Australia AI Ethics Framework
Australia’s eight AI Ethics Principles are voluntary. Existing laws, upcoming automated-decision privacy notices and separately proposed AI infrastructure standards have different scopes and legal status.
- Australia
- Framework
- Advisory
- Voluntary principles published: 2019-11
AU-AI-ETHICS-2019-POLICY-CONTEXT-2026Source checked: Resources ↗
Overview
The Australian Government published eight voluntary AI Ethics Principles in November 2019. They guide responsible design, development and use of AI; they are not a law that commenced in September 2024. Keep this voluntary framework distinct from applicable legislation and later policy proposals.
The eight voluntary AI Ethics Principles are: (1) Human, societal, and environmental wellbeing; (2) Human-centred values; (3) Fairness; (4) Privacy protection and security; (5) Reliability and safety; (6) Transparency and explainability; (7) Contestability; and (8) Accountability.
The government’s interim response to the Safe and Responsible AI consultation was announced on 17 January 2024. A separate high-risk mandatory-guardrails proposals paper opened on 5 September 2024. The official consultation now states that the government will not proceed at this time with those previous proposals. They must not be presented as enacted or inevitably incoming requirements.
The December 2025 National AI Plan builds on existing legal frameworks. Separately, the government announced Australian AI infrastructure and training standards in July 2026; the August National Cabinet statement described legislation intended for early 2027. These are distinct proposals, including large data-centre requirements, not a revival of the former high-risk guardrails or an already enacted general AI law.
From 10 December 2026, APP entities using personal information in qualifying automated decision-making must include specified information in their privacy policies under APP 1.7–1.9. The obligations concern the kinds of personal information and decisions involved. They do not by themselves create a general individual right to an explanation or human review. Assess the statutory significance threshold, entity coverage and any other applicable duties.
The Australian Human Rights Commission has also been active in the AI governance space, publishing a report on human rights and technology that recommended specific protections against AI-related discrimination and bias. The Commission's work has influenced the development of the broader governance framework.
Financial-services and healthcare organisations should assess the ASIC, APRA or TGA instruments applicable to their activities, along with other existing laws. Those sector-specific obligations are not created by the voluntary AI Ethics Principles. Determine the relevant entity, product and use-case scope with the accountable compliance owner.
The Office of the Australian Information Commissioner (OAIC) has provided guidance on the intersection of AI and privacy law, emphasising that existing privacy obligations apply to AI systems processing personal information and that organisations should adopt privacy by design approaches for AI development.
For an AI evaluation, separate three questions: which existing laws apply, which voluntary governance practices you choose to adopt, and which proposed or future obligations need monitoring. The Privacy Act does not automatically cover every Australian organisation or every AI interaction; assess APP-entity coverage and relevant exceptions. A security product or completed checklist does not establish legal compliance.
Review points
Use the eight AI Ethics Principles as voluntary governance guidance.
Assess whether Privacy Act and APP obligations apply to the entity and AI processing.
Ensure AI systems do not breach anti-discrimination legislation
Comply with Australian Consumer Law for AI-driven products and services
Track the separately proposed AI infrastructure and training standards without treating them as enacted high-risk guardrails.
Implement human oversight for high-risk automated decision-making
Provide transparency about AI use in consumer-facing applications
Ensure AI systems in financial services meet ASIC and APRA expectations
Maintain records of AI system development and deployment decisions
Implement testing and validation for AI system safety and reliability
Key Dates & Timeline
Australia publishes eight voluntary AI Ethics Principles
Attorney-General publishes Privacy Act Review report
Safe and Responsible AI consultation launched
Interim response to Safe and Responsible AI consultation announced
Previous mandatory-guardrails proposal opened for consultation, not enacted
National AI Plan launched; previous mandatory-guardrails proposals are not proceeding at this time
Separate Australian AI infrastructure standards announced and Office of AI established
National Cabinet describes legislation intended for early 2027, not an enacted general AI law
Qualifying APP automated-decision privacy-policy transparency obligations commence
Who It Affects
- Organisations developing or deploying AI in Australia
- Australian Government agencies using AI in service delivery
- Financial services companies using AI (regulated by ASIC/APRA)
- Healthcare organisations deploying AI systems (regulated by TGA)
- International companies offering AI services to Australian consumers
- Organisations processing personal information of Australians using AI
Frequently Asked Questions
Are the Australian AI Ethics Principles mandatory?
No. The eight AI Ethics Principles are voluntary. The official consultation says the previous high-risk mandatory-guardrails proposals are not proceeding at this time. Existing laws and separately announced legislative proposals must be assessed on their own scope and status.
Does the Privacy Act apply to AI in Australia?
It can apply when a covered APP entity handles personal information using AI, subject to the Act’s scope and exceptions. From 10 December 2026, qualifying automated decision-making requires specified privacy-policy information. Those provisions do not themselves create a general right to explanation or human review.
How should Australian companies prepare for AI regulation?
Identify applicable existing law and sector rules, use voluntary principles to structure governance, assess the forthcoming APP privacy-policy requirements, and track the separate AI standards proposals. Record the entity and AI activity in scope; do not treat a policy template as a compliance determination.
Stay Ahead of AI Regulations
Receive AI regulatory updates to help prepare your next review.