Australian AI Regulatory Tracker
12 frameworks tracked. Updated quarterly. Covering APRA, Privacy Act, EU AI Act, ISO 42001 and emerging AI-specific instruments — the single source of truth for compliance and risk teams operating in Australia.
AI Safety Standard (Voluntary)
Applies to all AI deployments across Australian industry. Voluntary today, but its structure signals the direction of mandatory requirements — early adoption builds a defensible compliance baseline. The standard defines 10 voluntary guardrails: (1) accountable humans for AI; (2) identify and manage risk; (3) protect AI from adversarial attack; (4) maintain human control; (5) inform users; (6) test AI; (7) release AI responsibly; (8) monitor AI; (9) update and improve; (10) connect with stakeholders. Government consultation in 2025 indicated these will become mandatory for Commonwealth agencies and likely extend to critical infrastructure sectors.
APRA CPS 234 Information Security
Mandatory for ADIs, insurers and superannuation funds that process personal data using AI. Requires board-level accountability, security capability frameworks, and incident notification obligations. Following its review of Medibank's 2022 cyber incident, APRA announced on 27 June 2023 that it would increase Medibank's capital adequacy requirement by $250 million until an agreed CPS 234 remediation program was complete. The cost of non-compliance is not a fine — it's operational restriction, increased capital requirements, and reputational damage that far exceeds the cost of compliance.
APRA CPS 230 Operational Resilience
AI systems that support critical operations are now in scope for continuity planning, risk tolerance mapping, and service provider oversight. APRA entities must document AI dependencies explicitly. Effective 1 July 2025, CPS 230 requires APRA-regulated entities to maintain a register of critical operations, with defined RTOs (Recovery Time Objectives) and RPOs (Recovery Point Objectives) for AI systems classified as critical. For an AI system that drives customer lending decisions, this likely means RTO ≤4 hours and an annual operational resilience test.
Privacy Act 1988 (AI amendments)
AI-driven automated decisions that materially affect individuals require consent and explainability obligations. Proposed amendments tighten data minimisation and introduce a direct right of action for breaches. The Privacy Act Review Report (February 2023) and the Government's response (September 2023) proposed: (1) a 'fair and reasonable' test for automated decisions; (2) a right to explanation for automated decisions that significantly affect individuals; (3) prohibition on automated decision-making in sensitive contexts (health, finance, employment) without human oversight. Stage 2 reforms expected in 2026 will likely codify these for AI specifically.
EU AI Act
Australian firms operating in the EU or offering AI products to EU users must comply with risk-tier obligations for high-risk AI systems. Prohibited uses took effect February 2025; full requirements apply from August 2026. Phase timeline relevant to AU enterprises: August 2024 (in force) → February 2025 (prohibited AI systems banned) → August 2025 (GPAI rules + governance) → August 2026 (high-risk AI obligations fully enforced). AU companies with EU customers/operations using AI in recruitment, credit scoring, education, or employment face Article 10–15 obligations including conformity assessments, CE marking, and registration in the EU AI Act database. Non-compliance: up to €30M or 6% of global annual turnover.
ISO/IEC 42001 AI Management System
The global AIMS standard is rapidly becoming a procurement prerequisite for AU enterprise and government contracts. Certification demonstrates a governance framework for responsible AI deployment across the organisation.
NIST AI RMF 1.0
Widely adopted by AU multinationals and agencies aligned with US counterparts. The GOVERN-MAP-MEASURE-MANAGE framework provides a structured vocabulary for AI risk that integrates with ISO 42001 and APRA requirements.
DTA AI Ethics Principles
Eight principles — human oversight, fairness, privacy, transparency, accountability, reliability, contestability, and inclusiveness — are mandatory for Commonwealth agencies procuring or deploying AI systems.
OWASP LLM Top 10
The de-facto security baseline for enterprise LLM deployments, covering prompt injection, insecure output handling, and training data poisoning. Increasingly referenced in AU government and financial services AI security frameworks.
Therapeutic Goods (AI Medical Devices)
AI systems meeting the Software as a Medical Device (SaMD) definition must obtain TGA approval before deployment. Applies to clinical decision support, diagnostic imaging AI, and patient-facing health applications.
Treasury — AI in Financial Services
Targets model risk management, explainability of AI-driven financial decisions, and consumer protection against algorithmic bias. Submissions closed; final guidance expected H2 2026.
Consumer Data Right (CDR) AI Rules
Proposed rules would govern AI systems that process CDR data, introducing purpose-limitation obligations, consent refresh requirements, and audit trail mandates for automated data-sharing decisions.
Turn tracker into readiness
Download the full compliance checklist or talk to an AEAI advisor about your current posture across these 12 frameworks.
Status classifications are based on publicly available regulatory instruments, consultation papers, and AEAI signal analysis. Not legal advice. Updated quarterly. Suggest a framework →