If you work in a Commonwealth agency and someone proposes an AI agent, a system that
plans and carries out steps on its own, this 32-page document is what the DTA has written
for you. On 29 September the DTA said Australia is joining the OECD’s new
Working
Group on Agentic AI in Government, alongside Canada, Estonia, Japan, Singapore, South
Korea, Israel and the United Kingdom, and that the DTA will contribute the Australian
Government’s practical experience
. The work it pointed to was the addendum,
released in May: This work provides a strong foundation for Australia’s contribution to the
international discussion
.
So we read it end to end. It is more concrete than most government AI guidance: it names orchestration frameworks, agent protocols and the kinds of action that need a human sign-off. It is also written in two registers at once, and a public servant reading it needs to know which one applies to them.
Fourteen musts, eleven shoulds
The addendum adds eight statements, AGT.1 to AGT.8, carrying 25 criteria between them,
and reuses one existing criterion from the parent standard for shutting a system down. Each
group of criteria is introduced by either Agencies must:
or Agencies should:
.
By our count, 14 of the 25 new criteria sit under “must” and 11 under
“should”.
- LifecycleAGT.1 Governance and safeguards1.11.21.31.4
- LifecycleAGT.2 Memory management2.1
- DesignAGT.3 Design for agentic workflow3.13.23.33.43.53.63.7
- DataAGT.4 Routing and data flow4.14.2
- TrainAGT.5 Agent, model and technology5.15.25.3
- EvaluateAGT.6 Continuous evaluation6.16.26.36.4
- IntegrateAGT.7 Tools and protocols7.17.2
- MonitorAGT.8 Ongoing monitoring8.18.2
under “Agencies must”: 14 under “Agencies should”: 11
Each mark is one criterion, labelled with its number. Statement names are shortened from the addendum. Not shown: the existing Criterion 147 (Statement 41, shut down the AI system), which the addendum extends under “Agencies must”. The counts are our tally of the headings in the addendum PDF (32 pages), checked against the web version, 8 October 2026.
The musts are not vague. Under AGT.1.1, a must criterion whose text explains that a human should be assigned accountability for
the decisions made by these agents
, including even where decisions are made
autonomously across multiple steps
. Under AGT.3.3 each agent gets its own identity and
only the access it needs, which the addendum says is to prevent agents from assigning access to themselves. Under
AGT.3.4 agencies set minimum technical requirements for implementing kill switches
.
And under AGT.2.1, a should, records capture prompts created by agents, and inputs and
outputs throughout the workflow
.
The bullets beneath a heading are a softer layer again. Most are introduced by This
may include
or This includes
, so even a must criterion leaves the agency to
decide how much of its list applies.
A human in the loop, or on it
The addendum defines three ways a person can relate to an agent, and the line it draws between them is the part a citizen would most want to know about.
Human-in-the-loop
- Definition
a human will review inputs and outputs and make the final decision
- The addendum’s use
- Pre-approvals on sensitive actions, such as
payments, entitlements, or mass notifications
- In the AGT.1.2 must
- Named
Human-on-the-loop
- Definition
- The system operates autonomously
while supervised by a human who holistically monitors the system and intervenes when needed
- The addendum’s use
- Real-time supervision with the ability to pause or override
- In the AGT.1.2 must
- Named
Human-out-of-the-loop
- Definition
Operates fully autonomously and makes decisions independently without human interaction
- The addendum’s use
- Periodic audits and post-action sampling
- In the AGT.1.2 must
- Not named
Definitions quoted from the addendum’s key terms; uses from its list of oversight modes (PDF page 14). “In the AGT.1.2 must” records whether the mode appears in the sentence quoted below. Source: Agentic AI addendum to the AI technical standard, last updated 4 June 2026.
The must criterion is AGT.1.2, and its key sentence is short: Oversight must be
maintained through a human-in-the-loop or human-on-the-loop governance model.
It goes on
to list enabling human intervention processes for irreversible or high-risk actions
.
The third mode is described in the document, but only for periodic audits and
post-action sampling; it is not one of the two governance models AGT.1.2 names.
The data section adds a gate before any of that, which it calls a mandatory
prerequisite for agentic AI systems
.
Agencies must not progress beyond early design or experimental stages unless data quality, governance, and security are confirmed and have been assessed as fit for the level of autonomy.Agentic AI addendum, Data section (PDF page 22)
Where the musts sit
None of this answers the public servant’s first question: do I have to? The
addendum’s first line calls it best practice guidance for Australian Government
agencies implementing agentic AI
, and says agencies using agentic AI are expected to
apply this addendum in conjunction with the AI technical standard
. Its own applicability
section then lists one item agencies must follow
, the Policy for the responsible use
of AI in government, and puts the technical standard it extends under
Related legislation, policies, and standards to consider
.
-
Policy for the responsible use of AI in government, v2.0
All non-corporate Commonwealth entities
must apply this policy
-
AI technical standard last updated 22 Aug 2025
Under the policy’s Recommended Actions:
It is strongly recommended that agencies apply the AI technical standard
-
Agentic AI addendum last updated 4 Jun 2026
best practice guidance
; agenciesare expected to apply this addendum
with the standard -
AI integration protocols standard (position) Australian Government Architecture
Compliance:
Non-mandatory
. Content status:Preview
The four documents a reader meets on the way from the policy to an agent protocol, with each one’s status in its own words. The addendum refers agencies to the protocols standard for current protocols. Sources: the policy (PDF and web pages), the technical standard page, the addendum and the Australian Government Architecture page, all read 8 October 2026.
The parent standard works the same way: its own page says each statement is
expanded to detail what agencies should or must do
. So “must” in either
document is binding in the sense that it is the standard’s requirement, once an
agency has chosen to apply the standard.
The policy does make agencies record that choice. Each agency’s internal register of
AI use cases must include a field for use of Technical standard for government’s use
of artificial intelligence (not applied, partially applied or fully applied)
. The same
register’s technology field offers Generative AI, Machine Learning, Natural Language
Processing and/or Computer Vision
, with no separate entry for agentic systems. The
register is internal. What the public sees is the agency’s transparency statement,
which must classify any use where the public may directly interact with, or be
significantly impacted by, AI or its outputs without human review
, but which is not
required to list individual use cases.
Our view
The addendum is good work, and better than its status. Its accountability rule, a named human answering for what agents do across many steps, is the right one, and its line on oversight is clearer than most frameworks manage: payments, entitlements and mass notifications get a human sign-off, and fully autonomous operation is not one of the two governance models its must criterion names.
But a document that says “must” fourteen times while describing itself as best practice invites a misreading in both directions. A cautious official will treat it as mandatory; a hurried one will notice that nothing in the binding policy requires it. The register field shows the DTA already expects some agencies to apply the standard partially or not at all. If Australia is offering this to the OECD as its practical experience, the government should settle the question at home: either lift the oversight and accountability criteria into the policy, or say plainly that they are advice. And transparency statements should say whether an agency runs agents at all.
How we did this
We read the DTA’s 29 September article and the addendum in full on 8 October 2026: the 32-page PDF and its web version (landing page and the ten section pages), and copied them before writing. The 14 and 11 are our count of criteria under each “Agencies must:” and “Agencies should:” heading, made by script over the PDF text and checked by eye against the web pages; Criterion 147 is excluded because it is an existing criterion of the parent standard, not a new one. The DTA’s article says the addendum was released in May 2026; the addendum page says it was last updated 4 June 2026. We report both.
The policy wording comes from the version 2.0 PDF and its web pages, which on 8 October
said version 2.0 is effective 15 December 2025
. A revision published after that
date would not be covered. We have not asked the DTA about anything here. “Our
view” is opinion based on the documents cited.
Sources
- Digital Transformation Agency, Australia joins new OECD working group on agentic AI in government, 29 September 2026 (read in full 8 October 2026): the working group and its listed members; the DTA’s contribution; the addendum released in May 2026 as the foundation.
- Digital Transformation Agency, Agentic AI addendum to the AI technical standard for Australian Government, last updated 4 June 2026, with the 32-page PDF and the web sections Key terms, Introduction, Background, Whole of AI lifecycle, Design and Data (all read in full 8 October 2026): statements AGT.1 to AGT.8, their must and should headings, the oversight modes, the applicability section and the data gate.
- Digital Transformation Agency, Policy for the responsible use of AI in government, version 2.0, 22 pages, with its web pages overview (effective 15 December 2025) and Preparedness and operations (read 8 October 2026): the policy binds non-corporate Commonwealth entities; the technical standard under Recommended Actions.
- Digital Transformation Agency, Policy for the responsible use of AI in government: Accountability (read 8 October 2026): the required fields of the internal AI use case register.
- Digital Transformation Agency, Technical standard for government’s use of artificial intelligence, last updated 22 August 2025 (read 8 October 2026): statements detail what agencies should or must do.
- Digital Transformation Agency, Standard for AI transparency statements (read 8 October 2026): what a statement must contain; individual use cases not required.
- Australian Government Architecture, Artificial intelligence integration protocols standard (position) (read 8 October 2026): compliance non-mandatory; content status preview.
Count the criteria differently, or know of a revised policy or addendum? Tell us and we will check it against the documents and log the outcome here.