Australia - Victoria - Generative AI Guidelines

Administrative Guideline for the safe and responsible use of Generative Artificial Intelligence in the Victorian Public Sector

Australia

RAI-AU-VI-ASRUGXX-2024
Effective: November 27, 2024
In Force(In Force)
GuidelineGovernance and OversightData Protection and PrivacyAccountability and Documentation
Export PDF

A principles-based administrative guideline issued by the Victorian Government (made by the Secretary, Department of Premier and Cabinet) establishing minimum requirements and safeguards for the use of generative AI across the Victorian Public Sector (VPS). It mandates use of agency-approved tools where possible, limits data inputs for public tools to publicly-available information, requires training, monitoring and compliance with existing privacy, records and human-rights law, and aligns VPS practice with Australia’s national AI assurance framework.

Overview

The Administrative Guideline for the safe and responsible use of Generative Artificial Intelligence in the Victorian Public Sector provides minimum whole-of-government direction for using generative AI in official Victoria Public Sector (VPS) work. It was endorsed by the Victorian Secretaries Board on 24 September 2024 and made by the Secretary, Department of Premier and Cabinet on 27 November 2024. The document adopts a principles-based approach aligned with Australia's AI Ethics Principles and the National AI Assurance Framework and distinguishes agency-approved tools from publicly-available tools, sets data sharing limits, requires training and monitoring, and reaffirms that personnel remain accountable for decisions and outputs when using generative AI.

Definitions

The Guideline defines key terms for consistent application across the VPS: "Generative AI" (models that generate text, images, code, audio or other data in response to prompts); "Agency-approved Generative AI tools" (tools assessed and authorised by an in-scope organisation after privacy, cybersecurity and legal review); "Publicly-available Generative AI tools" (third-party services not procured by government); "Official Work" (any tasks performed as part of VPS employment); "Publicly-available information" (data already public or approved for release); and "Personnel" (employees, contractors, consultants and volunteers who may access public sector information). These definitions are designed to be practically applied across procurement, information security and operational workflows.

Governance and Institutional Framework

The Guideline is issued within the Department of Premier and Cabinet (DPC) administrative framework and implementation support is led by the Department of Government Services (DGS). It requires each in-scope organisation (public service bodies and public entities under the Public Administration Act 2004) to: adopt local policies that meet or exceed the Guideline; establish approval processes to designate agency-approved tools; document roles and responsibilities for AI use; and put in place monitoring, recordkeeping and reporting mechanisms. It also mandates alignment with regulator guidance (for example from the Office of the Victorian Information Commissioner and the Victorian Public Sector Commission), and that Heads of agencies notify the Secretary, DPC if they intend to act inconsistently with the Guideline in accordance with s36A(3) Public Administration Act 2004.

Key Focus Areas

The Guideline concentrates on a set of risk and practice domains: (1) data protection and privacy — forbidding input of protected or non-public data into publicly-available tools and requiring protective marking controls for agency-approved solutions; (2) human rights and fairness — ensuring Generative AI use is compatible with the Victorian Charter of Human Rights and Responsibilities; (3) cybersecurity and model security — requiring cyber assessments as part of tool approval; (4) transparency and documentation — maintaining provenance, attribution and records of prompts and outputs incorporated into official work; (5) accountability and oversight — clarifying that personnel remain accountable for content and decisions; and (6) training, monitoring and recordkeeping to support safe adoption. The Guideline also explicitly warns against using generative AI as a substitute for validated decision-making, particularly where outcomes significantly impact rights, welfare, or legal status.

Implementation Framework

In-scope organisations must implement the Guideline through a practical plan that includes: a documented approval process for agency-approved tools (covering privacy, cyber, legal, commercial and IP review); protective marking and data-handling rules per tool; staff education and training modules (the Department of Government Services will supply adaptable modules); monitoring and audit controls to record usage and detect inappropriate input of sensitive information; and risk-assessment and assurance procedures aligned to the National AI Assurance Framework. The Guideline permits tailored, sector-specific measures where required (for example, Department of Education schools use school-specific guidance) and encourages adoption by special bodies where helpful. Practical implementation guidance is available at the complementary guidance page maintained by DGS (Guidance for the safe and responsible use of generative AI in the VPS).

Monitoring and Evaluation

Organisations are expected to monitor both agency-approved and publicly-available generative AI usage to ensure compliance and to inform continuous improvement. Monitoring must be carried out consistent with surveillance principles and privacy law, and should include logging prompts and outputs used in official work, periodic audits of compliance with protective marking and data-sharing rules, post-use quality checks and mechanisms for personnel to report incidents or near-misses. Evaluation is iterative: the Guideline will be reviewed periodically and material changes will be approved by the Victorian Secretaries Board; DGS will update the practical guidance and training materials concurrently.

Penalties, Liability, and Appeals

Although the Guideline itself is an administrative instrument rather than primary legislation, non-compliance may lead to breaches of VPS Codes of Conduct, disciplinary action, administrative directions under the Public Administration Act 2004, and potential statutory enforcement (for example, privacy investigations by OVIC where data breaches occur). The Guideline points to legal exposure related to privacy, health records, public records, human rights, and intellectual property, and suggests agencies involve legal counsel where necessary. Heads of in-scope organisations must provide written reasons to the Secretary, DPC under s36A(3) if operating inconsistently with the Guideline. Appeals and contestability processes for decisions materially affecting individuals remain available through existing administrative law and review mechanisms.

Relationship to Other Instruments

The Guideline is expressly intended to be read alongside several statutory and policy instruments: the Public Administration Act 2004 (scope and administrative mechanisms), Privacy and Data Protection Act 2014 and Health Records Act 2001 (data protection obligations), Public Records Act 1973 (recordkeeping duties), Freedom of Information Act 1982 (transparency obligations) and the VPS Codes of Conduct (standards of behaviour and accountability). It also references the national-level National AI Assurance Framework and Australia’s AI Ethics Principles, encouraging alignment with federal initiatives while retaining state-specific operational requirements.

International Alignment

The Guideline aligns Victoria’s approach with broader national and international AI governance trends by referencing Australia’s national AI Ethics Principles and the National AI Assurance Framework. It encourages practices consistent with international norms for safety, transparency, accountability and human-rights protection and aims to make procurement, risk assessment and assurance processes interoperable with standards likely to be adopted in other jurisdictions. Where cross-border data flows or foreign-operated tools are involved, the Guideline emphasises careful legal and privacy review, vendor due diligence, and attention to jurisdictional data storage and use terms.

Implementation Timeline

MilestoneDateNotes
VSB endorsement2024-09-24Endorsed by Victorian Secretaries Board
Made by Secretary, DPC (formal issue)2024-11-27Instrument issue date
Guidance published2024-11-27Companion guidance live at DGS site
Website update (status/FAQ)2025-02-12Vic.gov.au page updated with clarifications
Periodic reviewOngoing (annually or as required)Material changes returned to VSB for endorsement

Compliance Checklist

ActionCompliantNotes
Designate agency-approved Generative AI toolsYes / NoDocument assessments (privacy, cyber, legal, IP)
Restrict inputs to public info for public toolsYes / NoEnforce via network controls and training
Protective marking applied for agency toolsYes / NoSet marking thresholds per tool
Personnel training completedYes / NoUse DGS modules or agency-adapted equivalents
Usage logging and recordkeepingYes / NoKeep prompts, outputs and provenance for official documents
Periodic audit & risk reviewYes / NoSchedule assurance aligned to National AI Assurance Framework

Sources and References

SourceType
Administrative Guideline for the safe and responsible use of Generative Artificial Intelligence in the Victorian Public SectorPrimary Source
Guidance for the safe and responsible use of generative artificial intelligence in the Victorian public sector (companion guidance)Primary Source
Department of Government Services (DGS) - role & contactPrimary Source
Office of the Victorian Information Commissioner (OVIC)Relevant Regulator
Victorian Public Sector Commission (VPSC)Relevant Regulator
Plain English

This administrative guideline sets out minimum rules and safeguards for how generative artificial intelligence (AI) can be used by all employees, contractors, and volunteers across the Victorian Public Sector (VPS) in their official work.

The guideline applies to all Victorian public service bodies and public entities, as well as their personnel. It officially took effect on November 27, 2024.

At its core, the guideline mandates several key practices. Organisations must use agency-approved generative AI tools whenever possible. Crucially, personnel are strictly prohibited from inputting protected or non-public data into publicly available generative AI services. All use of generative AI must comply with existing laws, including those covering privacy, human rights, and public records. Each VPS organisation is also required to develop its own local policies, establish clear approval processes for AI tools, provide staff training, and implement monitoring and record-keeping systems.

While this is an administrative guideline, not a primary law, ignoring its requirements can have serious consequences. Non-compliance could lead to breaches of the VPS Code of Conduct, disciplinary action, and administrative directions. More broadly, it could expose individuals and agencies to legal liabilities under privacy, health records, human rights, or intellectual property laws, potentially triggering investigations by regulators like the Office of the Victorian Information Commissioner.

A key takeaway for anyone using these tools is that individuals remain fully accountable for any content or decisions made using generative AI. The AI is merely a tool, and it should never be used as a substitute for validated decision-making, especially when outcomes could significantly impact people's rights or welfare. This means robust human oversight is always essential.

Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.

What you must do — compliance checklist

0 / 13 marked complete

Plain-English obligations under Australia - Victoria - Generative AI Guidelines. Not legal advice — verify against the official text before relying on it.

  1. #1CriticalGovernance and Institutional FrameworkOngoing

    Applies to: In-scope Victorian Public Sector organisations.

    It requires each in-scope organisation (...) to: adopt local policies that meet or exceed the Guideline
  2. #2CriticalGovernance and Institutional FrameworkBefore using agency-approved tools

    Applies to: In-scope Victorian Public Sector organisations.

    establish approval processes to designate agency-approved tools
  3. #3CriticalKey Focus AreasBefore using publicly-available tools

    Applies to: Personnel using publicly-available generative AI tools.

    forbidding input of protected or non-public data into publicly-available tools
  4. #4CriticalKey Focus AreasBefore using agency-approved tools

    Applies to: In-scope Victorian Public Sector organisations.

    requiring protective marking controls for agency-approved solutions
  5. #5CriticalKey Focus AreasBefore tool approval

    Applies to: In-scope Victorian Public Sector organisations.

    requiring cyber assessments as part of tool approval
  6. #6CriticalKey Focus AreasOngoing

    Applies to: Personnel and in-scope Victorian Public Sector organisations.

    maintaining provenance, attribution and records of prompts and outputs incorporated into official work
  7. #7CriticalKey Focus AreasOngoing

    Applies to: In-scope Victorian Public Sector organisations.

    ensuring Generative AI use is compatible with the Victorian Charter of Human Rights and Responsibilities
  8. #8CriticalGovernance and Institutional FrameworkBefore acting inconsistently

    Applies to: Heads of in-scope Victorian Public Sector agencies.

    Heads of agencies notify the Secretary, DPC if they intend to act inconsistently with the Guideline
  9. #9CriticalKey Focus AreasOngoing

    Applies to: Personnel using generative AI in official work.

    warns against using generative AI as a substitute for validated decision-making, particularly where outcomes significantly impact rights
  10. #10ImportantImplementation FrameworkOngoing

    Applies to: In-scope Victorian Public Sector organisations.

    staff education and training modules (the Department of Government Services will supply adaptable modules)
  11. #11ImportantGovernance and Institutional FrameworkOngoing

    Applies to: In-scope Victorian Public Sector organisations.

    put in place monitoring, recordkeeping and reporting mechanisms
  12. #12ImportantMonitoring and EvaluationOngoing

    Applies to: In-scope Victorian Public Sector organisations.

    periodic audits of compliance with protective marking and data-sharing rules
  13. #13ImportantMonitoring and EvaluationOngoing

    Applies to: In-scope Victorian Public Sector organisations.

    mechanisms for personnel to report incidents or near-misses

© Regulations.AI — created on 13-Jun-2026