Australia - Responsible AI Use Policy
Policy for the responsible use of AI in government
Australia
RAI-AU-NA-RUAGXXX-2024The Digital Transformation Agency’s "Policy for the responsible use of AI in government" (Version 1.1) took effect 1 September 2024. It mandates non-corporate Commonwealth entities to designate accountable official(s) and publish AI transparency statements, and encourages a risk-based, human-centred approach to government AI adoption aligned with existing legal frameworks.
Summary
The Policy for the responsible use of AI in government (Version 1.1), published by the Digital Transformation Agency (DTA) in August–September 2024, sets a whole-of-government baseline for how the Australian Government should adopt and govern artificial intelligence. The policy is mandatory for non-corporate Commonwealth entities (NCEs) and is designed to position the Australian Government as an exemplar in safe, ethical, and responsible AI use while remaining adaptive to technological and regulatory change. Key mandatory elements include the designation of accountable official(s) within 90 days of the policy taking effect, and publication of an AI transparency statement within six months. It also establishes implementation expectations across three high-level pillars: enable and prepare (build capability, integrate AI into existing governance frameworks, and define definitions/standards); engage responsibly (risk-based assessment, transparency, explainability, human-centred design, monitoring and evaluation); and evolve and integrate (ongoing review, integration with procurement, data governance and standards). The policy explicitly excludes the Defence portfolio and the national intelligence community from mandatory application, while encouraging corporate Commonwealth entities to voluntarily adopt its measures where feasible. Complementary documents and instruments referenced by the policy include the National framework for the assurance of artificial intelligence in government, the Technical standard for government’s use of artificial intelligence, the Standard for accountable officials, and the Standard for AI transparency statements. The DTA also provides guidance on staff training, an AI assurance pilot, a risk matrix, and a technical standard for lifecycle statements. Implementation deadlines included designation of accountable officials by 30 November 2024 and publication of transparency statements by 28 February 2025. The policy relies on a mix of administrative compliance, public transparency obligations, whole-of-government coordination through the DTA, and oversight via existing Commonwealth governance and audit mechanisms (for example, audit attention by the Australian National Audit Office (ANAO) and privacy oversight by the Office of the Australian Information Commissioner (OAIC)). While the policy establishes baseline mandatory organisational practices, it does not itself create novel criminal sanctions; rather it integrates with existing legal obligations and accountability mechanisms (public reporting, parliamentary oversight, departmental governance, audits, and regulator action under existing statutes). The policy emphasises a proportionate, risk-based approach: agencies are expected to identify and notify the DTA of new high-risk use cases and to apply technical assurance, testing and monitoring proportional to the risk profile of a use case. Overall, the policy functions as a foundational, government-internal regulatory instrument establishing minimum expectations for governance, transparency and assurance while the broader national regulatory environment for AI (including proposed mandatory guardrails and voluntary safety standards) continues to evolve.
Full article
Read full text ↗Overview
The Policy for the responsible use of AI in government (Version 1.1) was published by the Digital Transformation Agency and took effect on 1 September 2024. The policy sets baseline mandatory expectations for all non-corporate Commonwealth entities to adopt a risk-based, transparent and accountable approach to AI, with targeted mandatory measures such as the designation of accountable official(s) and publication of AI transparency statements. The DTA frames the policy around three pillars—enable and prepare, engage responsibly, and evolve and integrate—to unify practice across agencies and build public trust. For the official policy text and PDF see Digital Transformation Agency — AI in government policy and the full policy PDF at Policy for the responsible use of AI in government (Version 1.1). This policy interoperates with other whole-of-government instruments including the National framework for the assurance of artificial intelligence in government and the Technical standard for government’s use of artificial intelligence, forming a practical baseline for accountability and transparency while higher‑order statutory regulation of AI is developed.
Definitions
The policy adopts the OECD definition of an "AI system" for operational consistency: machine-based systems that, for explicit or implicit objectives, infer from inputs how to generate outputs (predictions, content, recommendations, decisions) that can influence physical or virtual environments. It distinguishes levels of autonomy and adaptiveness and recommends agencies keep definitions under review as the policy and broader regulatory environment evolve. The policy also defines "high-risk use case" as those government AI uses that could significantly affect people’s rights, safety, wellbeing, or essential government services and requires agencies to notify the DTA where such cases are identified. "Accountable official(s)" are defined as named individual(s) or chairs of bodies responsible for implementing the policy in an agency context, and must be designated within 90 days of the policy taking effect.
Governance and Institutional Framework
The DTA is the primary steward of the policy, responsible for whole-of-government coordination, implementation guidance and maintaining standards. Agencies must designate accountable official(s) to implement the policy and to act as the contact point for whole-of-government coordination; responsibilities include notifying the DTA of new high-risk use cases and participating in cross‑agency forums. The policy is mandatory for non-corporate Commonwealth entities under the Public Governance, Performance and Accountability Act 2013 (as implemented by the DTA) and complements existing obligations such as the APS Code of Conduct, privacy and protective security frameworks. Implementation is supported by companion instruments published by the DTA: the Standard for accountable officials, the Standard for AI transparency statements, the Technical standard for government’s use of artificial intelligence, a risk matrix, and training guidance. Parliamentary and audit oversight is expected to be undertaken by bodies such as the Australian National Audit Office (ANAO), while privacy compliance is monitored by the Office of the Australian Information Commissioner (OAIC).
Key Focus Areas
The policy organizes requirements and recommended practice across three pillars. "Enable and prepare" focuses on organisational capability building: agencies must establish internal governance, define operational models, integrate AI considerations into procurement and data governance, and implement staff training (AI fundamentals for all staff within six months is strongly recommended). "Engage responsibly" emphasises a proportionate, risk-based approach to deployment: agencies must publish public AI transparency statements (within six months) describing purpose, classification of AI use, risk mitigation, monitoring measures and compliance with policy; identify high-risk use cases and notify the DTA; apply lifecycle-based technical assurance (testing for safety, robustness, conformance and unintended consequences); adopt explainability, contestability and human-centred design where relevant; protect privacy and data; and ensure cyber and model security measures. "Evolve and integrate" requires continuous improvement: agencies should adopt technical standards and the AI assurance framework, maintain documentation and records for auditability and reproducibility, apply version control and watermarking where appropriate, and participate in cross-government pilots to refine assurance practices. The policy explicitly excludes the Defence portfolio and the national intelligence community from mandatory application but encourages voluntary adoption where national security is not compromised.
Implementation Framework
Implementation is driven by mandatory deadlines and supported by operational guidance. Agencies must: designate accountable official(s) within 90 days (deadline: 30 November 2024) and publish AI transparency statements within six months (deadline: 28 February 2025). The DTA provides templates, a technical standard for lifecycle statements, a risk matrix (Attachment B in the policy) and a pilot AI assurance framework designed to be adapted to agency contexts. Agencies are expected to integrate AI checks into procurement and project governance, incorporate AI risk assessments in project scoping, and adopt lifecycle practices (pre‑work, design, train, evaluate, deploy, monitor, decommission) set out in the technical standard. Complementary activities include staff training, internal AI registers, and internal assurance or audit processes tailored to the agency’s risk profile.
Monitoring and Evaluation
Monitoring and evaluation are a central feature: agencies must monitor deployed AI systems for performance, reliability, safety and unintended consequences, and must keep transparency statements updated at least annually or sooner if material changes occur. The DTA runs a pilot AI assurance framework to help agencies operationalise monitoring, and the ANAO has signalled its intent to incorporate AI governance and assurance into its audit programs, providing parliamentary-level oversight. Agencies are expected to report new high-risk use cases to the DTA to allow whole-of-government visibility and development of further mitigation approaches. Internal mechanisms should include incident reporting, ongoing testing, metrics for performance and harm, and documented remediation pathways.
Penalties, Liability, and Appeals
The policy itself is an administrative, mandatory instrument for NCEs and does not create new criminal sanctions; compliance is enforced through existing governance and accountability mechanisms (agency internal controls, performance reporting, administrative action). Consequences for non-compliance may include administrative remediation, direction by responsible ministers or secretaries, negative findings in ANAO audits, reputational and parliamentary scrutiny, and referral to other regulators where statutory obligations (for example under the Privacy Act 1988) are breached. Privacy breaches and FOI obligations remain subject to the OAIC and FOI regime; agencies retain statutory liabilities under existing laws. The policy emphasises accountability and transparency to enable contestability and redress rather than prescriptive criminal penalties.
Relationship to Other Instruments
The policy is designed to complement and strengthen existing frameworks and should be read with the National framework for the assurance of artificial intelligence in government, the Technical standard for government’s use of artificial intelligence, the APS Code of Conduct, the Privacy Act 1988 and protective security policy. It aligns with ARM (assurance, risk, monitoring) activities and procurement rules coordinated by the Department of Finance and DTA's digital procurement instruments. The instrument references international standards (OECD definition of AI) and anticipates interoperability with proposed national mandatory guardrails and voluntary industry safety standards published elsewhere in the Australian Government ecosystem.
International Alignment
The policy intentionally aligns with international thinking and standards: it adopts the OECD AI system definition and references international regulatory developments that prioritise preventative, risk-based guardrails. The Australian Government’s approach positions government practice to be interoperable with international instruments and initiatives (for example OECD, G7/OECD discussions and other comparable national AI frameworks). The DTA and other agencies (DISR, OAIC) are engaged in international fora to help ensure the Australian approach remains compatible with global best practice while reflecting domestic legal and constitutional obligations.
Implementation Timeline
| Event | Date |
|---|---|
| Policy published (DTA announcement) | 2024-08-15 to 2024-08-16 |
| Policy effective date | 2024-09-01 |
| Designate accountable official(s) (90 days) | 2024-11-30 |
| Publish AI transparency statement (6 months) | 2025-02-28 |
| Annual review/update of transparency statements (ongoing) | Annually or sooner as material changes occur |
Sources and References
| Source | Type |
|---|---|
| Policy for the responsible use of AI in government (Version 1.1) — DTA (PDF) | Primary Source |
| Policy for the responsible use of AI in government — DTA (web) | Primary Source |
| Standard for accountable officials — DTA | Primary Source |
| Standard for AI transparency statements — DTA | Primary Source |
| ANAO — Governance of Artificial Intelligence at the Australian Taxation Office (Audit Report) | Primary Source |
Requirements for a company
What an organisation has to do under Australia - Responsible AI Use Policy, at a glance. Not legal advice — the table below gives the provision and deadline for each item.
Must do
12- Designate accountable official(s) responsible for implementing the AI policy.All non-corporate Commonwealth entities
- Publish public AI transparency statements describing purpose, risks, and monitoring.All non-corporate Commonwealth entities
- Notify the DTA of any identified high-risk AI use cases.Non-corporate Commonwealth entities using AI
- Adopt a risk-based, transparent, and accountable approach to AI use.All non-corporate Commonwealth entities
- Monitor deployed AI systems for performance, reliability, safety, and unintended consequences.Non-corporate Commonwealth entities deploying AI systems
- Update AI transparency statements at least annually or sooner if material changes occur.Non-corporate Commonwealth entities publishing AI transparency statements
- +6 more in the table below
Must not do
0Nothing in this category.
Should do
1- Implement staff training on AI fundamentals for all relevant personnel.Non-corporate Commonwealth entities
Should not do
0Nothing in this category.
Who must do what
The obligations under Australia - Responsible AI Use Policy, most serious first. Not legal advice — verify against the official text before relying on it.
| # | Who | Requirement | By when | Where | Severity |
|---|---|---|---|---|---|
| 1 | All non-corporate Commonwealth entities | Designate accountable official(s) responsible for implementing the AI policy. “Agencies must: designate accountable official(s) within 90 days (deadline: 30 November 2024)” | Nov 30, 2024 | — | Critical |
| 2 | All non-corporate Commonwealth entities | Publish public AI transparency statements describing purpose, risks, and monitoring. “Agencies must: ... publish AI transparency statements within six months (deadline: 28 February 2025).” | Feb 28, 2025 | — | Critical |
| 3 | Non-corporate Commonwealth entities using AI | Notify the DTA of any identified high-risk AI use cases. “requires agencies to notify the DTA where such cases are identified.” | — | — | Critical |
| 4 | All non-corporate Commonwealth entities | Adopt a risk-based, transparent, and accountable approach to AI use. “baseline mandatory expectations for all non-corporate Commonwealth entities to adopt a risk-based, transparent and accountable approach to AI” | Sep 1, 2024 | — | Critical |
| 5 | Non-corporate Commonwealth entities deploying AI systems | Monitor deployed AI systems for performance, reliability, safety, and unintended consequences. “agencies must monitor deployed AI systems for performance, reliability, safety and unintended consequences” | — | — | Critical |
| 6 | Non-corporate Commonwealth entities publishing AI transparency statements | Update AI transparency statements at least annually or sooner if material changes occur. “must keep transparency statements updated at least annually or sooner if material changes occur.” | Annually or sooner as material changes occur | — | Critical |
| 7 | Non-corporate Commonwealth entities using AI | Establish internal governance and define operational models for AI. “agencies must establish internal governance, define operational models, integrate AI considerations into procurement” | — | — | Important |
| 8 | Non-corporate Commonwealth entities using AI | Integrate AI considerations into existing procurement and data governance frameworks. “integrate AI considerations into procurement and data governance” | — | — | Important |
| 9 | Non-corporate Commonwealth entities deploying AI systems | Apply lifecycle-based technical assurance, including testing for safety and robustness. “agencies must ... apply lifecycle-based technical assurance (testing for safety, robustness, conformance and unintended consequences)” | — | — | Important |
| 10 | Non-corporate Commonwealth entities deploying AI systems | Protect privacy and data when using AI systems. “agencies must ... protect privacy and data; and ensure cyber and model security measures.” | — | — | Important |
| 11 | Non-corporate Commonwealth entities deploying AI systems | Ensure robust cyber and model security measures for AI systems. “agencies must ... ensure cyber and model security measures.” | — | — | Important |
| 12 | Non-corporate Commonwealth entities using AI | Maintain documentation and records for AI systems to ensure auditability and reproducibility. “agencies should ... maintain documentation and records for auditability and reproducibility” | — | — | Important |
| 13 | Non-corporate Commonwealth entities | Implement staff training on AI fundamentals for all relevant personnel. “implement staff training (AI fundamentals for all staff within six months is strongly recommended).” | Feb 28, 2025 | — | Recommended |
Related Regulations
Standard for AI transparency statements
Australia96% similar
DTA AI Policy Update - Impact Assessment Tool and Procurement Guidance
Australia96% similar
Standard for accountable officials (Policy for responsible use of AI in government)
Australia95% similar
National Framework for the Assurance of Artificial Intelligence in Government
Australia95% similar
Safe and Responsible AI in Australia — Discussion Paper
Australia95% similar
© Regulations.AI · updated on 13-Jun-2026