Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

AI companies in Australia must already comply with laws that apply to their data, products and conduct, even though the government’s earlier proposal for mandatory high-risk AI guardrails will not proceed at this time. The current approach combines existing laws and sector regulators with planned national AI standards, an Office of AI and an AI Safety Institute. Those plans are still being developed; the official sources do not establish a single wave of enforcement actions against AI firms.

What rules do AI companies have to follow in Australia?

There is no need for a law to mention AI by name for it to apply to an AI product or business practice. The National AI Centre says existing requirements can affect how organisations collect and use training data, handle user inputs and outputs, and develop or deploy systems. Which rules matter depends on the activity and setting.

Area How it can apply to AI
Privacy and intellectual property Privacy, copyright, confidence and contract obligations can constrain the use or disclosure of data, content or system outputs where required rights or consents are absent. (National AI Centre)
Consumer law Consumer protections may apply to misleading representations about an AI product or to poor-quality outputs. (National AI Centre)
Competition Competition law can apply to trade conduct involving AI. (National AI Centre)
Employment and workplace safety Workplace rules may be relevant when AI is used in employment or workplace settings. State and territory workplace-surveillance laws may also matter. (National AI Centre)
Prudential regulation Financial entities supervised by APRA face expectations under existing prudential oversight; this does not create a general AI licensing rule for vendors. (APRA)

Two privacy-law dates identified by the National AI Centre are especially relevant: the statutory tort for serious invasions of privacy commenced on 10 June 2025, and specified transparency provisions for some automated decision-making are due to apply from 10 December 2026.

Is Australia introducing a separate AI law?

The earlier high-risk guardrails proposal

In 2024, the government sought views on defining high-risk AI and requiring guardrails for responsible development and deployment. The proposal page now says the government “will not proceed at this time” with those earlier proposals, and that feedback informed development of the National AI Plan. That is a change in policy route, not a finding that high-risk AI is unregulated: existing laws and sector rules still apply where relevant.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The National AI Plan and existing regulators

The National AI Plan says existing legal and regulatory frameworks remain the foundation and that agencies and regulators retain responsibility in their respective domains. It also describes an AI Safety Institute intended to monitor, test and share information about emerging capabilities, risks and harms, providing independent advice to support existing regulators. The plan describes an institutional direction; it does not, by itself, establish a new general licensing regime for AI companies.

What are the planned Australian AI standards?

On 15 July 2026, Prime Minister Anthony Albanese announced Australian AI standards and the establishment of an Office of AI within the Department of the Prime Minister and Cabinet (PM&C). PM&C describes the Office as coordinating the design and legislation of a national AI standard, including requirements for large AI data centres and copyright protections for creators. The Office’s listed work includes a September 2026 consultation paper on AI infrastructure.

The July announcement described planned requirements for large data centres: underwriting new power supply, paying connection costs, reducing power use when needed and improving water efficiency. It also said the government would work with states and territories on siting, with local input. These are announced plans, not confirmed final requirements in the cited material; treat the standards and their details as in development or under consultation unless later official documents establish otherwise.

Albanese said the government’s approach would ensure Australian writers, artists and journalists “retain ownership over their work,” and that no company should use Australian creative works to train AI “without the artist’s control.” This is a statement of policy intent, not statutory text or a court ruling.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Can AI companies use copyrighted material to train models?

Australia’s copyright policy on AI remains an active question. The Attorney-General’s Department says the Copyright and Artificial Intelligence Reference Group is examining licensing arrangements for lawful use of copyright works in AI, greater certainty about copyright in AI-generated material, and lower-cost enforcement options, including a possible small-claims forum.

The department says the government is not considering a text-and-data-mining exception in Australian copyright law. That policy position does not settle every case involving training data: the available material does not resolve the legal treatment of every work, licence, jurisdiction or use. Companies should assess the rights and permissions relevant to the particular material and activity rather than treating the policy statement as a blanket answer.

What is happening with privacy and consumer proposals?

On 31 August 2026, the government released a privacy consultation paper and draft legislation. Proposed measures included a fair-and-reasonable test for collecting and using information, stronger consent standards, a right to erasure for certain digital platforms, and measures against trading personal information without clear permission. The announcement connected AI-powered tools and devices with increased privacy risks.

The announced deadline for submissions was 18 September 2026, which has passed. The 31 August release describes proposals, not enacted law, and does not establish what followed the consultation. It is therefore not a basis for saying these measures are now in force—or that their status and details have remained unchanged.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The Attorney-General’s portfolio also lists a proposed Digital Duty of Care for AI companies, workplace AI safety, consideration of consumer-law options for issues such as surveillance pricing and agentic commerce, further privacy reform, and a framework for automated decision-making in federal agencies. These are government priorities and workstreams, not all completed legal duties.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What scrutiny are financial-sector AI users facing?

APRA’s 30 April 2026 letter followed targeted engagement in late 2025 with selected large banks, insurers and superannuation trustees. APRA reported differing levels of maturity in governance, risk management and operational resilience, and said assurance practices were not keeping pace with AI adoption.

For regulated financial entities, APRA called for board understanding of AI, alignment with risk appetite, monitoring and reporting, and attention to third-party dependencies. It highlighted cyber, privacy, data governance, model risk, change management, compliance, procurement and supplier risks. APRA says it may take stronger supervisory action, and where appropriate pursue enforcement, if entities fail to identify, manage or control AI risks proportionately to their size, scale and complexity. These expectations operate within prudential supervision; they are not a general AI rule for every company selling software or models.

How should an AI company assess its Australian exposure?

The regulatory picture is best understood as a set of overlapping obligations and developing policy, not as one completed AI code. A company assessing its position should map the rules to its actual activities:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Identify what the system does and where it is used. A workplace deployment, a consumer-facing product and a service used by a regulated financial entity can raise different legal and supervisory questions.
  • Trace data and content rights. Review the basis for collecting, using, disclosing and retaining training data, customer information, prompts, outputs and copyrighted works.
  • Check claims and operational risks. Consider whether product representations, output quality, model changes, suppliers and monitoring create consumer, competition, privacy, safety or sector-specific concerns.
  • Separate current duties from announced work. Existing laws and APRA’s prudential expectations are distinct from proposed privacy changes, planned AI standards and policy priorities whose final status or requirements are not established by the announcements described above.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.