All stories

Every story, newest first

The front page and the section pages show what is current. This page lists everything we have published, so a story stays findable after it stops being news.

29 stories · most recent 30 August 2026 · this page is generated at build, so it is never out of date

Policy

The Commonwealth’s advice on frontier AI cyber risk is that you do not need frontier AI

PSPF Policy Advisory 001-2026, Cyber Security Readiness in the Frontier AI Era, says Australian Government entities do not need access to the most advanced frontier AI models to stay protected. It describes a vulnerability storm and exploit timelines collapsing from days to hours, and answers with the Essential Eight, the ISM and existing PSPF requirements. In ASD's six-strategy annex, adopting AI for cyber defence is fifth and medium-term.

Published

Policy

Parliament's AI inquiry made 13 recommendations. The response took 16 months and answered none of them by number

The Senate Select Committee on Adopting AI tabled 13 recommendations on 26 November 2024. Senate practice requires a government response within three months. It was tabled in the House of Representatives on 1 April 2026, sixteen months later, in five thematic parts that never address the recommendations by number. The Senate's own status pages still do not record it.

Published

Policy

Two frameworks bind how the Commonwealth uses AI, not one. The second is the one nobody points you at

Two frameworks bind Commonwealth AI use, not one. The Policy for the responsible use of AI in government reached version 2.0 on 15 December 2025 and carries eight mandatory requirements for non-corporate Commonwealth entities. The Protective Security Policy Framework binds the same entities, and its Directions include a standing ban on DeepSeek products and a requirement to adhere to the Commonwealth Technology Standard. The APS AI Plan, the AI technical standard, the agentic addendum and the PSPF policy advisories are guidance.

Published

Regulation

We read the FIIG judgment every AI cyber letter cites. It names five factors, and not the phrase you have been given

ASIC tells licensees that cyber risk management must be demonstrably effective and proportionate to the size, nature and complexity of a business, as set out in the FIIG judgment. We read the judgment. Those words are not in it. What is in it is a five-factor test that is more concrete and more useful, plus an explicit statement that the law does not require perfection.

Published

Policy

From 10 December every Australian privacy policy must disclose automated decisions. The regulator is still working out what counts

The automated decision-making transparency obligation commences 10 December 2026 under the Privacy Act. It has a three-limb test, and the limb that decides scope is whether a decision could reasonably be expected to significantly affect a person's rights or interests. The OAIC ran an Issues Paper consultation on what that means; it closed 15 June 2026 and the guidance is not out.

Published

Policy

The AI Safety Institute has published its first report. Its sharpest finding is that nobody owns the fix

On 10 August the Australian AI Safety Institute published its first publication, 119 pages by Gradient Institute on risks and controls for multi-agent systems. It answers a question we left open on 31 July, and its hardest conclusion is that the controls for AI agents meeting across organisations depend on infrastructure no single organisation can build. There is no Let's Encrypt for agent identity, and the report says nobody is positioned to become one.

Published

Policy

We passed on the government’s claims about its AI Safety Institute. Then we checked them.

Australia's AI Safety Institute was announced on 25 November 2025 and sits inside the department it advises. Its technical partners include the Australian Signals Directorate. The multi-agent risk project cited as its work was published four months before it existed and funded by the department. And the international network it belongs to has dropped the words AI Safety from its name.

Published

Policy

What replaced the mandatory AI guardrails: five priorities, five ministers, no dates

On 20 July 2026 six ministers jointly named the Albanese Government's AI safety priorities: a Digital Duty of Care, a second tranche of privacy reform, workplace AI safety, consumer law options, and a framework for automated decision-making in federal agencies. Each has a different lead minister and a different legal instrument. None carries a published date.

Published

Policy

The privacy regulator has rewritten its facial recognition guidance around one retailer’s loss

The OAIC has updated its guidance on facial recognition in retail spaces to implement the Administrative Review Tribunal's findings in the Bunnings matter, which covered 62 stores between 2018 and 2021. The Privacy Commissioner says a precautionary approach is required and that each deployment must still be assessed individually. The Kmart determination remains under review with hearings in early 2027.

Published

Research

Four per cent of Australians trust AI companies. The government's own survey says so.

The OAIC's triennial Australian Community Attitudes to Privacy Survey put AI companies equal-last on trust at 4 per cent. Ninety-six per cent want conditions before AI makes a decision about them, and every condition measured in both years rose. We read the 2026 report and set it against the policy Australia actually chose.

Published

Data

Australia has 1,533 AI companies and 23 research papers for every patent

The National AI Centre and CSIRO's census of Australia's AI ecosystem counts 1,533 companies, 25 urban clusters led by Melbourne CBD, patents nearly quadrupling, and a commercialisation gap of almost 23 publications per patent. The numbers, charted from the report.

Published