Policy Advisory 001-2026 describes a vulnerability storm and exploit
timelines collapsing from days to hours, then answers with patching, hardening and the
Essential Eight. In the attached ASD framework, adopting AI is the fifth of six strategies
and medium-term.
PSPF Policy Advisory 001-2025 confirms OFFICIAL information can be
used with generative AI, and names Hosting Certification Framework providers, OpenAI and
Anthropic as needing no additional Foreign Ownership, Control or Influence assessment.
Every other provider must be assessed under a separate Direction before staff get access.
An allow list you can read, beside a deny list you cannot.
PSPF Direction 001-2025 bans DeepSeek products, applications and web
services from government systems, and a footnote excludes open sourced LLMs on three
cumulative conditions: inspectable codebase, local deployment, mitigations in place. Since
Direction 004-2025 took effect on 31 October 2025 the operative list has been the
Commonwealth Technology Standard Deny List, which is not in the PSPF publications library.
The Senate select committee tabled its final report on 26 November 2024,
recommending dedicated legislation for high-risk AI, work health and safety coverage, and
transparency about copyrighted works in training data. Senate practice requires a response in
three months. It was tabled in the House on 1 April 2026, in five thematic parts that refer to
a numbered recommendation three times. The Senate’s own pages still do not record it.
The Policy for the responsible use of AI in government applies to all
non-corporate Commonwealth entities and carries eight mandatory requirements. So does the
Protective Security Policy Framework, whose Directions ban a named AI service outright. The
APS AI Plan, the technical standard, the agentic addendum and the PSPF policy advisories are
guidance. Corrected 29 August on a reader tip.
Eight mandatory requirements, read from the policy document rather
than the summary of it. A scope test that excludes AI spellcheckers, a named human
answerable for every in-scope use case, a register that goes to the DTA twice a year, and an
impact assessment that must be finished before deployment. One deadline has passed, a
cluster lands at the end of 2026, and everything already running is due by 30 April 2027.
The ACCC, ACMA, eSafety and the OAIC published 2026-28 priorities and a signed MoU two days apart in June. We read both plus all 2,332 words of the signed document. AI appears zero times, from a forum whose last three substantive publications were about AI.
The APS AI Plan published 15 deliverables against dated timeframes, and most of those dates have now passed. The oversight committee arrived, chaired by the DTA chief executive and seating the Privacy Commissioner and the head of the AI Safety Institute. Its own page says the advice is non-binding and that it does not replace agency accountability.
The obligation commences 10 December 2026 under the Privacy Act. Three limbs, and the one that decides scope is whether a decision could reasonably be expected to significantly affect a person’s rights or interests. The OAIC consulted on exactly that, closed submissions on 15 June, and the guidance is not out.
119 pages by Gradient Institute on what happens when AI agents from
different organisations meet. Three governance tiers, a map of who can act on each risk,
and a set of gaps that fall to no one: there is no trusted issuer for agent identity, and
the report says no single party has the standing or the funding model to become one.
The memorandum with Singapore was signed on 16 December 2024, a year
before the Canada and UK ones, and its text is published. We read it: no binding
obligations, each side bears its own costs, and every mechanism it creates is permissive.
The first dialogue it has produced met on 30 July, and its own review window opens on
16 December 2026.
We read both Directions to Comply on the eSafety register. Each names
the provider a high impact generative AI DIS with a tier 1 risk profile, each cites the same
two compliance measures, and the first of those reaches the moment before the material
exists: what a service will let a user ask it to generate.
Signed 25 May 2026. What is public is a three-bullet overview, where
the Canada agreement eleven weeks earlier was published in full, clauses and all. Because we
read that one, we can say precisely what this overview does not answer: whether it binds
anyone, whether it funds anything, and what may actually be shared.
The full text is published, so we read it. Seven areas of cooperation
including talent exchange between the two AI safety institutes, and two hard deadlines. It
creates no legally binding obligations, has no financial implication for either country, and
ends on six months' notice. The workplan is due around 1 September.
The ACITI Partnership was announced in November 2025 in a joint statement
that led with green energy innovation, resilient supply chains and critical minerals, and said
the partnership would also examine artificial intelligence. The memorandum signed on
10 July 2026 sets up a joint working group with four streams, and every one of them is AI.
Minerals, energy and net zero do not appear in it at all.
It is eight months old, it sits inside the department whose policy it
informs, and its technical partners include the Australian Signals Directorate, which the
ministerial release did not mention. The multi-agent project credited to it was published four
months before it existed and funded by the department. And the international network it belongs
to has quietly dropped the words “AI Safety” from its name.
Six ministers jointly named the government’s AI safety priorities on
20 July: a Digital Duty of Care, a second tranche of privacy reform, workplace AI safety,
consumer-law options covering agentic commerce and surveillance pricing, and a framework for
automated decision-making inside federal agencies. Each has a different lead minister and sits
in a different body of law, and none carries a published date.
Updated OAIC guidance implements what the Administrative Review Tribunal
decided in the Bunnings matter, covering 62 stores between 2018 and 2021. It clarifies when the
consent exceptions apply to biometric collection in retail, restates that a precautionary
approach is required, and cites a survey finding that 45 per cent of Australians now rate
facial recognition among the biggest privacy risks they face. The Kmart matter is still live.
The privacy regulator's triennial national survey puts AI
companies equal-last on trust, level with data brokers. Ninety-six per cent want
conditions before an AI decides anything about them, and of the eight conditions
measured in both 2023 and 2026, every one rose. We read the 80-page report and set
it against the regulatory posture Australia actually chose.
In 2024 the government proposed ten mandatory guardrails for
high-risk AI and three ways to make them law, up to an Australian AI Act. The plan
that answered commits to none of it; the word "guardrails" does not appear once in
its 37 pages. We read both documents end to end, and here is what actually binds
an Australian AI deployer today.
Zero mentions of artificial intelligence, machine learning or generative in the whole
Act. The category that catches AI services is defined by what it is not, and the reason
turns on a question worth asking about your own product: who is the other end-user?
The Attorney-General has announced the government is not considering a text and data
mining exception. That settles the question most of the argument has been about, and it
makes the three areas actually on the table worth reading.
The words ASIC attributes to the court do not appear in its judgment. What does is a
five-factor test for what counts as adequate, and an express statement that the law
does not demand perfection.
Schedule 6 of the Age-Restricted Material codes names AI companion chatbots, deems
some generative services highest-risk without an assessment, and regulates platforms
that host uploaded models.
Its sibling instrument covers messaging and email, and does not contain the word
once. What it says about AI instead, and the qualification that matters.
A binding standard defines a “high impact generative AI DIS” and tells
its provider what to do, including differentiate AI outputs. Read clause by clause.