The changelog

Key dates and what changed.

One timeline: the statutory dates that are coming, and dated notes on what changed and what it means for a business without a compliance team. Written by a person, every time.

  1. Key date
    Privacy Act reform: automated decision-making transparencyADM transparency obligation commences
  2. Key date
    Children’s Online Privacy CodeRegistration deadline
  3. Today
  4. Key date
    EU AI ActGeneral application date: most obligations apply
  5. EU

    Commission starts enforcing AI Act rules and new transparency requirements on 2 August

    The next phase of the EU AI Act takes effect, sharpening the duties of those building with and deploying AI tools

    What it means

    From 2 August the next phase of the EU AI Act takes effect, including transparency requirements and the rules the Commission can now enforce. This intensifies requirements on people and companies building AI systems and deploying them in the EU market.

    This is EU law, so it reaches you only if you sell into or operate in the EU. While most Australian businesses using everyday AI tools are outside its scope, if you have EU customers or operations, it’s worth checking where your AI use sits under the Act. Professional legal advise is recommended as the implications for non-compliance are severe.

    This appears to be the benchmark other AI governance regimes are moving toward.

    Applies to: Anyone building or deploying AI who sells into or operates in the EUPrimary source →
  6. OAICBinding

    Privacy Commissioner publishes updated guidance on facial recognition in retail spaces

    The OAIC published updated guidance on the use of facial recognition in retail spaces.

    What it means

    On 30 July 2026 the OAIC published updated guidance on the use of facial recognition in retail spaces. The updated guidance implements the findings of the Administrative Review Tribunal (ART) in the matter of Bunnings Group Limited (Bunnings), which concerned the retailer’s use of facial recognition technology in 62 of its stores for a period between 2018 and 2021.

    It sets out how the Privacy Act applies when a business captures and matches people’s faces

    The OAIC expects the use to be:

    • Genuinely necessary and proportionate
    • People to be given clear notice
    • And a privacy impact assessment to be done before it is switched on.

    This matters if you use facial recognition, in a store, a venue, or a security system. Most Everyday AI tools are not affected. If you do use facial recognition, this as the standard you will be measured against.

    Applies to: Businesses that use facial recognition, in a store, a venue, or a security system.Primary source →
  7. EUBinding

    Guidelines on transparency obligations for providers and deployers of AI systems

    The European Commission published guidelines on the AI Act's transparency obligations

    What it means

    On 20 July 2026 the European Commission published guidelines on the AI Act’s transparency obligations:

    • When you have to tell people they are dealing with AI
    • When AI-generated content has to be labelled
    • They explain how to meet duties that already sit in the Act
    • They apply to both the providers who build AI systems and the businesses that deploy them

    This matters if you build, deploy, or operate AI systems in the EU or have EU customers.

    For an Australian business it is a useful preview of where “tell people it’s AI” rules are heading, and it may be worth preparing now.

    Applies to: Anyone who builds, deploys, or operates AI systems in the EU or has EU customersPrimary source →
  8. Proposed

    Government to legislate mandatory 'Australian Standards for AI'

    Government announced it will legislate mandatory 'Australian Standards for AI'; to be considered by National Cabinet in August 2026, legislation expected early 2027.

    What it means

    On 15 July 2026 the government announced it will legislate mandatory “Australian Standards for AI”.

    A new Office of AI will sit inside the Department of the Prime Minister and Cabinet.

    The mandatory obligations named so far centre on large-scale data centres and copyright, not on how most businesses use AI.

    For a typical business, nothing concrete is in place just yet. We will know more after the National Cabinet in August 2026 and standards are expected to be legislated early in 2027.

    Applies to: Large-scale data centres initiallyPrimary source →
  9. Key date
    APRA letter to industry on artificial intelligenceLetter published
  10. Key date
    National AI PlanPlan released
  11. Standards Australia

    Spotlight on: AS ISO/IEC 42001:2023, Artificial intelligence - Management system

    Standards Australia published an explainer on AS ISO/IEC 42001:2023

    What it means

    Standards Australia published an explainer on AS ISO/IEC 42001:2023, the international management-system standard for AI.

    This can be thought of as ISO 27001 but specifically for AI: a recognised way to set up, run and improve how organisations govern the AI they use.

    While it’s not a law – it’s voluntary – we can expect enterprise to start requiring ISO 42001 certification in the near future in they same way they require ISO 27001 or SOC2 certification now. It’s easier for them to check if a business has a certificate, rather than verify your governance practices themselves.

    The themes of ISO 42001 cover ownership, risk assessment, monitoring and human oversight, and are the same ones sensible governance covers anyway.

    Applies to: All businessesPrimary source →
  12. Key date
    ASIC Report 798: governance arrangements and AIReport published

← Back to the map: AI regulation in Australia