Why the standard changed

The 2024 Voluntary AI Safety Standard was published while the government consulted on proposals for mandatory guardrails in high-risk settings, and the Department of Industry said adopting its guardrails would make it easier to comply with any potential future regulatory requirements. On 21 October 2025 the National AI Centre published the Guidance for AI Adoption as the first update to that standard. The government has since said it will not proceed at this time with the mandatory guardrails proposals, and the National AI Plan of December 2025 builds on existing laws. On 15 July 2026 the Prime Minister announced Australian Standards for AI, covering creators' control of their work used to train AI and rules for large data centres, and an Office of AI within the Department of the Prime Minister and Cabinet, with legislation aimed for Parliament in early 2027. The speech does not mention the guardrails proposal.

In the update, the National AI Centre says it condensed the 10 guardrails into 6 essential practices, removed redundant language and expanded the audience to developers as well as deployers. There are two versions: Foundations, for organisations in the early stages of adopting AI, and Implementation guidance, for teams that build or customise AI systems, use AI in more complex ways or manage higher-risk use cases.

The six essential practices

1. Decide who is accountable. The guidance starts from the point that your organisation is ultimately accountable for how and where AI is used. It asks you to assign, document and communicate who is accountable across the organisation, including contractors and third-party providers, to define each accountable person's competencies and authority, to set out accountabilities across the AI supply chain, to train staff, and to maintain an AI governance framework.

2. Understand impacts and plan accordingly. Because AI operates at speed and scale, a single system can cause widespread harm, such as a biased hiring shortlist. This practice covers identifying and engaging stakeholders, documenting each system's scope and potential benefits and harms, and establishing feedback, contestability and redress processes, then monitoring them for systemic issues.

3. Measure and manage risks: implement AI-specific risk management. Risks change with the type of system and how it is used. The guidance calls for a fit-for-purpose risk management framework, a triage of which systems may pose enhanced or unacceptable risk, a risk assessment for each system including those procured from third parties, risk treatment plans and controls, and incident monitoring and reporting, including under the Notifiable Data Breaches scheme.

4. Share essential information. People should know when they are interacting with AI and when AI decisions affect them. This practice includes an organisation-wide AI register, transparency and explainability for each system, supply chain transparency between developers and deployers, and transparency about AI-generated content. Separately, from 10 December 2026 new APP 1.7 requires privacy policies to address decisions that a computer program makes, or does a thing substantially and directly related to making, where the decision could reasonably be expected to significantly affect an individual's rights or interests.

5. Test and monitor. AI systems can change their behaviour over time. The guidance covers pre-deployment testing against defined acceptance criteria, documented deployment authorisation, monitoring system performance, additional testing proportionate to risk, and robust data and cybersecurity measures.

6. Maintain human control. AI systems need human oversight to operate safely, and the person overseeing a system should know how to override it if something goes wrong. The practice covers human oversight and control, and decommissioning systems when appropriate, as part of responsible AI use.

How AI6 relates to the old 10 guardrails

The National AI Centre describes the guidance as the first update to the VAISS, condensing its 10 guardrails into 6 practices. Organisations that built governance around the original guardrails can map that work across to the practices rather than rebuild it.

The visible differences are structure and audience: six practices in place of ten guardrails, a lifecycle view that runs through to decommissioning (practice 6.2), an audience that now includes developers as well as deployers, and two versions of the guidance, Foundations and Implementation guidance.

The AISI: Australia's new AI safety body

The Australian AI Safety Institute was backed by a A$29.9 million commitment, announced with the National AI Plan, to become operational in early 2026. The Department of Industry says it monitors and analyses emerging AI capabilities, with a focus on advanced and frontier AI models, and provides technical information and insights to support regulators and agencies; the government has said it will advise where updates to legislation might be needed.

Internationally, the Institute participates in the International Network for Advanced AI Measurement, Evaluation and Science, formerly called the International Network of AI Safety Institutes, and collaborates on AI safety and security under memorandums of understanding with frontier AI labs.

Related reading

Further reading: Australian Government, Guidance for AI Adoption (the 2024 Voluntary AI Safety Standard remains available as a legacy detailed control catalogue)