Back to Blog

Australia AI Regulation 2026–2027: What Changed and What Didn’t

Office of AI, proposed standards, a parliamentary committee — and a December 2026 privacy date that is already law.

Australia AI Regulation 2026–2027: What Changed and What Didn’t

Quick verdict

Australia’s AI setting moved in July and August 2026. It did not become a comprehensive AI Act. Treat three layers as different things: (1) law that already applies, (2) the 10 December 2026 automated-decision privacy-policy rule, (3) proposed Australian Standards for AI, aimed at Parliament in early 2027, with the first published subjects being large data centres and Australian creative works.

A mid-size company that only tracks “the 2027 AI Act” will miss the date that already has a commencement section. A company that builds an inventory and evidence trail now is ready for the standards in whatever form they take.

Best for: counsel, CIOs and risk owners who need a dated brief they can take to a board. Honest limit: this is not legal advice. The standards have no exposure draft as of 31 August 2026. We help you produce evidence. We do not tell you how a future Act will be enforced.

Last updated: 31 August 2026.


What should an Australian company do about AI regulation right now?

Do the work that every future rule will ask for anyway: list the AI, name the owners, record the data, and keep evidence of risk and controls. Then write the December 2026 privacy-policy disclosures from that list. Do not pause AI adoption to wait for an Act that has not been drafted.


Dated map (2024–2027)

Date Instrument Status Who it hits first
Sep 2024 Voluntary AI Safety Standard (10 guardrails) and Guidance for AI Adoption Voluntary Anyone a board, customer or tender already asks
Dec 2024 Privacy and Other Legislation Amendment Act 2024 (ADM text inserted into APP 1) Passed; delayed commencement APP entities
15 Jul 2026 “AI in Australia’s interests” — Office of AI in PM&C; Australian Standards for AI Announced; Office effective that day First subjects: large data centres; training on Australian creative works (no TDM exception)
20 Jul 2026 AI consumer-safety priorities Policy Consumer-facing automated systems
Aug 2026 National Cabinet consideration of the standards Process States and territories on infrastructure approvals
18 May 2026 → Sep 2026 OAIC issues paper, then planned guidance on the ADM obligation Guidance around a statute APP entities writing privacy policies
20 Aug 2026 Joint Select Committee on Artificial Intelligence Inquiry; report due 30 Nov 2026 Anyone with a view on copyright, sovereignty, deepfakes, consumer law
10 Dec 2026 APP 1 automated-decision-making disclosures Binding APP entities using in-scope ADM
Early 2027 Government aim: legislate Australian Standards for AI Proposed; no exposure draft Unknown beyond the first subjects. Coverage, regulator and penalties unsettled

Sources to keep open: the PM media release, the OAIC ADM issues paper, the committee page, and a cautious firm note such as Norton Rose Fulbright, August 2026.


What the July 2026 announcement is — and is not

It is a national coordination move. AI policy now sits next to the Prime Minister, not only in industry. “Standards” in the speech means requirements the government intends to make mandatory, not a voluntary ISO pamphlet.

It is not, on the published text, a general high-risk AI regime. There is no Annex III list. There is no AI-specific incident-reporting duty for every deployer. There is no named enforcement agency for private-sector models. The first legal obligations described in the speech are about data-centre energy, water and grid behaviour, plus a continued refusal of a text-and-data-mining exception for Australian copyright works.

If you run a hospital triage model or a hiring screener, you still sit under privacy, consumer, employment and (if relevant) health and APRA rules. You do not yet sit under a dedicated “high-risk AI” chapter. That is why an evidence trail is the useful 2026 investment: it satisfies today’s law and survives a 2027 statute in whatever form it arrives.


The Joint Select Committee: what it can change

The committee was appointed on 20 August 2026 by both Houses. It is bipartisan. Terms of reference cover productivity, sovereign capability, workforce, copyright, national security, data sovereignty, consumer protection, deepfakes and cyber security. A committee does not legislate. It can still move the 2027 bill. If you operate in media, education, health, finance or critical infrastructure, read the submissions when they are published and assume the report will be quoted in the second-reading speech.

Do not wait for 30 November to start an inventory. The December privacy date is earlier than the committee report.


What is already law while the standards are being written

The Privacy Act applies to personal information in prompts, logs, retrieved documents and vendor training opt-ins. The Australian Consumer Law already caught a recommender that misled people about “best deals” (Trivago, $44.7 million). Employment and anti-discrimination law already cover a hiring model that screens people out. APRA-regulated entities already treat material third-party technology as an operational-risk and information-security problem.

The Voluntary AI Safety Standard remains the practical checklist. It is not a statute. It is what a competent counterparty asks for when they say “show us your AI governance”. Implementation detail lives in our VAISS guide. The buying problem is evidence, not another policy: Can you prove it?


What a board paper should say this quarter

  1. We are already using AI, including vendor features we did not procure as “AI projects”.
  2. Existing law applies. The next statutory date for most APP entities is 10 December 2026.
  3. The 2027 standards are real and incomplete. First wave looks like infrastructure and copyright, not a copy of the EU AI Act.
  4. Our control is an inventory with owners, data, vendors and a living evidence record — not a promise to “comply when the Act lands”.
  5. Legal sign-off stays with counsel. Certification stays with an assessor if we later want ISO 42001.

Unique insight from Power Days: boards that only asked “are we ready for the AI Act?” in 2025 now have to be told the Act they imagined does not exist, and the privacy-policy date does. That conversation is shorter when the inventory is already on the table.

FAQ

Is there a Q1 2027 commencement date for a general AI Act? No published commencement section for a general private-sector AI Act exists as of 31 August 2026. The government has said it aims to bring standards legislation to Parliament in early 2027. Treat that as a legislative target, not a duty that has started.

Do the Australian Standards for AI apply to our ChatGPT use? Not on the published first subjects. ChatGPT use is already a privacy, confidentiality and records problem. It may be pulled into later standards. Do not wait to inventory it.

Should we pause AI projects until 2027? No. Pause only the uses you cannot name, own, or put personal information into safely. Build the record as you ship.

Where do Singapore and the EU fit? If you operate in those markets, you already have a second and third regime. Comparison: EU AI Act vs Australia vs Singapore.


Related: Prove it · 10 December 2026 ADM rule · AI inventory · Power Day

Share this article

Share:

Using AI without an evidence trail?

Power Hour onboarding, then a Power Day: inventory, owners, data flows, and a living record. We build the evidence layer — we do not certify you.