Practical AI governance guides, regulatory analysis, and research, for enterprise leaders, businesses, and individuals navigating the AI landscape.
Boards, APRA, ASIC, controls & programmes
Start herePrivacy Act, ACCC consumer law, AI6 basics
Start hereFounder guide, investor due diligence, EU AI Act
Start hereYour rights, Right to Disconnect, AI at work
Start hereAn AI scribe or diagnostic aid does not take on your professional obligations. Under the Health Practitioner Regulation National Law, AHPRA and the National Boards regulate your conduct, and you remain the accountable clinician when you use a tool.
Read article2026
The Online Safety Act 2021 gives the eSafety Commissioner powers over harmful online content and conduct, and generative AI now sits squarely inside that frame. Here is what the Act requires, where AI is captured, and what compliance operators should build.
2026
The NDB scheme has run since 2018, but AI has quietly widened what counts as a breach. Staff pasting personal information into public chatbots, AI vendors suffering their own incidents, and shadow AI you cannot see all feed the same 30-day assessment clock. Here is how the Notifiable Data Breaches scheme applies to AI, and what a compliance team should have in place before an incident, not after.
2026
Most AI governance writing is aimed at boards and lawyers. This is for the people who actually build and run the systems. It maps the AI development lifecycle, from data and model selection through evaluation, deployment, and monitoring, onto the Australian obligations that attach at each stage: APP 11 security, the AI6 essential practices, ISO 42001, the automated-decision transparency duty commencing 10 December 2026, and the APRA standards that reach any team supplying a regulated customer.
2026
The Australian Competition and Consumer Commission has made clear that Australian Consumer Law applies fully to AI-driven business practices. Misleading AI pricing, dark patterns, and AI-generated false claims are enforcement priorities. Here's what Australian businesses need to know.
2026
Australian banks, insurers, superannuation funds and credit providers face overlapping AI obligations from APRA, ASIC, the OAIC and the ACCC. This guide maps every obligation and tells you what to do first.
2026
Clinical AI in Australia sits at the intersection of TGA medical device regulation, Privacy Act health information obligations, state-based health records laws, and professional indemnity obligations. Here is what healthcare organisations need to know.
2026
HR and people teams in Australia are using AI for recruitment, performance management, workforce planning, and employee monitoring. Each use case creates specific legal obligations under the Fair Work Act, Privacy Act, anti-discrimination law, and state workplace surveillance legislation.
2026
Listed companies face AI governance obligations beyond those applying to private entities, continuous disclosure, ASX Corporate Governance Principles, and heightened director liability exposure. What boards and company secretaries need to know.
2026
Superannuation funds are using AI in member communications, investment management, complaints handling, and fraud detection. The SIS Act trustee obligations, APRA prudential standards, and ASIC conduct requirements create a governance framework that most funds have not fully mapped.
2026
Australian law firms are adopting AI for research, document review, contract analysis, and drafting. The professional obligations of solicitors and barristers, confidentiality, competence, candour to tribunals, apply fully to AI-assisted legal work. Here is what Australian legal practitioners need to know.
2026
Whether you are starting from scratch or trying to catch up with what the regulators expect, this 30-day plan gives you a structured path to defensible AI governance. Structured around the Australian Government's AI6 framework, six essential practices for responsible AI governance.
2026
Your employer using AI to monitor, assess, or make decisions about you has privacy implications that many Australians do not know about. Here is what the Privacy Act, state laws, and Fair Work Act give you the right to know and do.
2026
Singapore's Personal Data Protection Act applies fully to AI systems that collect, use and disclose personal data. The PDPC has issued AI-specific advisory guidelines that organisations must understand alongside the Model AI Governance Framework.
2026
The Monetary Authority of Singapore has the most developed AI governance framework for financial services in Asia. MAS's FEAT principles, the Veritas methodology, and evolving model risk expectations set the standard for banks, insurers, and asset managers across the region.
2026
India's DPDP Act came into force in 2023, establishing a comprehensive data protection framework that applies directly to AI systems processing personal data. With 1.4 billion people and a massive AI industry, understanding India's data protection framework is essential for any organisation operating in or building AI for the Indian market.
2026
The UK has chosen a principles-based, sector-led approach to AI regulation rather than a comprehensive AI law. But that doesn't mean AI governance in the UK is simple, ICO, FCA, CMA, Ofcom, and MHRA all have relevant powers, and UK companies with EU customers still face the EU AI Act.
2026
The United States has no comprehensive federal AI law, but that doesn't mean US enterprises are ungoverned. FTC, CFPB, EEOC, and sector regulators all have active AI enforcement programs. State laws are proliferating. And the EU AI Act applies to US companies with EU customers.
2026
The EU AI Act Omnibus reached provisional agreement on 7 May 2026, extending the high-risk AI deadline from August 2026 to December 2027. This is the definitive guide to what changed, what did not, and what organisations must do now.
2026
On 21 October 2025, Australia's National AI Centre published new Guidance for AI Adoption, replacing the 2024 Voluntary AI Safety Standard with a streamlined framework of six essential practices. This is the authoritative guide to what changed and what it means for Australian organisations.
2026
Brazil's LGPD applies fully to AI systems processing personal data. In 2026, the ANPD became an independent regulatory agency with strengthened enforcement powers and made AI a top supervisory priority for 2026-2027. Here is what organisations operating in Brazil need to understand.
2026
Canada's federal AI legislation (AIDA) died in January 2025 when Parliament was prorogued and will not return in its original form. Canada has no federal AI law. Quebec's Law 25 is the strongest privacy legislation in the country. Here is what organisations in and doing business with Canada actually need to know.
2026
Japan passed its first dedicated AI law in May 2025, the AI Promotion Act. It has no penalties, no prohibitions, and no mandatory conformity assessments. But METI guidelines carry real weight, and the new AI Strategic Headquarters chaired by the Prime Minister signals Japan's serious approach to AI governance.
2026
South Korea's AI Framework Act took effect January 22, 2026, making it the first country in APAC to have a comprehensive AI law with real obligations for high-impact AI systems. Unlike Japan's approach, South Korea's law requires transparency, risk assessments, human oversight, and carries financial penalties.