Insights & News
AI Regulation in Australia: Where It Stands
- October 2, 2026
Australia has no AI Act. As at October 2026 there is no general law that regulates AI directly, and no mandatory guardrails for high-risk AI. What exists is a set of voluntary standards, the full force of existing laws such as the Privacy Act, and a legislative programme aimed at large data centres and AI training that the Government intends to introduce in early 2027. The position has reversed twice in under two years, so here is the sequence and what it actually means for an SME.
Key facts
- There is no Australian AI Act and no mandatory guardrails for high-risk AI in force.
- The Voluntary AI Safety Standard, published by the National AI Centre on 5 September 2024, sets out ten voluntary guardrails and remains the main published Commonwealth guidance.
- A proposals paper on mandatory guardrails for high-risk AI was consulted on in 2024 but never legislated.
- The National AI Plan of 2 December 2025 chose to rely on existing technology-neutral laws and sector regulators, supported by an Australian AI Safety Institute, rather than a standalone statute.
- On 15 July 2026 the Government announced an Australian Standards for AI framework covering large data centres and AI training, and established an Office of AI within the Department of the Prime Minister and Cabinet.
- National Cabinet endorsed developing those standards as mandatory on 26 August 2026, covering energy, water, land use and skills for large data centres, with the Commonwealth committing to legislate in early 2027.
What applies to your business today?
Existing law, in full, with no AI carve-out. The Privacy Act governs personal information you put into an AI tool, and the Australian Privacy Principles apply to that use and any disclosure it involves. Serious interferences with privacy carry penalties up to the greater of AU$50 million, three times the benefit obtained, or 30 per cent of adjusted turnover. Australian Consumer Law governs claims you make about AI-assisted services and the quality of what you deliver. Copyright governs what you feed in and what comes out. Your professional obligations and your client contracts have not changed because the drafting was done by a model.
That is the whole regulatory answer for a typical SME: no new duty, all the old ones. Which is less comforting than it sounds, because the old ones were written for a world where your staff did not paste client files into a website run by a company in another jurisdiction.
How did we get here?
- 2019. Australia's AI Ethics Principles published. Voluntary, high level.
- 5 September 2024. The National AI Centre publishes the Voluntary AI Safety Standard with ten guardrails, alongside a proposals paper on mandatory guardrails for AI in high-risk settings.
- 2025. Guidance for AI Adoption published, consolidating the ten guardrails into six essential practices that scale down to small business.
- 2 December 2025. The National AI Plan declines to introduce mandatory guardrails, relying on existing laws and establishing an AI Safety Institute. Widely read at the time as settling the question.
- 23 March 2026. Voluntary Data Centre Expectations published, covering energy, water, jobs and the national interest.
- 15 July 2026. The Prime Minister announces Australian Standards for AI and the Office of AI is established in PM&C the same day.
- 26 August 2026. National Cabinet endorses nationally consistent mandatory standards for large data centres, with legislation committed for early 2027.
Will the mandatory standards apply to us?
On the published material, almost certainly not directly. The mandatory requirements named so far attach to large AI data centres and the conditions around AI training, covering energy, water, land use and skills. If you are a professional services firm in Castle Hill using Copilot, none of that lands on you.
What is worth watching is scope creep in the drafting, and the separate question of whether the general guardrails are revisited. A Joint Select Committee on Artificial Intelligence was appointed in August 2026 to examine AI laws, copyright, national security and related questions, which is usually where broader proposals get aired first.
So what should an SME actually do?
Run to the voluntary guardrails now, at the scale your business justifies. Not because they are law, but because the work is small, it answers the client questionnaires that are already arriving, and it is the version of this that maps across to whatever eventually lands. In practice: know which AI tools are in use, write a short policy, decide what data is off limits, put a technical control behind it, and review it quarterly.
The thing not to do is wait. The regulatory position has moved twice and may move again, but client contracts, insurers and tenders are not waiting for Parliament, and the evidence they want is the same evidence a future standard would want.
Frequently asked questions
Is there an AI law in Australia?
No. There is no AI Act and no mandatory guardrails for high-risk AI in force as at October 2026. AI use is governed by existing technology-neutral laws, principally the Privacy Act, Australian Consumer Law, copyright and sector-specific regulation, supported by voluntary standards.
What happened to the mandatory guardrails for high-risk AI?
They were consulted on in a 2024 proposals paper and never legislated. The National AI Plan of 2 December 2025 chose existing laws and sector regulators instead, and the guardrails remain published as the voluntary standard.
What are the Australian Standards for AI?
A framework announced on 15 July 2026 covering large data centres and AI training, including mandatory requirements for large AI data centres on energy, water and land use. National Cabinet endorsed developing them as mandatory on 26 August 2026, and the Commonwealth has committed to legislate in early 2027. They are not a general AI compliance regime for every business.
Does the EU AI Act apply to Australian businesses?
Only if you place an AI system on the EU market or your output is used there. For a domestic Australian SME it generally does not apply, and building to it voluntarily imports a great deal of cost for no local benefit.
Could the rules change again?
Yes, and they have twice already. A Joint Select Committee on Artificial Intelligence is examining the broader questions, and the standards legislation is still to be drafted. The hedge is to build governance that is framework-agnostic: a register, a policy, assessments and records, which every published framework asks for in some form.
If you want to know what your obligations actually are rather than what the headlines say, we will walk through it against your business and tell you which parts are real for you.
About the author
Brett Muscio is the Director of 4iT Support Pty Ltd, a managed services provider based in Castle Hill, NSW. He works with SME clients across Sydney, Melbourne, and Brisbane on AI governance, Privacy Act obligations, Microsoft 365 security and the Essential Eight, with on-site support across the Sydney metro area and remote delivery nationally. Connect on LinkedIn.
Recent Posts
-
AI Regulation in Australia: Where It Stands -
What Goes in an AI Governance Framework -
ISO 42001 Explained for Australian SMEs -
How to Write a Data Loss Prevention Policy -
Microsoft Purview DLP for Australian SMEs -
What Is Data Loss Prevention (DLP)? -
Has the Privacy Act small business exemption been removed? -
Microsoft Authenticator Setup for Business -
Windows Hello for Business: Passwordless Sign-In for SMEs -
Microsoft 365 MFA Setup: Security Defaults or Conditional Access







