Australia has no AI Act. As at September 2026, AI governance in Australia runs on existing law — the Privacy Act 1988, the Australian Consumer Law, the Spam Act 2003 and the Do Not Call Register Act 2006 — plus voluntary federal guidance. One binding date is already fixed: 10 December 2026.
At a glance — what is law, and what is advice:
- Binding now: Privacy Act and the 13 Australian Privacy Principles; Australian Consumer Law; Spam Act 2003; Do Not Call Register Act 2006; anti-discrimination, WHS and Fair Work obligations; directors’ duties under s 180 of the Corporations Act 2001.
- Binding from 10 December 2026: the automated decision-making transparency obligation in APP 1.
- Binding since 10 June 2025: the statutory tort for serious invasions of privacy.
- Voluntary, and current: the National AI Centre’s Guidance for AI Adoption and its six essential practices (21 October 2025).
- Voluntary, and still published: the 2024 Voluntary AI Safety Standard and its 10 guardrails, and Australia’s eight AI Ethics Principles. The government describes the 2025 guidance as evolving both; neither has been withdrawn, and neither was ever law.
Is there an AI law in Australia?
No. There is no Australian equivalent of the EU AI Act. The National AI Plan, published 2 December 2025, states that the regulatory approach “will continue to build on Australia’s robust existing legal and regulatory frameworks, ensuring that established laws remain the foundation”, with individual regulators keeping responsibility inside their own domains. The plan also commits to establishing an Australian AI Safety Institute to advise those regulators.
The consequence is the most useful sentence on this page: in Australia, nothing about your AI system is exempt because it is AI. A misleading claim generated by a model is misleading conduct under the Australian Consumer Law. A marketing SMS written by a model is a commercial electronic message under the Spam Act. The National AI Centre’s AI and Australian law page maps this across seven harm categories.
How it works
Running the four-touch test on one AI use case
List the use case
Write down one AI use case, not one tool. The same chatbot is a different problem on a marketing page than in a hiring workflow.
Run the four touches
Does it touch personal information, a decision about a person, an outbound message or call, or a claim made to a customer?
Map touches to Acts
Personal information to the Privacy Act, decisions to APP 1 and anti-discrimination law, outbound to the Spam Act and Do Not Call Register, claims to the Australian Consumer Law.
Set the December date
If the use case makes decisions that significantly affect people, its decision types must appear in your privacy policy from 10 December 2026.
MAKE MORE SALES.
Pay-Per-Result pricing — We scale sales HARD aligned to your interests, better than anyone else.
Which AI rules apply to my business in Australia?
These are the instruments that decide the answer. Watch the status column: mixing voluntary guidance into a compliance register is how businesses end up over-engineering one thing and missing a real obligation elsewhere.
| Instrument | Status | What it turns on for AI | Key date |
|---|---|---|---|
| Privacy Act 1988 + Australian Privacy Principles | Law | Any personal information collected by, fed into, generated by or disclosed through an AI system | In force; APP 1 automated decision-making disclosure from 10 Dec 2026 |
| Statutory tort for serious invasions of privacy | Law | Individuals can sue directly for serious invasions of privacy, separately from an OAIC complaint | Commenced 10 June 2025 |
| Australian Consumer Law | Law | Misleading or deceptive conduct — including misleading claims about what your AI does, and silence about when AI is used | In force |
| Spam Act 2003 | Law | Consent, sender identification and a working unsubscribe on every commercial email or SMS, whoever or whatever composed it | In force |
| Do Not Call Register Act 2006 | Law | Telemarketing voice calls, including AI voice agents, to numbers on the register | In force; 30-day washing defence |
| NAIC Guidance for AI Adoption — six essential practices | Voluntary | Governance baseline: accountability, impacts, risk, disclosure, testing, human control | Published 21 Oct 2025 |
| Voluntary AI Safety Standard — 10 guardrails | Voluntary | Still published; the government says the 2025 guidance “evolves” it, so work to the six practices | Published 5 Sep 2024, page updated 2 Dec 2025 |
One threshold catches people out. The Privacy Act generally does not cover a business turning over $3 million or less — but the OAIC lists exceptions that apply regardless of turnover, and one is squarely commercial: a business that trades in personal information, meaning it discloses personal information “for a benefit, service or advantage” without the individual’s consent and without being required or authorised by law. Buy or sell lead data on that basis and turnover is not your escape hatch.
Want this done for you? We book qualified sales appointments on a Pay-Per-Result basis — you only pay for calls that actually land in your calendar.
The four-touch test: how to work out which instruments you have triggered
Most frameworks ask you to classify risk in the abstract. This one asks what the system touches, because in Australia each touch switches on a different named Act. Run it per use case, not per tool — the same chatbot is a different problem on a marketing page than in a hiring workflow.
| Touch | Instrument it switches on | The action it forces |
|---|---|---|
| 1. It touches personal information (input, output, training or logs) | Privacy Act 1988, APPs 1, 5, 6 and 11 | Collection notice, privacy policy updated, and a lawful basis for any secondary use such as model training |
| 2. It touches a decision about a person | APP 1 automated decision-making obligation; anti-discrimination law; Fair Work Act | Disclose the decision types in your privacy policy from 10 Dec 2026, and keep a human able to override |
| 3. It touches an outbound message or call | Spam Act 2003; Do Not Call Register Act 2006 | Provable consent, sender identification, functional unsubscribe; wash call lists within 30 days |
| 4. It touches a claim made to a customer | Australian Consumer Law | Substantiate what the output asserts, and do not let the AI imply it is a person when that matters |
A use case that trips zero touches needs a register entry and nothing more; a use case that trips three needs a named owner before it goes live. That is the whole decision, and it is cheaper than a risk matrix nobody updates.
What changes on 10 December 2026
The Privacy and Other Legislation Amendment Act 2024 inserted an automated decision-making transparency obligation into APP 1. From 10 December 2026, an APP entity that has arranged for a computer program to use personal information to make a decision that could reasonably be expected to significantly affect an individual’s rights or interests must say so in its privacy policy — naming the kinds of personal information used and the kinds of decisions made. The OAIC is still drafting its guidance, having consulted during 2026.
The work this creates is not legal drafting. It is an inventory: you cannot disclose decision types you have not written down. If your lead scoring, credit pre-assessment or application triage runs on a model, that is the list you need before December.
If we can’t make you money, we don’t deserve yours.
Pay-Per-Result pricing — performance-based alignment.
The guidance that changed on 21 October 2025 — and what it did not do
An Australian AI governance article that tells you to implement “the 10 voluntary guardrails” is a version behind rather than wrong: the guardrails have not been repealed or withdrawn, because they were never law. The Department of Industry’s own Voluntary AI Safety Standard page is still live, was last updated 2 December 2025, still sets out the 10 guardrails, and carries this notice above them: “On 21 October 2025, we published the Guidance for AI Adoption, which outlines 6 essential practices for safe and responsible AI governance. This updated and simplified guidance for industry evolves the Voluntary AI Safety Standard.”
The current voluntary baseline is six practices, published in a foundations version for early or low-risk use and an implementation version for higher-risk use: decide who is accountable; understand impacts and plan accordingly; measure and manage risks; share essential information; test and monitor; maintain human control. Practice 1 asks for a named senior owner and an AI policy; practice 4 asks for an AI register and disclosure of AI use. Neither is legally enforceable in itself — both are what a regulator, an insurer or an enterprise procurement team will ask to see.
A documented miss of our own: the rotating audit of our own FAQ page on 15 September 2026 covered 16 answers and fixed seven defects, and the worst was a quotation we had attributed to the ACMA — about SMS sender IDs being labelled “Unverified” — that appears nowhere on the ACMA’s site. We deleted the quotation and the answer carrying it. That is why every instrument on this page is checked against the regulator’s own page and dated from it. Australian AI material has moved repeatedly since 2024, including between industry.gov.au and ai.gov.au, and a confident secondary summary is how both a stale date and an invented quotation get through.
If your AI contacts customers, the Spam Act applies to the message, not the machine
This is where AI governance stops being a policy document and starts costing money. The ACMA does not assess authorship; it assesses the message. In March 2026 it announced that Lululemon Athletica Australia paid a $702,900 penalty for sending more than 370,000 emails with commercial content and no unsubscribe option — service emails such as shipping updates that also carried sales links. The ACMA called it the fifth such action in 18 months, a period in which businesses paid over $6.7 million in spam penalties.
Three Australian specifics that AI outbound stacks tend to get wrong, all verifiable at source:
- Unsubscribe must stay functional for at least 30 days after sending and must not require an account or extra personal information (ACMA, avoid sending spam). Under the Spam Act the burden of proving consent sits with you.
- Express consent for telemarketing expires three months after it was given, unless it was given for a set period or indefinitely, and it ends immediately if the person says stop (Do Not Call Register). A model that re-engages an 18-month-old “consented” list is not working from consent.
- Outsourcing does not move liability. Both the party making the call and the business that caused it to be made must comply. Your AI vendor’s compliance is not a defence for you, which is exactly why our AI outbound compliance checklist for enterprise buyers asks vendors for evidence rather than assurances.
Disclosure sits alongside this. Practice 4 asks organisations to tell people when they are interacting with AI, and the Australian Consumer Law reaches silence that misleads. On our own AI voice agents for sales in Australia the disclosure is configurable, and we recommend turning it on: the agent opens by saying it is an AI assistant and naming the business it is calling for — a second of call time, and an argument you never have to have.
What an honest Australian AI governance baseline costs to run
The six practices are cheap to start and expensive to sustain. Getting started is roughly: a named senior owner, a one-page AI policy, a register listing every AI system including those embedded in your HR and CRM tools, a risk screen per use case, and a disclosure rule — a few days of work using the NAIC’s free templates.
The upkeep is what costs: re-screening every new use case, keeping the register honest as staff adopt tools nobody procured, evidencing consent across every channel, and testing models that drift. Practice 5 asks you to monitor after deployment and to ask suppliers for proof of testing — a standing job, not a project. Firms running AI in regulated Australian industries carry sector obligations on top, which is usually where internal capacity runs out. Where AI belongs in the business at all is a prior question — see AI for business.
This page is general information, not legal advice. For anything consequential — a high-impact automated decision, a data breach, a contested consent position — take it to your own lawyer or to the regulator: the OAIC for privacy, the ACMA for spam and telemarketing.
Frequently asked questions
Does Australia have an AI Act?
No. Australia has no AI-specific statute. The National AI Plan of 2 December 2025 confirms the government will build on existing legal frameworks rather than a standalone AI law, with an AI Safety Institute to advise regulators. Existing privacy, consumer, discrimination, workplace and directors’ duty obligations apply to AI systems unchanged.
Are the 10 AI guardrails still current in Australia?
They have not been withdrawn, but they are no longer the guidance the government puts first. The Department of Industry’s Voluntary AI Safety Standard page, updated 2 December 2025, still publishes the 10 voluntary guardrails and carries a notice that on 21 October 2025 it published the Guidance for AI Adoption, which “evolves” the standard into six essential practices. Work to the six practices. Neither set is law.
Do I need an AI policy for my business in Australia?
No law requires one. The National AI Centre’s current guidance asks you to assign a senior AI governance owner and create an AI policy as its first “getting started” action, and free templates are published with it. Enterprise procurement and insurers increasingly ask for both.
Does the Privacy Act apply to my small business if it uses AI?
Usually not below $3 million annual turnover — but the OAIC lists exceptions that apply regardless of turnover, including health service providers, credit reporting bodies and businesses that trade in personal information. Trading means disclosing personal information for a benefit, service or advantage without the individual’s consent and without being required or authorised by law. Buy or sell lead data on that basis and you are covered whatever your turnover.
Can I put customer data into ChatGPT or a similar tool?
The OAIC’s guidance on commercially available AI products, published 21 October 2024, recommends that organisations do not enter personal information, and particularly sensitive information, into publicly available AI chatbots. It also warns that a secondary use such as AI training is often hard to justify as within reasonable expectations under APP 6.
What happens on 10 December 2026?
The automated decision-making transparency obligation in APP 1 commences. Entities using personal information in automated decisions that could significantly affect a person’s rights or interests must disclose in their privacy policy the kinds of personal information used and the kinds of decisions made. OAIC guidance is still in development.
Pay-Per-Result appointments
See if we’re a fit
We book qualified sales appointments for you and you pay on results, not retainers. Our booking page asks a few quick questions so you find out in two minutes whether that model suits your business.
- 50,769+ appointments booked without cold calling.
- Pay-Per-Result pricing — you pay for booked, qualified calls.
- Pick your own time on our live calendar, no phone tag.
