Australia decided not to regulate artificial intelligence with a dedicated Act. That decision is often read as a reduction in obligation. For an organisation buying an AI system, it is the opposite. When no regulator sets a control standard for the vendor, the only place those controls can exist is the contract you sign and the evaluation that precedes it.
What Australia decided, and when
In September 2024 the Department of Industry, Science and Resources published the Voluntary AI Safety Standard, ten guardrails covering accountability, risk, data governance, testing, human oversight, transparency, contestability, supply chain disclosure, record keeping and stakeholder engagement. Alongside it came a proposals paper on making a similar set of guardrails mandatory in high-risk settings.
The National AI Plan, released in December 2025, took a different path. It states that Australia has strong existing, largely technology-neutral legal frameworks that can apply to AI, and that the government is clarifying how those laws apply rather than writing new AI-specific ones. An AI Safety Institute was established to monitor, test and report on emerging capabilities and harms. No general AI Act followed.
On 15 July 2026 the Prime Minister announced Australian Standards for AI and established an Office of AI within the Department of the Prime Minister and Cabinet. Reading the release closely matters here. The standards it describes set rules for large data centres and AI training infrastructure: power underwriting, connection costs, water efficiency, siting. They are due to be legislated early in 2027. They do not set control requirements for the AI system a bank, insurer or hospital is buying from a vendor.

The obligation moved, it did not disappear
One date on that timeline binds directly. From 10 December 2026, Australian organisations must set out in their privacy policy how computer programs use personal information to make decisions that significantly affect people, under a new element of Australian Privacy Principle 1 (OAIC APP 1 guidelines). The duty sits with the organisation that arranged for the program to run, not the vendor who built it. We covered the contractual consequences of that in detail in what APP 1.7 means for your vendor contracts.
The same pattern repeats across the laws that already apply. APP 11 requires reasonable security steps for personal information, whoever holds it. Australian Consumer Law does not exempt a claim because a model produced it. For critical infrastructure, the enhanced CIRMP Rules pull major suppliers inside the compliance boundary, which we set out in the enhanced CIRMP supply chain obligations. For APRA-regulated entities, CPS 230 makes material service provider management a board-level obligation regardless of what the provider’s model does internally.
In every one of those, the accountable party is the decision owner. A vendor can decline to answer a question during evaluation. The regulator will still ask the decision owner.
The ten guardrails, read as procurement requirements
The Voluntary AI Safety Standard is more useful to a decision owner than its status suggests, because it was written with the supply chain in mind. Each guardrail carries its own procurement guidance describing what to establish with a supplier. Guardrail 2 asks you to understand your supplier’s risk management process. Guardrail 4 asks you to clarify who is accountable for monitoring once the system is live. Guardrail 8 asks you to agree roles and information flows across the whole lifecycle, through to end of life.

Read as a list of policies to write, the standard is a compliance exercise with no deadline and no enforcement. Read as a requirements schedule for a tender, it is a set of questions vendors have to answer while they still want your business. The difference is timing. Guardrail 9 asks for records that allow a third party to assess compliance. A vendor will produce those during a competitive evaluation. Two years into a contract, that same request becomes a change order.
What evidence is worth accepting
The guardrails align with ISO/IEC 42001:2023, the management system standard for AI, and with the NIST AI Risk Management Framework. Both give you a way to convert a vendor claim into something checkable.
Certification against ISO/IEC 42001 is a genuine signal, with one caveat that decides most of its value: read the scope statement on the certificate. A management system certificate covers a defined set of activities and locations. It is common for a vendor to hold certification covering a platform business unit while the product on your shortlist sits outside that boundary, or for the certificate to cover the development process without covering the hosted service you would consume. The certificate number and the scope wording take five minutes to check and are the highest-yield question in an AI evaluation.
Beyond certification, ask for three things that vendors either have or do not. Model and system test results with the evaluation method named. A written statement of expected use, tested capability and known limitation, which is guardrail 9 in plain language. And a data statement covering where inputs are processed, whether your data trains the vendor’s models, and what happens to derived artefacts when the contract ends. Where those answers are unavailable, that is itself a scored result rather than a gap to be filled later.
Four gates that hold
Most AI purchases that go wrong were not evaluated badly. They were evaluated in the wrong order, with a commercial decision already made and the assessment fitted around it. Sequencing fixes more than scoring rigour does.

The purpose gate is the one most often skipped, and skipping it is what makes the rest unanswerable. Until the organisation can state which decision the system contributes to and who is affected by the output, there is no basis for deciding how much oversight is proportionate, no way to know whether APP 1.7 applies, and no way to weight the evaluation criteria. Vendors are usually happy to define the purpose on your behalf. That produces a purpose their product satisfies.
Where this leaves an Australian decision owner
The regulatory position is stable enough to plan around. There is no AI Act coming for enterprise deployment. The standards being legislated in 2027 govern the infrastructure layer. Existing privacy, consumer, security and sector-specific law applies to AI the same way it applies to anything else, and the accountable party under all of it is the organisation running the system.
That makes the evaluation and the contract the entire control surface. It also means the work is available to any organisation willing to do it, without waiting for a compliance deadline to force the question. Our enterprise AI vendor selection criteria sets out the five evidence lenses in more depth, and how to manage procurement risk in IT and cybersecurity covers the wider decision-quality problem these gates sit inside.
Common questions
Does Australia have mandatory AI regulation in 2026?
No general AI Act applies to enterprise AI deployment. The National AI Plan of December 2025 relies on existing technology-neutral law, sector regulators and the AI Safety Institute. The Australian Standards for AI announced on 15 July 2026 are directed at large data centres and AI training infrastructure and are expected to be legislated early in 2027.
Is the Voluntary AI Safety Standard worth using if it is not enforceable?
Yes, as a procurement instrument rather than a compliance one. Each of the ten guardrails carries procurement guidance describing what to establish with a supplier, and those requirements are obtainable during a competitive evaluation in a way they are not after contract signature.
What should we ask an AI vendor about ISO/IEC 42001?
Ask for the certificate and read its scope statement. Certification covers a defined set of activities, sites and services, and the product you are buying is not always inside that boundary. Confirm the certification body, the scope wording and the expiry date before the claim is scored.
Who is accountable when a purchased AI system produces a harmful outcome?
Under Australian privacy, consumer and sector-specific law, the accountable party is generally the organisation that deployed the system, not the vendor that built it. From 10 December 2026 that includes disclosing in a privacy policy how computer programs use personal information to make decisions that significantly affect people.
How does AI procurement differ from ordinary technology procurement?
The decision structure is the same, and two things change. Vendor claims describe probabilistic behaviour that varies with your data, so they need test evidence rather than a specification. And the obligations attach to how you use the system rather than to the product itself, which makes the documented purpose a prerequisite for the rest of the evaluation.
Related guidance: AI procurement expertise, what is vendor due diligence, third-party risk management, structured vendor comparison methods, and guided vendor evaluations.



