AI Governance for Australian Businesses: Privacy, Security and Responsible Adoption
How Australian businesses can govern AI: what is law, what is commencing and what is voluntary, plus privacy, security, staff policy and a starter kit.
What does AI governance mean for an Australian business?
AI governance is the set of decisions, records and controls that keep your use of AI lawful, secure and accountable. In Australia there is no AI-specific law for private businesses as at October 2026, so governance means applying existing obligations, mainly privacy, consumer law, data breach and cyber reporting rules, to AI, preparing for reforms with fixed commencement dates, and using voluntary national guidance where it helps.
This guide separates those three categories carefully, because much online commentary blurs them. It then walks through the controls that matter in practice: data handling, access, vendor checks, human oversight, output verification, security, monitoring, incident handling, staff policies and intellectual property. It ends with a starter kit you can adapt.
Two cautions. This is general information, not legal advice; for your situation, use the OAIC's guidance, the ACCC or a lawyer. And no checklist, including ours, can ensure compliance. A checklist helps you ask the right questions; the answers depend on your data, systems, contracts and sector. For the generic framework behind this page, see our AI governance framework guide, which covers roles, risk classification and international standards in depth. If you are planning a first project, our AI implementation guide for Australian businesses shows where governance fits in the sequence.
Key takeaways
- No AI-specific law applies to private businesses as at October 2026; existing laws apply to AI use.
- The proposed mandatory guardrails are not law: under the December 2025 National AI Plan the Government did not proceed with them at this time (as reported).
- Fixed dates to plan for: automated decision-making transparency in privacy policies from 10 December 2026, and a Children's Online Privacy Code due to be registered by the same date.
- Many small businesses are outside the Privacy Act, but not all: health service providers, businesses trading in personal information and others are covered regardless of turnover.
- The OAIC recommends not entering personal information, particularly sensitive information, into publicly available generative AI tools.
- Existing reporting duties cover AI incidents too: Notifiable Data Breaches, and ransomware payment reporting within 72 hours for businesses over AUD 3 million.
- The voluntary Guidance for AI Adoption (October 2025) gives six practices and templates; use them as a structure, not as a compliance certificate.
Where the rules stand: existing law, reforms and voluntary guidance
The answer first: sort every rule you hear about into one of three columns before acting on it. Existing obligations apply now. Commenced or commencing reforms are enacted, with dates. Proposals and voluntary guidance are not legal obligations, although they show where expectations are heading and can be useful structure.
| Existing obligations (in force) | Commenced or commencing reforms (enacted) | Proposals and voluntary guidance (not law) |
|---|---|---|
| Privacy Act 1988 and the 13 APPs for APP entities: generally businesses over AUD 3 million turnover, plus some smaller businesses regardless of turnover (OAIC) | Statutory tort for serious invasions of privacy: commenced 10 June 2025 (Federal Register commencement table) | Mandatory guardrails for high-risk AI: proposed September 2024; not proceeding at this time under the National AI Plan, December 2025 (as reported) |
| Notifiable Data Breaches scheme: notify affected individuals and the OAIC when a breach is likely to result in serious harm | Automated decision-making transparency in privacy policies: commences 10 December 2026 | Guidance for AI Adoption (AI6): voluntary, October 2025, condensing the 2024 Voluntary AI Safety Standard into six practices |
| Australian Consumer Law: misleading or deceptive conduct and false representations apply to what a chatbot tells customers | Children's Online Privacy Code: OAIC must register it within 24 months of 10 December 2024; an exposure draft was released in 2026 (as reported) | Australian AI Safety Institute: announced November 2025 with AUD 29.9 million; advisory, with no enforcement powers (as reported) |
| Cyber Security Act 2024 ransomware payment reporting: active from 30 May 2025 for businesses over AUD 3 million turnover and critical infrastructure entities (Home Affairs) | AML/CTF tranche 2: from 1 July 2026, newly regulated small reporting entities are covered by the Privacy Act for AML/CTF-related handling (OAIC; secondary summaries) | Privacy Act tranche 2: a draft bill released for consultation in 2026, as reported; it does not address the small business exemption, which still stands |
| Sector and other rules: health, financial services, critical infrastructure (SOCI Act), workplace, anti-discrimination and the Spam Act | ACCC penalty increases: higher maximum corporate penalties commenced 28 March 2026 (as summarised by law firms) | International frameworks: NIST AI RMF and ISO/IEC 42001 are voluntary and useful for structure |
Worth noting
Dates in the middle column come from the commencement table of the Privacy and Other Legislation Amendment Act 2024 on the Federal Register of Legislation (Royal Assent 10 December 2024). Items marked 'as reported' were checked against secondary sources because the official pages could not be loaded; confirm them on industry.gov.au, ai.gov.au or ag.gov.au before relying on them.
The small business exemption, and why it is not a free pass
What the OAIC says. Most small businesses, defined as those with annual turnover of AUD 3 million or less, are not covered by the Privacy Act. But some are covered regardless of turnover, including health service providers, businesses that trade in personal information, Commonwealth contracted service providers, credit reporting bodies, AML/CTF reporting entities, businesses related to a covered business, and businesses that opt in.
Why it matters for AI. A small clinic using an AI scribe, or a small business selling enriched customer lists, may be fully covered. From 1 July 2026, many newly regulated AML/CTF businesses, such as real estate agents, lawyers, conveyancers and accountants, are covered for AML/CTF-related handling, according to OAIC and law-firm summaries.
Why exempt businesses should still govern AI. The exemption does not cover the Australian Consumer Law, the Spam Act, workplace law or your contracts. Larger customers increasingly ask suppliers about data handling in due diligence. And a data incident still damages trust whether or not a law requires notification. Treating the APPs as good practice is usually cheaper than retrofitting them later.
A working model: the AI governance loop
Governance fails when it is a document nobody uses. We suggest a loop of seven steps that every AI use passes through, scaled to its risk. A staff member using an approved writing assistant passes through it in minutes; an automation that changes customer records takes weeks.
1 REGISTER record the AI use, owner, data, vendor
|
2 ASSESS privacy, security, consumer and
| operational risk; rate low/medium/high
3 APPROVE named approver, conditions attached
|
4 CONTROL access, data minimisation, human review,
| output checks, logging
5 VERIFY test before launch and after changes
|
6 MONITOR quality, incidents, drift, cost
|
7 REVIEW on schedule or after an incident,
| then back to 1 with changes
+--------------------------------------> 1Worth noting
The loop mirrors the six practices in the voluntary Guidance for AI Adoption: accountability (register and approve), understanding impacts and managing risks (assess), sharing information (disclosure in the controls), testing and monitoring, and maintaining human control. The generic framework guide linked above adds roles and risk tiers.
Data handling: mapping the APPs to AI controls
The OAIC's October 2024 guidance on commercially available AI products is the clearest official starting point. Its top takeaways include that privacy obligations apply to personal information input into an AI system and to outputs that contain personal information; that businesses should update privacy policies and notices and identify public-facing tools such as chatbots as AI; that generating or inferring personal information with AI is a collection under APP 3; and that use and disclosure should generally be limited to the primary purpose under APP 6. The table maps these to practical controls for APP entities.
| APP | What it means for AI use | Practical control |
|---|---|---|
| APP 1: open and transparent management | Privacy policy must reflect AI use; from 10 December 2026, also certain automated decisions | Review the policy whenever a new AI use is registered |
| APP 3: collection | AI-generated or inferred personal information counts as a collection | Only generate inferences you would be entitled to collect; avoid sensitive inferences |
| APP 5: notification | People should know when and how AI is used with their information | Label chatbots as AI; update collection notices |
| APP 6: use and disclosure | Inputs are generally limited to the primary purpose unless consent or a reasonably expected secondary use applies | Check vendor terms on using your inputs for training |
| APP 8: cross-border disclosure | Reasonable steps before disclosing personal information overseas; you can remain accountable | Record processing regions and sub-processors for each vendor |
| APP 10: quality | AI outputs can be inaccurate or out of date | Verify outputs before they are relied on or stored |
| APP 11: security | Reasonable steps to protect information, including in prompts and logs | Access control, retention limits, log redaction |
| APPs 12 and 13: access and correction | People can ask for and correct their information | Know where AI-held copies and logs are kept |
Pro tip
The simplest control with the biggest effect is data minimisation: send each AI step only the fields it needs, and strip identifiers where the task does not require them. Our AI data privacy guide covers redaction, retention and privacy-aware architecture in depth.
Access control and security
Least privilege, by default. An AI tool or agent should have its own identity and only the permissions its task needs: read-only where reading is enough, no access to systems outside its scope, and no shared administrator credentials. OWASP's Top 10 for LLM Applications 2025 calls the failure mode excessive agency, alongside prompt injection, sensitive information disclosure, improper output handling and unbounded consumption.
Treat inputs as untrusted. Emails, documents and web pages an AI reads can contain instructions designed to manipulate it. Do not let content the AI reads decide what the AI is allowed to do; enforce permissions in your systems, not in the prompt.
Build on existing security basics. ASD's Essential Eight, which includes multi-factor authentication, restricting administrative privileges, patching and regular backups, is guidance rather than a legal obligation for private businesses, but it is a sound baseline for the systems AI connects to. For websites and customer portals, see website security for Australian businesses.
Log what the AI does. Record which user or process triggered each action, what data was accessed, which tools were called and what changed. Without logs you cannot investigate an incident or answer an access request. Our AI security guide covers threat modelling, tool permissions and runtime monitoring in depth, and AI agent governance covers controls specific to agents. If you are weighing whether an agent is needed at all, see AI agents for Australian businesses.
Vendor assessment: questions before you sign
Most Australian businesses buy AI rather than build models, so the vendor's practices become yours. Ask in writing, keep the answers in your AI register, and repeat the check when the vendor changes its terms or models. Where the AI connects to your own systems, the integration itself needs the same scrutiny; API integration for Australian businesses covers authentication and error handling.
- Data use: are our inputs and outputs used to train or improve models, and can we opt out by contract, not just by a setting?
- Location: in which countries are data stored and processed, including sub-processors? What does that mean for APP 8?
- Retention: how long are prompts, files and logs kept, and can we delete them?
- Security: which controls are in place, how is administrator access managed, and is there independent assurance we can review?
- Access: can we enforce single sign-on, multi-factor authentication and role-based permissions?
- Incidents: how and how quickly will you tell us about a breach affecting our data?
- Change: how are model changes announced, and can we test before they reach production?
- Exit: can we export our data, configuration and prompts, and what happens to our data when we leave?
Worth noting
For outsourced IT, the ACSC suggests asking managed service providers whether they implement better-practice security such as the Essential Eight, administer systems securely, monitor activity, assess their systems regularly and are prepared to respond to incidents. The same questions work for AI vendors. Our AI agent vendor assessment guide has a fuller question set.
Human oversight and output verification
Decide where a person must approve. Require human approval before AI output is sent to customers in high-impact situations, changes financial or customer records, or affects someone's access to a service, employment or credit. The voluntary Guidance for AI Adoption lists maintaining human control as one of its six practices. Our human-in-the-loop guide covers approval thresholds and review interfaces.
Prepare for automated decision transparency. From 10 December 2026, covered entities' privacy policies must describe the kinds of personal information used, and the kinds of decisions made, where a computer program makes or does something substantially and directly related to making a decision that could reasonably be expected to significantly affect an individual's rights or interests. The amendment applies to decisions made after it commences. Your AI register is the natural place to identify which uses are in scope; confirm the analysis with an adviser.
Verify outputs that customers rely on. The Australian Consumer Law's prohibitions on misleading or deceptive conduct and false or misleading representations apply to what a business tells customers, including through a chatbot. A chatbot that misstates refund or warranty rights is your statement, not the software's. Treasury's October 2025 review of AI and the Australian Consumer Law found the ACL broadly capable of handling AI-enabled goods and services, as reported, so expect existing rules to be applied rather than new AI-specific ones. Ground customer-facing answers in approved content, test them against real questions, and route uncertain cases to a person. AI customer service for Australian businesses covers this in detail.
Sample, even when confidence is high. Review a regular sample of outputs that were not escalated. Errors that never trigger a review are the ones that drift unnoticed.
Monitoring and incident handling
Monitor quality, not just uptime. Track accuracy on a fixed test set, escalation and correction rates, complaints, unusual data access and cost per task. Set thresholds that trigger a review.
Know the reporting duties that already apply. The Notifiable Data Breaches scheme requires covered organisations to notify affected individuals and the OAIC when a data breach is likely to result in serious harm; the OAIC says an organisation that suspects an eligible breach must quickly assess it. An AI tool exposing personal information to the wrong person is a data breach like any other. The OAIC received 1,205 notifications in 2025, the highest since the scheme began, with malicious or criminal attacks the leading cause.
Ransomware payments. Under the Cyber Security Act 2024, businesses with annual turnover over AUD 3 million (per Home Affairs), and responsible entities for critical infrastructure assets, must report a ransomware or cyber extortion payment to ASD within 72 hours of making it or becoming aware of it. No report is required if a demand is made but nothing is paid.
Plan the AI-specific steps. Your incident plan should say who can switch off an AI feature or revoke an agent's credentials, how to find every action it took during the incident window, and how to reverse them. Our AI agent incident response guide walks through detection, containment and root-cause analysis.
Staff policies: an acceptable-use policy outline
Most early AI risk comes from well-meaning staff using tools nobody approved. Bans tend to push use out of sight; a short, specific policy works better. The Guidance for AI Adoption includes an AI policy template you can adapt. Whatever template you use, cover these points in plain language.
- Purpose and scope: which staff, contractors and tools the policy covers.
- Approved tools: a list, with the business account each must be used through, and how to request a new tool.
- Data rules: which data classes may go into which tools; no personal or sensitive information in public generative AI tools, consistent with the OAIC's recommendation.
- Verification: staff are responsible for checking AI output before relying on it, sending it or publishing it.
- Disclosure: when to tell customers or colleagues that AI was used, including labelling chatbots.
- Prohibited uses: for example, decisions about individuals without review, or generating content that imitates real people.
- Intellectual property: check provider terms; do not paste in confidential third-party material.
- Incidents: how to report a mistake or suspected data exposure, without blame, and quickly.
- Ownership and review: who owns the policy and when it is next reviewed.
Pro tip
Pair the policy with discovery. Ask teams which AI tools and automations they already use, and register them rather than penalising them. Our guide to shadow AI agents explains how to find unapproved automations without driving them underground.
Intellectual property: proceed with caution
Copyright in AI outputs is unsettled. Whether, and when, material generated with AI attracts copyright protection in Australia is not settled; it was among the questions put to the Government's Copyright and AI Reference Group, established in December 2023, as reported. Until it is clarified, do not assume your business holds exclusive rights in purely AI-generated text, images or code, and keep a record of the human contribution to work that matters commercially.
Contractor work needs a written assignment. Under section 196(3) of the Copyright Act 1968, an assignment of copyright does not have effect unless it is in writing and signed by or on behalf of the assignor. Law-firm and Business Victoria guidance notes that a business paying a non-employee developer does not automatically own the code. If a supplier builds your AI automation, the contract should say who owns the code, prompts, configuration and evaluation data. Our guide to custom software development in Australia covers contracts and ownership more broadly.
Check provider terms and inputs. Read what your AI provider's terms say about ownership of outputs and use of your inputs, and do not feed in material you are not licensed to use. None of this is legal advice; get it for anything you intend to sell, licence or rely on as an asset.
An AI governance starter kit
The answer first: five artefacts cover most of what a small or mid-sized business needs to start. Keep them short, give each an owner, and review them on a schedule. The Guidance for AI Adoption offers templates for a policy and a register that can be adapted.
- Week 1: appoint an accountable owner and start the register with the AI tools already in use.
- Week 2: publish the acceptable-use policy and a list of approved tools.
- Week 3: rate each registered use low, medium or high risk and assess the high-risk ones first.
- Week 4: send the vendor questionnaire to providers of high-risk uses, and check your privacy policy and collection notices.
- Ongoing: a short quarterly governance review, plus an extra review before 10 December 2026 for any use that may involve significant automated decisions.
| Artefact | What it contains | Owner | Review cadence |
|---|---|---|---|
| AI acceptable-use policy | Approved tools, data rules, verification, disclosure, incident reporting | Business owner or operations lead | Every six months, and when a major tool is added |
| Register of AI uses | Each use: purpose, owner, vendor, data classes, processing regions, risk rating, controls, automated-decision flag | Named register owner | Monthly additions; full review quarterly |
| Risk assessment template | Privacy (APPs), consumer law, security, operational and reputational risks; rating; required controls | Use owner, with privacy or IT input | Before launch and after significant change |
| Vendor questionnaire | Data use, location, retention, security, access, incidents, change, exit | Procurement or IT | At onboarding and on renewal or terms change |
| Incident and review log | AI incidents, near misses, complaints, decisions taken, follow-ups | Operations lead | Reviewed at each governance meeting |
Key takeaway
A starter kit does not make you compliant. It gives you a record of what AI you use, why, with what data and under whose authority, which is what you will need when a customer, regulator or adviser asks. For businesses that want a formal management system later, ISO/IEC 42001 and the voluntary NIST AI Risk Management Framework provide fuller structures.
Common mistakes
- Treating proposals as law, or guidance as a certificate. Mandatory guardrails are not law; the Guidance for AI Adoption is voluntary.
- Assuming the small business exemption covers everyone under AUD 3 million. Health providers and several other categories are covered regardless of turnover.
- Governing models but not data. Most risk comes from what you send to AI and where it goes.
- Letting prompts enforce permissions. Enforce access in systems, not in instructions to the model.
- No owner for each AI use. Unowned tools are never reviewed.
- Forgetting existing reporting duties. AI incidents can trigger Notifiable Data Breaches and other obligations.
- Leaving the 10 December 2026 change until December. Identifying automated decisions takes time.
- Assuming you own AI output. Copyright in AI-generated material is unsettled; contractor work needs a written assignment.
Sources
Privacy: OAIC guidance on privacy and commercially available AI products; OAIC small business guidance; OAIC APP 8 guidelines; Privacy and Other Legislation Amendment Act 2024 (Federal Register of Legislation); OAIC on the passage of the privacy bill; OAIC Children's Online Privacy Code consultation; HSF Kramer on the draft tranche 2 reforms (as reported).
Breaches and cyber: OAIC: about the Notifiable Data Breaches scheme; OAIC 2025 NDB statistics; Home Affairs ransomware payment reporting factsheet; ACSC questions to ask managed service providers; ASD Essential Eight Maturity Model.
AI policy (official pages timed out; checked via search and secondary coverage): Guidance for AI Adoption (DISR); National AI Plan (DISR); Ministerial release on the AI Safety Institute; Piper Alderman on the National AI Plan; Treasury review of AI and the Australian Consumer Law.
Security frameworks and IP: OWASP Top 10 for LLM Applications 2025; NIST AI Risk Management Framework; Copyright Act 1968 s196 (AustLII); Business Victoria on software ownership; Cyber Daily on the Copyright and AI Reference Group.
Policy status changes; check the official pages before relying on any date or status here. This article is general information, not legal advice.
Conclusion
Good AI governance in Australia today is mostly disciplined application of laws you already have: know which AI you use and with what data, keep personal information out of tools that should not have it, control what AI can access, keep people accountable for decisions that matter, and know what you must report when something goes wrong. Add the 10 December 2026 privacy policy change to your plan now, use the voluntary Guidance for AI Adoption as structure, and review the starter kit on a schedule.
Governance also shapes budgets: controls, review time and vendor checks all cost money, which our guide to AI automation costs in Australia accounts for. To choose where AI should go first, see AI automation for Australian businesses, and for the broader picture of building AI-enabled products, digital product development in Australia.
Building AI with governance designed in?
ZSpace Labs is an India-based, remote-first technology studio working with Australian and international businesses on AI automation with access controls, review steps and audit logging built in from the start. We are not lawyers, so we work alongside your advisers. If useful, we can review a planned AI use with you and map the controls it needs.
Common questions.
Not an AI-specific law for private businesses, as at October 2026. The Government's National AI Plan of December 2025 did not proceed with the proposed mandatory guardrails at this time, as reported, and relies on existing laws instead. Your AI use is still governed by the Privacy Act, the Australian Consumer Law, the Notifiable Data Breaches scheme, cyber security reporting rules, workplace and anti-discrimination laws, and sector rules.