AI Policy & Acceptable Use
Board-endorsed policy covering acceptable use, tiered approval pathways, and prohibited-use schedules.
Four regulatory deadlines converge in 2026 (the Privacy Act, the EU AI Act, APRA CPS 230, and the Australian Consumer Law). Organisations deploying AI without governance documentation, updated vendor contracts, and human oversight protocols are exposed to enforcement under laws already in force. We help you identify the gaps and close them.
Most organisations now use AI in their operations. Far fewer have governance that would survive scrutiny from a regulator or a court. The distance between what you deploy and what you can account for is where enforcement is concentrated.
Our research indicates that only a fraction of organisations deploying AI have functioning governance in place. Unmanaged 'Shadow' AI is already a source of enterprise-level data breaches, disproportionately exposing personal information and intellectual property.
An organisation that cannot produce an inventory of its AI systems is in a difficult position if a regulator asks for one. The gap between what is deployed and what is documented is where accountability obligations attach.
The OAIC's determination against Bunnings over its facial-recognition deployment. The Federal Court's finding in ASIC v Bekier that AI cannot displace independent director judgment. Doubled ACL maximum penalties of $100 million per contravention.
There is no standalone Australian AI Act, and waiting for one is not a strategy; enforcement is already running through the Privacy Act, the Corporations Act, the ACL, and APRA standards that your organisation answers to.
The six areas reflect where AI governance actually sits in an organisation: in policy and risk management, in vendor relationships, in employment law, and in how a board exercises oversight. Engagements are scoped to the AI your organisation deploys and the regulatory obligations those deployments create; most draw from several areas rather than treating each as a standalone project.
Board-endorsed policy covering acceptable use, tiered approval pathways, and prohibited-use schedules.
Every AI system mapped to intended use, data inputs, and risk tier.
Privacy and algorithmic impact assessments for high-risk applications and deployments.
Model-change notices, audit rights, data exit, and training restrictions negotiated upstream.
Screening reviews, anti-discrimination overlays, and oversight protocols for AI-assisted HR.
Board accountability structures and governance documentation built to withstand scrutiny.
Australia does not have a standalone AI Act. That does not mean AI is unregulated. The Privacy Act, the Corporations Act, the Australian Consumer Law, and APRA's prudential standards all impose obligations on organisations deploying AI, and all are already in force. What applies to your organisation depends on who you are and what you deploy.
APP 1.7, commencing 10 December 2026, requires APP entities that use personal information in automated or semi-automated decisions with a significant effect on individual rights to disclose data input categories and decision types in their privacy policy. The trigger is the significance of the effect; rule-based logic and GenAI both qualify. OAIC infringement penalties reach $330,000 per contravention. OAIC v Bunnings confirmed that technical complexity does not displace privacy obligations where personal data is operationally processed.
Maximum ACL penalties doubled to $100 million per contravention from 28 March 2026. AI-washing (unsubstantiated claims about capability, accuracy or safety) constitutes misleading conduct under ss 18 and 29 of the Australian Consumer Law. The ACCC's 2026–27 enforcement priorities name AI-washing, algorithmic pricing and dark patterns as focal areas. Prior enforcement on algorithmic misrepresentation is already on record.
In ASIC v Bekier [2026] FCA 196, Lee J confirmed that AI can assist discharge of the duty of care under s 180(1) of the Corporations Act 2001 (Cth) but cannot replace independent human judgment. The Court required evidence of transparent collective board governance over AI use in decision materials. Directors unable to demonstrate oversight of material AI-driven decisions are exposed on the existing statutory duty.
Prudential Standard CPS 230 took effect 1 July 2025; material service-provider provisions — documented exit strategies, audit rights, ongoing performance oversight — become fully operational 1 July 2026. APRA has taken the position that AI vendors embedded in critical financial-services operations meet the material service-provider threshold where their failure would materially disrupt regulated operations. LLMs in customer communications, algorithmic credit systems and model-driven risk tools all sit within the CPS 230 perimeter. APRA has signalled direct supervisory engagement with AI suppliers, making vendor due diligence no longer solely a contractual matter.
No AI-specific employment statute exists, but the Fair Work Act 2009 (Cth), the Disability Discrimination Act 1992 (Cth) and state anti-discrimination frameworks apply to algorithmic decisions affecting workers and applicants. Vicarious liability for biased screening outcomes attaches to effect, not intent. In the landmark US case of Mobley v Workday, the court certified a collective action against the operator of an AI screening system on the basis that the operator relationship gave rise to liability independent of the end-user employer. Human oversight of AI screening and performance tools is fast becoming an objective standard for responsible deployment.
High-risk obligations under Regulation (EU) 2024/1689 apply from 2 August 2026. The Act follows GDPR's extraterritorial model: Australian providers and deployers placing systems on the EU market, or whose outputs are used within the EU, are in scope regardless of where the system is developed or hosted. High-risk classifications cover employment screening, credit decisioning, education, biometric identification and law enforcement-adjacent uses. Penalties reach EUR 35 million or 7% of global annual turnover, whichever is higher. EU procurement processes are already testing conformity requirements; Australian vendors supplying EU public-sector clients are being assessed against the Act whether or not they have taken steps to comply.
AI governance only works if your team actually uses it. We build systems designed for ongoing operation: an inventory, a policy, monitored contracts, and a reporting cadence.
Identify what each AI system does, what data it processes, who is affected, and which regulatory regime applies. The inventory is the foundation — you cannot govern what you have not mapped.
Each system is scored against the Voluntary AI Safety Standard guardrails and EU AI Act risk tiers. High-risk and prohibited-use cases are identified and separated from lower-risk productivity tooling.
Draft the AI policy tiered for employee productivity tools, customer-facing systems, and high-risk applications. Impact assessments — PIAs and algorithmic assessments — are produced in working, auditable form alongside board governance documentation.
Identify AI vendor agreements that lack model-change notices, audit rights, or data exit provisions. Gaps are prioritised by risk exposure and contract term, and negotiating positions are prepared for each.
Standing board reporting, a quarterly review cadence, and incident response integration with your NDB programme. Governance that runs; not a document that sits in a drawer.
The questions we field at the first call. If yours isn't here, ask us.
An AI policy is one document. Governance is a system: an inventory that maps AI to its risk, impact assessments for high-risk applications, oversight protocols, vendor contracts that include audit rights, and a monitoring cadence. Most organisations have the policy; few have the system. Complying with the automated decision-making obligations, CPS 230, and the EU AI Act each requires more than a documented policy; they require a working system.
APP 1.7 applies to entities using personal information in automated or semi-automated decisions that have a significant effect on an individual's rights, opportunities, or interests. The definition captures rule-based logic as well as machine-learning systems. Significant effect is not limited to adverse outcomes; credit approvals, employment recommendations, and content-access decisions are all within scope. The obligation is to disclose the types of data used and the categories of decisions made, in your privacy policy. Commencement: 10 December 2026.
It does if your company places an AI system on the EU market, uses an AI system whose outputs are used in the EU, or has EU customers who are affected by an AI system's decisions. The high-risk obligations (employment screening, credit, education, biometric categorisation) applied from 2 August 2026. The extraterritorial scope mirrors the GDPR model.
The GDPR comparison is instructive. The GDPR technically applied to very few Australian companies; only those with an EU establishment or that systematically target EU residents fell within scope. Despite that, GDPR concepts were proactively imported into Australian practice: the Privacy Act was subsequently reformed with GDPR principles in mind, and GDPR-aligned documentation became a benchmark that clients, auditors, and procurement processes reached for. The EU AI Act is following the same path. Whether or not your organisation has EU exposure, its framework (risk tiering, algorithmic impact assessments, human oversight requirements, conformity documentation) is already the reference standard that Australian regulators and large procurers are adopting. Building to that standard now makes sense regardless.
An initial AI governance engagement (inventory, risk classification, AI policy, and priority impact assessments) typically runs three to six weeks. Vendor contract uplift is scoped separately; timing depends on which agreements need renegotiation and how cooperative the suppliers are.
Most SaaS AI vendor agreements (Copilot, Workday, Salesforce Einstein, and their equivalents) are silent on model change, training data usage, data exit, and audit rights. Uplift involves reviewing what your current agreement actually permits the vendor to do with your data, identifying which gaps create material risk under CPS 230 or the Privacy Act, and negotiating the key provisions: model-change notice periods, prohibition on training on your data without consent, portability and exit provisions, audit rights, and indemnity scope for AI-generated outputs.
Tell us where your organisation is in its AI rollout and the governance gaps you are aware of. We will come back with a practical assessment of what needs attention first .
We map the AI systems you are running and the regulatory exposure those systems create. Typically one call followed by a short written summary.
We can deliver a fixed-fee/scope engagement delivering the inventory, policy, impact assessments, and vendor contract review your organisation needs.
Online Statement of Work once we've agreed to help. Quick summary of the work and the estimate. Don't sign anything until you've seen ours.