The short version
Six facts, each with a date attached, describe the entire Australian AI regulatory position as at today.
- There is no Australian AI Act, and there is not going to be one soon. The National AI Plan, released on 2 December 2025, dropped the mandatory guardrails proposed in September 2024 in favour of existing technology-neutral law, voluntary guidance and a new safety institute.
- $29.9 million. The funding committed to establish the Australian AI Safety Institute, which became operational in early 2026. It monitors, tests and advises. It does not regulate.
- 15 July 2026. The Prime Minister announced an Office of AI inside his own department and a framework called the Australian Standards for AI. Read the actual obligations in that announcement and they are about data centres: bring your own power, pay your own connection costs, curtail on demand, use water efficiently.
- 26 August 2026. National Cabinet backed it. The communique language is that the Commonwealth “intends to legislate the AI standards in early 2027”.
- 9 September 2026. One week away. App distribution services must have age assurance in place before they let anyone download an 18+ app, under codes that also reach AI companion chatbots.
- 10 December 2026. A new Australian Privacy Principle takes effect requiring organisations to disclose, in their privacy policy, the kinds of personal information they feed to automated decision-making and the kinds of decisions they make with it. This is the one that applies to a decision about you.
The gap between the fourth fact and the sixth is the story. What the government calls AI regulation is largely industrial policy about the physical footprint of AI. What most people mean when they ask whether AI is regulated — can a computer decide something about me, and do I get to know — is being handled, thinly, by privacy law.
How we got here: the guardrails that were written and never used
Australia did draft AI rules. In September 2024 the Department of Industry, Science and Resources published two documents on the same theme. One was the Voluntary AI Safety Standard, released on 5 September 2024, setting out ten guardrails for organisations across the AI supply chain: accountability and governance, risk management, data governance and security, pre-deployment testing and ongoing monitoring, human oversight, disclosure to users that they are interacting with or affected by AI, contestability, supply chain transparency, record keeping and stakeholder engagement. It creates no legal obligation on anyone.
The other was a proposals paper on mandatory guardrails for AI in high-risk settings, which took a similar set of ten obligations and asked how they should be made binding, offering three regulatory options ranging from adapting existing law to a dedicated AI Act.
That consultation drew more than 300 responses. The answer, delivered fourteen months later in the National AI Plan on 2 December 2025, was none of the above.
| 5 September 2024 | Voluntary AI Safety Standard published: ten guardrails, no legal force, positioned as preparation for mandatory rules to come. |
|---|---|
| September 2024 | Proposals paper on mandatory guardrails for high-risk AI: ten proposed obligations, three implementation options including a dedicated Act. |
| 2 December 2025 | National AI Plan. Three pillars — capture the opportunities, spread the benefits, keep Australians safe. Mandatory guardrails not proceeded with. Reliance placed on existing technology-neutral frameworks, voluntary guidance and sector regulators. $29.9 million committed to an AI Safety Institute. |
| Early 2026 | Australian AI Safety Institute established, joining the international network of equivalent bodies. Its role is to assess capabilities, datasets and system design upstream and harms downstream, support specialist regulators and coordinate incident response. |
| 15 July 2026 | Prime Minister’s keynote, AI in Australia’s interests, Sydney. Office of AI stood up inside the Department of the Prime Minister and Cabinet effective immediately. Australian Standards for AI announced, to go to National Cabinet in August and to legislation in early 2027. |
| 26 August 2026 | National Cabinet affirms the plan across nine governments and commits to consistent mandatory standards for data centre energy, water and land use, designed to complement rather than duplicate state planning and approval processes. |
Reasoning beyond the sources: the drop was not a reversal so much as a re-scoping. A mandatory-guardrails regime would have imposed testing, oversight and contestability duties on anyone deploying AI in a high-risk setting, which is expensive and slow and lands on employers, insurers and government agencies. The framework that replaced it imposes hard, measurable duties on a much smaller and much more visible group — the operators of very large data centres — while leaving everything about how AI is used to laws that already exist. That is a defensible choice. It is not the choice most people assume has been made when they hear that Australia is legislating AI standards.
What the Australian Standards for AI actually contain
On the Prime Minister’s own media release of 15 July 2026, the framework has a handful of visible components, and most of them are about physical infrastructure.
| Power | Large data centres to underwrite their own new power supply and pay the full cost of their network connections, rather than drawing on generation and network capacity built for households and existing businesses. |
|---|---|
| Grid stability | An obligation to reduce power draw when the grid needs it. |
| Water and siting | Maximum water efficiency requirements, and coordination with states and territories on where these facilities are located, with local community input. |
| Copyright | The stated position is that Australian artists, writers and journalists keep ownership of their work, and that companies cannot use Australian creative works to train AI without the creator’s control. The National Cabinet communique refers to legislating “conditions associated with delivering AI training”. Contemporaneous reporting noted that a copyright clarification is unlikely in the near term. |
| Timing | Legislation intended in early 2027. The Government’s claim is that these would be the first AI standards legislated by any government in the world. |
The Prime Minister’s framing was: “This world leading framework is about Australia choosing to shape the future rather than letting the future of AI shape us.” The Opposition Leader’s response to the Office of AI was that it amounted to “an office in an office … inside his own office”.
We covered the energy half of this in detail when the market rules landed — see AI data centres and your power bill. What matters for this article is the negative space. There is nothing in the announced framework about automated decisions, no risk classification of AI systems, no registration or licensing, no mandatory disclosure that content is AI-generated, and no right for an individual to contest a machine’s output. The draft standards have not been published, so that could change. As at today it is what the announcement says.
The rule that does reach you: APP 1.7, from 10 December 2026
Inside the Privacy and Other Legislation Amendment Act 2024, which received Royal Assent on 10 December 2024, is a transparency obligation with a two-year runway. It commences on 10 December 2026.
It works like this. If an organisation covered by the Privacy Act has arranged for a computer program to make a decision, or to do something substantially and directly related to making a decision, and that decision uses personal information and could significantly affect an individual’s rights or interests, then its privacy policy must say so.
| What must be disclosed | The kinds of personal information used in the automated decision-making; the kinds of decisions made entirely by a computer program; and the kinds of decisions where a program does something substantially and directly related to making the decision. |
|---|---|
| Which decisions count | Ones that could significantly affect rights or interests. The Act clarifies that the effect can be beneficial or adverse. Worked examples in the legal commentary include decisions to grant or refuse a benefit under legislation, decisions affecting contractual rights, and decisions affecting access to a significant service or support. |
| What is carved out | Commercial-in-confidence detail about how the system works does not have to be published. |
| How it is enforced | The OAIC can issue compliance notices and infringement notices where a privacy policy fails the requirement, and civil penalty exposure applies to non-compliant policies. |
| Guidance | The OAIC opened consultation on its guidance for the obligation on 18 May 2026 and closed submissions on 15 June 2026. As at today we could not find final guidance published. |
Now the honest part, because this obligation is routinely oversold as “Australia’s AI law”.
What it gives you. For the first time, a bank, insurer, telco, employer platform, utility or agency that runs your application through a model has to write down, in a public document, that it does so and roughly what it feeds in. That is a real change. It creates a dated artefact you can read, quote, compare against a competitor’s and complain about to a regulator that holds notice powers. Before this, an organisation could run a scoring model on you and say nothing at all.
What it does not give you. It is a disclosure duty about kinds of decisions, not an explanation of your decision. It does not give you a right to human review. It does not give you a right to know why the system reached its conclusion in your case. It does not stop any use of AI, prohibit any category of system, or require anyone to test a model before pointing it at you. It is a paragraph in a privacy policy, and the enforcement is against the adequacy of the paragraph.
Reasoning beyond the sources: that sounds like a criticism and it is only half of one. Disclosure obligations of this shape tend to do their work indirectly. Once an organisation has to describe its automated decision-making publicly, someone internal has to inventory it, and the inventory is usually the first time anybody has counted. The written description then becomes evidence — in a complaint, in a discrimination claim, in a regulator’s inquiry — and a mismatch between a bland policy paragraph and an actual system is exactly the sort of thing that gets litigated. The value is not the paragraph. It is that the paragraph has to be true.
The other rules that already apply, none of which are AI rules
The National AI Plan’s position is that existing law covers AI. It is worth being specific about which existing law, because the coverage is real but uneven.
| Australian Consumer Law | Consumer guarantees apply to a product with AI in it exactly as they apply to a toaster: acceptable quality, fit for purpose, matching its description. A claim about what an AI feature does is a representation, and a false one is misleading conduct. No AI-specific provision is needed for this and none exists. |
|---|---|
| Privacy Act, generally | Personal information used to train or run a system is still personal information. Collection, use, disclosure and security obligations all apply, and the automated decision-making transparency clause above sits on top of them from 10 December 2026. |
| Statutory privacy tort, since 10 June 2025 | A cause of action for serious invasions of privacy, by intrusion upon seclusion or misuse of information, requiring intentional or reckless conduct and seriousness, and actionable without proof of damage. It reaches individuals and organisations that are not covered by the Australian Privacy Principles at all — which is the gap a good deal of AI-enabled surveillance falls into. We wrote about one version of that problem in camera glasses and Australian law. |
| Online safety codes, in effect since 9 March 2026 | Industry codes registered on 9 September 2025 covering social media, messaging, designated internet services, app distribution and equipment suppliers. They expressly reach AI companion chatbots and companion features inside other services, and treat high-risk generative AI platforms as needing age assurance. App distribution services have until 9 September 2026 to have age assurance in place before allowing downloads of 18+ apps. This is the same machinery as the under-16 social media rules, one layer down the stack. |
| Unfair trading practices, from 1 July 2027 | The Competition and Consumer Amendment (Unfair Trading Practices) Act 2026 introduces a technology-neutral prohibition on conduct that manipulates consumers or unreasonably distorts the environment in which they decide, plus drip-pricing disclosure and subscription rules requiring at least one straightforward online way to cancel. Penalties run to $100 million for corporations and $2.5 million for individuals. It is not an AI law, but a personalised, model-driven dark pattern is squarely the kind of thing it describes. |
Read that table as a whole and the plan’s logic holds up better than the headlines suggested. What is genuinely missing is not coverage of AI-adjacent harms — it is anything that operates before harm: no pre-deployment testing duty, no impact assessment, no register of high-risk systems, no obligation to keep a human in the loop. Australia has chosen an after-the-fact model, enforced by general regulators, with one transparency obligation bolted to the front.
What we could not establish
Four things, and they bear on how much weight to put on the rest.
We could not find the OAIC’s final guidance on the automated decision-making obligation. Consultation closed on 15 June 2026 and secondary commentary expected final guidance around September 2026. With the obligation commencing on 10 December, the practical scope of “substantially and directly related” is still being settled roughly three months out.
We could not read a draft of the Australian Standards for AI. Everything above about their content comes from the announcement and the National Cabinet communique. Whether the legislated version contains anything consumer-facing is unknown, and we would not assume either way.
We could not independently confirm what the Australian AI Safety Institute has actually tested. Its establishment and funding are on the public record; a published programme of work with results is not something we could locate.
And we could not establish whether the major app stores will meet the 9 September deadline, or what their age assurance will look like in practice for Australian users. Nothing had been announced that we could find as at today.
What to do about it, concretely
- After 10 December, read one privacy policy properly. Pick the organisation that makes the most consequential decisions about you — your bank, your insurer, your landlord’s platform, the agency that pays you something. Search the policy for “automated”. If there is nothing there and you have reason to think a model is involved, that absence is now itself a compliance question.
- Ask in writing, and keep the answer. A request for the kinds of decisions an organisation automates is cheap to send and produces a dated record. If the policy is silent after 10 December, the OAIC can be told, and it has notice powers rather than only persuasion.
- Do not expect to be told when content is AI-generated. No Australian rule requires labelling of AI-generated text, images or audio. Treat everything unverified accordingly, particularly anything that arrives unsolicited asking for money or credentials.
- If a chatbot harms a child, there is now a route. The online safety codes reach AI companion services, and eSafety is the regulator. That is a complaint channel that did not exist eighteen months ago.
- For AI features you paid for, use consumer law, not AI law. If a feature does not do what the box said, that is a misleading representation and a failed consumer guarantee. It is a far stronger position than anything AI-specific on the books.
The bottom line
Australia has spent two years producing a great deal of AI governance and very little AI regulation, and the distinction is not pedantic. The Voluntary AI Safety Standard binds nobody. The AI Safety Institute advises rather than enforces. The Office of AI coordinates. The Australian Standards for AI, when legislated in early 2027, look set to bind the people who build the buildings rather than the people who point the models at you.
Against all of that, one clause commencing on 10 December 2026 will require an organisation to admit, in public, that a computer is deciding things about you. It is thin. It carries no explanation right and no human-review right. It is also the only item on this list that an ordinary person can read, check and complain about — and it arrives in fourteen weeks, with the regulator’s guidance not yet final. If you diarise one date from this article, diarise that one.
Sources
Dates, figures and quotes above are drawn from these sources, captured 2 September 2026:
- Prime Minister of Australia — AI in Australia’s interests (15 July 2026): the Office of AI within the Department of the Prime Minister and Cabinet effective immediately, the Australian Standards for AI, the data centre obligations on power supply, connection costs, curtailment and water efficiency, the copyright position on Australian creative works, the referral to National Cabinet in August 2026, the intention to legislate in early 2027, and the quoted framing about shaping the future rather than being shaped by it.
- Prime Minister of Australia — Meeting of National Cabinet (26 August 2026): the nine-government commitment, consistent mandatory standards for data centre energy, water and land use, the design intent to complement rather than duplicate state planning and approvals, and the statement that the Commonwealth intends to legislate the AI standards in early 2027 including conditions associated with delivering AI training.
- ABC News — Albanese maps out AI future with new national framework (July 2026): the end of the issue-by-issue approach, the scope of the Office of AI across data centre approvals, copyright, workplace impacts and national security, the note that a copyright clarification is unlikely for now, and Opposition Leader Angus Taylor’s “an office in an office” response.
- Minister for Science and the Digital Economy — National AI Plan: Empowering all Australians (2 December 2025): the plan’s release, its three pillars, and the $29.9 million commitment to establish the Australian AI Safety Institute.
- Montreal AI Ethics Institute — From proposed mandatory guardrails to the National AI Plan: the September 2024 proposals paper with ten mandatory guardrails and three regulatory options, the more than 300 consultation responses, the December 2025 decision not to proceed, the plan’s three pillars, and the reliance on existing technology-neutral frameworks and voluntary guidance.
- Department of Industry, Science and Resources — Voluntary AI Safety Standard (5 September 2024): the ten voluntary guardrails covering accountability, risk management, data governance and security, testing and monitoring, human oversight, user disclosure, contestability, supply chain transparency, record keeping and stakeholder engagement, and the fact that the standard creates no new legal obligation.
- OAIC — Consultation on guidance for transparency in automated decision making (published 18 May 2026, closed 15 June 2026): the commencement date of 10 December 2026, the requirement to describe in privacy policies the kinds of personal information used and the kinds of decisions made using automated decision-making, and the scope covering entities whose automated decision-making has the potential to affect rights or interests.
- Johnson Winter Slattery — Practical implications of the new transparency requirements for automated decision making: the new APP 1.7 and the disclosure content required, the “substantially and directly related” test, the clarification that effects on rights or interests may be beneficial or adverse, the worked examples, the commercial-in-confidence carve-out, and the OAIC’s compliance and infringement notice powers.
- OAIC — Statutory tort for serious invasions of privacy: the tort commencing 10 June 2025 under the Privacy and Other Legislation Amendment Act 2024 (Royal Assent 10 December 2024), covering intrusion upon seclusion and misuse of information, requiring intentional or reckless conduct and seriousness, actionable without proof of damage, and reaching parties beyond Australian Privacy Principle entities.
- Baker McKenzie Connect on Tech — Phase 2 online safety codes registered by the eSafety Commissioner: the codes registered on 9 September 2025 across social media, relevant electronic services, designated internet services, app distribution services and equipment providers, taking effect 9 March 2026, and their express coverage of AI companion chatbots and companion features within other services.
- ID Tech Wire — Australia registers new industry codes for online safety, expanding age assurance requirements: the 9 September 2026 milestone for app distribution services to implement age assurance before enabling downloads of 18+ apps, the treatment of high-risk generative AI platforms as designated internet services requiring age assurance, and the technology-neutral approach to verification methods.
- DLA Piper — Australia introduces new unfair trading practices laws: the Competition and Consumer Amendment (Unfair Trading Practices) Act 2026 commencing 1 July 2027, the prohibition on conduct that manipulates consumers or unreasonably distorts their decision environment including dark patterns, the drip-pricing disclosure obligations, the subscription contract requirements including at least one straightforward online cancellation method, and penalties of up to $100 million for corporations and $2.5 million for individuals.