The regulatory shift: what the December 2025 National AI Plan changed
In September and October 2024, the Australian Government consulted on a proposals paper for introducing mandatory guardrails for high-risk AI, a formal regulatory framework that many organisations were preparing for. The Department of Industry, Science and Resources now states that the government will not proceed at this time with those proposals, and that feedback on the paper informed the National AI Plan released on 2 December 2025. The Plan builds on Australia's existing, largely technology-neutral legal and regulatory frameworks, with regulators responsible in their own domains, targeted laws where needed, the voluntary Guidance for AI Adoption (AI6) and a new Australian AI Safety Institute (AISI).
Update, 15 July 2026: In a speech at the University of Sydney, Prime Minister Albanese announced that the government will establish a set of Australian Standards for AI and, effective that day, an Office of AI in the Department of the Prime Minister and Cabinet. As the speech describes them, the standards will protect Australian creators' control of their work used to train AI and set rules for where large data centres are built and the power and water they use, bringing the March 2026 data centre expectations into one framework the Prime Minister called "clear, consistent and mandatory". He will seek agreement at National Cabinet and aims to bring legislation to Parliament early in 2027, while saying it is not the government's goal "to try and legislate for every possible eventuality or risk". The speech does not mention the 2024 mandatory guardrails proposal. Read the speech.
The Plan's approach can be summarised as: existing laws apply to AI just as they apply to other technologies; the Privacy Act, ACL, sector regulation, and common law all already govern AI to a significant degree; where gaps emerge, the government says it will continue to update and introduce targeted laws where needed. The AISI, which the government said would become operational in early 2026, provides technical information and insights to support regulators and agencies.
Why "voluntary" doesn't mean "optional" for enterprises
The gap between what the law formally requires and what organisations must do in practice is narrower than it appears. Several mechanisms are tightening it. Enterprise buyers, particularly in financial services, healthcare, and government, are incorporating AI governance evidence into vendor assessments. Directors' duties under the Corporations Act apply to material risks, and AI is increasingly material. The OAIC (Office of the Australian Information Commissioner), ACCC, APRA (Australian Prudential Regulation Authority), ASIC (Australian Securities and Investments Commission), and the Fair Work Commission all have existing powers that apply to AI-related harms, and AI6 is the government's own guidance on governing AI responsibly within those laws.
APRA's April 2026 letter to industry warned that governance, risk management, assurance and operational resilience practices are not keeping pace with AI adoption. The Federal Court ordered Trivago to pay A$44.7 million in penalties in proceedings brought by the ACCC for misleading consumers over hotel room rates, where an algorithm placed significant weight on which booking sites paid Trivago the highest cost-per-click fee. The OAIC has made determinations against Bunnings and Kmart over facial recognition, with the Bunnings consent finding set aside on review in 2026. This is not a passive enforcement environment.
The Privacy Act reform: the one new obligation that is coming
The Privacy and Other Legislation Amendment Act 2024, which received Royal Assent on 10 December 2024, adds a requirement (new APP 1.7) that privacy policies describe decisions that a computer program makes, or does a thing substantially and directly related to making, where the decision could reasonably be expected to significantly affect an individual's rights or interests. This comes into effect in December 2026. It is not voluntary. For organisations using AI in consequential decisions, credit assessment, employment screening, insurance underwriting, service access decisions, this creates a specific, legally required disclosure obligation. Most organisations' current privacy policies do not address this. Updating them should be a priority before December 2026.
The strategic advantage for early movers
The regulatory retreat from mandatory guardrails creates genuine uncertainty about where Australian AI regulation will land, and this uncertainty itself is a governance risk. Organisations that have invested in strong AI governance, documented frameworks, clear accountability, monitoring, human oversight of high-risk decisions, are well-positioned regardless of how the regulatory landscape evolves. Those that interpret the voluntary framework as permission to wait are accumulating governance debt that will be more expensive to discharge when formal requirements eventually come. And on current trajectory, globally and domestically, they will come.
Related reading
- Australia's AI Safety Standard: What It Actually Requires and Who It Applies To
- EU AI Act vs Australia: Two Approaches to AI Governance and What It Means for Your Organisation
- AI Governance in New Zealand: Privacy Act, Algorithmic Decision-Making, and the NZ Framework
Further reading: OECD AI Principles