Australia published a set of mandatory AI guardrails and a nearly identical set of voluntary ones on the same day in September 2024. One was a consultation proposal and one was available to adopt immediately, and a great deal of subsequent writing treats the first as though it had become law.
Two documents, one day
On 5 September 2024 the Department of Industry, Science and Resources released a proposals paper, Safe and responsible AI in Australia: proposals paper for introducing mandatory guardrails for AI in high-risk settings, opening a consultation that closed in October 2024. The consultation material is published by the department: the mandatory guardrails consultation.
The same day, the National AI Centre published the Voluntary AI Safety Standard, a standard organisations could adopt straight away. The two documents share nine of ten guardrails word for word. The pairing was deliberate: give organisations something to implement now, and consult on making a version of it compulsory in high-risk settings later.
This is a factual status page about a proposal, not legal advice, and not a description of Australian law. Nothing in the mandatory guardrails binds anyone unless and until legislation is enacted. Check the department’s current publications before relying on any statement about Australian AI obligations.
The ten guardrails
As proposed in the September 2024 paper, an organisation developing or deploying AI in a high-risk setting would be required to:
- Establish, implement and publish an accountability process, including governance, internal capability, and a strategy for regulatory compliance.
- Establish and implement a risk management process to identify and mitigate risks.
- Protect AI systems and implement data governance measures to manage data quality and provenance.
- Test AI models and systems to evaluate model performance, and monitor the system once deployed.
- Enable human control or intervention in an AI system to achieve meaningful human oversight.
- Inform end users of AI-enabled decisions, of interactions with AI, and of AI-generated content.
- Establish processes for people impacted by AI systems to challenge use or outcomes.
- Be transparent with other organisations across the AI supply chain about data, models and systems, to help them effectively address risk.
- Keep and maintain records to allow third parties to assess compliance with the guardrails.
- Undertake conformity assessments to demonstrate and certify compliance with the guardrails.
The paper proposed a principles-based definition of high-risk settings rather than a fixed list, keyed to factors including the risk of adverse impacts on rights, on physical and mental health and safety, on legal effects and on groups and society, with general-purpose AI models addressed separately. That is a different architecture from the AI Act’s enumerated high-risk categories, and it was one of the more contested elements of the consultation precisely because a principles-based scope is harder to answer “am I in it?” against.
Where the two lists diverge
Guardrails 1 to 9 are the same in both documents. The tenth is where they part, and the substitution tells you what the mandatory version is for.
The Voluntary AI Safety Standard’s tenth guardrail asks organisations to engage stakeholders and evaluate their needs and circumstances, with a focus on safety, diversity, inclusion and fairness. The mandatory proposal replaces that with conformity assessment— demonstrating and certifying compliance, whether by self-assessment, by an accredited third party, or by government certification.
That is the whole regulatory difference in a sentence. Nine of the ten guardrails describe good practice that an organisation can adopt without anyone checking. The tenth is the mechanism by which somebody checks, and it is the only one that cannot exist voluntarily in any meaningful sense. The same logic explains why conformity assessment is the load-bearing part of the European scheme too.
The three regulatory options
The proposals paper canvassed three ways of giving the guardrails force, and did not pick one:
- A domain-specific approach. Adapt existing legislation in each regulated domain—privacy, consumer, health, financial services, work health and safety—to carry the guardrails. Lowest disruption, highest risk of gaps and inconsistency between regulators.
- A framework approach. New framework legislation that sets the guardrails once and amends existing statutes to apply them through existing regulators.
- A whole-of-economy approach. A single cross-economy AI Act with its own regulator, closest to the European model.
Australia has substantial existing law that already reaches AI harms— the Australian Consumer Law, the Privacy Act 1988 and its recent amendments including the automated decision transparency requirements added in 2024, anti-discrimination statutes, and the Therapeutic Goods Administration’s regulation of software as a medical device. The argument for the first option is that these are already in force and already have regulators; the argument against is that a person harmed by an AI system should not have to work out which of eight regimes applies.
Status, and what to watch
As at the date on this page, no mandatory guardrails legislation has been enacted in Australia, and none had been introduced into the Parliament. The Voluntary AI Safety Standard remains available and voluntary. Government statements and policy work through 2025, including work on national AI capability, pointed towards using and adapting existing regulatory frameworks rather than legislating a standalone cross-economy AI Act—but a stated direction is not an enacted one, and the position should be verified rather than inferred from this page.
Three signals would tell you the position has actually moved:
- A bill before the Parliament. Australian bills, their explanatory memoranda and their progress are published on the Parliament’s website. Until a bill exists, nothing is imminent.
- Amendments to a sectoral statute that carry guardrail language. Under the first option the guardrails would arrive as amendments to existing Acts rather than as an AI Act, which is easy to miss if you are watching for the wrong instrument.
- Regulator guidance applying existing law to AI. The Office of the Australian Information Commissioner and the ACCC can act under their current powers, and guidance from either changes what is expected without any legislation at all.
For an organisation deciding what to do in the meantime, the useful observation is that guardrails 1 to 9 duplicate what the NIST AI Risk Management Framework and an ISO/IEC 42001 management system already ask for. Work done against either maps onto the Australian list with very little translation, which makes the voluntary standard a cheap adoption for anyone already doing the work rather than a separate programme.
Top comments (0)