"There's no Ai law in Australia" is true, and one of the more expensive things a board can believe. There is no Ai Act. There are obligations with dates already fixed, sitting inside laws you are subject to whether you have thought about Ai or not.
What the Commonwealth actually decided
The National AI Plan sets out an approach that regulates Ai through the law that already exists rather than through a new statute, with regulators keeping their own domains and adapting what they already enforce. The mandatory guardrails for high-risk settings proposed in 2024 are not taken up in it. Nor is the door shut: the Plan reserves the government's ability to intervene if broader harms warrant it.
What July's announcement was, and what it wasn't
On 15 July 2026 the Prime Minister announced that "Effective today, the Office of AI will be established within the Department of Prime Minister and Cabinet to accelerate implementation of the Australian Standards on a national level."
This is where commentary ran ahead of the source. On the announcement's own wording, the "Australian Standards for AI" are a framework for large data centres and Ai training: they would have to "underwrite their own new power supply, pay their full share of connection costs so energy bills are not impacted, reduce power when needed to strengthen the grid, and be as water efficient as possible". The release also promised copyright protections for Australian creators. Energy, water, grid and copyright. If your business buys or deploys Ai, that announcement creates no duty for you.
The approach was to be "considered by National Cabinet in August, with standards expected to be legislated early next year". As at 21 August 2026 the National Cabinet meeting outcomes register listed nothing later than 22 June 2026.
The date to put in the diary: 10 December 2026
The one real deadline comes from the Privacy Act, not from anything Ai-specific. Amendments made by the Privacy and Other Legislation Amendment Act 2024 insert new subclauses into Australian Privacy Principle 1, commencing on 10 December 2026. From that date an APP entity must add information to its privacy policy where it has arranged for a computer program to use personal information to make a decision that "could reasonably be expected to significantly affect the rights or interests of an individual".
That trigger decides whether any of this applies to you. Predictive maintenance, demand forecasting and visual quality inspection will not usually meet it. Screening job applicants, setting a price for a person, or deciding whether someone gets credit may.
What goes in the policy is set by APP 1.8: the kinds of personal information used in those programs, the kinds of decisions made solely by them, and the kinds of decisions where the program does something "substantially and directly related to making the decision". Read that last limb twice. A human at the end of the process does not automatically take you outside the obligation.
The OAIC consulted on transparency in automated decision-making from 18 May to 15 June 2026, and the guidance is still to come.
Whether you are covered at all is worth settling first. A small business operator with annual turnover of $3 million or less is generally outside the Privacy Act, but the OAIC says "Annual turnover for the purposes of the Privacy Act includes all income from all sources", and the carve-ins pull plenty of small operators back in: health service providers holding health information, businesses that trade in personal information, contracted service providers under a Commonwealth contract, accredited participants in the Consumer Data Right. The OAIC also counts private schools and tertiary institutions among health service providers, so "we're in education" is not an answer.
If you sell to government
The Digital Transformation Agency's Policy for the responsible use of AI in government binds Commonwealth agencies, not their suppliers, and its requirements have come in stages. Sell into a Commonwealth agency and you will meet it anyway, through their procurement and their questionnaires: it is the closest thing Australia has to a published benchmark of expected practice.
The law that already applies to what your Ai does
The Australian Consumer Law covers what your Ai tells a customer, and what you tell customers about your Ai. The ACCC's line has not changed because the technology did: "Any information or claim that a business provides about its products or services must be accurate, truthful and based on reasonable grounds."
The Privacy Act applies now, not from December. Collection, use, disclosure and security obligations are already live. December only adds transparency about automated decisions.
APRA's CPS 230 Operational Risk Management commenced on 1 July 2026. It is not an Ai standard. Ai lands inside it as operational risk and as service provider risk, and that is where an APRA-regulated entity has to manage it.
The TGA regulates medical devices on their intended purpose, not on the technology inside them.
Copyright is the honest gap: how the Copyright Act 1968 applies to training data is unsettled, and July's announcement promised protections rather than delivering them.
Reporting duties that are live right now
Neither is about Ai. Both bite when an Ai failure becomes a cyber incident or a ransom payment.
Part 2B of the Security of Critical Infrastructure Act 2018 requires the responsible entity for a critical infrastructure asset to notify the Australian Cyber Security Centre of a cyber security incident, on deadlines the Act counts in hours. There is no turnover test; the duty attaches to the asset.
The Cyber Security Act 2024 added ransomware payment reporting, with a turnover threshold and a short reporting window set out in the Home Affairs factsheet. That threshold is the same $3 million figure as the Privacy Act small business test and a legally separate one, so do not assume the two travel together.
Who enforces any of this
The Australian AI Safety Institute sits inside the Department of Industry, Science and Resources, testing models and supporting regulators on emerging risks. Enforcement itself stays where it already sits: the OAIC for privacy, the ACCC for consumer law, eSafety, the Fair Work Ombudsman, ASIC and the sector regulators.
So there is no single Ai regulator to satisfy and no single Ai audit to pass, only your existing regulator asking its existing questions about a system it has not seen before.
South Australia's Royal Commission
We are based in Adelaide, so this one is close to home.
The South Australian government announced in August 2026 that it will establish a Royal Commission into Artificial Intelligence, to begin later this year and report during 2027. The terms of reference are still to come. Nobody is being investigated: on the announcement's framing this is a policy inquiry, holding a Royal Commission's powers to gather evidence.
If you operate in South Australia, a submission is the cheapest way you will ever get to put your case to the people writing the next set of rules.
What to do before December
Find where personal information already meets an automated decision in your organisation, and whether any of those decisions could significantly affect a person. That mapping tells you whether 10 December 2026 is your problem or somebody else's.
Then write the register: what Ai is in use, who approved it, what data goes in, who reviews the output, and what happens when it gets something badly wrong. Every obligation here asks for a version of the same evidence.
Test the reporting path before you need it. Both cyber regimes run their clocks in hours, which is shorter than most incident response plans assume.
None of that is a policy document. It is a management system, which is how we got here from ISO 9001: that story is on our story page. The global picture sits in Whose Ai rules apply to you.