Australia Just Walked Away From Mandatory AI Guardrails. That Doesn't Mean What You Think.

Canberra shelved AI-specific legislation in favour of existing law, a safety institute, and adoption guidance. The compliance burden didn't disappear. It moved.
2 July 2026·5 min read
Dr Tania Wolfgramm
Dr Tania Wolfgramm
Chief Research Officer
Isaac Rolfe
Isaac Rolfe
Managing Director
For two years, Australian businesses prepared for mandatory guardrails on high-risk AI. That plan is now shelved. The government has confirmed it will not proceed with AI-specific legislation, betting instead on existing law, a new AI Safety Institute, and refreshed adoption guidance. Read quickly, that sounds like deregulation. Read properly, it's a redistribution of responsibility, onto you.

What Australia Actually Did

Three moves, announced across the policy roadmap:
Existing law does the work. Privacy, consumer protection, copyright, anti-discrimination, sector rules: the government's position is that these already govern AI outcomes, and regulators will enforce them accordingly. Technology-neutral, as the lawyers say.
A safety institute watches the frontier. The Australian AI Safety Institute launched in early 2026 with AUD$29.9 million to test systems, assess risks, and recommend targeted reform where genuine gaps appear.
Guidance replaces guardrails. The National AI Centre's Guidance for AI Adoption folds the ten-guardrail Voluntary AI Safety Standard into six essential practices: decide accountability, understand impacts, measure and manage risks, share information, test and monitor, maintain human control. Government agencies, meanwhile, got hard rules: from 15 June 2026 the first mandatory requirements apply to Commonwealth agencies, including AI impact assessments, procurement guidance, foundational AI training, and appointing Chief AI Officers, with full compliance due by 10 December 2026.

The Trans-Tasman Convergence

Here's what interests us: Australia has landed almost exactly where New Zealand did. Wellington's national AI strategy chose light-touch, principles-based regulation from the start; Canberra arrived at the same place after consulting on the heavier option. Both countries now rely on existing law plus guidance, both are watching the EU's timeline stretch, and both are, in effect, running the same experiment: can trust in AI grow without an AI act?
For businesses operating on both sides of the Tasman, that's a genuine simplification. One governance programme, built on the six practices and honest data governance, covers you in both markets.

Why "No Guardrails" Raises Your Bar

The uncomfortable flip side: mandatory guardrails would have told you exactly what to do. Their absence means the standard of care is being set elsewhere, by regulators applying old law to new failures, by insurers pricing AI risk, by enterprise customers writing AI clauses into procurement, and by public expectations that don't care which act applies.
When something goes wrong with your AI, "we complied with the legislation" was always a weak defence. Now it isn't even available. What courts, customers, and boards will ask instead: did you know what your AI was doing, could you explain it, and did you act like an organisation that took the risk seriously? That's a governance question, and voluntary-vs-mandatory doesn't change the answer. As we argued in AI governance is not optional: the absence of an act is not the absence of accountability.
Our take: the winners under light-touch regimes are the organisations that govern as if the guardrails were mandatory, because they get the trust dividend without the compliance theatre. The discipline Canberra just imposed on its own agencies (impact assessments, accountable AI leadership, mandatory training) is a fine place for any private organisation to start. If the government thinks every agency needs a Chief AI Officer, ask who owns AI in your organisation.