Australia's Voluntary AI Safety Standard set out 10 guardrails for using AI safely when it was published in September 2024. On 21 October 2025 the National AI Centre replaced it with simpler Guidance for AI Adoption, built on six essential practices. Both are voluntary.
What isn't voluntary is the law you already follow. For most mid-market businesses, that means the Privacy Act, including a new obligation to explain automated decisions from 10 December 2026. This guide explains what changed, what the six practices ask for and where to start.
This is general guidance, not legal advice. Check your own obligations with a qualified adviser.
What Happened to the Voluntary AI Safety Standard
The Voluntary AI Safety Standard was published by the National AI Centre on 5 September 2024. Its 10 guardrails covered accountability, risk management, data governance, testing, human oversight, transparency, contestability, supply chain, records and stakeholder engagement.
The standard's page now notes that the Guidance for AI Adoption "evolves" it into an updated and simplified framework. The 10 guardrails remain available as a more detailed reference. If your business already mapped its work to the guardrails, that work still counts. The six practices cover the same ground in fewer, plainer steps.
Many people still search for "the AI Safety Standard" when they mean the current guidance. Suppliers and clients may also ask whether you follow it. The honest answer in 2026 is that you follow the Guidance for AI Adoption, which replaced it.
Is AI Governance Mandatory in Australia?
Not as a standalone AI law. In 2024 the government consulted on mandatory guardrails for high-risk AI. The National AI Plan, published on 2 December 2025, took a different path. It builds on existing, largely technology-neutral laws, with each regulator responsible for AI harms in its own area.
The plan also sets up an AI Safety Institute to monitor, test and share information on AI capabilities and risks, and to advise regulators.
In practice, that means the laws that already apply to your business apply to your AI use as well. Privacy, consumer law, workplace law, anti-discrimination law and your sector's own rules all still hold. The six practices are the government's recommended way to meet them.
The Six Essential Practices
The Guidance for AI Adoption has two versions. The foundations guidance is for organisations starting out or using AI in low-risk ways. The implementation guidance is for those building or customising AI, or using it in higher-risk decisions. Most mid-market businesses should start with the foundations.
| Practice | What It Asks | Where a Mid-Market Business Starts |
|---|---|---|
| 1. Decide who is accountable | A named senior owner for AI, and an owner for each AI system | Name one executive owner and write a short AI policy |
| 2. Understand impacts and plan accordingly | Know who each AI use could affect and give people a way to raise concerns | List who is affected by each use, starting with staff and customers |
| 3. Measure and manage risks | Screen each use and apply controls in proportion to the risk | Run every new use through a short screening checklist |
| 4. Share essential information | Keep an AI register and tell people when AI is involved | Record every AI tool in use, including AI inside existing software |
| 5. Test and monitor | Test before use, monitor after, and ask suppliers for proof of testing | Agree what "working" means for each use before it goes live |
| 6. Maintain human control | Human oversight that matches the stakes, with points to pause or override | Name who reviews AI outputs and when a person must decide |
The National AI Centre publishes free templates for an AI policy, an AI register and risk screening questions. They're a sensible starting point and take hours to adapt, not weeks.
Why the Practices Matter More Than the Paperwork
The guidance makes a point worth repeating: the same tool can carry very different risks depending on how you use it. Drafting marketing emails with AI is not the same as using it to assess job applications. A register and a policy help, but the useful work is looking at each use in its workflow and deciding how much oversight it needs.
That's also where most governance problems start. Staff adopt tools on their own when the business hasn't given them approved ones. Our guide to shadow AI covers how to bring that use into the open.
The Privacy Obligations You Can't Skip
The Privacy Act generally applies to businesses with annual turnover above A$3 million, and to some smaller ones such as health service providers. That covers most mid-market businesses.
Personal information in AI tools. The OAIC's guidance on commercially available AI products says privacy obligations apply to both what you put into an AI system and what comes out of it. As a matter of best practice, it recommends not entering personal information, particularly sensitive information, into publicly available generative AI tools. Business versions with contractual data protections are a different decision, but they still need due diligence.
Automated decisions from 10 December 2026. From that date, your privacy policy must explain when you use a computer program, including AI, to make decisions that could significantly affect someone's rights or interests using their personal information. It must describe the kinds of personal information used and the kinds of decisions made. The obligation covers decisions made after that date, even if the information was collected earlier. The OAIC has consulted on guidance for this obligation.
Hiring, credit, pricing, eligibility and customer service triage are common places this shows up. If you use AI anywhere near those decisions, check your privacy policy now rather than in December.
Where ISO/IEC 42001 Fits
ISO/IEC 42001:2023 is the international standard for an AI management system. Unlike the Australian guidance, you can be certified against it. The Australian guidance is designed to align with international standards, so work done on the six practices carries across.
Certification makes sense when a client, regulator or tender requires it, or when AI is central to what you sell. For most mid-market businesses using AI in their own operations, the six practices are the proportionate place to start. You can ask your AI suppliers whether they hold ISO/IEC 42001 as part of your due diligence under practice 5.
If You Also Operate in New Zealand
New Zealand has no AI-specific law either. In July 2025 MBIE published Responsible AI Guidance for Businesses alongside the country's first AI strategy. It is voluntary and takes a proportionate, risk-based approach similar to Australia's.
The Privacy Act 2020 applies to AI use in New Zealand as it does to any other handling of personal information. The Biometric Processing Privacy Code has applied since 3 November 2025 and covers tools such as facial recognition. If you work across both countries, one set of practices can meet both, as long as your privacy review covers each country's law.
A 90-Day Starting Plan
For a business of 20 to 500 people, this is a realistic first quarter:
First month: ownership and visibility.
- Name an executive owner for AI.
- Adapt the AI policy template and tell staff which tools are approved.
- Start an AI register, including AI features inside software you already use.
Second month: risk and privacy.
- Screen each use on the register and flag any that affect customers, staff or decisions about people.
- Check your privacy policy against the automated decisions obligation.
- Confirm what your AI suppliers do with your data and how they test their products.
Third month: testing and control.
- For each higher-risk use, agree what good output looks like and who reviews it.
- Set the points where a person must decide, and how staff can pause or override the tool.
- Train the people who use and oversee each tool on its limits.
None of this needs a large programme. It needs an owner, a few hours from the people doing the work and a habit of reviewing new uses before they spread.
How ELab AI Helps
We build governance into the work rather than bolting it on afterwards. When we help a business adopt AI, the owner, register entry, review points and human control for each workflow are part of the design. Our AI enablement approach starts with people and process, then knowledge and data, then technology.
We work with mid-market businesses in New Zealand and Australia, mainly in general business and professional services, as well as industrial operators and investment managers. We're not a law firm. For legal obligations we work alongside your advisers.
Getting Started
If you're not sure where your business stands, take our AI Readiness Assessment. It covers people, process, knowledge and data, then technology, and shows where governance needs attention first.
If you'd like help putting the six practices into your AI work, tell us about your business. You can also read how we work with Australian businesses.

