Australian carriers and carriage service providers carry critical-infrastructure security, consumer, metadata and privacy duties, and AI adds automation-transparency and safety expectations on top. This is the map.
Critical-infrastructure duties on top of the usual privacy and consumer law. Map your AI systems against each.
Telecommunications is a critical infrastructure sector under the SOCI Act 2018. Carriers and relevant carriage service providers must maintain a Telecommunications Security and Risk Management Program addressing cyber, personnel, supply-chain and physical hazards. The Rules commenced 4 April 2025, moving the former reforms from Part 14 of the Telecommunications Act 1997 into the SOCI Act, with cyber maturity phased through 2026 and 2027.
Source: SOCI (Telco Security and Risk Mgmt Program) Rules 2025Responsible entities for critical telecommunications assets must report a critical cyber security incident to the Australian Signals Directorate within 12 hours, and any other reportable cyber incident within 72 hours. AI-driven network monitoring and automated response tooling must feed these mandatory notification workflows rather than obscure them.
Source: SOCI Act 2018 ss 30BC-30BD (Federal Register)Telcos hold large volumes of customer and account data and must handle it under the Australian Privacy Principles, including transparency, use limitation and security. The automated-decision transparency duty added by the Privacy and Other Legislation Amendment Act 2024 requires privacy policies to describe substantially automated decisions that significantly affect individuals, commencing 10 December 2026.
Source: OAIC: Privacy Act obligations for telecommunicationsUnder the Telecommunications (Interception and Access) Act 1979 providers must retain a prescribed set of telecommunications data for at least two years and keep it encrypted and secure (s 187BA). Any AI analytics applied to retained metadata must respect access controls and the limited lawful-access purposes of the scheme.
Source: TIA Act 1979, Part 5-1A (Federal Register)The Reducing Scam Calls and Scam SMS code (C661) requires originating providers to identify, trace and block scam calls and messages. The SMS Sender ID Register Industry Standard 2025 requires participating telcos to verify alphanumeric sender IDs, with registration from 30 November 2025 and unregistered IDs shown as unverified from 1 July 2026. AI scam classifiers must be governed for accuracy and false positives.
Source: ACMA: Combating phone scams (C661:2022 code)The Telecommunications Consumer Protections Code C628:2019 (incorporating Variation No. 1/2022) is the code in force across sales, contracts, billing, credit and hardship. NB: ACMA announced in March 2026 that it will make an enforceable industry standard to replace it. AI used in sales, credit assessment, chatbots and hardship triage must deliver accurate, non-misleading outcomes and preserve access to human assistance.
Source: ACMA: Telecommunications Consumer Protections CodeAll carriers and eligible carriage service providers must join and comply with the Telecommunications Industry Ombudsman scheme for external dispute resolution. Where AI systems drive billing, complaints handling or service decisions, providers remain accountable for outcomes escalated to the Ombudsman.
Source: ACMA: TIO scheme requirements and exemptionsThe Voluntary AI Safety Standard published in 2024 sets ten guardrails covering accountability, risk management, data governance, testing, human oversight, transparency and record keeping. Although voluntary, it is a practical benchmark for telco AI deployed in networks and customer service and signals the direction of proposed mandatory guardrails.
Source: DISR, Voluntary AI Safety Standard, 10 guardrailsEach obligation links to its primary or official source. Verified against the relevant Australian regulators and legislation, July 2026. General information, not legal advice: confirm your specific obligations with the regulator or your adviser.
Detailed analysis of the frameworks that apply to this sector.
Build or refresh the Telecommunications Security and Risk Management Program to the SOCI TSRMP Rules and track the phased cyber-maturity milestones
Stand up 12-hour and 72-hour cyber incident notification playbooks that route through automated detection tooling to the ASD ACSC
Update privacy policies for the automated-decision transparency duty commencing 10 December 2026 and map where AI significantly affects customers
Confirm metadata retention, encryption and lawful-access controls under the TIA Act before applying any AI analytics to retained data
Register alphanumeric sender IDs and verify scam-blocking controls ahead of the 1 July 2026 SMS Sender ID Register enforcement
Govern AI used in sales, credit assessment, chatbots and hardship handling against the TCP Code and preserve human escalation to the TIO
Adopt the Voluntary AI Safety Standard guardrails as an internal baseline for AI accountability, testing and human oversight
The free AI Health Check maps your sector and the AI you actually use to the specific Australian duties you have triggered, then gives you a board-ready report. Your answers stay in your browser.
Take the free AI Health Check