An Australian company that has spent the past two years building its AI governance program around the National AI Centre's voluntary AI6 guidance, the Privacy Act 1988 (Cth), and whichever sector regulator applies to it, such as APRA, ASIC or the TGA, is about to encounter a fundamentally different regulatory logic the moment its AI system's output reaches a user in the European Union. That shift is not gradual. It is structural: from a voluntary, principles-based framework layered over existing sector law, to a binding, risk-tiered regulation with fixed obligations, fixed deadlines, and fines calculated as a percentage of global turnover. This guide sets out what changes, when it changes, and what an Australian compliance team should do first, using Germany, the Netherlands, Spain and France as illustrations of how the same EU-level law is administered differently once a company actually operates inside a given member state.

The structural shift: from voluntary alignment to binding law

In Australia, there is no standalone AI statute. AI governance obligations are assembled from the Privacy Act 1988 (Cth), enforced by the Office of the Australian Information Commissioner (OAIC), sitting alongside sector-specific binding rules such as APRA's CPS 230 for regulated financial entities, ASIC's conduct obligations for financial services, the Therapeutic Goods Administration (TGA) for AI in medical devices, the Fair Work Commission for AI-affected employment disputes, and state-based statutes such as the NSW Workplace Surveillance Act 2005. Layered over this binding patchwork is the National AI Centre's voluntary AI6 Guidance for AI Adoption, which recommends governance practices but imposes no penalty for non-adherence in itself. A company can be fully compliant with Australian law while never having conducted a mandatory conformity assessment or filed a technical file with any regulator.

The EU AI Act (Regulation (EU) 2024/1689) inverts this. It is a single binding regulation that applies uniformly across all EU member states, classifies AI systems into risk tiers with defined legal obligations attached to each tier, and backs those obligations with fines set as the higher of a fixed euro amount or a percentage of worldwide annual turnover. There is no voluntary tier for systems that meet a high-risk or prohibited classification. For an Australian company, the mental model has to change from "what does good practice look like" to "which tier does this system fall into, and what does the Act require before I can place it on, or make its output available in, the EU market."

The extraterritorial trigger: presence in the EU is not required

The provision that most surprises Australian companies is Article 2 of the Act, which extends its scope to providers and deployers established in a third country where the output produced by their AI system is used in the Union. Physical presence, a local subsidiary, or even a direct sales relationship with an EU customer is not the trigger. If an Australian company's chatbot answers a query from a user in Germany, if its recommendation engine ranks products for a shopper in the Netherlands, or if its recruitment-screening tool scores a candidate applying from Spain, the Act's extraterritorial hook applies to that AI system regardless of where the company's servers, staff or headquarters sit. Providers established outside the EU that place a high-risk AI system on the EU market must also appoint an authorised representative established in the Union under Article 22, a written-mandate role responsible for holding technical documentation, cooperating with regulators, and meeting registration obligations on the provider's behalf. Placing a high-risk system on the market without one is itself a breach carrying fines of up to 15 million euros or 3 percent of global turnover.

Risk tiers and the penalty structure

The Act sorts AI systems into four bands: unacceptable risk (prohibited outright), high risk (subject to conformity assessment, technical documentation, human oversight and registration duties), limited risk (subject to transparency obligations under Article 50), and minimal risk (largely unregulated). Prohibited practices, covering manipulative systems, exploitation of vulnerabilities, social scoring by public authorities and unauthorised biometric identification in public spaces, have been in force since 2 February 2025. Obligations on general-purpose AI (GPAI) models have applied since 2 August 2025. Penalties are tiered to match under Article 99: prohibited practices draw fines of up to 35 million euros or 7 percent of total worldwide annual turnover, whichever is higher; most other obligations carry fines up to 15 million euros or 3 percent; and supplying incorrect information to regulators carries fines up to 7.5 million euros or 1 percent. For SMEs and start-ups, the calculation flips to whichever figure is lower rather than higher. This is a materially different exposure profile from the Privacy Act's serious-interference penalty of the greater of 50 million dollars, three times the benefit obtained, or 30 percent of adjusted turnover during the breach period, and an Australian compliance team should not assume the two regimes are interchangeable simply because both scale with turnover.

The Digital Omnibus timeline: what moved and what did not

In 2026, the EU adopted a "Digital Omnibus" simplification package that pushed back several of the Act's harder deadlines without touching the ones already in force. The Council of the European Union gave final approval to the package on 29 June 2026, deferring the compliance deadline for stand-alone high-risk systems under Annex III from 2 August 2026 to 2 December 2027, and deferring high-risk obligations for AI embedded in regulated products under Annex I to 2 August 2028. What the Omnibus did not move is Article 50. Transparency obligations, including chatbot disclosure, labelling of AI-generated or manipulated content, and deepfake marking, remain enforceable from 2 August 2026 as originally scheduled. An Australian company that reads "high-risk deadlines delayed to 2027" and concludes it has an extra eighteen months across the board will miss the transparency obligations that bind in a matter of days from the date of this guide.

DateWhat becomes binding
2 February 2025Prohibited AI practices (already in force)
2 August 2025General-purpose AI model obligations (already in force)
2 August 2026Article 50 transparency obligations: chatbot disclosure, synthetic content labelling, deepfake marking
2 December 2027High-risk obligations for stand-alone Annex III systems
2 August 2028High-risk obligations for AI embedded in Annex I regulated products

The national layer: one Act, different regulators

The AI Act is a regulation, directly applicable across the EU without national transposition, but enforcement runs through national competent authorities that each member state designates under Article 70. This is where the practical experience of compliance diverges sharply depending on which country an Australian company actually establishes in, appoints an authorised representative in, or does the bulk of its EU business through.

Germany has taken a centralised, single-regulator approach through its AI Market Surveillance and Innovation Promotion Act (KI-MIG). The Federal Cabinet adopted the draft law on 11 February 2026, and the Bundestag passed it on 11 June 2026. The Bundesrat gave its consent at its 1067th session on 10 July 2026, declining to call the mediation committee. The law has therefore cleared all three stages, Cabinet, Bundestag and Bundesrat, and is now awaiting only promulgation and entry into force, not further Bundesrat review. Under KI-MIG, the Bundesnetzagentur (BNetzA) becomes the default market surveillance authority, the single point of contact to the EU AI Office, and the central complaints office, supported by a new internal Coordination and Competence Centre (KoKIVO) that pools AI expertise for other sector regulators to draw on. A company dealing primarily with Germany should expect one central regulatory relationship rather than a fragmented sectoral one.

The Netherlands instead built its model around its existing data protection authority. The Autoriteit Persoonsgegevens (AP) has served as the coordinating supervisor for algorithms and AI carrying fundamental-rights risk since 2023, operating through its Department for the Coordination of Algorithmic Oversight (DCA) and working alongside the Rijksinspectie Digitale Infrastructuur (RDI) on technical market surveillance, while existing sectoral regulators retain oversight within their own domains. The Netherlands is also notable for its public algorithm register covering government AI use, a transparency instrument that goes beyond what the Act itself requires and signals the AP's broader appetite for algorithmic accountability.

Spain took the most distinctive path by creating a wholly new, dedicated regulator. The Agencia Española de Supervisión de la Inteligencia Artificial (AESIA), established by Royal Decree 729/2023 and operational since June 2024, was the EU's first dedicated national AI supervisory agency, acting as Spain's single contact point to the European Commission and running its own regulatory sandbox for companies testing AI systems before formal high-risk obligations bite. An Australian company entering Spain deals with an AI-specialist regulator from day one, not a data protection authority or a network regulator with AI added to its remit.

France, by contrast, had not finalised its designated authority as of mid-2026. The government's proposed framework is decentralised, splitting supervisory responsibility by sector and designating the Direction générale de la concurrence, de la consommation et de la répression des fraudes (DGCCRF) as the single point of contact coordinating a set of sectoral regulators, including the CNIL for personal-data-related AI uses, ARCOM for digital content, ANSSI for cybersecurity, and the HAS for AI embedded in medical devices. This proposal still requires parliamentary adoption, meaning a company operating in France in mid-to-late 2026 should expect the supervisory landscape to keep shifting even as the underlying EU-level obligations do not.

The practical lesson is that "EU AI Act compliance" is not a single relationship to manage. It is the same substantive obligations administered through up to four distinct regulatory postures across just these four markets, ranging from Germany's single strong central authority, to the Netherlands' privacy-regulator-led coordination model, to Spain's AI-specialist agency, to France's still-forming, sector-split coordination structure.

Concrete first steps for an Australian compliance team

  1. Map every AI system by where its output actually lands. Under Article 2, the test is not where the company is based but where the output is used. Any system whose responses, scores, rankings or generated content reach a user physically in the EU should be treated as in scope, regardless of billing address or contract governing law.
  2. Classify each in-scope system against the Act's four risk tiers now, rather than waiting for the December 2027 or August 2028 deadlines. Systems touching employment decisions, credit, biometric identification or safety components of regulated products are the most likely candidates for the high-risk Annex III or Annex I categories.
  3. Check immediately for prohibited-practice exposure. These obligations have applied since February 2025 and were not touched by the Digital Omnibus. Manipulative interface design, inferred emotion detection in workplaces, or social-scoring-adjacent features carry the Act's highest penalty tier now, not in 2027.
  4. Prioritise Article 50 transparency work ahead of 2 August 2026. This is the nearest binding deadline that was not deferred. Any AU-built chatbot, generative content tool, or synthetic media feature reaching EU users needs disclosure and labelling mechanisms built and tested well before that date.
  5. Appoint an EU authorised representative under Article 22 if the company has no EU establishment and any system qualifies as high-risk, and decide which member state that representative should sit in based on the regulatory posture the company can most efficiently work with, rather than defaulting to wherever the first EU customer happens to be.
  6. Identify the actual national competent authority for each market of operation. A company entering through Germany should build a KI-MIG-literate relationship with the Bundesnetzagentur; through the Netherlands, expect the AP's Department for the Coordination of Algorithmic Oversight and RDI to be the working contacts; through Spain, expect AESIA and its sandbox process; through France, track the DGCCRF/CNIL/ARCOM coordination model as it is finalised.
  7. Cross-map EU obligations against existing Australian controls. Data governance documentation built for APRA CPS 230 or ASIC conduct obligations will partially, but not fully, satisfy the Act's technical documentation and human-oversight requirements for high-risk systems; gaps should be identified now rather than at conformity-assessment stage.
  8. Build the compliance calendar around both deadlines, not one. Track 2 August 2026 for transparency, and 2 December 2027 and 2 August 2028 for high-risk obligations, as separate workstreams with separate owners, since the deferral of the high-risk deadlines does not reduce the urgency of the transparency deadline.

The overarching change for an Australian company is not merely a new compliance checklist. It is a shift in regulatory posture, from a domestic environment where AI governance is substantially self-directed and enforcement runs through general privacy and sector law, to a market where a single binding regulation sets fixed risk classifications and fixed penalties, administered through national authorities whose expectations and working style differ meaningfully by country. Getting the extraterritorial trigger, the transparency deadline and the correct national contact point right early is considerably cheaper than discovering any of the three after the fact.

Primary sources

Related articles