Quick verdict
Australia’s AI setting moved in July and August 2026. It did not become a comprehensive AI Act. Treat three layers as different things: (1) law that already applies, (2) the 10 December 2026 automated-decision privacy-policy rule, (3) proposed Australian Standards for AI, aimed at Parliament in early 2027, with the first published subjects being large data centres and Australian creative works.
A mid-size company that only tracks “the 2027 AI Act” will miss the date that already has a commencement section. A company that builds an inventory and evidence trail now is ready for the standards in whatever form they take.
Best for: counsel, CIOs and risk owners who need a dated brief they can take to a board. Honest limit: this is not legal advice. The standards have no exposure draft as of 31 August 2026. We help you produce evidence. We do not tell you how a future Act will be enforced.
Last updated: 31 August 2026.
What should an Australian company do about AI regulation right now?
Do the work that every future rule will ask for anyway: list the AI, name the owners, record the data, and keep evidence of risk and controls. Then write the December 2026 privacy-policy disclosures from that list. Do not pause AI adoption to wait for an Act that has not been drafted.
Dated map (2024–2027)
| Date | Instrument | Status | Who it hits first |
|---|---|---|---|
| Sep 2024 | Voluntary AI Safety Standard (10 guardrails) and Guidance for AI Adoption | Voluntary | Anyone a board, customer or tender already asks |
| Dec 2024 | Privacy and Other Legislation Amendment Act 2024 (ADM text inserted into APP 1) | Passed; delayed commencement | APP entities |
| 15 Jul 2026 | “AI in Australia’s interests” — Office of AI in PM&C; Australian Standards for AI | Announced; Office effective that day | First subjects: large data centres; training on Australian creative works (no TDM exception) |
| 20 Jul 2026 | AI consumer-safety priorities | Policy | Consumer-facing automated systems |
| Aug 2026 | National Cabinet consideration of the standards | Process | States and territories on infrastructure approvals |
| 18 May 2026 → Sep 2026 | OAIC issues paper, then planned guidance on the ADM obligation | Guidance around a statute | APP entities writing privacy policies |
| 20 Aug 2026 | Joint Select Committee on Artificial Intelligence | Inquiry; report due 30 Nov 2026 | Anyone with a view on copyright, sovereignty, deepfakes, consumer law |
| 10 Dec 2026 | APP 1 automated-decision-making disclosures | Binding | APP entities using in-scope ADM |
| Early 2027 | Government aim: legislate Australian Standards for AI | Proposed; no exposure draft | Unknown beyond the first subjects. Coverage, regulator and penalties unsettled |
Sources to keep open: the PM media release, the OAIC ADM issues paper, the committee page, and a cautious firm note such as Norton Rose Fulbright, August 2026.
What the July 2026 announcement is — and is not
It is a national coordination move. AI policy now sits next to the Prime Minister, not only in industry. “Standards” in the speech means requirements the government intends to make mandatory, not a voluntary ISO pamphlet.
It is not, on the published text, a general high-risk AI regime. There is no Annex III list. There is no AI-specific incident-reporting duty for every deployer. There is no named enforcement agency for private-sector models. The first legal obligations described in the speech are about data-centre energy, water and grid behaviour, plus a continued refusal of a text-and-data-mining exception for Australian copyright works.
If you run a hospital triage model or a hiring screener, you still sit under privacy, consumer, employment and (if relevant) health and APRA rules. You do not yet sit under a dedicated “high-risk AI” chapter. That is why an evidence trail is the useful 2026 investment: it satisfies today’s law and survives a 2027 statute in whatever form it arrives.
The Joint Select Committee: what it can change
The committee was appointed on 20 August 2026 by both Houses. It is bipartisan. Terms of reference cover productivity, sovereign capability, workforce, copyright, national security, data sovereignty, consumer protection, deepfakes and cyber security. A committee does not legislate. It can still move the 2027 bill. If you operate in media, education, health, finance or critical infrastructure, read the submissions when they are published and assume the report will be quoted in the second-reading speech.
Do not wait for 30 November to start an inventory. The December privacy date is earlier than the committee report.
What is already law while the standards are being written
The Privacy Act applies to personal information in prompts, logs, retrieved documents and vendor training opt-ins. The Australian Consumer Law already caught a recommender that misled people about “best deals” (Trivago, $44.7 million). Employment and anti-discrimination law already cover a hiring model that screens people out. APRA-regulated entities already treat material third-party technology as an operational-risk and information-security problem.
The Voluntary AI Safety Standard remains the practical checklist. It is not a statute. It is what a competent counterparty asks for when they say “show us your AI governance”. Implementation detail lives in our VAISS guide. The buying problem is evidence, not another policy: Can you prove it?
What a board paper should say this quarter
- We are already using AI, including vendor features we did not procure as “AI projects”.
- Existing law applies. The next statutory date for most APP entities is 10 December 2026.
- The 2027 standards are real and incomplete. First wave looks like infrastructure and copyright, not a copy of the EU AI Act.
- Our control is an inventory with owners, data, vendors and a living evidence record — not a promise to “comply when the Act lands”.
- Legal sign-off stays with counsel. Certification stays with an assessor if we later want ISO 42001.
Unique insight from Power Days: boards that only asked “are we ready for the AI Act?” in 2025 now have to be told the Act they imagined does not exist, and the privacy-policy date does. That conversation is shorter when the inventory is already on the table.
FAQ
Is there a Q1 2027 commencement date for a general AI Act? No published commencement section for a general private-sector AI Act exists as of 31 August 2026. The government has said it aims to bring standards legislation to Parliament in early 2027. Treat that as a legislative target, not a duty that has started.
Do the Australian Standards for AI apply to our ChatGPT use? Not on the published first subjects. ChatGPT use is already a privacy, confidentiality and records problem. It may be pulled into later standards. Do not wait to inventory it.
Should we pause AI projects until 2027? No. Pause only the uses you cannot name, own, or put personal information into safely. Build the record as you ship.
Where do Singapore and the EU fit? If you operate in those markets, you already have a second and third regime. Comparison: EU AI Act vs Australia vs Singapore.
Related: Prove it · 10 December 2026 ADM rule · AI inventory · Power Day
