Australian government agencies face the tightest AI accountability regime in the country. Non-corporate Commonwealth entities must obey the DTA responsible-AI policy, name accountable officials, publish transparency statements and meet administrative-law duties of lawfulness, natural justice and reasons. The Robodebt Royal Commission showed what happens when automated systems bypass the law. Layered on top sit the Privacy Act, freedom-of-information duties and the protective security framework governing official data.
9 obligations across the government regulators. Map every AI system you run against each.
The Policy for the responsible use of AI in government (Version 2.0, December 2025) is mandatory for all non-corporate Commonwealth entities. Agencies must designate accountable officials, take a strategic and operational approach to AI, apply risk-based use-case actions and report new high-risk use cases. Accountable officials were required within the first implementation window and act as the whole-of-government contact point.
Source: DTA AI in government policy v2.0Under the DTA Standard for AI transparency statements, in-scope agencies must publish a statement on their public website by 28 February 2025 and keep it current. It must set out why the agency uses AI, classify uses by pattern and domain, flag where the public may be significantly affected without human review, and describe monitoring and safeguards. Agencies notify the DTA of publication and changes.
Source: DTA Standard for AI transparency statementsGovernment decisions, including those made or assisted by AI, must be lawful, procedurally fair and within power. The Administrative Decisions (Judicial Review) Act 1977 lets affected people seek review for breach of natural justice, improper exercise of power or error of law (s 5), and obtain a written statement of findings on material questions of fact and the reasons for the decision (s 13). Robodebt is the cautionary precedent.
Source: Administrative Decisions (Judicial Review) Act 1977The Privacy and Other Legislation Amendment Act 2024 adds an APP 1 duty commencing 10 December 2026. Where a computer program uses personal information to make, or substantially help make, a decision that could reasonably be expected to significantly affect the rights or interests of an individual, the privacy policy must disclose the kinds of information used and the kinds of decisions made. It applies to decisions made from that date.
Source: OAIC APP 1 automated decision guidanceAustralian Government agencies are APP entities bound by the Australian Privacy Principles across the AI lifecycle. Personal information may only be used or disclosed for a permitted purpose (APP 6), and agencies must take reasonable steps to protect it from misuse, interference, loss and unauthorised access (APP 11). Training data ingestion, model outputs and vendor arrangements all engage these duties and breach-notification obligations.
Source: OAIC Australian Privacy PrinciplesPublished 21 October 2025, the Guidance for AI Adoption sets out six essential practices for safe and responsible AI, evolving and simplifying the earlier Voluntary AI Safety Standard from ten guardrails. It covers accountability, risk management, data governance, testing and monitoring, human oversight, transparency and stakeholder engagement. It is voluntary but is the national benchmark regulators and courts are expected to reference when assessing reasonable AI governance.
Source: National AI Centre Guidance for AI AdoptionThe Technical standard for governments use of artificial intelligence brings together practices for designing, developing, deploying and using AI systems, embedding fairness, transparency and accountability as technical requirements across the whole AI lifecycle. Agencies apply it alongside the AI impact assessment tool and AI procurement guidance, which press for transparency over models, training data and decision logic when buying AI systems and services.
Source: DTA technical standard for AIThe Freedom of Information Act 1982 promotes open and accountable government. Agencies must proactively publish operational information under the Information Publication Scheme (s 8), including the rules and guidelines used to make decisions that affect the public. AI decision logic, business rules and models that drive administrative outcomes can be subject to access requests and publication, so agencies should document and version them accordingly.
Source: Freedom of Information Act 1982The Protective Security Policy Framework sets mandatory information-security requirements for Australian Government entities. Agencies must classify and handle official information correctly and safeguard ICT systems by applying the Australian Government Information Security Manual cyber principles across each system lifecycle. AI platforms, training datasets and model endpoints that hold or process official information must be secured, assessed and governed under these directions.
Source: PSPF information security policiesEach obligation links to its primary or official source. Verified against DTA, OAIC, Cwlth Ombudsman, AGD and the relevant Australian legislation, July 2026. General information, not legal advice: confirm your specific obligations with the regulator or your adviser.
Detailed analysis of the obligations that apply in this sector.
Designate accountable officials for AI under the DTA policy and register every high-risk use case with the accountable official for escalation
Publish and maintain a plain-English AI transparency statement on the agency website meeting the DTA Standard
Map each automated or AI-assisted decision to its enabling legislation and confirm a lawful basis, natural justice and a genuine human decision-maker where required
Build reason-giving into automated decisions so affected people can obtain a statement of findings and reasons under the ADJR Act
Update the agency privacy policy before 10 December 2026 to disclose automated decision-making that significantly affects rights or interests
Apply the six practices in the Guidance for AI Adoption and the AI technical standard across the AI lifecycle, including AI impact assessment
Secure training data and AI systems to the Protective Security Policy Framework and the Information Security Manual, and record AI use for FOI disclosure
The free AI Health Check maps your sector and the AI you actually use to the specific Australian duties you have triggered, then gives you a board-ready report. Your answers stay in your browser.
Take the free AI Health Check