In September 2024, Australia announced 10 mandatory guardrails for high-risk AI — real, binding requirements with real teeth. Fifteen months later, the government shelved every one of them. Australia's National AI Plan, released December 2025, is the clearest example yet of a government choosing "existing law is enough" over dedicated AI legislation, and it's worth understanding both what got abandoned and what replaced it.
Australia proposed 10 mandatory AI guardrails in September 2024, then abandoned them entirely in its December 2025 National AI Plan, opting instead for "technology-neutral" regulation using existing laws (Privacy Act, Consumer Law) plus a non-binding AI Safety Institute launched early 2026. There is no AI-specific statute and no immediate plan to introduce one.
The 2024 Proposal That Almost Became Law
In September 2024, then-Industry Minister Ed Husic released a proposals paper outlining 10 mandatory guardrails for AI in "high-risk settings" — covering testing, transparency, and accountability obligations for both developers and deployers. The paper laid out three possible implementation paths: amending existing sector-specific legislation, introducing framework legislation, or passing a standalone, whole-of-economy AI Act with a dedicated regulator. This looked, at the time, like a clear trajectory toward binding EU-style regulation.
Why It Got Shelved
Public consultation drew over 300 responses, with industry feedback — including from DIGI, the lobbying group representing Apple, Google, Meta, and Microsoft in Australia — arguing the guardrails would hinder productivity and innovation without corresponding safety benefit. The Productivity Commission separately estimated AI could deliver up to $116 billion in economic value to Australia and explicitly welcomed the pivot away from mandatory guardrails, arguing such requirements risked stifling that opportunity. By December 2025, the National AI Plan confirmed the guardrails were dead, replaced by a "technology-neutral" approach: rely on existing law — the Privacy Act, Australian Consumer Law, the Copyright Act, sector-specific rules — rather than write AI-specific statute.
The reversal wasn't uncontested. AI governance experts, including researchers like Dr. Rebecca Johnson, publicly criticized the Plan for lacking a clear enforcement mechanism and prioritizing economic opportunity ahead of safety. Critics specifically flagged deepfakes, algorithmic bias, and autonomous decision-making as areas where existing, non-AI-specific law may leave real gaps.
What Replaced the Guardrails
- Guidance for AI Adoption (GfAA). Published October 2025, this non-binding guidance condenses the original 10 mandatory guardrails into six essential practices — more prescriptive than Australia's prior voluntary standard, but still carrying no legal force.
- Australian AI Safety Institute (AISI). Launched early 2026 with AUD $29.9 million in funding, AISI tests systems, assesses risks, and recommends targeted reforms — but it's explicitly a monitoring and advisory body with no power to compel compliance. It joins the International Network of AI Safety Institutes alongside comparable bodies in the US, UK, Canada, and South Korea.
- Automated decision-making transparency, effective December 10, 2026. New privacy law amendments (APP 1.7–1.9) will require entities to disclose, in their privacy policies, the categories of personal information used in substantially automated decisions and the nature of decisions that could significantly affect individual rights — a real, binding obligation, just one routed through privacy law rather than a dedicated AI statute.
Existing Law Is Already Being Tested
Australia's "existing law is sufficient" thesis is being actively tested in real enforcement matters. In February 2026, the Administrative Review Tribunal reviewed a 2024 finding that hardware retailer Bunnings had breached privacy law through its use of AI facial recognition — and found Bunnings was entitled to rely on exemptions for the limited purpose of combating retail crime, a result that illustrates how unpredictable outcomes can be when AI-specific conduct is assessed under general-purpose privacy law never written with AI in mind. Separately, the Australian Competition and Consumer Commission has flagged "AI-washing" — misleading claims about AI capabilities — as an active enforcement priority under existing consumer law, and corporate penalties for misleading conduct doubled to AUD $100 million per contravention effective March 28, 2026.
How This Compares to Other Regulatory Reversals
Australia's U-turn joins a small but notable pattern of jurisdictions that proposed EU-style comprehensive AI frameworks and then pulled back before enactment or shortly after. Colorado actually passed its comprehensive law and then repealed it in favor of something narrower. Texas rewrote its bill before passage, never enacting the risk-tier model its own original draft used. Australia never got as far as introducing legislation at all — its reversal happened entirely at the proposal stage, making it the most complete abandonment of the three, and a useful data point for anyone assuming international regulatory convergence toward the EU model is inevitable.
What This Means for Organizations Operating in Australia
- There is no AI-specific compliance obligation to track in Australia today beyond the December 2026 ADM transparency requirement — but that doesn't mean AI activity is unregulated, since privacy, consumer, and copyright law all apply in full.
- Treat the Guidance for AI Adoption as a genuine best-practice benchmark even though it's non-binding — regulators and the AI Safety Institute are likely to reference it when assessing whether an organization acted reasonably under existing law.
- Watch AISI's gap-analysis outputs closely. If it identifies deficiencies existing law genuinely can't reach, that's the most likely pathway toward future AI-specific legislation — the government has left that door open even while shelving the 2024 proposal.
- Don't assume Australia is a low-priority jurisdiction because it lacks dedicated AI law — the ACCC's active AI-washing enforcement focus and doubled penalty regime mean real, current legal exposure exists under general consumer law.
Frequently Asked Questions
Does Australia have an AI Act like the EU?
No. Australia proposed 10 mandatory AI guardrails in 2024 but abandoned them in its December 2025 National AI Plan, opting for a technology-neutral approach using existing privacy, consumer, and copyright law instead.
What is Australia's AI Safety Institute?
A body launched in early 2026 with AUD $29.9 million in funding to test AI systems, assess risks, and recommend reforms — it has no enforcement power and functions purely in an advisory and monitoring capacity.
Is there any binding AI-specific law in Australia?
The clearest example is automated decision-making transparency obligations under amended privacy law, taking effect December 10, 2026, requiring disclosure of personal data used in significant automated decisions.
Why did Australia abandon its proposed mandatory AI guardrails?
Industry lobbying, a Productivity Commission economic analysis favoring innovation over binding requirements, and over 300 consultation responses raising concerns about productivity impact all contributed to the reversal.
Related reading: Canada's abandoned AIDA legislation, the UK's deliberate no-AI-Act approach, and China's layered AI regulatory framework.