Summary
The Australian Federal Government’s new National AI Centre is moving from voluntary guidance to a more prescriptive framework indicating that formal legislation may not be far off. Five areas are now directly in the sights of Parliament: duty of care, privacy, workplace safety, consumer protection, and automated decision making. Businesses that build governance now avoid an expensive scramble later.
What’s Changing in Australian AI Regulation
For two years, Australian businesses treated AI governance as optional. The Federal Government took a relatively ‘hands-off’ approach to AI regulation, the extent of regulation contained within the Voluntary AI Safety Standard1, with no penalty for skipping it. This has now changed.
In August 2026, the Department of Industry, Science and Resources signalled a shift toward a standards-led, enforceable framework2 for artificial intelligence. The NAIC has now published formal guidance on the following topics, including an “Essential Six”3:
- Duty of Care
- Privacy
- Workplace Safety
- Consumer Protection
- Automated Decision Making
The announcement follows a rapid build-up4 of legal cases5 involving AI misuse6. Yet the government is walking a careful line between regulation and growth.
Risk, compliance, and legal teams have first-hand knowledge of how quickly guidance is changing and how difficult it can be to form a defensible AI-use policy.
During Dell Tech Forum 2026, senior industry leaders spoke about their experiences in forming internal operating procedures in the absence of official guidance, finding that adopting a core set of ‘common sense’ principles based on recent EU AI Act has achieved the most success in satisfying the risk appetite of boardrooms.
While the absence of specific law may be an intentional move from Parliament (“legislating for every conceivable risk would only push investment offshore”7), there are steps Australian businesses can take to today to reduce the chance of ending up in a precedent-setting legal case.
The “Essential Six” You Need to Implement
Accountability
One or more people inside your business now must be held accountable for the actions of AI and agents. AI complexity can create gaps where no one takes clear responsibility for outcomes, especially as organisations move further toward autonomous agents. Without accountability, AI and agents are now able to materially affect business trade and reputation with no redress.
Committee Reporting by November 2026
A Joint Select Committee on Artificial Intelligence will report back by 30 November 2026. Its findings will shape the technical detail of the legislation, including risk classification thresholds and audit obligations.
Legislation Due Early 2027
Formal legislation covering all five standards is due in early 2027. For any organisation running production AI systems, that’s a tight runway to demonstrate compliant architecture, not just policy documents.
Where Australian Businesses Stand Today
We talk to organisations across every stage of AI maturity, and two clear cohorts have emerged.
Early-Stage Organisations (80%)
Around 80% of the organisations we speak with sit early in their AI journey. Most run off-the-shelf cowork platforms, isolated pilots, or point tools rather than a governed platform with centralised logging and access control.
If that sounds like your business, you’re actually well positioned. You can design a data and AI architecture from the ground up, guided by the National AI Centre’s foundation recommendations7, instead of retrofitting governance onto production systems already carrying technical debt.
Advanced Organisations (20%)
The remaining 20% are progressing a genuine data platform, fostering citizen developers, and experimenting with agentic architectures. If this describes you, this announcement should shape your AI governance charter directly, particularly around model monitoring and decision auditability. The NAIC also publishes implementation guidance8 for organisations operating at this level of complexity.
Why Data Strategy Now Outweighs Adoption
A few years ago, the advice was simple: adopt AI or risk being out competed. That’s still broadly true, but the conversation has matured considerably.
Simply licensing AI tools isn’t a strategy anymore. What separates outcomes is the quality and governance of the data feeding those models. Proprietary, well-labelled, access-controlled data is what turns a generic model into a genuine differentiator.
We’ve seen the consequence of skipping this step firsthand. 95% of organisations without an informed, achievable data strategy tell us their AI projects have produced no measurable results. That’s a data governance failure, not a model failure.
Most businesses now recognise that accurate, curated, well-governed data underpins every AI initiative worth deploying. Fewer have operationalised it.
Data Sovereignty is Now AI Sovereignty
Data sovereignty used to describe something fairly contained: keeping data within Australian borders, subject to Australian law. AI has stretched that definition well beyond storage location.
A model’s outputs now depend on more than where training data physically sits. AI sovereignty spans the full technical stack: where inferencing executes, which jurisdiction holds the encryption keys, who controls the model weights, and who owns the energy infrastructure powering the data centre.
In practice, AI sovereignty means your organisation can verify every layer beneath an AI system, from model to physical site, remains under domestic control. That includes resilience against disruption at the infrastructure layer, not just the application layer.
Government will legislate the national dimension of this. But organisational AI sovereignty is increasingly a procurement requirement. A year ago, around 9% of organisations we spoke with ranked a sovereign AI platform among their top priorities. Within six months, that figure jumped to 33%, concentrated in education, research, and healthcare, sectors with strict data classification requirements.
The Australian Signals Directorate’s Cyber Security Centre reinforces this expectation directly. It advises organisations to confirm that any AI system they use can meet their data residency and sovereignty obligations9.
How We Built Our Own AI Foundations First
We rebuilt our data foundations on Microsoft Fabric before bringing this thinking to clients. We structured information into governed bronze, silver, and gold layers, with lineage and access policy enforced before any dataset reached a model. That structure now underpins our business decisions and every customer interaction.
The lesson translated directly. Clean, curated, and centralised data isn’t a nice-to-have for AI success. It’s the architectural backbone the entire system depends on, and it’s auditable by design.
Two Technical Paths to Compliant AI
Extend Your Existing Microsoft Investment
If you’ve already invested in Microsoft, you can extend that investment with Copilot, or build data agents natively within Fabric using its existing governance and access controls. Either path builds on infrastructure you likely already licence.
Deploy a Sovereign Platform
If sovereignty is the priority, Launch AI is worth evaluating. It’s backed by the technology group trusted by 42% of Federal Government, and it delivers predictable pricing alongside enterprise-grade governance. It gives you control over data residency at rest and in transit, customer-managed encryption keys, and defined inferencing regions, built on ISO 27001 and PCI-DSS certified infrastructure.
Neither path requires starting from scratch. Both require starting now, while the runway before legislation remains generous.
Frequently asked questions
When does Australia’s AI legislation take effect?
Legislation covering duty of care, privacy, workplace safety, consumer protection, and automated decision making is due in early 2027, following a Joint Select Committee report by 30 November 2026.
What is the difference between data sovereignty and AI sovereignty?
Data sovereignty covers where data is stored and under which jurisdiction’s law it sits. AI sovereignty extends this to inferencing location, encryption key control, model ownership, and the underlying infrastructure’s energy and physical security.
What counts as automated decision making under the new framework?
It covers systems that make or materially influence decisions affecting individuals, such as credit assessments, employment screening, or insurance eligibility, without meaningful human review.
Do small and mid-sized businesses need to act now?
Yes. Building governance before legislation lands is significantly cheaper than remediation after an audit finding or an incident.
Talk to Us Before the Legislation Forces the Issue
Businesses that build governance in now can demonstrate compliance the moment legislation lands in 2027. Waiting means running an expensive remediation project against a hard deadline instead.
Acting early also lowers your risk today. Well-governed systems are far less likely to join the 95% of AI projects that never deliver measurable results.
So, ask yourself honestly: could your organisation stand behind a duty of care obligation right now? If the answer is uncertain, our team can assess your current posture and help you build a compliant foundation before the legislation forces the issue.
Get in touch to talk through what this change means for your business.
Sources
1Department of Industry, Science and Resources, “Voluntary AI Safety Standard.”
2Minister for Industry, Science and Resources, “AI consumer safety priorities,” August 2026.
3National AI Centre, “Guidance for AI adoption: implementation guidance | National AI Centre”
4ABC News, “William Yeates charged over deepfake image creation,” 25 February 2026.
5AWDR, “Fake AI case law sinks Fair Work unfair dismissal claim.”
6ABC News, “Deepfake images trial: Antonio Rotondo,” 25 August 2026.
6Prime Minister of Australia, “AI: Australia’s interests,” 15 July 2026.
8National AI Centre, “Guidance for AI adoption: foundations.”
9National AI Centre, “Guidance for AI adoption: implementation.”
10Australian Signals Directorate’s Cyber Security Centre (ACSC), “Engaging with artificial intelligence,” citing its guidance that organisations confirm AI systems meet data residency and sovereignty obligations.







