformity assessment for some high-risk categories; and rules for supply-chain contracts and third-party validation. The Paper proposes that regulators be empowered with investigative and enforcement tools, guidance materials and standardised reporting templates. It also examines options for transitional arrangements (including reliance on a Voluntary AI Safety Standard and grace periods to enable business adaptation).

Monitoring and Evaluation

Monitoring and evaluation provisions in the Paper cover regulator-coordinated market surveillance, data-driven monitoring of reported incidents, periodic compliance audits, and public reporting on enforcement actions. The Paper proposes that regulators share intelligence and coordinate investigations to detect systemic risks, and recommends establishing metrics for measuring effectiveness such as incident rates, remediation times, and outcomes for affected persons. It also suggests periodic policy reviews to ensure guardrails remain aligned with technological developments and international standards and proposes stakeholder engagement channels for iterative improvement.

Penalties, Liability, and Appeals

The Paper sets out the types of enforcement measures that could be used to secure compliance, including infringement notices, civil penalties, orders to cease deployment or disable systems, remediation orders, and directions to publish corrective information. It discusses aligning penalties with existing regulator powers and the need for clear liability rules so affected individuals can seek redress. The Paper further contemplates appeal and review mechanisms (administrative review or judicial review) to ensure decisions by regulators are contestable and transparent.

Relationship to Other Instruments

The Paper describes how the guardrails would interact with existing Australian law and reform processes — for example, privacy law (the Privacy Act and proposed amendments), consumer protection laws enforced by the ACCC, sectoral safety and medical device regulation (TGA), financial regulation (APRA/ASIC), telecommunications and critical infrastructure rules, and criminal law. It emphasises a complementary approach, seeking to uplift existing frameworks rather than create unnecessary duplication, while also identifying areas where harmonisation or new legislative authority may be necessary to close gaps.

International Alignment

The Proposals Paper positions Australia’s approach to mandatory guardrails in the context of international developments such as the European Union AI Act, Canadian approaches to high-risk AI, and other national initiatives. The Paper stresses interoperability, cross-border data flow considerations, and the benefits of adopting internationally-recognised conformity assessment standards to support trade and regulatory cooperation. It also highlights the necessity of engagement in international standard-setting bodies and bilateral regulatory dialogues to enable mutual recognition of assessments and reduce compliance costs for global AI providers.

Implementation Timeline

MilestoneDate
Proposals Paper published (consultation opened)2024-09-05
Consultation closed2024-10-04
Public feedback published2024-10-2024 to 2025 (staged publication by DISR and regulators)
Further policy decisions / preferred regulatory approach announcedTo be determined following consultation (expected 2025 under original timetable)
Enabling legislation / regulatory instruments draftedTo be determined
Staged implementation / transitional periodsTo be specified in final regulatory instruments

Sources and References

SourceType
Introducing mandatory guardrails for AI in high-risk settings: proposals paperPrimary Source
Proposals Paper for Introducing Mandatory Guardrails for AI in High-Risk Settings (PDF)Primary Source
The Albanese Government acts to make AI safer (media release)Primary Source
OAIC submission on the Proposals PaperPrimary Source

Requirements for a company

What an organisation has to do under Australia - AI Guardrails in High-Risk Settings, at a glance. Not legal advice.

No current requirements. This instrument is withdrawn; it imposes nothing today.

© Regulations.AI · updated on 26-Aug-2026