Skip to content
Mon–Sat: 9:00am – 5:00pm · Merrylands, NSW

Australia AI Governance June 2026: No AI Act, But Real Obligations Are Here

June 11, 2026 ·

Summary

Australia continues to take a distinctive, principles-led approach to AI governance in 2026 — one without a standalone AI Act, but with growing regulatory substance. The AI Safety Institute (AISI) became operational in early 2026, backed by AUD $29.9 million in government funding. The National AI Plan 2025 sets the strategic direction, while existing laws — the Privacy Act 1988, Australian Consumer Law, and the Online Safety Act 2021 — remain the primary compliance frameworks. A critical new obligation takes effect in December 2026: automated decision-making disclosure requirements under the amended Privacy Act.

Key Developments

  • AI Safety Institute operational (early 2026): Australia’s new AISI provides independent technical analysis, safety testing, and monitoring of AI systems. It complements — but does not replace — existing sectoral regulators.
  • National AI Plan 2025: A non-binding but influential roadmap focused on investment, workforce capability, and responsible AI adoption. Signals regulatory priorities for businesses and regulators alike.
  • Privacy Act automated decision-making (ADM) rules: From 10 December 2026, organisations must disclose in their privacy policies when AI or automated systems make decisions that significantly affect individuals’ rights or interests.
  • Sector-specific oversight intensifying: ASIC and APRA are increasing scrutiny of AI governance in financial services; the TGA regulates AI as Software as a Medical Device; public sector AI use requires mandatory transparency and risk assessments.
  • International engagement: Australia is a founding member of GPAI, part of the Hiroshima AI Process, and deepening ties with the EU on digital and AI governance.

Implications for Businesses

The absence of a dedicated AI Act does not mean the absence of accountability. Australian businesses deploying AI face real obligations across privacy, consumer protection, corporate governance, and sector-specific regulation. The “patchwork” nature of Australia’s approach requires organisations to map AI use cases against multiple legal frameworks rather than a single compliance checklist.

The December 2026 ADM disclosure requirement is the most immediate new obligation for most organisations. Businesses should also monitor the Privacy Act reform process — further changes around automated decision-making are expected.

Compliance Checklist

  1. ☐ Map all AI systems to the applicable existing laws: Privacy Act, ACL, Online Safety Act, Corporations Act
  2. ☐ Identify AI uses that involve automated decision-making affecting individuals — prepare privacy policy disclosures ahead of December 2026
  3. ☐ If in financial services: review ASIC/APRA expectations on AI risk management and governance
  4. ☐ If in healthcare: confirm whether any AI tools qualify as Software as a Medical Device under TGA rules
  5. ☐ Review AI outputs for compliance with Australian Consumer Law (misleading or deceptive AI outputs)
  6. ☐ Align internal AI governance policies with the Government’s Guidance for AI Adoption (GfAA)
  7. ☐ Assess whether voluntary frameworks (e.g., VAISS, GfAA) have been incorporated into existing policies

IT & Admin Impact

  • Privacy policy updates: IT and legal teams must update privacy policies to include ADM disclosures by December 2026 — identify all systems that make or support decisions affecting individuals.
  • Data governance: The Privacy Act’s existing requirements around personal data use in AI systems are being actively enforced. Ensure data sourcing, retention, and purpose limitation practices are documented.
  • Vendor due diligence: Procurement of AI tools must include assessment of compliance with Australian privacy and consumer law obligations — particularly for offshore vendors.
  • Risk registers: Add AI-related risks to corporate risk registers, particularly for financial services and healthcare where regulators are most active.

Sources: Department of Industry Science and Resources (2026), Adaptavist Group (February 2026), Inspirepreneur Magazine (April 2026), Bird & Bird AI Regulatory Tracker. Last updated: June 2026.

Need help securing or supporting your business IT?

Talk to SHAH IT — Sydney's local managed IT and cybersecurity partner.