Skip to main content
Skip to content

AI compliance for Australian business

Australia has no single AI law. Your existing obligations still apply.

There is no Commonwealth AI Act and no mandatory AI guardrails in force. What governs your use of AI is the law you already had: privacy, consumer, work health and safety, employment and copyright. None of it stopped applying because the work was done by a model.

So the practical question is not whether your business is allowed to use AI. It is whether you know what AI it is already using, who is accountable for it, what information goes into it, and whether any of that is recorded anywhere.

General information about Australian obligations, not legal advice.

Where AI actually lands
1
Privacy law Privacy obligations attach to personal information put into an AI system and to personal information the system generates.
2
Reasonable steps APP 11 asks for steps that are reasonable in the circumstances. Since December 2024 the clause says those steps include technical and organisational measures.
3
Existing law, not new law Consumer, work health and safety, employment, copyright and confidentiality obligations all reach AI use without needing an AI statute.
4
Voluntary guidance The Australian Government's six essential practices for AI governance are guidance, not obligation. They are still the clearest description of what good looks like here.
Privacy Act 1988
APP 11 reasonable steps
Guidance for AI Adoption
ASD's ACSC
Definition

What is AI compliance in Australia?

AI compliance in Australia means meeting the legal obligations you already have in the way your organisation actually uses AI, and being able to show that you did. There is no single Australian AI statute to comply with, so compliance is not measured against an AI law. It is measured against privacy, consumer, work health and safety, employment, anti-discrimination and copyright obligations that apply to AI the same way they apply to anything else the business does.

In practice it covers four things: knowing which AI systems the business uses, deciding what information may go into them and who is accountable, keeping a person in control of outputs and decisions that affect others, and keeping dated records of those decisions.

Two consequences follow from that definition. The first is that a business cannot be compliant or non-compliant with "AI" as such: it is compliant or otherwise with the specific obligations its AI use engages, which depend on what information is involved and what the AI is being used to decide. The second is that most of the work is organisational rather than technical, because the obligations attach to decisions a business makes and can evidence, not to the software it has licensed.

The regulatory position

Does Australia have an AI law?

No. As at August 2026 there is no Australian law that regulates artificial intelligence specifically, and no mandatory Commonwealth AI guardrails are in force. AI use is governed by existing, largely technology-neutral law. The Australian Government confirmed that approach in the National AI Plan, released on 2 December 2025.

This is worth stating plainly, because a lot of published material still describes a regime that never arrived. In September 2024 the Department of Industry, Science and Resources released a proposals paper on mandatory guardrails for AI in high-risk settings. It set out ten proposed guardrails and consulted on making them binding. That proposal did not become a Bill. The National AI Plan instead commits to building on existing legal frameworks, with regulators handling AI harms inside their own domains and an AI Safety Institute being established to advise them.

If you read an article telling you that ten mandatory guardrails apply to your business, check its date. They were a consultation position, not law.

What is not in force

  • A Commonwealth AI Act.
  • Mandatory guardrails for high-risk AI in the private sector.
  • A licensing or registration regime for AI systems.
  • A general legal duty to label AI-generated content.

The government has said it will legislate further if existing law proves inadequate. Nothing here suggests the position is permanent, only that it is the position now.

What is in force

  • The Privacy Act 1988 and the Australian Privacy Principles, in full, wherever AI touches personal information.
  • The Notifiable Data Breach scheme, including where the exposure happened through an AI tool.
  • Australian Consumer Law, including misleading and deceptive conduct and the consumer guarantees.
  • Work health and safety, employment, anti-discrimination, copyright, confidentiality and directors' duties.
  • A statutory tort for serious invasions of privacy, which commenced on 10 June 2025.

One dated obligation is coming

From 10 December 2026, an APP entity that has arranged for a computer program to make, or to do something substantially and directly related to making, a decision that could reasonably be expected to significantly affect an individual's rights or interests must say so in its privacy policy. The disclosure covers the kinds of personal information used and the kinds of decisions involved. It does not require you to explain the logic of a model or to justify an individual decision.

This is narrower than it sounds. Drafting, summarising, transcription and documenting a decision a person has already made are not captured. Shortlisting job applicants, pricing risk or deciding eligibility can be. What this means for your privacy policy.

Sources: National AI Plan (Department of Industry, Science and Resources, 2 December 2025); AI and Australian law (National AI Centre); Privacy and Other Legislation Amendment Act 2024 (Cth).

The obligations that reach AI

Which existing obligations apply when a business uses AI?

For most Australian small and medium businesses the answer starts and ends with privacy law, because the AI use that matters is staff putting information about people into a tool owned by somebody else. The rows below are the ones that come up in practice.

Obligation How it reaches AI use
APP 1
Open and transparent management
Requires a clearly expressed and up to date privacy policy, and practices and procedures that make compliance happen. The OAIC expects businesses to describe their use of AI in the policy and to have internal rules for it.
APP 3
Collection
Where an AI system generates or infers information about an identifiable person, that is a collection. It has to be reasonably necessary for your functions and collected by lawful and fair means.
APP 5
Notification
Notices at the point of collection should cover AI-related purposes and any disclosure to an AI provider. If the provider can access what you put in, that is a disclosure.
APP 6
Use and disclosure
Personal information can only be used or disclosed for the purpose it was collected for, unless an exception applies. Pasting a client record into a public chatbot is usually a disclosure to the provider, and it needs to survive that test.
APP 8
Cross-border disclosure
Most widely used AI services process outside Australia. If personal information leaves the country, APP 8 is engaged and you generally remain accountable for what the overseas recipient does with it.
APP 10
Accuracy
Generative systems produce confident errors. Where AI output about a person feeds a record or a decision, accuracy obligations still sit with you, not the vendor.
APP 11
Security
Reasonable steps to protect the personal information you hold. Since 11 December 2024 the clause states that those steps include technical and organisational measures.
NDB scheme
Part IIIC, Privacy Act
An unauthorised disclosure through an AI tool can be an eligible data breach. The ACSC records an Australian case where a contractor uploaded names, contact details and health records into an AI system and it was treated as a notifiable breach.
APP 1.7 to 1.9
From 10 December 2026
Privacy policy disclosure where a computer program makes, or substantially contributes to, decisions that significantly affect a person's rights or interests.
Australian Consumer Law Misleading or deceptive conduct covers AI-generated claims, and silence about AI use where it matters. Treasury's review found consumers get the same protections for AI-enabled goods and services as for anything else.
Work health and safety A business cannot transfer responsibility to a system. Where AI is used in rostering, monitoring or performance management, physical and psychosocial risk obligations follow.
Copyright and confidentiality Client material, source code and third-party content put into a tool are still governed by the contract and the duty of confidence that covered them before.

Whether the Privacy Act applies to you at all

A small business operator with annual turnover of $3 million or less is generally outside the Privacy Act. That exemption is narrower than most owners assume. It does not apply to a business that provides a health service and holds health information, which captures allied health, dental, psychology and most clinics regardless of size. It does not apply to businesses that trade in personal information or that are contracted service providers under a Commonwealth contract. Tax file number obligations apply to anyone who handles TFNs, exemption or not. And turnover is measured once: a single financial year above the threshold takes a business out of the exemption permanently.

If your organisation is exempt, the material below is still the sensible standard to work to. Clients, insurers and larger customers ask the same questions the Act does. More on Privacy Act obligations.

Reasonable steps

Why does APP 11 matter more once AI is in the picture?

Because AI moves personal information out of systems you control and into systems you do not, usually without anyone deciding that it should. APP 11 does not ask whether you were unlucky. It asks what steps you had taken, and whether they were reasonable given the information you hold and the risk you face.

Reasonable steps have never been a fixed checklist. They depend on the sensitivity of the information, the size and nature of the organisation, and the harm that would follow if the information were exposed. What changed in December 2024 is that APP 11.3 now states expressly that the steps include technical and organisational measures. The organisational half is the half that is usually assumed rather than done: who owns the decision, whether staff were told, whether anyone checked.

AI is a clean illustration of why that half matters. A firewall does not stop an employee pasting a client file into a browser tab. What stops it is a decision about which tools are approved, a rule that says what may go into them, training that reaches the people doing the work, and someone whose job it is to notice when the position drifts.

Technical

What your IT provider owns

Identity and access controls, endpoint protection, encryption, blocking or allowing specific services, tenant configuration, logging. Real and necessary, and not sufficient on its own.

Organisational

What management owns

Which tools are approved, what information may be entered, who assesses a new provider, who reviews outputs before they are relied on, who is told when something goes wrong.

Evidential

What has to exist afterwards

A dated record that those decisions were made, communicated and reviewed. After an incident, the question is what was in place beforehand, and reconstruction carries little weight.

The everyday decision

What should staff be allowed to put into ChatGPT, Claude, Copilot or Gemini?

The OAIC recommends as a matter of best practice that organisations do not enter personal information, and particularly sensitive information, into publicly available generative AI tools. That is a recommendation rather than a prohibition, and it applies to the public products. A business account with assessed terms sits differently, which is exactly why the organisation has to make the decision rather than leaving it to each staff member.

The moment personal information is entered into a system the provider can access, it is a disclosure under APP 6, and once it is in a generative system it is very difficult to trace or retrieve. That is the reasoning behind the OAIC's position, and it is also why "we told everyone to be careful" is a weak answer.

Usually straightforward

  • Information already public, such as your own published material.
  • Drafting and rewriting where no client or staff details are included.
  • General research and explanation, verified before it is relied on.
  • Structuring or summarising a document you have already de-identified.
  • Code and configuration that contain no secrets and no client data.

Needs a decision before it happens

  • Anything identifying a customer, client, patient or employee.
  • Health, financial, biometric or other sensitive information.
  • Client files, contracts and material held under confidentiality obligations.
  • Credentials, API keys and anything that grants access to a system.
  • Recordings and transcripts of meetings with people outside the business.
  • Anything feeding a decision about a person's employment, credit, care or eligibility.

The list on the right is not a prohibition

Plenty of Australian businesses legitimately process client information through AI services. The difference between doing that well and doing it by accident is whether the service was assessed, whether the terms and settings were checked, whether the arrangement is recorded, and whether the people doing the work know which account they are supposed to use. Can staff put customer information into ChatGPT?

Security

What AI actually changes about your security position

The ASD's Australian Cyber Security Centre published guidance for small business on this in January 2026, with the New Zealand NCSC and the Council of Small Business Organisations Australia. It groups the risk into three, and none of the three is a new class of attacker.

Risk one

Data leaks and privacy breaches

Staff paste customer, employee or financial detail into a tool with no idea whether the provider retains it or uses it for training. Configuration and subscription tier decide that, and almost nobody checks.

Risk two

Unreliable or manipulated output

Hallucinated facts and prompt injection both produce answers that read correctly and are not. The consequence lands on the business that acted on them, not on the model.

Risk three

Supply chain dependency

An AI feature inside a product you already use inherits that vendor's security, infrastructure and subprocessors. Their weakness becomes your exposure, and you may not know they are in the chain.

Governance

What governance should a small or medium business establish?

Enough to answer four questions without going away to find out: what AI are we using, who is accountable for it, what information is allowed near it, and who checks the output. Everything else is refinement.

The Australian Government's Guidance for AI Adoption, published by the National AI Centre in October 2025, sets out six essential practices: decide who is accountable, understand impacts and plan accordingly, measure and manage risks, share essential information, test and monitor, and maintain human control. It is voluntary and it replaces the 2024 Voluntary AI Safety Standard, condensing its ten guardrails into six. It is written for organisations of any size, and its getting-started actions are genuinely achievable in a twenty-person business.

A note in that guidance is worth repeating, because it is the point most summaries skip: keep clear records of the actions you take under each practice, because good documentation is what lets you audit and review your governance later.

Essential practice What it looks like in a business without a governance team
Decide who is accountableOne named senior person owns AI use. Not a committee, and not the IT provider, who does not control what staff type into a browser.
Understand impacts and plan accordinglyWork out who is affected by each use. Drafting an internal email and screening a job applicant are not the same decision and should not get the same treatment.
Measure and manage risksA short screening step before a new tool goes into use, and a record of what was decided and why.
Share essential informationA register of the AI systems in use, including AI features inside software you already licence. Tell people when they are dealing with AI rather than a person.
Test and monitorAsk the supplier for evidence the system was tested. Check that it still behaves as expected once it is in use, at a frequency that matches the stakes.
Maintain human controlA person reviews output before it is relied on, published or sent, and that person has the standing to override it.
The distinction that matters

AI can generate your policy. It cannot generate proof that you followed it.

An organisation can produce a complete set of AI, privacy and security policies in an afternoon now. That is genuinely useful. It is also the point at which a lot of businesses stop, believing the work is done, because the folder looks the way a compliant business's folder looks.

Reasonable steps are not a document set. They are what the organisation put in place, what people actually did, and what can substantiate it.

AI can help you produce What the organisation still has to be able to show
An AI usage policyThat it was approved, issued to staff, acknowledged, and reviewed on a date somebody owns.
Training material about AI riskThat named people completed training appropriate to their role, and when.
A supplier assessment questionnaireThat someone assessed the supplier, recorded the answers, and made a decision to approve or refuse.
A risk assessmentThat the risk was considered, rated, assigned to an owner and treated or accepted deliberately.
A security procedureThat the control is actually implemented and still working, checked on a date.
Management review minutesThat the review happened, that these people attended, and that the decisions in it were owned.

This is not an argument against using AI for compliance work

AI-drafted documentation is not invalid, and treating it as suspect would be wrong. A well-drafted policy is a real improvement over no policy. The precise point is narrower: generated text describes an intended state. It cannot stand in for the implementation, the decision, the activity or the review that the text describes. Ten excellent policies produced in an afternoon are an improvement in documented governance, and they are not ten reasonable steps.

Why AI does not change the reasonable steps question, and what evidence to keep about your use of AI.

Where a compliance platform fits

The organisational layer is the part that has to be maintained

Cleverer is an Australian cyber compliance platform. It does not scan systems, connect to your tenant or monitor AI traffic. It holds the layer around those controls: the policies and who adopted them, the responsibilities and who owns them, training by role, the supplier and asset registers, the risks and their treatment, the incidents, the open gaps and the reviews, each with a date against it.

An AI Governance Policy that reflects your answers

The Policy Builder includes an AI Governance Policy. It asks what tools are in use, whether personal or sensitive data goes into them and whether output is reviewed, then writes the document around the answers given, including where the honest answer is that nobody knows yet.

AI providers in the supplier register

An AI service is a third party that receives your information. The vendor register records what data types it receives, where it is stored, whether the disclosure is offshore, whether subprocessors are known, whether a contract is in place, who owns the relationship and when it is next reviewed.

Dated records instead of reconstruction

Policy adoption and acknowledgement, training completions by name, assigned obligations, management review, incidents and the evidence behind each control, all exportable as one dated Evidence Pack when a client, insurer or regulator asks.

No platform can guarantee legal compliance, and Cleverer does not claim to. What it does is let an organisation establish, maintain and demonstrate the reasonable steps it has actually taken. How the evidence system works.

The rest of this guide

Go deeper on the part that applies to you

Obligation

AI and reasonable steps

The difference between a document, an implementation, an activity, evidence and a review, and why AI makes the distinction sharper.

Read the guide

Privacy

Does your privacy policy need to mention AI?

What the OAIC actually says, what the December 2026 change requires, and the questions to answer before you edit a word of the policy.

Read the guide

Policy

What an AI usage policy should control

The decisions a policy has to embody to be worth anything, and the seven steps that come after it is written.

Read the guide

Governance

AI governance without a GRC team

A governance model sized for ten, twenty, fifty or a hundred people, aligned to the six essential practices.

Read the guide

Security

AI security for small business

The exposure created by ordinary staff usage, the supplier questions worth asking, and where it connects to controls you already run.

Read the guide

Evidence

What evidence to keep about AI

Sixteen concrete records, the difference between evidence of a position and evidence of a control operating, and an evidence map you can copy.

Read the guide

Practical

Can staff put customer information into ChatGPT?

The real answer, covering Claude, Copilot and Gemini as well, and what changes between a personal account and a business one.

Read the guide

Sector

Medical and allied health practices

Health information is sensitive information, and the small business exemption does not reach a practice that holds it.

Read the guide

Sector

Law firms

Confidentiality, privilege, court practice notes on generative AI, and the verification obligation that sits behind all three.

Read the guide

Sector

Accounting and bookkeeping firms

Tax file numbers, client financial records, and why the turnover exemption is not the end of the question.

Read the guide

Sector

Financial services and advice

What ASIC found when it looked at AI governance in licensees, and what that implies for a small advice practice.

Read the guide

Assessment

Cyber Compliance Readiness Check

Benchmarks policies, training, responsibilities, registers and evidence against what a business in your position should be able to show.

Open the check

See what your organisation could actually show

Most businesses reading this already have technical controls in place and no record of the decisions around them. The Readiness Check takes a few minutes and tells you which side of that line you are on.

FAQ

Common questions about AI compliance in Australia

Does Australia have an AI law?

No. As at August 2026 there is no Australian law regulating artificial intelligence specifically and no mandatory Commonwealth AI guardrails are in force. The mandatory guardrails consulted on in September 2024 did not proceed. The National AI Plan, released on 2 December 2025, confirms the government's approach is to apply existing, largely technology-neutral law and to legislate further only where gaps appear.

Does the Privacy Act apply when a business uses AI?

Yes, wherever personal information is involved. The Privacy Act and the Australian Privacy Principles apply to personal information entered into an AI system and to personal information the system generates or infers, including where that output is inaccurate. Whether the Act applies to your business at all depends on turnover and the exceptions to the small business exemption.

Does APP 11 apply when staff use AI tools?

Yes. APP 11 requires an APP entity to take reasonable steps to protect the personal information it holds, and since 11 December 2024 the clause states that those steps include technical and organisational measures. Where staff can move personal information into a third-party AI service, the organisational measures are the ones that decide whether the position is defensible.

Do the six essential practices in the Guidance for AI Adoption apply to my business?

They are voluntary. The Guidance for AI Adoption was published by the National AI Centre in October 2025 and replaces the 2024 Voluntary AI Safety Standard. It carries no legal force in itself. It is still the clearest Australian statement of what reasonable AI governance looks like, which makes it a sensible benchmark and a reasonable thing to be measured against by a client or an insurer.

Is an AI-generated policy evidence of compliance?

It is evidence that a policy exists. It is not evidence that the policy was approved, issued, understood, followed or reviewed, and it says nothing about whether the controls it describes are actually in place. That gap matters more now that a complete policy set can be produced in an afternoon, because the document set no longer distinguishes an organisation that has done the work from one that has not.

Who should be responsible for AI governance in a small business?

A named senior person with the authority to approve or refuse a tool. Australian guidance is explicit that a senior leader should own AI governance overall. In a smaller organisation that is usually the owner, a director or an operations lead. It should not default to the IT provider, who has no control over what staff type into a browser and no standing to set business rules.

Should AI providers be recorded in the vendor register?

Yes. An AI service that receives your information is a third party like any other, and it is often the one with the least clarity around retention, training use, subprocessors and where processing happens. Recording it alongside your other suppliers, with an owner and a review date, is the practical way to keep the assessment from being a one-off.

© 2026 Cleverer. Human-layer cyber compliance for Australian businesses.