Jurisdiction
Australia
- Source
- Editorial review of primary sources — not yet re-anchored
- Verified
- Evidence not verified
- Confidence
- Low
Structured issue-spotting to support your own review — not legal advice. Verify against the cited primary sources and your counsel.
01Framework
Australia has no AI statute and, after consulting on mandatory guardrails in 2024, decided not to proceed with them. AI deployment is governed by the Privacy Act 1988 and its thirteen Australian Privacy Principles, by OAIC guidance written specifically for buying and for training AI, and by sectoral supervision that in practice bites harder than privacy law — APRA’s CPS 230 and CPS 234 for financial institutions, ASIC for licensees, the TGA for clinical software, and eSafety codes for services that generate content. Two timing facts matter: the automated decision-making transparency duty is not yet in force, and APP 8 still has no prescribed countries.
- Region
- Oceania
- ISO code
- AU
- Privacy framework
- Privacy Act 1988, through the thirteen Australian Privacy Principles. They govern open handling, anonymity, collection, notification, use and disclosure, direct marketing, cross-border disclosure, government identifiers, quality, security, access and correction, and they apply to an AI pipeline the same way they apply to a filing cabinet. The Privacy and Other Legislation Amendment Act 2024 added a statutory tort for serious invasion of privacy, doxxing offences, a Children’s Online Privacy Code still in development, a mechanism to prescribe countries with substantially similar laws that has never been used, and an automated decision-making transparency duty that commences twenty-four months after Royal Assent — that is, in December 2026. The OAIC has published two AI-specific guidance documents, one for organisations buying commercially available AI products and one for developing and training generative AI models.
- AI-specific rules
- No AI statute, and no mandatory guardrails: the 2024 consultation on mandatory guardrails for high-risk AI was not proceeded with, and the feedback fed the National AI Plan published in December 2025 instead. What remains is the Voluntary AI Safety Standard, guidance for AI adoption from the National AI Centre, and sectoral supervision. APRA published a letter to industry in April 2026 calling for a step-change in how regulated entities manage AI risk, on top of CPS 230 and CPS 234. ASIC published REP 798 on the gap between AI deployment and governance, and an open letter in 2026 on AI-accelerated cyber threats. The eSafety Commissioner has registered an industry code with obligations aimed specifically at high-impact generative AI services, effective March 2026, including age assurance before generation.
- Last reviewed
- 20 Aug 2026
- Status
- published
Cross-border transfer
APP 8 governs disclosure of personal information overseas, and the default is accountability rather than permission: the discloser stays liable for what the overseas recipient does with the information, unless an APP 8.2 exception applies. The Privacy and Other Legislation Amendment Act 2024 created a mechanism to prescribe countries with substantially similar laws or binding schemes, and the OAIC states plainly that it does not have such a list. So there is no adequacy shortcut and no whitelist to point at — every offshore inference hop runs through APP 8.1 accountability or through a specific exception. Practically, that makes the vendor contract and the security assessment the work, and it makes the vendor’s own subprocessors part of the question rather than someone else’s problem.
Regulators
Primary sources
- LegislationPrivacy Act 1988 — Federal Register of Legislation
- LegislationPrivacy and Other Legislation Amendment Act 2024 (No. 128, 2024)
- Regulator guidanceOAIC — Sending personal information overseas
- Regulator guidanceOAIC — Guidance on privacy and the use of commercially available AI products
- Regulator guidanceOAIC — Guidance on privacy and developing and training generative AI models
- Regulator pageOAIC — Children’s Online Privacy Code
- LegislationOnline Safety Act 2021 — Federal Register of Legislation
- StandardAPRA — Prudential Standard CPS 234 Information Security
- StandardAPRA — Operational risk management (CPS 230)
- Regulator guidanceAPRA — Letter to industry on artificial intelligence
- Regulator guidanceASIC — REP 798 Beware the gap: Governance arrangements in the face of AI innovation
- Regulator pageASIC — 26-092MR ASIC calls for urgent cyber uplift as AI accelerates cyber threats
02Regulations and guidance
| Instrument | Status |
|---|---|
| APRA AI LetterAPRA’s summary of common weaknesses and expectations for regulated entities using AI. It calls for a step-change, warning that governance, risk management, assurance and operational resilience practices are not keeping pace with adoption. | In force |
| ASIC 26-092MRAn open letter from an ASIC Commissioner, intended to be tabled at boards, calling for urgent cyber uplift as AI accelerates cyber threats. It reframes AI adoption as a security question for directors rather than a technology question for the project team. | In force |
| APP 8APP 8 sets what an APP entity must do before disclosing personal information overseas. The accountability approach is the default: the discloser remains liable for what the overseas recipient does, unless an APP 8.2 exception applies. There is no list of acceptable destinations. | In force |
| COP CodeA code the Information Commissioner is developing under the 2024 amendment Act, setting how the Australian Privacy Principles apply to services likely to be accessed by children. Still in development, so it is a design constraint on a product being built now rather than a live duty. | Proposed |
| OAIC GenAI training guidanceThe OAIC’s guidance for organisations that develop or fine-tune generative AI. It directs developers to Australian Privacy Principles 1, 3, 5, 6 and 10 in particular, covering open handling, collection, notification, use and disclosure, and the quality of the personal information used. | In force |
| OAIC AI products guidanceThe OAIC’s guidance for organisations buying rather than building AI. It expects due diligence on whether the product suits the intended use, how human oversight is embedded, what the privacy and security risks are, and who can reach the personal information going in and coming out. | In force |
| Online Safety ActThe statute behind Australia’s industry codes and standards for online services, administered by the eSafety Commissioner. Codes registered under it now carry obligations aimed specifically at services capable of generating restricted material, which is how generative AI is regulated here. | In force |
| Privacy ActAustralia’s general privacy statute. The thirteen Australian Privacy Principles govern collection, use, disclosure, quality, security, access and correction for APP entities, and they apply to an AI pipeline the same way they apply to any other handling of personal information. | In force |
| POLA Act 2024The 2024 amendment package: a statutory tort for serious invasion of privacy, doxxing offences, a Children’s Online Privacy Code, a mechanism to prescribe countries with substantially similar laws, and an automated decision-making transparency duty that commences twenty-four months after assent. | Partly in force |
| CPS 230APRA’s operational risk standard, covering critical operations, service provider management and business continuity. A model vendor in a critical operation is a material service provider under it, which brings tolerances, testing and notification duties with it. | In force |
| CPS 234APRA’s information security standard for regulated entities, supported by practice guide CPG 234. It has not been amended for AI, and APRA’s position is that the existing framework already reaches AI use by banks, insurers and superannuation funds. | In force |
| ASIC REP 798ASIC’s review of how licensees use AI, identify and mitigate consumer risks, and govern the whole thing. Its finding is the title: governance lags deployment, and the gap is what ASIC intends to act on. | In force |
03Common enterprise issues
Cross-border transfers
There is no whitelist, so you stay accountable for the overseas recipient
Teams often look for the country list before choosing a model provider. There is not one. APP 8.1 keeps the discloser accountable for the recipient’s acts and practices, which means contractual terms and a real assessment of the receiving environment rather than a jurisdiction lookup.
Automated decision-making
The ADM transparency duty is coming, and privacy policies are slow to change
The automated decision-making transparency duty commences twenty-four months after the 2024 Act’s Royal Assent. It is not in force today, which is exactly why it gets forgotten: by the time it applies, the system will already be making the decisions the policy has to describe.
Sector rules
For a regulated financial institution, APRA binds before privacy does
CPS 230 makes a model vendor in a critical operation a material service provider, with tolerances, testing and notification attached, and CPS 234 already covers its information security. APRA’s 2026 letter says governance is not keeping pace. This is usually the constraint that decides the architecture.
Model training
Training on data you already hold is a fresh collection question
The OAIC’s generative AI guidance directs developers to APPs 1, 3, 5, 6 and 10. Re-using customer records to fine-tune a model is a use for a new purpose, and the notice given at collection almost never covers it.
Acceptable-use restrictions
A service that can generate restricted material is inside the online safety codes
The registered industry code for designated internet services reaches services that use machine learning to let an end user produce material, with obligations including age assurance before generation and regular review and testing of models. Most teams building a generative feature have never read it.
04Vendor restrictions
Restrictions we have written down and the page each one must be checked against. A restriction becomes a verified claim only once the sync job has fetched that page and found the phrase it declares; until then it is an editorial note with a link, and says so.
No vendor restriction has been recorded for this jurisdiction.
05Stacks with notes for this jurisdiction
No published stack carries a compliance note for this jurisdiction yet.
06Evidence
Every instrument above that we have fetched and anchored carries a footnote. The rest link to their primary source but have not been fetched and hashed yet, and are marked ASSESSMENT rather than FACT.
No sources were recorded for this answer. Nothing on this page should be treated as verified.
Improve this page
Sign in to contribute
From the field
0 deployments · 0 questions
Nobody has reported deploying this here yet, and no question has been opened against this page. Both appear once a reviewer accepts them.