Australia - Victoria - Generative AI Guidelines
Administrative Guideline for the safe and responsible use of Generative Artificial Intelligence in the Victorian Public Sector
Australia
RAI-AU-VI-ASRUGXX-2024A principles-based administrative guideline issued by the Victorian Government (made by the Secretary, Department of Premier and Cabinet) establishing minimum requirements and safeguards for the use of generative AI across the Victorian Public Sector (VPS). It mandates use of agency-approved tools where possible, limits data inputs for public tools to publicly-available information, requires training, monitoring and compliance with existing privacy, records and human-rights law, and aligns VPS practice with Australia’s national AI assurance framework.
Summary
Read full text ↗Plain English
Overview
The Administrative Guideline for the safe and responsible use of Generative Artificial Intelligence in the Victorian Public Sector provides minimum whole-of-government direction for using generative AI in official Victoria Public Sector (VPS) work. It was endorsed by the Victorian Secretaries Board on 24 September 2024 and made by the Secretary, Department of Premier and Cabinet on 27 November 2024. The document adopts a principles-based approach aligned with Australia's AI Ethics Principles and the National AI Assurance Framework and distinguishes agency-approved tools from publicly-available tools, sets data sharing limits, requires training and monitoring, and reaffirms that personnel remain accountable for decisions and outputs when using generative AI.
Definitions
The Guideline defines key terms for consistent application across the VPS: "Generative AI" (models that generate text, images, code, audio or other data in response to prompts); "Agency-approved Generative AI tools" (tools assessed and authorised by an in-scope organisation after privacy, cybersecurity and legal review); "Publicly-available Generative AI tools" (third-party services not procured by government); "Official Work" (any tasks performed as part of VPS employment); "Publicly-available information" (data already public or approved for release); and "Personnel" (employees, contractors, consultants and volunteers who may access public sector information). These definitions are designed to be practically applied across procurement, information security and operational workflows.
Governance and Institutional Framework
The Guideline is issued within the Department of Premier and Cabinet (DPC) administrative framework and implementation support is led by the Department of Government Services (DGS). It requires each in-scope organisation (public service bodies and public entities under the Public Administration Act 2004) to: adopt local policies that meet or exceed the Guideline; establish approval processes to designate agency-approved tools; document roles and responsibilities for AI use; and put in place monitoring, recordkeeping and reporting mechanisms. It also mandates alignment with regulator guidance (for example from the Office of the Victorian Information Commissioner and the Victorian Public Sector Commission), and that Heads of agencies notify the Secretary, DPC if they intend to act inconsistently with the Guideline in accordance with s36A(3) Public Administration Act 2004.
Key Focus Areas
The Guideline concentrates on a set of risk and practice domains: (1) data protection and privacy — forbidding input of protected or non-public data into publicly-available tools and requiring protective marking controls for agency-approved solutions; (2) human rights and fairness — ensuring Generative AI use is compatible with the Victorian Charter of Human Rights and Responsibilities; (3) cybersecurity and model security — requiring cyber assessments as part of tool approval; (4) transparency and documentation — maintaining provenance, attribution and records of prompts and outputs incorporated into official work; (5) accountability and oversight — clarifying that personnel remain accountable for content and decisions; and (6) training, monitoring and recordkeeping to support safe adoption. The Guideline also explicitly warns against using generative AI as a substitute for validated decision-making, particularly where outcomes significantly impact rights, welfare, or legal status.
Implementation Framework
In-scope organisations must implement the Guideline through a practical plan that includes: a documented approval process for agency-approved tools (covering privacy, cyber, legal, commercial and IP review); protective marking and data-handling rules per tool; staff education and training modules (the Department of Government Services will supply adaptable modules); monitoring and audit controls to record usage and detect inappropriate input of sensitive information; and risk-assessment and assurance procedures aligned to the National AI Assurance Framework. The Guideline permits tailored, sector-specific measures where required (for example, Department of Education schools use school-specific guidance) and encourages adoption by special bodies where helpful. Practical implementation guidance is available at the complementary guidance page maintained by DGS (Guidance for the safe and responsible use of generative AI in the VPS).
Monitoring and Evaluation
Organisations are expected to monitor both agency-approved and publicly-available generative AI usage to ensure compliance and to inform continuous improvement. Monitoring must be carried out consistent with surveillance principles and privacy law, and should include logging prompts and outputs used in official work, periodic audits of compliance with protective marking and data-sharing rules, post-use quality checks and mechanisms for personnel to report incidents or near-misses. Evaluation is iterative: the Guideline will be reviewed periodically and material changes will be approved by the Victorian Secretaries Board; DGS will update the practical guidance and training materials concurrently.
Penalties, Liability, and Appeals
Although the Guideline itself is an administrative instrument rather than primary legislation, non-compliance may lead to breaches of VPS Codes of Conduct, disciplinary action, administrative directions under the Public Administration Act 2004, and potential statutory enforcement (for example, privacy investigations by OVIC where data breaches occur). The Guideline points to legal exposure related to privacy, health records, public records, human rights, and intellectual property, and suggests agencies involve legal counsel where necessary. Heads of in-scope organisations must provide written reasons to the Secretary, DPC under s36A(3) if operating inconsistently with the Guideline. Appeals and contestability processes for decisions materially affecting individuals remain available through existing administrative law and review mechanisms.
Relationship to Other Instruments
The Guideline is expressly intended to be read alongside several statutory and policy instruments: the Public Administration Act 2004 (scope and administrative mechanisms), Privacy and Data Protection Act 2014 and Health Records Act 2001 (data protection obligations), Public Records Act 1973 (recordkeeping duties), Freedom of Information Act 1982 (transparency obligations) and the VPS Codes of Conduct (standards of behaviour and accountability). It also references the national-level National AI Assurance Framework and Australia’s AI Ethics Principles, encouraging alignment with federal initiatives while retaining state-specific operational requirements.
International Alignment
The Guideline aligns Victoria’s approach with broader national and international AI governance trends by referencing Australia’s national AI Ethics Principles and the National AI Assurance Framework. It encourages practices consistent with international norms for safety, transparency, accountability and human-rights protection and aims to make procurement, risk assessment and assurance processes interoperable with standards likely to be adopted in other jurisdictions. Where cross-border data flows or foreign-operated tools are involved, the Guideline emphasises careful legal and privacy review, vendor due diligence, and attention to jurisdictional data storage and use terms.
Implementation Timeline
| Milestone | Date | Notes |
|---|---|---|
| VSB endorsement | 2024-09-24 | Endorsed by Victorian Secretaries Board |
| Made by Secretary, DPC (formal issue) | 2024-11-27 | Instrument issue date |
| Guidance published | 2024-11-27 | Companion guidance live at DGS site |
| Website update (status/FAQ) | 2025-02-12 | Vic.gov.au page updated with clarifications |
| Periodic review | Ongoing (annually or as required) | Material changes returned to VSB for endorsement |
Compliance Checklist
| Action | Compliant | Notes |
|---|---|---|
| Designate agency-approved Generative AI tools | Yes / No | Document assessments (privacy, cyber, legal, IP) |
| Restrict inputs to public info for public tools | Yes / No | Enforce via network controls and training |
| Protective marking applied for agency tools | Yes / No | Set marking thresholds per tool |
| Personnel training completed | Yes / No | Use DGS modules or agency-adapted equivalents |
| Usage logging and recordkeeping | Yes / No | Keep prompts, outputs and provenance for official documents |
| Periodic audit & risk review | Yes / No | Schedule assurance aligned to National AI Assurance Framework |
Sources and References
This administrative guideline sets out minimum rules and safeguards for how generative artificial intelligence (AI) can be used by all employees, contractors, and volunteers across the Victorian Public Sector (VPS) in their official work.
The guideline applies to all Victorian public service bodies and public entities, as well as their personnel. It officially took effect on November 27, 2024.
At its core, the guideline mandates several key practices. Organisations must use agency-approved generative AI tools whenever possible. Crucially, personnel are strictly prohibited from inputting protected or non-public data into publicly available generative AI services. All use of generative AI must comply with existing laws, including those covering privacy, human rights, and public records. Each VPS organisation is also required to develop its own local policies, establish clear approval processes for AI tools, provide staff training, and implement monitoring and record-keeping systems.
While this is an administrative guideline, not a primary law, ignoring its requirements can have serious consequences. Non-compliance could lead to breaches of the VPS Code of Conduct, disciplinary action, and administrative directions. More broadly, it could expose individuals and agencies to legal liabilities under privacy, health records, human rights, or intellectual property laws, potentially triggering investigations by regulators like the Office of the Victorian Information Commissioner.
A key takeaway for anyone using these tools is that individuals remain fully accountable for any content or decisions made using generative AI. The AI is merely a tool, and it should never be used as a substitute for validated decision-making, especially when outcomes could significantly impact people's rights or welfare. This means robust human oversight is always essential.
Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.
What you must do — compliance checklist
0 / 13 marked completePlain-English obligations under Australia - Victoria - Generative AI Guidelines. Not legal advice — verify against the official text before relying on it.
- #1CriticalGovernance and Institutional Framework⏰ Ongoing
Applies to: In-scope Victorian Public Sector organisations.
“It requires each in-scope organisation (...) to: adopt local policies that meet or exceed the Guideline”
- #2CriticalGovernance and Institutional Framework⏰ Before using agency-approved tools
Applies to: In-scope Victorian Public Sector organisations.
“establish approval processes to designate agency-approved tools”
- #3CriticalKey Focus Areas⏰ Before using publicly-available tools
Applies to: Personnel using publicly-available generative AI tools.
“forbidding input of protected or non-public data into publicly-available tools”
- #4CriticalKey Focus Areas⏰ Before using agency-approved tools
Applies to: In-scope Victorian Public Sector organisations.
“requiring protective marking controls for agency-approved solutions”
- #5CriticalKey Focus Areas⏰ Before tool approval
Applies to: In-scope Victorian Public Sector organisations.
“requiring cyber assessments as part of tool approval”
- #6CriticalKey Focus Areas⏰ Ongoing
Applies to: Personnel and in-scope Victorian Public Sector organisations.
“maintaining provenance, attribution and records of prompts and outputs incorporated into official work”
- #7CriticalKey Focus Areas⏰ Ongoing
Applies to: In-scope Victorian Public Sector organisations.
“ensuring Generative AI use is compatible with the Victorian Charter of Human Rights and Responsibilities”
- #8CriticalGovernance and Institutional Framework⏰ Before acting inconsistently
Applies to: Heads of in-scope Victorian Public Sector agencies.
“Heads of agencies notify the Secretary, DPC if they intend to act inconsistently with the Guideline”
- #9CriticalKey Focus Areas⏰ Ongoing
Applies to: Personnel using generative AI in official work.
“warns against using generative AI as a substitute for validated decision-making, particularly where outcomes significantly impact rights”
- #10ImportantImplementation Framework⏰ Ongoing
Applies to: In-scope Victorian Public Sector organisations.
“staff education and training modules (the Department of Government Services will supply adaptable modules)”
- #11ImportantGovernance and Institutional Framework⏰ Ongoing
Applies to: In-scope Victorian Public Sector organisations.
“put in place monitoring, recordkeeping and reporting mechanisms”
- #12ImportantMonitoring and Evaluation⏰ Ongoing
Applies to: In-scope Victorian Public Sector organisations.
“periodic audits of compliance with protective marking and data-sharing rules”
- #13ImportantMonitoring and Evaluation⏰ Ongoing
Applies to: In-scope Victorian Public Sector organisations.
“mechanisms for personnel to report incidents or near-misses”
Related Regulations
Guidance for the use of artificial intelligence in Tasmanian Government
Australia93% similar
Responsible AI Guidance for the Public Service: GenAI
New Zealand93% similar
Policy for the responsible use of AI in government
Australia92% similar
Buenos Aires Province Generative AI Guidelines
Argentina92% similar
Artificial Intelligence (AI) Technologies and Recordkeeping Policy
Australia92% similar
© Regulations.AI — created on 13-Jun-2026