Back to all articles
Industry Trends25 June 20268 min read

Australia didn't pass an AI Act. That should worry you more, not less.

R

Riverstone Labs

Riverstone Labs

Australia didn't pass an AI Act. That should worry you more, not less.

Late in 2025 the Federal Government confirmed there would be no standalone AI Act, and the mandatory "guardrails" it had floated the year before got quietly parked. Around a lot of boardroom tables, a small exhale. No Act, no compliance project, no new line item.

Read it again. That exhale is the mistake.

One AI Act would have been a gift, in a backhanded way. One statute. One commencement date. One box the auditor ticks and moves on. What you got instead is the opposite shape: AI obligations threaded through laws that already bind you, the Privacy Act, the Australian Consumer Law, the prudential regulators, and the EU's reach stacked on top. Four or five surfaces, not one. Different regulators, different dates, no master checklist. Nobody is going to post you a form.

Here is the patchwork, with the dates that bite.

10 December 2026

That's when the Privacy Act starts requiring you to say, in your privacy policy, where you make automated decisions that could significantly affect a person. The source is the Privacy and Other Legislation Amendment Act 2024, the new Australian Privacy Principles 1.7 through 1.9. The OAIC is still drafting how hard it will lean on this.

Read the definition slowly, because that's where firms get caught. "Automated decision-making" is not "the expensive model you licensed last quarter." It is wide enough to swallow software you've run for years and never once called AI. Lead scoring in the CRM. The applicant-tracking tool that ranks CVs before a human opens one. Pricing that shifts per customer. Tenant screening. Automated credit and risk checks. Most firms have never listed these, never graded them by risk, never imagined they'd have to. You can't disclose what you haven't found. And you won't find it in the fortnight before Christmas, which happens to be where the deadline sits.

Disclosure, not prohibition. The work is unglamorous rather than heroic. But step one is being able to name which of your systems are in scope, and today most firms genuinely can't.

The exemption roughly 100,000 businesses are about to lose

For decades a business turning over under $3 million sat almost entirely outside the Privacy Act. That carve-out is going. On current timing, around 1 July 2026, something like 100,000 small businesses come under the Act for the first time in their existence.

Underneath that sits a change most people blinked past. Since June 2025 there has been a statutory tort for serious invasions of privacy. In plain English: a person can take you to court directly over a serious breach, without a regulator acting as the go-between. If your operating assumption has been "privacy law is a big-company problem," that assumption now has a use-by date on it. And the AI tools quietly ingesting customer records are precisely the sort of thing that turns a complaint into a claim.

"AI" turned into a hundred-million-dollar word

March 2026: the maximum penalty for misleading or deceptive conduct under the Australian Consumer Law climbed to A$100 million. In the same stretch of the calendar, the ACCC put "AI-washing" on its enforcement-priority list. AI-washing means painting a product as more autonomous, or more intelligent, than it can actually back up.

Call a workflow "agentic" while a staffer does the real lifting. Imply a feature reasons when it runs if-then rules. Stamp "AI-powered" across a capability page to make a tender shortlist. Each one is now a consumer-law exposure with nine figures behind it. Your marketing site stopped being purely a marketing problem the day that penalty doubled.

It reaches the boardroom. Then it reaches Europe.

In April and May 2026, APRA and ASIC each wrote to the sectors they regulate asking for a "step-change" in how AI risk is governed. APRA's tone was sharp for a prudential regulator. It called out boards that sign off AI risk off the back of a vendor slide deck, with no grasp of what sits underneath. Its asks are mundane, which is rather the point. Keep a register of where AI operates. Name a human who owns each high-risk decision. Make sure directors can actually interrogate what they're shown instead of nodding at it.

Financial services first. Not financial services only. Sell software or a service into a regulated business and their obligations land on you secondhand, through procurement questionnaires and contract clauses. "We're not a bank" and "this can't reach us" are two different sentences that people keep treating as one.

Then there is Europe, which doesn't much care where you are incorporated. The EU AI Act triggers on where the AI is used. If your product, or even just its output, reaches a user in the EU, you can be in scope, with general-purpose AI duties already running and the serious enforcement powers switching on in August 2026. Next to those fines, Australia's hundred million reads almost polite.

Scattered is harder to manage than strict

Stack it all up and the difficulty isn't any single rule. It's the absence of a single rule. No one form, no certificate to frame, no audit you survive once and shelve. Your exposure is spread thin across tools you already run, decisions you already automate, claims you already publish, and markets you already ship to.

We won't pretend it's all locked down. The OAIC's final guidance on automated decisions isn't expected until around September 2026, so the exact boundary of "significantly affects" a person is still soft, and anyone quoting you the precise line is improvising. Here is our working rule, and we'll say plainly where we're sure and where we aren't. The obvious cases are not escaping scope, so prepare them now: hiring, credit, pricing, screening. Send the genuine edge cases for a second look when the guidance lands. Confident on the first list. Less so at the margins. Certain that sitting still until September is the worst of the available options.

The downside isn't hypothetical. Late in 2025, Deloitte repaid part of a A$290,000 report it had produced for a federal department, after the thing turned out to contain AI-fabricated citations and a quote pinned on a judge who never said it. One of the largest firms on earth. A government client. Every review layer you'd assume was in place. The takeaway isn't "AI is dangerous", which is the lazy read. It's narrower: AI failures are specific, public and expensive, and they pick off careful people who left one control in the wrong spot.

Your instinct was right. The law just caught up to it.

Ask Australian firms why they're slow on AI and the top answer isn't budget, and it isn't a skills gap. It's trust. A flat reluctance to hand decisions that carry consequences to a machine. For years that hesitation got written up as falling behind.

It wasn't falling behind. Keeping a human answerable for consequential calls is, near enough, what the regulators are now demanding in writing. The firms that map where their automated decisions live, put a person visibly in the loop, and can explain in one honest paragraph what their AI does and why, clear the compliance bar almost by accident. They also pocket something their rivals don't get: AI they can set in front of a customer, a board, or a regulator without a flinch. While half the market is overclaiming and the other half is hoping nobody asks, "here is exactly how this works, and here is the name of the person accountable for it" is a sentence you can put a price on.

So, the actual moves. Not a steering committee. Four, in sequence.

Find it. Write down every place automated decisions and AI already operate, the dull embedded tools included. You can't govern or disclose what you've never located.

Triage it. For each one, ask the law's own question, could this significantly affect a person, and push those to the front of the queue.

Staff it. Put a human where the decision matters and record who carries it. A name, not "the team".

Say it. Your privacy policy and your marketing should both describe what your AI genuinely does. Not a word more. Not a word less.

None of this argues for slowing down on AI. It argues the reverse. The firms that get this right will adopt faster and wider, because they'll trust their own systems, and so will everyone they answer to.

Want a concrete read on where you stand? We built a short AI Exposure Check. A few plain questions about the tools you run, and you get back a map of where you're likely exposed across these rules, plus the short list to clear before December. It's the same first step we'd take with you in the room.

General information about a moving regulatory picture, not legal advice. Where it matters, have a lawyer check it. Our job is the operational work: finding where AI lives in your business, making it defensible, and making it pay.

AI regulationPrivacy Actautomated decisionsANZAI governancecompliance

Share this article

Want to implement what you just read?

Book a free 15-minute assessment. We'll look at your operations and identify the highest-ROI automation opportunities.

Book your free assessment