Policy

The only binding rule on Commonwealth AI: what it actually makes an agency do, and the deadlines

We have written that four documents govern how the Commonwealth uses AI and that only one of them binds. This is what that one contains. The Policy for the responsible use of AI in government reached version 2.0 on 15 December 2025 and applies to all non-corporate Commonwealth entities. It carries eight mandatory requirements. One of their deadlines has already passed, a cluster of them lands twelve months from December 2025, and everything an agency is already running has to be brought into line by 30 April 2027.

First question: does it apply to what you are building?

Most of the argument about AI rules skips this, and it is the part that decides everything else. The policy does not cover every use of AI in government. Appendix C sets out the in-scope criteria, and a use case is in scope if any of them apply.

The five are: that the use, misuse or failure of AI could lead to more than insignificant harm to individuals, communities, organisations, the environment or the collective rights of cultural groups including First Nations peoples; that the AI will materially influence administrative decisions affecting those same groups; that It is possible the public will directly interact with, or be significantly impacted by, the AI or its outputs without human review; that The AI is designed to use personal or sensitive data or security classified information; or that the DTA has deemed it elevated risk.

And the policy is equally clear about what falls outside. This policy has been designed to exclude incidental and lower risk uses of AI that do not meet the criteria, which it illustrates as off-the-shelf software with AI features such as grammar checks and internet searches with AI functionality. So the officer using an AI spellchecker is not triggering a governance process, and that is deliberate.

There is a second list, of areas to consider carefully rather than a test: recruitment and other employment-related decision making, automated decision making of discretionary decisions, administration of justice and democratic processes, law enforcement and profiling and border control, health, education, and critical infrastructure. The policy is careful about their status: While use cases in these areas are not automatically high-risk, they are more likely to involve risks needing attention.

The eight mandatory requirements

The policy lists them as accountable officials, transparency statements, a strategic approach to AI adoption, operationalising responsible use, AI use case accountability, internal use case registers, staff training, and AI use case impact assessment. In practice they fall into three groups.

Who is answerable

Agencies must designate accountable official(s) to take accountability for implementing this policy, following the Standard for accountability, and must tell the DTA who they are. Separately, each in-scope use case needs a designated accountable use case owner, within twelve months of the policy taking effect.

What has to be written down

A publicly available AI transparency statement, reviewed at least annually. A strategic position: Agencies must develop a strategic position on AI adoption within 6 months of this policy taking effect, which is the deadline that has already gone by. And a register: Agencies must create a register of in-scope AI use cases within twelve months, and then Agencies must share the register with the DTA every 6 months.

That last one is worth pausing on. It is not a one-off compliance artefact. It is a standing reporting obligation into the central agency, twice a year, listing what AI each department is running.

What has to happen before deployment

Two things. Agencies must implement mandatory training for all staff on responsible AI use within 12 months of this policy taking effect, and an approach to embed responsible AI practices in the same window, which must include a pathway for staff to report AI safety concerns and pathways for the public to do the same.

Then the assessment itself. Agencies must assess all new AI use cases against the in-scope criteria during the design phase, documented. If a use case is in scope, an AI use case impact assessment must be commenced at design stage and finalised, with risk treatments applied, before deployment.

The assessment, and the escape hatch that is not one

The Australian Government publishes an AI impact assessment tool for this. Its own description is modest: It helps teams identify, assess and manage AI use case impacts and risks against Australia's AI Ethics Principles.

Agencies do not have to use it. The policy allows either the tool or an internal process that integrates all provisions of the impact assessment tool. That sounds like a loophole until you read the condition attached: the internal process must be consistent and it delivers the same (or a higher) risk outcome for inherent and residual risk. An agency may bring its own process, but not a laxer one, and it must be able to revise that process whenever the tool is updated.

The dates, in one place

Version 2.0 took effect on 15 December 2025, and the periods run from there. The six month requirement, the strategic position, fell due in mid-2026 and has passed. The twelve month requirements, being accountable use case owners, the internal register, the operationalising approach, mandatory staff training and beginning use case assessments, fall due around the end of 2026. And for anything already running there is a flat date: For existing use cases not yet assessed, agencies must determine whether they are in scope of this policy and apply all relevant policy actions by 30 April 2027.

We have deliberately not converted the six and twelve month periods into exact days. The policy expresses them as periods from the day it took effect, and an agency counting its own deadline should count from the source rather than from us.

Our view

Labelled as opinion, on the provisions quoted above. This is a better document than the public debate about Australia's absent AI legislation would suggest, and it is worth saying so plainly: it has a scope test that excludes trivia, a named human answerable for each use case, a register that flows to the centre twice a year, and an assessment that must be finished before deployment rather than after. Several of those are things critics have called for in statute and which already exist in practice for the Commonwealth's own use of AI.

What it is not is a law. It binds agencies through policy, not through a provision anybody outside government can enforce, and its remedy for non-compliance is not stated in the way a statutory obligation's would be. That is the honest limit, and it is the same pattern this masthead keeps finding on this beat: real machinery, carefully built, with the enforcement layer left soft on purpose.

The thing we would watch is the register. Twice-yearly reporting to the DTA of every in-scope AI use case is, on paper, the most complete picture of government AI use anyone will hold. Whether any of it becomes public is a separate question, and nothing in the policy says it will.

What this page does not tell you

It does not tell you whether any particular agency has complied, and we make no claim about any of them. Non-corporate Commonwealth entities are the scope, with exceptions the policy notes, so it does not automatically cover corporate Commonwealth entities, state agencies or the private sector. This is a description of a policy document, not legal advice, and the policy states it will evolve, so check the version number before relying on a detail here.

Sources

  1. Digital Transformation Agency, Policy for the responsible use of AI in government, version 2.0 (PDF, 22 pages, downloaded and read 26 Aug 2026): every mandatory requirement quoted above, being the transparency statement and its annual review, the strategic position within six months, accountable officials and accountable use case owners, the internal use case register and the six-monthly share with the DTA, the approach to operationalise responsible AI and its minimum contents, mandatory staff training within twelve months, the assessment of all new use cases against the in-scope criteria, the choice between the impact assessment tool and an internal process, the same-or-higher risk outcome condition, the 30 April 2027 date for existing use cases, and Appendix C in full including the five in-scope criteria, the exclusion of incidental uses and the seven areas for careful consideration.
  2. Digital Transformation Agency, Policy for the responsible use of AI in government, policy landing page (read 26 Aug 2026): that version 2.0 is effective 15 December 2025, that the first version 1.1 took effect on 1 September 2024, that it applies to all non-corporate Commonwealth entities with some exceptions, and the list of the eight areas for which departments and agencies must meet mandatory requirements.
  3. Digital Transformation Agency, Artificial intelligence impact assessment tool (read 26 Aug 2026): that the tool is for Australian Government teams working on an AI use case and what it is described as helping those teams do.

Methodology. The requirements are quoted from the policy PDF rather than from the web summary of it, because the web pages paraphrase and the deadlines only appear in full in the document. Where this page summarises a requirement rather than quoting it, that is signalled. We have not converted the six and twelve month periods into exact dates, because the policy expresses them as periods and an agency should count from the source. A route note for anyone following us: the policy is at digital.gov.au/ai/ai-in-government-policy, not under /policy/ai/, which is where several links appear to point and which returns 404. No agency, official or company is named or assessed here, and we make no claim about anyone's compliance. We have not sought comment from the DTA.

Spotted an error, or has the policy moved to a new version? Tell us and we will check it against the policy and log the outcome here.