AU — Country Profile

Australia

336TOTAL
336OFFICIAL SOURCES
23TOPIC AREAS
Law / Act44
Executive Order29
Policy / Guidance51
National Strategy74
Standard / Framework19
International Agreement20
Working Paper25
Court Case11
Report2
Other61
31 AUG 2026 · National Strategy

AI system implementation issues and risk mitigation: Living evidence

Updated in early 2026, the framework is structured around the principles of community benefit, fairness, privacy/security, transparency, and accountability . The NSW Government also has an associated Agentic AI guide.62, 63 · The NSW Ministry ...

Official materialNational StrategyOfficial source · aci.health.nsw.gov.au ↗
26 AUG 2026 · Other

Meeting of National Cabinet

Official materialNational StrategyOfficial source · pm.gov.au ↗
20 AUG 2026 · Policy / Guidance

Administrative Review Tribunal (Use of Generative AI) Practice Direction 2026

Tribunal practice direction governing verification, explanation and disclosure of generative AI use in submissions and evidence. Signed and effective on 20 August 2026.

Official materialNational StrategyOfficial source · art.gov.au ↗
16 APR 2026 · Policy / Guidance

Federal Court of Australia Practice Note on Generative AI in Proceedings

The Federal Court of Australia released a new Practice Note on the use of Generative AI in proceedings before the Court. It outlines the Court's expectations, highlights potential benefits of Generative AI, and sets clear guidance on responsible use, accountability and disclosure obligations. It identifies areas where particular caution is required, including pleadings, submissions, evidence and confidential material.

Official materialJudicial & Law Enforcement ·Generative AI ·TransparencyOfficial source · fedcourt.gov.au ↗
01 APR 2026 · Standard / Framework

Guidance on assessing application of online safety codes and standards

On 1 April 2026, the eSafety Commissioner published guidance on assessing the application of online safety codes and standards under the Online Safety Act 2021 to help electronic service providers assess which online safety codes and standards apply to their services in respect of unlawful and age-restricted material. As the first step, providers must confirm they offer an electronic service or manufacture or supply related equipment. As the second step, providers must identify whether they o...

Official materialContent ModerationOfficial source · esafety.gov.au ↗
26 MAR 2026 · Executive Order

Online Safety (Age-Restricted Social Media Platforms) Amendment Rules 2026

On 26 March 2026, the Online Safety (Age-Restricted Social Media Platforms) Amendment Rules 2026 entered into force, setting out the platform features that trigger age-restriction obligations. The instrument amends the 2025 Rules to specify that an electronic service is classified as an age-restricted social media platform if it includes a recommender feature or a logged-in feature, such as infinite scrolling feeds, user feedback mechanisms like “likes”, or time-limited ephemeral content. The...

Primary legal sourceConsumer ProtectionOfficial source · legislation.gov.au ↗
25 MAR 2026 · Working Paper

Global Privacy Enforcement Network's inquiry into children's privacy practices on websites and applications

On 25 March 2026, the Global Privacy Enforcement Network (GPEN) published a sweep report examining children's privacy practices across 876 websites and applications. The inquiry found that, while age assurance use has increased since 2015, 88% of platforms relied solely on easily circumvented self-declaration methods. It also highlighted that data collection has intensified, with 85% of privacy policies disclosing third-party data sharing, up from 51% a decade ago. It also found that only 56%...

Official materialNational StrategyOfficial source · datatilsynet.no ↗
24 MAR 2026 · International Agreement

European Union-Australia Free Trade Agreement

On 24 March 2026, the European Union and Australia concluded negotiations for a Free Trade Agreement (FTA), which includes provisions on digital trade. The agreement prohibits unjustified data localisation requirements, enabling cross-border data flows while preserving personal data and privacy protection. It also removes certain distinctions between online and offline trade, prohibits customs duties on electronic transmissions, and includes provisions on source code, electronic contracts, an...

Primary legal sourceNational StrategyOfficial source · ec.europa.eu ↗
23 MAR 2026 · Working Paper

eSafety Commissioner assessment of Character Technologies (character.ai) regarding compliance with Basic Online Safety Expectations

On 23 March 2026, Australia’s eSafety Commissioner published interim findings concerning Character Technologies (character.ai) compliance with Basic Online Safety Expectations (BOSE). In response to a notice requesting information regarding BOSE compliance issued 16 October 2025, Character Technologies reported that it had made or intended to make improvements to child safety. Such improvements include age assurance mechanisms, restricting access to open-ended chat with AI companions, and imp...

Official materialContent ModerationOfficial source · esafety.gov.au ↗
18 MAR 2026 · Other

European Union-Australia Security and Defence Partnership

On 18 March 2026, the European Union (EU) and Australia signed the Security and Defence Partnership. The agreement establishes a framework for the two parties to exchange expertise on their respective cybersecurity frameworks and share information to prevent, deter, and respond to malicious cyber activities. The agreement includes provisions for regular consultations on artificial intelligence (AI), including its responsible use in security and defence contexts. Furthermore, the parties will ...

Official materialNational StrategyOfficial source · eeas.europa.eu ↗
17 MAR 2026 · Policy / Guidance

Privacy guidance on age assurance technologies

On 17 March 2026, the Office of the Australian Information Commissioner (OAIC) released privacy guidance on age assurance technologies aimed at organisations and public authorities subject to the Privacy Act (APP entities) that are considering implementing systems involving the collection, use, or disclosure of personal information. The guidance is intended to support compliance with the Privacy Principles (APPs) and to help both regulated entities and third-party providers assess and manage ...

Official materialConsumer ProtectionOfficial source · oaic.gov.au ↗
04 MAR 2026 · Executive Order

Cyber Security Rules 2025 for Smart Devices

On 4 March 2026, the Cyber Security (Security Standards for Smart Devices) Rules 2025, covering consumer-grade smart devices enter into force. The rules establish mandatory security standards for consumer-grade connectable products acquired in Australia, excluding smartphones, tablets, desktop and laptop computers, road vehicles and components, and therapeutic goods. Manufacturers must ensure that each device has a unique password or user-defined credentials, and that passwords are not based ...

Primary legal sourceNational StrategyOfficial source · legislation.gov.au ↗
03 MAR 2026 · Other

Global Coalition on Telecommunications' 6G security and resilience principles

On 3 March 2026, the telecommunications authorities from Japan, the United Kingdom, Australia, Canada, and the United States adopted the Global Coalition on Telecommunications' 6G security and resilience principles. The principles outline security and resilience considerations that should be incorporated from the early stages of network design, standardisation, and deployment to ensure that 6G infrastructure functions safely and reliably as critical digital infrastructure. The principles reco...

Official materialNational StrategyOfficial source · soumu.go.jp ↗
27 FEB 2026 · Law / Act

Privacy guidance for reporting entities under Anti-Money Laundering and Counter-Terrorism Financing Act

On 27 February 2026, the Office of the Australian Information Commissioner released privacy guidance for reporting entities under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (AML/CTF Act). The guidance explains the application of the Privacy Act 1988 to reporting entities and authorised agents when handling personal information for the purposes of, or in connection with, AML/CTF obligations. It clarifies that reporting entities, including small businesses with an annual...

Primary legal sourceNational StrategyOfficial source · oaic.gov.au ↗
26 FEB 2026 · Law / Act

eSafety Commissioner evaluation of Social Media Minimum Age under Online Safety Amendment (Social Media Minimum Age) Act 2024

On 26 February 2026, the eSafety Commissioner commenced an evaluation of Australia’s social media minimum age to assess implementation of the new obligation on platforms and its impacts on children. The evaluation concerns the Online Safety Amendment (Social Media Minimum Age) Act 2024, which commenced on 10 December 2025 and requires age-restricted social media platforms to take reasonable steps to prevent Australians under the age of 16 from creating or keeping an account, with preliminary ...

Primary legal sourceConsumer ProtectionOfficial source · esafety.gov.au ↗
19 FEB 2026 · Policy / Guidance

Guidance on quantum technology pertaining to computing

On 19 February 2026, the Cyber Security Centre adopted the guidance on quantum technology pertaining to computing. The guidance explains how quantum computing may affect cybersecurity and calls for early preparedness for post-quantum risks. It applies to small and medium businesses, large organisations, critical infrastructure operators, and government bodies that rely on cryptography, cloud services, or high-performance computing. The guidance outlines the differences between quantum and cla...

Official materialNational StrategyOfficial source · cyber.gov.au ↗
13 FEB 2026 · Other

Securities and Investments Commission investigation into FIIG Securities over alleged failure to meet cybersecurity requirements (Securities and Investments Commission v FIIG Securities Limited/No. QUD144/2025)

On 13 February 2026, the Federal Court of Australia ordered FIIG Securities Limited (FIIG) to pay a pecuniary penalty of AUD 2'500'000 for contravening its Australian Financial Services licence obligations under section 912A of the Corporations Act 2001 (Cth) between 13 March 2019 and 8 June 2023. The Court found that FIIG failed to maintain adequate technological, human, and financial resources, as well as appropriate risk management systems, to manage cybersecurity risks. These deficiencies...

Official materialNational StrategyOfficial source · asic.gov.au ↗
14 JAN 2026 · Policy / Guidance

Guidance on managing cyber security risks in Artificial intelligence for small business

On 14 January 2026, the Australian Signals Directorate's Australian Cyber Security Centre (ASD's ACSC) published guidance on managing cybersecurity risks of artificial intelligence for small businesses, aimed at managing cybersecurity risks when adopting cloud-based artificial intelligence (AI) technologies. The guidance aims to address vulnerabilities such as data leaks, privacy breaches, unreliable AI outputs, and supply chain dependencies. It clarifies that businesses should implement inte...

Official materialNational StrategyOfficial source · cyber.gov.au ↗
27 DEC 2025 · Executive Order

Hosting Services Online Safety Code (Class 1C and Class 2 Material) under Online Safety Act 2021

On 27 December 2025, the Hosting Services Online Safety Code (Class 1C and Class 2 Material) under the Online Safety Act 2021 enters into force. The Code was developed by the Australian online industry, including the Australian Mobile Telecommunications Association (AMTA), the Communications Alliance, the Consumer Electronics Suppliers Association (CESA), the Digital Industry Group Inc (DIGI), and the Interactive Games and Entertainment Association (IGEA). It applies to services that store co...

Primary legal sourceContent ModerationOfficial source · esafety.gov.au ↗
15 DEC 2025 · Policy / Guidance

Australia - Policy for Responsible Use of AI in Government v2.0

Australia's Policy for the responsible use of AI in government (Version 2.0, effective 15 December 2025) guides Australian government agencies on responsible AI use. The policy mandates transparency for automated decision-making.

Official materialGovernment AI Policy ·Transparency ·Automated Decision-MakingOfficial source · digital.gov.au ↗
10 DEC 2025 · Law / Act

Online Safety Amendment (Social Media Minimum Age) Act 2024

On 10 December 2025, the requirement for providers of age-restricted social media platforms to take reasonable steps to prevent users under 16 years of age from having accounts enters into force, following a commencement date set within the 12-month implementation period allowed after the Online Safety Amendment (Social Media Minimum Age) Act’s commencement. From this date, all accounts held by users under 16 years of age, including those created before the enforcement start date, became subj...

Primary legal sourceConsumer ProtectionOfficial source · minister.infrastructure.gov.au ↗
10 DEC 2025 · Executive Order

Minister of Communications Online Safety (Age-Restricted Social Media Platforms) Rules, 2025

On 10 December 2025, the Online Safety (Age-Restricted Social Media Platforms) Rules 2025 enter into force. The rules define which services are excluded from being classified as age-restricted social media platforms under the Online Safety Act 2021. The rules specify that services primarily designed for messaging, calling, gaming, product reviews, professional networking, education, or health are not considered age-restricted platforms. This also includes services that significantly facilitat...

Primary legal sourceConsumer ProtectionOfficial source · legislation.gov.au ↗
05 DEC 2025 · Standard / Framework

Online Safety Codes and Standards Regulatory Guidance

On 5 December 2025, the eSafety Commissioner published the Online Safety Codes and Standards Regulatory Guidance. The guidance is designed to assist service providers regulated by the Online Safety Codes and Standards, including the Unlawful Material Codes (1A and 1B), Unlawful Material Standards (1A and 1B), and Age-Restricted Material Codes (1C and 2). The guidance details a non-exhaustive list of services covered by the Codes and Standards, details which regulations apply to which sections...

Official materialContent ModerationOfficial source · esafety.gov.au ↗
04 DEC 2025 · Policy / Guidance

Guidance regarding Generative AI tools in workplace

On 4 December 2025, the Office of the Australian Information Commissioner (OAIC) published guidance outlining the privacy risks and management strategies for businesses integrating Generative AI (GenAI) tools in workplaces. The guidance highlighted that GenAI use presents challenges for personal information protection, reminding entities subject to Australia's Privacy Act to avoid inputting sensitive data into publicly available GenAI tools due to control difficulties. Businesses must activel...

Official materialNational StrategyOfficial source · oaic.gov.au ↗
27 NOV 2025 · Working Paper

eSafety Commissioner issued enforcement action against technology company responsible for AI generated nudify services used to create deepfake pornography

On 27 November 2025, the eSafety Commissioner issued an enforcement action under the Online Safety Act against a provider of three nudify services based in the United Kingdom, resulting in the provider restricting access for Australian users. The action applies to Artificial Intelligence (AI) image-manipulation tools and AI model-hosting platforms, with the services previously receiving around 100,000 visits per month from Australia. It was also stated that penalties of up to AUD 49.5 million ma

Official materialContent ModerationOfficial source · esafety.gov.au ↗
25 NOV 2025 · Executive Order

Order establishing Australian Artificial Intelligence Safety Institute

On 25 November 2025, the Australian Government announced the establishment of the Australian Artificial Intelligence Safety Institute (AISI) to support best practice regulation, advise on legislative updates, and support regulatory action. The AISI is intended to provide technical capability for monitoring, testing and analysing emerging AI technologies, and to support the government in identifying future AI-related risks to ensure appropriate protections for the public. The AISI will operate...

Primary legal sourceNational StrategyOfficial source · industry.gov.au ↗
24 NOV 2025 · Law / Act

Content moderation regulation in Online safety and other legislation amendment (My face, My rights) Bill 2025

On 24 November 2025, the Online safety and other legislation amendment (My face, My rights) Bill 2025, including content moderation regulation, was introduced to the Senate. The Bill defines deepfake material as any realistic, technology-generated, or altered image, audio, or audio-visual content that falsely depicts an Australian person’s face, voice, or their attributes, and defines the person depicted by the deepfake as the subject of that material. The Bill defines non-consensual deepfake...

Primary legal sourceContent ModerationOfficial source · parlinfo.aph.gov.au ↗
20 NOV 2025 · Other

Cross-border data transfer regulation in CPTPP-ASEAN Trade and Investment Dialogue Joint Ministerial Statement

On 20 November 2025, Parties to the Comprehensive and Progressive Agreement for Trans-Pacific Partnership (CPTPP) and ASEAN Members announced the CPTPP-ASEAN Trade and Investment Dialogue Joint Ministerial Statement, including cross-border data transfer regulation provisions. The Statement included a commitment to continue cooperation on the facilitation of cross-border data flows and endorsed efforts to effect the incorporation of the Agreement on Electronic Commerce with the World Trade Org...

Official materialNational StrategyOfficial source · asean.org ↗
02 NOV 2025 · International Agreement

PIPC, CNIL, OAIC, ICO and DPC declaration on AI and data protection regulation

Official source record dated 2025-11-02 for Australia concerning PIPC, CNIL, OAIC, ICO and DPC declaration on AI and data protection regulation. See the linked cnil.fr source for the authoritative text, procedural context, and implementation details.

Primary legal sourceNational StrategyOfficial source · cnil.fr ↗
01 NOV 2025 · International Agreement

APEC Leaders' Gyeongju Declaration

On 1 November 2025, APEC leaders issued the Gyeongju Declaration, outlining measures to support digital and AI development. The declaration notes the growing role of data in the digital economy and outlines commitments to increase cooperation to facilitate cross-border data flows. APEC members reaffirmed support for the Internet and Digital Economy Roadmap (AIDER) and encouraged sharing information on ICT and digital policies to support regional economic cooperation. The declaration also addr...

Primary legal sourceNational StrategyOfficial source · apec.org ↗
31 OCT 2025 · Policy / Guidance

Guidance on strengthening Microsoft Exchange Server security

On 31 October 2025, Australian Cyber Security Centre issued guidance on strengthening Microsoft Exchange Server security. The guidance describes best practices for organisations using Microsoft Exchange Server environments to protect them from malicious actors. Specifically, the Centre recommends measures like ensuring that servers are updated with the latest patches and migrated to supported versions. Further, organisations should enable Microsoft's inbuilt protection features, strengthen au...

Official materialNational StrategyOfficial source · cyber.gov.au ↗
27 OCT 2025 · Court Case

Australian Competition and Consumer Commission lawsuit against Microsoft over alleged misleading conduct

On 27 October 2025, the Australian Competition and Consumer Commission (ACCC) announced a lawsuit against Microsoft and its subsidiary Microsoft Australia, alleging misleading or deceptive conduct and false or misleading representations under sections 18, 29(1)(i), (l), and (m) of the Australian Consumer Law (ACL). The ACCC claims that since 31 October 2024, Microsoft offered existing Microsoft 365 Personal or Family subscribers a choice between continuing their subscription with artificial i...

Court recordConsumer ProtectionOfficial source · accc.gov.au ↗
26 OCT 2025 · Executive Order

Amendments to Copyright Laws

On 26 October 2025, the Attorney-General announced that the Government is consulting on potential updates to Australia’s copyright laws to address challenges arising from artificial intelligence (AI). The Government confirmed it will not introduce a text and data mining exception, which would have allowed AI developers to use creators’ works without payment. The Copyright and AI Reference Group will discuss options to encourage fair and legal access to copyright material for AI use, assess wh...

Primary legal sourceIntellectual PropertyOfficial source · ministers.ag.gov.au ↗
20 OCT 2025 · Policy / Guidance

Guidance for individuals and small and medium businesses on cloud shared responsibility model

On 20 October 2025, the Australian Cyber Security Centre (ACSC) released guidance on the cloud shared responsibility model for individuals and small and medium businesses. It outlines how security responsibilities are divided between customers and cloud service providers (CSPs), depending on the type of service used. CSPs are accountable for securing infrastructure and third-party operations, while customers must safeguard their data, control user access, maintain software and device security...

Official materialNational StrategyOfficial source · cyber.gov.au ↗
20 OCT 2025 · Policy / Guidance

Guidance on cloud shared responsibility model

On 20 October 2025, the Australian Cyber Security Centre (ACSC) released executive guidance on the cloud shared responsibility model for government, critical infrastructure, and large organisations. It explains that cybersecurity duties are shared between cloud service providers (CSPs) and customers, but ultimate responsibility for data remains with the customer. Organisations must understand legislative obligations, know which cloud services they use, and assess risks based on data sensitivi...

Official materialNational StrategyOfficial source · cyber.gov.au ↗
16 OCT 2025 · Policy / Guidance

Guidance on artificial intelligence and machine learning concerning supply chain risks and mitigation

On 16 October 2025, the Australian Signals Directorate (ASD) issued guidance on artificial intelligence (AI) and machine learning (ML), focusing on supply chain risks and mitigation. The guidance addressed to organisations and personnel involved in the development or deployment of AI and ML systems and components. It highlights potential vulnerabilities across the AI/ML supply chain, covering AI data, ML models, AI software, infrastructure and hardware, and third-party services. Specific dat...

Official materialNational StrategyOfficial source · cyber.gov.au ↗
15 OCT 2025 · Policy / Guidance

Guidance on strengthening network infrastructure

On 15 October 2025, the Australian Signals Directorate (ASD) published guidance aimed at strengthening the network infrastructure of medium-to-large organisations and government entities. The guidance provides advice for executive and technical staff on protecting internet-facing and internal network devices from unauthorised access, lateral movement, and data exfiltration. It complements existing ASD advice on securing edge devices by extending mitigations across core routing, switching, and...

Official materialNational StrategyOfficial source · cyber.gov.au ↗
13 OCT 2025 · Policy / Guidance

Signals Directorate's Critifical Infrastructure Fortify guidance for operators

On 13 October 2025, the Australian Signals Directorate (ASD) released "Critical Infrastructure (CI) Fortify," a guidance document for CI operators. It applies to large organisations and government entities managing operational technology (OT) and essential services. The guidance urges operators to maintain updated OT inventories, identify vital systems, isolate them from external networks for up to three months, and rebuild them quickly using trusted backups. It responds to rising state-spons...

Official materialNational StrategyOfficial source · cyber.gov.au ↗
10 OCT 2025 · Law / Act

Office of the Australian Information Commissioner Privacy guidance on Part 4A (Social Media Minimum Age) of the Online Safety Act 2021

On 10 October 2025, the Office of the Australian Information Commissioner (OAIC) released the Privacy Guidance on Part 4A of the Online Safety Act 2021, addressing the Social Media Minimum Age (SMMA) scheme and its interaction with the Privacy Act 1988 and the Australian Privacy Principles. The guidance applies to providers of age-restricted social media platforms and third-party age assurance providers and sets out obligations under Section 63F of Part 4A, including purpose limitation, destr...

Primary legal sourceConsumer ProtectionOfficial source · oaic.gov.au ↗
08 OCT 2025 · Law / Act

Regulatory Reform Omnibus Bill 2025 including amendments to Australian Communications and Media Authority Act

On 8 October 2025, the Regulatory Reform Omnibus Bill 2025, including amendments to the Australian Communications and Media Authority (ACMA) Act, was introduced to the House of Representatives. The Act establishes the ACMA, defines its functions and powers and covers the ACMA's telecommunications, spectrum, broadcasting, content, and datacasting roles. The Bill seeks to increase ACMA’s efficiency by updating delegation rules for legislative instruments. The amendments apply to communications ...

Primary legal sourceContent ModerationOfficial source · parlinfo.aph.gov.au ↗