started · updated
Australia sets AI governance deadlines for businesses and government finance
From 10 December 2026 Australia will amend its Privacy Act to require organisations that use AI to make decisions affecting individuals to disclose that use in their privacy policies. Non‑compliance can attract civil penalties of up to $66,000 per offence and fines of up to $50 million or 30 % of annual turnover. The rules cover hiring, lending, insurance, customer access and service delivery. The Australian Information Commissioner has begun compliance sweeps of high‑risk sectors, and the AI Safety Institute has been operating with a $29.9 million budget. Experts warn that “Shadow AI”—unauthorised employee use of generative tools—now touches more than 70 % of staff and is implicated in a third of data‑security incidents, underscoring the need for firms to audit and map all AI tools.
Separately, the Department of Finance released guidance tying staff use of generative AI to the Protective Security Policy Framework, the Privacy Act 1988 and internal privacy rules. Public AI tools such as ChatGPT, Claude and Gemini may only handle unofficial, non‑sensitive data, while Microsoft 365 Copilot is restricted to a “work mode” deployment for sensitive information. Staff must complete a privacy impact assessment before using personal data with AI, and record‑keeping rules require disclosure when AI content significantly influences policy or operational decisions. An AI Governance Committee oversees these measures, limiting use to low‑risk cases.
Both initiatives aim to bring AI use under clear legal and ethical controls before the December deadline.