Energy and utility operators run AI across load forecasting, DER orchestration, predictive maintenance, outage prediction and smart-meter analytics on assets that Australia treats as critical infrastructure. That places AI decisions inside the Security of Critical Infrastructure regime, AEMO market and power-system security rules, AER customer protections, and the Privacy Act. The obligations below map the duties every Australian energy business should build into its AI governance now, each tied to a verified primary source.
9 obligations across the energy and utilities regulators. Map every AI system you run against each.
Responsible entities for critical electricity, gas and energy market operator assets must adopt and maintain a Critical Infrastructure Risk Management Program that identifies and mitigates material risks across cyber, personnel, supply chain and physical and natural hazards. AI systems that operate or protect these assets fall inside scope, so model failure, data poisoning and automation risk must be assessed and managed within the all-hazards program.
Source: SOCI CIRMP Rules 2023 (F2023L00112)The responsible entity must give the regulator an annual report on its risk management program within 90 days of the end of the financial year, and that report must be approved by the board, council or other governing body. AI governance controls sit inside this attested cycle, so directors carry personal sign-off accountability for how AI-related hazards are managed across the energy asset.
Source: Security of Critical Infrastructure Act 2018 (s 30AG)Responsible entities must notify the Australian Signals Directorate of a cyber security incident with a significant impact within 12 hours, and one with a relevant impact within 72 hours, of becoming aware of it. AI-driven or AI-targeted intrusions, model compromise and automated control failures that hit an energy asset trigger these mandatory clocks, so incident playbooks must treat AI events as reportable.
Source: CISC - SOCI Act cyber incident reportingThe Australian Energy Sector Cyber Security Framework, run by AEMO, lets electricity, gas and liquid-fuel participants assess and benchmark cyber maturity through an annual program, and a Level 2 AESCSF assessment is one of the frameworks a CIRMP can rely on. Governance of AI and machine-learning tooling, data pipelines and operational-technology models should be brought into the maturity assessment.
Source: AEMO - AESCSF framework and resourcesSmart-meter interval data, consumption profiles and customer records are personal information, so retailers and networks that are APP entities must collect, secure, use and disclose them under the Australian Privacy Principles. AI analytics that profile households from granular energy data must meet collection limits, notice, quality and security duties, and any eligible data breach must be reported to the OAIC and affected customers.
Source: Privacy Act 1988 (Cth)From 10 December 2026, where an APP entity uses personal information in a computer program to make, or substantially help make, a decision that could reasonably be expected to significantly affect an individual, its privacy policy must disclose the kinds of information used and decisions made. Energy uses such as automated credit, disconnection triage or hardship assessment must be surfaced in the policy.
Source: OAIC - APP 1 automated decision transparencyThe October 2025 Guidance for AI Adoption, which evolves the Voluntary AI Safety Standard, sets out six essential practices covering accountability, risk management, data governance, testing, transparency and human oversight. It is voluntary but is the benchmark Australian regulators point to for responsible AI, and energy operators should map their AI controls to the six practices to show due diligence.
Source: Guidance for AI Adoption (National AI Centre)The AER enforces the National Energy Retail Law and Rules across the participating jurisdictions, setting protections on billing accuracy, hardship, payment difficulty, disconnection limits and life-support registration. AI used for billing, debt scoring, disconnection decisions or customer communications must not breach these protections, and retailers stay accountable for automated outcomes that harm vulnerable or life-support customers.
Source: AER - retail regulation (Retail Law and Rules)Under the National Electricity Law and Chapter 4 of the National Electricity Rules, AEMO and network businesses must keep the power system in a secure operating state, including frequency near 50 hertz. AI and automation used in dispatch, forecasting, DER orchestration and control must not undermine these power-system security obligations, and their outputs need validation, fallback and human oversight.
Source: AEMC - National Electricity Rules chapter summariesEach obligation links to its primary or official source. Verified against Home Affairs / CISC, AEMO, AER, OAIC and the relevant Australian legislation, July 2026. General information, not legal advice: confirm your specific obligations with the regulator or your adviser.
Detailed analysis of the obligations that apply in this sector.
Bring every AI and machine-learning system that touches a critical electricity, gas or market-operator asset inside the CIRMP all-hazards register, with named owners and mitigations.
Add AI failure, model compromise and automation events to cyber incident playbooks and pre-wire the 12-hour and 72-hour SOCI notifications to the Australian Signals Directorate.
Map AI and operational-technology governance controls into the annual AESCSF assessment and target Level 2 maturity for CIRMP-relevant systems.
Update privacy policies before 10 December 2026 to disclose automated decisions affecting customers, covering credit, disconnection triage and hardship assessment.
Review AI used in billing, debt scoring and disconnection against AER Retail Law protections and protect life-support and hardship customers from automated harm.
Give the board an AI governance summary inside the section 30AG annual report so directors can attest to how AI-related hazards are managed.
Benchmark the AI control environment against the six practices in the October 2025 Guidance for AI Adoption and close the gaps.
The free AI Health Check maps your sector and the AI you actually use to the specific Australian duties you have triggered, then gives you a board-ready report. Your answers stay in your browser.
Take the free AI Health Check