Australia - Queensland - AI Governance Policy (RAI-AU-QL-ARTINGO-2024)
Artificial intelligence governance policy
Australia
RAI-AU-QL-ARTINGO-2024This policy guides Queensland government agencies in the ethical, transparent, and accountable use of AI, requiring comprehensive risk assessments and adherence to ISO 38507 standards.
Summary
Read full text ↗Plain English
Overview
The Queensland Artificial Intelligence Governance Policy, introduced in September 2024, is a foundational document designed to ensure that Queensland Government agencies approach the planning, evaluation, and deployment of Artificial Intelligence (AI) solutions with a structured and consistent methodology. The primary purpose of this policy is to foster transparency, accountability, and robust risk management throughout the entire AI lifecycle within the public sector. It is officially designated as a 'CurrentMandated' policy, signifying its compulsory application across relevant government entities.
The policy applies broadly to all Queensland Government departments, as defined by the Public Sector Act 2022, and to statutory bodies falling under the Financial and Performance Management Standard 2019. It also extends its applicability to accountable officers within departments who hold delegated responsibility for other statutory bodies, particularly concerning internal controls, financial information management systems, and risk management.
By mandating a consistent and evidence-based approach, the Queensland Government seeks to derive significant benefits from AI technologies while proactively managing associated challenges. These benefits include enhancing agency investment governance processes by instilling confidence that AI investments yield positive outcomes and avert potential harm or bias. The policy promotes an evidence-based framework for aligning AI-related decisions with the core values and obligations of the Queensland Government. Furthermore, it aims to facilitate collaborative opportunities, thereby reducing duplication of effort, effectively managing risks, and leveraging existing AI investments or capabilities across the government. It also seeks to increase the availability of information to support evidence-based decision-making, improve the appropriate selection of AI solutions to augment business capabilities, assist government stakeholders in discerning when AI is suitable for reasoning and decision-making, and critically, mitigate information security risks inherent in AI systems.
The policy's design aligns with broader national and international frameworks for AI governance, notably the Australian AI Ethics Principles and the international standard ISO 38507. This alignment underscores Queensland's commitment to integrating globally recognized best practices for responsible AI into its public sector operations. The Queensland Government Enterprise Architecture (QGEA) provides overarching direction and guidance for strategic planning, governance, risk management, and the ethical use of IT solutions that incorporate AI, with this policy being a cornerstone within that framework.
Definitions
While the Queensland AI Governance Policy itself does not feature a dedicated 'Definitions' section within the publicly available snippets, it operates on a set of implicitly defined key terms and concepts critical to its understanding and implementation. These terms are derived from the policy's stated purpose, requirements, and its relationship with supporting documents and international standards:
- Artificial Intelligence (AI): Refers to systems or technologies that can perform tasks typically requiring human intelligence, such as learning, problem-solving, decision-making, and perception. The policy implicitly covers various forms of AI, including generative AI, as evidenced by references to the 'Use of Generative AI in Queensland Government Guideline'.
- AI Lifecycle: Encompasses all stages of an AI solution, from its initial conception, design, development, procurement, and implementation to its operation, monitoring, evaluation, and eventual decommissioning. The policy emphasizes structured and consistent approaches throughout this entire lifecycle.
- Transparency: The principle that the operation and decision-making processes of AI systems should be understandable, explainable, and open to scrutiny. This includes clarity about when, where, and how AI is being used, and the underlying evidence, principles, and assumptions driving its predictions and decisions.
- Accountability: The principle that there must be clear responsibility for AI-driven decisions and their outcomes, including any potential adverse effects. It addresses the need to establish who is responsible for AI decisions and their flow-on effects.
- Risk: Refers to the potential for adverse impacts or unintended consequences arising from the design, development, or deployment of AI systems. The policy specifically highlights ethical risks, data exposure, poor information quality, automated decision-making risks, potential biases, cybersecurity risks, and risks to privacy.
- Ethical Framework: A set of principles and guidelines that direct the design, development, and use of AI to ensure it aligns with societal values, human rights, and public expectations. The policy mandates its incorporation into AI evaluation processes.
- Bias: Systematic and unfair prejudice for or against a person or group, which can be embedded in AI systems through biased data or algorithmic design, leading to discriminatory or inequitable outcomes.
- Privacy by Design: An approach to developing and integrating AI systems where privacy considerations are embedded into the design and operation of IT systems, networked infrastructure, and business practices from the outset.
- Security by Design: A similar approach where security considerations are fundamentally integrated into the design and architecture of AI systems and related infrastructure from the earliest stages.
- ISO 38507: An international standard titled 'Information technology – Governance of IT – Governance implications of the use of artificial intelligence by organisations'. It provides guidance for governing bodies to ensure the effective, efficient, and acceptable use of AI within an organization, focusing on governance, accountability, and ethical considerations.
- Foundational Artificial Intelligence Risk Assessment (FAIRA): A specific guideline and framework developed by the Queensland Government to assist agencies in conducting comprehensive, consistent, and evidence-based risk assessments for AI solutions. It serves as a transparency, accountability, and risk identification tool.
Governance and Institutional Framework
The governance and institutional framework for the Queensland AI Governance Policy is multi-layered, involving various government entities and existing legislative instruments to ensure comprehensive oversight and responsible implementation of AI across the public sector. The Queensland Government Customer and Digital Group (QGCDG), specifically the Department of Customer Services, Open Data and Small and Family Business (CDSB), is the central authority responsible for the development, release, and ongoing maintenance of this policy. CDSB's role is critical in setting policies on information and communication technology (ICT) and data management, ensuring that policies for the ethical use of AI are evidence-based, clear, and user-friendly.
The policy's applicability extends to all Queensland Government departments, as defined by the Public Sector Act 2022, and to statutory bodies operating under the Financial and Performance Management Standard 2019. This broad scope ensures that a consistent approach to AI governance is adopted across a wide array of public service operations. Individual agencies bear the primary responsibility for establishing and implementing their own AI governance arrangements, which must be consistent with existing agency governance structures such as ICT governance, agency risk governance, or Information Security Management System (ISMS) governance. This integration with existing frameworks aims to streamline compliance and leverage established oversight mechanisms.
A key mandate within the policy is for agencies to establish AI governance arrangements based on the current version of ISO 38507, the international standard for 'Information technology – Governance implications of the use of artificial intelligence by organisations'. This makes Queensland the first jurisdiction nationally to mandate public sector entity compliance with this international best practice standard. The emphasis of ISO 38507 is on the governance (human oversight) of an organization's use of AI, rather than solely on the technologies themselves, requiring an understanding of the implications of these technologies.
The Queensland Audit Office (QAO) plays a crucial oversight role, assessing whether the Queensland public sector has adequate policies and procedures to effectively manage the ethical risks associated with AI systems. The QAO's reports provide insights into entities' financial performance, risk, and internal controls, including the efficiency, effectiveness, and economy of public service delivery in relation to AI. The Queensland Government Enterprise Architecture (QGEA) also provides essential direction and guidance for strategic planning, governance, risk management, and the ethical use of IT solutions that incorporate AI, assisting executives in understanding their obligations when business processes are augmented with AI.
Key Focus Areas
- Ethical Framework and Principles: The policy fundamentally requires agencies to implement an ethical framework in their evaluation processes for AI solutions. This framework must ensure transparency, accountability, and proper risk assessment throughout the AI lifecycle. The Queensland Government's approach is aligned with the Australian AI Ethics Principles, which emphasize fairness, transparency, and accountability in the governmental use of AI. This commitment ensures that AI technologies are not used in ways that perpetuate or introduce discrimination or bias against individuals or groups, particularly in administrative decision-making. The policy highlights that acting ethically is not a new obligation, but AI creates new contexts where these responsibilities must be diligently applied.
- Risk Management: A cornerstone of the policy is the mandatory requirement for agencies to conduct comprehensive and structured risk assessments before the deployment and throughout the lifecycle of any AI solution. This process must be consistent, evidence-based, and incorporate an ethical framework. The complexity of the risk assessment should be appropriate for the AI solution being evaluated. To facilitate this, the Queensland Government has released two critical supporting documents: the Foundational Artificial Intelligence Risk Assessment (FAIRA) guideline and the FAIRA framework. The FAIRA framework is explicitly designed as a transparency, accountability, and risk identification tool that helps stakeholders identify risks and potential mitigation actions specific to the AI lifecycle. It requires a components analysis to fully describe the AI solution and a values assessment to identify and manage risks, aligning with 'The National Framework for the Assurance of AI in Government 2024'. Key areas of risk assessment include data privacy, potential biases in AI systems, and cybersecurity vulnerabilities. Agencies must integrate these AI-specific risks into their existing ICT risk registers.
- Transparency and Accountability: The policy explicitly aims to enhance transparency and accountability in the government's use of AI. It addresses concerns about a lack of public understanding regarding AI deployment and the absence of clear accountability for AI-driven decisions and their consequences. The FAIRA framework supports these objectives by providing a structured way to identify and communicate risks and mitigation strategies to stakeholders, thereby fostering public trust in how government manages AI. Ethical use also mandates agencies to be open about their AI use, including the algorithms that inform government decisions.
- Data Protection and Privacy: The policy places significant emphasis on data protection and privacy, requiring agencies to prioritize 'privacy by design' and 'security by design' principles in all AI technology implementations. This means that privacy and data security considerations must be embedded from the outset of AI project development. Agencies are obligated to understand how AI technologies interact with the personal data they collect, hold, and use. A critical provision states that using personal information held by government agencies to train AI tools through Large Language Models (LLMs) is generally considered a breach of Queensland information privacy principles, unless a specific exemption applies. This highlights a strong stance against unauthorized data use for AI training. Agencies must also ensure that third-party AI suppliers adhere to Queensland privacy laws and information security standards and conduct regular audits of service providers.
- Alignment with ISO Standards: A mandatory requirement of the policy is that agencies must establish their AI governance arrangements based on the current version of ISO 38507. This international standard, titled 'Information technology – Governance of IT – Governance implications of the use of artificial intelligence by organisations', provides a robust framework for evaluating, directing, and monitoring AI usage. ISO 38507 focuses on ensuring that AI decision-making aligns with corporate objectives, legal requirements, ethical expectations, and societal values. Queensland's mandate of this standard demonstrates a commitment to integrating global best practices for responsible AI operations, promoting safer data management, and strengthening governance controls over AI, thereby supporting accountability and public confidence.
Implementation Framework
The implementation of the Queensland AI Governance Policy is designed to be integrated seamlessly into existing government operational and governance structures. Agencies are required to establish AI governance arrangements that are consistent with their current ICT governance, risk governance, or Information Security Management System (ISMS) governance frameworks. This approach avoids creating parallel systems and leverages established expertise and processes within agencies.
To support agencies in complying with the policy, the Queensland Government has released several key supporting documents and guidelines. Central among these are the Foundational Artificial Intelligence Risk Assessment (FAIRA) guideline and the FAIRA framework. These resources provide practical tools and methodologies for agencies to conduct the mandated risk assessments for AI solutions. The FAIRA framework, for instance, includes a components analysis and a values assessment to ensure a comprehensive understanding of an AI solution's context, design, human interaction, and potential impacts. It also offers a list of common controls to assist teams in identifying actions to mitigate identified risks. The FAIRA framework is intended to be initiated at the earliest opportunity when an AI solution is under consideration for procurement, development, use, or discontinuance, and throughout its deployment and operation.
Further guidance is provided through the Queensland Government Enterprise Architecture (QGEA), which offers directions and guidelines for strategic planning, governance, risk management, and the ethical use of IT solutions encompassing AI. The QGEA helps executives understand their obligations and mitigate risks such as data exposure, poor information quality, and issues arising from automated decision-making. Other related guidelines, such as the 'Use of Generative AI in Queensland Government Guideline' (effective August 2023), provide key considerations for employees when using generative AI products and services, emphasizing employee responsibility for generated content and adherence to existing legislation and policies.
The government is also fostering a culture of awareness and skill development in emerging technologies, including AI. An 'Emerging Technologies Community of Practice' is being established with representatives from all Queensland Government Departments. This community is intended to host training events and leverage online and vendor training to enhance awareness and skills related to AI and other new technologies. This collaborative initiative aims to promote knowledge sharing, insights, skills, and data across government to improve efficiency and service delivery. Agencies are also encouraged to refer to the Financial and Performance Management Standard 2019 and supporting Agency Planning Requirements for further information on planning obligations related to AI investments.
Monitoring and Evaluation
Effective monitoring and evaluation are critical components of the Queensland AI Governance Policy, ensuring that AI systems are used responsibly and that the policy's objectives are met. The Department of Customer Services, Open Data and Small and Family Business (CDSB), which is responsible for the policy, plays a key role in monitoring AI usage and associated risks across the Queensland Government.
The Queensland Audit Office (QAO) conducts independent audits to assess whether the Queensland public sector effectively manages the ethical risks associated with AI systems. Their reports provide valuable insights and identify opportunities for improvement in the AI governance framework. For example, the QAO has noted that CDSB could strengthen its guidance on the application of ethical risk assessments to support a more consistent and effective application of the framework. It also highlighted the need for CDSB to determine how it will evaluate its AI governance policy and supporting tools to ensure their effective implementation and continuous improvement.
Individual entities are responsible for implementing and managing the risks specific to their AI systems and ensuring alignment with other government policies and laws. This decentralized responsibility for day-to-day risk management is complemented by centralized oversight from CDSB and independent auditing by the QAO. Agencies are also expected to continuously review and update their governance arrangements to manage ethical risks and align with the policy's requirements, implementing appropriate assurance frameworks to ensure effectiveness. The 'Use of Generative AI in Queensland Government Guideline' also indicates that the government will provide options to access generative AI capabilities in a secure and managed environment, consistent with existing policies, and that employees should use capabilities approved by their agency. For specific AI tools, such as QChat, an evaluation program is carried out to assess performance and user experience.
Penalties, Liability, and Appeals
The Queensland AI Governance Policy, as a governance policy for government agencies, does not explicitly outline specific criminal penalties, civil penalties, fines, or a detailed appeals process for non-compliance within its provisions. Instead, the enforcement and accountability mechanisms for adherence to this policy are integrated within the broader existing legislative and administrative frameworks governing the Queensland public sector.
Non-compliance with the policy's requirements would likely be addressed through established public sector accountability processes. This includes obligations under the Public Sector Act 2022, the Financial and Performance Management Standard 2019, and the Queensland Public Service Code of Conduct. These instruments provide frameworks for ethical conduct, financial management, and performance accountability for government departments and statutory bodies. Breaches related to data protection and privacy would fall under existing Queensland privacy legislation and information security standards. Misuse of AI or non-compliance could lead to disciplinary action as outlined in an agency's disciplinary processes.
The policy emphasizes that agencies must ensure their AI systems and use align with other government policies and laws. Therefore, any liability or appeals would likely be pursued under these overarching legal and regulatory instruments rather than specific provisions within the AI Governance Policy itself. For instance, issues related to discrimination or bias perpetuated by AI would engage human rights and anti-discrimination legislation. The focus of the policy is on proactive governance, risk mitigation, and ethical deployment to prevent issues, rather than detailing reactive penalties.
Relationship to Other Instruments
The Queensland AI Governance Policy operates within a comprehensive ecosystem of existing legislation, standards, and guidelines at both state and federal levels, ensuring a holistic approach to AI governance. Its relationship with these instruments is crucial for its effective implementation and for ensuring consistency across government operations:
- Public Sector Act 2022 (Qld): The policy applies to Queensland Government departments as defined by this Act, establishing the foundational legal framework for public sector operations to which AI governance must adhere.
- Financial and Performance Management Standard 2019 (Qld): The policy extends its applicability to statutory bodies and accountable officers under this Standard, particularly in the context of internal controls, financial information management systems, and risk management. Agencies are advised to refer to this Standard for planning obligations.
- Queensland Public Service Code of Conduct: Queensland Government employees are reminded of their obligations under this Code of Conduct when using generative AI products and services, ensuring ethical behavior extends to AI interactions.
- Queensland Privacy Legislation and Information Security Standards: Compliance with existing Queensland privacy laws and information security standards is paramount. The policy emphasizes 'privacy by design' and 'security by design' and restricts the use of personal government data for training AI models unless explicitly exempted.
- Australian AI Ethics Principles: The Queensland policy aligns with these national principles, which focus on fairness, transparency, and accountability in the use of AI across government. These principles serve as a guide for incorporating ethical standards into the design, development, and implementation of AI.
- ISO 38507 Information technology – Governance implications of the use of artificial intelligence (AI) by organisations: This international standard is a mandatory requirement for agencies in establishing their AI governance arrangements. It provides a global best-practice framework for governing AI use, emphasizing transparency, accountability, and ethical considerations. Queensland is noted as the first jurisdiction nationally to mandate compliance with this standard in its public sector.
- Foundational Artificial Intelligence Risk Assessment (FAIRA) Guideline and Framework: These are critical supporting documents released alongside the policy. They provide agencies with a consistent and evidence-based process for identifying, evaluating, communicating, and managing risks associated with the AI lifecycle.
- The National Framework for the Assurance of AI in Government 2024: The FAIRA framework is aligned with this national framework, ensuring consistency with broader Australian government initiatives for AI assurance.
- Use of Generative AI in Queensland Government Guideline: This guideline, effective from August 2023, provides key considerations and recommendations for entities and employees regarding the safe and responsible use of generative AI tools, complementing the broader governance policy.
- Other QGEA Policies and Guidelines: The AI Governance Policy is part of the Queensland Government Enterprise Architecture (QGEA), which provides a suite of directions and guidance on various aspects of IT and digital transformation, including cyber security, information asset custodianship, and records governance.
- Federal Government Direction 001-2025 on DeepSeek products: The Queensland Government's 'DeepSeek products, applications and web services policy' aligns with this federal direction, prohibiting the use of specific generative AI tools on government systems due to security risks.
International Alignment
The Queensland AI Governance Policy demonstrates a strong commitment to international best practices in AI governance, primarily through its mandatory alignment with ISO 38507. This standard, officially titled 'Information technology – Governance of IT – Governance implications of the use of artificial intelligence by organisations', is a globally recognized framework that provides guidance for the governing body of an organization to ensure the effective, efficient, and acceptable use of AI. Queensland has distinguished itself as the first jurisdiction nationally to mandate compliance with ISO 38507 in its public sector, positioning itself as a leader in responsibly adopting AI within government operations.
The policy's adherence to ISO 38507 signifies a commitment to universal principles of transparency, accountability, and ethical use of AI technologies. This alignment establishes uniform standards for assessing AI systems, emphasizing data privacy, operational transparency, and accountability, which are critical elements for maintaining public trust in AI deployment. The standard helps organizations understand the enterprise-wide impact of AI, clarify roles and responsibilities for AI-related decisions, develop mechanisms for risk management and performance evaluation, and integrate AI governance into existing corporate governance frameworks.
Beyond ISO 38507, the Queensland policy also aligns with the broader Australian AI Ethics Principles. These national principles, which focus on fairness, transparency, and accountability, reflect an international consensus on ethical AI development and deployment. This dual alignment with both a specific international technical standard and broader ethical principles ensures that Queensland's approach to AI governance is robust, comprehensive, and globally informed, promoting safer data management practices and enhancing public confidence in government AI initiatives. The policy's framework also considers and aligns with the National Framework for the Assurance of AI in Government, further demonstrating a coordinated approach to AI governance that incorporates both national and international best practices.
Implementation Timeline
| Date | Event |
|---|---|
| 2023-08 | Use of Generative AI in Queensland Government Guideline became effective. |
| Late 2023 | QChat, the Queensland Government's generative AI tool, was introduced in private preview to select departments. |
| 2024-09-01 | Queensland Government's Artificial intelligence governance policy was introduced and became effective. |
| 2024-09-01 | Foundational Artificial Intelligence Risk Assessment (FAIRA) framework and guideline were published. |
| 2024-10-03 | Queensland Government published an Artificial intelligence governance policy and a Foundational artificial intelligence risk assessment framework (further reference to publication). |
| 2025-02 | Queensland Government released its 'DeepSeek products, applications and web services policy', aligning with federal direction to prohibit specific AI tools. |
| Mid-2024 | QChat rolled out statewide (approximately a year prior to May 2025). |
| 2025-04 | The model underpinning QChat was upgraded to GPT4o (mid-April 2025). |
Compliance Checklist
| Requirement | Description |
|---|---|
| Conduct Comprehensive Risk Assessments | Agencies must use a consistent and evidence-based process, incorporating an ethical framework, to evaluate the transparency, accountability, and risk associated with the AI lifecycle. This includes applying the Foundational Artificial Intelligence Risk Assessment (FAIRA) framework or an equivalent. |
| Establish ISO 38507-Based Governance | Agencies must establish AI governance arrangements based on the current version of ISO 38507 Information technology – Governance implications of the use of artificial intelligence (AI) by organisations, ensuring alignment with international best practices. |
| Integrate Ethical Frameworks | Ensure that an ethical framework is explicitly incorporated into all evaluation processes for AI solutions, aligning with principles of fairness, transparency, and accountability. |
| Prioritize Data Protection and Privacy | Implement 'privacy by design' and 'security by design' principles from the outset of AI technology implementation. Understand how AI interacts with personal data and comply with Queensland privacy legislation and information security standards. |
| Restrict Training Data Use | Do not use personal information held by government agencies to train AI tools through Large Language Models (LLMs) unless a specific exemption applies, to prevent breaches of Queensland information privacy principles. |
| Align with Existing Governance Structures | Ensure AI governance arrangements are consistent with existing agency governance structures, such as ICT governance, agency risk governance, or Information Security Management System (ISMS) governance. |
| Refer to Financial and Performance Management Standard | For planning obligations related to AI investments, agencies should refer to the Financial and Performance Management Standard 2019 and its supporting Agency Planning Requirements. |
| Mitigate Specific AI Risks | Understand and actively mitigate risks related to data exposure, poor information quality, potential biases, cybersecurity threats, and issues arising from automated decision-making processes. |
| Ensure Third-Party Compliance | Verify that third-party suppliers of AI technologies are bound by Queensland privacy laws and information security standards, and conduct periodical audits of their compliance. |
| Monitor and Review AI Use | Continuously monitor and review AI use within the agency, including audit logs and regular assessments, to ensure ongoing compliance and protection of information. |
Sources and References
| Source | Type |
|---|---|
| Artificial intelligence governance policy | Government Website |
| Foundational artificial intelligence risk assessment framework | Government Website |
| Managing the ethical risks of artificial intelligence (Report 2: 2025–26) | Government Website |
| From the Information Commissioner: Government use of AI in Queensland | Government Website |
| Use of generative AI in Queensland Government | Government Website |
The Queensland Artificial Intelligence Governance Policy sets out mandatory rules for all Queensland government departments and statutory bodies on how to ethically, transparently, and accountably use Artificial Intelligence (AI) solutions.
This policy, which became effective on September 1, 2024, applies to all Queensland Government departments (as defined by the Public Sector Act 2022) and statutory bodies (under the Financial and Performance Management Standard 2019). It aims to ensure that AI investments deliver positive outcomes while proactively managing risks like bias and privacy breaches.
Agencies must adhere to several key obligations. They are required to: - Conduct comprehensive and structured risk assessments for all AI solutions throughout their lifecycle, using the Foundational Artificial Intelligence Risk Assessment (FAIRA) framework. - Establish AI governance arrangements based on the international standard ISO 38507, making Queensland the first Australian jurisdiction to mandate this for its public sector. - Implement an ethical framework in their AI evaluation processes, aligning with the Australian AI Ethics Principles to ensure fairness, transparency, and accountability. - Prioritise "privacy by design" and "security by design" in all AI implementations. A critical prohibition states that using personal information held by government agencies to train AI tools, especially Large Language Models (LLMs), is generally considered a breach of Queensland information privacy principles, unless a specific exemption applies.
While the policy itself doesn't detail specific fines or penalties, non-compliance would trigger existing public sector accountability mechanisms. This means breaches could lead to disciplinary action under the Public Sector Act 2022, the Queensland Public Service Code of Conduct, or existing privacy and information security laws. A key practical takeaway for teams is the strict stance on data use: government personal data cannot generally be used to train AI models without explicit exemption, which is a significant limitation for AI development and deployment.
Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.
What you must do — compliance checklist
0 / 15 marked completePlain-English obligations under Australia - Queensland - AI Governance Policy (RAI-AU-QL-ARTINGO-2024). Not legal advice — verify against the official text before relying on it.
- #1Critical
Applies to: Queensland Government agencies
“A key mandate within the policy is for agencies to establish AI governance arrangements based on the current version of ISO 38507...”
- #2Critical⏰ Before deployment and throughout the lifecycle
Applies to: Queensland Government agencies
“A cornerstone of the policy is the mandatory requirement for agencies to conduct comprehensive and structured risk assessments...”
- #3Critical
Applies to: Queensland Government agencies
“The policy fundamentally requires agencies to implement an ethical framework in their evaluation processes for AI solutions.”
- #4Critical
Applies to: Queensland Government agencies
“requiring agencies to prioritize 'privacy by design' and 'security by design' principles in all AI technology implementations.”
- #5Critical
Applies to: Queensland Government agencies
“using personal information held by government agencies to train AI tools... is generally considered a breach...”
- #6Critical
Applies to: Queensland Government agencies using third-party AI
“Agencies must also ensure that third-party AI suppliers adhere to Queensland privacy laws and information security standards...”
- #7Critical
Applies to: Queensland Government agencies and employees
“prohibiting the use of specific generative AI tools on government systems due to security risks.”
- #8Important
Applies to: Queensland Government agencies
“Agencies are required to establish AI governance arrangements that are consistent with their current ICT governance...”
- #9Important
Applies to: Queensland Government agencies
“The FAIRA framework is explicitly designed as a transparency, accountability, and risk identification tool...”
- #10Important
Applies to: Queensland Government agencies
“Agencies must integrate these AI-specific risks into their existing ICT risk registers.”
- #11Important⏰ At the earliest opportunity
Applies to: Queensland Government agencies considering AI solutions
“The FAIRA framework... is intended to be initiated at the earliest opportunity...”
- #12Important
Applies to: Queensland Government agencies
“Ethical use also mandates agencies to be open about their AI use, including the algorithms that inform government decisions.”
- #13Important
Applies to: Queensland Government agencies
“Agencies are obligated to understand how AI technologies interact with the personal data they collect, hold, and use.”
- #14Important
Applies to: Queensland Government employees using generative AI
“emphasizing employee responsibility for generated content and adherence to existing legislation and policies.”
- #15Important
Applies to: Queensland Government agencies
“Agencies are also expected to continuously review and update their governance arrangements...”
Related Regulations
Artificial intelligence governance policy (Queensland Government)
Australia98% similar
Foundational Artificial Intelligence Risk Assessment (FAIRA) guideline (Queensland Government)
Australia95% similar
Policy for the responsible use of AI in government
Australia94% similar
Western Australia AI Policy Framework
Australia93% similar
Guidance for the use of artificial intelligence in Tasmanian Government
Australia93% similar
© Regulations.AI — created on 06-Jan-2026 using Gemini 2.5 Flash