Australia’s artificial intelligence (AI) regulatory landscape continues to evolve in response to the technology’s widespread adoption. As of the date of this publication, Australia does not have specific laws dealing with AI (such as the European AI Act) and the Federal Government has indicated that at least in certain situations, such as in copyright law, the existing legal infrastructure will apply to AI.
The Department of Industry, Science and Resources released the Australian government’s National AI Plan in December 2025. The National AI Plan, a centrepiece of the Australian government’s Future Made in Australia agenda, sets out the government’s strategy to capture economic opportunities, spread the benefits of AI, and manage emerging risks.
The government has reaffirmed its ambition to position Australia as a global leader in the development, adoption, and governance of trusted, secure, and responsible AI, with a focus on ensuring that the benefits of AI are shared equitably across all sectors of Australian society.
Australia’s AI industry continued to rapidly expand in 2025. The most recent government data published by the Department of Industry, Science and Resources in June 2025 identified approximately 1,533 AI companies operating nationwide — including 1,121 private companies and 412 public companies. Of the private companies, 110 were founded in 2023 or 2024, highlighting the sector’s strong growth trajectory. The ecosystem is underpinned by 167 research institutes, eight major AI clusters, and six Australian universities ranked in the world’s top 100 for AI research. The AI workforce has grown to over 33,000 professionals as of 2023, with Australian universities producing close to 2,000 AI-qualified graduates annually.
Investment in the Australian AI sector is strong: in 2024, private investment in Australian AI firms exceeded AUD 700 million, and businesses registered around AUD 950 million in AI-related activities under the R&D Tax Incentive program across the 2022–23 and 2023–24 income years. The government has committed more than AUD 460 million in targeted AI and related initiatives, and major technology companies have announced plans for data centre investments that could scale to over AUD 100 billion. These investments are accelerating the commercialisation of AI solutions and the development of critical digital infrastructure, including advanced data centres and Australia’s first sovereign AI cloud.
Regulatory and ethical frameworks
While Australia does not intend to enact a dedicated legislative regime to regulate AI, the existing regulatory landscape has developed in response to AI adoption. The current government’s approach is best characterised as incremental reform, with a focus on updating existing technology-neutral laws — such as those relating to privacy, consumer protection, and anti-discrimination — to address AI-specific risks.
The Policy for the Responsible Use of AI in Government (December 2025) is now mandatory for all non-corporate Commonwealth entities and requires Commonwealth government agencies to implement strategic AI adoption plans, transparency statements, and risk-based impact assessments.
The Commonwealth has also published updated voluntary guidance for business and government, including the Guidance for AI Adoption (2025) and updates to the Voluntary AI Safety Standard (2024), which build on Australia’s AI Ethics Principles. These eight key principles are central to Australia’s approach to responsible AI and AI ethics:
- human, societal and environmental well-being;
- human-centred values;
- fairness;
- privacy protection and security;
- reliability and safety;
- transparency and explainability;
- contestability;
- and accountability.
Key regulators in Australia relevant to AI include:
- Office of the Australian Information Commissioner (OAIC). The OAIC is the primary national regulator for privacy, personal data protection, and freedom of information. It oversees compliance with the Privacy Act 1988 (Cth) (“Privacy Act”) and the Australian Privacy Principles (APPs), investigates data breaches, issues guidance on the use of AI and automated decision-making, and enforces privacy rights in relation to personal information, including biometric and AI-generated data.
- Australian Competition and Consumer Commission (ACCC). The ACCC is responsible for enforcing consumer protection, competition, and fair trading laws, including the Australian Consumer Law. It plays a key role in regulating digital platforms, algorithmic transparency, and the use of AI in consumer-facing products and services. The ACCC also co-leads the Digital Platform Regulators Forum (DP-REG), which coordinates regulatory responses to emerging digital and AI-related issues.
- Australian Communications and Media Authority (ACMA). ACMA regulates Australia’s communications and media sectors, including the use of AI in digital communications. This includes the regulation of AI-powered scams and spam messages. ACMA administers industry codes and standards that increasingly address AI-generated content and the use of AI for content moderation and detection of prohibited material.
- eSafety Commissioner. The eSafety Commissioner is Australia’s independent regulator for online safety, with powers to enforce the Online Safety Act 2021 (Cth) (“Online Safety Act”) and issue removal notices for deepfakes and harmful or illegal online content.
- Australian Securities and Investments Commission (ASIC). ASIC regulates companies, financial services and markets, including the use of AI in financial products, automated advice, and algorithmic trading. ASIC has issued guidance on the responsible use of AI and data analytics in the financial sector, with a focus on transparency, fairness, and consumer protection. On 29 October 2024, ASIC released ASIC Report 798 on AI Governance in Financial Services in which they surveyed the use of AI in the credit and financial services sector.
- Sector-Specific Regulators. Other regulators, such as the Therapeutic Goods Administration (TGA) for AI in medical devices, the National Transport Commission (NTC) for automated vehicles, and state-based privacy and information commissioners, also play important roles in the oversight of AI technologies within their respective domains.
These regulators collaborate with each other through formal forums and working groups to ensure a coordinated, risk-based, and adaptive approach to the regulation of AI and emerging technologies in Australia. While not a regulator, Standards Australia also plays an important role in developing and promoting national and international standards for AI, data governance, and cybersecurity in Australia, supporting regulatory frameworks and best practice across industries.
The Australian government is empowered under section 51(v) of the Australian Constitution to establish legislation regulating “postal, telegraphic, telephonic and other like services”. This head of power could potentially support the establishment of any federal legislation relating to AI. The Australian Constitution otherwise does not contain any express provisions in respect of AI.
There are certain human rights provisions enshrined in the Australian Constitution, such as the implied freedom of political communication, which potentially might impact the regulation of AI technologies from a constitutional perspective.
The Australian Human Rights Commission (AHRC) plays an important role in shaping the national conversation and policy direction on AI, with its Human Rights and Technology Final Report (2021) remaining a key reference document.
There have been several significant developments since the date of that report, reflecting both government action and broader societal expectations.
Establishment of the Australian AI Safety Institute
In response to the AHRC’s recommendations and international trends, the Australian government announced the creation of the Australian Artificial Intelligence Safety Institute (AISI), which will become operational in early 2026. The AISI is tasked with monitoring, testing, and providing guidance on the risks and harms associated with emerging AI technologies, with a particular focus on upholding human rights and supporting Australia’s commitments under international AI safety agreements. The Institute will work closely with regulators, industry, and civil society to ensure that AI systems are developed and used in ways that respect and protect the rights of all Australians, especially vulnerable and marginalised groups.
Human rights impact assessments and government use of AI
There is now a clear expectation, as reflected in the National Framework for the Assurance of AI in Government (2024) and the updated Policy for the Responsible Use of AI in Government (2025), that government agencies conduct Human Rights Impact Assessments (HRIAs) for high-risk AI use cases. These assessments are intended to identify, mitigate, and monitor potential adverse impacts on human rights, with a particular emphasis on transparency, fairness, and non-discrimination. Government agencies are also required to provide clear notice to individuals when AI is used in decision-making processes, and to ensure that affected individuals have access to meaningful explanations and avenues for independent review or redress.
Transparency, contestability and recourse
The updated Australian government policy framework mandates that individuals subject to significant decisions by the Commonwealth government made or influenced by AI must be provided with reasons explaining the basis of those decisions. There is also a strengthened commitment to contestability, with clear processes for individuals to challenge AI-driven government decisions and seek independent merits review. These requirements are designed to ensure that the use of AI in public administration does not undermine procedural fairness or access to justice.
Private sector and the AI ethics principles
While there is no specific legislation applicable to AI ethics in the private sector in Australia, the private sector is increasingly expected as a matter of industry best practice to align with Australia’s Guidance for AI Adoption (2025) and AI Ethics Principles, which explicitly incorporate human rights, fairness, and accountability. The National AI Plan and associated guidance encourage private organisations to conduct human rights and ethical impact assessments as part of their AI governance frameworks. There is also growing regulatory and public scrutiny of AI systems in use by the private sector that may have discriminatory or otherwise adverse impacts on individuals or communities.
Biometric technologies and high-risk use cases
The use of biometric technologies in high-risk decision-making contexts remains a particular focus of regulatory concern in Australia. While there is currently no specific legislation outside of the Privacy Act (discussed further below) which regulates the use of biometric data, the government and regulators have signalled that the deployment of biometric technologies in Australia will be subject to heightened scrutiny, including mandatory impact assessments for any government adoption and strict compliance with privacy and anti-discrimination laws. The OAIC and AHRC have both recently issued updated guidance on the use of facial recognition and other biometric systems, emphasising the need for robust safeguards and clear justification for their use.
International alignment and ongoing reform
Australia’s approach to human rights and AI is broadly aligned with international best practice, including the OECD AI Principles, the Bletchley Declaration, and the Seoul Declaration on AI safety and inclusivity. The Australian government has committed to ongoing review and reform of laws and policies to ensure that human rights remain at the centre of Australia’s AI regulatory framework.
The main source of law governing patents in Australia is the Patents Act 1990 (Cth) (“Patents Act”). There are no express references to AI under the Patents Act. However, there has been contention as to whether an AI system can be named as an “inventor” to which a patent is registered.
In Thaler v. Commissioner of Patents [2021] FCA 879, the court originally held that the relevant AI system (known as “DABUS”) could be considered an “inventor”, within the definition of section 15(1) of the Patents Act, on the basis that an “inventor is an agent noun” and “an agent can be a person or a thing that invents”.
On appeal, the Full Court of the Federal Court of Australia in Commissioner of Patents v. Thaler [2022] FCAFC 62 overturned the original decision, on the basis that an “inventor”, within the meaning of section 15(1) of the Patents Act, had to be a “natural person”, citing the historical role of an inventor in patent law, plain reading of the section and structure and policy objectives of the Patents Act. Dr Thaler sought special leave to appeal to the High Court of Australia. However, the High Court of Australia refused the application after hearing oral arguments on 11 November 2022.
While AI is not capable of being named as an inventor as a result of the High Court’s decision, this may be a prelude to future policy debate in Australia for inventions involving AI. Interestingly, the Full Court considered:
- whether an “inventor” should be redefined to expressly include AI, and if so, to whom such an AI-invented patent could be granted, and the standard of the inventive step that should be applied; and
- that its decision did not necessarily preclude the granting of patents from AI-devised inventions in another case.
The High Court of Australia refused special leave to appeal this decision, although it left open the possibility that it would consider this issue in future in an “appropriate vehicle” (Thaler v. Commissioner of Patents [2022] HCA Trans 199).
For AI-assisted inventions, the ordinary statutory criteria for patent rights under the Patents Act apply. As such, there needs to be novelty and an inventive step. Ownership of patent rights vests in the inventor (i.e. the person responsible for the inventive concept) or a person deriving title to the invention from the inventor.
Australian patent law does not currently address AI-generated prior art.
The definitions of “prior art base” and “prior art information” under the Patents Act includes “information in a document that is publicly available, whether in or out of the patent area”. Therefore, AI-generated prior art that is publicly available could potentially affect the validity of patents in Australia.
IP Australia’s current practice does not address AI-generated prior art. However, IP Australia has identified this as a potential issue arising from generative AI and in July 2023, it published a paper titled Generative AI and patents: a provocation which raised the possibility of filtering out mass AI-generated content from being considered as prior art at all.
The main source of law governing copyright in Australia is the Copyright Act 1968 (Cth) (“Copyright Act”). There are no express references to AI under the Copyright Act. However, to the extent that an AI algorithm is written (e.g. represented in software as source code), the software will be considered a “literary work” and potentially subject to the protections under the Copyright Act, including a prohibition on unauthorised reproduction. Australia has no copyright registration system so works need not be registered as copyright in Australia in order to be afforded protection.
In respect of computer-generated works, the Copyright Act restricts the provision of copyright protection to works originating from an “author” — that is, a person who brings the work into existence in its material form. Specifically, an author must be a human person and any works emerging entirely from the operation of a computer system cannot originate from an individual (see Telstra Corp Ltd v. Phone Directories Co Pty Ltd [2010] FCAFC 149 (Telstra)). This is because copyright requires “originality” which depends on human authorship.
In Telstra, the court held that phone directories which had been largely organised and presented by a computer program were not subject to copyright protection as the compilation did not originate from an individual (i.e. there was an absence of human authorship).
Whether works generated by both a human author and a computer program together will be subject to copyright protection will depend on:
- the authorial contribution of the person;
- the control the person exerts over the final material form of the work; and
- the extent to which the relevant computer program is used as a “tool”.
As such, Australian copyright law may be unlikely to recognise copyright subsisting in works entirely generated by an AI system, although this is currently untested specifically in respect of AI generated works.
For works generated with the assistance of AI tools, copyright will only subsist if there was “independent intellectual effort” from a human author (Telstra). The human(s) who exercised that effort will be the author(s). Under sections 35–36 of the Copyright Act, the first owner of the rights is the author, subject to the usual employment or commissioning rules.
An AI system will not have moral rights under Australian law.
AI copyright infringement risk
Although the position is currently untested in Australia, the substantial reproduction in Australia of copyright-protected works as part of training AI will likely constitute copyright infringement (without authorisation from the copyright owners). Copying entire works to create a training corpus therefore strongly risks infringement. No AI-specific exceptions or defences to copyright infringement permitting copying to train an AI exist in Australia. The Australian government has recently declined to introduce a text and data mining exception for training AI systems in Australia as has been introduced in Europe.
Whether the reproduction is “substantial” is a question of fact and degree. This can involve consideration of whether an essential or material part has been reproduced, or whether there has been an appropriation of the essential features and substance of a work (SW Hart & Co Pty Ltd v. Edwards Hot Water Systems (1985) 159 CLR 466).
It is also untested whether an AI model itself (i.e. the system of weights and parameters) would infringe copyright in Australia, including for example in the context of importing or otherwise using trained AI models in Australia that were pre-trained outside of Australia. It is possible that Australian courts would adopt a similar view to the UK in Getty Images (US) v Stability AI Ltd [2025] EWHC 2863 (Ch) that merely using a trained AI model does not in and of itself involve the substantial reproduction of copyright-protected works.
The limited exceptions to copyright infringement under the Copyright Act are unlikely to encompass the unauthorised use of copyright-protected works in AI training, although this is untested. While there is an exception to infringement for “fair dealing” for the purpose of research or study (sections 40 and 103C, Copyright Act), this is a narrow exception that requires the consideration of several factors including the effect of the dealing on the market. Commercial scale copying to develop an AI model is unlikely to constitute fair dealing on this basis.
The exception under section 43B of the Copyright Act for temporary reproductions of works as part of a technical process of use would also be unlikely to encompass training AI systems on copyrighted materials.
The key test for infringement in Australia is whether an output reproduces, in a material form, a “substantial part” of a copyrighted work (see section 14(1)(a), Copyright Act).
If a work is used in AI training, then a substantial reproduction of that work in an output is likely to amount to an infringement as this will satisfy the requirement for copying, whether directly or indirectly, from the original work.
The primary infringer would be the user who generates the output that substantially reproduces a copyrighted work.
The AI provider may also be liable for authorising copyright infringement (section 36(1), Copyright Act) if it “sanctions, approves or countenances” infringing acts (see Roadshow Films Pty Ltd v. iiNet Ltd (2012) 248 CLR 42). Relevant considerations include the provider’s power to prevent the doing of the infringing act, the relationship between the provider and the infringer, and whether the provider took any reasonable steps to prevent the infringing act. Contractual terms disclaiming liability for copyright infringement and content filters will therefore be relevant to whether an AI provider is liable for authorising copyright infringement in outputs by a user.
Infringing acts that take place in Australia will be actionable in Australia. Even if a provider and its servers are located outside of Australia, if a user is located in Australia and generates an infringing output this could amount to copyright infringement under Australian law (as well as potential authorisation of the infringement by the provider).
Rights management information and training materials
There is no positive obligation to maintain copyright management information in AI outputs under Australian law.
However, there is civil liability to the copyright owner and criminal liability if:
- a person distributes or communicates a copy of a copyrighted work to the public;
- the person knew that the electronic rights management information had been removed or altered without the permission of the owner; and
- the person knew or ought reasonably to have known that the distribution or communication would induce, enable, facilitate or conceal copyright infringement (sections 116C and 132AR, Copyright Act).
There can also be civil liability to the copyright owner and criminal liability where a person intentionally removes or alters electronic rights management information without permission of the copyright owner (sections 116B and 132AQ, Copyright Act).
It is untested in Australia whether an AI provider would be liable for outputs that do not include electronic rights management information. However, the AI provider may be liable in relation to outputs if it intentionally removes (or has the requisite knowledge of the removal of) electronic rights management information during training of an AI model.
There are no trade secrets or confidentiality law requirements specifically in respect of AI in Australia.
Company confidential information disclosed within AI prompts will in general be protected in Australia if there is a contractual obligation to that effect with the AI provider or otherwise only if the circumstances import an obligation of confidence under common law or equity.
For an obligation of confidence to arise, the information must possess the necessary quality of confidence, it must have been imparted in circumstances importing an obligation of confidence, and unauthorised use must cause detriment. This would likely require the AI provider to have made contractual commitments or other clear representations that it will keep user data secure and confidential.
Australian IP case law specifically on AI remains limited. The key authority continues to be the Thaler line of patent decisions, with no Australian judgments yet determining copyright infringement from AI training or subsistence/ownership in purely AI‑generated outputs. Foreign decisions (US/UK/EU) are closely watched by IP practitioners in Australia and may be of varying persuasive influence for Australian courts in any future litigation.
See above, Sections 2.1 and 2.2, for summaries of Thaler and Telstra.
The principal legislation governing data privacy in Australia is the Privacy Act. While the Privacy Act does not at present contain provisions that specifically regulate the use of AI, its scope has expanded significantly in recent years and encompasses the handling of personal information within AI systems. The Act applies to any data that constitutes “personal information” — that is, information or an opinion about an identified individual, or an individual who is reasonably identifiable, regardless of whether the information is true or recorded in a material form.
The Australian Privacy Principles (APPs) in the Privacy Act set out obligations regarding the collection, use, disclosure, security, and retention of personal information. In the context of AI, this means in general that any personal information used as input or generated as output by AI systems must only be used for the primary purpose for which it was collected, or for a secondary purpose that the individual would reasonably expect, unless an exception applies.
Major privacy law reforms (2024–2026)
Since the last edition of this guide, Australia has enacted the most significant reforms to its privacy regime in decades. The Privacy and Other Legislation Amendment Act 2024 (Cth) (POLA), which received Royal Assent in December 2024, marks the first tranche of a broader reform agenda. These reforms have implications for the use of AI and automated decision-making (ADM) in Australia.
The most significant changes include:
- Transparency for automated decision-making. From December 2026, entities will be required to update their privacy policies to include clear information about the use of AI and ADM. Specifically, privacy policies must set out:
- the types of personal information used in substantially automated decisions that have a legal or similarly significant effect on individuals’ rights or interests;
- the kinds of decisions made solely or substantially by automated means; and
- the circumstances in which such automated decisions are made.
The OAIC has also recently published a review and report on the use of ADM by Australian government agencies at: www.oaic.gov.au/freedom-of-information/information-commissioner-decisions-and-reports/foi-reports/Automated-decision-making-and-public-reporting-under-the-Freedom-of-Information-Act.
- Right to information about automated decisions. Individuals will have the right to request meaningful information about how decisions made by automated means that have a legal or similarly significant effect on them are reached. This is intended to enhance transparency and accountability in the use of AI, and to ensure individuals are not subject to opaque or unchallengeable automated processes.
- Privacy impact assessments for high-risk activities. Regulated government agencies will be required to conduct Privacy Impact Assessments (PIAs) prior to undertaking “high risk activities”, which expressly include the use of AI and ADM where such activities are likely to have a significant impact on individuals’ privacy. This requirement is designed to ensure that privacy risks are identified and mitigated at the outset of any project involving AI.
- Enhanced enforcement and penalties. The OAIC has been granted expanded enforcement powers, including the ability to issue infringement and compliance notices for breaches of the APPs, and to seek significantly increased civil penalties for serious or repeated interferences with privacy. The maximum penalty for organisations now stands at the greater of AUD 50 million, three times the value of any benefit obtained, or 30% of adjusted turnover during the breach period.
- Children’s Online Privacy Code. The OAIC is developing a Children’s Online Privacy Code, which will introduce additional protections for children’s personal information in online environments, including those involving AI-driven services. The Code is expected to be in force by December 2026.
- Cross-border data transfers. The reforms introduce a mechanism for the government to “whitelist” countries with substantially similar privacy protections, streamlining compliance for international data transfers relevant to AI systems hosted or operated overseas.
Ongoing and future privacy reforms
Further reforms are anticipated as part of the Australian government’s ongoing privacy agenda, including proposals to introduce a “fair and reasonable” test for the collection and use of personal information, and to remove existing exemptions for small businesses and employee records. The regulatory landscape for AI and privacy in Australia is therefore expected to continue evolving, with a strong emphasis on transparency, accountability, and the protection of individual rights in the context of emerging technologies.
The European General Data Protection Regulation will apply to Australian organisations that fall within the extraterritorial ambit of the GDPR (in general, where Australian organisations are operating, or otherwise targeting customers, within the EU).
There are “open data” legislative regimes in Australia that enable the sharing of data which may support the development and adoption of AI technologies in Australia.
The Data Availability and Transparency Act 2021 (Cth) (“DAT Act”) facilitates the sharing of “public sector data” (meaning data that is lawfully created, collected or held by or on behalf of a Commonwealth body) with government departments and universities to stimulate the use of public sector data for prescribed purposes, including research and development. The DAT Act sets out a comprehensive accreditation framework and establishes requirements in order for accredited users to access the relevant datasets (e.g. the use must align with the “data sharing purposes” and be consistent with the data sharing principles). A statutory review of the DAT Act is presently taking place led by Dr. Stephen King and supported by the Department of Finance, with a final report due to Parliament to review whether the Act has been effective and should be continued (or amended) before its potential sunsetting in April 2027.
Separately, the Consumer Data Right (CDR) was enacted by the Treasury Laws Amendment (Consumer Data Right) Act 2019 (Cth) amending the Competition and Consumer Act 2010 (Cth) (CCA). Essentially, the CDR grants consumers the right to access their data held about them by businesses or “data holders” in prescribed regulated industries (e.g. energy, banking, and telecommunications) and to have that data transferred to an accredited recipient.
The use of biometric data — including facial, voice, fingerprint, and iris recognition data — remains regulated in Australia under the Privacy Act, which classifies biometric information used for automated biometric verification or identification, and biometric templates, as “sensitive information”. This classification triggers the highest level of protection under the Act.
Key requirements for biometric data
Organisations subject to the Privacy Act must comply with strict requirements regarding the collection, use, and disclosure of sensitive information including biometric data. In particular:
- Collection. An organisation must generally not collect biometric data unless the individual has provided express consent and the collection is reasonably necessary for one or more of the organisation’s functions or activities. The use of implied consent is generally not sufficient for biometric data, and the OAIC has emphasised that express, informed, and voluntary consent is required.
- Use and disclosure. Biometric information may generally only be used or disclosed for the primary purpose for which it was collected, or for a directly related secondary purpose that the individual would reasonably expect, unless another exception applies. Use for unrelated purposes, or without adequate transparency, is likely to breach the Act.
- Additional safeguards. Organisations should undertake a PIA before deploying high-risk biometric systems, such as facial recognition in public or sensitive contexts. The OAIC’s 2024 guidance on facial recognition technology sets out best practice for necessity, proportionality, consent, transparency, accuracy, bias mitigation, and governance.
Recent enforcement and regulatory developments
- OAIC determinations. The OAIC has continued to take enforcement action against organisations using biometric data. Following the landmark 2021 Clearview AI determination, the OAIC in 2024 and 2025 issued further determinations against major Australian retailers alleging unlawful collection and use of facial recognition data in stores. The OAIC found that these deployments failed to meet the requirements of necessity, proportionality, and informed consent, and ordered the cessation of such practices and the destruction of unlawfully collected data. One of Australia’s largest retailers, Bunnings Warehouse (a part of the Wesfarmers group of companies), subsequently challenged the OAIC’s findings in the Australian Administrative Review Tribunal (ART). The ART decided in February 2026 that Bunnings’ use of a facial recognition system in its hardware store chain to identify repeat offenders did not require the consent of individuals for their photographs to be taken and a biometric template derived from their photograph to be made on the basis that it fell within a permitted general exception because it was implemented by Bunnings for the purpose of preventing theft and violence towards staff (Bunnings Group Limited and Privacy Commissioner (Guidance and Appeals Panel) [2026] ARTA 130). See also the determination of the OAIC on 26 August 2025 ([2025] AICmr 155).
- Regulatory focus. The OAIC’s 2025–2026 regulatory strategy identifies biometrics as a priority area, with proactive monitoring, guidance, and enforcement. The OAIC has also published updated guidance for both government and private sector entities on the use of facial recognition and other biometric technologies, emphasising the need for robust privacy risk management and human rights safeguards.
Human rights and law reform
- Moratorium and model law. The AHRC continues to recommend a moratorium on the use of biometric technologies in high-risk decision-making contexts — such as policing, education, and essential services — until comprehensive law reform is enacted. The AHRC and other stakeholders have highlighted persistent concerns, including:
- High error rates and algorithmic bias, particularly in one-to-many facial recognition, which disproportionately affect vulnerable groups based on characteristics such as skin colour, gender, and disability.
- The proliferation of facial recognition trials in sensitive government and commercial settings, increasing the risk of discrimination, exclusion, and harm.
- The risk of mass surveillance and its chilling effect on fundamental rights, including freedom of expression and association.
- Model law and future legislation. The University of Technology Sydney, in collaboration with the former Human Rights Commissioner, has released a draft Model Law for Facial Recognition Systems, proposing a dedicated legal framework for the deployment, oversight, and accountability of facial recognition in Australia. The Federal Government has signalled its intention to develop a dedicated facial recognition law, with public consultation expected in late 2026.
Concerns about potential bias and discrimination remain at the forefront of Australia’s regulatory and policy agenda for AI.
Government and regulatory action
The AHRC’s 2020 report, Using Artificial Intelligence to make decisions: Addressing the problem of algorithmic bias, continues to serve as a key resource for both government and industry. However, recent years have seen a shift from guidance to more concrete regulatory and policy measures. The National AI Plan (2025) and the updated Policy for the Responsible Use of AI in Government (2025) both require government agencies to assess and address the risk of algorithmic bias as part of mandatory HRIAs and PIAs for high-risk AI deployments.
The OAIC and the AHRC have jointly issued updated guidance on algorithmic fairness, transparency, and accountability, emphasising the need for:
- rigorous testing and validation of AI systems for disparate impact across different demographic groups;
- ongoing monitoring and auditing of deployed AI systems to detect and correct emerging biases;
- clear documentation of data provenance, model design, and decision-making processes to support transparency and contestability.
Legal and policy developments
POLA and the National AI Plan have introduced new requirements for organisations to provide meaningful information about automated decisions and to ensure that individuals can challenge decisions that may be discriminatory or unfair. These reforms are complemented by the government’s commitment to updating anti-discrimination laws to explicitly address algorithmic and data-driven discrimination, with a public consultation on draft amendments expected in late 2026.
AI ethics principles and industry practice
The Australian AI Ethics Framework and its eight core principles (see Introduction, above) remain central to both government and industry practice. The National AI Plan and associated guidance encourage both public and private sector organisations to be able to demonstrate how these principles are operationalised in practice, particularly in relation to fairness and non-discrimination.
Sector-specific initiatives
There has been a particular focus on the use of AI in high-stakes domains such as employment, financial services, policing, and social services. The government has funded research and pilot projects aimed at developing tools and methodologies for bias detection and mitigation and has supported the creation of sector-specific codes of practice for the ethical use of AI.
The main source of law governing bias and discriminatory practices in Australia is the Disability Discrimination Act 1992 (Cth) (“Discrimination Act”). The Discrimination Act does not contain any express references to AI. Instead, it generally prohibits an organisation from discriminating against a person on the basis of their disability when providing goods and services to that person. To avoid discriminatory conduct, the organisation must take steps to make the relevant goods and services accessible to persons with a disability by making reasonable adjustments to the manner in which goods and services are provided to that person. However, as an exception, an organisation is not required to make such reasonable adjustments or otherwise take action to avoid discriminatory conduct if it would impose an unjustifiable hardship on the organisation.
It is possible that an AI system would be considered a good or service for the purposes of the Discrimination Act. Therefore, the general requirements set out above would apply to the use of an AI system.
Operating in conjunction with the above, there are other anti-discrimination laws which may be relevant to the types of AI that may be developed and their algorithmic content such as:
- the Racial Discrimination Act 1975 (Cth), which prohibits discrimination on the basis of race, colour, descent, nationality, ethnicity, or immigration status;
- the Sex Discrimination Act 1984 (Cth), which prohibits discrimination on the basis of gender, marital status, or pregnancy; and
- the Age Discrimination Act 2004 (Cth), which prohibits discrimination on the basis of age.
There are no specific Australian requirements directly related to AI. Australia does, however, have certain legislative cybersecurity and resilience requirements that, while not AI-specific, have potential implications for organisations developing, deploying, or relying on artificial intelligence systems in particular sectors.
Security of Critical Infrastructure Act reforms
The most notable recent development in this area in Australia is the ongoing expansion and strengthening of the Security of Critical Infrastructure Act 2018 (Cth) (“SOCI Act”). The SOCI Act imposes comprehensive asset registration, cybersecurity, risk management, and incident reporting obligations on owners and operators of critical infrastructure assets across 11 sectors — including communications, data storage and processing, financial services, healthcare, and transport. These obligations are potentially relevant to the adoption of AI in Australia in particular contexts, as many critical infrastructure entities are increasingly integrating AI into their operations, and AI systems themselves may be considered critical assets or components.
Key SOCI Act requirements include:
- Register of interests. Responsible entities are required to register and update ownership and control information about critical infrastructure assets in a register maintained by the Commonwealth Government’s Critical Infrastructure Security Centre (CISC).
- Mandatory cybersecurity risk management. Responsible entities must implement and maintain a Critical Infrastructure Risk Management Program (CIRMP) that addresses cyber, personnel, supply chain, and physical risks — including those arising from the use of AI and automated systems.
- Incident reporting. Entities must report cyber incidents with significant or relevant impact on critical infrastructure assets to the Australian Cyber Security Centre (ACSC) within strict timeframes (12 or 72 hours, depending on severity).
- Enhanced obligations for systems of national significance. For assets designated as Systems of National Significance (SoNS), there are additional requirements such as vulnerability assessments, cyber exercises, and real-time system information sharing with government agencies.
Broader cybersecurity and resilience landscape
Beyond the SOCI Act, the Australian government’s 2023–2030 Cyber Security Strategy and the recent Cyber Security Act 2024 (Cth) have further elevated the national baseline for cyber resilience. These reforms introduce:
- mandatory ransomware payment reporting for certain entities;
- minimum security standards for smart devices and IoT products;
- Expanded powers for government entities, including the Australian Signals Directorate (ASD) and the Australian Security Intelligence Organisation (ASIO).
While there are no AI-specific cybersecurity laws, these frameworks require organisations to consider the security, reliability, and resilience of all digital systems — including AI — across their lifecycle. The ASD and other agencies have also published best practice guidance for deploying secure and resilient AI systems, including threat-led penetration testing and supply chain risk management.
AI-related anti-competitive behaviour is explored further below.
The principal legislation governing trade practices, antitrust, and competition in Australia is the CCA, which is administered and enforced by the ACCC. The CCA applies economy-wide and is technology-neutral, meaning it covers conduct involving artificial intelligence and algorithmic systems even though it does not contain AI-specific provisions.
Recent development and ACCC focus
The ACCC has significantly increased its scrutiny of digital markets and the use of AI, particularly in the context of competition, consumer protection, and data-driven business models. The ACCC’s five-year Digital Platform Services Inquiry (concluded in March 2025) and its ongoing enforcement priorities have placed algorithmic conduct, digital platforms, and data-driven market power at the centre of Australia’s antitrust agenda.
Key areas of focus and recent developments include:
- Big data and market power. The ACCC continues to examine the role of big data and AI in the accumulation and exercise of market power, especially by large digital platforms. The 2025 Final Report of the Digital Platform Services Inquiry reiterated concerns about the anti-competitive risks associated with data-driven ecosystems, including barriers to entry, self-preferencing, and the leveraging of data advantages to entrench dominant positions.
- Algorithmic collusion and price-fixing. The ACCC has reaffirmed its position that the use of AI and machine learning algorithms to facilitate collusion or concerted practices — such as price-fixing or market sharing — falls squarely within the scope of the CCA. The ACCC’s Approach to Colluding Robots (2017) remains relevant, but recent enforcement activity and guidance have emphasised that liability cannot be avoided by attributing anti-competitive outcomes to autonomous systems. The new concerted practices provisions and the misuse of market power reforms (introduced in 2017) are considered fit-for-purpose to address algorithmic collusion, even where there is no explicit agreement between competitors.
- Merger control and digital markets. The CCA’s merger provisions have been updated, with a new mandatory, suspensory merger regime coming into effect from 1 January 2026. The ACCC now has enhanced powers to review and block mergers that may substantially lessen competition, including those involving the acquisition of data assets, AI capabilities, or nascent competitors in digital markets. The ACCC has signalled that it will closely scrutinise serial acquisitions and “killer acquisitions” in the tech sector and will consider the role of algorithms and data in assessing market power and competitive effects.
- Algorithmic transparency and consumer protection. The ACCC has also focused on the transparency and fairness of algorithmic decision-making in consumer-facing markets. Issues such as dark patterns, algorithmic discrimination, and the manipulation of consumer choice through AI-driven interfaces have been the subject of enforcement action and policy reform proposals. The ACCC’s recommendations for new unfair trading practices prohibitions and service-specific codes for digital platforms are expected to further address these risks.
- Case law and enforcement. The proceedings in Google Inc v. ACCC [2013] HCA 1 concerned Google’s deployment of sponsored links in which consumers’ search results would instead produce competitor names who had entered into advertising arrangements with Google. The High Court accepted Google’s appeal and ultimately held that such conduct was not misleading or deceptive on the basis that Google had not itself created the published links. While there have been no further High Court decisions in Australia on AI-specific antitrust issues since, the ACCC has commenced proceedings and accepted enforceable undertakings in several cases involving algorithmic conduct, digital advertising, and online marketplaces. The ACCC’s enforcement approach is increasingly informed by advanced data analytics and international cooperation with other competition authorities.
There is currently no legislative guidance or jurisprudence in Australia which expressly deals with whether AI agents are recognised as having legal personality, capacity to enter contracts, or ability to act on behalf of principals.
The chair of the ACCC, Gina Cass-Gottlieb, has, however, recently been reported as publicly expressing concerns about the proliferation of artificial intelligence systems in online retail, saying bots deployed by rival businesses could collude to fix prices.
The chair highlighted a number of risks of AI “agents” or bots and indicated these will be a key focus for the watchdog this year, including concerns that:
- AI-powered bots acting on behalf of consumers and being tricked into higher-cost deals;
- the risk of cartel conduct involving AI-powered bots;
- AI’s potential to “supercharge” scams; and
- companies overplaying the extent to which machine learning features in their software or products to justify charging consumers more, in a practice dubbed “AI washing”.
There are currently no specific industry-specific rules for autonomous AI agents in sectors such as financial services, healthcare, transportation, or defence.
In Australia, AI systems would likely be assessed under existing product liability frameworks in the Australian Consumer Law, which generally treat them as either “goods” or “services”. If an AI system is considered a “good”, it would be subject to consumer guarantees related to safety, fitness for purpose, and acceptable quality. If considered a “service”, then general consumer protection provisions and professional duties of care would apply.
There is no legislative guidance or jurisprudence which expressly deals with responsibility for the decisions made by AI systems, and any liability that flows from such decisions. For example, there is no standard Australian position as to whether responsibility and liability should fall on the user deploying the AI system, end user of the AI system, or any other parties who have contributed to the development of the AI system (i.e. hardware and software manufacturers, programmers and data supplier).
The attribution of responsibility and liability in respect of AI systems will likely depend upon how the decision can be traced back through the decision-making matrix to identify the “bad actor” or fault component. This will depend upon the extent to which the factors contributing to the relevant decision can be identified.
Australia has strict liability regimes for defective products under the Australian Consumer Law. These provisions would apply to AI systems if they were considered “goods” and are found to have a safety defect that causes loss or damage, regardless of fault.
Obligations for AI system recalls, updates, or safety measures when defects or risks are discovered would generally fall under existing product safety laws and regulations, such as those found in the Australian Consumer Law. Manufacturers and suppliers have obligations to notify authorities and recall unsafe goods.
There is currently no specific legislative guidance or significant jurisprudence in Australia that expressly deals with product liability for AI systems, including notable cases or emerging litigation trends.
Review of AI and Australian consumer law
The Treasury of Australia has published its final report in October 2025 titled Review of AI and the Australian Consumer Law, in which it concluded that existing consumer laws are broadly capable of adapting to the increasing uptake of AI enabled goods and services and, as such, there is no present proposal to amend existing consumer laws to address AI specific risks. However, the situation will be monitored and further considered in ongoing review of consumer protection laws by the Consumer Affairs Minister.
As at the start of 2026, Australia does not intend to enact a dedicated, comprehensive AI Act for regulation of artificial intelligence across the economy. The government has signalled instead a preference for a sector-led, risk-based approach, relying on targeted amendments to existing laws and the introduction of enforceable standards in high-risk domains.
National AI Plan and legislative direction
The National AI Plan (2025) confirms that, for the foreseeable future, Australia will not introduce a standalone AI Act akin to the EU AI Act. Instead, the government is pursuing a strategy of updating and harmonising existing laws — such as privacy, consumer protection, copyright, anti-discrimination, and critical infrastructure legislation — to address AI-specific risks and opportunities. The government has also established the Australian AI Safety Institute (AISI) to monitor, test, and provide guidance on emerging AI risks, and to advise on the need for future legislative intervention.
Online Safety Act 2021 (Cth) and AI-specific standards
The Online Safety Act remains the most prominent example of enacted legislation that directly addresses the use of AI in a specific context. The Act establishes mandatory Designated Industry Codes and Standards for organisations engaged in “online activity”, including those deploying “high impact generative AI” services. The Designated Internet Services Standard (“DIS Standard”), updated in 2025, imposes specific obligations on providers of internet services that enable users to generate synthetic high-impact material (such as deepfake films likely to be classified R18+ or X18+).
Key features of the DIS Standard include:
- Monitoring and notification. Providers must implement robust systems and processes — including AI and machine learning technologies — to detect, identify, and report prohibited material (e.g. child sexual exploitation, pro-terror, or extreme violence content) on their platforms.
- Escalation and removal. Providers are required to develop technical capabilities to escalate and remove prohibited material swiftly, and to cooperate with the eSafety Commissioner in enforcement actions.
- AI as compliance tool. The DIS Standard expressly references the use of AI and machine learning as essential tools for meeting these compliance obligations, highlighting the government’s willingness to encourage responsible AI adoption in online safety contexts.
Other targeted legislative developments
- Critical infrastructure. Amendments to the SOCI Act have introduced new cyber and risk management obligations which would be relevant for entities deploying AI in critical infrastructure sectors.
- Privacy and automated decision-making. POLA introduces new transparency, impact assessment, and contestability requirements for automated decision-making, including AI-driven systems, with further reforms anticipated.
- Copyright and data use. Ongoing consultation is underway regarding copyright law reform and the use of copyrighted material in AI training, with a focus on licensing and fair remuneration for creators.
Legislative outlook
While there is no comprehensive AI Act, the government has left open the possibility of introducing dedicated AI legislation in the future, should regulatory gaps emerge or international alignment require it. In the meantime, the regulatory environment is characterised by a patchwork of sector-specific and technology-neutral laws, supported by enforceable standards and best practice guidance.
The National AI Plan released in December 2025 now serves as the central policy framework for AI governance, investment, and risk management in Australia, superseding earlier discussion and proposal papers. The strategy reflects a shift from prescriptive, mandatory guardrails towards a more flexible, risk-based, and sector-led approach, while maintaining a strong emphasis on safety, accountability, and international alignment.
National AI Plan and Guidance for AI Adoption
Following extensive consultation and feedback — including from the Productivity Commission, industry, and civil society — the Australian government announced in late 2025 that it would not proceed with mandatory guardrails or a standalone AI Act at this stage. Instead, the National AI Plan (December 2025) sets out a coordinated, whole-of-government strategy to:
- capture the economic and social opportunities of AI;
- spread the benefits of AI adoption across all sectors and communities;
- keep Australians safe by strengthening existing legal frameworks and establishing new institutional capabilities, such as AISI.
The Plan is supported by the updated Guidance for AI Adoption (2025), which distils the earlier 10 guardrails into six essential practices for responsible AI governance. These voluntary standards, developed by the National Artificial Intelligence Centre (NAIC), are now widely recognised as the baseline for best practice in both the public and private sectors.
Key features of the current strategy
- Risk-based and sector-led regulation. The government has committed to a “regulation where necessary” approach, relying on targeted amendments to existing laws (e.g. privacy, consumer, copyright, critical infrastructure) and sector-specific codes and standards to address AI risks.
- International alignment. Australia’s definitions and standards for general-purpose and high-risk AI are designed to be interoperable with international frameworks, including the EU AI Act, the Canadian Artificial Intelligence and Data Act, and the OECD AI Principles.
- Institutional capability. The establishment of the AISI in 2026 will provide ongoing monitoring, testing, and guidance on AI risks, and support the government in identifying regulatory gaps and responding to emerging harms.
- Transparency and accountability. The Policy for the Responsible Use of AI in Government (December 2025) is now mandatory for all non-corporate Commonwealth entities, requiring agencies to implement strategic AI adoption plans, transparency statements, and risk-based impact assessments.
- Voluntary standards and best practice. The NAIC’s Guidance for AI Adoption and the Voluntary AI Safety Standard provide practical, actionable guidance for organisations to implement safe, ethical, and trustworthy AI systems.
State-level initiatives
The States and Territories of Australia are developing or updating their own AI assurance and governance frameworks in line with national and international best practice. For example, the New South Wales (NSW) Government continues to require agencies to complete the AI Assurance Framework for high-value AI projects, incorporating risk-benefit analysis and alignment with NSW’s AI Ethics Principles.
Does Australia have a dedicated, comprehensive AI Act like the EU?
Australia has not enacted a standalone AI Act. The government prefers a sector-led, risk-based approach, relying on targeted amendments to existing laws (e.g. privacy, consumer protection) and introducing enforceable standards in high-risk domains, guided by the National AI Plan.
How do recent privacy reforms impact the use of AI in Australia?
Recent privacy reforms introduce new transparency requirements for ADM in privacy policies, grant individuals the right to information about ADM, and mandate PIAs for high-risk AI and ADM activities.
How does Australian competition law address potential anti-competitive behaviour involving AI?
Australia’s CCA applies to AI, with the ACCC actively scrutinising digital markets. Key focus areas include algorithmic collusion, the accumulation of market power through AI and data, and ensuring algorithmic transparency for consumer protection.
What is the current approach to product liability for AI systems in Australia?
AI systems are assessed under existing Australian Consumer Law frameworks, treated as either “goods” or “services”. If classified as “goods”, they are subject to consumer guarantees and strict liability for safety defects. There is currently no specific AI product liability legislation or significant case law.
What are the ACCC’s primary concerns regarding “Agentic AI” or AI bots?
The ACCC is concerned about AI-powered bots potentially colluding to fix prices, consumers being manipulated into higher-cost deals, AI enhancing scams, and “AI washing” — companies overstating AI features to justify higher prices.
Addendum
- On 15 July 2026, Prime Minister Anthony Albanese announced the "AI in Australia's Interests" framework, marking a significant shift to purpose-built AI regulation.
- The centrepiece of the new policy is a proposed set of mandatory Australian Standards for AI, to be designed by a newly established Office of AI within the Department of the Prime Minister and Cabinet, with enabling legislation expected to be introduced to Parliament in early 2027.
- On 20 July 2026, the Government released AI consumer safety priorities foreshadowing reform in areas including a digital duty of care, privacy, workplace AI safety, consumer protections, and automated decision-making within federal agencies.
- A Joint Select Committee on Artificial Intelligence was appointed on 20 August 2026 to examine the adequacy of existing laws, including copyright, national security, data sovereignty, deepfakes, and cybersecurity.
- Most recently, in September 2026, the Office of AI published a formal consultation paper titled "Getting it right: Building AI infrastructure that works for Australia," seeking feedback on the future of AI training and large data centres.
- The proposed AI Standards include significant obligations specifically targeting large data centre and AI infrastructure operators, requiring them to underwrite their own new power supply (including renewable energy), pay the full cost of grid connections, reduce power when needed to support the electricity grid, and minimise water usage. Data centres will be required not to pass energy costs on to consumers and to maximise energy efficiency. Several states and territories are now developing complementary frameworks, including NSW's comprehensive Data Centre Guidelines and South Australia has proposed legislation to manage data centre growth.
- The Government has also signalled its new policies will consider stronger copyright protections, ensuring Australian artists, writers, and journalists retain ownership and control over their works in relation to AI training.
- The proposed new framework is to be considered further by National Cabinet, with the Government describing it as the first such comprehensive national AI standards regime to be legislated by a government worldwide.