The changelog

What changed, and what it means.

A dated log of changes to AI regulation in Australia.

  1. Key date
    EU AI ActHigh-risk AI obligations apply to standalone systems (embedded systems follow 2 Aug 2028)
  2. Key date
    Children’s Online Privacy CodeRegistration deadline
  3. Key date
    Privacy Act reform: automated decision-making transparencyAutomated decision-making transparency obligation commences
  4. Today
  5. ASICBinding

    ASIC amends Market Integrity Rules to cover AI and algorithmic trading, effective 2028

    ASIC has amended the Market Integrity Rules for securities and futures markets to require participants to test, monitor and govern their trading systems and algorithms, including AI and machine learning ones, and to clarify that AI-driven trading that creates a false or misleading appearance breaches the rules. The amendments take effect in 2028 after an 18-month transition; consultation on the updated guidance (RG 265 and RG 266) closes 5 November 2026.

    What it means

    This affects firms that trade on Australian securities and futures markets as ASIC market participants. If that is not you, nothing changes.

    If it is you, the rules now make a trading algorithm your responsibility whether a person wrote it or a model learned it.

    You must test it before it trades, watch it while it trades, and be able to show how you govern it. The rules are technology neutral, so a vendor’s AI trading tool is covered the same way as your own code. The false or misleading rule now expressly catches AI-driven trading that creates a false appearance in the market, whether or not anyone intended it.

    You have time. The amendments commence in 2028, and ASIC extended the transition to 18 months after industry feedback. The practical step now is to list every trading algorithm you run, name who owns each one, and record how it is tested and monitored. That record is what ASIC will ask to see.

    ASIC is also consulting on simpler guidance for market participants (updated RG 265 Guidance on ASIC market integrity rules for participants of securities markets, and RG 266 Guidance on ASIC market integrity rules for participants of futures markets, with RG 241 Electronic Trading withdrawn) until 5 November 2026. If the current guidance is problematic to apply, this is an opportunity to have your voice heard.

    Applies to: ASIC market participants: securities and futures trading firmsPrimary source →
  6. eSafety CommissionerProposed

    Government releases draft Digital Duty of Care legislation, naming AI chatbots

    The government released draft Digital Duty of Care legislation for targeted consultation on 9 September 2026. It would require digital services, including AI chatbots, apps and online games, to protect Australian users and especially under-18s from harmful design and content, document their measures, and give social media users a choice over algorithmic feeds ("My Feed, My Way"). eSafety would enforce it, with penalties up to $109.2 million. A bill is promised for 2026.

    What it means

    This draft duty falls on businesses that provide a digital service to the public: social media platforms first, and then apps, online games and AI chatbots that Australians, and especially under-18s, use directly.

    If your AI use is internal, or your chatbot serves adult customers of a business, nothing in this draft reaches you.

    If you run a public-facing chatbot or app that a minor could reach, the draft would require you to protect young users from addictive design and from listed categories of harmful content, and to keep a written record of the measures you take and evidence that they keep working. Start that record now: it is the same record a regulator asks for after something goes wrong, and it costs little to begin.

    This is an exposure draft, not law. The government is consulting platforms, industry bodies and civil society and says it will introduce the bill to Parliament this year. Scope, and the size of business it catches, will settle in the bill.

    Applies to: Digital service providers, including public-facing AI chatbots, apps and online games used by AustraliansPrimary source →
  7. Proposed

    National Cabinet backs mandatory AI and data centre standards

    First Ministers endorse the framework; data centre standards to be developed

    What it means

    On 26 August 2026, National Cabinet agreed to the Commonwealth’s plan for a nationally consistent framework on AI, with mandatory minimum standards for large data centres covering energy, water and land use. All states and territories are behind it, with some flexibility built in on the energy detail. The Commonwealth will now work with the states to develop the actual standards, and national AI laws are still expected in early 2027.

    For a typical business, this changes nothing you have to do today. The mandatory part lands on operators of large data centres, not on how most businesses use AI.

    The framework announced in July now has the states behind it, so it is far more likely to become law. The dates to watch are the draft legislation later this year and the bill in early 2027, which will define any obligations that reach general business.

    Applies to: Operators of large data centresPrimary source →
  8. EU

    Commission starts enforcing AI Act rules and new transparency requirements on 2 August

    The next phase of the EU AI Act takes effect, sharpening the duties of those building with and deploying AI tools

    What it means

    From 2 August the next phase of the EU AI Act takes effect, including transparency requirements and the rules the Commission can now enforce, for anyone building AI systems or deploying them in the EU market.

    This is EU law, so it reaches you only if you sell into or operate in the EU. Most Australian businesses using everyday AI tools are outside its scope. If you have EU customers or operations, check where your AI use sits under the Act; the penalties are large enough to justify legal advice.

    Applies to: Anyone building or deploying AI who sells into or operates in the EUPrimary source →
  9. OAICBinding

    Privacy Commissioner publishes updated guidance on facial recognition in retail spaces

    The OAIC published updated guidance on the use of facial recognition in retail spaces.

    What it means

    On 30 July 2026 the OAIC published updated guidance on the use of facial recognition in retail spaces. The updated guidance implements the findings of the Administrative Review Tribunal (ART) in the matter of Bunnings Group Limited (Bunnings), which concerned the retailer’s use of facial recognition technology in 62 of its stores for a period between 2018 and 2021.

    It sets out how the Privacy Act applies when a business captures and matches people’s faces

    The OAIC expects the use to be:

    • Genuinely necessary and proportionate
    • People to be given clear notice
    • And a privacy impact assessment to be done before it is switched on.

    If you use facial recognition in a store, a venue or a security system, this is the standard you will be measured against. Everyday AI tools are not affected.

    Applies to: Businesses that use facial recognition, in a store, a venue, or a security system.Primary source →
  10. EUBinding

    Guidelines on transparency obligations for providers and deployers of AI systems

    The European Commission published guidelines on the AI Act's transparency obligations

    What it means

    On 20 July 2026 the European Commission published guidelines on the AI Act’s transparency obligations:

    • When you have to tell people they are dealing with AI
    • When AI-generated content has to be labelled
    • They explain how to meet duties that already sit in the Act
    • They apply to both the providers who build AI systems and the businesses that deploy them

    If you build, deploy or operate AI systems in the EU, or have EU customers, these guidelines set out when you must tell people they are dealing with AI and when generated content must be labelled.

    For an Australian business outside the EU, they show where disclosure rules are heading: expect to tell people when they are dealing with AI and to label generated content. Both cost little to start now.

    Applies to: Anyone who builds, deploys, or operates AI systems in the EU or has EU customersPrimary source →
  11. Proposed

    Government to legislate mandatory 'Australian Standards for AI'

    Government announced it will legislate mandatory 'Australian Standards for AI'; to be considered by National Cabinet in August 2026, legislation expected early 2027.

    What it means

    On 15 July 2026 the government announced it will legislate mandatory “Australian Standards for AI”.

    A new Office of AI will sit inside the Department of the Prime Minister and Cabinet.

    The mandatory obligations named so far centre on large-scale data centres and copyright, not on how most businesses use AI.

    For a typical business, nothing concrete is in place yet. National Cabinet considers the framework in August 2026 and legislation is expected early in 2027.

    Applies to: Large-scale data centres initiallyPrimary source →
  12. Key date
    APRA letter to industry on artificial intelligenceLetter published
  13. Key date
    NSW AI Assessment FrameworkModernised framework released
  14. Key date
    Mandatory guardrails for high-risk AI (proposals paper)Withdrawn: National AI Plan opts for existing law
  15. Key date
    National AI PlanPlan released
  16. Key date
    Guidance for AI Adoption (National AI Centre)Guidance for AI Adoption published
  17. Key date
    Voluntary AI Safety StandardSuperseded by the Guidance for AI Adoption
  18. Standards Australia

    Spotlight on: AS ISO/IEC 42001:2023, Artificial intelligence - Management system

    Standards Australia published an explainer on AS ISO/IEC 42001:2023

    What it means

    Standards Australia published an explainer on AS ISO/IEC 42001:2023, the international management-system standard for AI.

    It is ISO 27001 for AI: a recognised way to set up, run and improve how an organisation governs the AI it uses.

    It is voluntary, not law. Expect large customers to start asking for ISO 42001 certification the way they ask for ISO 27001 or SOC 2 now, because a certificate is easier to check than your governance practices.

    The themes of ISO 42001 cover ownership, risk assessment, monitoring and human oversight, and are the same ones sensible governance covers anyway.

    Applies to: All businessesPrimary source →
  19. Key date
    ASIC Report 798: governance arrangements and AIReport published

← Back to the map: AI regulation in Australia