Privacy, cyber, and AI regulation for Australian operators
The Real Bytes index of every Australian regulatory page we publish. Organised into four reading lanes: Privacy, AI governance, Cyber, and what boards ask us next. Each item has a status indicator and a one-line description so you can scan the whole picture in under a minute.
Need the dates rather than the obligations? Open the regulatory calendar for a chronological view of every commencement and consultation we track.
All in one place
Nine pages, four reading lanes
Sourced and dated
Each page references primary regulators
Operationally grounded
Tied to Microsoft 365 and field controls
The Privacy Act, the tort, and the OAIC.
Three movements changing the Australian privacy landscape together: the statutory tort already in force, the pending removal of the small business exemption, and the OAIC's strengthened enforcement powers.
Voluntary today. Mandatory standards on the way.
Australia's AI framework is still voluntary, but the direction is now settled: mandatory Australian AI Standards were announced in July 2026, with legislation expected in early 2027. Insurers, boards and procurement teams already reference the Voluntary AI Safety Standard, and the OAIC has clarified how the Privacy Act applies to AI tooling.
ASD, the Cyber Security Act, and the insurance market.
The technical baseline most Australian businesses are already working through. ASD is evolving Essential Eight into a successor framework while the Cyber Security Act 2024 has introduced new reporting obligations, and the insurance market has hardened proposal form requirements.
CPS 230 is the resilience standard. CPS 234 is still the cyber one.
APRA Prudential Standard CPS 230 Operational Risk Management commenced on 1 July 2025 for most regulated entities, and applied to smaller entities from 1 July 2026, so it now covers the whole regulated population. It consolidates five prior standards covering operational risk, business continuity and outsourcing, and makes boards accountable for critical operations, tolerance levels, continuity testing and the material service provider register.
What boards and executive teams ask us next.
Once a board is aware of the regulatory picture, the next questions are operational. How is this reported? Who is accountable? What does our incident response actually look like? Three pages cover the practical follow-up work.
The pages above are the framing
Real Bytes does the operational work behind each one.
Privacy Act readiness, Voluntary AI Safety Standard alignment, Cyber Security Act 2024 reporting playbooks, Essential Eight maturity uplift, and the quarterly board reporting cadence that pulls it all together. If you are not sure where to start, we will walk a board or executive team through the picture in a single session.
This page is general information drawn from publicly available Australian government and legal sources. It is not legal advice. For decisions affecting your business, refer to the linked primary sources or seek qualified advice.
Keep exploring
Related services, locations and industries
Explore how this connects across our wider offering.

Remote Support