Mandatory guardrails for high-risk AI (proposals paper)
The September 2024 proposal for ten mandatory guardrails on high-risk AI, withdrawn by the National AI Plan in December 2025. Kept on record because tenders and policies written in 2024 and 2025 still cite it.
- Status
- Lapsed · Australia (Commonwealth) · DISR
- Applies to
- Nobody. Withdrawn. The voluntary Guidance for AI Adoption and existing law took its place.
- Key date
- 2 December 2025: Withdrawn: National AI Plan opts for existing law
- Primary source
- Official document →
- Last reviewed
- 28 September 2026
What it is
A government proposals paper released on 5 September 2024, consulted until 4 October 2024, that would have made ten guardrails mandatory for anyone developing or deploying AI in “high-risk settings”. The guardrails matched the ten in the Voluntary AI Safety Standard published the same day, with one change: the tenth required a conformity assessment to demonstrate the others had been met. The paper defined high-risk by the severity of potential harm to people’s rights, health, safety and legal position, offered three ways to legislate (amend existing laws, pass framework legislation, or a standalone AI Act with its own regulator) and justified the whole exercise with the line that the “current regulatory system is not fit for purpose to respond to the distinct risks that AI poses”. On 2 December 2025 the National AI Plan withdrew it: the government “will not proceed at this time with previous proposals to introduce mandatory guardrails for AI development and deployment”.
What it requires
Nothing, and it never did. Had it become law, a business deploying high-risk AI would have had to establish accountability and governance, run a risk management process, govern its data, test before deployment and monitor after, keep a person able to intervene, tell people when AI was involved, give them a way to contest outcomes, be transparent about its supply chain, keep records, and pass a conformity assessment. Nine of those ten survive, word for word in spirit, as the six practices of the Guidance for AI Adoption. The tenth, the certification, did not.
Does this reach your business?
No. It was never in force. Two things do reach you from its afterlife. First, contracts, tenders and internal policies drafted in late 2024 and 2025 sometimes reference “the mandatory guardrails” as if they were coming; those references need updating to the Guidance for AI Adoption. Second, the idea did not die, it moved: the July 2026 decision to legislate Australian Standards for AI is the government’s second attempt at mandatory rules, starting with data centres. Watch that entry, not this one.
What we recommend
Our advice is to treat this page as a footnote and act on its replacement. If a document you rely on cites the mandatory guardrails, swap the citation for the Guidance for AI Adoption; the substance is the same. If you built controls around the ten guardrails in 2024, keep them; they are the six practices with two extra headings. And keep half an eye on the Australian Standards for AI, where a mandatory layer is now being built for real.
Questions people ask
No. They were proposed in September 2024 and withdrawn on 2 December 2025 when the National AI Plan chose to rely on existing laws instead.
The voluntary Guidance for AI Adoption, which carries nine of the ten guardrails as six practices, and existing law applied to AI. Separately, the government decided in July 2026 to legislate Australian Standards for AI, starting with data centres.
Update the reference to the Guidance for AI Adoption. The obligations it described are the same ones, minus the conformity assessment.