Australia Isn’t Getting an AI Act: Here’s What Applies Instead

Australia’s position was settled in December 2025, when the National AI Plan did not propose a standalone AI Act and instead emphasised a technology-neutral governance model based on existing laws, regulatory guidance, safety frameworks, workplace protections, and targeted interventions. On 15 July 2026, the Prime Minister went further, announcing plans to legislate an Australian Standards for AI framework (initially directed at large data centres and AI training), and establishing an Office of AI within the Department of the Prime Minister and Cabinet. That announcement is not itself legislation and creates no general compliance duty for organisations using AI: National Cabinet is expected to consider the approach in August 2026, with standards anticipated to be legislated in early 2027. For businesses anxious about EU-style compliance obligations landing here, the message is not “less regulation”; it’s that existing law already applies, and buying AI from a vendor doesn’t shift your liability.

 

A lot of Australian businesses have spent the last two years bracing for an EU-style AI Act equivalent. It isn’t coming, at least not in that form. What has emerged instead is arguably more work for legal and compliance teams, not less: a standards-led approach that leans on laws you are already subject to, plus at least one hard commencement date already in the diary.

The Approach Australia Has Actually Taken

Rather than a single AI-specific statute with a mandatory high-risk regime, Australia’s National AI Plan leaves AI governance to existing, technology-neutral law, and will continue to until the announced Standards are actually legislated. The stack you are already subject to includes the Privacy Act 1988 (Cth), the Australian Consumer Law, anti-discrimination legislation, directors’ duties under the Corporations Act 2001 (Cth), sector regulators such as the TGA for AI-enabled software as a medical device, and APRA’s prudential standards on operational risk management and information security, CPS 230 and CPS 234. The Competition and Consumer Amendment (Unfair Trading Practices) Act 2026, which received assent on 6 July 2026 and commences 1 July 2027, adds a further layer for consumer-facing deployments. Government use of AI is governed far more prescriptively. The Digital Transformation Agency’s Policy for the Responsible Use of AI in Government introduced the first mandatory Commonwealth requirements from 15 June 2026 (AI impact assessments, AI procurement guidance and foundational AI training for all APS staff), and the APS AI Plan required non-corporate Commonwealth entities to appoint a Chief AI Officer by 30 June 2026. If you supply to government, expect those obligations to be pushed down to you through contract terms rather than through legislation.

For businesses, this means there is no single “AI compliance checklist” to work through. There is, instead, a requirement to map AI use against every sectoral and general law that already applies: privacy, discrimination, consumer law, and directors’ duties among them.

There is also one hard date that tends to surprise businesses who have been waiting for an AI Act. From 10 December 2026, new Australian Privacy Principles 1.7 to 1.9 (inserted by the Privacy and Other Legislation Amendment Act 2024) require an APP entity to disclose in its privacy policy where it has arranged for a computer program to make, or do something substantially and directly related to making, a decision that could reasonably be expected to significantly affect an individual’s rights or interests, together with the kinds of personal information and kinds of decisions involved. Two points are routinely missed. First, the obligation is not AI-specific: rules-based software that scores an application qualifies just as readily as a machine learning model. Second, the OAIC’s May 2026 Issues Paper commenced consultation on guidance for the automated decision-making transparency obligation, including questions about its scope, with final guidance expected around September 2026. The obligation is due to commence on 10 December 2026, although the consultation page does not specify exactly when the final guidance will be issued.

The Point Too Many Businesses Are Missing

The misconception I encounter most often when reviewing vendor AI terms is that buying a tool from a reputable supplier transfers the compliance risk to that supplier. It doesn’t. If a third-party recruitment tool produces a discriminatory hiring outcome, or a customer-facing AI tool makes an unfair decision, accountability in Australia sits with the business that deployed it. The Privacy Act, the Australian Consumer Law and anti-discrimination legislation attach to the entity that makes the decision, not the entity that built the model. The decision entity remains just that, the AI model is merely another tool that entity deploys in its operations. A vendor indemnity allocates cost between the parties after the fact; it does not transfer the obligation, and a regulator will not accept it as an answer.

What This Means in Practice

  • Don’t wait for AI-specific legislation: map current AI use against the Privacy Act, sector regulator expectations, and general consumer and employment law now. The National AI Centre’s Guidance for AI Adoption (October 2025) and its six essential practices are the closest thing I have found to a government-endorsed baseline, having evolved the 2024 Voluntary AI Safety Standard; ISO/IEC 42001 is the certifiable equivalent if you need something you can evidence to a customer or a regulator.
  • Treat vendor AI tools as a governance responsibility, not a procurement decision to close out and forget.
  • If your business is regulated by a sector body (financial services, health, government contracting), check that body’s existing AI guidance specifically.
  • Diarise 10 December 2026. Updating the privacy policy is a short exercise; building the inventory of rights-affecting automated decisions that makes the disclosure defensible is not, and that is the work the deadline is really asking for.
  • Revisit AI use as the Australian Standards for AI framework develops (National Cabinet considers the approach in August 2026, with legislation expected in early 2027), but don’t treat its absence today as an absence of obligation.

Disclaimer

This article is general information only and is not legal advice. It summarises publicly announced government policy positions current as at 8 August 2026, which may be further developed or changed; the Australian Standards for AI framework in particular has not yet been drafted or introduced to Parliament. Obtain advice for your organisation’s specific use of AI before acting.

Share :

About the author

Kirsten Dilena

Kirsten Dilena is the founder and principal lawyer at DLC Legal, a boutique commercial and regulatory practice advising on governance, compliance, cybersecurity and data privacy law, and government procurement. With 20+ years of legal experience across government, defence, and commercial and emerging technology sectors, Kirsten helps regulated businesses build compliance architecture that is proportionate, defensible, and workable.