Australian technology firms sit at the sharp end of AI regulation. The same product can trigger privacy, online-safety, consumer, data-portability, copyright and cyber-security duties at once, and several instruments are new for 2025 and 2026. This matrix maps the obligations that bite when you build, train, ship or embed AI, from the Privacy Act and eSafety codes to the automated-decision transparency duty commencing 10 December 2026. Every entry links to an official source.
9 obligations across the technology regulators. Map every AI system you run against each.
The 13 Australian Privacy Principles are the baseline for any tech business that handles personal information, including data used to train, fine-tune or run AI. They govern collection, notice, use and disclosure, quality, security and access. A breach of an APP is an interference with privacy that can draw regulatory action and civil penalties. Bake privacy into model pipelines, vendor contracts and default settings.
Source: OAIC: Australian Privacy PrinciplesFrom 10 December 2026, entities that use personal information in a computer program to make, or substantially help make, a decision that could reasonably be expected to significantly affect the rights or interests of an individual must disclose this in their privacy policy, covering the kinds of information and decisions involved. Inventory every automated decision now and rewrite the privacy policy before the date.
Source: Privacy and Other Legislation Amendment Act 2024Published 21 October 2025, the Guidance for AI Adoption evolves the Voluntary AI Safety Standard into six essential practices covering accountability, risk management, data governance, testing, transparency and human oversight. It is voluntary but is fast becoming the reference the regulators and enterprise buyers expect. Adopting it early is the most practical way to show a defensible AI governance posture and to prepare for future mandatory guardrails.
Source: DISR: Guidance for AI AdoptionRegistered industry codes and eSafety-made standards bind social media, hosting, search, app distribution, internet carriage and designated internet and relevant electronic services. They require measures against class 1 material such as child sexual exploitation and pro-terror content, increasingly including generative-AI outputs. eSafety can direct, register standards and enforce. If your platform hosts, generates or ranks content, confirm which code or standard applies and evidence compliance.
Source: eSafety: Register of Online Safety Codes and StandardsSection 18 prohibits misleading or deceptive conduct, and section 54 guarantees acceptable quality, both of which reach AI features and the claims made about them. The ACCC has moved on AI-related conduct, including its 2025 action alleging misleading representations over an AI-integrated subscription. Overstated model accuracy, hidden pricing tied to AI, or buggy AI in a product can breach the ACL. Substantiate every AI capability claim.
Source: ACCC: False or misleading claimsUnder Part IVD of the Competition and Consumer Act 2010, data holders must share designated consumer data on request, and accredited data recipients must pass ACCC accreditation and meet the CDR Rules and privacy safeguards. If AI models consume or generate CDR data, the consent, data minimisation and security duties flow through to the model. Map CDR data lineage and honour deletion and consent-withdrawal duties.
Source: ACCC: The Consumer Data RightAustralia has ruled out a text-and-data-mining exception, so training or fine-tuning on copyright material without a licence carries infringement risk. The Copyright and AI Reference Group is examining licensing, output ownership and cheaper enforcement, with priorities set on 28 October 2025. Track provenance of training data, secure licences, and record how AI-generated outputs are produced to manage authorship and infringement exposure.
Source: AGD: Copyright and AI Reference Group (CAIRG)The Cyber Security Act 2024 sets security standards for relevant connectable products, so manufacturers and suppliers of smart and IoT devices, including AI-enabled hardware, must meet mandatory requirements. It also imposes mandatory reporting after a ransomware payment for in-scope entities and enables limited-use information sharing with the National Cyber Security Coordinator. Confirm device compliance and stand up a ransomware-payment reporting process.
Source: Cyber Security Act 2024 (Federal Register)Under Part IIIC, an entity must notify affected individuals and the OAIC when an eligible data breach is likely to result in serious harm, and must assess suspected breaches with reasonable steps generally within 30 days. AI systems widen the attack surface through model endpoints, prompt logs and training stores. Include AI assets in the breach response plan and rehearse the assessment and notification workflow.
Source: OAIC: About the Notifiable Data Breaches schemeEach obligation links to its primary or official source. Verified against OAIC, eSafety, ACCC, Home Affairs and the relevant Australian legislation, July 2026. General information, not legal advice: confirm your specific obligations with the regulator or your adviser.
Detailed analysis of the obligations that apply in this sector.
Build an AI and automated-decision inventory now, then rewrite the privacy policy to meet the 10 December 2026 ADM transparency duty
Map every product against the Online Safety codes and standards and evidence the measures that apply to your service class
Substantiate all AI capability, accuracy and pricing claims so they survive ACCC scrutiny under ACL sections 18 and 54
Adopt the six essential practices in the Guidance for AI Adoption and record accountability, oversight and testing controls
Trace training-data provenance, secure copyright licences, and log how AI outputs are generated given no text-and-data-mining exception
Confirm smart and connectable products meet Cyber Security Act standards and stand up a ransomware-payment reporting process
Fold AI endpoints, prompt logs and model stores into the data-breach response plan and rehearse the 30-day assessment and OAIC notification
The free AI Health Check maps your sector and the AI you actually use to the specific Australian duties you have triggered, then gives you a board-ready report. Your answers stay in your browser.
Take the free AI Health Check