Not legal advice, an engineering read. Updated September 2026: the ten MANDATORY guardrails that were proposed for high-risk AI have been shelved. They were replaced with non-binding guidance rather than legislation. The voluntary standard below is still the clearest statement of what responsible looks like, but nothing in it binds you. The one Australian AI obligation that does bind, with a fixed date and civil penalties, is the automated decision-making transparency requirement commencing 10 December 2026 - covered separately in the December deadline article.
The Australian Government published a Voluntary AI Safety Standard built around ten guardrails, alongside a proposals paper on mandatory guardrails for high-risk AI. The mandatory track did not survive: the proposals were dropped and the approach moved to technology-neutral regulation under existing law, plus non-binding adoption guidance. So the ten guardrails are a design brief and nothing more. Useful as one, and worth reading that way rather than as a compliance checklist.
The ten guardrails, compressed
Stripped of policy language, they cluster into four things: know who is accountable, know what could go wrong, be able to show your work, and tell people when AI is involved.
Accountability - a named owner, an internal policy, and someone whose job it is. Not a committee.
Risk management - identify and mitigate the specific harms of the specific system, documented, and revisited rather than done once.
Data governance - know what data trains and feeds the system, its quality, its provenance, and its legal basis.
Testing and monitoring - evaluate before deployment against defined criteria, then keep monitoring, because models drift and inputs change.
Human control - a person can intervene, override, or stop the system. This has to be real, not a button nobody has authority to press.
Informing end users - people are told when AI is materially involved in something that affects them.
Contestability - a person affected by an AI-influenced outcome has a route to challenge it, and that route reaches a human.
Supply chain transparency - you know what is in the AI you bought, and you can tell your own customers.
Record keeping - documentation sufficient for someone else to assess compliance later.
Stakeholder engagement - consider the people affected, particularly on safety, diversity and fairness.
Which ones cost real engineering effort
Most of the list is organisational and costs meeting time. Four of them are genuine engineering work, and they are the four that are painful to add late.
Testing and monitoring - needs an evaluation set, a defined pass criterion, and drift monitoring on inputs and outputs. If you have never built this, it is a real project, not a checkbox.
Human control - an override path has to exist in the data model, not just in the interface. A system that cannot record 'a human overrode this, and why' cannot demonstrate human control.
Contestability - requires that you can reconstruct why a specific decision came out the way it did, for a specific person, months later. That is a logging and explainability requirement.
Record keeping - the documentation only exists if it is generated as you go. Nobody successfully writes it retrospectively.
The model choice this pushes you towards
Contestability and human control are much cheaper to satisfy with a model that can explain a specific decision. Gradient boosting on your own tabular data returns per-feature attribution for every prediction, so 'why was I declined' has a real answer. A language model asked to produce the same score gives you a plausible sentence that may not describe the actual computation, which is worse than no explanation because it looks like one.
This is the same conclusion we reach for reasons that have nothing to do with regulation - determinism, cost at volume, auditability. It is convenient when the compliant choice and the engineering choice are the same choice, and it is worth noticing when they are not.
What happened to the mandatory track
It was abandoned. Australia proposed ten mandatory guardrails for high-risk AI and, roughly fifteen months later, shelved all of them in favour of regulating through laws that already exist - the Privacy Act and Consumer Law - with non-binding guidance on top. If you built a compliance plan around those ten becoming law, that plan is now aimed at nothing. The engineering underneath it is still worth doing, for the reasons in the sections above, but call it engineering rather than compliance.
The practical question for an SMB is therefore not 'do we use AI' but 'does our AI make or materially influence a consequential decision about a person'. If yes, design against the guardrails now. If no, take the four engineering ones anyway because they are just good practice, and skip the governance overhead.
A proportionate response for a small business
The failure mode here is a small company building an AI governance programme it does not need, and the opposite failure mode is a small company automating a hiring decision with no logging at all. Both are avoidable.
Write down what each AI system does, who owns it, and what happens if it is wrong. One page per system is enough to start.
Decide explicitly whether any of them influence a consequential decision about a person. That answer sets the effort level for everything else.
For anything that does: log the inputs, the output, and any human override, and make sure you could explain one specific decision a year from now.
Tell users when AI is materially involved. This is cheap, it is increasingly expected, and it is the thing customers notice you hiding.
Do not write a policy you will not follow. An unfollowed policy is worse evidence than no policy.
This area moves, and a blog post is the wrong source for a date: verify current status before any compliance decision. What is not in doubt is the automated decision-making transparency obligation commencing 10 December 2026, which does carry civil penalties. If you run an automation that touches personal data and makes decisions about people, that one has your name on it. The audit at /audit is free. Ivan / 2pizza.team
Originally published at 2pizza.team. We build AI and automation systems for small teams - fixed price, two to six weeks. See the work.
Top comments (0)