Where Australia stands
Australia regulates AI mainly through existing laws, such as privacy, consumer, discrimination, copyright and workplace law, which apply to AI systems like any other technology. On top of that, government publishes voluntary guidance that shows what good practice looks like. For most organisations the best single starting point is the National AI Centre's Guidance for AI Adoption, which organises responsible AI into six essential practices. The full landscape is in our Australian AI compliance guide.
Six practices, in plain terms
The practices below follow the structure of the Guidance for AI Adoption, described in our own words. Check the official guidance for the full detail.
- Decide who is accountable. Name a senior owner for AI across the organisation, and an owner for each AI system. Accountability should sit with someone who can say no.
- Understand the impacts and plan for them. Before you deploy, ask who the system affects, what could go wrong for them, and what you will do if it does.
- Measure and manage the risks. Assess each use case against a simple risk scale and apply controls in proportion. A drafting assistant and a system that decides loan applications need very different care.
- Share essential information. Tell staff, customers and the public when and how you use AI, especially where it affects them.
- Test and monitor. Test systems on your own real tasks before launch, and keep measuring after launch. Models, data and usage all drift.
- Maintain human control. Keep a person able to understand, override and switch off the system, and make sure decisions about people can be reviewed.
The building blocks
1. An AI use policy
Staff are almost certainly using AI already. A short, clear policy is the fastest way to turn unmanaged use into managed use. It should fit on one or two pages, name the approved tools, and be specific about what information must never go into them.
2. An AI register
Keep a simple list of every AI system in use, including AI features switched on inside software you already pay for. For each one, record the owner, the purpose, what data it touches, where that data is processed, the risk rating and the date of the last review. You can't govern what you can't see.
3. A proportionate risk assessment
Rate each use case before it goes live. A three level scale is enough for most organisations:
| Risk | Examples | Typical controls |
|---|---|---|
| Low | Drafting internal emails, summarising public documents | Approved tool, staff training, no sensitive data |
| Medium | Customer facing chat, search over internal documents | Testing before launch, human review, monitoring, clear escalation |
| High | Decisions about people: hiring, credit, claims, eligibility | Impact assessment, bias testing, human decision maker, explanation and review rights, senior sign off |
4. Vendor due diligence
Before adopting an AI product, get clear answers to these questions:
- Where is our data processed and stored, and by which companies?
- Is our data used to train or improve models, and can we switch that off?
- How long are prompts, files and outputs retained?
- What security certifications and controls does the provider have?
- Which model is used, and will we be told when it changes?
- How do we get our data out, and what happens if the service ends?
5. Human oversight and incident response
Decide in advance who reviews AI output, who can switch a system off, and how staff and customers report problems. Treat a harmful or badly wrong AI output as an incident: record it, fix the cause and learn from it.
6. Training
Everyone using AI should understand what it is good at, how it fails, and what the policy asks of them. The most common failure isn't a malicious model. It is a busy person trusting a confident answer they didn't check.
A starter AI use policy
Adapt this outline to your organisation:
- Purpose. Why the organisation uses AI and what this policy protects.
- Approved tools. Which AI tools are approved, and how to request a new one.
- Never enter. Personal, health or financial information about customers or staff, client confidential material, passwords and security details, unless the tool is approved for that data.
- Check the output. You are responsible for anything you send, publish or decide using AI.
- Be open about it. Disclose AI use where it matters to the reader, the customer or the decision.
- Report problems.Who to tell when AI gets something wrong or data goes where it shouldn't.
- Review. When the policy will next be reviewed, and by whom.
When you are ready for more
Larger organisations, and those whose customers ask for assurance, can build a formal AI management system on ISO/IEC 42001, adopted in Australia as AS ISO/IEC 42001:2023. It fits alongside ISO/IEC 27001 if you already have an information security management system.
Checklist
- A named senior owner for AI
- A published internal AI use policy
- An AI register, including AI features inside existing software
- A risk rating for every use case before launch
- Vendor answers on data location, training and retention
- Human review for decisions about people
- A way to report and handle AI incidents
- Training for everyone who uses AI
- A review date for all of the above
This guide is general information, not legal or professional advice. Check the official sources, and get advice for your situation.
More guides:
- Australian AI compliance: The laws, standards and guidance to know.
- Data sovereignty: Where your data goes when you use AI.
- Self hosting AI: Run open weight models on hardware you own.