AI compliance in Australia: what boards must be able to evidence
The Australian AI compliance landscape — privacy, sector obligations, ethics principles and standards — and the evidence directors should expect.
The landscape as it stands
Australian organisations do not face a single omnibus AI statute. AI use is governed by existing law — privacy, consumer law, anti-discrimination, records and sector-specific obligations — supplemented by voluntary standards and government guidance.
That makes the compliance question practical rather than theoretical: which existing obligations does this AI system touch, and can we evidence that we have met them?
Privacy is the sharpest edge
Where an AI system handles personal information, the Australian Privacy Principles apply as they do anywhere else: collection limits, notice, use and disclosure consistent with the primary purpose or a reasonable expectation, overseas disclosure obligations, data quality, security and access rights.
Reform activity continues to move in the direction of stronger transparency around automated decision-making. Organisations that already document purpose, notice and oversight will absorb changes with far less disruption.
Sector obligations and expectations
Regulated sectors carry additional weight. Financial services entities work within operational risk and outsourcing expectations; critical infrastructure operators carry security-of-critical-infrastructure obligations; health, education and government carry their own record-keeping and fairness expectations.
Map the relevant obligations to specific AI systems rather than to AI in general. An abstract compliance statement helps nobody at an audit.
Standards and principles as scaffolding
Australia's AI Ethics Principles, ISO/IEC 42001 and the NIST AI Risk Management Framework are not law, but they give directors a defensible structure for oversight and give assurance teams something concrete to test against.
Adopting one framework consistently is significantly better than referencing three inconsistently.
Want this assessed against your environment?
Send us the specifics and a senior advisor will respond within one business day.
What a board should ask for
Ask for the AI inventory with impact tiers, the impact assessments for high-tier systems, the approval decisions and conditions, the oversight and incident record, the supplier assurance position, and the residual risks management has accepted.
Ask what the organisation would say to a regulator or a customer tomorrow if a system produced a harmful outcome today. If that answer is not ready, the governance is not ready.
Where this connects to security
Compliance and security converge on the same artefacts: knowing what runs, what data it touches, who approved it and what evidence exists. Building those once serves both.
General information only — not legal advice. Confirm obligations with your legal adviser and current regulator guidance.
Sources and further reading
- Australia's AI Ethics Principles
- OAIC guidance on privacy and the Privacy Act
- ISO/IEC 42001 AI management systems
- NIST AI Risk Management Framework
This article provides general information and decision support. It is not legal advice, audit assurance, certification advice or a guarantee of outcome.
Related reading
Securing enterprise AI adoption: a practical AI security control set
The AI security controls that matter first — identity, data boundaries, model access, logging, human oversight and supplier assurance.
Read articleAI risk assessment: how to assess an AI system before it ships
A repeatable AI risk assessment covering purpose, data, model behaviour, integration, human oversight, failure modes and evidence.
Read articleISO 42001 vs ISO 27001: how the two management systems interlock
What each standard covers, where they overlap, and how to run one integrated management system instead of two parallel programmes.
Read article