The short answer
No. At the time of writing (September 2026), Australia has no standalone AI Act and no mandatory AI guardrails law, so AI regulation in Australia works through laws that already exist. The National AI Plan, released on 2 December 2025, confirmed that the government will regulate AI through existing, largely technology-neutral laws, such as privacy, consumer, anti-discrimination, online safety and work health and safety law, supported by a new AI Safety Institute and voluntary guidance. The one new AI-relevant legal duty with a fixed date is the Privacy Act automated decision-making disclosure, which starts on 10 December 2026.
Key takeaways
- There is no Australian AI Act. The government proposed mandatory guardrails for high-risk AI in 2024 but chose, in the December 2025 National AI Plan, to rely on existing laws instead.
- Existing laws already bite on AI: the Privacy Act, Australian Consumer Law, anti-discrimination law, online safety law, work health and safety law, negligence and directors' duties.
- The Guidance for AI Adoption, published on 21 October 2025, is the government's voluntary framework and replaced the Voluntary AI Safety Standard as the recommended starting point.
- Federal agencies are bound by the DTA's Policy for the responsible use of AI in government, version 2.0, effective 15 December 2025.
- Australian businesses serving EU customers may also fall under the EU AI Act, which applies based on where a system is used, not where the developer is based.
Is there an AI Act in Australia?
No. At the time of writing (September 2026), Australia has no AI-specific statute. AI is regulated through the same laws that govern any other product, service or decision, and the government has said that is deliberate.
The National AI Plan, launched by the Department of Industry, Science and Resources on 2 December 2025, sets it out plainly: the government’s regulatory approach “will continue to build on Australia’s robust existing legal and regulatory frameworks”, with agencies and regulators responsible for AI harms in their own domains. It adds that the government “will not hesitate to intervene” if more regulation is needed. So “no AI Act” does not mean “no rules”. It means the rules are spread across many laws, and you have to know which ones touch your system.
How did Australia get here?
Australia moved from voluntary principles, to a proposal for mandatory guardrails, and then back to existing laws plus voluntary guidance. The timeline matters because many articles online still describe the 2024 proposals as if they were law.
| Date | Event |
|---|---|
| 7 November 2019 | Australia’s AI Ethics Principles published (8 voluntary principles) |
| 1 September 2024 | DTA Policy for the responsible use of AI in government (v1.1) takes effect for federal agencies |
| 5 September 2024 | Voluntary AI Safety Standard published with 10 guardrails |
| 2024 | Government consults on mandatory guardrails for AI in high-risk settings |
| 10 December 2024 | Privacy and Other Legislation Amendment Act 2024 receives Royal Assent |
| 10 June 2025 | Statutory tort for serious invasions of privacy commences |
| 21 October 2025 | Guidance for AI Adoption published: 6 essential practices replace the 10 guardrails as the starting point |
| 2 December 2025 | National AI Plan released; relies on existing laws and announces the AI Safety Institute |
| 15 December 2025 | DTA AI policy version 2.0 takes effect |
| 10 December 2026 | Privacy Act automated decision-making disclosures (APP 1.7 to 1.9) commence |
What AI laws apply in Australia right now?
Most of the legal risk in an AI system comes from laws you already know, applied to new failure modes. The National AI Centre’s summary of AI and Australian law groups them by the harm they address. The table maps that summary to what engineering teams actually control.
| Risk | Laws that can apply | What the software team controls |
|---|---|---|
| Insecure AI systems, data leakage | Privacy Act (APP 11), directors’ duties, Security of Critical Infrastructure Act, sector rules, negligence | Access control, prompt injection defences, logging, secrets handling |
| Misleading outputs | Australian Consumer Law (misleading and deceptive conduct) | Grounding, citations, disclaimers, honest claims about what the AI can do |
| Harmful or defective outputs | Product liability, WHS laws, online safety laws, defamation, negligence | Evaluation, content filters, human review for high-impact outputs |
| Misuse of data | Privacy Act, copyright, confidentiality, contract | Data provenance records, consent flags, licensing checks on training data |
| Inaccurate outputs | Privacy Act (APP 10), ACL statutory guarantees | Accuracy testing, monitoring, correction workflows |
| Bias and exclusion | Federal and state anti-discrimination law, Fair Work Act | Bias testing across groups, accessible design, contestability |
| Supply chain | Privacy Act transparency, ACL unfair contract terms, competition law | Vendor due diligence, contract terms, documentation passed downstream |
The government’s summary also notes that Fair Work obligations can require consulting employees before introducing AI in the workplace, and that state laws apply where AI is used for workplace surveillance.
Are there Australian laws on deepfakes and AI copyright?
Deepfakes: yes, for sexual material. Copyright: existing law applies, and the government lists copyright and AI as an area of ongoing work rather than a settled new rule.
The Criminal Code Amendment (Deepfake Sexual Material) Act 2024 added section 474.17A to the Criminal Code. It makes it an offence to use a carriage service to transmit sexual material depicting an adult without their consent, and it expressly covers material that has been “created, or altered in any way, using technology”. It is written with generated and manipulated content in mind, even though it doesn’t use the word AI. Other deepfake harms, such as scams, defamation or impersonation, fall under consumer, defamation, online safety and criminal law.
On copyright, the National AI Plan includes work on copyright and AI among its targeted reforms. Unless and until that work changes the law, the Copyright Act 1968 applies to AI training data and outputs in the same way it applies to anything else, which is why the risk table above lists copyright under misuse of data. If your product trains on or reproduces third-party content, get copyright advice specific to your use.
What’s actually new and binding?
Three things carry specific new obligations, and only one applies to most private businesses.
- Privacy Act automated decisions (10 December 2026). APP entities must describe in their privacy policy the kinds of personal information used, and the kinds of decisions made, when computer programs make or substantially assist decisions that could significantly affect individuals. It applies to rules engines as well as AI. See our guide to the Privacy Act automated decision-making rules.
- Stronger Privacy Act enforcement (from 11 December 2024). New civil penalty tiers, infringement notices for lower-level breaches such as privacy policy defects, and a statutory tort for serious invasions of privacy from 10 June 2025. Our guide to using personal information in AI systems covers how these apply.
- The DTA AI policy for federal agencies. Mandatory for non-corporate Commonwealth entities, with requirements for accountable officials, transparency statements, use case registers and impact assessments. Suppliers feel it through procurement. See the DTA AI policy.
Sector regulators add their own layers. APRA’s prudential standards on information security and operational risk apply to AI systems at banks, insurers and super funds, and the TGA regulates AI that meets the definition of a medical device.
What is voluntary but expected?
The Guidance for AI Adoption is the government’s recommended baseline, and it is what customers, boards and auditors increasingly ask about. It sets out 6 essential practices: decide who is accountable, understand impacts and plan accordingly, measure and manage risks, share essential information, test and monitor, and maintain human control. It comes in a foundations version for early or low-risk use and an implementation version for complex or higher-risk use. Our explainer on the Guidance for AI Adoption turns each practice into engineering tasks, and the older AI Ethics Principles remain the values underneath.
Voluntary doesn’t mean irrelevant. When a regulator or court asks whether you took reasonable steps, published government guidance is an obvious benchmark.
What does the AI Safety Institute do?
Australia’s AI Safety Institute, part of the Department of Industry, Science and Resources, analyses advanced AI capabilities and supports regulators; it doesn’t license or approve AI systems. Its stated goals are to analyse and test new AI models, support regulators and agencies responding to AI risks, and shape safe AI development and international governance. It works with the Australian Signals Directorate and CSIRO and takes part in joint international testing of frontier models. For a business building AI, it is a source of research and signals about where regulation may tighten, not a gatekeeper.
Worked example: one AI feature, many laws
A single, ordinary AI feature can engage half a dozen laws at once, which is why “there’s no AI Act” is not a reason to skip governance. Take a property management platform that adds an AI tenant screening assistant. It reads rental applications, summarises income and rental history, and produces a suitability score for the property manager.
- Privacy Act. Applications contain personal and sometimes sensitive information. APP 3 governs what is collected, APP 6 limits reuse (for example, training a model on past applicants), APP 10 requires accuracy, and APP 11 requires security. From 10 December 2026, the score is likely to be a thing substantially and directly related to a decision affecting access to housing, so the privacy policy must describe it.
- Anti-discrimination law. If the score correlates with age, disability, race or family status, even indirectly through postcode or employment gaps, the platform and its customers are exposed. That means bias testing across groups before release, not after a complaint.
- Australian Consumer Law. Marketing the assistant as “objective” or “unbiased” without evidence risks misleading conduct. The claims have to match the test results.
- State residential tenancy laws. These can limit what information may be requested from applicants and how it is used, and they differ between states. Check each state the platform operates in.
- Contract and negligence. The property manager’s customers, the landlords, rely on the output. Clear documentation of limitations and a human decision point reduce the risk of a system failure turning into a liability claim.
The engineering response is the same regardless of which law you worry about most: minimise the data, record where it came from, test for accuracy and bias, log each score with its inputs and model version, keep a human making the final decision, and tell applicants how the process works. Doing those things once satisfies most of the laws above at the same time.
How does Australia compare with the EU?
The EU regulates AI through a dedicated, risk-tiered law; Australia regulates it through the laws that already govern the harm. The EU AI Act sorts systems into prohibited, high-risk and lower-risk categories with obligations attached to each. Its scope clause, Article 2, covers providers placing AI systems on the EU market regardless of where they are established, and providers and deployers outside the EU where a system’s output is used in the EU. An Australian SaaS company with European customers can therefore have EU AI Act obligations even though Australia has no equivalent. The EU has amended its staged application dates since the Act entered into force, so check the current timetable with EU counsel rather than relying on older summaries.
Practical checklist: building AI in Australia without an AI Act
- List every AI system and automated decision you run, including features embedded in vendor products.
- For each, note which existing laws are engaged: privacy, consumer, discrimination, WHS, sector rules.
- Check whether any system makes or substantially assists significant decisions about people, ahead of 10 December 2026.
- Test accuracy and bias before release and monitor after, with results kept on file.
- Make sure marketing and in-product claims about the AI are accurate, to avoid misleading conduct.
- Give users a way to query or challenge AI outputs that affect them.
- Map your practices against the 6 essential practices in the Guidance for AI Adoption.
- If you sell to federal agencies, prepare the information they need under the DTA policy.
- If you have EU customers, get advice on the EU AI Act.
- Put a date on this review and repeat it at least every six months.
How All Webbed Labs approaches this
We build AI systems so the evidence of responsible design exists as part of the codebase: an inventory of AI features and automated decisions, evaluation results, decision logs, and documentation of data sources and vendors. That evidence supports your legal and risk teams; it doesn’t replace their judgement, and we don’t certify that any system meets the law. See our AI governance and responsible AI engineering service and our guide to evaluating an LLM application before launch.
Frequently asked questions
Does Australia have an AI Act like the EU?
No. At the time of writing there is no Australian equivalent of the EU AI Act. The National AI Plan of 2 December 2025 says the government's regulatory approach will build on existing legal and regulatory frameworks, with regulators responsible for AI harms in their own domains, and targeted new laws where gaps are found.
What happened to the mandatory guardrails for high-risk AI?
The Department of Industry, Science and Resources consulted on mandatory guardrails for AI in high-risk settings in 2024. The National AI Plan did not adopt them. Instead it relies on existing laws, the AI Safety Institute and voluntary guidance, while saying the government will intervene if more regulation is needed.
Is the Voluntary AI Safety Standard still current?
It has been superseded as the recommended starting point. On 21 October 2025 the National AI Centre published the Guidance for AI Adoption, which condenses the 10 voluntary guardrails into 6 essential practices. The standard remains published for reference.
Which laws apply to AI in Australia right now?
The government's own summary lists privacy law, the Australian Consumer Law, anti-discrimination law, online safety law, work health and safety law, product liability, negligence, defamation, intellectual property, directors' duties, competition and criminal law, and sector rules such as financial services laws and the Security of Critical Infrastructure Act.
Is an Australian AI law coming?
Targeted changes are more likely than a single AI Act. The National AI Plan lists work on privacy reform, copyright and AI, consumer law clarifications, AI in healthcare and medical device software, and online harms. Check this page's updated date, since the landscape moves quickly.
Does the EU AI Act apply to Australian companies?
It can. The EU AI Act applies to providers placing AI systems on the EU market and to systems whose outputs are used in the EU, regardless of where the provider is established. If you sell software to European customers, get EU legal advice on your obligations.
This page is general information about Australian law and regulation, current at the date shown. It is not legal advice. Get advice from a qualified lawyer about your circumstances.
Sources
- National AI Plan (2 December 2025) , Department of Industry, Science and Resources
- National AI Plan: Keep Australians safe , Department of Industry, Science and Resources
- AI and Australian law , National AI Centre
- Australia's AI Safety Institute , Department of Industry, Science and Resources
- Voluntary AI Safety Standard , National Artificial Intelligence Centre
- Policy for the responsible use of AI in government , Digital Transformation Agency
- EU Artificial Intelligence Act, Article 2: Scope , Future of Life Institute (EU AI Act Explorer)
- Criminal Code Amendment (Deepfake Sexual Material) Act 2024 (No. 78, 2024) , Federal Register of Legislation
- Privacy and Other Legislation Amendment Act 2024 (No. 128, 2024), as made , Federal Register of Legislation