Corrected 29 August 2026, on a reader tip. This story originally ran under the headline Four documents govern how the Commonwealth uses AI. Only one of them binds anybody, and it left out the Protective Security Policy Framework. A reader wrote in to say the PSPF is binding on non-corporate Commonwealth entities, and on that central point they are right: the same entities that must follow the AI policy must also apply the PSPF, and its Directions include one that bans a named AI service outright. The headline, the standfirst and the section below have been changed to say so. One qualification to the tip itself, because the distinction is the whole point of the piece: the PSPF policy advisories, including both of the AI ones, are guidance rather than obligation, and the framework's own page says so. Our thanks for the correction.

The reason to lay this out now is that the government has said it is moving from trials to production. In a keynote at Tech in Gov on 4 August 2026, published by the Digital Transformation Agency three days later, deputy chief executive Lucy Poole put it as A pilot proves that something can work. Scale proves that we can operate it, and argued that the challenge is no longer whether the technology is capable but whether institutions can absorb change at that speed. She named the instruments as The APS AI Plan, Responsible Use of AI Policy, AI Impact Assessment Tool and AI Technical Standard provide common scaffolding.

Scaffolding is a fair word for it, and it is also the problem. Four documents named in one breath sound like one regime. They are not.

The AI policy, which is mandatory

The Policy for the responsible use of AI in government is the instrument with obligations in it. The current text says This version of the policy (v2.0) is effective 15 December 2025, and that The first version (v1.1) took effect on 1 September 2024. On coverage it is equally direct: It applies to all non-corporate Commonwealth entities, with some exceptions.

That scope line is the first thing to check against your own employer. Non-corporate Commonwealth entities are the departments and the agencies that are legally part of the Commonwealth. Corporate Commonwealth entities, which are legally separate, are not captured by that sentence, and neither are state and territory agencies, which run their own frameworks.

Where it does apply, the policy sets mandatory requirements in eight areas: accountable officials, transparency statements, developing a strategic approach to AI adoption, operationalising the responsible use of AI, AI use case accountability, internal use case registers, staff training on AI, and AI use case impact assessment.

Two of those are worth pausing on because they produce artefacts an outsider can look for. A transparency statement is a public document, so an agency's compliance with that requirement is visible from outside. An internal use case register is not public, but it means the agency is expected to be able to answer the question of what AI it is running, and that is the sort of thing an audit, an estimates hearing or a freedom of information request can reach.

The three that guide

The AI technical standard is the longest and most detailed of the four, and it is explicitly not an obligation. In its own description it provides practical guidance for technical specialists and business owners embedding AI in government systems, and it outlines best practice for the end-to-end design, development, deployment, and use of AI systems, reinforcing the AI Ethics Principles rather than creating duties. It was last updated on 22 August 2025 and is organised as numbered statements across the AI lifecycle, from defining an operational model and enabling AI auditing through data, design, evaluation, monitoring and decommissioning.

The agentic AI addendum sits on top of it and is the newest thing in the set, last updated on 4 June 2026. It says agencies exploring, developing or using agentic AI are expected to apply this addendum in conjunction with the AI technical standard, and that it highlights best practices key considerations for the secure and governed implementation of agentic AI systems. One line in it is easy to miss and useful: Some criteria within this addendum may also apply to non-agentic forms of AI, for example memory management. An agency that has decided it is not doing agentic AI may still find parts of the addendum relevant to what it is doing.

The AI Plan for the Australian Public Service 2025 is the third of the guiding documents, organised around trust, people and tools, with a deliverables appendix. A plan is a statement of intent with dates against it, which makes it the document to hold the government to later rather than the one that tells an agency what it must do today.

The framework nobody points you at, which also binds

The four documents above are the ones named in the speeches and the briefings. They are not the whole of what binds. The Protective Security Policy Framework is a security framework rather than an AI one, which is why it does not appear on the AI reading lists, and it reaches AI use anyway.

Its scope is the same population as the AI policy, and it is stated just as plainly. The framework's own page on who must follow it says the Directive on the Security of Government Business establishes the PSPF as Australian Government policy, and that this means non-corporate Commonwealth entities that are subject to the Public Governance, Performance and Accountability Act 2013 must apply the PSPF (to the extent consistent with legislation). For corporate Commonwealth entities and wholly-owned Commonwealth companies it represents better practice, which is the same split the AI policy draws. The current edition is PSPF Release 2026, issued on 1 July 2026.

Inside it are two kinds of instrument, and only one of them is an obligation.

Directions bind. The Secretary of the Department of Home Affairs may issue a direction to accountable authorities to manage a protective security risk, and The Accountable Authority of each entity must adhere to any Direction issued. Two of the current ones reach AI directly. Direction 001-2025, published 4 February 2025, requires Australian Government entities to prevent the access, use or installation of DeepSeek products, applications and web services and where found remove all existing instances from Australian Government systems and devices. That is a named AI service banned outright, and it is not in the AI policy. Direction 004-2025, published 22 October 2025, requires entities to adhere to the Commonwealth Technology Standard which sets out mandatory requirements and guidance relating to products, applications, and web services, a category most AI tools sit inside.

Policy advisories do not bind, and this is the trap in the name. The PSPF's own advisories page says they are publicly available guidance products that aim to assist entities in implementing the Protective Security Policy Framework. Two of them are about AI: Policy Advisory 001-2025, OFFICIAL Information Use with Generative Artificial Intelligence, published 7 October 2025, and Policy Advisory 001-2026, Cyber Security Readiness in the Frontier AI Era, published 27 May 2026. They are the most AI-specific documents in the framework and they are advice, which is exactly the confusion this article set out to clear up and then fell into itself.

So the count is two binding frameworks, not one. If you are checking yourself against the eight mandatory requirements in the AI policy and stopping there, the DeepSeek direction and the Commonwealth Technology Standard still apply to you.

Why the distinction is worth holding

Because the failure modes are opposite. Treat the standard as binding and you have invented obligations for yourself that nobody imposed, which is a way of making AI adoption slower and more expensive than the rules require. Treat the policy as advisory and you have missed eight actual requirements, one of which is publishing a statement about yourself.

The DTA's own speech is alert to the first failure. Poole argued that Governance should make the safe path the easy path, and warned that where it is slow or disconnected from real work, people find workarounds that create risks the organisation cannot see. That is a regulator-adjacent body saying that governance applied indiscriminately produces shadow AI, which is the outcome nobody wants.

What to do with this

If you work in a non-corporate Commonwealth entity, the eight mandatory requirements are the list to check yourself against, the transparency statement is the one with a public artefact attached, and the current PSPF Directions are the second list, because they bind the same entities and are maintained somewhere else entirely. If you sell to government, the policy tells you what your buyer must be able to demonstrate, and the technical standard tells you what good looks like to them without either of you having to pretend it is law. And if you are looking at agentic systems, the addendum is four months old and is where the current thinking sits.

None of this is the law that applies to AI generally in Australia. It governs the Commonwealth's use of AI on itself. The rules that reach private-sector AI are a different and much less settled question, and we have covered the one that already has a date on it.

Sources

  1. Policy for the responsible use of AI in government, Version 2.0, digital.gov.au (read 25 August 2026): that v2.0 is effective 15 December 2025 and v1.1 took effect 1 September 2024; that it applies to all non-corporate Commonwealth entities with some exceptions; and the eight areas of mandatory requirement listed above.
  2. Technical standard for government's use of artificial intelligence, digital.gov.au (read 25 August 2026): that it provides practical guidance and outlines best practice for the end-to-end design, development, deployment and use of AI systems, that it reinforces the AI Ethics Principles, its last update of 22 August 2025, and the lifecycle organisation of its numbered statements.
  3. Agentic AI addendum to the AI technical standard, digital.gov.au (read 25 August 2026): that agencies using agentic AI are expected to apply it in conjunction with the technical standard, that it highlights best practice for secure and governed implementation, that some criteria may also apply to non-agentic AI such as memory management, and its last update of 4 June 2026. The same page carries the contents of the AI Plan for the Australian Public Service 2025 in its navigation, including the trust, people and tools structure and the deliverables appendix.
  4. Digital Transformation Agency, Speech: Moving from AI pilots to whole-of-government scale, published 7 August 2026 (read 25 August 2026): delivered by Lucy Poole, Deputy CEO, Strategy, Planning and Performance Division, at the 2026 Tech in Gov event on 4 August 2026, and marked check against delivery. Source of the four quoted passages about pilots and scale, capability, the common scaffolding, and governance making the safe path the easy path.
  5. Applying the Protective Security Policy Framework, protectivesecurity.gov.au (read 29 August 2026): that the Directive on the Security of Government Business establishes the PSPF as Australian Government policy; the quoted sentence that non-corporate Commonwealth entities subject to the PGPA Act must apply the PSPF to the extent consistent with legislation; and that it represents better practice for corporate Commonwealth entities and wholly-owned Commonwealth companies.
  6. Protective Security Directions under the PSPF, protectivesecurity.gov.au (read 29 August 2026): the quoted line that the Accountable Authority of each entity must adhere to any Direction issued; Direction 001-2025 on DeepSeek products, applications and web services, published 4 February 2025, and its quoted requirement; and Direction 004-2025 on Commonwealth Technology Management, published 22 October 2025, and its quoted requirement to adhere to the Commonwealth Technology Standard.
  7. Policy Advisories under the PSPF, protectivesecurity.gov.au (read 29 August 2026): the quoted description of policy advisories as publicly available guidance products; Policy Advisory 001-2025, OFFICIAL Information Use with Generative Artificial Intelligence, published 7 October 2025; and Policy Advisory 001-2026, Cyber Security Readiness in the Frontier AI Era, published 27 May 2026.
  8. PSPF Annual Release, protectivesecurity.gov.au (read 29 August 2026): that PSPF Release 2026 was issued on 1 July 2026 and that the release carries mandatory requirements.

How we checked this. All four instruments were read on digital.gov.au and dta.gov.au on 25 August 2026, and the quotations are from those pages rather than from any summary of them. The characterisation of the policy as the only mandatory instrument of the four is ours, and rests on the language each document uses about itself: the policy states mandatory requirements, while the technical standard describes itself as practical guidance and best practice and the addendum describes itself as best practice guidance. The description of what a non-corporate Commonwealth entity is, and the observation about which requirements produce artefacts visible from outside, are ours. The speech is marked check against delivery by the DTA, so it is quoted as published rather than as spoken. We have not sought comment from the DTA.

Spotted an error? Tell us and we will check it against the sources and log the outcome here.