No AI Act: The National AI Plan
Updated 2 September 2026: this article was rewritten. An earlier version said Australia was moving to binding AI rules in 2026 with compliance audits by Q1 2026. That is not what happened. The 2024 proposal for mandatory guardrails for high-risk AI is not proceeding.
The National AI Plan, released on 2 December 2025, sets Australia's direction: no stand-alone AI Act, existing technology-neutral laws continue to apply, and sector regulators such as APRA, ASIC and the OAIC supervise AI within their existing remits. The Australian AI Safety Institute, announced on 25 November 2025 and operational by July 2026, is not a regulator.
Voluntary Guidance for AI Adoption
The Voluntary AI Safety Standard of September 2024 was replaced on 21 October 2025 by the Guidance for AI Adoption, which sets out six practices for organisations using AI. It remains voluntary in 2026. It is a useful structure for an AI governance program, but it does not create obligations on its own.
The OAIC's AI guidance of 21 October 2024 covers using commercially available AI products and developing or training generative AI. It explains how the existing Australian Privacy Principles apply to AI, which is where most binding obligations for Australian organisations currently sit.
Privacy Act: ADM Transparency from 10 December 2026
The Privacy and Other Legislation Amendment Act 2024 (Royal Assent 10 December 2024) is the binding change that matters for AI. From 10 December 2026, APP entities must describe in their privacy policy the kinds of personal information used, and the kinds of decisions made, by computer programs where the decision could reasonably be expected to significantly affect an individual's rights or interests. OAIC guidance consultation on this obligation opened on 18 May 2026.
The same Act introduced a statutory tort for serious invasions of privacy, in force since 10 June 2025, and requires a Children's Online Privacy Code to be registered by 10 December 2026. A second tranche of reforms (fair-and-reasonable test, right to erasure, consent, restrictions on trading personal information) was released as an exposure draft on 31 August 2026 with submissions closing 18 September 2026. It is not law.
APRA and ASIC Expectations for Financial Services
APRA's Prudential Standard CPS 230 on operational risk has been in force since 1 July 2025, with transition for legacy service-provider contracts to 1 July 2026. On 30 April 2026 APRA wrote to industry describing AI as a step-change and setting out expectations: AI inventories, board oversight, human involvement in high-risk decisions, and supplier risk management.
ASIC published REP 798 on AI use by licensees on 29 October 2024 and an open letter on frontier AI and cyber on 8 May 2026. On 27 August 2026 ASIC and APRA jointly said that awareness must turn to action, and ASIC's 2026-27 Corporate Plan (26 August 2026) adds AI in customer-facing banking to its focus areas.
What Australian Organisations Should Do Now
Start with an AI system inventory: document every AI system in use, its purpose, the personal information it processes, and the decisions it influences. That inventory feeds the APP privacy policy disclosure due on 10 December 2026 and the AI inventory APRA expects from regulated entities.
Arcus supports Australian organisations with AI impact assessments, PIA and DPIA evidence, an AI bill of materials, and a jurisdiction map that covers the Privacy Act ADM obligation, APRA and ASIC expectations, and the EU AI Act for exporters with Annex III systems in scope from 2 December 2027.