HomeBlogAI Governance
AI Governance

AI Governance in Australia and NZ: 2026 Guide

Sep 2026 · 10 min read

Isometric illustration of an AI register, a balance scale, a human override lever and a checklist around a central AI chip

If you read AI governance guidance written in 2024, you will come away believing that Australia is about to impose mandatory guardrails on high-risk AI and that the Voluntary AI Safety Standard is the framework to follow. Neither is true any more. Both Australia and New Zealand have chosen to regulate AI through existing law rather than a dedicated AI Act, but that does not mean there is nothing to do. There is one hard deadline this year, a regulator that has told financial services to lift its game, and a clear government playbook. This is what applies as of September 2026.

Does Australia have an AI law in 2026?

No. There is no standalone AI Act. The National AI Plan, published on 2 December 2025, says regulation will continue to build on Australia's existing legal and regulatory frameworks, with existing regulators responsible for AI harms in their own areas.

The plan relies on targeted action rather than a general statute: online safety codes, criminal offences for deepfake sexual material, a copyright review, medical device software regulation through the TGA, and privacy reform.

What happened to mandatory guardrails for high-risk AI?

They were set aside. When the National AI Plan was released, the government chose a technology-neutral approach built on existing law instead of the mandatory guardrails it had consulted on in 2024. It also moved away from a single AI Act and a central AI regulator.

If a vendor, consultant or policy template still tells you mandatory guardrails are coming, it is working from the 2024 position.

Is the Voluntary AI Safety Standard still current?

No. The Guidance for AI Adoption, published by the National AI Centre on 21 October 2025, replaces the Voluntary AI Safety Standard of September 2024. The earlier standard's ten guardrails were streamlined into six practices.

Both were always voluntary. Neither has ever been a legal requirement for private organisations.

What are the six practices in the Guidance for AI Adoption?

Decide who is accountable. Understand impacts and plan accordingly. Measure and manage risks. Share essential information. Test and monitor. Maintain human control.

The guidance comes in two versions: Foundations, for organisations starting out or using AI in low-risk ways, and Implementation guidance, for higher-risk use or more mature organisations. The National AI Centre provides free templates, including an AI screening tool, an AI policy template and an AI register template.

The practical starting actions are concrete: a senior owner for AI governance, an AI policy, a stakeholder impact assessment, a way for people to contest decisions, risk screening of each use case, an AI register, disclosure of AI use, testing before deployment, and defined points where a human can override the system.

What does the Australian AI Safety Institute do?

It was announced in November 2025 with $29.9 million over four years and began operating in 2026 within the Department of Industry, Science and Resources. It monitors, tests and shares information on AI risks and harms, and by July 2026 ministers said it had begun safety testing of frontier AI systems.

It is not a regulator. It does not enforce anything against organisations that use AI.

What are the Australian AI Standards announced in July 2026?

The Office of AI was established in the Department of the Prime Minister and Cabinet on 15 July 2026. It is coordinating the design of legislated Australian AI Standards, which the government expects to legislate in early 2027.

Read the scope carefully. The standards announced so far cover mandatory requirements for large AI data centres, including energy and water, and copyright protections for creators. They are not a general set of obligations on every organisation that uses AI, although some commentary has presented them that way.

Ministers also set out five AI safety priorities in July 2026: a digital duty of care for AI companies, a second tranche of privacy reform, workplace AI safety, consumer law options for issues such as surveillance pricing and agentic commerce, and a framework for automated decision-making in federal agencies. These are signals of direction, not yet obligations.

What must our privacy policy say about automated decisions by 10 December 2026?

This is the hard deadline. From 10 December 2026, organisations covered by the Australian Privacy Principles that use personal information in automated decision-making that could significantly affect an individual's rights or interests must say so in their privacy policy. The policy must describe the kinds of personal information used and the kinds of decisions made.

The obligation comes from the Privacy and Other Legislation Amendment Act 2024. It covers any computer program that makes, or substantially and directly contributes to, such decisions, not only AI. It is a disclosure duty in the privacy policy, not a right to an individual explanation.

The OAIC consulted on guidance between May and June 2026. Check whether final guidance has been published before you finalise your wording.

The most efficient way to meet this is to drive the disclosure from the same AI register the Guidance for AI Adoption recommends. If you know which systems make or shape decisions and what data they use, the privacy policy wording follows.

What do APRA and ASIC expect from financial firms using AI?

APRA wrote to industry on 30 April 2026 calling for a step-change in AI risk management and governance. Its concerns were governance lagging adoption, limited AI literacy on boards, concentration on single providers, AI embedded in vendor platforms without visibility, and fragmented assurance.

APRA said it is not proposing additional requirements at this stage. It expects regulated entities to meet existing prudential standards on information security, operational risk, governance and data risk as they apply to AI. That is not a lighter expectation. It means an APRA supervisor can test your AI use against CPS 234 and CPS 230 today.

ASIC's report REP 798, Beware the gap, published in October 2024, reviewed 624 AI use cases across 23 licensees, found governance lagging adoption, and set out eleven questions licensees should be able to answer.

What must Commonwealth agencies do?

Version 2.0 of the policy for the responsible use of AI in government took effect on 15 December 2025. It is mandatory for non-corporate Commonwealth entities and encouraged for corporate entities, with national security carve-outs. AI impact assessments for in-scope use cases are required by 15 December 2026.

It does not bind private businesses directly, but suppliers to government feel it through procurement requirements and agency questions.

Does New Zealand regulate AI?

Not through an AI Act. New Zealand released its first AI Strategy and the Responsible AI Guidance for Businesses on 8 July 2025. MBIE describes the guidance as practical and voluntary, and Cabinet agreed a light-touch, proportionate and risk-based approach that uses existing mechanisms in preference to a standalone AI Act, aligned with the OECD AI Principles.

The Public Service AI Framework for government agencies sets five principles and six pillars, and states that it is not binding.

What is binding for AI in New Zealand?

The Privacy Act 2020 applies to any AI that processes personal information, and the Biometric Processing Privacy Code 2025 is binding under it. The code has applied to new biometric processing since 3 November 2025, and to biometric processing that was already in place from 3 August 2026.

If you use facial recognition, voice identification or similar tools in New Zealand, this code is the most concrete AI-related obligation you have.

Where does ISO/IEC 42001 fit?

No Australian or New Zealand law requires ISO/IEC 42001. What it provides is the management system that makes the voluntary guidance operational: policy, roles, risk and impact assessment, monitoring and continual improvement, all auditable.

The mapping is direct. The AI register template becomes your AI system inventory. The screening tool becomes your risk and impact assessment. The privacy policy disclosure for automated decisions draws on the same register. And for APRA-regulated entities, a 42001 management system is a credible way to show that existing prudential standards are being applied to AI deliberately rather than by accident.

How GRCLens supports AI governance

GRCLens implements ISO/IEC 42001 alongside ISO/IEC 27001 and the Australian and New Zealand frameworks on one control model, with an AI system register that feeds impact assessments and disclosure records. Its own AI features run on a model hosted inside the customer's infrastructure, with no third-party model API, which is a practical answer to the question APRA raised about AI embedded in vendor platforms.

Primary sources

Department of Industry, Science and Resources: National AI Plan (December 2025), Guidance for AI Adoption (October 2025), Voluntary AI Safety Standard (September 2024). Department of the Prime Minister and Cabinet: Office of AI. OAIC: consultation on transparency in automated decision-making (2026). APRA letter to industry on AI (30 April 2026). ASIC REP 798. Digital Transformation Agency: policy for the responsible use of AI in government, version 2.0. MBIE: New Zealand AI Strategy and Responsible AI Guidance for Businesses (July 2025). Office of the Privacy Commissioner: Biometric Processing Privacy Code 2025.

This article is general information, not legal advice.

This article is general information, not legal advice. Regulations change, so confirm current requirements with the relevant regulator before relying on them. Questions?info@grclens.net.

← All articles