Knowledge Hub Australian AI regulation

Australian AI regulation, explained

Australia does not yet have a single AI law. Organisations work across a mix of frameworks already in force: the voluntary AI Ethics Principles (2019) and Guidance for AI Adoption (October 2025), the Privacy Act 1988 as reformed, APRA CPS 230 for regulated financial entities, ASIC's guidance for licensees, and a set of mandatory AI Standards announced in July 2026 with legislation expected in early 2027. This page maps each framework to who it affects, with a detailed explainer for each.

In brief
  • No single Australian AI law exists yet. Organisations are working across several frameworks at once, some voluntary, some already mandatory.
  • Two broad, non-sector frameworks (the AI Ethics Principles and the Guidance for AI Adoption) sit alongside sector-specific rules (the Privacy Act, APRA CPS 230, ASIC guidance) and a horizontal set of mandatory AI Standards taking shape for 2027.
  • Which frameworks matter most depends on sector: financial services carries the heaviest load, working across APRA, ASIC and the Privacy Act together, while most other sectors mainly need the AI Ethics Principles, the Guidance for AI Adoption and the Privacy Act.
Plain English

Voluntary means there is no fine for ignoring a framework on its own. It does not mean optional in practice: the AI Ethics Principles and the Guidance for AI Adoption are already the yardstick regulators, auditors and clients reach for when judging whether an organisation's AI use was responsible.

A regulated entity is APRA's term for the banks, insurers and superannuation trustees that CPS 230 applies to. An AFS licensee or credit licensee is who ASIC's guidance is written for. If neither term describes your organisation, CPS 230 and ASIC's guidance are useful context but are not obligations that apply to you directly.

Explainers in this section

Each framework gets its own detailed page, checked against the regulator's own source document before publishing.

Live

Australia's AI Ethics Principles explained for business leaders

The eight voluntary principles published in 2019: what they require, and how the Guidance for AI Adoption builds on them.

Read the explainer
Coming soon

Australia's Guidance for AI Adoption: the six essential practices

A practical walkthrough of the six practices released by the National AI Centre in October 2025, with how to apply each one.

Publishing soon
Coming soon

From principles to practice: mapping the six practices to the eight principles

Which of the six essential practices operationalises which principle, with worked scenarios for organisations at different stages.

Publishing soon
Coming soon

Privacy Act 1988 and AI: what the reforms mean for your organisation

What the Privacy Act reforms change for organisations using AI to process personal information, and where the gaps still sit.

Publishing soon
Coming soon

APRA CPS 230 and AI: what financial services firms need to build

What operational resilience under CPS 230 requires when AI sits inside a critical business function or a third-party arrangement.

Publishing soon
Coming soon

ASIC's guidance on AI: what it means for financial services and consulting

How ASIC expects licensees to govern AI use under existing obligations, and what that means in practice for advice and disclosure.

Publishing soon
Australian context

Three separate regulatory threads are easy to conflate and worth keeping straight. The AI Ethics Principles (2019) are the foundational voluntary framework. The Voluntary AI Safety Standard's ten guardrails (August 2024) were streamlined into the Guidance for AI Adoption's six essential practices, released by the National AI Centre in October 2025, a later stage of the same thread. The mandatory AI Standards, announced 15 July 2026 by the Office of AI and covering areas including data centres, copyright and national security, are a separate, newer thread, with legislation expected in early 2027, not a direct evolution of either of the first two.

Sources: Department of Industry, Science and Resources, Australia's AI Ethics Principles, 2019; National AI Centre, Guidance for AI Adoption, October 2025; Office of AI, AI Standards announcement, 15 July 2026.

Frequently asked

Is there a single AI law in Australia?

Not yet. Australia currently governs AI through a mix of voluntary frameworks, existing law applied to AI, and sector-specific rules. Mandatory AI Standards were announced in July 2026, with legislation expected in early 2027, which will be the closest Australia has come to a single horizontal AI law.

Which of these frameworks actually applies to my organisation?

It depends on sector. The AI Ethics Principles, the Guidance for AI Adoption and the Privacy Act 1988 apply broadly to any organisation using AI. APRA CPS 230 applies only to APRA-regulated entities, banks, insurers and superannuation trustees. ASIC's guidance applies to AFS and credit licensees. Most financial services organisations need to work across all of them at once.

What is the difference between the AI Ethics Principles and the mandatory AI Standards?

The AI Ethics Principles, published in 2019, are voluntary and set out what responsible AI looks like at a high level. The AI Standards, announced in July 2026 by the Office of AI, are a separate and later thread covering areas including data centres, copyright and national security, and are expected to carry legislated force from early 2027.

Working through this regulatory landscape in a structured way is what AAAI's certifications are built around. If you're establishing baseline AI capability, start with AI Core. If you're accountable for AI strategy and governance, CAIS: Certified AI Strategist goes deep on exactly this territory.

Explore AI Core Explore CAIS