For most Australian executives, AI arrived in the business without an invitation. A staff member started using ChatGPT to draft client correspondence. The marketing team trialled an AI tool to summarise meetings. The finance function quietly integrated an AI assistant into the accounting platform. None of it required board approval. None of it triggered a risk review. And almost none of it has been formally registered, governed or audited.
That is the problem regulators are now responding to. And while Australia is not following the European Union’s heavy-handed path, the rules that apply to your business are tightening — and the next twelve months matter.
Australia’s Approach: No AI Act, But Plenty of Obligations
Australia has chosen, at least for now, not to introduce a standalone AI Act. The National AI Plan released in December 2025 confirms that AI will continue to be governed through the laws we already have: the Privacy Act, the Australian Consumer Law, anti-discrimination law, workplace law, and the obligations imposed by sector regulators such as ASIC, APRA, the OAIC, AHPRA and the Therapeutic Goods Administration.
This sounds permissive. It is not. It means every existing legal obligation your business already has now applies to whatever your AI tools are doing on your behalf — silently, invisibly and at scale. The regulator’s view is straightforward: if a person would have had to comply with a rule, an AI doing the same task does not get a free pass.
To help organisations meet that responsibility, on 21 October 2025 the National AI Centre released the Guidance for AI Adoption, which sets out six essential practices known as the AI6. The six practices cover accountability, understanding impacts, managing risk, transparency, testing and monitoring, and maintaining human oversight. The guidance is voluntary, but it is now the federal government’s clearest statement of what “responsible AI” looks like in an Australian business. Regulators, insurers, auditors and your larger clients are already using it as the benchmark.
The December 2026 Deadline
The most concrete change for boards is the amendment to the Privacy Act 1988, which takes effect on 10 December 2026. From that date, organisations covered by the Act will be required to explain in their privacy policies how computer programs — including AI — are used to make decisions that significantly affect individuals. This covers both the kinds of decisions involved and the categories of personal information used to make them.
In plain terms: if your business uses an AI tool to help decide who gets a loan, who is shortlisted for a tenancy, who is offered a particular legal or medical service, or whose insurance application is accepted, you will be required to disclose that — clearly and proactively.
Penalties for serious or repeated breaches of the Privacy Act are now substantial. They can range between $66,000 to $50 million. The Office of the Australian Information Commissioner is publishing supporting guidance progressively through 2026, but the deadline itself is fixed.
Why This Matters More in Compliance-Heavy Industries
If your business operates in medical, legal, finance, fintech or real estate, the stakes are higher, and the runway is shorter.
These are sectors where personal information is sensitive, where decisions affecting clients carry real-world consequences, and where the regulators are actively watching. An AI tool that quietly drafts file notes, screens applications, summarises medical records, or scores investment risk is now a governance matter, not merely a productivity one. Boards in these industries should expect direct questions from auditors, professional indemnity insurers and clients about how AI is being used, where the data flows, and who is responsible when something goes wrong.
It is also worth noting what the federal government has not done. In late 2025, the Attorney-General confirmed there would be no broad text-and-data-mining exception under copyright law for AI training. That means Australian organisations using AI tools that learn from documents, contracts, case files, or client records cannot assume those uses are protected. The legal exposure cuts both ways — privacy on one side, intellectual property on the other.
What Good Governance Actually Looks Like
You do not need to become an AI expert. You do need to be able to answer a few questions clearly. What AI is being used in your business, by whom, and for what purpose? Where is the data going, and is any client or personal information leaving your controlled environment? Who is accountable when an AI-assisted decision goes wrong? And how would you evidence to a regulator, an insurer or a client that you are using AI responsibly?
In practice, this means doing four things over the next year. The first is maintaining an AI register — every AI tool, paid or free, sanctioned or shadow, recorded with its purpose, its data flows and its accountable owner. The second is updating privacy policies and client communications well before December 2026, not the week before. The third is bringing AI under your existing risk and governance frameworks rather than treating it as a separate, exotic problem. The fourth is ensuring someone at the executive level is genuinely accountable for AI; for most mid-market businesses, this is best served by a Virtual/Fractional CIO or Virtual/Fractional CISO who can work alongside the board without the cost of a full-time hire.
These are not radical steps. They are the same disciplines that good organisations already apply to cybersecurity, financial controls and data protection — extended to a new category of tool that, until very recently, no one was watching.
The Window Is Now
The next twelve months are a window. Australia has not legislated a heavy-handed AI regime and may not need to if business takes the existing rules seriously. The boards that act now — by mapping their AI use, tightening their data controls, updating their policies, and bringing AI into their existing risk discipline — will be the ones that avoid both regulatory and reputational fallout.
The boards that wait will find themselves explaining to a regulator, a client or an insurer why they did not.
Good governance has never been complicated to describe, even when it is hard to do. It means knowing what is happening inside your business, being able to evidence it, and being safe, secure and compliant so you can sleep at night.
How to approach rolling out AI
I’ve seen this more times than I can count, a business wants to roll out AI to all its staff, but they communicate it all wrong, firstly, an AI Acceptable Use Policy dictating exactly what is permitted must be created and circulated.
Next, instead of doing what I’ve witnessed so many times, don’t tell/demand of your staff to learn the AI tool the business goes with and force it on them with the threat of them losing their job if they don’t adapt and increase work output. People don’t like being dictated to; they generally will rebel or worse.
Try a softer, more human approach. Set up a department or an entire company meeting, and carefully and calmly explain which tool has been selected, why, and what the company’s vision/expectations for AI are, framing it as upskilling your staff instead. That they’ll be much better at their jobs with the use of AI, and have a firm like Forefront IT run workshops to train your staff properly on how to really get the most out of AI.
If any of the above resonates with you, contact us and let’s chat.
