← Back to Blog

Australian Government AI Legislation 2026 — What Businesses Need to Know

 ·  By Paul Harvey

Australia does not have a standalone AI Act — instead, AI obligations for Australian businesses in 2026 come from three sources: mandatory DTA policy requirements for government contractors (effective June and December 2026), Privacy Act automated decision-making disclosure obligations (effective December 2026), and existing laws including the Australian Consumer Law and the Cyber Security Act 2024. Mycelium 365 helps Australian businesses deploy AI within a compliant Microsoft 365 environment.

Editor's note (18 July 2026): This article was originally published on 11 July 2026. On 15 July 2026 the Prime Minister announced a significant shift away from Australia's voluntary AI posture toward a mandatory, whole-of-government framework. We've added a new section below ("July 2026 update: Australia moves to a mandatory AI framework") and refreshed the meta description. The rest of the article — covering the DTA policy, Privacy Act ADM obligations, the Cyber Security Act 2024 and existing consumer law — remains accurate and is unchanged.

July 2026 update: Australia moves to a mandatory AI framework

On 15 July 2026, Prime Minister Anthony Albanese delivered a keynote titled "AI in Australia's interests" signalling a clear pivot from the voluntary posture Australia has taken to date. The Government intends to introduce a set of Australian Standards for AI that will apply across the economy and, for the first time, carry mandatory obligations rather than relying on guidance and self-attestation.

A few elements stand out for Australian businesses and their IT partners:

  • Mandatory rules for large data centres. The Standards are expected to place legal obligations on data centre operators to underwrite their own new power supply and pay their full share of grid connection costs — an unusually direct intervention aimed at ensuring AI compute growth does not push its costs onto other electricity users.
  • A new Office of AI. An Office of AI has been established immediately inside the Department of the Prime Minister and Cabinet to lead implementation and coordinate across portfolios.
  • Copyright protections for Australian creative works. The framework will restrict the use of Australian creative works to train AI systems without the artist retaining control over price and value — a meaningful signal for any business fine-tuning or licensing models on Australian content.
  • Timeline. National Cabinet is expected to consider the Standards in August 2026, with legislation anticipated to be introduced in Parliament in early 2027.

For most Australian SMBs the near-term compliance picture (DTA, Privacy Act ADM, Cyber Security Act 2024) hasn't changed — those obligations still land in June and December 2026. What has changed is the direction of travel: the "wait for guidance" strategy is no longer viable. Businesses that stand up basic AI governance now — a use-case register, an impact assessment process, clear approval and incident-reporting steps — will be in a materially better position when the Australian Standards for AI move from announcement to enforceable rules.

Source: Prime Minister of Australia, AI in Australia's interests, 15 July 2026.

What AI legislation actually applies to Australian businesses in 2026?

Australia rejected a standalone AI Act in December 2025, opting instead for a voluntary framework that leans on existing laws. The National AI Plan 2025 sets strategic direction but is non-binding for private businesses. What IS binding is a patchwork of pre-existing statutes now applied to AI use cases: the Privacy Act 1988 for businesses over $3M annual turnover that handle personal data in automated decisions; the Digital Transformation Agency (DTA) Policy for Responsible Use of AI in Government for federal contractors; the Cyber Security Act 2024 for critical infrastructure entities; and the Australian Consumer Law for misleading AI capability claims. The AI Safety Institute became operational in early 2026 with $29.9M in funding but holds an advisory role only — it has no enforcement powers. In practical terms, most Australian businesses will face AI obligations through existing laws rather than through new AI-specific legislation, which places the compliance burden on internal governance rather than waiting for a regulator to prescribe controls.

What are the DTA mandatory AI requirements — and do they affect your business?

The Digital Transformation Agency's Policy for Responsible Use of AI in Government Version 2.0 came into effect on 15 December 2025 and introduced its first mandatory requirement on 15 June 2026: all 94 non-corporate Commonwealth entities must maintain an internal AI use case register with a named accountable owner for each use case, and every APS staff member must complete foundational AI training. The remaining DTA obligations commence in December 2026 and include completing an AI Impact Assessment before deploying any AI system, implementing formal approval and oversight processes, and reporting AI incidents. Why does this matter for private businesses? Any organisation supplying services to the Australian Government — IT providers, professional services firms, defence contractors, consultancies — must understand and align with these requirements. Government clients are already writing DTA alignment into procurement documents, and non-alignment increasingly disqualifies bids.

What does the Privacy Act automated decision-making requirement mean for your business?

From 10 December 2026, the Privacy Act 1988 will require all regulated entities — businesses with more than $3M annual turnover, plus health, education and financial services providers regardless of turnover — to disclose in their privacy policy when automated systems make or significantly influence decisions affecting individuals. Disclosures must cover the kinds of decisions being automated and the kinds of personal information used. This is the second tranche of Privacy Act reforms following the Privacy and Other Legislation Amendment Act 2024. The practical implications are wide: businesses using AI for hiring decisions, credit assessments, customer segmentation, insurance underwriting, or automated service responses need to update their privacy policies before December 2026. Microsoft 365 environments running Copilot for automated drafting or decision support also fall within scope where personal information is involved. Waiting until late 2026 leaves no room to audit AI use cases and rewrite disclosures.

How does the Cyber Security Act 2024 affect businesses using AI?

The Cyber Security Act 2024 introduced Australia's first mandatory ransomware payment reporting regime — 72 hours for critical infrastructure entities — along with a Cyber Incident Review Board and new smart device security standards. For AI specifically, systems connected to operational technology or used within critical infrastructure sectors (mining, energy, defence, healthcare, financial services) fall under Security of Critical Infrastructure (SOCI) Act obligations, including risk management program requirements and incident reporting. Separately, the Treasury Laws Amendment Act doubled corporate penalties effective 28 March 2026 — a maximum of $100M per contravention — and those penalties apply to misleading AI capability claims prosecuted under the Australian Consumer Law. Any business making claims about its AI systems to clients, in marketing collateral, or in sales conversations must ensure those claims are accurate and substantiated. See our guide to the Cyber Security Act 2024 for more detail on critical infrastructure obligations.

What is the Unfair Trading Practices Bill 2026 and how does it affect AI?

The Competition and Consumer Amendment (Unfair Trading Practices) Bill 2026, introduced on 1 April 2026, explicitly targets AI-enabled dark patterns — algorithmic manipulation of consumer choice, drip pricing, and unfair subscription practices. Proposed commencement is 1 July 2027 if passed. Maximum penalties are the greatest of $50M, three times the benefit gained, or 30% of adjusted turnover. Combined with the doubled penalty regime already in effect from March 2026, businesses using AI in consumer-facing contexts face a materially higher-risk environment. Practical examples that fall in scope include AI-powered dynamic pricing that manufactures artificial urgency, automated recommendation engines that push consumers toward higher-cost options without transparent rationale, and AI-generated urgency signals ("only 2 left!") in checkout flows. Businesses deploying AI on the consumer edge should be reviewing recommendation and pricing logic against the Bill's proposed prohibitions now.

What should Australian businesses do before December 2026?

A five-step action plan closes the gap before the December 2026 obligations bite:

  1. Conduct an AI use case inventory — document every AI tool in use across the business and what personal information each one processes.
  2. Review and update your privacy policy to include automated decision-making disclosure language before December 2026.
  3. If you supply services to the Australian Government, understand and align with the DTA's AI governance framework — government clients will require this in procurement.
  4. Audit AI capability claims in marketing, sales collateral, and client communications to ensure they are accurate and substantiated — the $100M penalty regime is now in effect.
  5. Deploy AI tools (particularly Microsoft 365 Copilot) within a governed Microsoft 365 environment with appropriate DLP policies, sensitivity labels, and access controls — not consumer AI tools that send data to third-party servers.

Our governance and compliance advisory service covers AI governance frameworks aligned with the DTA policy and Privacy Act obligations.

How does Microsoft 365 help Australian businesses meet AI governance obligations?

Microsoft 365 Copilot operates within the organisation's existing Microsoft 365 tenant boundary — data does not leave the tenant and is subject to existing DLP policies, sensitivity labels, and Entra ID access controls. Microsoft's Australian data residency (Azure Australia East) means data stays in Australia, addressing sovereign data concerns for government contractors and regulated industries. Microsoft Purview provides audit logging for AI interactions — precisely the kind of documentation required for Privacy Act disclosure obligations and DTA AI use case registers. Conditional Access policies in Entra ID control which users can access Copilot and under what conditions (device compliance, location, risk signals). For businesses preparing for the December 2026 Privacy Act requirements, a Microsoft 365 governance review is the practical first step — ensuring the environment is configured correctly before AI tools are enabled, rather than retrofitting controls after data has already been processed.

How Mycelium 365 helps Australian businesses prepare for AI compliance

Mycelium 365 helps Australian businesses deploy Microsoft 365 Copilot and AI automation tools within a governed, compliant environment — covering the Microsoft 365 permissions audit, DLP policy configuration, sensitivity labelling, and Entra ID controls required before AI deployment. Our AI Readiness Assessment is designed specifically for businesses preparing for the December 2026 Privacy Act obligations and DTA alignment requirements. We work with professional services firms, government contractors, defence businesses, and organisations across Melbourne, Sydney, Brisbane, Perth, Canberra, and Adelaide. For businesses ready to deploy AI, see our Managed AI Automation service.

Frequently asked questions

Does Australia have an AI Act in 2026?

No. Australia rejected a standalone AI Act in December 2025 in favour of a voluntary framework that relies on existing laws. AI obligations for Australian businesses come from the Privacy Act 1988, the DTA Policy for Responsible Use of AI in Government (for federal contractors), the Cyber Security Act 2024 (for critical infrastructure), and the Australian Consumer Law (for misleading AI claims).

When do the Privacy Act automated decision-making requirements take effect in Australia?

From 10 December 2026, the Privacy Act 1988 requires all regulated entities — businesses over $3M annual turnover plus health, education and financial services regardless of turnover — to disclose in their privacy policy when automated systems make or significantly influence decisions affecting individuals, including the kinds of decisions automated and the kinds of personal information used.

Do the DTA mandatory AI requirements apply to private businesses?

The DTA Policy for Responsible Use of AI in Government is mandatory for 94 non-corporate Commonwealth entities, not private businesses directly. However, any organisation supplying services to the Australian Government — IT providers, professional services firms, defence contractors — must understand and align with the framework because government clients increasingly require DTA alignment in procurement.

What are the penalties for misleading AI claims in Australia?

Under the Treasury Laws Amendment Act (effective 28 March 2026), maximum corporate penalties under the Australian Consumer Law doubled to $100M per contravention. These penalties apply to misleading claims about AI systems made to clients or in marketing. The proposed Unfair Trading Practices Bill 2026 would add further penalties of up to $50M, three times the benefit gained, or 30% of adjusted turnover for AI-enabled dark patterns.

What do I need to do before December 2026 to comply with Australia's AI obligations?

Five steps: (1) conduct an AI use case inventory documenting every AI tool and the personal information it processes; (2) update your privacy policy to include automated decision-making disclosure; (3) if you supply the Australian Government, align with the DTA AI governance framework; (4) audit AI capability claims in marketing and client communications; (5) deploy AI tools within a governed Microsoft 365 environment with DLP, sensitivity labels, and Entra ID controls.