AI Policy Wiki
Dashboard

Australia Voluntary AI Safety Standard (2024)

high confidence · updated 2026-07-17

Australian government's voluntary framework for safe and responsible AI, issued September 2024. Ten guardrails applicable across the AI supply chain; precursor to a proposed mandatory framework for AI in high-risk settings.

The Voluntary AI Safety Standard is a non-binding framework for safe and responsible AI issued by Australia's Department of Industry, Science and Resources (DISR) on 5 September 2024. It sets out ten guardrails that apply across the AI supply chain and is designed as a practice framework and an on-ramp to anticipated mandatory requirements. It was released alongside a companion consultation document, the Proposals Paper for Introducing Mandatory Guardrails for AI in High-Risk Settings, which contemplates a future binding regime for AI in high-risk settings (Source: DISR Voluntary AI Safety Standard, Sept 2024).

The Standard was developed by DISR with input from the National AI Centre (hosted within CSIRO's Data61) and informed by the Responsible AI Network.

Status and timeline

Australian AI governance policy developed through a sequence of consultation documents. In June 2023, the government released the initial "Safe and Responsible AI in Australia" discussion paper. In January 2024, it published an Interim Response that foreshadowed a mandatory-guardrails approach. On 5 September 2024, DISR released the Voluntary AI Safety Standard and simultaneously opened consultation on the Mandatory Guardrails Proposals Paper; that consultation closed on 4 October 2024.

Through 2025 and 2026 the government continued to consider a mandatory framework. No bill had been introduced as of April 2026, and the parallel mandatory-guardrails proposal remained subject to government consideration, with an indicative legislative decision expected in 2026.

The mandatory framework was announced on July 15, 2026, when Prime Minister Anthony Albanese unveiled mandatory "Australian Standards for AI" and an Office of AI within the Department of the Prime Minister and Cabinet, with legislation expected in early 2027 (Source: substack.com). The announcement converts the voluntary standard's anticipated "on-ramp" role into a concrete legislative program.

Scope

The Standard applies to all organisations in the Australian AI supply chain, including developers, deployers, and users. It is voluntary, imposing no legal obligations. It applies across AI types, including generative AI, predictive AI, and automated decision-making, and is horizontal rather than sector-specific: the guardrails apply regardless of deployment context.

The ten guardrails

The Standard sets out ten guardrails (Source: DISR Voluntary AI Safety Standard, Sept 2024):

  1. Accountability process. Establish, implement and publish an accountability process including governance, internal capability and a strategy for regulatory compliance.
  2. Risk management. Establish and implement a risk-management process to identify and mitigate risks.
  3. Data governance. Protect AI systems and implement data-governance measures to manage data quality and provenance.
  4. Testing and monitoring. Test AI models and systems to evaluate performance and monitor systems once deployed.
  5. Human control. Enable human control or intervention in an AI system to achieve meaningful human oversight across the life cycle.
  6. User disclosure. Inform end-users regarding AI-enabled decisions, interactions with AI, and AI-generated content.
  7. Contestability. Establish processes for people impacted by AI systems to challenge use or outcomes.
  8. Supply-chain transparency. Be transparent with other organisations across the AI supply chain about data, models and systems to help them effectively address risks.
  9. Records and documentation. Keep and maintain records to allow third parties to assess compliance with guardrails.
  10. Stakeholder engagement. Engage your stakeholders and evaluate their needs and circumstances, with a focus on safety, diversity, inclusion and fairness.

The proposed mandatory guardrails for high-risk settings would track guardrails 1–9 closely, replacing guardrail 10's stakeholder-engagement focus with conformity assessment (audit/assurance and public certification).

Mandatory framework proposal

The Proposals Paper, released in parallel with the Standard, contemplates a mandatory regime for AI in "high-risk settings". Three options were consulted on: Option 1, a domain-specific approach that adapts existing sectoral regulators; Option 2, a framework approach using cross-economy legislation with principles; and Option 3, a whole-of-economy AI Act in the form of a comprehensive, EU-style statute. The indicative government preference, per the January 2024 Interim Response, was toward Option 2 or a hybrid: a framework law for high-risk settings with existing regulators retained for sectoral enforcement.

The definition of "high-risk" contemplated in the Proposals Paper covers risk to individual rights (legal, health, financial, safety effects); risk to physical or mental wellbeing; risk to groups and systemic societal risk; and specific high-risk use cases to be enumerated, which had not yet been finalised.

Governance structure

Australia's AI governance is distributed across multiple bodies rather than led by a single AI regulator. The Department of Industry, Science and Resources is the lead policy ministry. The National AI Centre (CSIRO Data61) provides practice guidance and capability building. The Office of the Australian Information Commissioner (OAIC) handles privacy-adjacent AI regulation via the Privacy Act, the Australian Competition and Consumer Commission (ACCC) provides consumer-protection-based AI oversight, and the eSafety Commissioner covers online safety-related AI, particularly generative content. Sectoral regulators including APRA, TGA, and ASIC retain their existing AI oversight within their domains.

Australia does not yet have an AI Safety Institute, though participation in the international AISI network has been discussed; an Australian AISI was not established as of April 2026. Australia is the only AUKUS member without an operational AISI as of 2026, and its connections to the UK and US institutes run through the Bletchley, Seoul, and Paris framework rather than a domestic institutional equivalent.

Comparison with other approaches

DimensionAustralia VAISS[[eu-ai-actEU AI Act]][[south-korea-ai-basic-actKorea AI Basic Act]][[japan-ai-promotion-actJapan AI Promotion Act]][[singapore-mgf-genaiSingapore MGF]]
Legal statusVoluntary; mandatory proposedBinding lawBinding law (eff. 2026)Binding law; no penaltiesVoluntary guidance
Structure10 guardrails (voluntary) + proposed mandatory regimeFour-tier risk + GPAIHigh-impact tier + AI of national significanceCabinet coordination + soft lawNine dimensions
Sector coverageHorizontalHorizontalHorizontalHorizontalHorizontal (genAI focus)
Individual rightsDisclosure + contestability guardrails (non-binding)Transparency + complaintsExplanation + contestNoneShared responsibility
PenaltiesNone (voluntary)Up to €35M / 7% turnoverKRW 30M / infractionNoneNone
AISINone yetEU AI OfficeK-AISI (statutory)AISI JapanNone

Australia's approach is characterised by an explicit two-stage sequencing: a voluntary standard now, with a mandatory framework under consideration. The Standard is deliberately aligned with ISO/IEC 42001, the international AI-management-system standard, which supports interoperable compliance. The governance model is multi-regulator rather than AI-regulator-led, preserving existing sectoral capacity rather than creating a new central regulator, a posture similar to the UK's before its Data (Use and Access) Act. Structurally and philosophically it most closely tracks Singapore's approach, which is voluntary, interoperable, and practice-focused. Within the Indo-Pacific, the Australian model differs from Korea's comprehensive statute, Japan's pro-innovation statute, Singapore's purely voluntary guidance, and China's content-control model.

Tensions and critiques

Several points of contention surround the framework. The voluntary-to-mandatory transition carries uncertainty: as of April 2026 the mandatory framework remained under government consideration without a firm legislative timetable, complicating industry planning. The scope of the "high-risk" definition was contested, with industry bodies including the Tech Council of Australia and the Business Council of Australia lobbying for a narrower scope, while civil society groups including the Human Rights Commission and Digital Rights Watch argued for broader coverage including biometric AI and automated welfare-decision systems.

The Robodebt scheme (2015–2020), an automated welfare-debt-recovery program that the 2023 Royal Commission found to be unlawful, is a recurring point of reference in Australian AI governance debate. Civil society cites Robodebt as evidence that voluntary guardrails are insufficient; the government cites it as a reason to regulate carefully without stalling innovation. The Standard's alignment with ISO/IEC 42001 is described as creating a credible compliance pathway for organisations already pursuing that certification, while also creating dependence on international standards bodies over which Australia has limited direct influence.

As a federation, Australia faces questions of federal-state allocation, similar to Brazil and Canada, because some AI-relevant domains such as healthcare, education, and policing are state-level; the mandatory-framework proposal does not fully address this allocation. An Australian federal election is due by September 2028, and an earlier election or change of government could reshape the mandatory-framework proposal.

Commentators describe the Australian approach as a test of a "voluntary-first, mandatory-later" sequencing model that several jurisdictions are watching, and as structurally similar to the UK's posture of a voluntary and sectoral base with a comprehensive framework deferred.

Relationships

Sources

  • Voluntary AI Safety Standard source summary
  • DISR Voluntary AI Safety Standard: https://www.industry.gov.au/publications/voluntary-ai-safety-standard
  • DISR Proposals Paper on Mandatory Guardrails for AI in High-Risk Settings (Sept 2024)
  • Ashurst, "Australia: New AI safety 'guardrails,' and a targeted approach to high-risk settings"
  • Herbert Smith Freehills, "Australia releases new mandatory guardrails and voluntary standards on AI"
  • White & Case, "Australia launches new AI guidance"
  • Corrs Chambers Westgarth, "Australia releases proposed mandatory guardrails for AI regulation"