Australia's reference AI frameworkSix chapters · sourced

Australia's Voluntary AI Safety Standard in practice

A practical adoption guide for Australian businesses deploying AI tools in production. Covers the ten guardrails, deployer obligations, the Privacy Act intersection, and an eight-week pathway.

Drawn from the Department of Industry, Science and Resources, the Office of the Australian Information Commissioner and the National AI strategy.

Ten guardrails

Practical, testable, documentable

Privacy Act intersects

OAIC guidance applies in full

Eight-week pathway

Proportionate adoption for SMBs

Editorially reviewed
Last reviewed18 May 2026
Sources verified18 May 2026
Effective fromVAISS published Sep 2024
01

The Australian AI landscape

Australia has chosen guidance first, then targeted regulation.

The Voluntary AI Safety Standard sits at the centre.

Rather than introducing AI-specific legislation, Australia has published the Voluntary AI Safety Standard (VAISS) through the Department of Industry, Science and Resources, alongside a separate proposals paper on mandatory guardrails for high-risk AI settings. Most Australian businesses currently sit under the voluntary regime, with sector-specific obligations layered on top.

01

VAISS published September 2024

The Voluntary AI Safety Standard provides ten guardrails for organisations developing or deploying AI in Australia. It is voluntary, but it is the reference framework government and regulators expect businesses to be moving toward.

Source · Voluntary AI Safety Standard
02

Mandatory guardrails proposed for high-risk AI

A separate proposals paper consulted on making the same guardrails mandatory for AI use in high-risk settings. The definition of 'high-risk' is the subject of ongoing consultation as of 2026.

Source · Mandatory guardrails proposals paper
03

Australia's AI Ethics Principles

The eight AI Ethics Principles published in 2019 remain in effect and underpin the VAISS. Businesses are encouraged to apply them across AI design, deployment and operation.

Source · AI Ethics Principles
04

National AI strategy

AI policy sits within the Department of Industry, Science and Resources. National strategy emphasises safe and responsible adoption alongside economic opportunity.

Source · National AI strategy
02

The ten guardrails

VAISS sets out ten practical guardrails.

Each is testable, evidenceable, and reviewable.

The guardrails are written to be implementable by Australian businesses of any size. They are not abstract principles. Each guardrail describes a control the business should be able to demonstrate, including in writing, on request from a customer or regulator.

01

G1 : Establish an AI governance and accountability process

Documented governance, with named accountability for AI decisions inside the organisation.

How we implement this

Drafted AI governance charter naming the policy owner, decision rights and review cadence. Aligned to the existing risk and audit committee where one exists. Templated for businesses that do not yet have one.

02

G2 : Establish a risk management process

Identify and assess AI risks to people, communities, society and the environment across the AI lifecycle.

How we implement this

Run an AI risk workshop covering each in-scope tool. Outputs a risk register that feeds the broader enterprise risk view, not a parallel artefact.

03

G3 : Protect AI systems and implement data governance

Cybersecurity controls, data quality, and lineage applied to AI systems and the data that trains them.

How we implement this

Microsoft 365 tenant baseline hardening, SharePoint oversharing audit, sensitivity labels rolled out with auto-labelling, conditional access enforced on Copilot and Azure OpenAI service principals.

04

G4 : Test AI models and systems, and monitor in deployment

Pre-deployment testing and ongoing monitoring against the intended use case.

How we implement this

Quarterly Copilot output sampling against documented use cases, plus Microsoft Purview audit log review for unusual prompt or response patterns. Findings logged and presented at the governance review.

05

G5 : Enable human control or intervention

Humans able to oversee, intervene in, override or disable AI systems at appropriate points.

How we implement this

Documented kill-switch procedure for each licensed AI tool and each Copilot Studio agent. Tested annually. Approval workflows on agents that take any action beyond information retrieval.

06

G6 : Inform end-users about AI-enabled decisions, interactions and content

Disclosure of AI involvement to end users, including content generated or modified by AI.

How we implement this

Privacy policy updated with the ADM transparency statement required from 10 December 2026. Customer-facing AI agents disclosed at first interaction. AI-generated marketing content labelled in the brief, not in the published asset.

07

G7 : Establish processes for people impacted by AI to challenge use or outcomes

Avenues for redress where an AI decision affects an individual.

How we implement this

Redress channel added to the privacy policy and complaints process. Mapped to the existing OAIC complaint pathway so it does not create a parallel obligation.

08

G8 : Be transparent with other organisations across the AI supply chain

Information sharing with customers, suppliers, deployers and developers about how the AI works and its limitations.

How we implement this

Vendor AI questionnaire added to procurement intake. Pre-filled answers prepared for customer due diligence so the business can respond in days, not weeks.

09

G9 : Keep records to enable third-party assessment

Documentation of design, training data, testing, deployment and monitoring sufficient for external audit.

How we implement this

AI tool register, prompt and output sampling logs, Copilot Studio agent specifications, and governance meeting minutes maintained in the existing SharePoint records site, retained under the standard Purview policy.

10

G10 : Engage with stakeholders, evaluate needs, and provide context

Stakeholder engagement integrated into AI lifecycle, including affected workforce and customers.

How we implement this

Staff briefing delivered before each significant AI rollout, including the four AI threat patterns from the AI threats brief. Feedback loop run quarterly through the governance group.

03

Accountability roles

Most businesses are deployers, not developers.

Obligations differ by role in the AI supply chain.

VAISS distinguishes between developers, deployers, and end users of AI systems. Most Australian SMBs and mid-market organisations operate as deployers (using Microsoft 365 Copilot, ChatGPT Enterprise, Gemini for Workspace, Anthropic Claude in workflows) rather than as developers of foundation models. The guardrails apply differently across these roles.

01

Developer

Builds and trains AI models. Carries the strongest obligations under G3, G4, G8 and G9.

02

Deployer

Integrates AI into business workflows. Carries strong obligations under G1, G2, G5, G6 and G10. Most Australian businesses fall here.

03

End user

Individual employee using AI tools. Operates within deployer-set policies. Personal use is generally not directly captured.

04

Supply chain transparency

Deployers should expect their AI vendors to provide the information needed to meet G8 obligations downstream. Vendor due diligence has become part of standard procurement.

04

Privacy Act intersection

VAISS does not replace existing law.

The Privacy Act 1988 still applies to AI use.

The OAIC has published specific guidance on the use of commercial AI products. Where AI processes personal information, the Australian Privacy Principles apply in full. Of particular note are APP 3 (collection), APP 6 (use and disclosure), APP 8 (cross-border disclosure) and APP 11 (security).

01

OAIC guidance on AI products

The OAIC published guidance on privacy and the use of commercially available AI products. Of note: entering personal information into a general-purpose AI tool may constitute a use or disclosure under the APPs.

Source · OAIC AI guidance
02

APP 8 cross-border disclosure

Many commercial AI products process data outside Australia. Deployers remain accountable for the acts of overseas recipients under APP 8.1 unless an exception applies.

Source · OAIC AI guidance
03

APP 11 security obligations

Organisations must take reasonable steps to protect personal information from misuse, interference and loss. Feeding personal information into uncontrolled AI tools may breach this obligation.

04

Privacy impact assessment expected

OAIC guidance encourages a PIA before significant AI deployments touching personal information. The PIA becomes part of the VAISS G2 evidence.

05

Practical adoption

An eight-week pathway for most Australian businesses.

Documented, defensible, and proportionate.

VAISS adoption is not a single project. Most Australian businesses can establish a defensible position against the ten guardrails inside two months of focused work, then refine over the following six to twelve months. The pathway below is intentionally proportionate.

01

Weeks 1 to 2 : Discovery

Inventory of current AI use across the business, including shadow AI. Map each tool to a deployer or developer role. Identify data flows touching personal information.

02

Weeks 3 to 4 : Governance

Establish an AI governance group with named accountability. Document the AI risk appetite. Adopt G1 and G2 in writing.

03

Weeks 5 to 6 : Policy and disclosure

Draft a plain-English AI use policy for staff. Address acceptable use, prohibited inputs, disclosure to customers under G6, and training expectations.

04

Weeks 7 to 8 : Operational controls

Implement G3 (data governance, security), G4 (testing and monitoring), and G5 (human oversight) for each significant AI deployment.

05

Months 3 to 6 : Embed and evidence

Move from documented to operating. Begin collecting the records required under G9 and the supply chain transparency under G8.

06

Months 6 to 12 : Mature and audit

First internal review of VAISS alignment. Position the business for any future mandatory guardrails that emerge from the consultation process.

06

If mandatory guardrails arrive

Voluntary today does not mean voluntary forever.

Watch the high-risk consultation closely.

The Department of Industry, Science and Resources has consulted on making the ten guardrails mandatory for AI use in high-risk settings. As of 2026, the definition of high-risk remains under consultation. Businesses applying VAISS now are likely to be well positioned regardless of the regulatory direction Australia ultimately takes.

01

Consultation on mandatory guardrails

The proposals paper canvassed making the same ten guardrails mandatory for high-risk AI, with definitions and enforcement mechanisms still under consultation.

Source · Mandatory guardrails proposals paper
02

Likely high-risk sectors

Indicative areas include AI used in employment decisions, credit assessment, healthcare, law enforcement and education. Final scope will follow consultation outcomes.

03

Alignment with international frameworks

Australian policy direction aligns broadly with the EU AI Act risk-based approach, while drawing on US NIST AI Risk Management Framework.

04

Sector regulators may move first

APRA, ASIC, ACCC and the OAIC have all signalled increased AI scrutiny within their existing remits. Sector-specific guidance is likely to outpace any horizontal AI law.

05

Position adopted now is broadly portable

Businesses with documented VAISS alignment are generally well placed to meet any future mandatory regime with marginal additional work.

07

Agentic AI: the new risk layer

ASD and the Five Eyes have published specific guidance on agentic AI.

Autonomy plus tool access changes the risk picture.

In May 2026 the Australian Signals Directorate and its Five Eyes partners (US CISA and NSA, Canadian Cyber Centre, NZ NCSC, UK NCSC) published joint guidance on the careful adoption of agentic AI services. The guidance followed testing that showed advanced AI models can autonomously reason about objectives, adapt to changing circumstances, identify alternative pathways and combine multiple technical actions into sophisticated attack sequences. This is a new risk layer that sits on top of the ten guardrails.

01

What agentic AI changes

Unlike traditional AI that generates information for human review, agentic AI systems can make decisions, interact with tools, access enterprise systems and take actions with limited human intervention. That combination of autonomy, tool access and operational privileges creates opportunities for privilege escalation, prompt injection attacks, unintended behaviour, data compromise and cascading failures across interconnected systems.

Source · ASD: Careful adoption of agentic AI services
02

ASD Secure-by-Design approach

ASD recommends limiting agent permissions to the minimum required, maintaining human oversight for high-impact actions, continuously monitoring agent behaviour and tool usage, implementing comprehensive logging and auditing, conducting regular red teaming and adversarial testing, validating third-party tools and integrations before deployment, deploying capabilities progressively with autonomy increasing only as assurance matures, and isolating agents with strict controls on system interactions.

03

How this maps to VAISS

Agentic AI security does not replace the ten guardrails. It extends them. Guardrail G3 (data governance and security) applies to agent tool access and permissions. Guardrail G4 (testing and monitoring) applies to agent behaviour and decision logging. Guardrail G5 (human control) applies to oversight of high-impact agent actions. Guardrail G9 (records) applies to agent audit trails. The guardrails are the framework; agentic AI is where they get stress-tested.

04

Start low-risk, expand slowly

ASD encourages organisations to introduce agentic AI in a measured and risk-informed manner, beginning with clearly defined, lower-risk use cases before expanding autonomy, privileges and operational scope. This is the same proportionate approach VAISS recommends for all AI deployment, applied specifically to the agentic layer.

05

Defence in depth still applies

ASD recommends a defence-in-depth approach: multiple overlapping layers of security controls across user inputs, tool integrations, data sources, model outputs and agent-to-agent communications. AI-specific security measures complement, not replace, established cyber security practices. The Essential Eight and the ISM still apply.

What the 2026 breach data shows about AI use

Shadow AI is now the dominant governance gap

The Verizon 2026 DBIR is the first edition to surface AI use at scale. Two figures stand out: corporate AI use has tripled in twelve months, and most of that use is happening through personal accounts that sit outside the tenant. That is precisely the gap VAISS Guardrails G1, G3 and G5 are written to close.

Read the Verizon 2026 DBIR

45%

45% of employees regularly use generative AI on corporate devices

Up from 15% in the prior edition. Tripled in twelve months.

67%

67% of that AI use goes through personal, non-corporate accounts

Data leaving the tenant via personal logins is the dominant AI governance gap.

62%

62% of breaches still involved a human element across all sectors

Identity, awareness and process discipline remain the controllable variables.

16%

16% of breaches started with social engineering, with voice and mobile pretexting on the rise

Voice phishing inside the workday is now common enough to warrant its own playbook.

Source: Verizon 2026 Data Breach Investigations Report. Dataset window Oct 2024 to Nov 2025. 31,000+ incidents and 22,000+ confirmed breaches across 145 countries.

The checklist, not just the explainer

Download the one-page VAISS evidence checklist.

The chapters above explain the ten guardrails. This block hands you the one-page artefact a director can take to the next risk and audit committee. Each guardrail mapped to a met / in progress / not started field, an evidence reference and an accountable owner.

Print it. Fill it in by hand. Table it at the next sitting.

Includes

  • All ten guardrails on one page
  • Met / in progress / not started fields
  • Evidence reference and owner per row
  • Summary and decisions-sought section

Common questions

Questions Australian leadership teams ask about AI governance.

No. VAISS is voluntary. A separate proposals paper consulted on making the same ten guardrails mandatory for high-risk AI settings, but as of 2026 the scope and timing remain under consultation by the Department of Industry, Science and Resources.

If your business is deploying AI in 2026

A defensible VAISS position is mostly documentation work.

If your business is rolling out Microsoft 365 Copilot, ChatGPT Enterprise, Gemini for Workspace, or other AI tools in production, the eight-week pathway above gets you to a defensible VAISS-aligned position. Most of the work is documentary rather than technical.

This page is general information drawn from publicly available Australian government and legal sources. It is not legal advice. For decisions affecting your business, refer to the linked primary sources or seek qualified advice.