Australia - AI Safety Standard
Voluntary AI Safety Standard (VAISS)
Australia
RAI-AU-NA-VASVXXX-2024The Voluntary AI Safety Standard (VAISS) is an Australian government publication issued by the National Artificial Intelligence Centre (NAIC) providing 10 voluntary guardrails and practical guidance for organisations to develop, deploy and oversee AI systems safely. It emphasises a risk-based, human-centred approach aligned with international standards such as AS ISO/IEC 42001 and the NIST AI RMF and focuses on governance, risk management, testing, transparency, recordkeeping and stakeholder engagement.
Summary
Read full text ↗Plain English
Overview
The Voluntary AI Safety Standard (VAISS) is a practical, non‑binding framework published by the Australian Government’s National Artificial Intelligence Centre (NAIC) to help organisations in Australia design, procure, deploy and oversee AI systems safely. VAISS sets out 10 voluntary guardrails covering governance and accountability, risk management, data governance, testing and monitoring, human oversight, disclosure to users, processes for challenge and redress, supply‑chain transparency, recordkeeping, and stakeholder engagement. The standard is intended to be usable by organisations of any size and across sectors, with emphasis on AI deployers, while alignment with international instruments (for example the international AI management system standard AS ISO/IEC 42001:2023 and the United States' NIST AI RMF 1.0) is a design feature to promote interoperability and mutual recognition. The NAIC publishes the full standard and supporting materials, including an illustrated guide, case examples and downloadable resources on the Department site: Voluntary AI Safety Standard (NAIC).
Definitions
VAISS provides practical definitions to ensure consistent application of the guardrails. Key defined terms include: "AI system" (software-based tools that generate outputs such as predictions, content or recommendations), "AI model" (mathematical engine within AI systems), "AI deployer" (an entity that supplies or uses an AI system to provide a product or service), "developer" (an entity that designs, builds or trains an AI model), "risk" and "harm" (potential negative impacts to individuals, groups or societal structures), and "meaningful human oversight" (human control mechanisms proportionate to risk). The standard maps these definitions to existing legal concepts — for example linking privacy-related definitions to the Privacy Act and the Australian Privacy Principles as reflected in OAIC guidance: OAIC guidance on AI and privacy.
Governance and Institutional Framework
VAISS recommends that organisations establish and publish an accountability process that includes identifiable ownership (an AI owner or executive sponsor), an AI strategy aligned with organisational goals, and governance structures for compliance and oversight. The standard emphasises internal capability building (training for staff and board-level awareness), procurement controls to embed guardrails into supplier contracts, and cross-functional structures (legal, security, privacy, product, compliance and ethics) to manage AI risks. VAISS also positions NAIC and the Department of Industry, Science and Resources as central facilitators of voluntary adoption and guidance, while directing practitioners to coordinate with other Australian regulators (for example the Office of the Australian Information Commissioner for privacy matters: OAIC, and sectoral regulators such as the Australian Prudential Regulation Authority or health regulators where relevant). The standard situates itself as complementary to national standardisation efforts (notably AS ISO/IEC 42001) and crosswalks to international frameworks to reduce duplication and promote a coherent governance ecosystem.
Key Focus Areas
VAISS contains 10 guardrails which together form the operational heart of the standard. The guardrails require organisations to: 1) establish, implement and publish an accountability process (governance, capability, regulatory compliance strategy); 2) put in place a risk management process to identify and mitigate risks (including ongoing risk assessments and impact assessments); 3) protect AI systems and implement data governance measures for data quality and provenance; 4) test AI models and systems thoroughly before deployment and monitor performance post-deployment; 5) enable meaningful human control or intervention mechanisms proportionate to risk; 6) inform end-users when decisions, interactions or content are AI-enabled, with clear disclosure practices; 7) establish processes for people impacted by AI outcomes to challenge decisions and seek remedies; 8) be transparent across the AI supply chain about data, models and system components to facilitate risk management; 9) keep and maintain records (including an AI inventory and system documentation) to allow third-party assessment of compliance; and 10) actively engage stakeholders and evaluate impacts with a focus on safety, diversity, inclusion and fairness. Across these focus areas VAISS provides practical examples and checklists that organisations can adapt. The standard explicitly anticipates a tiered approach where controls are scaled to the severity and likelihood of harms, and it signals preparatory steps for future conformity assessment and potential mandatory guardrails in high-risk domains.
Implementation Framework
VAISS outlines an implementation path: (a) Governance set-up — appoint an AI owner, board reporting and policy baseline; (b) Risk scoping — use impact assessment tools (for example the NAIC AI Impact Navigator) to classify system risk; (c) Controls design — select data governance, testing and oversight controls proportionate to risk; (d) Procurement alignment — include contractual clauses and supplier evidence requirements to ensure supply-chain transparency; (e) Operationalisation — embed human oversight, monitoring dashboards and incident response; and (f) Documentation & records — maintain an AI inventory, testing logs and evidence to enable internal and third‑party review. Implementation guidance cross-references ISO management system practices and the NIST AI RMF to help organisations translate guardrails into auditable processes and metrics. The standard provides templates and worked examples to support smaller organisations to adopt scaled measures and to assist larger organisations to integrate AI governance into existing management systems.
Monitoring and Evaluation
VAISS requires continuous monitoring and evaluation of AI systems after deployment. Organisations should define acceptance criteria, performance metrics, and monitoring regimes to detect model drift, performance degradation, bias, safety incidents and security events. The standard recommends scheduled re-testing, logging of outputs and incidents, periodic re-assessment of risk and impact (including stakeholder feedback) and maintenance of records to demonstrate ongoing compliance with the guardrails. VAISS encourages organisations to publish summary results of monitoring where appropriate to build public trust and to support third-party conformity assessment processes that may be introduced in the future. The guidance also highlights the importance of incident response and escalation pathways that integrate with existing organisational risk, legal and cybersecurity processes.
Penalties, Liability, and Appeals
As a voluntary standard, VAISS does not itself create statutory penalties. However, the standard explains legal contexts in which non-compliance with guardrails may increase exposure to existing regulatory or civil liability — notably under privacy law (Privacy Act and APPs), consumer protection and anti-discrimination laws. Organisations that fail to adopt reasonable safeguards may face civil liability, regulatory enforcement by relevant agencies (for example OAIC or sector regulators), contractual remedies (procurement disqualification or indemnities) and reputational and commercial consequences. VAISS also recommends internal redress processes and external challenge mechanisms for impacted individuals, and advises organisations to maintain evidence and recordkeeping to support appeals, dispute resolution and legal defence where necessary.
Relationship to Other Instruments
VAISS is explicitly designed to sit alongside and complement existing Australian laws and international standards. The standard cross-references the Privacy Act, the Australian Consumer Law, sectoral regulation in healthcare and finance, existing cybersecurity frameworks (for example the Australian Cyber Security Centre Essential Eight) and management-system standards such as ISO/IEC 42001. VAISS also maps its guardrails to the government’s consultation on mandatory guardrails for high-risk AI settings and to procurement requirements that may incorporate the guardrails as an element of supplier assessment. The standard provides a crosswalk to the NIST AI RMF and indicates alignment with other international guidance to reduce friction for multinational operators and supply chains.
International Alignment
International alignment is an explicit goal of VAISS. The NAIC designed the standard to be consistent with international instruments: the standard references the international AI management system standard AS ISO/IEC 42001, the NIST AI RMF, and other internationally recognised guidelines. This alignment helps organisations that operate across borders to apply similar governance and risk management approaches and supports the development of future cross-border conformity assessment and mutual recognition arrangements. VAISS also anticipates engagement with international partners to harmonise approaches to transparency, testing methodologies and supply-chain information exchange.
Implementation Timeline
| Event | Date | Notes |
|---|---|---|
| PDF / initial draft dated | 2024-08-xx | PDF metadata indicates August 2024 creation. |
| Online publication (department web page) | 2024-09-05 | Department of Industry, Science and Resources publication date. |
| NAIC reference / update note | 2024-10-xx | NAIC references and resources updated through Oct 2024. |
| Ongoing consultation on mandatory guardrails | 2024-2025 | Government consultation process and proposals paper (ongoing). |
Compliance Checklist
| Requirement | Yes/No | Evidence |
|---|---|---|
| Appointed AI owner / governance body | AI policy, board minutes | |
| Risk & impact assessment completed | Risk register, assessments | |
| Data governance & provenance controls in place | Data inventories, data lineage | |
| Pre-deployment testing and acceptance criteria documented | Test reports, acceptance logs | |
| Human oversight & intervention mechanisms defined | Operational playbooks, training records | |
| User disclosure practices implemented | Privacy notices, UI disclosures | |
| Challenge/redress process available | Complaint forms, escalation logs | |
| Supply‑chain transparency measures adopted | Supplier contracts, model provenance statements | |
| Records & AI inventory maintained | AI inventory, documentation repository | |
| Stakeholder engagement documented | Engagement logs, consultation summaries |
Sources and References
| Source | Type |
|---|---|
| Voluntary AI Safety Standard — Department of Industry, Science and Resources (web page) | Primary Source |
| Voluntary AI Safety Standard (PDF) — NAIC / Department of Industry, Science and Resources | Primary Source |
| OAIC guidance on privacy and AI | Primary Source |
| NIST AI Risk Management Framework (AI RMF 1.0) | Primary Source |
| AS ISO/IEC 42001:2023 (Standards Australia) | Primary Source |
Australia's Voluntary AI Safety Standard (VAISS) offers practical, non-binding guidance for organisations across all sectors to safely design, procure, deploy, and oversee Artificial Intelligence systems. Published by the National Artificial Intelligence Centre (NAIC), it applies to any Australian entity developing, using, or managing AI, regardless of size.
Effective from September 5, 2024, VAISS outlines ten "guardrails" to promote responsible AI. Key among these are the requirements to: - Establish clear governance and accountability, including robust risk management processes to identify and mitigate potential harms. - Ensure thorough testing of AI models and systems before deployment, followed by continuous monitoring of their performance. - Provide meaningful human oversight and transparently disclose to users when they are interacting with or impacted by AI. - Set up accessible processes for individuals to challenge AI-driven decisions and seek redress.
While VAISS is voluntary and doesn't introduce new penalties, organisations should not mistake this for a lack of consequence. Failing to adopt these reasonable safeguards can significantly increase exposure to existing Australian laws, such as privacy, consumer protection, and anti-discrimination legislation. This means regulators like the Office of the Australian Information Commissioner (OAIC) or sector-specific bodies could still take action, leading to civil liability, contractual issues, and reputational damage. The standard also signals that these voluntary guardrails may become mandatory for high-risk AI applications in the future, making early adoption a strategic advantage. VAISS is designed to align with international frameworks like ISO/IEC 42001 and the NIST AI Risk Management Framework, promoting global interoperability.
Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.
What you must do — compliance checklist
0 / 12 marked completePlain-English obligations under Australia - AI Safety Standard. Not legal advice — verify against the official text before relying on it.
- #1ImportantKey Focus Areas
Applies to: Organisations designing, procuring, deploying, or overseeing AI systems.
“establish, implement and publish an accountability process”
- #2ImportantKey Focus Areas
Applies to: Organisations designing, procuring, deploying, or overseeing AI systems.
“put in place a risk management process to identify and mitigate risks”
- #3ImportantKey Focus Areas
Applies to: Organisations designing, procuring, deploying, or overseeing AI systems.
“protect AI systems and implement data governance measures for data quality and provenance”
- #4ImportantKey Focus Areas⏰ Before placing on market
Applies to: Organisations deploying AI systems.
“test AI models and systems thoroughly before deployment and monitor performance post-deployment”
- #5ImportantKey Focus Areas⏰ Before placing on market
Applies to: Organisations deploying AI systems.
“enable meaningful human control or intervention mechanisms proportionate to risk”
- #6ImportantKey Focus Areas⏰ Before placing on market
Applies to: Organisations deploying AI systems that interact with users.
“inform end-users when decisions, interactions or content are AI-enabled”
- #7ImportantKey Focus Areas
Applies to: Organisations deploying AI systems that impact individuals.
“establish processes for people impacted by AI outcomes to challenge decisions and seek remedies”
- #8ImportantKey Focus Areas
Applies to: Organisations procuring or deploying AI systems.
“be transparent across the AI supply chain about data, models and system components”
- #9ImportantKey Focus Areas
Applies to: Organisations designing, procuring, deploying, or overseeing AI systems.
“keep and maintain records (including an AI inventory and system documentation)”
- #10ImportantKey Focus Areas
Applies to: Organisations designing, procuring, deploying, or overseeing AI systems.
“actively engage stakeholders and evaluate impacts with a focus on safety, diversity, inclusion and fairness”
- #11ImportantGovernance and Institutional Framework
Applies to: Organisations procuring AI systems.
“procurement controls to embed guardrails into supplier contracts”
- #12ImportantMonitoring and Evaluation
Applies to: Organisations deploying AI systems.
“importance of incident response and escalation pathways”
Related Regulations
Safe and Responsible AI in Australia — Government Interim Response to Consultation
Australia94% similar
Safe and Responsible AI in Australia — Discussion Paper
Australia93% similar
Proposals Paper for Introducing Mandatory Guardrails for AI in High-Risk Settings
Australia93% similar
AI Ethics Framework (Australia) / Australia’s AI Ethics Principles
Australia93% similar
Standard for AI transparency statements
Australia93% similar
© Regulations.AI — created on 13-Jun-2026