Australia has no AI Act — and one hard deadline that catches automated decisions.
Australia has no AI Act. The mandatory guardrails for high-risk AI that were proposed in 2024 were not taken forward, and the Australian Standards for AI the government has since announced set rules for large data centres and for training AI on Australian creative work — not for a business that uses AI tools. For that business, the law you already have — privacy, consumer, anti-discrimination — is the law that governs what your AI does.
That is easy to hear as "nothing to do", and it is the opposite. A regulator applying existing law to a new tool gives you no implementation window and no checklist. The one hard date in the calendar sits in the Privacy Act, and it asks a question most firms cannot currently answer: which of your decisions are made by a computer, and what does it use to make them?
New Zealand has taken the same route with no AI statute of its own, and its Privacy Commissioner has been explicit that the Privacy Act applies to everyone using AI tools there.
What actually governs AI in Australia and New Zealand.
No summaries of summaries. Each of these was read at the publisher's own site, and the obligation is stated as the thing you have to do rather than the clause it comes from.
Australia
The Privacy Act 1988 (Cth) and the Australian Privacy Principles. There is no AI-specific statute. The Act reaches a business outside Australia that carries on business in Australia. It does not reach a small business — one whose annual turnover has never been above three million Australian dollars in a financial year, counted across the whole business rather than only its Australian sales — unless, among other exceptions, that business provides a health service and holds health information, or trades in personal information. A business stops being a small business only once a financial year in which its turnover was above that line has ended. The Act sets the line in Australian dollars and says nothing about how turnover earned in another currency is converted, so a business trading in pounds should record the rate it used. An employer's handling of employee records about its own current and former staff is exempt where it relates directly to that employment.
If the Act reaches you, your privacy policy must account for decisions made by a computer program where those decisions could reasonably be expected to significantly affect somebody's rights or interests — what personal information goes in, and what kinds of decisions come out. The duty is on the business that arranged for the program to make or feed the decision, whether or not it built the program. Writing that down means first knowing where automated decisions happen in your business, which is the work. The Act does not require a business outside Australia to appoint a representative or agent there.
The National AI Centre publishes Guidance for AI Adoption, which develops the earlier Voluntary AI Safety Standard into six practices. It is voluntary and it is what a tender will ask you about.
New Zealand
The Privacy Act 2020 and its information privacy principles. There is no AI-specific statute. The Act reaches a business overseas for anything it does in the course of carrying on business in New Zealand, wherever the information is collected or held — and a business can be carrying on business there without an office there and without being paid. There is no exemption for a small business.
Before you use or disclose personal information — including what an AI tool produces about a person — take reasonable steps to make sure it is accurate, up to date, complete, relevant and not misleading. For an AI tool, that means knowing what it gets wrong before you rely on what it says. The Act does not require a business overseas to appoint a representative or agent in New Zealand.
The Privacy Commissioner's starting point is that the Privacy Act applies to everyone using AI tools in New Zealand, and its guidance recommends a privacy impact assessment before you start using one, kept up to date.
28 dates that decide whether you are compliant.
14 of them have already passed.
Australia is one line of 9. Yours is marked. Almost every business we speak to sits on more than one of these lines, because they follow your customers and your staff rather than your head office.
Europe
- in force Obligations for general-purpose AI models.
- in force Article 50 transparency duties and enforcement powers for national regulators.
- coming New prohibitions, and Article 50(2) marking of synthetic content.
- coming Every Member State must have an AI regulatory sandbox running.
- coming High-risk obligations for Annex III systems — including AI used in recruitment, credit scoring, education and essential services.
- coming High-risk obligations for Annex I systems — AI embedded in products already covered by EU product safety law.
United Kingdom
- in force Most Part 5 data protection provisions of the Data (Use and Access) Act 2025, including the wider lawful bases for solely automated decisions and the safeguards that come with them.
- in force The duty on controllers to operate a complaints procedure and respond to data protection complaints within set time limits.
United States
- in force New York City Local Law 144 — an employer or agency using an automated employment decision tool for a New York City job needs a bias audit within the past year, published results, and notice to candidates.
- in force Washington My Health My Data Act (RCW 19.373) — consent before collecting or sharing consumer health data and a published health data privacy policy, for any business targeting Washington consumers; small businesses from 30 June 2024. A breach is an unfair practice under the Consumer Protection Act.
- in force Utah Artificial Intelligence Policy Act (SB 149, 2024) — a business using generative AI with a consumer must say so when the consumer clearly asks; licensed professions must disclose it up front in high-risk interactions. Narrowed by SB 226 from 7 May 2025, with a safe harbour for disclosing at the start.
- in force Texas HB 149, the Responsible Artificial Intelligence Governance Act — prohibited uses, government AI disclosure, and Attorney General enforcement.
- in force California SB 942, the AI Transparency Act — free AI detection tool and latent provenance disclosure for large generative AI providers. Delayed from 1 January 2026 by AB 853.
- coming Colorado SB 26-189 — developer and deployer duties for automated decision-making technology used in consequential decisions. It repealed and reenacted SB 24-205, which never took effect. California SB 1050 (Chapter 246, Statutes of 2026) — an advert shown in California that prominently features an AI-generated performer who looks or sounds human must say so clearly, in words like "this performance features a synthetic performer". Any size of business; enforced as false advertising. California CCPA regulations on automated decisionmaking technology (Cal. Code Regs. tit. 11, s. 7200) — a business using ADMT for a significant decision about a consumer must give pre-use notice, opt-out and access rights. In force 1 January 2026; businesses already using ADMT must comply by this date. Only businesses within the CCPA. Connecticut Public Act 26-15, sections 4 to 6 — duties on operators of AI companions, including detecting and responding to signs of self-harm. Washington HB 2225 (Chapter 168, Laws of 2026) — AI companion chatbots must disclose that they are not human, with safeguards for minors and a private right of action. A customer-service bot that does not sustain a relationship is excluded. Oregon SB 1546 (Chapter 85, Oregon Laws 2026) — operators of AI companions must tell users they are not talking to a person, keep a protocol for users who express thoughts of suicide or self-harm, and add safeguards for minors; a user who is harmed can sue. Software used solely for customer service, business operations or productivity is excluded.
- coming Idaho Conversational AI Safety Act (S 1297, Session Law Chapter 249 of 2026; Idaho Code Title 48, Chapter 21) — a conversational AI service open to the public must say it is AI where a person could be misled, answer prompts about suicide with a crisis referral, and protect account holders who are minors. Enforced by the Attorney General. A chatbot used only for customer service or a business's own operations is excluded.
- coming Connecticut Public Act 26-15 (Substitute SB 5, 2026), sections 7 to 12 — any business doing business in Connecticut that uses an automated employment-related decision technology for a hiring, promotion or discipline decision must disclose it and give written notice before the decision. No size threshold. A breach is an unfair trade practice.
- coming California CCPA regulations, s. 7157 — risk assessments conducted in 2026 and 2027 must be submitted to the California Privacy Protection Agency by this date.
Canada
- in force Ontario ESA / O. Reg. 476/24 — a publicly advertised job posting must disclose the use of AI to screen, assess or select applicants. Employers of 25 or more, including where a third party screens on their behalf.
Australia this page
- coming Privacy Act 1988 (Cth), APP 1.7 — a privacy policy must say what kinds of personal information a computer program uses to make decisions that could reasonably be expected to significantly affect a person, and what kinds of decisions those are — the automated decision-making (ADM) transparency obligations, regulated by the OAIC.
United Arab Emirates
- in force DIFC Data Protection Regulation 10 — a business deploying an autonomous or semi-autonomous system that processes personal data must tell users, on first use, what the system decides for itself, what it was built to do and what it does with the output.
Saudi Arabia
- in force The Saudi Data and AI Authority's grace period under the Personal Data Protection Law ends, and with it the undertaking not to apply penalties. The authority has said it may extend the grace period for a business that gives it good reason.
South Korea
- in force Framework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust in force. A business in the AI industry must tell users in advance where a product runs on generative or high-impact AI, and label what generative AI produces. It applies to conduct outside Korea that affects the Korean market or its users.
China
- in force Personal Information Protection Law in force. A business outside China that handles the personal information of people in China — to offer them products or services, or to analyse their behaviour — must have a lawful basis for it and must appoint a representative or a dedicated body inside the country. Nothing in the duty turns on how much data is held.
Does this apply to you?
Most firms read a page like this and conclude it is about somebody bigger. These are the things that decide it, and the first one catches almost everybody.
- You use a tool that scores, ranks, shortlists or prices — recruitment screening, credit decisions, claims triage.
- You bought that tool rather than built it. The duty is on the business that arranged for the program to decide, not on whoever wrote it.
- You sell to customers in Australia, your turnover has passed three million Australian dollars, and your privacy policy was written before any of this existed.
What we would do about it.
We build AI compliance frameworks — the policy, the register of where AI touches your business, the record that shows a regulator you thought about it before something went wrong. Fixed price, plain English, written for a business owner rather than a lawyer.
Every price, every line and every figure below is read from the same place the checkout reads it, so what the page says and what you are charged cannot drift apart.
- Which countries in the region reach your business, and on what basis
- AI Acceptable Use Policy
- Employee AI guidelines
- Data processing documentation for AI tools
- Cross-border data transfer position
- Basic compliance roadmap
- ISO/IEC 42001 and NIST AI RMF alignment map
- Answers to the AI questions clients send their suppliers
In your inbox by the end of the business day · annual — covers you for 12 months, renews yearly, legal updates included
Buy Foundation — £797/year →- Everything in Australasia AI Compliance Foundation
- Local representative requirements assessment
- Consumer-facing AI transparency disclosures
- AI Risk Register (populated for your current tools)
- Incident Response Procedure
- HR AI procedures and disclosure templates
- Monitoring and logging procedures
- Banned AI practices declaration
- Your AI compliance dashboard: a to-do list, your AI tools, staff sign-off, an incident log, every document and a shareable statement See the dashboard →
In your inbox by the end of the business day · annual — covers you for 12 months, renews yearly, legal updates included
Buy Complete — £1,497/year →Not sure which countries reach you? That is the first document in both tiers, and it names the ones that do not as well as the ones that do. If you would rather talk it through first, the call below is free and there is no pitch deck.
Read it before you buy it.
This is not a mock-up or a contents page. It is a genuine AI Policy — Essentials pack, produced by the same system that will produce yours, for a fictional accountancy practice we invented to test it. Every page below came out of the real thing.
26 September 2026 — added: Answers to the AI questions clients send their suppliers
The gap. Public bodies and large companies now send their suppliers questions about the AI they use. Our frameworks held most of the answers, but a client had to know where to look, usually with a renewal waiting.
What we added. The questions real buyers publish, each put in plain words, with the document in your framework that answers it and anything still yours to do.
24 September 2026 — added: ISO/IEC 42001 and NIST AI RMF alignment map
The gap. Bigger clients, insurers and tenders can ask a supplier whether its AI governance meets ISO/IEC 42001 or the NIST AI Risk Management Framework. Our frameworks held most of the evidence, but nothing in them showed it.
What we added. A map that names, clause by clause, which of your documents meets each standard and what is still yours to do. It shows alignment, not certification.
Every framework, in all seven markets, has these changes. The pages below were made before them, so they show 2 documents fewer than a framework bought today.
This framework also comes with a compliance dashboard you run all year: a dated to-do list, your AI tools and their risks, staff sign-off, an incident log, every document to download, the deadlines for your markets and a statement you can share. See a fictional example → · What the dashboard does →
The same work, done in-house.
8 documents to write, and 15 records a year to keep afterwards. Costed against what a member of staff on the median UK salary actually costs an hour:
£1,556+
Your own staff — 60 hours of their time
£797/year
Australasia AI Compliance — in your inbox by the end of the business day
Marked + because the reading is not in that figure yet — we are still counting this market's statutes, so the real in-house cost is higher than shown, never lower.
Find out where you stand in Australasia.
A free call, no pitch deck. We will tell you which of the obligations above reach your business and which do not — including if the answer is none of them.