Skip to content
Research

Regulation

Australia's AI Regulation Gap: What the Lack of Mandatory Guardrails Means for Your Business

Amulet TeamAmulet AI
10 min read

Australia is one of the most AI-active economies in the Asia-Pacific region. It's also one with a conspicuous gap at the centre of its AI governance framework: no mandatory AI-specific regulation for businesses deploying AI systems.

While the European Union has its AI Act, and the United States is developing federal AI standards, Australia has taken a different path — leaning on existing "technology-neutral" laws, voluntary guidance, and a wait-and-see approach to binding rules. In late 2025 and early 2026, that approach became more pronounced: the government scrapped its expert AI advisory body, replaced its Voluntary AI Safety Standard with broader guidance, and paused work on mandatory guardrails.

For businesses, this creates an unusual situation: less regulatory compliance burden in the short term, but significant uncertainty about what's coming — and real exposure from the laws that do apply, which are often opaque in their AI-specific implications.


The Regulatory Landscape as It Stands

Australia currently regulates AI through existing legislation rather than AI-specific laws. The relevant frameworks include:

  • Privacy Act 1988 (Cth) — as amended by the Privacy and Other Legislation Amendment Act 2024, including the new automated decision-making transparency requirements commencing December 2026
  • Competition and Consumer Act 2010 (Cth) — covering misleading and deceptive conduct, including by AI-driven systems
  • Corporations Act 2001 (Cth) — covering directors' duties and financial services obligations where AI is used in regulated activities
  • Anti-Discrimination legislation — state and federal laws prohibiting discriminatory outcomes, regardless of whether they're produced by a human or an algorithm
  • Online Safety Act 2021 (Cth) — covering harmful online content, including AI-generated content

The Department of Industry, Science and Resources (DISR) published updated Guidance for AI Adoption in October 2025, outlining six essential practices for safe and responsible AI governance. This replaced the previous Voluntary AI Safety Standard but does not carry legal force.

The Scrapped Advisory Body: What It Means

In December 2025, DISR confirmed in Senate Estimates that appointments to the government's permanent AI Advisory Body would not proceed. The body had been in development for 15 months.

In February 2026, ABC News reported that the scrapping of the body was drawing criticism from AI safety experts who feared ongoing delays to AI regulation could cause Australia to miss a limited window to properly safeguard citizens and businesses from AI harms.

The AI Safety Hub noted that the government has "paused work on standalone AI-specific legislation and mandatory guardrails, instead relying on existing 'technology-neutral' laws and regulators, supported by a new AI Safety Institute" announced in November 2025.

What this signals for businesses: do not expect new mandatory AI-specific compliance obligations in the near term. The government is not moving toward EU-style AI regulation. But this doesn't mean the regulatory risk is low — it means that existing laws will be applied to AI contexts with increasing vigour, and the standards by which they're applied may not be predictable.


Where Australia Has Acted: Age Verification and Online Safety

While mandatory AI guardrails have been deprioritised, Australia has moved decisively in one adjacent area: online safety and age verification.

The Online Safety Amendment (Social Media Minimum Age) Act 2024 requires social media platforms to take reasonable steps to prevent users under 16 from having accounts. Platforms that fail to comply face civil penalties of up to $49.5 million AUD.

In July 2025, the Minister for Communications made legislative rules specifying which platforms are covered and what counts as "reasonable steps." This represents Australia's most aggressive regulatory intervention in the digital platform space to date — and it relies heavily on AI-based age verification systems to work in practice.

The significance for AI businesses: the government is clearly willing to use heavy financial penalties to enforce online safety obligations. The precedent matters. When mandatory AI rules eventually arrive — and most experts believe they will — the enforcement model being established now suggests the penalties will be substantial.


The Voluntary vs. Mandatory Debate

The core tension in Australian AI policy is between two positions:

The voluntary approach argues that prescriptive AI regulation risks stifling innovation, creating compliance burdens that disadvantage Australian businesses against overseas competitors, and locking in rules that don't keep pace with technological change. Better to let industry self-regulate and enforce existing laws, the argument goes. The mandatory approach argues that voluntary frameworks create a race to the bottom, that existing laws weren't designed for AI and leave significant gaps, and that without binding rules, harms will accumulate before anyone acts. Critics point to the scrapping of the advisory body as evidence that the government isn't moving fast enough on even the voluntary framework.

The Conversation has noted that Australia's regulatory approach creates risks: businesses deploying AI for consequential decisions — hiring, lending, pricing, healthcare — may be doing so with no obligation to audit for bias, explain decisions, or provide human review. The EU's AI Act would require all of this. Australia's framework requires none of it explicitly.

For businesses, this means: the current environment permits a lot. But it also means that when things go wrong — biased hiring outcomes, discriminatory pricing, privacy breaches enabled by AI — existing laws will be applied in ways that may not have been clearly anticipated.


What "Technology-Neutral" Regulation Actually Means in Practice

DISR's position is that existing laws apply to AI just as they apply to any other technology. In practice, this means:

Consumer protection law applies to AI outputs. If your AI-driven product makes false claims, produces misleading outputs, or engages in conduct that would be deceptive if done by a human, the Australian Consumer Law still applies. The ACCC has already pursued enforcement action against companies for non-transparent automated decision-making on the grounds of misleading conduct. Privacy law applies to AI data handling. The amended Privacy Act applies regardless of whether data processing is done by a human or an algorithm. Using AI to analyse personal information, make decisions about individuals, or generate content based on personal data is covered. Employment law applies to AI-assisted HR decisions. If your AI-assisted screening process produces discriminatory outcomes — even unintentionally — you may face liability under the Fair Work Act or state anti-discrimination legislation. Financial services law applies to AI advisory tools. If you're using AI to provide financial product advice, credit assessments, or investment recommendations, ASIC's regulatory framework applies and may require an Australian Financial Services Licence.

The practical risk for businesses is not zero just because there's no AI-specific law. It's that the existing legal obligations are being applied to AI contexts in real time, through enforcement action and litigation, without the clarity that purpose-built legislation would provide.


What Businesses Should Do Proactively

In the absence of clear mandatory guardrails, responsible AI governance is simultaneously a risk management strategy and a competitive differentiator. Here's what the gap means for your practical decision-making:

1. Adopt the voluntary guidance anyway

DISR's six essential practices for AI governance — accountability, transparency, fairness, privacy, security, and reliability — are good operational standards regardless of their legal status. Organisations that build these practices into their AI deployments will be better prepared when mandatory rules arrive and better insulated from enforcement action under existing laws.

2. Document your AI decision-making

For any AI system involved in consequential decisions — hiring, pricing, credit, access to services — maintain records of how the system works, what data it uses, what safeguards are in place, and what human oversight exists. This documentation will matter if a decision is ever challenged under employment, consumer, or privacy law.

3. Conduct bias audits

There is no law in Australia currently requiring AI systems to be audited for discriminatory outcomes. There is, however, law prohibiting discriminatory outcomes. Proactively auditing your AI-assisted decision-making is the only way to catch systemic problems before they produce liability.

4. Watch the EU AI Act for signal

Australian businesses that operate internationally, or that use AI tools built by European or US-based companies, will be affected by international AI regulation even if Australia doesn't enact its own. The EU AI Act's risk-based framework — which classifies AI systems from minimal risk to prohibited and applies corresponding obligations — is likely to influence Australian policy when it eventually moves, and is already shaping the compliance posture of major AI platform providers.

5. Choose AI tools with governance built in

In a voluntary governance environment, the AI tools you choose largely determine your compliance posture. Tools built with privacy by design, audit logging, explainability features, and Australian data residency give you the building blocks of a defensible governance framework. Tools without these features leave you exposed.

This is one of the considerations that drove the design of Amulet — building AI tooling that gives Australian businesses governance features as standard, not as an expensive optional extra. In an environment where regulation is evolving and the stakes of getting it wrong are increasing, governance-first design is an operational necessity, not a marketing claim.


Looking Ahead: When Will Mandatory Rules Arrive?

The honest answer is: no one knows. The pattern in Australian technology regulation has been to let problems accumulate until a significant harm event forces legislative action — the Online Safety Act and the social media age limits both emerged from exactly this dynamic.

For AI, the most likely triggers for mandatory regulation are:

  • A high-profile AI-related harm event affecting Australian consumers or employees (discriminatory hiring at scale, financial harm from AI-assisted fraud, health outcomes from AI-assisted clinical decisions)
  • International pressure from trading partners implementing mandatory AI rules
  • A change of government with a different regulatory philosophy
  • Growing momentum from civil society and industry groups pushing for clearer rules

The AI Safety Institute announced in November 2025 may provide some regulatory infrastructure — but its mandate and resources are unclear, and it is not a regulatory body with enforcement powers.

For now, the regulatory gap is real. The voluntary framework is better than nothing. Existing laws create real obligations that apply to AI. And businesses that build AI governance into their operations today will be better positioned whenever mandatory rules arrive.


Key Takeaways

  • Australia has no mandatory AI-specific regulation and has paused work on creating it
  • The government's Voluntary AI Safety Standard has been replaced with non-binding guidance
  • The AI Advisory Body was scrapped in December 2025 after 15 months of development
  • Existing laws — Privacy Act, Consumer Law, Anti-Discrimination, Financial Services — apply to AI and are being actively enforced
  • The social media age verification law ($49.5M fines) signals the government will use substantial penalties when it does act
  • Proactive AI governance is both a risk management strategy and a competitive advantage in the current environment
  • Monitor EU AI Act developments — they will influence Australian policy and your tools' compliance posture

Further reading:

A practical next step

Put AI to work with the operating boundary visible.

Approvals, evidence and the rollout path should be mapped to the real workflow.

Explore Delivery