Artificial Intelligence in Australia

Controls on generative AI in Australia

Australia has not enacted a generally applicable statute devoted exclusively to generative AI. Generative-AI development and use are regulated through existing laws and, where applicable, sectoral instruments including the Online Safety Act codes and standards.

Privacy and data

Developers and deployers should determine whether training, fine-tuning, retrieval-augmented generation, prompting, logging or other records where they contain personal information, or output handling involves personal information; whether collection, use and disclosure are lawful and fair; whether an APP notice or privacy-policy update is required; whether information is accurate and secure; whether cross-border disclosure rules are engaged; and whether access, correction, retention and deletion obligations apply. Public accessibility does not automatically make data lawful to collect or use for training.

Consent is not universally required for every handling of personal information under the Privacy Act. An entity should determine whether consent is required or relied upon, particularly for sensitive information or secondary uses, and whether another applicable permission or exception is available. The analysis depends on the relevant Australian Privacy Principle and the facts.

The OAIC treats personal information entered into an AI system and personal information contained in system output as potentially regulated, including inferred, inaccurate or hallucinated information about an identified or reasonably identifiable person. The OAIC recommends particular caution with sensitive information and publicly available generative-AI tools.

Cyber security and operational control

AI-specific security analysis should address access control, data leakage, prompt injection, insecure output handling, model inversion or extraction, maliciously modified or poisoned data, supply-chain compromise, model drift, logging, provenance, change control and incident response. Organisations subject to critical-infrastructure, prudential or other cyber security regimes must integrate AI controls with those binding requirements rather than treat AI governance as a standalone exercise.

AI-generated content transparency

The National AI Centre first published voluntary best-practice guidance on AI-generated content transparency, covering labelling, watermarking and metadata recording, on 28 November 2025. The current version, published on 22 April 2026, recommends proportionate disclosure methods such as labelling, watermarking and metadata or provenance measures. This is voluntary best-practice guidance, not a generally applicable statutory labelling regime. Separate binding obligations may arise under consumer, electoral, online-safety, privacy or sector-specific law depending on the content and context.

Continue reading

  • no results

Previous topic
Back to top