A narrow, dated note on Australian instruments relevant to AI-agent oversight. Australia's national framework is voluntary guidance layered on existing law; each entry names the instrument's exact status. Guidance, prudential standards and legislation are different things, and this note keeps them apart.
These pages describe the product and cite public instruments. They are not legal advice, not a certification, and not a statement that any instrument applies to your organisation. The official source is authoritative; applicability questions belong to your advisers.
Instruments, by status
| Instrument | Status | What it addresses |
|---|---|---|
| Guidance for AI Adoption (six essential practices) · National AI Centre, DISR | Voluntary guidance. Released 21 October 2025; updated 5 May 2026. Evolves the 2024 Voluntary AI Safety Standard; creates no legal duty. | Any organisation adopting AI. The six practices (referenced below as AI6): decide who is accountable, understand impacts, measure and manage risks, share essential information, test and monitor, maintain human control. Practices 1 and 6 are the ones action-layer records speak to most directly. |
| National AI Plan and announced Australian Standards for AI · Australian Government | Policy, not law. The National AI Plan (December 2025) kept existing laws and sector regulators as the foundation and did not proceed with the September 2024 mandatory-guardrails proposals paper, which is a closed consultation document, not law and not a progressing legislative regime. On 15 July 2026 the Government announced plans to legislate a framework for large data centres and AI training, with standards expected in early 2027; no bill had been introduced when this note was reviewed. | Economy-wide direction. Nothing in it creates an obligation for organisations using AI today. |
| Privacy and Other Legislation Amendment Act 2024 · automated-decision transparency | Binding law, not yet commenced. The APP 1 transparency duty commences 10 December 2026. | Privacy policies must disclose the kinds of personal information used in, and the kinds of, decisions made by computer programs where the decision is reasonably expected to significantly affect an individual's rights or interests, including programs doing things substantially and directly related to making the decision, not only solely automated ones. |
| CPS 230 and CPS 234 · APRA | Binding prudential standards for APRA-regulated entities. CPS 230 (operational risk) in force 1 July 2025; pre-existing service-provider arrangements transitioned by 1 July 2026, earlier where an arrangement was renewed before then. CPS 234 (information security) has applied since 1 July 2019. | Operational risk, service-provider oversight and controls that cover AI and agent deployments inside regulated entities. The regulated entity answers to APRA; using AAES does not transfer that responsibility. |
What AAES records may contribute
| Expectation | AAES contribution | Capability status |
|---|---|---|
| Decide who is accountable (AI6 practice 1) | Every registered agent has a named accountable manager, a configured association rather than a statutory appointment; approvals are attributable to a named person; agent identities cannot act as approvers through the supported AAES approval path. | Implemented. |
| Maintain human control (AI6 practice 6) | Actions the operator registers as irreversible (a registration classification, not an independent assessment of effects) require approval by an authorized person, bound to one intent and the exact payload, with expiry. An approval record does not by itself show the approver had adequate information, time or practical power to intervene. | Implemented. |
| Records an internal audit or APRA review can inspect (AI6 practices 3 and 5; CPS 230 / CPS 234 evidence) | Sealed, hash-chained decision records with offline integrity verification by the client's own reviewer. | Implemented. An independently controlled witness can be configured separately; that is not an external assessment, and the default deployment has none. |
AAES decision records may support review of access and approval controls. They do not establish lawful processing, model fairness, suitability, or compliance with any instrument as a whole.
Within the configured trust model, integrity verification checks the exported records; it does not establish that every action was recorded, that an external action succeeded, or that recorded assertions are true. Approval records do not by themselves establish meaningful human oversight. Enforcement depends on control of the credential path, and actions bypassing AAES are not recorded.
Residual responsibility and explicit gaps
- The client remains the regulated entity. Whether CPS 230, the Privacy Act duty from December 2026, or any other instrument applies to you (and how) is your adviser's question, not this page's.
- Work outside AAES is invisible to AAES. Records cover actions routed through AAES; they say nothing about actions on bypass paths.
- No independent certification or assessment of AAES exists. No SOC 2 report, no penetration test.
- Status changes. The announced Australian Standards for AI may be introduced after this note's review date. Re-check the primary source before relying on the status shown here.
Bring the instruments your risk team cites to a scoped evaluation.
Related pages:
This note: https://aaes.ai/library/jurisdictions/australia.html
Hong Kong note: https://aaes.ai/library/jurisdictions/hong-kong.html
Singapore note: https://aaes.ai/library/jurisdictions/singapore.html
Trust model: https://aaes.ai/library/trust-model.html
Scope an evaluation: https://aaes.ai/contact.html?ref=library-evaluation
