Australian EnterpriseAI Index
Regulatory intelligence

Australian AI Regulatory Tracker

12 frameworks tracked. Updated quarterly. Covering APRA, Privacy Act, EU AI Act, ISO 42001 and emerging AI-specific instruments — the single source of truth for compliance and risk teams operating in Australia.

12 Frameworks Tracked10 In Force2 Under ConsultationLast updated Jun 2026
StatusIn ForceConsultationUpcomingWatch
In Force10 frameworks — act now
In ForceAU Government

AI Safety Standard (Voluntary)

REG001
DISRSep 2024

Applies to all AI deployments across Australian industry. Voluntary today, but its structure signals the direction of mandatory requirements — early adoption builds a defensible compliance baseline. The standard defines 10 voluntary guardrails: (1) accountable humans for AI; (2) identify and manage risk; (3) protect AI from adversarial attack; (4) maintain human control; (5) inform users; (6) test AI; (7) release AI responsibly; (8) monitor AI; (9) update and improve; (10) connect with stakeholders. Government consultation in 2025 indicated these will become mandatory for Commonwealth agencies and likely extend to critical infrastructure sectors.

All EnterprisesGov AgenciesTech Vendors
Read guidance
In ForceAU Regulator

APRA CPS 234 Information Security

REG002
APRAJul 2019

Mandatory for ADIs, insurers and superannuation funds that process personal data using AI. Requires board-level accountability, security capability frameworks, and incident notification obligations. Following its review of Medibank's 2022 cyber incident, APRA announced on 27 June 2023 that it would increase Medibank's capital adequacy requirement by $250 million until an agreed CPS 234 remediation program was complete. The cost of non-compliance is not a fine — it's operational restriction, increased capital requirements, and reputational damage that far exceeds the cost of compliance.

BanksInsurersSuper Funds
Read guidance
In ForceAU Regulator

APRA CPS 230 Operational Resilience

REG003
APRAJul 2025

AI systems that support critical operations are now in scope for continuity planning, risk tolerance mapping, and service provider oversight. APRA entities must document AI dependencies explicitly. Effective 1 July 2025, CPS 230 requires APRA-regulated entities to maintain a register of critical operations, with defined RTOs (Recovery Time Objectives) and RPOs (Recovery Point Objectives) for AI systems classified as critical. For an AI system that drives customer lending decisions, this likely means RTO ≤4 hours and an annual operational resilience test.

BanksInsurersSuper Funds
Read guidance
In Force + AmendingAU Government

Privacy Act 1988 (AI amendments)

REG004
AG Department1988 / 2025 consultation

AI-driven automated decisions that materially affect individuals require consent and explainability obligations. Proposed amendments tighten data minimisation and introduce a direct right of action for breaches. The Privacy Act Review Report (February 2023) and the Government's response (September 2023) proposed: (1) a 'fair and reasonable' test for automated decisions; (2) a right to explanation for automated decisions that significantly affect individuals; (3) prohibition on automated decision-making in sensitive contexts (health, finance, employment) without human oversight. Stage 2 reforms expected in 2026 will likely codify these for AI specifically.

All EnterprisesHealthFinanceGov Agencies
Read guidance
In Force (phased)International

EU AI Act

REG005
European CommissionAug 2024 – Aug 2026

Australian firms operating in the EU or offering AI products to EU users must comply with risk-tier obligations for high-risk AI systems. Prohibited uses took effect February 2025; full requirements apply from August 2026. Phase timeline relevant to AU enterprises: August 2024 (in force) → February 2025 (prohibited AI systems banned) → August 2025 (GPAI rules + governance) → August 2026 (high-risk AI obligations fully enforced). AU companies with EU customers/operations using AI in recruitment, credit scoring, education, or employment face Article 10–15 obligations including conformity assessments, CE marking, and registration in the EU AI Act database. Non-compliance: up to €30M or 6% of global annual turnover.

AU MultinationalsSaaS VendorsFinanceHealth
Read guidance
In ForceStandard Body

ISO/IEC 42001 AI Management System

REG007
ISODec 2023

The global AIMS standard is rapidly becoming a procurement prerequisite for AU enterprise and government contracts. Certification demonstrates a governance framework for responsible AI deployment across the organisation.

All EnterprisesGov VendorsTech Vendors
Read guidance
In ForceStandard Body

NIST AI RMF 1.0

REG008
NISTJan 2023

Widely adopted by AU multinationals and agencies aligned with US counterparts. The GOVERN-MAP-MEASURE-MANAGE framework provides a structured vocabulary for AI risk that integrates with ISO 42001 and APRA requirements.

AU MultinationalsGov AgenciesDefence
Read guidance
In ForceAU Government

DTA AI Ethics Principles

REG009
DTA2019 / updated 2024

Eight principles — human oversight, fairness, privacy, transparency, accountability, reliability, contestability, and inclusiveness — are mandatory for Commonwealth agencies procuring or deploying AI systems.

Gov AgenciesGov Vendors
Read guidance
In ForceIndustry Body

OWASP LLM Top 10

REG010
OWASP2025 (v1.1)

The de-facto security baseline for enterprise LLM deployments, covering prompt injection, insecure output handling, and training data poisoning. Increasingly referenced in AU government and financial services AI security frameworks.

All EnterprisesTech VendorsFinanceHealth
Read guidance
In ForceAU Regulator

Therapeutic Goods (AI Medical Devices)

REG011
TGA2023

AI systems meeting the Software as a Medical Device (SaMD) definition must obtain TGA approval before deployment. Applies to clinical decision support, diagnostic imaging AI, and patient-facing health applications.

Health TechMedtechDigital Health
Read guidance
Consultation2 frameworks — shape the outcome
ConsultationAU Government

Treasury — AI in Financial Services

REG006
Treasury2025–2026

Targets model risk management, explainability of AI-driven financial decisions, and consumer protection against algorithmic bias. Submissions closed; final guidance expected H2 2026.

BanksSuper FundsFintechsLenders
Read guidance
ConsultationAU Regulator

Consumer Data Right (CDR) AI Rules

REG012
ACCC2025–2026

Proposed rules would govern AI systems that process CDR data, introducing purpose-limitation obligations, consent refresh requirements, and audit trail mandates for automated data-sharing decisions.

BanksFintechsEnergyTelecoms
Read guidance

Turn tracker into readiness

Download the full compliance checklist or talk to an AEAI advisor about your current posture across these 12 frameworks.

Status classifications are based on publicly available regulatory instruments, consultation papers, and AEAI signal analysis. Not legal advice. Updated quarterly. Suggest a framework →