Guidance for AI Adoption (National AI Centre)
The National AI Centre's six essential practices for adopting AI, published 21 October 2025 to replace the Voluntary AI Safety Standard. Voluntary, but the closest thing to an official Australian definition of reasonable AI governance.
- Status
- Voluntary · Australia (Commonwealth) · NAIC
- Applies to
- Any organisation developing or deploying AI. Voluntary. Written for businesses without a specialist team.
- Key date
- 21 October 2025: Guidance for AI Adoption published
- Primary source
- Official document →
- Last reviewed
- 28 September 2026
What it is
Voluntary guidance from the National AI Centre, published 21 October 2025, setting out six practices any organisation should follow when it adopts AI. It comes in two editions: Foundations, for organisations starting out or using lower-risk tools, and Implementation Practices, for those building or customising AI or deploying it in higher-risk settings, with a screening tool, a policy template and a register template. It replaced the Voluntary AI Safety Standard’s ten guardrails. It is not law, but the National AI Plan of December 2025 put it at the centre of the government’s approach: existing laws and regulators carry AI risk, supported by this guidance, with no standalone AI Act.
What it requires
Six practices. Decide who is accountable: name a senior owner for AI overall and a responsible person for each system and its supply chain. Understand impacts and plan accordingly: assess who could be affected and how, including bias and privacy harms, and give people a way to challenge automated outcomes. Measure and manage risks: treat AI as a business risk in your existing register, screen use cases, and scale controls to the risk. Share essential information: tell people when they are dealing with AI, keep a register of your AI systems, and explain what tools do and where they stop. Test and monitor: test for accuracy, security and bias before deployment, and keep monitoring rather than set and forget. Maintain human control: keep meaningful oversight, build in override points, and avoid over-reliance on high-stakes outputs.
Does this reach your business?
It is written for you if you use AI at all, and it scales: a two-person business using Copilot can follow Foundations in an afternoon; a business shipping an AI product uses the Implementation edition. Nothing in it is enforceable on its own. Its weight comes from elsewhere: when a regulator or a court asks whether a business took reasonable steps with AI, this is the published description of what reasonable looks like, and when a large customer asks how you govern AI, its six headings are the shape of the answer they expect.
What we recommend
Our advice is to use it as your checklist and nothing more elaborate. Work the six practices in order, because the first two carry the rest: name the owner, list the uses and who they affect. Then the register, then the disclosure line in your privacy policy and customer communications, then testing and a review rhythm. Keep the evidence as you go; the guidance is explicit that an AI register and documented decisions are the output. If you already hold a record of what AI you use, who owns it and what it touches, you are most of the way through Foundations.
Questions people ask
No. It is voluntary guidance from the National AI Centre. The government's December 2025 National AI Plan relies on it alongside existing law rather than a standalone AI Act.
This guidance, on 21 October 2025. The ten guardrails became six practices.
Foundations, unless you build or customise AI or use it where the consequences for people are high, in which case the Implementation Practices edition.
Decide who is accountable; understand impacts and plan accordingly; measure and manage risks; share essential information; test and monitor; maintain human control.