The changelog
One timeline: the statutory dates that are coming, and dated notes on what changed and what it means for a business without a compliance team. Written by a person, every time.
The next phase of the EU AI Act takes effect, sharpening the duties of those building with and deploying AI tools
From 2 August the next phase of the EU AI Act takes effect, including transparency requirements and the rules the Commission can now enforce. This intensifies requirements on people and companies building AI systems and deploying them in the EU market.
This is EU law, so it reaches you only if you sell into or operate in the EU. While most Australian businesses using everyday AI tools are outside its scope, if you have EU customers or operations, it’s worth checking where your AI use sits under the Act. Professional legal advise is recommended as the implications for non-compliance are severe.
This appears to be the benchmark other AI governance regimes are moving toward.
The OAIC published updated guidance on the use of facial recognition in retail spaces.
On 30 July 2026 the OAIC published updated guidance on the use of facial recognition in retail spaces. The updated guidance implements the findings of the Administrative Review Tribunal (ART) in the matter of Bunnings Group Limited (Bunnings), which concerned the retailer’s use of facial recognition technology in 62 of its stores for a period between 2018 and 2021.
It sets out how the Privacy Act applies when a business captures and matches people’s faces
The OAIC expects the use to be:
This matters if you use facial recognition, in a store, a venue, or a security system. Most Everyday AI tools are not affected. If you do use facial recognition, this as the standard you will be measured against.
The European Commission published guidelines on the AI Act's transparency obligations
On 20 July 2026 the European Commission published guidelines on the AI Act’s transparency obligations:
This matters if you build, deploy, or operate AI systems in the EU or have EU customers.
For an Australian business it is a useful preview of where “tell people it’s AI” rules are heading, and it may be worth preparing now.
Government announced it will legislate mandatory 'Australian Standards for AI'; to be considered by National Cabinet in August 2026, legislation expected early 2027.
On 15 July 2026 the government announced it will legislate mandatory “Australian Standards for AI”.
A new Office of AI will sit inside the Department of the Prime Minister and Cabinet.
The mandatory obligations named so far centre on large-scale data centres and copyright, not on how most businesses use AI.
For a typical business, nothing concrete is in place just yet. We will know more after the National Cabinet in August 2026 and standards are expected to be legislated early in 2027.
Standards Australia published an explainer on AS ISO/IEC 42001:2023
Standards Australia published an explainer on AS ISO/IEC 42001:2023, the international management-system standard for AI.
This can be thought of as ISO 27001 but specifically for AI: a recognised way to set up, run and improve how organisations govern the AI they use.
While it’s not a law – it’s voluntary – we can expect enterprise to start requiring ISO 42001 certification in the near future in they same way they require ISO 27001 or SOC2 certification now. It’s easier for them to check if a business has a certificate, rather than verify your governance practices themselves.
The themes of ISO 42001 cover ownership, risk assessment, monitoring and human oversight, and are the same ones sensible governance covers anyway.