The front page and the section pages show what is current. This page lists everything we have published, so a story stays findable after it stops being news.
29 stories · most recent 30 August 2026 · this page is generated at build, so it is never out of date
PSPF Policy Advisory 001-2026, Cyber Security Readiness in the Frontier AI Era, says Australian Government entities do not need access to the most advanced frontier AI models to stay protected. It describes a vulnerability storm and exploit timelines collapsing from days to hours, and answers with the Essential Eight, the ISM and existing PSPF requirements. In ASD's six-strategy annex, adopting AI for cyber defence is fifth and medium-term.
The Senate Select Committee on Adopting AI tabled 13 recommendations on 26 November 2024. Senate practice requires a government response within three months. It was tabled in the House of Representatives on 1 April 2026, sixteen months later, in five thematic parts that never address the recommendations by number. The Senate's own status pages still do not record it.
PSPF Direction 001-2025 bans DeepSeek products, applications and web services from Australian Government systems, but a footnote excludes open source LLMs meeting three conditions. Since Direction 004-2025 took effect on 31 October 2025 the banned list has been the Commonwealth Technology Standard Deny List, which is not in the PSPF publications library.
PSPF Policy Advisory 001-2025 confirms OFFICIAL information can be used with generative AI, and names OpenAI and Anthropic alongside Hosting Certification Framework providers as not requiring an additional Foreign Ownership, Control or Influence assessment. All other providers must be assessed under PSPF Direction 001-2024 before staff get access.
Two frameworks bind Commonwealth AI use, not one. The Policy for the responsible use of AI in government reached version 2.0 on 15 December 2025 and carries eight mandatory requirements for non-corporate Commonwealth entities. The Protective Security Policy Framework binds the same entities, and its Directions include a standing ban on DeepSeek products and a requirement to adhere to the Commonwealth Technology Standard. The APS AI Plan, the AI technical standard, the agentic addendum and the PSPF policy advisories are guidance.
ASIC tells licensees that cyber risk management must be demonstrably effective and proportionate to the size, nature and complexity of a business, as set out in the FIIG judgment. We read the judgment. Those words are not in it. What is in it is a five-factor test that is more concrete and more useful, plus an explicit statement that the law does not require perfection.
Queensland's Auditor-General found the department responsible for AI policy has limited visibility of AI use across government. Five weeks later NSW's auditor counted 357 AI tools across 21 agencies. Different methods, same blind spot.
The automated decision-making transparency obligation commences 10 December 2026 under the Privacy Act. It has a three-limb test, and the limb that decides scope is whether a decision could reasonably be expected to significantly affect a person's rights or interests. The OAIC ran an Issues Paper consultation on what that means; it closed 15 June 2026 and the guidance is not out.
On 10 August the Australian AI Safety Institute published its first publication, 119 pages by Gradient Institute on risks and controls for multi-agent systems. It answers a question we left open on 31 July, and its hardest conclusion is that the controls for AI agents meeting across organisations depend on infrastructure no single organisation can build. There is no Let's Encrypt for agent identity, and the report says nobody is positioned to become one.
Australia's AI memorandum with Singapore was signed in December 2024, well before the Canada and UK ones. On 30 July 2026 it produced the first Australia-Singapore Cyber and Digital Senior Officials Dialogue. We read the memorandum in full: it creates no binding obligations, commits no money, and its first review window opens on 16 December 2026.
We read both Directions to Comply on the eSafety register. Each targets a high impact generative AI DIS with a tier 1 risk profile, each cites the same two compliance measures, and each is about age assurance on AI-generated pornography.
Schedule 6 of the Age-Restricted Material codes has bound designated internet services since 9 March 2026. It names AI companion chatbots, deems some generative services highest-risk without an assessment, and creates a regulated category for platforms that host uploaded models.
The Online Safety (Designated Internet Services) Industry Standard 2024 defines a 'high impact generative AI DIS' and binds it: prevent prohibited outputs, test models, differentiate AI outputs, and assess before a material change. Registered June 2024, in force 22 December 2024.
The Relevant Electronic Services industry standard, covering messaging and email, was determined by the same Commissioner on the same day as the standard that regulates generative AI. It does not use the word generative once. What it does say about AI, and what that means.
On 25 May 2026 Australia and the UK signed a memorandum of understanding on AI safety and security. The department published a three-bullet overview, not the instrument. Eleven weeks earlier it published the Canada MoU in full, so we know what these agreements usually contain and what the overview leaves out.
The ACITI Partnership was announced in November 2025 with an emphasis on green energy innovation, resilient supply chains and critical minerals, and AI as something it would also examine. The memorandum of understanding signed on 10 July 2026 sets up four working streams, all of them AI, and does not mention minerals, energy or net zero at all.
The Australia-Canada memorandum of understanding on AI safety is published in full. It creates no legally binding obligations, has no financial implication for either country, and can be ended on six months' notice. It also sets two hard deadlines, and the second one falls around 1 September 2026.
Australia's AI Safety Institute was announced on 25 November 2025 and sits inside the department it advises. Its technical partners include the Australian Signals Directorate. The multi-agent risk project cited as its work was published four months before it existed and funded by the department. And the international network it belongs to has dropped the words AI Safety from its name.
On 20 July 2026 six ministers jointly named the Albanese Government's AI safety priorities: a Digital Duty of Care, a second tranche of privacy reform, workplace AI safety, consumer law options, and a framework for automated decision-making in federal agencies. Each has a different lead minister and a different legal instrument. None carries a published date.
The OAIC has updated its guidance on facial recognition in retail spaces to implement the Administrative Review Tribunal's findings in the Bunnings matter, which covered 62 stores between 2018 and 2021. The Privacy Commissioner says a precautionary approach is required and that each deployment must still be assessed individually. The Kmart determination remains under review with hearings in early 2027.
The OAIC's triennial Australian Community Attitudes to Privacy Survey put AI companies equal-last on trust at 4 per cent. Ninety-six per cent want conditions before AI makes a decision about them, and every condition measured in both years rose. We read the 2026 report and set it against the policy Australia actually chose.
The National AI Centre and CSIRO's census of Australia's AI ecosystem counts 1,533 companies, 25 urban clusters led by Melbourne CBD, patents nearly quadrupling, and a commercialisation gap of almost 23 publications per patent. The numbers, charted from the report.
ASIC Commissioner Simone Constant's 8 May 2026 open letter tells every AFS licensee that frontier AI is accelerating cyber attacks now, lists twelve expected actions, and anchors the lot to the FIIG Securities judgment. What a board must be able to show.
DEWR's new monitoring report is the first Australian government data on AI and employment: exposed occupations grew 5.6 per cent against 9.5 per cent for the least exposed, the effect is not robust, software jobs are up 25 per cent, and the most exposed workers are majority women and degree-holders.
OpenAI's system card rates all three GPT-5.6 models High capability for cybersecurity and biological risk. Washington reportedly held the launch for testing. In Australia the same models arrived under no AI-specific check, which is the government's explicit design.
In September 2024 the government proposed ten mandatory guardrails for high-risk AI and three ways to legislate them, including an Australian AI Act. The National AI Plan commits to none of them, and the word guardrails does not appear once in its 37 pages.
The NSW Auditor-General's 2025 internal controls report found 21 of the state's 26 largest agencies using 357 AI tools, while only 38 per cent have a formal AI policy and 5 per cent have AI procurement guidance. The numbers, from the audit itself.
OpenAI's own documentation lists Australia as a data residency region with storage yes, processing no: prompts are still processed on offshore infrastructure, and residency endpoints carry a 10 per cent price uplift for new models. What that means before you tick the compliance box.
WiseTech Global's 1H26 ASX release announces a phased headcount reduction of up to 50 per cent in product, development and customer service, about 2,000 roles, framed as becoming an AI-led organisation. What the filing actually says, and the caveats it carries.