Australia - AI Regulation Discussion Paper

Safe and Responsible AI in Australia — Discussion Paper

Australia

RAI-AU-NA-SRAADXX-2023
Draft(Being written or scoped)
PolicyGovernance and OversightRisk Management
Export PDF

The Australian Government published the "Safe and Responsible AI in Australia" Discussion Paper on 1 June 2023 to begin a national consultation on AI governance. It sets out a risk-based approach, canvasses international models, and seeks views on options including voluntary measures, standards, labelling, transparency, and potential mandatory guardrails for high-risk AI.

Summary

The "Safe and Responsible AI in Australia" Discussion Paper (June 2023) was released by the Australian Government (Department of Industry, Science and Resources) to invite public and stakeholder input on regulating and governing artificial intelligence. The paper recognizes both the economic and societal opportunities from AI and the emerging risks—particularly from the rapid diffusion of generative models and foundation models—while noting existing protections embedded in Australia’s general regulatory frameworks (for example privacy, consumer protection and sectoral regulation). The discussion paper frames a risk-based approach to AI governance, exploring a spectrum of policy options from non-regulatory measures (codes, standards, voluntary labelling and watermarking, capability building and public education) to targeted regulatory interventions for higher-risk uses.

Key themes in the paper include transparency and explainability, documentation and accountability across the AI lifecycle, human oversight and rights protections, data stewardship and privacy, safety testing and post-deployment monitoring, and international alignment. The paper asks about how to define high-risk settings and whether existing laws are sufficient or whether new targeted obligations should be introduced for developers, deployers and distributors of AI systems. It highlights potential measures such as mandatory testing and evaluation (pre- and post-deployment), record-keeping and provenance requirements, incident reporting, labelling or watermarking of AI-generated content, and strengthened obligations where AI decisions materially affect rights, safety or economic outcomes for individuals.

The document situates Australia within the broader international policy landscape by comparing approaches from the EU, UK, US, Canada and selected Asia-Pacific jurisdictions, and seeks views on conformity assessment, certification, and the role of standards bodies. It also flags the roles of existing regulators—such as the Office of the Australian Information Commissioner (OAIC), the eSafety Commissioner and sector regulators (for financial services, health, transport, etc.)—in any future regulatory architecture, and considers institutional options including a stronger convening role for the National AI Centre.

While the paper itself does not impose binding obligations, it launched a consultation (closing 26 July 2023) and set the groundwork for the Government’s subsequent interim responses and policy development (including the 17 January 2024 interim response and later proposals on mandatory guardrails for high-risk AI). The Discussion Paper is thus an early, consultative policy instrument aimed at mapping options, collecting evidence from stakeholders across industry, civil society and academia, and guiding future legislative and non-legislative steps to ensure AI is deployed in Australia safely and responsibly.

Full article

Read full text ↗

Overview

The "Safe and Responsible AI in Australia" Discussion Paper, published 1 June 2023 by the Department of Industry, Science and Resources, opens a national consultation to assess whether existing Australian regulatory frameworks are sufficient for addressing the opportunities and risks of AI. The paper sets out a risk-based approach and an array of policy options ranging from voluntary measures to targeted mandatory obligations for AI used in high-risk settings. The Government coupled the release with the National Science and Technology Council’s Rapid Response Report on Generative AI. The paper and consultation were announced by the Minister for Industry and Science; see the Minister’s release at Safe and responsible AI (Ministerial media release) and the Department’s page at Supporting responsible AI: discussion paper. The consultation hub hosting the discussion document and submissions is available at the Department’s consultation hub.

Definitions

The Discussion Paper adopts broad working definitions to capture a range of systems often labelled "AI", including machine learning models, automated decision-making systems, and generative and foundation models (such as large language models and multimodal systems). It distinguishes between developers (those who create or train models), deployers (those who integrate models into products and services), and end-users. The paper frames "high-risk" as context-specific—based on potential for harm to safety, fundamental rights, economic wellbeing or the public interest—and asks consultees to propose concrete thresholds and criteria for risk categorization. These core definitions are intended to be adaptive, reflecting rapid technological change while linking to existing legal categories under Australia’s privacy, safety and consumer laws.

Governance and Institutional Framework

The paper explores institutional options for Australia’s AI governance landscape. It highlights the National AI Centre’s convening role and the potential need for cross-agency coordination between portfolio regulators including the Office of the Australian Information Commissioner (OAIC), the eSafety Commissioner, the Australian Competition and Consumer Commission (ACCC) and sector regulators (for example APRA and the Therapeutic Goods Administration). The paper considers whether an AI-specific regulator is required, or whether existing regulators should be empowered and resourced to address AI-related harms. It also contemplates advisory expert groups and multi-stakeholder mechanisms to maintain technical expertise and public legitimacy. Further details and the Department’s public resources are on the consultation site at Supporting responsible AI and contextual commentary is provided by the National Science and Technology Council’s rapid report at Rapid Response Information Report: Generative AI.

Key Focus Areas

The Discussion Paper identifies several priority policy areas: (1) Risk-based regulation and the definition of high-risk use-cases; (2) Transparency and documentation obligations (including model cards, data provenance and deployment disclosures); (3) Safety testing and assurance, requiring pre-deployment evaluation and ongoing monitoring; (4) Human oversight and ‘‘meaningful human control’’ where automated decisions materially affect people; (5) Privacy and data stewardship aligning with the Privacy Act and OAIC guidance; (6) Consumer protection, misinformation and labelling/watermarking of AI-generated content; (7) Conformity assessment and certification pathways, potentially leveraging standards bodies; and (8) Capability building—training, accreditation and public education. The paper solicits views on trade-offs between innovation and protective steps, and whether voluntary measures (codes, standards) can provide sufficient assurance in most settings or if targeted mandatory guardrails are required. Throughout, the paper emphasizes alignment with international developments—particularly the European Union’s AI Act discussions and other jurisdictional experiments in high-risk regulation—to avoid regulatory fragmentation and support trade and interoperability.

Implementation Framework

The paper suggests an implementation approach that starts with a mix of voluntary and regulatory measures: (a) issuing guidance and best practice frameworks; (b) encouraging voluntary labelling/watermarking schemes and a voluntary AI Safety Standard developed with industry; (c) piloting conformity assessment mechanisms and certification for high-consequence applications; (d) strengthening regulator capability (funding, technical expertise); and (e) establishing reporting channels for incidents and harms. It sets out possible legal mechanisms—amendments to existing laws, targeted new obligations, or a hybrid approach—asking stakeholders to comment on proportionality, enforceability and transitional arrangements. The Department’s consultation materials and submissions illustrate a wide range of stakeholder perspectives and suggested design features for any implementation roadmap (consultation hub).

Monitoring and Evaluation

The Discussion Paper stresses the necessity of robust monitoring and evaluation to keep regulatory measures current with technological change. Proposed monitoring tools include mandated incident reporting for high-risk systems, post-market surveillance, regular audits and transparency registers, and metrics to measure public trust and harm reduction. It envisions a feedback loop where data from monitoring informs iterative policy updates, standards development and regulator capacity building. The interim Government response later published (17 January 2024) signals movement toward testing voluntary standards and exploring mandatory guardrails in high-risk contexts; see the Government interim response at Action to help ensure AI is safe and responsible.

Penalties, Liability, and Appeals

As a discussion paper, there are no immediate penalties prescribed. However, the document canvasses enforcement options that could be applied if mandatory obligations are adopted: civil penalties, infringement notices, corrective orders, product recalls or bans, and possible criminal sanctions for egregious conduct. It discusses mechanisms for appeals and remedies, including administrative review and judicial processes, and the role of sectoral regulators in adjudicating breaches. Stakeholders were invited to comment on proportionality and on ensuring remedies are accessible to harmed individuals while avoiding undue burdens on innovators and SMEs.

Relationship to Other Instruments

The Discussion Paper situates potential AI measures within Australia’s existing regulatory framework: the Privacy Act 1988 and Australian Privacy Principles (OAIC), the Competition and Consumer Act (Australian Consumer Law) (ACCC), the Online Safety Act and eSafety Commissioner responsibilities, sectoral law such as the Therapeutic Goods Act (TGA) and financial services regulation (APRA/ASIC), and workplace and safety law. The paper asks how AI-specific obligations should interact with these instruments to avoid duplication, close enforcement gaps, and ensure consistent protections across sectors. For related rapid research, see the National Science and Technology Council materials at Generative AI Rapid Report.

International Alignment

The paper explicitly compares international regulatory experiments and emerging instruments, seeking to ensure Australia’s approach remains interoperable and aligned with major partners. It reviews the European Union’s AI Act proposals, UK approaches to safety and standards, US sectoral developments, Canada’s initiatives and Singapore’s AI Verify/certification models. The Discussion Paper solicited views on how Australia can shape multilateral standards, mutual recognition of conformity assessment, and cross-border incident cooperation to maintain market access while protecting Australians.

Implementation Timeline

MilestoneDate
Discussion Paper published2023-06-01
Consultation period (public submissions close)2023-07-26
Interim government response published2024-01-17
Proposals paper for mandatory guardrails published2024-09-05

Sources and References

SourceType
Safe and Responsible AI in Australia — Discussion Paper (Consultation hub)Primary Source
Ministerial media release (1 June 2023)Primary Source
Rapid Response Information Report: Generative AI (National Science & Technology Council)Primary Source

Requirements for a company

What an organisation has to do under Australia - AI Regulation Discussion Paper, at a glance. Not legal advice — the table below gives the provision and deadline for each item.

Not yet in force (Draft). These requirements apply once the instrument takes effect and may change before then.

Must do

6
  • Identify the risk level of your AI system based on potential for harm.Developers and deployers of AI systems.
  • Document the AI model's design, training data provenance, and intended uses.Developers and deployers of AI systems.
  • Implement pre-deployment safety testing and validation for your AI system.Developers and deployers of AI systems.
  • Establish processes for ongoing monitoring and incident reporting for your AI system.Deployers of AI systems.
  • Ensure your AI system aligns with privacy and data governance obligations.Developers and deployers of AI systems.
  • Ensure meaningful human control where automated decisions materially affect people.Deployers of AI systems.

Must not do

0

Nothing in this category.

Should do

2
  • Consider implementing voluntary labelling or watermarking for AI-generated content.Developers and deployers of generative AI systems.
  • Engage with and consider adopting a voluntary AI Safety Standard.Developers and deployers of AI systems.

Should not do

0

Nothing in this category.

Who must do what

The obligations under Australia - AI Regulation Discussion Paper, most serious first. Not legal advice — verify against the official text before relying on it.

#WhoRequirementBy whenWhereSeverity
1Developers and deployers of AI systems.Identify the risk level of your AI system based on potential for harm.
Identify whether your AI use is low-, medium- or high-risk
Before placing on marketImportant
2Developers and deployers of AI systems.Document the AI model's design, training data provenance, and intended uses.
Document model design, training data provenance and intended uses
Before placing on marketImportant
3Developers and deployers of AI systems.Implement pre-deployment safety testing and validation for your AI system.
Implement pre-deployment safety testing and validation
Before placing on marketImportant
4Deployers of AI systems.Establish processes for ongoing monitoring and incident reporting for your AI system.
Establish monitoring and incident reporting
Upon deploymentImportant
5Developers and deployers of AI systems.Ensure your AI system aligns with privacy and data governance obligations.
Ensure privacy and data governance alignment
Before placing on marketImportant
6Deployers of AI systems.Ensure meaningful human control where automated decisions materially affect people.
Human oversight and ‘‘meaningful human control’’ where automated decisions materially affect people
Before placing on marketImportant
7Developers and deployers of generative AI systems.Consider implementing voluntary labelling or watermarking for AI-generated content.
encouraging voluntary labelling/watermarking schemes
Recommended
8Developers and deployers of AI systems.Engage with and consider adopting a voluntary AI Safety Standard.
encouraging ... a voluntary AI Safety Standard developed with industry
Recommended

© Regulations.AI · updated on 13-Jun-2026