Australia - Responsible AI Use Policy

Policy for the responsible use of AI in government

Australia

RAI-AU-NA-RUAGXXX-2024
Effective: September 1, 2024
In Force(In Force)
PolicyGovernance and OversightTransparency and DisclosureRisk Management
Export PDF

The Digital Transformation Agency’s "Policy for the responsible use of AI in government" (Version 1.1) took effect 1 September 2024. It mandates non-corporate Commonwealth entities to designate accountable official(s) and publish AI transparency statements, and encourages a risk-based, human-centred approach to government AI adoption aligned with existing legal frameworks.

Summary

The Policy for the responsible use of AI in government (Version 1.1), published by the Digital Transformation Agency (DTA) in August–September 2024, sets a whole-of-government baseline for how the Australian Government should adopt and govern artificial intelligence. The policy is mandatory for non-corporate Commonwealth entities (NCEs) and is designed to position the Australian Government as an exemplar in safe, ethical, and responsible AI use while remaining adaptive to technological and regulatory change. Key mandatory elements include the designation of accountable official(s) within 90 days of the policy taking effect, and publication of an AI transparency statement within six months. It also establishes implementation expectations across three high-level pillars: enable and prepare (build capability, integrate AI into existing governance frameworks, and define definitions/standards); engage responsibly (risk-based assessment, transparency, explainability, human-centred design, monitoring and evaluation); and evolve and integrate (ongoing review, integration with procurement, data governance and standards). The policy explicitly excludes the Defence portfolio and the national intelligence community from mandatory application, while encouraging corporate Commonwealth entities to voluntarily adopt its measures where feasible. Complementary documents and instruments referenced by the policy include the National framework for the assurance of artificial intelligence in government, the Technical standard for government’s use of artificial intelligence, the Standard for accountable officials, and the Standard for AI transparency statements. The DTA also provides guidance on staff training, an AI assurance pilot, a risk matrix, and a technical standard for lifecycle statements. Implementation deadlines included designation of accountable officials by 30 November 2024 and publication of transparency statements by 28 February 2025. The policy relies on a mix of administrative compliance, public transparency obligations, whole-of-government coordination through the DTA, and oversight via existing Commonwealth governance and audit mechanisms (for example, audit attention by the Australian National Audit Office (ANAO) and privacy oversight by the Office of the Australian Information Commissioner (OAIC)). While the policy establishes baseline mandatory organisational practices, it does not itself create novel criminal sanctions; rather it integrates with existing legal obligations and accountability mechanisms (public reporting, parliamentary oversight, departmental governance, audits, and regulator action under existing statutes). The policy emphasises a proportionate, risk-based approach: agencies are expected to identify and notify the DTA of new high-risk use cases and to apply technical assurance, testing and monitoring proportional to the risk profile of a use case. Overall, the policy functions as a foundational, government-internal regulatory instrument establishing minimum expectations for governance, transparency and assurance while the broader national regulatory environment for AI (including proposed mandatory guardrails and voluntary safety standards) continues to evolve.

Full article

Read full text ↗

Overview

The Policy for the responsible use of AI in government (Version 1.1) was published by the Digital Transformation Agency and took effect on 1 September 2024. The policy sets baseline mandatory expectations for all non-corporate Commonwealth entities to adopt a risk-based, transparent and accountable approach to AI, with targeted mandatory measures such as the designation of accountable official(s) and publication of AI transparency statements. The DTA frames the policy around three pillars—enable and prepare, engage responsibly, and evolve and integrate—to unify practice across agencies and build public trust. For the official policy text and PDF see Digital Transformation Agency — AI in government policy and the full policy PDF at Policy for the responsible use of AI in government (Version 1.1). This policy interoperates with other whole-of-government instruments including the National framework for the assurance of artificial intelligence in government and the Technical standard for government’s use of artificial intelligence, forming a practical baseline for accountability and transparency while higher‑order statutory regulation of AI is developed.

Definitions

The policy adopts the OECD definition of an "AI system" for operational consistency: machine-based systems that, for explicit or implicit objectives, infer from inputs how to generate outputs (predictions, content, recommendations, decisions) that can influence physical or virtual environments. It distinguishes levels of autonomy and adaptiveness and recommends agencies keep definitions under review as the policy and broader regulatory environment evolve. The policy also defines "high-risk use case" as those government AI uses that could significantly affect people’s rights, safety, wellbeing, or essential government services and requires agencies to notify the DTA where such cases are identified. "Accountable official(s)" are defined as named individual(s) or chairs of bodies responsible for implementing the policy in an agency context, and must be designated within 90 days of the policy taking effect.

Governance and Institutional Framework

The DTA is the primary steward of the policy, responsible for whole-of-government coordination, implementation guidance and maintaining standards. Agencies must designate accountable official(s) to implement the policy and to act as the contact point for whole-of-government coordination; responsibilities include notifying the DTA of new high-risk use cases and participating in cross‑agency forums. The policy is mandatory for non-corporate Commonwealth entities under the Public Governance, Performance and Accountability Act 2013 (as implemented by the DTA) and complements existing obligations such as the APS Code of Conduct, privacy and protective security frameworks. Implementation is supported by companion instruments published by the DTA: the Standard for accountable officials, the Standard for AI transparency statements, the Technical standard for government’s use of artificial intelligence, a risk matrix, and training guidance. Parliamentary and audit oversight is expected to be undertaken by bodies such as the Australian National Audit Office (ANAO), while privacy compliance is monitored by the Office of the Australian Information Commissioner (OAIC).

Key Focus Areas

The policy organizes requirements and recommended practice across three pillars. "Enable and prepare" focuses on organisational capability building: agencies must establish internal governance, define operational models, integrate AI considerations into procurement and data governance, and implement staff training (AI fundamentals for all staff within six months is strongly recommended). "Engage responsibly" emphasises a proportionate, risk-based approach to deployment: agencies must publish public AI transparency statements (within six months) describing purpose, classification of AI use, risk mitigation, monitoring measures and compliance with policy; identify high-risk use cases and notify the DTA; apply lifecycle-based technical assurance (testing for safety, robustness, conformance and unintended consequences); adopt explainability, contestability and human-centred design where relevant; protect privacy and data; and ensure cyber and model security measures. "Evolve and integrate" requires continuous improvement: agencies should adopt technical standards and the AI assurance framework, maintain documentation and records for auditability and reproducibility, apply version control and watermarking where appropriate, and participate in cross-government pilots to refine assurance practices. The policy explicitly excludes the Defence portfolio and the national intelligence community from mandatory application but encourages voluntary adoption where national security is not compromised.

Implementation Framework

Implementation is driven by mandatory deadlines and supported by operational guidance. Agencies must: designate accountable official(s) within 90 days (deadline: 30 November 2024) and publish AI transparency statements within six months (deadline: 28 February 2025). The DTA provides templates, a technical standard for lifecycle statements, a risk matrix (Attachment B in the policy) and a pilot AI assurance framework designed to be adapted to agency contexts. Agencies are expected to integrate AI checks into procurement and project governance, incorporate AI risk assessments in project scoping, and adopt lifecycle practices (pre‑work, design, train, evaluate, deploy, monitor, decommission) set out in the technical standard. Complementary activities include staff training, internal AI registers, and internal assurance or audit processes tailored to the agency’s risk profile.

Monitoring and Evaluation

Monitoring and evaluation are a central feature: agencies must monitor deployed AI systems for performance, reliability, safety and unintended consequences, and must keep transparency statements updated at least annually or sooner if material changes occur. The DTA runs a pilot AI assurance framework to help agencies operationalise monitoring, and the ANAO has signalled its intent to incorporate AI governance and assurance into its audit programs, providing parliamentary-level oversight. Agencies are expected to report new high-risk use cases to the DTA to allow whole-of-government visibility and development of further mitigation approaches. Internal mechanisms should include incident reporting, ongoing testing, metrics for performance and harm, and documented remediation pathways.

Penalties, Liability, and Appeals

The policy itself is an administrative, mandatory instrument for NCEs and does not create new criminal sanctions; compliance is enforced through existing governance and accountability mechanisms (agency internal controls, performance reporting, administrative action). Consequences for non-compliance may include administrative remediation, direction by responsible ministers or secretaries, negative findings in ANAO audits, reputational and parliamentary scrutiny, and referral to other regulators where statutory obligations (for example under the Privacy Act 1988) are breached. Privacy breaches and FOI obligations remain subject to the OAIC and FOI regime; agencies retain statutory liabilities under existing laws. The policy emphasises accountability and transparency to enable contestability and redress rather than prescriptive criminal penalties.

Relationship to Other Instruments

The policy is designed to complement and strengthen existing frameworks and should be read with the National framework for the assurance of artificial intelligence in government, the Technical standard for government’s use of artificial intelligence, the APS Code of Conduct, the Privacy Act 1988 and protective security policy. It aligns with ARM (assurance, risk, monitoring) activities and procurement rules coordinated by the Department of Finance and DTA's digital procurement instruments. The instrument references international standards (OECD definition of AI) and anticipates interoperability with proposed national mandatory guardrails and voluntary industry safety standards published elsewhere in the Australian Government ecosystem.

International Alignment

The policy intentionally aligns with international thinking and standards: it adopts the OECD AI system definition and references international regulatory developments that prioritise preventative, risk-based guardrails. The Australian Government’s approach positions government practice to be interoperable with international instruments and initiatives (for example OECD, G7/OECD discussions and other comparable national AI frameworks). The DTA and other agencies (DISR, OAIC) are engaged in international fora to help ensure the Australian approach remains compatible with global best practice while reflecting domestic legal and constitutional obligations.

Implementation Timeline

EventDate
Policy published (DTA announcement)2024-08-15 to 2024-08-16
Policy effective date2024-09-01
Designate accountable official(s) (90 days)2024-11-30
Publish AI transparency statement (6 months)2025-02-28
Annual review/update of transparency statements (ongoing)Annually or sooner as material changes occur

Sources and References

SourceType
Policy for the responsible use of AI in government (Version 1.1) — DTA (PDF)Primary Source
Policy for the responsible use of AI in government — DTA (web)Primary Source
Standard for accountable officials — DTAPrimary Source
Standard for AI transparency statements — DTAPrimary Source
ANAO — Governance of Artificial Intelligence at the Australian Taxation Office (Audit Report)Primary Source

Requirements for a company

What an organisation has to do under Australia - Responsible AI Use Policy, at a glance. Not legal advice — the table below gives the provision and deadline for each item.

Must do

12
  • Designate accountable official(s) responsible for implementing the AI policy.All non-corporate Commonwealth entities
  • Publish public AI transparency statements describing purpose, risks, and monitoring.All non-corporate Commonwealth entities
  • Notify the DTA of any identified high-risk AI use cases.Non-corporate Commonwealth entities using AI
  • Adopt a risk-based, transparent, and accountable approach to AI use.All non-corporate Commonwealth entities
  • Monitor deployed AI systems for performance, reliability, safety, and unintended consequences.Non-corporate Commonwealth entities deploying AI systems
  • Update AI transparency statements at least annually or sooner if material changes occur.Non-corporate Commonwealth entities publishing AI transparency statements
  • +6 more in the table below

Must not do

0

Nothing in this category.

Should do

1
  • Implement staff training on AI fundamentals for all relevant personnel.Non-corporate Commonwealth entities

Should not do

0

Nothing in this category.

Who must do what

The obligations under Australia - Responsible AI Use Policy, most serious first. Not legal advice — verify against the official text before relying on it.

#WhoRequirementBy whenWhereSeverity
1All non-corporate Commonwealth entitiesDesignate accountable official(s) responsible for implementing the AI policy.
Agencies must: designate accountable official(s) within 90 days (deadline: 30 November 2024)
Nov 30, 2024Critical
2All non-corporate Commonwealth entitiesPublish public AI transparency statements describing purpose, risks, and monitoring.
Agencies must: ... publish AI transparency statements within six months (deadline: 28 February 2025).
Feb 28, 2025Critical
3Non-corporate Commonwealth entities using AINotify the DTA of any identified high-risk AI use cases.
requires agencies to notify the DTA where such cases are identified.
Critical
4All non-corporate Commonwealth entitiesAdopt a risk-based, transparent, and accountable approach to AI use.
baseline mandatory expectations for all non-corporate Commonwealth entities to adopt a risk-based, transparent and accountable approach to AI
Sep 1, 2024Critical
5Non-corporate Commonwealth entities deploying AI systemsMonitor deployed AI systems for performance, reliability, safety, and unintended consequences.
agencies must monitor deployed AI systems for performance, reliability, safety and unintended consequences
Critical
6Non-corporate Commonwealth entities publishing AI transparency statementsUpdate AI transparency statements at least annually or sooner if material changes occur.
must keep transparency statements updated at least annually or sooner if material changes occur.
Annually or sooner as material changes occurCritical
7Non-corporate Commonwealth entities using AIEstablish internal governance and define operational models for AI.
agencies must establish internal governance, define operational models, integrate AI considerations into procurement
Important
8Non-corporate Commonwealth entities using AIIntegrate AI considerations into existing procurement and data governance frameworks.
integrate AI considerations into procurement and data governance
Important
9Non-corporate Commonwealth entities deploying AI systemsApply lifecycle-based technical assurance, including testing for safety and robustness.
agencies must ... apply lifecycle-based technical assurance (testing for safety, robustness, conformance and unintended consequences)
Important
10Non-corporate Commonwealth entities deploying AI systemsProtect privacy and data when using AI systems.
agencies must ... protect privacy and data; and ensure cyber and model security measures.
Important
11Non-corporate Commonwealth entities deploying AI systemsEnsure robust cyber and model security measures for AI systems.
agencies must ... ensure cyber and model security measures.
Important
12Non-corporate Commonwealth entities using AIMaintain documentation and records for AI systems to ensure auditability and reproducibility.
agencies should ... maintain documentation and records for auditability and reproducibility
Important
13Non-corporate Commonwealth entitiesImplement staff training on AI fundamentals for all relevant personnel.
implement staff training (AI fundamentals for all staff within six months is strongly recommended).
Feb 28, 2025Recommended

© Regulations.AI · updated on 13-Jun-2026