Australia AI Regulation Overview

Australia AI Regulation Overview

Australia

RAI-AU-NA-SUMMARY-2026
Governance and OversightRisk ManagementTransparency and Disclosure
Export PDF

Tracked instruments in Australia

15 instruments tracked — 8 In Force, 2 Draft, 1 Under Review, 1 Withdrawn, 1 Superseded, 1 Repealed, 1 Adopted. Built directly from our records, so — unlike the article below — it cannot go stale.

InstrumentTypeStatusYearEffective
Australia's National AI Standards FrameworkPolicyIn Force202615 Jul 2026
Australia - AI Policy UpdatePolicyIn Force202515 Dec 2025
Australia - AI Regulation Inquiry Report (No. 111)PolicyUnder Review202519 Dec 2025
Australia - National AI Strategy (2025)PolicyIn Force20252 Dec 2025
Australia - AI Assurance Framework (2024)GuidelineIn Force202421 Jun 2024
Australia - AI Governance Interim ResponsePolicyDraft202417 Jan 2024
Australia - AI Governance StandardStandardIn Force20241 Sep 2024
Australia - AI Guardrails in High-Risk SettingsPolicyWithdrawn20245 Sep 2024
Australia - AI Safety StandardGuidelineSuperseded20245 Sep 2024
Australia - AI Transparency Standard (RAI-AU-NA-AITRSTX-2024)StandardIn Force20241 Sep 2024
Australia - Responsible AI Use PolicyPolicyIn Force20241 Sep 2024
Australia - AI Regulation Discussion PaperPolicyDraft20231 Jun 2023
Australia - National AI Action PlanPolicyRepealed202118 Jun 2021
Australia - National AI CentrePolicyIn Force202114 Dec 2021
Australia - AI Ethics Framework (2019)GuidelineAdopted20197 Nov 2019

Australia regulates AI using technology-neutral sectoral laws, mandatory public sector standards issued by the DTA, and national policy initiatives coordinated by the Office of AI and DISR.

Full article

Overview

Australia’s governance of artificial intelligence combines whole-of-economy policy strategies, public sector administrative mandates, and reliance on existing technology-neutral legal frameworks. Initial federal policy took shape through non-binding national frameworks, notably Australia’s AI Ethics Principles (2019) and the National AI Action Plan (2021), which established the National Artificial Intelligence Centre (NAIC). These early initiatives prioritised industry capability, voluntary guidance, and ethical standards to build public trust and foster economic adoption across small and medium-sized enterprises (SMEs).

As AI deployment accelerated, the federal regulatory architecture evolved into a multi-tiered governance framework. In the public sector, the Digital Transformation Agency (DTA) introduced binding administrative directives for non-corporate Commonwealth entities through the Policy for the Responsible Use of AI in Government (v1.1 in 2024; updated to v2.0 in December 2025). Broad economy-wide strategy was formalized in the Australia National AI Plan 2025, published by the Department of Industry, Science and Resources (DISR). In July 2026, Prime Minister Anthony Albanese announced the 'AI in Australia's Interests' framework, establishing an Office of AI within the Department of the Prime Minister and Cabinet (PM&C) to drive mandatory 'Australian Standards for AI' and introduce enabling legislation to Parliament.

Regulatory Approach

Australia follows a risk-based, technology-neutral, and sectoral approach to AI regulation across the private economy, paired with prescriptive soft-law directives for government agencies. Rather than enacting a immediate, cross-cutting statutory AI Act for the entire economy, the Australian Government primary relies on existing statutory regulators—such as the Office of the Australian Information Commissioner (OAIC) for privacy, the Australian Competition and Consumer Commission (ACCC) for consumer rights, the eSafety Commissioner for online harm, and the Therapeutic Goods Administration (TGA) for health software—to apply established legal frameworks to AI systems.

While the federal government consulted on standalone mandatory guardrails for high-risk AI contexts in a 2024 Proposals Paper, the National AI Plan 2025 superseded that proposal, opting instead to adapt technology-neutral laws and address specific regulatory gaps where necessary. Conversely, regulatory obligations within the Commonwealth public sector are strict and mandatory: non-corporate Commonwealth entities must designate Accountable Officials, complete mandatory AI use-case impact assessments using the DTA AI Impact Assessment Tool, maintain internal registers, enforce procurement due diligence, and publish annual public AI transparency statements.

Key AI Legislation

  • AI in Australia's Interests (2026): Framework announced in July 2026 establishing the Office of AI within PM&C to accelerate mandatory Australian Standards for AI, set regulatory expectations for large AI data centres, and enforce copyright protections for Australian artists and media, with enabling legislation planned for early 2027.
  • Australia National AI Plan 2025: Whole-of-economy policy published by DISR structured around capturing economic opportunity, spreading social benefits, and ensuring citizen safety using existing sectoral laws and specialized technical bodies like the AI Safety Institute (AISI).
  • Policy for the Responsible Use of AI in Government (v2.0, 2025 / v1.1, 2024): DTA policy imposing mandatory governance, risk management, and transparency requirements on non-corporate Commonwealth entities.
  • Standard for Accountable Officials (v1.1, 2024): DTA standard requiring government agencies to designate Accountable Officials responsible for agency-level AI policy implementation and high-risk use-case notification.
  • Standard for AI Transparency Statements (v1.1, 2024): Mandatory DTA instrument directing federal agencies to publish accessible, plain-language public statements detailing their adoption and governance of AI systems.
  • National Framework for the Assurance of Artificial Intelligence in Government (v1.0, 2024): Inter-governmental guideline adopted by Data and Digital Ministers establishing five cornerstones (governance, data governance, standards, procurement, risk-based approach) across federal, state, and territory jurisdictions.
  • Australia’s AI Ethics Principles (2019): Eight voluntary principles (wellbeing, human values, fairness, privacy/security, reliability/safety, transparency/explainability, contestability, accountability) serving as the baseline for national guidelines and standards.

Governance & Enforcement Bodies

Institutional oversight of AI in Australia is distributed across several central policy bodies, specialized technical institutes, and existing statutory portfolio regulators. Strategic policy oversight resides within the Department of the Prime Minister and Cabinet (PM&C) via the Office of AI (established July 2026), which leads national implementation of mandatory Australian Standards for AI. The Department of Industry, Science and Resources (DISR) acts as the lead steward for broader economy-wide strategy, overseeing the National Artificial Intelligence Centre (NAIC)—which moved from CSIRO Data61 to DISR in July 2024 to support business adoption—and the Australian Artificial Intelligence Safety Institute (AISI), an independent technical body tasked with testing, evaluating, and monitoring advanced AI capabilities and harms.

Public sector adoption is governed by the Digital Transformation Agency (DTA) alongside the Department of Finance and the Australian Public Service Commission (APSC). The DTA issues binding technical standards, updates procurement guidance, maintains the AI Impact Assessment Tool, and receives high-risk notifications. Enforcing statutory obligations remains the mandate of sectoral regulators coordinated through mechanisms like the Digital Platform Regulators Forum, including the OAIC, ACCC, ACMA, eSafety Commissioner, and TGA.

Penalties & Enforcement

Australia's primary federal AI policy documents—including the National AI Plan 2025, the Policy for the Responsible Use of AI in Government, and the 'AI in Australia's Interests' framework—do not themselves create novel standalone statutory criminal offences or civil monetary penalties. Instead, compliance monitoring and enforcement rely on sanctions embedded within existing legislation enforced by established portfolio regulators, such as civil penalties under the Privacy Act 1988 administered by the OAIC or consumer law enforcement by the ACCC.

Within the Commonwealth public sector, adherence to mandatory DTA standards is enforced through administrative governance, public reporting accountability, procurement eligibility restrictions, and internal audit oversight. Public sector AI deployment is subject to parliamentary scrutiny and independent review by the Australian National Audit Office (ANAO). Non-compliance with government AI policy triggers internal administrative escalation, risk review by the AI Review Committee for higher-risk use cases, and public oversight via required transparency disclosures.

Data Protection Framework

Data privacy in Australia is regulated primarily by the Privacy Act 1988 and the Australian Privacy Principles (APPs), enforced by the Office of the Australian Information Commissioner (OAIC). Applicable across federal agencies and private entities with annual turnover exceeding AUD 3 million, the Privacy Act governs the collection, storage, security, and processing of personal information, extending to training data and automated outputs generated by AI models. The OAIC issues targeted guidance applying APP obligations to AI development and deployment.

Policy developments continually evaluate data protection mechanisms in relation to AI. The Productivity Commission's 2025 final inquiry report ('Harnessing data and digital technology') recommended transitioning toward an outcomes-based privacy compliance pathway to reduce regulatory burden while maintaining protections, alongside rightsizing the Consumer Data Right (CDR) framework. Furthermore, national AI plans explicitly incorporate First Nations data governance standards, emphasizing Indigenous data sovereignty when handling First Nations cultural data.

Sector-Specific Rules

Sector-specific AI regulation in Australia relies on adapting domain-specific statutory frameworks. In healthcare and medical technology, AI applications, diagnostic software, and medical device algorithms fall under the oversight of the Therapeutic Goods Administration (TGA) and the Department of Health. The National AI Plan 2025 identifies healthcare, medical device software, automated decision-making in welfare services, biometric surveillance, and online safety as high-impact settings requiring targeted legal updates and heightened risk management.

In the Commonwealth public sector, automated decision-making and generative AI deployment are strictly regulated by DTA policies. Non-corporate Commonwealth entities are subject to mandatory use-case impact assessments, Chief AI Officer appointments under the APS AI Plan, and secure GovAI platform protocols. Regarding physical infrastructure, the 2026 'AI in Australia's Interests' policy imposes specific regulatory expectations on 'Large AI Data Centres', requiring developers to underwrite their own power supply, pay full grid connection costs, contribute to grid stability during stress, adhere to water efficiency standards, and consult local communities on site location. The supplied corpus holds no detailed record of sector-specific rules for autonomous vehicles or employment AI.

International Alignment

Australia deliberately aligns its national AI standards, guidance, and safety evaluation procedures with international governance frameworks. Australia's AI Ethics Principles and the Voluntary AI Safety Standard (VAISS) are explicitly crosswalked with international benchmarks, including the OECD AI Principles, the international AI management system standard (AS ISO/IEC 42001), and the United States NIST AI Risk Management Framework (AI RMF 1.0).

Additionally, Australia actively participates in global safety testing networks and multilateral initiatives. The Australian Artificial Intelligence Safety Institute (AISI) was established to collaborate with international safety institutes and support commitments under global forums such as the Bletchley Declaration and Seoul outcomes. Federal policy inquiries, including those conducted by DISR and the Productivity Commission, continuously monitor international regulatory developments—such as the European Union AI Act, Canadian legislative approaches, and overseas legal developments regarding copyright and training data—to maintain regulatory interoperability and facilitate cross-border digital trade.

Future Developments

The primary upcoming legislative development is the anticipated introduction of enabling legislation to the Australian Parliament early in 2027 to enact mandatory 'Australian Standards for AI', as announced under the 2026 'AI in Australia's Interests' framework. This legislation follows National Cabinet considerations in August 2026 involving state Premiers and Chief Ministers to ensure harmonised federal-state adoption.

In copyright and intellectual property, the Australian Government has adopted a three-year monitoring approach recommended by the Productivity Commission in December 2025. Rather than immediately amending the Copyright Act 1968 (Cth) or introducing text and data mining (TDM) exceptions, the government is observing licensing market developments for open web material, impacts on creator incomes, and international jurisprudence through the Copyright and Artificial Intelligence Reference Group (CAIRG). Further public sector oversight will expand through the operationalization of the DTA's central standing AI Review Committee for high-risk public sector use cases.

Enforcement Bodies

AgencyMandateKey PowersWebsite
Office of AI (Department of the Prime Minister and Cabinet)Central executive body established in July 2026 to accelerate national implementation of mandatory Australian Standards for AI across government and industry.Direct executive oversight, policy coordination, and legislative framework development for national AI standards.
Department of Industry, Science and Resources (DISR)Lead federal department responsible for whole-of-economy AI strategy, industry scaling, research investment, and national AI plans.Policy formulation, grant program administration, international engagement, and departmental stewardship over NAIC and AISI.https://www.industry.gov.au/publications/national-ai-plan
Digital Transformation Agency (DTA)Central Commonwealth agency coordinating public sector digital strategy, AI policy implementation, procurement frameworks, and technical standards.Issues binding administrative policies for non-corporate Commonwealth entities, sets AI transparency standards, and mandates AI use-case impact assessments.https://www.digital.gov.au
Australian Artificial Intelligence Safety Institute (AISI)Independent technical body established to monitor, test, and analyze advanced AI capabilities, risks, harms, and emerging technical trends.Conducts safety testing, technical vulnerability assessments, and provides risk intelligence to portfolio regulators and government ministers.
National Artificial Intelligence Centre (NAIC)National hub established to support industry AI adoption, build business capability, and promote responsible AI practices (moved to DISR in July 2024).Publishes guidance frameworks, operates the AI Adoption Tracker, manages the Responsible AI Index, and coordinates AI Adopt Centres for SMEs.
Office of the Australian Information Commissioner (OAIC)Independent statutory regulator enforcing national privacy, data protection, and information freedom laws.Investigates privacy breaches, enforces the Privacy Act 1988, issues regulatory guidance on AI data handling, and applies statutory civil remedies.
Productivity CommissionThe Australian Government's independent research and advisory body on economic, statutory, and social policy issues.Conducts public inquiries (e.g., Inquiry Report No. 111) and provides formal policy recommendations to the Australian Government.https://www.pc.gov.au/inquiries/current/data-digital/report

Real enforcement actions

6 entries recorded · ~€344K in fines

Public enforcement actions where regulators cited Australia AI Regulation Overview. Helps you see how the law is actually applied in practice.

  1. FineSep 26, 2025

    eSafety Commissioner / Federal Court of Australia vs Anthony Rotondo

    344K
    Fine

    The Federal Court ordered Anthony Rotondo to pay a civil penalty of AUD 343,500 in eSafety Commissioner proceedings for posting non-consensual sexually explicit AI deepfake images of six prominent Australian women.

    Source ↗
  2. Enforcement orderSep 18, 2025

    Office of the Australian Information Commissioner (OAIC) vs Kmart Australia Limited

    The Privacy Commissioner found Kmart's use of facial recognition to tackle refund fraud across 28 stores (2020-2022) unlawful, collecting sensitive biometric data without consent, and ordered Kmart to cease, apologise, and delete the biometric data.

    Source ↗
  3. Enforcement orderNov 19, 2024

    Office of the Australian Information Commissioner (OAIC) vs Bunnings Group Limited

    The Privacy Commissioner found Bunnings breached the Privacy Act by capturing the faces of hundreds of thousands of customers via facial-recognition CCTV across 63 stores without consent, and ordered it to cease the practice.

    Source ↗
  4. Enforcement orderDec 16, 2021

    Office of the Australian Information Commissioner (OAIC) vs Australian Federal Police (AFP)

    The Commissioner determined the AFP breached the APP Code by trialling Clearview AI's facial recognition without a privacy impact assessment, and ordered it to engage an independent assessor and undertake privacy training.

    Source ↗
  5. Enforcement orderNov 3, 2021

    Office of the Australian Information Commissioner (OAIC) vs Clearview AI, Inc.

    The Australian Information Commissioner determined Clearview AI breached the Privacy Act by covertly scraping Australians' facial images and biometric templates without consent, and ordered it to stop collecting such data and destroy all images and templates collected from Australia.

    Source ↗
  6. Enforcement orderOct 14, 2021

    Office of the Australian Information Commissioner (OAIC) vs 7-Eleven Stores Pty Ltd

    The Commissioner found 7-Eleven interfered with customers' privacy by collecting facial images and faceprints via in-store survey tablets without consent or adequate notice, and ordered it to destroy all faceprints collected.

    Source ↗

© Regulations.AI — created on 9 Jan 2026 using Gemini 3.6 Flash · updated on 12 Sep 2026