Australia - AI Safety Standard

Voluntary AI Safety Standard (VAISS)

Australia

RAI-AU-NA-VASVXXX-2024
Effective: September 5, 2024
In Force(In Force)
GuidelineGovernance and OversightRisk ManagementAccountability and Documentation
Export PDF

The Voluntary AI Safety Standard (VAISS) is an Australian government publication issued by the National Artificial Intelligence Centre (NAIC) providing 10 voluntary guardrails and practical guidance for organisations to develop, deploy and oversee AI systems safely. It emphasises a risk-based, human-centred approach aligned with international standards such as AS ISO/IEC 42001 and the NIST AI RMF and focuses on governance, risk management, testing, transparency, recordkeeping and stakeholder engagement.

Overview

The Voluntary AI Safety Standard (VAISS) is a practical, non‑binding framework published by the Australian Government’s National Artificial Intelligence Centre (NAIC) to help organisations in Australia design, procure, deploy and oversee AI systems safely. VAISS sets out 10 voluntary guardrails covering governance and accountability, risk management, data governance, testing and monitoring, human oversight, disclosure to users, processes for challenge and redress, supply‑chain transparency, recordkeeping, and stakeholder engagement. The standard is intended to be usable by organisations of any size and across sectors, with emphasis on AI deployers, while alignment with international instruments (for example the international AI management system standard AS ISO/IEC 42001:2023 and the United States' NIST AI RMF 1.0) is a design feature to promote interoperability and mutual recognition. The NAIC publishes the full standard and supporting materials, including an illustrated guide, case examples and downloadable resources on the Department site: Voluntary AI Safety Standard (NAIC).

Definitions

VAISS provides practical definitions to ensure consistent application of the guardrails. Key defined terms include: "AI system" (software-based tools that generate outputs such as predictions, content or recommendations), "AI model" (mathematical engine within AI systems), "AI deployer" (an entity that supplies or uses an AI system to provide a product or service), "developer" (an entity that designs, builds or trains an AI model), "risk" and "harm" (potential negative impacts to individuals, groups or societal structures), and "meaningful human oversight" (human control mechanisms proportionate to risk). The standard maps these definitions to existing legal concepts — for example linking privacy-related definitions to the Privacy Act and the Australian Privacy Principles as reflected in OAIC guidance: OAIC guidance on AI and privacy.

Governance and Institutional Framework

VAISS recommends that organisations establish and publish an accountability process that includes identifiable ownership (an AI owner or executive sponsor), an AI strategy aligned with organisational goals, and governance structures for compliance and oversight. The standard emphasises internal capability building (training for staff and board-level awareness), procurement controls to embed guardrails into supplier contracts, and cross-functional structures (legal, security, privacy, product, compliance and ethics) to manage AI risks. VAISS also positions NAIC and the Department of Industry, Science and Resources as central facilitators of voluntary adoption and guidance, while directing practitioners to coordinate with other Australian regulators (for example the Office of the Australian Information Commissioner for privacy matters: OAIC, and sectoral regulators such as the Australian Prudential Regulation Authority or health regulators where relevant). The standard situates itself as complementary to national standardisation efforts (notably AS ISO/IEC 42001) and crosswalks to international frameworks to reduce duplication and promote a coherent governance ecosystem.

Key Focus Areas

VAISS contains 10 guardrails which together form the operational heart of the standard. The guardrails require organisations to: 1) establish, implement and publish an accountability process (governance, capability, regulatory compliance strategy); 2) put in place a risk management process to identify and mitigate risks (including ongoing risk assessments and impact assessments); 3) protect AI systems and implement data governance measures for data quality and provenance; 4) test AI models and systems thoroughly before deployment and monitor performance post-deployment; 5) enable meaningful human control or intervention mechanisms proportionate to risk; 6) inform end-users when decisions, interactions or content are AI-enabled, with clear disclosure practices; 7) establish processes for people impacted by AI outcomes to challenge decisions and seek remedies; 8) be transparent across the AI supply chain about data, models and system components to facilitate risk management; 9) keep and maintain records (including an AI inventory and system documentation) to allow third-party assessment of compliance; and 10) actively engage stakeholders and evaluate impacts with a focus on safety, diversity, inclusion and fairness. Across these focus areas VAISS provides practical examples and checklists that organisations can adapt. The standard explicitly anticipates a tiered approach where controls are scaled to the severity and likelihood of harms, and it signals preparatory steps for future conformity assessment and potential mandatory guardrails in high-risk domains.

Implementation Framework

VAISS outlines an implementation path: (a) Governance set-up — appoint an AI owner, board reporting and policy baseline; (b) Risk scoping — use impact assessment tools (for example the NAIC AI Impact Navigator) to classify system risk; (c) Controls design — select data governance, testing and oversight controls proportionate to risk; (d) Procurement alignment — include contractual clauses and supplier evidence requirements to ensure supply-chain transparency; (e) Operationalisation — embed human oversight, monitoring dashboards and incident response; and (f) Documentation & records — maintain an AI inventory, testing logs and evidence to enable internal and third‑party review. Implementation guidance cross-references ISO management system practices and the NIST AI RMF to help organisations translate guardrails into auditable processes and metrics. The standard provides templates and worked examples to support smaller organisations to adopt scaled measures and to assist larger organisations to integrate AI governance into existing management systems.

Monitoring and Evaluation

VAISS requires continuous monitoring and evaluation of AI systems after deployment. Organisations should define acceptance criteria, performance metrics, and monitoring regimes to detect model drift, performance degradation, bias, safety incidents and security events. The standard recommends scheduled re-testing, logging of outputs and incidents, periodic re-assessment of risk and impact (including stakeholder feedback) and maintenance of records to demonstrate ongoing compliance with the guardrails. VAISS encourages organisations to publish summary results of monitoring where appropriate to build public trust and to support third-party conformity assessment processes that may be introduced in the future. The guidance also highlights the importance of incident response and escalation pathways that integrate with existing organisational risk, legal and cybersecurity processes.

Penalties, Liability, and Appeals

As a voluntary standard, VAISS does not itself create statutory penalties. However, the standard explains legal contexts in which non-compliance with guardrails may increase exposure to existing regulatory or civil liability — notably under privacy law (Privacy Act and APPs), consumer protection and anti-discrimination laws. Organisations that fail to adopt reasonable safeguards may face civil liability, regulatory enforcement by relevant agencies (for example OAIC or sector regulators), contractual remedies (procurement disqualification or indemnities) and reputational and commercial consequences. VAISS also recommends internal redress processes and external challenge mechanisms for impacted individuals, and advises organisations to maintain evidence and recordkeeping to support appeals, dispute resolution and legal defence where necessary.

Relationship to Other Instruments

VAISS is explicitly designed to sit alongside and complement existing Australian laws and international standards. The standard cross-references the Privacy Act, the Australian Consumer Law, sectoral regulation in healthcare and finance, existing cybersecurity frameworks (for example the Australian Cyber Security Centre Essential Eight) and management-system standards such as ISO/IEC 42001. VAISS also maps its guardrails to the government’s consultation on mandatory guardrails for high-risk AI settings and to procurement requirements that may incorporate the guardrails as an element of supplier assessment. The standard provides a crosswalk to the NIST AI RMF and indicates alignment with other international guidance to reduce friction for multinational operators and supply chains.

International Alignment

International alignment is an explicit goal of VAISS. The NAIC designed the standard to be consistent with international instruments: the standard references the international AI management system standard AS ISO/IEC 42001, the NIST AI RMF, and other internationally recognised guidelines. This alignment helps organisations that operate across borders to apply similar governance and risk management approaches and supports the development of future cross-border conformity assessment and mutual recognition arrangements. VAISS also anticipates engagement with international partners to harmonise approaches to transparency, testing methodologies and supply-chain information exchange.

Implementation Timeline

EventDateNotes
PDF / initial draft dated2024-08-xxPDF metadata indicates August 2024 creation.
Online publication (department web page)2024-09-05Department of Industry, Science and Resources publication date.
NAIC reference / update note2024-10-xxNAIC references and resources updated through Oct 2024.
Ongoing consultation on mandatory guardrails2024-2025Government consultation process and proposals paper (ongoing).

Compliance Checklist

RequirementYes/NoEvidence
Appointed AI owner / governance body AI policy, board minutes
Risk & impact assessment completed Risk register, assessments
Data governance & provenance controls in place Data inventories, data lineage
Pre-deployment testing and acceptance criteria documented Test reports, acceptance logs
Human oversight & intervention mechanisms defined Operational playbooks, training records
User disclosure practices implemented Privacy notices, UI disclosures
Challenge/redress process available Complaint forms, escalation logs
Supply‑chain transparency measures adopted Supplier contracts, model provenance statements
Records & AI inventory maintained AI inventory, documentation repository
Stakeholder engagement documented Engagement logs, consultation summaries

Sources and References

SourceType
Voluntary AI Safety Standard — Department of Industry, Science and Resources (web page)Primary Source
Voluntary AI Safety Standard (PDF) — NAIC / Department of Industry, Science and ResourcesPrimary Source
OAIC guidance on privacy and AIPrimary Source
NIST AI Risk Management Framework (AI RMF 1.0)Primary Source
AS ISO/IEC 42001:2023 (Standards Australia)Primary Source
Plain English

Australia's Voluntary AI Safety Standard (VAISS) offers practical, non-binding guidance for organisations across all sectors to safely design, procure, deploy, and oversee Artificial Intelligence systems. Published by the National Artificial Intelligence Centre (NAIC), it applies to any Australian entity developing, using, or managing AI, regardless of size.

Effective from September 5, 2024, VAISS outlines ten "guardrails" to promote responsible AI. Key among these are the requirements to: - Establish clear governance and accountability, including robust risk management processes to identify and mitigate potential harms. - Ensure thorough testing of AI models and systems before deployment, followed by continuous monitoring of their performance. - Provide meaningful human oversight and transparently disclose to users when they are interacting with or impacted by AI. - Set up accessible processes for individuals to challenge AI-driven decisions and seek redress.

While VAISS is voluntary and doesn't introduce new penalties, organisations should not mistake this for a lack of consequence. Failing to adopt these reasonable safeguards can significantly increase exposure to existing Australian laws, such as privacy, consumer protection, and anti-discrimination legislation. This means regulators like the Office of the Australian Information Commissioner (OAIC) or sector-specific bodies could still take action, leading to civil liability, contractual issues, and reputational damage. The standard also signals that these voluntary guardrails may become mandatory for high-risk AI applications in the future, making early adoption a strategic advantage. VAISS is designed to align with international frameworks like ISO/IEC 42001 and the NIST AI Risk Management Framework, promoting global interoperability.

Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.

What you must do — compliance checklist

0 / 12 marked complete

Plain-English obligations under Australia - AI Safety Standard. Not legal advice — verify against the official text before relying on it.

  1. #1ImportantKey Focus Areas

    Applies to: Organisations designing, procuring, deploying, or overseeing AI systems.

    establish, implement and publish an accountability process
  2. #2ImportantKey Focus Areas

    Applies to: Organisations designing, procuring, deploying, or overseeing AI systems.

    put in place a risk management process to identify and mitigate risks
  3. #3ImportantKey Focus Areas

    Applies to: Organisations designing, procuring, deploying, or overseeing AI systems.

    protect AI systems and implement data governance measures for data quality and provenance
  4. #4ImportantKey Focus AreasBefore placing on market

    Applies to: Organisations deploying AI systems.

    test AI models and systems thoroughly before deployment and monitor performance post-deployment
  5. #5ImportantKey Focus AreasBefore placing on market

    Applies to: Organisations deploying AI systems.

    enable meaningful human control or intervention mechanisms proportionate to risk
  6. #6ImportantKey Focus AreasBefore placing on market

    Applies to: Organisations deploying AI systems that interact with users.

    inform end-users when decisions, interactions or content are AI-enabled
  7. #7ImportantKey Focus Areas

    Applies to: Organisations deploying AI systems that impact individuals.

    establish processes for people impacted by AI outcomes to challenge decisions and seek remedies
  8. #8ImportantKey Focus Areas

    Applies to: Organisations procuring or deploying AI systems.

    be transparent across the AI supply chain about data, models and system components
  9. #9ImportantKey Focus Areas

    Applies to: Organisations designing, procuring, deploying, or overseeing AI systems.

    keep and maintain records (including an AI inventory and system documentation)
  10. #10ImportantKey Focus Areas

    Applies to: Organisations designing, procuring, deploying, or overseeing AI systems.

    actively engage stakeholders and evaluate impacts with a focus on safety, diversity, inclusion and fairness
  11. #11ImportantGovernance and Institutional Framework

    Applies to: Organisations procuring AI systems.

    procurement controls to embed guardrails into supplier contracts
  12. #12ImportantMonitoring and Evaluation

    Applies to: Organisations deploying AI systems.

    importance of incident response and escalation pathways

© Regulations.AI — created on 13-Jun-2026