AI Governance Frameworks, Explained Without the Jargon
"AI governance framework" covers a handful of documents that do different jobs. Here is an overview of the main frameworks as of August 2026, and a discussion of what actually applies to your Australian business.

Image: Nanobanana (AI-generated)
“AI governance framework” covers a small number of documents that do different jobs.
Most Australian businesses are inside the scope of one of them, and it is not the one they expect.
Four come up again and again:
- the EU AI Act
- ISO/IEC 42001
- the NIST AI Risk Management Framework
- Australian law and guidance
They are not competing options to choose between. Three of them do different jobs, and most businesses need none of them yet. The fourth is not really a framework at all: it’s the law that already applies to you.
Three frameworks, three jobs
- The EU AI Act is law. If you are in scope, it is a floor with penalties attached.
- ISO 42001 is proof. A certificate that shows outsiders your governance exists.
- The NIST AI RMF is a method. A structure for running governance day to day.
Large organisations commonly touch on all three. Most smaller organisations won’t need any just yet – although laws still apply regardless of organisation size.
The EU AI Act: a dedicated AI law
This is European law with reach beyond Europe.
A business outside the EU can be in scope if its AI system, or the output of that system, is used in the EU.
It classifies AI systems by risk. Prohibited uses sit at the top; minimal-risk uses carry no obligations, so this puts a high importance on the correct classification of your AI use case.
The substantive duties fall on “high-risk” systems in areas such as recruitment, credit and access to essential services.
Whether it applies to a given Australian business is a scoping question, and a separate guide covers how to work through it.
For most Australian SMBs it applies only where they sell into the EU, but “sell into the EU” is broader than it sounds.
ISO 42001: a certifiable standard
This is what your enterprise customers might start asking for.
ISO/IEC 42001 is a certifiable management-system standard.
An accredited auditor checks that the business has AI governance processes in place and operating in accordance with their requirements, and issues a certificate that says so.
No law requires this certification, but it is an important and internationally recognised proof-element which certifies that the organisation’s processes align with responsible and safe AI practices. It does not show that any particular system is safe; it applies to the organisation’s overall practices.
Sources indicate that enterprise customers are increasingly requesting ISO 42001 before contracting, on the same path ISO 27001 took for information security.
The NIST AI RMF: a voluntary framework
The NIST AI Risk Management Framework is a voluntary structure for managing AI risk, built on four functions: govern, map, measure, manage. It is a US publication with no legal force anywhere.
It has value as a cohesive system of best practices and provides a common vocabulary for managing AI risk.
It maps onto both the EU AI Act and ISO 42001, which is why it is often used as the working method underneath either.
Where the law stands in Australia
At the time of writing, there is no Australian AI Act, but we are actively tracking the legislative landscape.
What applies in Australia today is existing law, government guidance, and announced legislation.
Existing law. The Privacy Act applies whenever personal information goes into or comes out of an AI tool, and the OAIC has said so directly.
From 10 December 2026, businesses covered by the Australian Privacy Principles must disclose in their privacy policies where personal information is used in substantially automated decisions that could significantly affect someone.
Consumer law, anti-discrimination law and work health and safety law apply to AI use as they apply to everything else; in New South Wales, WHS legislation now names digital work systems specifically.
Financial services and superannuation carry additional expectations set out by ASIC and APRA. The Privacy Act is already being checked without a complaint. In January 2026 the OAIC ran its first compliance sweep, reviewing the privacy policies of around sixty businesses across six sectors that collect personal information face to face.
Government guidance. The Voluntary AI Safety Standard of September 2024 was superseded in October 2025 by the National AI Centre’s Guidance for AI Adoption. It sets out six practices:
- Decide who is accountable. Assign clear internal ownership, designate a senior leader as an overall AI governance owner, and ensure specific individuals are responsible for every AI system and its supply chain.
- Understand impacts and plan accordingly. Conduct stakeholder impact assessments to identify potential harms (such as bias or privacy breaches) and establish feedback channels for people to challenge automated outcomes.
- Measure and manage risks. Treat AI like any material business risk by integrating it into enterprise risk registers, screening use cases, and applying controls scaled to the level of risk.
- Share essential information. Be transparent with users when they are interacting with AI, maintain an internal AI systems register, and provide clear explanations of what tools do and where their limits lie.
- Test and monitor. Rigorously test systems for accuracy, security, and bias before deployment, and establish ongoing monitoring rather than a “set and forget” approach.
- Maintain human control. Ensure meaningful human oversight, build in override points so people can step in or reverse automated decisions, and avoid blind over-reliance on high-stakes outputs.
This is non-binding, but it is also the closest published statement of what Australian regulators will treat as reasonable, and it was written for the local context the international frameworks were not.
The direction of travel. Federal policy has moved once already, and the move is worth reading precisely.
In December 2025 the National AI Plan set the position: existing laws and sector regulators would carry AI risk, supported by voluntary guidance, with no standalone AI Act and no mandatory guardrails.
Seven months later, in July 2026, the government announced it would legislate the Australian Standards for AI and established an Office of AI within the Department of the Prime Minister and Cabinet.
The first legislated layer is aimed at infrastructure: large data centres and AI training, including mandatory energy and water requirements, with legislation expected in 2027.
For a business that uses AI, nothing changed in July. The standards as published do not create duties for AI users. What changed is the posture. In December the government said existing law was sufficient; by July it had decided to legislate, and built an office to do it.
Whether the second layer reaches AI deployers, and when, is the open question.
The practical effect today: an Australian SMB’s current obligations are not in an AI framework. They are in laws the business already answers to, applied to a new kind of tool.
Which do you need?
- Selling AI, or AI-touched services, into the EU: the EU AI Act. Start with scope.
- Selling to large enterprise customers: ISO 42001, once a contract depends on it and not before.
- Neither: the NIST functions or Australia’s six practices give a method without the certification cost.
For most Australian SMBs, no framework applies yet – but Australian law does. The first thing every framework and every regulator asks is generally a variation of the same: what AI does the business use? Who owns it? And what does it touch?
The governance foundation without the framework overhead – what AI is in use, who owns it, and a record that can be shown when someone asks – is what we help Australian businesses put in place.
Further reading
- EU AI Act, official text (EUR-Lex, Regulation (EU) 2024/1689)
- ISO/IEC 42001:2023 (ISO)
- NIST AI RMF (NIST ITL)
- Guidance for AI Adoption (National AI Centre)
- OAIC guidance on commercially available AI products
- AI in Australia’s interests (15 July 2026 announcement)
- National AI Plan
- ASIC REP 798 (29 Oct 2024)
- APRA Letter to Industry on AI (30 Apr 2026)
- OAIC APP Guidelines, Chapter 1 (new APP 1.7–1.9, from 10 December 2026)
- OAIC consultation on ADM transparency guidance (May 2026)
- NSW WHS Amendment (Digital Work Systems) Act 2026
- Privacy Act 1988 (Federal Register)
A few quick questions. No sign-up, no scanning. See where your AI risk actually is.
Find your AI risk


