Current at August 2026. This is general information and it is not legal advice.
The short answer for a small or mid sized Australian business is that there is no AI-specific statute you have to comply with. What binds you is the law that already bound you before any of this existed.
The mandatory rules that did not arrive
On 5 September 2024 the Department of Industry, Science and Resources released a proposals paper on introducing mandatory guardrails for AI in high-risk settings. It arrived the same day as the Voluntary AI Safety Standard, which consists of 10 voluntary guardrails that apply to all organisations throughout the AI supply chain. Plenty of businesses read the coverage, missed which document was which, and concluded a compliance regime was coming.
Nearly two years later it has not arrived. The National AI Plan, published on 2 December 2025, sets the direction instead, and the direction is to work through law that already exists: Australia has strong existing, largely technology-neutral legal frameworks, including sector-specific guidance and standards, that can apply to AI and other emerging technologies.
On responsible practice the plan commits the government to explore practical ways to support responsible deployment, including through voluntary measures and shared guidance. Voluntary is the operative word, and it has stayed voluntary.
One thing worth knowing if you sell to government. The Policy for the responsible use of AI in government does carry mandatory requirements, including accountable officials, transparency statements and use case registers. It applies to all non-corporate Commonwealth entities. It does not apply to you. It may still turn up in a tender you answer, which is a different problem.
What is voluntary, and which parts are worth your time
There is a formal standard. Standards Australia adopted AS ISO/IEC 42001:2023 in February 2024, the first of its kind anywhere. It can be used by any size or type of organisation that intends to make use of AI for developing or delivering its products and services.
Certifying a 25 person business against a management system standard is a real project with a real cost, and almost none of the businesses we talk to need it. The structure underneath it is still worth reading, because it is the shape a large client or an insurer will eventually ask you to describe.
Closer to the ground, the National AI Centre published its Guidance for AI Adoption in October 2025. It is written for organisations rather than auditors and replaces the older ten guardrail framing: this updated and simplified guidance for industry evolves the Voluntary AI Safety Standard. If you read one government document about AI governance, read that one.
The obligations that actually bite
None of that is where a business this size gets into trouble. The exposure sits in law that is not about AI at all.
Consumer law is the clearest case. Treasury reviewed AI against the Australian Consumer Law and found that Australians enjoy the same strong consumer protections for AI products and services as they do for traditional goods and services. If an AI tool writes something wrong into a quote, a customer's rights are what they always were, and so are yours.
Then privacy, which under the turnover threshold is a genuine question rather than an assumption in either direction. Then employment law, professional obligations, and the confidentiality clauses in contracts you have already signed. That last one catches more people than the Privacy Act does.
Where that leaves you
Nothing here requires you to buy or certify anything. The honest checklist is shorter and duller than the compliance industry suggests: know whether privacy law covers you, read your own client contracts, write down which tools are approved and what may go into them, and name the person who owns it.