Australia has no AI Act — and one hard deadline that catches automated decisions.
Australia decided not to legislate AI on its own. The mandatory guardrails for high-risk AI that were proposed in 2024 were not taken forward, and the position now is that the law you already have — privacy, consumer, anti-discrimination — is the law that governs what your AI does.
That is easy to hear as "nothing to do", and it is the opposite. A regulator applying existing law to a new tool gives you no implementation window and no checklist. The one hard date in the calendar sits in the Privacy Act, and it asks a question most firms cannot currently answer: which of your decisions are made by a computer, and what does it use to make them?
New Zealand has taken the same route with no AI statute of its own, and its Privacy Commissioner has been explicit that the Privacy Act applies to everyone using AI tools there.
What actually governs AI in Australia and New Zealand.
No summaries of summaries. Each of these was read at the publisher's own site, and the obligation is stated as the thing you have to do rather than the clause it comes from.
Australia
The Privacy Act 1988 (Cth) and the Australian Privacy Principles. There is no AI-specific statute.
Your privacy policy must account for decisions made by a computer program where those decisions could significantly affect somebody — what personal information goes in, and what kinds of decisions come out. Writing that down means first knowing where automated decisions happen in your business, which is the work.
The National AI Centre publishes Guidance for AI Adoption, which develops the earlier Voluntary AI Safety Standard into six practices. It is voluntary and it is what a tender will ask you about.
New Zealand
The Privacy Act 2020 and its information privacy principles. There is no AI-specific statute.
The Privacy Commissioner expects a privacy impact assessment before an AI tool goes anywhere near personal information, and expects you to be able to show the tool is accurate and fair before you rely on what it produces.
14 dates that decide whether you are compliant.
8 of them have already passed.
Australia is one line of 6. Yours is marked. Almost every business we speak to sits on more than one of these lines, because they follow your customers and your staff rather than your head office.
Europe
- in force Obligations for general-purpose AI models.
- in force Article 50 transparency duties, deployer obligations, and enforcement powers for national regulators.
- coming New prohibitions, and Article 50(2) marking of synthetic content.
- coming Every Member State must have an AI regulatory sandbox running.
- coming High-risk obligations for Annex III systems — including AI used in recruitment, credit scoring, education and essential services.
- coming High-risk obligations for Annex I systems — AI embedded in products already covered by EU product safety law.
United Kingdom
- in force Most Part 5 data protection provisions of the Data (Use and Access) Act 2025, including the wider lawful bases for solely automated decisions and the safeguards that come with them.
- in force The duty on controllers to operate a complaints procedure and respond to data protection complaints within set time limits.
United States
- in force Texas HB 149, the Responsible Artificial Intelligence Governance Act — prohibited uses, government AI disclosure, and Attorney General enforcement.
- in force California SB 942, the AI Transparency Act — free AI detection tool and latent provenance disclosure for large generative AI providers. Delayed from 1 January 2026 by AB 853.
- coming Colorado SB 26-189 — developer and deployer duties for automated decision-making technology used in consequential decisions. It repealed and reenacted SB 24-205, which never took effect.
Canada
- in force Ontario ESA / O. Reg. 476/24 — a publicly advertised job posting must disclose the use of AI to screen, assess or select applicants. Employers of 25 or more, including where a third party screens on their behalf.
Australia this page
- coming Privacy Act 1988 (Cth), APP 1.7 — a privacy policy must say what kinds of personal information a computer program uses to make decisions that could reasonably be expected to significantly affect a person, and what kinds of decisions those are.
United Arab Emirates
- in force DIFC Data Protection Regulation 10 — a business deploying an autonomous or semi-autonomous system that processes personal data must tell users, on first use, what the system decides for itself, what it was built to do and what it does with the output.
Does this apply to you?
Most firms read a page like this and conclude it is about somebody bigger. These are the three things that decide it, and the first one catches almost everybody.
- You use a tool that scores, ranks, shortlists or prices — recruitment screening, credit decisions, claims triage.
- You bought that tool rather than built it. The duty follows the business getting the benefit, not the developer.
- You have staff or customers in Australia and a privacy policy written before any of this existed.
What we would do about it.
We build AI compliance frameworks — the policy, the register of where AI touches your business, the record that shows a regulator you thought about it before something went wrong. Fixed price, plain English, written for a business owner rather than a lawyer.
We sell fixed-price frameworks off the shelf for the UK, the EU, the US and Canada. Australasia is not one of them yet, so this starts as a conversation rather than a checkout: tell us where your people and your customers are, and we will tell you honestly which of these obligations reaches you and what it takes to meet them. If the answer is that you are covered by a framework we already build, we will say so.
Find out where you stand in Australasia.
A free call, no pitch deck. We will tell you which of the obligations above reach your business and which do not — including if the answer is none of them.