Lander & Rogers logo
1 Insights

Australian AI regulation: what proposed AI standards and safety reforms mean for business

Australian AI regulation: what proposed AI standards and safety reforms mean for business

On 15 July, Prime Minister Anthony Albanese announced the Federal Government's intent to introduce a set of Australian Standards for AI, with legislation expected to be brought to Parliament early next year.

The proposed framework is to sit alongside the newly established Office of AI within the Department of the Prime Minister and Cabinet. The Office of AI is intended to coordinate Australia’s approach to AI regulation, investment and safety.

The announcement was followed closely by the release of the Federal Government's AI consumer safety priorities on 20 July. The priorities contemplate further legislation, including a 'Digital Duty of Care' and tranche two privacy reforms.

This is not the first time that AI-specific laws have been considered in Australia. Over the past two years, the Federal Government’s position has shifted markedly – from proposing mandatory guardrails in September 2024 to favouring a light-touch, pro-productivity approach by 2025. The latest announcement confirms that AI regulation is firmly back on the agenda, though the detail and form that it will take remains thin.

This update sets out what we know so far, what we expect and what organisations should be doing now to prepare.

Standards for AI

The proposed content of the AI Standards is not yet known in full. However, at minimum the standards are intended to include:

  • requirements for AI data centres, including in relation to power use and generation, water use and energy efficiency; and
  • restrictions on use of Australian copyright material to train AI.

Consumer safety priorities

The AI consumer safety priorities which were separately announced are:

  • a legislated 'Digital Duty of Care' to require AI companies to build in safety by design;
  • privacy reforms to modernise and simplify privacy regulation;
  • AI safety in the workplace;
  • consumer protections in the Australian Consumer Law, including in relation to retail surveillance pricing and agentic commerce; and
  • regulation of automated decision-making in federal agencies to ensure fair, accurate and transparent decision making.

These priorities signal the general direction of travel, but detail on implementation, timelines (beyond early next year) and regulatory architecture remains sparse.

Our take – how this may pan out

We expect the proposed Digital Duty of Care is likely to be the centrepiece of this shift. Current online safety laws largely respond to harm after it occurs. A duty of care would move the focus to prevention, requiring online services and AI companies to take reasonable steps to address foreseeable harms by design. This could represent a significant new obligation for any business deploying AI-powered products or services to the public.

Privacy reform will also be central. Automated decision-making transparency requirements under the Privacy Act will commence on 10 December 2026 (see our earlier article), but these obligations are mainly focused on transparency. We expect the Government to consider whether Australia’s privacy framework adequately addresses the broader privacy risks created by AI systems that rely on large datasets or may infer information about individuals.

For workplaces, we anticipate the focus is likely to be on consultation, transparency and accountability where AI is used in recruitment, monitoring, rostering, productivity assessment or other employment-related decisions.

Consumer law is another area to watch. Treasury has previously concluded that the Australian Consumer Law can generally respond to AI products and services, but the Government has now identified retail surveillance pricing and agentic commerce as specific risks requiring further attention. This revised position reflects the increasing capability of AI products and the increasing complexity of the interactions between AI and consumers. Lander & Rogers has previously considered the legal risks of agentic AI, including questions of accountability where autonomous systems transact or act on behalf of users. Consumer protections are likely to be tested by emerging ways of doing business, particularly in the agentic commerce space.

Finally, a framework to better regulate automated decision-making in federal agencies should help clarify when automation can be used, what human oversight is required and how affected individuals can understand or challenge decisions.

What this means for business

Businesses should actively monitor the Government’s reform agenda.

The Government’s announcements suggest that AI regulation is back on the legislative agenda, but in a more targeted form than the mandatory guardrails proposed in 2024. For businesses, the key issue will be coherence: how these separate reform streams interact, which regulators will be responsible, and whether the new Office of AI can provide a clear organising framework.

In addition, the history of policy changes over the past two years means that businesses should be aware that the current direction may evolve before implementation.

In the meantime, organisations should not be waiting for legislation to mature before acting. As the Productivity Commissioner identified in 2025, existing laws already apply to most AI use cases, and any future legislation is likely to apply as an additional layer. Organisations who are already treating AI governance as an immediate compliance and risk issue are likely to be on the front foot when any new laws do arrive.

For further insights on how AI is affecting your business now, see Lander & Rogers’ AI in Practice series, which explores evolving AI governance best practice, workers’ rights in the deployment of AI, emerging cybersecurity risks, and the use of AI in litigation and investigations.

All information on this site is of a general nature only and is not intended to be relied upon as, nor to be a substitute for, specific legal professional advice. No responsibility for the loss occasioned to any person acting on or refraining from action as a result of any material published can be accepted.