Australia
Australia AI Regulation
A lengthy public consultation on mandatory guardrails for high-risk AI, but no enacted comprehensive statute yet — existing privacy and consumer protection law is the current baseline.
Australia's federal government ran an extended public consultation on mandatory guardrails for high-risk AI systems, proposing a risk-tiered structure conceptually similar to the EU's approach. As of this writing, that consultation process has not converted into enacted legislation — Australia currently sits without a comprehensive AI-specific statute, relying on existing law applied to AI use cases.
What the proposed guardrails would cover
The consultation process outlined mandatory obligations that would apply specifically to systems deemed high-risk, including testing, transparency, human oversight, and record-keeping requirements — directionally similar to the EU AI Act's high-risk obligations, though the specific classification test and thresholds proposed differ in detail.
What currently applies in the absence of enacted legislation
- The Privacy Act 1988 — itself currently undergoing a significant reform process — governs personal information handling by AI systems, and reform proposals under discussion would likely tighten requirements specifically relevant to automated decision-making.
- The Australian Competition and Consumer Commission (ACCC) applies existing consumer protection law to AI-driven conduct, including misleading or deceptive practices involving AI-generated content or claims.
- Sector regulators (financial services, health) apply their existing frameworks to AI use cases within their remits, similar to the pattern seen in the UK and pre-AIDA Canada.
What to watch
Given the consultation is substantially complete, legislative movement is plausible within a shorter window than in jurisdictions still at an earlier policy stage — but "plausible" isn't "scheduled." We treat status changes here as genuine news, not an assumed timeline, and update this page directly when the picture changes.
Practical guidance in the meantime
Companies operating in Australia with AI exposure elsewhere (particularly EU or Colorado exposure) are generally well served by building to the stricter jurisdiction's standard rather than waiting for Australia-specific requirements to crystallize — the proposed Australian guardrails track closely enough with the EU's risk-tiered approach that EU-aligned compliance work is unlikely to require a rebuild if and when Australian legislation is enacted.
Sources & references
Suggested next reading
regulations uk
UK AI Regulation
regulations canada