Australian AI compliance

What an Australian organisation should know before it adopts AI: the laws that already apply, the government and industry rules, and the security guidance and standards that show what good looks like.

This guide is general information, not legal advice. Rules change, so check the official source linked on each card, and get advice for your situation. For how to put this into practice, see our AI governance guide.

Laws that already apply to AI

Australia has no single AI act. Existing, technology neutral laws apply to AI systems just as they apply to any other way of handling information or dealing with people.

Law

Privacy Act 1988 and the Australian Privacy Principles

Applies to: Most organisations with annual turnover above $3 million, all health service providers, Australian Government agencies and some others.

The main law for personal information in AI systems, whether it is typed into a prompt, used to train or fine tune a model, or used to make decisions. The OAIC has published guidance on using commercially available AI products and on developing and training generative AI models.

  • Check whether putting personal information into an AI tool is a permitted use (APP 6).
  • Know where your AI provider processes data before disclosing it overseas (APP 8).
  • Secure AI systems, prompts and logs like any other system holding personal information (APP 11).
  • From 10 December 2026, explain substantially automated decisions that significantly affect people in your privacy policy.
OAIC

Law

Statutory tort for serious invasions of privacy

Applies to: Everyone, including organisations exempt from the Privacy Act.

Since June 2025, individuals can take action for serious invasions of privacy, such as misuse of their information or intrusion upon seclusion, where the conduct was intentional or reckless.

  • Consider it whenever AI is used to monitor, profile or generate content about real people.
Attorney-General's Department

Law

Australian Consumer Law

Applies to: Businesses supplying goods or services to consumers.

Overstated claims about what an AI product can do, and incorrect statements a chatbot makes to customers, can be misleading or deceptive conduct. Consumer guarantees still apply to AI enabled products and services.

  • Be able to back up every claim you make about AI capability.
  • Review what customer facing AI says about prices, refunds and consumer rights.
ACCC

Law

Anti discrimination and workplace laws

Applies to: Employers and anyone making decisions about people.

AI used in recruitment, rostering, performance management or service decisions can produce discriminatory outcomes, and the organisation using it remains responsible. Some states also regulate workplace surveillance, such as NSW's Workplace Surveillance Act 2005.

  • Test AI assisted decisions for different outcomes across groups.
  • Keep a person accountable for decisions about people.
  • Consult staff before introducing AI that monitors or assesses them.
Australian Human Rights Commission

Government policy

Mandatory for government entities, and a useful benchmark for their suppliers and for any organisation designing AI governance.

Government policy

Policy for the responsible use of AI in government

Applies to: Non corporate Commonwealth entities.

Requires agencies to designate accountable officials for AI and to publish AI transparency statements, among other requirements. States and territories have their own AI frameworks.

  • Agencies: confirm your accountable official and transparency statement are current.
  • Suppliers: expect agencies to ask how your AI is governed and tested.
Digital Transformation Agency

Government policy

Protective Security Policy Framework (PSPF)

Applies to: Commonwealth entities, and often their suppliers by contract.

Sets protective security requirements for government. PSPF directions have restricted specific AI products on government systems and devices.

  • Check current PSPF directions before approving any AI tool.
  • Classify data before deciding which AI systems may process it.
PSPF

Industry rules

Regulated industries have additional obligations that apply to AI like any other technology.

Industry rules

APRA CPS 234 and CPS 230

Applies to: APRA regulated banks, insurers and superannuation trustees.

CPS 234 requires information security capability matched to the threats an entity faces. CPS 230, in force from July 2025, covers operational risk and material service providers, which can include AI vendors.

  • Include AI systems and vendors in information security and service provider assessments.
  • Plan for the failure or exit of an AI provider.
APRA

Industry rules

ASIC expectations for AI governance

Applies to: Financial services and credit licensees.

ASIC's Report 798, Beware the gap, reviewed AI use by licensees and found governance lagging behind adoption. Existing obligations, such as acting efficiently, honestly and fairly, apply to AI.

  • Make AI governance proportionate to how AI affects consumers.
  • Document how AI assisted decisions are tested and monitored.
ASIC

Industry rules

TGA regulation of software as a medical device

Applies to: Developers and suppliers of health software, including AI.

Software intended to diagnose, prevent, monitor or treat a condition can be a regulated medical device, whether or not it uses AI.

  • Check the TGA's guidance before building or buying clinical AI tools.
TGA

Industry rules

Ahpra guidance on AI in healthcare

Applies to: Registered health practitioners.

Practitioners remain responsible for the care they provide when using AI, including accuracy of records, informed consent and patient privacy.

  • Review AI generated clinical notes before signing them.
  • Tell patients when AI scribes or tools are used in their care.
Ahpra

Industry rules

Court practice notes on generative AI

Applies to: Legal practitioners and parties to proceedings.

Several Australian courts restrict and set conditions on generative AI in court documents, including the NSW Supreme Court's Practice Note SC Gen 23.

  • Verify every authority and citation an AI tool produces.
  • Check the practice notes of each court you appear in.
Supreme Court of NSW

Industry rules

Australian Framework for Generative AI in Schools

Applies to: Schools and education systems.

Endorsed by education ministers, it sets principles for the safe, ethical and effective use of generative AI in Australian schools.

  • Align school AI policies and tool choices with the framework.
Department of Education

Security guidance

AI systems are information systems. Established security controls apply, plus some risks that are new to AI.

Security guidance

ASD Essential Eight

Applies to: All organisations. Mandatory for many government entities.

Eight prioritised mitigation strategies, including patching, application control, multi factor authentication and backups. They apply to the servers, software and accounts behind AI systems.

  • Apply the Essential Eight to AI infrastructure, especially MFA and patching.
ASD's ACSC

Security guidance

ASD's ACSC guidance on AI

Applies to: Organisations engaging with, building or deploying AI.

ASD's Australian Cyber Security Centre publishes AI security guidance, including Engaging with artificial intelligence and joint guidance with international partners on deploying AI systems securely and on AI data security.

  • Use the guidance to threat model AI systems before deployment.
cyber.gov.au

Security guidance

Information Security Manual (ISM)

Applies to: Government, and widely used across industry.

ASD's cyber security framework of controls for protecting systems and data. Its controls apply to the systems that host and serve AI models.

  • Map AI hosting, access and logging to the relevant ISM controls.
ASD's ACSC

Security guidance

OWASP Top 10 for LLM Applications

Applies to: Anyone building applications on large language models.

The most critical security risks for LLM applications, including prompt injection, sensitive information disclosure, excessive agency and improper output handling.

  • Separate system instructions from user and document content.
  • Limit the tools and permissions any model can use.
  • Sanitise model output before rendering or executing it.
OWASP GenAI

Standards

International standards give a structure you can build on, and certification you can show customers.

Standard

ISO/IEC 42001 AI management systems

Applies to: Organisations that develop, provide or use AI.

The first certifiable management system standard for AI, covering policy, risk, impact assessment and lifecycle controls. Adopted in Australia as AS ISO/IEC 42001:2023.

  • Use it as the backbone of a formal AI governance programme.
Standards Australia

Standard

ISO/IEC 23894 AI risk management

Applies to: Organisations managing AI risk.

Guidance on applying risk management principles, based on ISO 31000, to AI.

  • Extend your existing risk framework to cover AI specific risks.
ISO

Standard

ISO/IEC 27001 information security

Applies to: Any organisation managing information security.

The widely recognised standard for information security management. AI systems and suppliers belong inside its scope.

  • Bring AI systems and vendors into your ISMS scope.
ISO

Voluntary guidance

Government guidance that isn't mandatory, but sets out what good practice looks like and what regulators are likely to expect.

Voluntary guidance

Guidance for AI Adoption

Applies to: Any Australian organisation developing or using AI.

Published by the National AI Centre in 2025, it organises responsible AI into six essential practices and builds on the earlier Voluntary AI Safety Standard. It is the best single starting point for a business.

  • Use the six practices as the structure for your AI governance.
  • Start with the foundations version if you are a small organisation.
ai.gov.au

Voluntary guidance

Australia's AI Ethics Principles

Applies to: Any organisation designing, developing or using AI.

Eight principles published in 2019: wellbeing, human centred values, fairness, privacy and security, reliability and safety, transparency and explainability, contestability, and accountability.

  • Reference them in your AI policy and impact assessments.
Department of Industry