Yes, and the picture changed twice in eight months.
In December 2025 the government dropped the mandatory AI guardrails everyone had spent two years preparing for. A lot of businesses read that as a reprieve and stopped thinking about it. Then in July 2026 the Prime Minister announced Australian Standards for AI that will carry mandatory obligations, and National Cabinet is considering them as I write this.
Meanwhile, quietly, one obligation with a real date on it has been sitting there the whole time.
What actually happened
Two things, and most commentary only covers the first.
December 2025. After consultation that drew more than 300 submissions, the government decided not to proceed with the proposed mandatory guardrails for high-risk AI. The National AI Plan of 2 December leaned on existing law instead, supported by non-binding guidance and an AI Safety Institute that advises rather than compels.
July 2026. On 15 July the Prime Minister set out a different direction: Australian Standards for AI intended to apply across the economy and, for the first time, carry mandatory obligations rather than relying on guidance and self-attestation. An Office of AI was established in the Department of the Prime Minister and Cabinet the same day.
The concrete requirements published so far are aimed at large AI data centres, covering energy, water and grid connection, plus protections for Australian creative work. Whether anything lands on ordinary businesses is not settled. National Cabinet is considering the approach this month, and legislation is expected in early 2027.
So the honest position is not “we dodged it”. It is that the shape of any future obligation is being decided right now, and nobody can tell you yet what it will ask of a ten-person firm.
Is anything actually required today?
Yes, though not by anything with “AI” in its title.
Australian law is technology neutral. The Privacy Act does not care whether a person or a model exposed a client’s information. Consumer law does not care whether a misleading quote was typed or generated. Discrimination law does not care whether a shortlist came from a hiring manager or a tool the hiring manager trusts. None of that softened when the guardrails were dropped, and none of it is waiting for 2027.
The practical consequence is not a reversed burden of proof. It is that if something goes wrong you will be asked what steps you took, and “the AI did it” has never been an answer.
The one obligation with a date on it
From 10 December 2026, an organisation covered by the Privacy Act has to say in its privacy policy where it uses personal information in automated decisions that could reasonably be expected to significantly affect an individual’s rights or interests. You describe the kinds of personal information involved and the kinds of decisions being made.
Here is the part that catches people out, and it is the reason I have written this section carefully.
The obligation is not limited to decisions a computer makes on its own. It also covers a program that does something substantially and directly related to making the decision, which includes recommending a decision to a human or guiding one. A person reviewing and approving the output does not put you outside it. If a tool is materially shaping the decision, it counts.
It is also not limited to AI. Rule-based systems and automated assessments are captured on the same terms.
The obligation carries civil penalty exposure, so it is not purely a paperwork exercise, and it applies to decisions made after commencement even where the system and the data predate it. The OAIC ran an issues-paper consultation to the middle of 2026 and has said it intends to publish guidance before the obligation starts, so the detail may sharpen before December.
Does any of this apply to a small firm?
This is where I want to be careful, because the honest answer is “it depends”, and the alarmist version of this article would be more persuasive and less true.
The Privacy Act’s small business exemption still exists. It has been narrowed rather than removed, and there are two narrowings worth knowing about.
The AML/CTF reforms, from 1 July 2026. A new group came into the reporting regime, and it reads like a list of my clients: real estate professionals, lawyers, accountants, conveyancers, trust and company service providers. But capture depends on providing a designated service, not on your profession. A tax-only accountant or a litigation-only firm may not be caught at all.
And where a firm is caught, the exemption falls away for the personal information it handles for those obligations, not for the whole practice. So a conveyancer who is now a reporting entity picks up Privacy Act obligations around their customer due diligence, and the December disclosure requirement bites only if something in that scope is automated. Using AI to draft client letters is not what this is about.
The statutory tort, since June 2025. This one ignores the exemption entirely. An individual can sue for a serious invasion of privacy, and the defendant does not have to be covered by the Privacy Act at all. It requires conduct that was intentional or reckless and an invasion that is genuinely serious, so it is not a trap for ordinary mistakes. But it does mean “we are under the threshold” stopped being a complete answer over a year ago.
I am not a lawyer, and if you think you are in scope this is the point to talk to one rather than to me. What you can do without advice is answer the question underneath all of it: does an automated tool shape decisions about people in this business? If yes, the advice is worth paying for. If no, you can stop reading here.
What does governance look like for a firm my size?
Less than the phrase suggests, and more than nothing.
I work with small and mid-sized Australian professional services firms, and this section is written for them. A large enterprise, or anyone running AI through hiring, lending or customer decisions at volume, is in different territory and needs more than four questions.
Almost none of the firms I work with need a framework. What they need is to be able to answer four questions about any AI that touches a client:
What goes in? If client information is being pasted into a tool, someone should have decided that on purpose, knowing where the data goes and whether it trains anything.
Who checks what comes out? Not “we all keep an eye on it”. A name. This is about output quality and accountability inside your business. As above, it does not change your position under the Privacy Act.
What happens when it’s wrong? It will be, occasionally. The question is whether that surfaces in a review step or in front of a client.
Would you be comfortable explaining it? If a client asked how their proposal was produced, is the honest answer one you would happily give?
Answer those four for each place AI touches your work and you have governance. It might fit on a page, which is fine, and is considerably more than most firms have.
What do most businesses get wrong?
Three things, none of them about policy.
They buy tools before deciding who owns the output. The subscriptions arrive one person at a time, each solving somebody’s immediate problem, and nobody is accountable for what comes out the other end. That is not a tooling failure. It is a decision nobody got around to making.
They write the document and stop. A policy nobody has tested against a real workflow is a hypothesis. If it has never changed how a single quote gets produced, it is a file, not governance.
They treat consistency as optional. Different people using AI differently across one firm produces work that does not sound like one business. Clients notice that long before a regulator would.
If you want a starting point that is not written for a large enterprise, the National AI Centre’s Guidance for AI Adoption updated the ten guardrails in the 2024 Voluntary AI Safety Standard into six essential practices. It is non-binding guidance. Your own version should be shorter and more specific than anything published for general use.
When is this genuinely overkill?
Often enough that I would rather say so.
If the only AI in your business is one person using ChatGPT to tidy up their own emails, you do not need a governance process. You need them to know not to paste client financials into it. That is a conversation, not a document.
If AI touches only internal work that never reaches a client and never involves personal information, the risk is that the output is wrong and someone wastes an afternoon. Annoying, not governance.
The threshold moves when AI output reaches a client, shapes a decision about a person, or touches information you hold on someone else’s behalf. Below it, writing a policy is theatre. Above it, not writing one is a decision you have made whether you meant to or not.
I would rather tell someone their first AI project needs none of this than sell them a framework they will never open.
Where should you start?
Not with a policy.
Start with a list. Every place AI currently touches your work, including the informal ones nobody wrote down. Most firms are surprised by this list, because the tools arrived one person at a time.
Then answer the four questions above for each. Most resolve in a sentence. One or two will not, and those are where an actual problem is waiting.
Then write down only what you had to decide. That is your governance. If it runs past a few pages for a firm your size, you have written it for an audience that does not exist.
That is the order I work in with clients: find out what is really happening, decide who owns what, then write down only the decisions. You can see how that runs in the Korbai Method, and what an engagement covers in services. If you would rather talk it through, a conversation costs you half an hour.
FAQ
Is AI governance a legal requirement in Australia?
Not as a standalone requirement. There is no Australian AI Act and the proposed mandatory guardrails were not taken forward. Mandatory Australian Standards for AI were announced in July 2026 with legislation flagged for early 2027, but the detail for ordinary businesses is not settled. What already applies is existing privacy, consumer, discrimination and work safety law.
What does the Privacy Act now require about automated decisions?
From 10 December 2026, organisations covered by the Act must disclose in their privacy policy where personal information is used in automated decisions that could significantly affect someone’s rights or interests, including the kinds of information and the kinds of decisions involved.
We have a human review every AI output. Are we exempt?
No. The obligation reaches systems that recommend or guide a human decision, not only ones deciding on their own. If the tool is substantially and directly shaping the decision, human sign-off does not remove it from scope. Human review is still worth having, just not for that reason.
Does the Privacy Act apply to what we put into AI tools?
If you are covered by the Act, yes, in the same way as anything else you do with personal information. Putting client data into a third-party tool will in most circumstances be a disclosure, and needs the same thought as any other disclosure.
We’re under the $3 million turnover threshold. Are we outside all of this?
Less reliably than you were. The small business exemption still exists, but the AML/CTF reforms from 1 July 2026 brought firms providing designated services into the regime, and the exemption does not apply to the personal information handled for those obligations. Separately, the statutory tort for serious invasions of privacy has applied since June 2025 regardless of turnover or whether you are covered by the Act at all. Worth checking with your own adviser rather than assuming either way.
Who should own AI governance in a small business?
Whoever owns the process the AI touches, not IT and not a committee. If AI drafts your quotes, the person accountable for quotes is accountable for the AI in them. Governance that sits outside the work gets ignored by the work.
Should we wait for the new standards before doing anything?
I would not. Knowing what you use, who owns it and what happens when it is wrong is the same short piece of work whatever arrives in 2027, and the December Privacy Act obligation does not wait for it.
General information only, not legal advice. Current as at August 2026: this area is moving quickly and the position may have changed by the time you read it.

