What an Australian organisation should know before it adopts AI: the laws that already apply, the government and industry rules, and the security guidance and standards that show what good looks like.
This guide is general information, not legal advice. Rules change, so check the official source linked on each card, and get advice for your situation. For how to put this into practice, see our AI governance guide.
01 / Laws that already apply to AI
Laws that already apply to AI
Australia has no single AI act. Existing, technology neutral laws apply to AI systems just as they apply to any other way of handling information or dealing with people.
Law
Privacy Act 1988 and the Australian Privacy Principles
Applies to: Most organisations with annual turnover above $3 million, all health service providers, Australian Government agencies and some others.
The main law for personal information in AI systems, whether it is typed into a prompt, used to train or fine tune a model, or used to make decisions. The OAIC has published guidance on using commercially available AI products and on developing and training generative AI models.
Check whether putting personal information into an AI tool is a permitted use (APP 6).
Know where your AI provider processes data before disclosing it overseas (APP 8).
Secure AI systems, prompts and logs like any other system holding personal information (APP 11).
From 10 December 2026, explain substantially automated decisions that significantly affect people in your privacy policy.
Applies to: Everyone, including organisations exempt from the Privacy Act.
Since June 2025, individuals can take action for serious invasions of privacy, such as misuse of their information or intrusion upon seclusion, where the conduct was intentional or reckless.
Consider it whenever AI is used to monitor, profile or generate content about real people.
Applies to: Businesses supplying goods or services to consumers.
Overstated claims about what an AI product can do, and incorrect statements a chatbot makes to customers, can be misleading or deceptive conduct. Consumer guarantees still apply to AI enabled products and services.
Be able to back up every claim you make about AI capability.
Review what customer facing AI says about prices, refunds and consumer rights.
Applies to: Anyone training or fine tuning models, or publishing AI output.
Australia has no general text and data mining exception, and in 2025 the government said it would not introduce one. The Copyright and AI Reference Group (CAIRG) advises government on copyright and AI.
Check the licence of every model and dataset you use.
Get permission for material you fine tune on.
Review AI output for reproduced third party content before publishing it.
Applies to: Employers and anyone making decisions about people.
AI used in recruitment, rostering, performance management or service decisions can produce discriminatory outcomes, and the organisation using it remains responsible. Some states also regulate workplace surveillance, such as NSW's Workplace Surveillance Act 2005.
Test AI assisted decisions for different outcomes across groups.
Keep a person accountable for decisions about people.
Consult staff before introducing AI that monitors or assesses them.
Mandatory for government entities, and a useful benchmark for their suppliers and for any organisation designing AI governance.
Government policy
Policy for the responsible use of AI in government
Applies to: Non corporate Commonwealth entities.
Requires agencies to designate accountable officials for AI and to publish AI transparency statements, among other requirements. States and territories have their own AI frameworks.
Agencies: confirm your accountable official and transparency statement are current.
Suppliers: expect agencies to ask how your AI is governed and tested.
Regulated industries have additional obligations that apply to AI like any other technology.
Industry rules
APRA CPS 234 and CPS 230
Applies to: APRA regulated banks, insurers and superannuation trustees.
CPS 234 requires information security capability matched to the threats an entity faces. CPS 230, in force from July 2025, covers operational risk and material service providers, which can include AI vendors.
Include AI systems and vendors in information security and service provider assessments.
Applies to: Financial services and credit licensees.
ASIC's Report 798, Beware the gap, reviewed AI use by licensees and found governance lagging behind adoption. Existing obligations, such as acting efficiently, honestly and fairly, apply to AI.
Make AI governance proportionate to how AI affects consumers.
Document how AI assisted decisions are tested and monitored.
AI systems are information systems. Established security controls apply, plus some risks that are new to AI.
Security guidance
ASD Essential Eight
Applies to: All organisations. Mandatory for many government entities.
Eight prioritised mitigation strategies, including patching, application control, multi factor authentication and backups. They apply to the servers, software and accounts behind AI systems.
Apply the Essential Eight to AI infrastructure, especially MFA and patching.
Applies to: Organisations engaging with, building or deploying AI.
ASD's Australian Cyber Security Centre publishes AI security guidance, including Engaging with artificial intelligence and joint guidance with international partners on deploying AI systems securely and on AI data security.
Use the guidance to threat model AI systems before deployment.
Applies to: Anyone building applications on large language models.
The most critical security risks for LLM applications, including prompt injection, sensitive information disclosure, excessive agency and improper output handling.
Separate system instructions from user and document content.
Limit the tools and permissions any model can use.
Sanitise model output before rendering or executing it.
International standards give a structure you can build on, and certification you can show customers.
Standard
ISO/IEC 42001 AI management systems
Applies to: Organisations that develop, provide or use AI.
The first certifiable management system standard for AI, covering policy, risk, impact assessment and lifecycle controls. Adopted in Australia as AS ISO/IEC 42001:2023.
Use it as the backbone of a formal AI governance programme.
Government guidance that isn't mandatory, but sets out what good practice looks like and what regulators are likely to expect.
Voluntary guidance
Guidance for AI Adoption
Applies to: Any Australian organisation developing or using AI.
Published by the National AI Centre in 2025, it organises responsible AI into six essential practices and builds on the earlier Voluntary AI Safety Standard. It is the best single starting point for a business.
Use the six practices as the structure for your AI governance.
Start with the foundations version if you are a small organisation.
Applies to: Any organisation designing, developing or using AI.
Eight principles published in 2019: wellbeing, human centred values, fairness, privacy and security, reliability and safety, transparency and explainability, contestability, and accountability.
Reference them in your AI policy and impact assessments.