Sonia Sharma
Sonia has wide ranging experience advising on technology, cyber, telecommunication and general commercial matters, specialising in cyber and data resilience advice.
View profile
Maddocks contributed to the 4th Edition of the Legal 500: Capital Markets Comparative Guide — a country-specific Q&A providing an overview of Artificial Intelligence laws and regulations applicable in Australia.
Australia has no single statutory or judicial definition of “artificial intelligence”.
Australian regulators and courts commonly distinguish between ‘machine learning’ or LLMs and AI, and often adopt or reference the Organisation for Economic Co-operation and Development’s (OECD’s) definition, which describes an ‘AI system’ as:
“… a machine-based system that, for explicit or implicit objectives, infers, from the input it receives, how to generate outputs such as predictions, content, recommendations, or decisions that can influence physical or virtual environments. Different AI systems vary in their levels of autonomy and adaptiveness after deployment.”
Australia’s national Privacy Regulator, the Office of the Australian Information Commissioner, notes that, “while there is no single agreed definition of artificial intelligence (AI), as a general term it refers to the ability of machines to perform tasks which normally require human intelligence.”
Although the Australian courts have engaged with AI in specific contexts, these cases have not yet defined AI as a legal concept and there is currently no judicially agreed definition of artificial intelligence.
The Commonwealth Government released a National AI Plan on 2 December 2025 that sets out the steps the Australian Government will take to “support Australia to build an AI-enabled economy that is more competitive, productive and resilient”.
The National AI Plan has three objectives: capturing economic opportunities, sharing benefits across society, and keeping Australians safe through robust legal and regulatory frameworks.
Key implementation measures from the National AI Plan include:
The Australian government has implemented several of its identified key measures since the National AI Plan was released, including by allocating $70 million in grant funding to the AI Accelerator to help develop local AI capability and $30 million to the establishment of AISI. In May 2026, Australia also signed agreements with partner AISI institutes in the UK and Canada, giving AISI access to shared testing methods, shared expertise, and shared intelligence on the risks of advanced AI systems.
While there are no published plans to formally revise the National AI Plan, the establishment of the Office of AI in July 2026 to develop and legislate the mandatory Australian Standards for AI represents a significant new implementation measure that is likely to materially affect Australia’s AI governance framework. See Questions 3 and 16 for further details.
Unlike the EU, Australia has not adopted a dedicated legislative framework for the regulation of AI systems or products. Instead, Australia seeks to adopt a technology-neutral approach to AI regulation, relying on existing laws (including privacy, consumer, copyright, discrimination and sector-specific regulation), supplemented by targeted legislative reforms and regulatory guidance to address the use of AI in relation to identified high-risk use cases.
To date, examples of targeted legislative reform include:
Australia has focused heavily on producing guidance and governance measures to assist businesses and organisations with the adoption and deployment of AI systems, including Guidance for AI Adoption (October 2025), published by the National AI Centre (NAIC), which streamlined the 10 Voluntary AI Safety Standards (2024) and Australia’s 8 AI Ethics Principles (2019) into six essential AI practices to support safe and responsible use of artificial intelligence.
In July 2026, the Commonwealth Government announced plans to legislate AI standards for data centres, reiterated its intention to ensure that creative works are protected by copyright, and announced the establishment of a new Office of AI.
Key takeaways from the announcement are as follows:
From 10 December 2026, under new Australian Privacy Principles (APP) 1.7 to 1.9, entities covered by the Privacy Act (APP Entities) must disclose in their APP 1 Privacy Policy the use of automated decision making (ADM), where they have used computer programs (including artificial intelligence) and personal information to make a decision that could be reasonably expected to significantly affect the rights or interests of an individual.
Under APP 1.8, APP entities must update their privacy policies to disclose:
In addition to the mandatory ADM obligations set out above, APP entities also have notification obligations under the Privacy Act to:
In relation to both notification obligations, guidance from the Australian Privacy Regulator, the Office of the Australian Information Commissioner (OAIC), sets out expectations regarding the level of granularity and specificity of information to be provided, which will vary depending on the nature, context and sensitivity of the personal information being collected. Where artificial intelligence is used to collect, use or otherwise process personal information, including for the development, testing or training of artificial intelligence systems, in addition to mandatory ADM disclosure requirements, APP entities should have regard to APP 1 and APP 5 and their associated transparency requirements more generally. Consistent with guidance from the Privacy Regulator, APP Entities should also update their APP 1 privacy policies and APP 5 notifications with clear and transparent information about their use of AI, including ensuring that any public facing AI tools (such as chatbots) are clearly identified as such to users.
Regarding audits and explainability, there are currently no specific legal requirements for AI audits under Australian law. However, existing technology-neutral obligations will apply to AI systems that handle personal information. For example, APP 11 requires APP entities to take reasonable steps to implement organisational and technical measures to protect personal information. This includes maintaining appropriate logs (such as AI incident logs) and putting in place measures to monitor how the AI system performs. Regulatory guidance from the OAIC also encourages organisations to keep records of, and to test and monitor, any AI systems used in connection with personal information. In addition, APP 1 requires an APP Entity to take reasonable steps to comply with the APPs. Consistent with guidance from the Privacy Regulator, organisations considering the use of AI products should consider taking a ‘privacy by design’ approach, which includes conducting a Privacy Impact Assessment and establishing policies and procedures for the use of AI systems to facilitate transparency and ensure good privacy governance. Recent enforcement action in Australia indicates that, for an AI deployment, “reasonable steps” for the purpose of APP 1 and 11 would be closely examined, including in respect of transparency, explainability and audits.
While not mandated, ‘Share essential information’ is also one of the 6 Essential AI Practices, which encourages organisations to inform users and stakeholders when and how they are interacting with AI. The Privacy Regulator also strongly encourages businesses and organisations to provide clear and transparent information about their use of AI generally in their privacy policies.
There are no legislative requirements in Australia that expressly require human oversight and human-in-the-loop in AI systems. However, recent guidance in the form of strongly worded warning letters calling for urgent attention on managing AI risks from Australian regulators such as APRA, ASIC and the ACSC reflects a consistent regulatory expectation that organisations deploying AI implement robust governance, accountability and risk management frameworks.
Common themes include board and senior management responsibility for AI-related risks, maintaining sufficient AI literacy to support effective oversight, implementing governance and monitoring processes proportionate to the relevant use case, ensuring clear accountability for AI outcomes, and maintaining meaningful human oversight, or a “human-in-the-loop” approach, for high-risk, consequential or customer-facing decisions. Taken together, this guidance indicates an increasing expectation that organisations adopt structured governance arrangements for the safe, responsible and sustainable use of AI throughout its lifecycle, supported by appropriate policies, controls, documentation, training and ongoing oversight. APRA and ASIC both have enforcement powers and have demonstrated an increased willingness to hold Boards and directors to account where governance and risk management failures occur in respect of cyber security issues more generally.
In addition to the recent regulatory letters, the following guidance and determination have also been released:
In light of the strong regulatory focus on AI risk management and warnings issued in regulatory guidance, a failure to implement appropriate oversight, governance and accountability measures may increase regulatory enforcement risk, including regulatory investigations, remediation requirements, infringement notices, licence-related consequences and, in appropriate circumstances, enforcement action against the organisation and its responsible officers.
Australia has no AI-specific anti-discrimination legislation addressing algorithmic bias. However, existing federal and state anti-discrimination laws (including the Fair Work Act 2009 (Cth), Racial Discrimination Act 1975 (Cth), Sex Discrimination Act 1984 (Cth), Disability Discrimination Act 1992 (Cth) and Age Discrimination Act 2004 (Cth)) apply regardless of whether a decision is made by a human or an AI system.
In the Australian Human Rights Commission’s Technical Paper: Addressing Algorithmic Bias (2020) the AHRC established that algorithmic bias can constitute unlawful direct or indirect discrimination under these statutes, and recommended rigorous design, testing and monitoring to avoid it.
A number of Australian, state and territory governments have developed and adopted published guidance or policies which incorporate principles relating to the ethical use of AI and with a stated intention to ensure use of AI complies with legal protections for human rights and basic principles of fairness.
The Australian Consumer Law may also capture unfair algorithmic outputs, with the Australian Competition and Consumer Commission confirming that entities cannot avoid liability for misleading or deceptive conduct by attributing it to an automated system.
While there is no AI-specific liability statute in Australia, the Australian Government’s 2025 Review of AI and the Australian Consumer Law (Review) concluded that the existing technology-neutral protections under the Australian Consumer Law (ACL), which is Schedule 2 to the Competition and Consumer Act 2010 (Cth), are generally capable of addressing AI-related consumer law risks. This means that the established principles under the ACL regarding misleading or deceptive conduct, false representations, consumer guarantees and product safety provisions would apply to AI-enabled goods and services.
Under the ACL, manufacturers may be held liable in respect of personal injury and property damage caused by a “safety defect” in their product. Goods have a “safety defect” if they are not as safe as a consumer would generally expect. The ACL defines the scope of a “manufacturer” broadly to include persons who produce goods (including computer software) as well as importers and persons who permit their brand to be applied to goods. This broad definition could encompass AI developers, deployers, suppliers or distributors depending on the circumstances.
The burden of proof lies with the claimant seeking a remedy. The claimant must establish, on the balance of probabilities, that the claimed loss was caused by a failure of a consumer guarantee or malfunction of a good. Claimants can take legal action against manufacturers or lodge a complaint with the regulator.
Under the consumer guarantees regime in the ACL, customers of defective AI products may also have recourse against a supplier (including retailers) that is not a manufacturer. The consumer guarantees regime provides for non-excludable warranties in respect of goods and services supplied to consumers – for example, products and services must be of acceptable quality.
There is no single cybersecurity legislation or framework that applies exclusively to AI systems.
However, there are a number of cybersecurity-related policies and legislative frameworks that apply to technology systems generally, including AI systems and systems which use or host AI models.
Legislative frameworks include:
At the State and Territory governmental level, AI systems are also generally regulated through existing privacy, information management and public sector governance legislation rather than AI-specific statutes. Key examples include various State and Territory privacy acts that are similar to the Privacy Act 1988 (Cth). However:
Government entities may also be subject to separate policy requirements relevant to cyber security. Government entities may ‘flow down’ obligations to comply with these policy requirements when purchasing relevant goods and services from private industry. These include obligations not to use certain banned AI systems, and other relevant obligations relating to location of hosting for certain types of data, encryption and cybersecurity risk assessments.
Yes. While dedicated AI insurance products are still emerging, AI-related risks are often already covered under existing insurance policies through so-called “silent AI” coverage, where policies respond to AI-related losses without expressly referring to AI.
Insurance in Australia is generally technology-neutral, and AI-specific claims data remains relatively limited. As a result, insurers typically assess AI-related losses under traditional insurance lines unless coverage is expressly excluded. Depending on the circumstances, AI-related risks may be covered under professional indemnity, directors’ and officers’ liability, product liability, cyber, employment practices liability, and property damage/business interruption policies.
Cyber insurance is currently one of the primary forms of cover for AI-related risks. Traditional cyber policies generally respond to losses arising from privacy breaches, security failures, incident response and recovery costs, data restoration, media liability, and business interruption. Insurers are increasingly incorporating AI-specific underwriting questions and, in some cases, issuing AI-related endorsements as they seek to better understand and price AI risk.
However, coverage may be limited by exclusions, sub-limits, or other policy restrictions. Common areas of concern include intellectual property infringement, discriminatory or biased AI outputs, performance or warranty-related claims, regulatory investigations and penalties, and systemic or catastrophic cyber events.
Organisations adopting AI should carefully review their existing insurance arrangements to determine whether AI-related losses are covered and whether any exclusions, conditions, or coverage gaps may apply. In some cases, organisations may need to seek bespoke endorsements or specialised cyber coverage to address AI-specific risks.
Artificial intelligence cannot be named as an inventor for a patent application filed in Australia. The current legal position is that an inventor must be a natural person (which was established by an enlarged bench of the Full Court of the Federal Court of Australia in Commissioner of Patents (Cth) v Thaler [2022] FCAFC 62, and effectively endorsed by the High Court of Australia by its refusal to grant Mr Thaler special leave to appeal the decision).
In Australia, AI-generated work without any human contribution is unlikely to attract copyright protection. Under the Copyright Act 1968 (Cth), copyright protection is granted to original literary, dramatic, musical and artistic works that originate from an “author” and are expressed in material form.
While ‘author’ is not defined in the Copyright Act 1968 (Cth), Australian courts have consistently interpreted “author” as requiring human authorship. In Telstra Corporation Ltd v Phone Directories Co Pty Ltd [2010] FCAFC 149, the Full Federal Court held that works generated by automated processes without sufficient human ‘intellectual effort’ did not attract copyright protection.
While it’s possible that where a human exercises sufficient creative control, for example through detailed prompting, curation, editing and selection, the human authorship requirement may be satisfied, with copyright protection vesting in that individual, this position remains untested by Australian courts in the generative AI context.
In July 2026, the Australian Government also reiterated its intention to strengthen copyright protections for artists, writers and musicians (for more about this see Question 3).
The main workplace issues to consider when using AI systems include:
Australia’s existing workplace and discrimination laws are technology-neutral and employers remain responsible and liable for decisions made or materially influenced by AI, including recruitment, promotion, performance management or dismissal decisions. Employers must also assess and manage AI related risks in order to comply with their general WHS duty of care.
NSW is currently the first Australian State to specifically regulate AI risks in the workplace. Under recent amendments to its WHS laws (yet to commence), a person conducting a business or undertaking must:
The amendments also empower union officials to access and inspect a PCBU’s digital work systems relevant to a suspected breach of WHS obligations.
The main privacy and data protection issues arising from AI development and use in Australia relate to the collection, use, disclosure and retention of personal information, particularly where AI systems are trained on large datasets containing personal information. Key risks include:
The main data protection authority in Australia, the Office of the Australian Information Commissioner (OAIC) has issued substantial guidance on these issues. The OAIC’s central position is that there is no “AI exemption” from the Privacy Act; existing APP obligations apply to AI inputs, training data and outputs.
Key takeaways from the OAIC guidance include:
Overall, Australian regulators are taking the view that existing privacy laws already apply to AI, and organisations must adopt a “privacy by design” approach when developing and deploying AI systems.
Data scraping activities present multiple legal and regulatory risks.
The Privacy Act imposes obligations on entities governed by the Act who ‘data scrape’ personal information. Under Australian Privacy Principle 3, businesses may generally only collect personal information directly from the individual unless it is unreasonable or impracticable to do so. Consent is also required where the collection of personal information pertains to sensitive information. There are very limited exceptions to these requirements.
In recent years, the Office of the Australian Information Commissioner (OAIC) has also warned that web scraping raises “significant privacy concerns” , particularly where personal information is scraped without the knowledge of the data subject and against their expectations.
The OAIC has recently taken action against multiple businesses in relation to data scraping activities:
In some cases, data scraping may also infringe copyright in the scraped material. In October 2025, the Attorney-General confirmed that Australia will not introduce a text and data mining exception under the Copyright Act 1968 (Cth) that would allow AI companies to use Australian copyrighted materials for training purposes without permission of or compensation to the creator, citing its rationale behind this was to provide certainty to creators and to ensure that they are fairly compensated for providing their copyrighted material for AI training. This position was reinforced in a speech by the Prime Minister in July 2026, despite pressure from leading global AI developers, in which he stated that Australia’s laws will make clear that creators must retain ownership and control of their work.
Platform or website terms of use often prohibit data scraping. Whether and how that prohibition can be enforced is a nuanced question that turns on the parties, their contractual relationship (or lack thereof), the nature of the data, and the purpose of the data scraping. If the party doing the scraping has entered into a service agreement prohibiting such activity, enforcement is usually quite straightforward.
Although this question has been tested in the courts of other jurisdictions (including Europe and the United States), there is no definitive appellate authority squarely addressing the enforceability of website anti-scraping clauses. The issue was touched upon in the Clearview AI AAT Determination (see Question 14 above), however the Tribunal noted that it was not in a position to judge whether the interactions between Clearview’s web-crawler and [LinkedIn and Twitter terms of service] amount to breaches of conditions of access.
Generally, Australian courts enforce properly incorporated online contractual terms, particularly click-wrap agreements. Accordingly, the overall view is that an express prohibition on data scraping is likely to be enforceable where the scraper has agreed to the relevant terms, subject to ordinary contractual principles and any competing statutory considerations.
Australia does not (yet) have a unitary AI Regulator. Instead, oversight is distributed through the regulators that pre-existed the emergence of the technology. These regulators form a distributed enforcement model, applying developing statutory powers. The most significant regulators are:
Artificial intelligence adoption in Australia is widespread conceptually but remains uneven in practice, with a clear gap between intent and mature implementation. According to the Australia Responsible AI Index 2025 final report (sponsored by the Australian Government) (Report), approximately 78% of organisations recognise and agree with principles supporting ethical AI use, indicating strong awareness and willingness to engage with AI technologies. However, this high level of endorsement is not matched by practical uptake, as:
In terms of sectors leading the way in implementation and maturity, the Report indicates the top industries are (1) Information Media & Telecoms, (2) Health, Education and Government and (3) Financial & Other Services.
Artificial intelligence is used in the Australian legal sector by lawyers and in‑house counsel to automate routine, process‑driven work and enhance efficiency. A 2025 report by the University of Melbourne identified common uses of GenAI legal tools to include drafting document summaries and chronologies, contract analysis, due diligence, and generating insights, recommendations and predictions. Law firms are adopting a mix of legal generative AI chatbots and tools, including inhouse built chatbots (for example, Microsoft Azure AI bots) and bespoke legal technology (for example, Harvey, Legora and Claude for Legal).
LexisNexis’s 2025-26 Australian Legal AI Survey Report has identified wide adoption of AI-driven legal tools, with 69% of respondents using or planning to use generative AI for legal work, 90% feeling confident using AI and 45% using AI for legal research.
Key concerns include client confidentiality and data security, with practitioners warned not to input sensitive information into unsecured AI systems, as well as accuracy risks (including hallucinated outputs), bias, and misleading results. The Law Society of New South Wales emphasises that lawyers retain full responsibility for their advice, and must not rely on AI outputs without independent verification.
The key challenges raised by AI for lawyers in Australia include:
The key opportunities raised by AI for lawyers in Australia include:
Over the next 12 months, the most significant developments are likely to occur through the expansion of existing regulatory frameworks to AI, rather than through the enactment of a standalone Australian AI Act. A key exception is the development of a mandatory Australian AI Standard by the newly established Office of AI (see Questions 3 and 16), which is expected to introduce binding requirements covering AI governance, data centre infrastructure, and copyright protections for creators – representing the most significant structural change to Australia’s AI regulatory landscape in the near term.
Key privacy reform and AI-related data governance changes are a particular area to watch. Further privacy reforms could materially affect AI development and deployment. For example:
Australia has also established the Australian AI Safety Institute, which is intended to function as a technical and policy body whose role includes evaluating advanced AI systems, conducting safety assessments, supporting AI assurance and testing methodologies, and contributing to domestic and international AI safety initiatives. The Australian AI Safety Institute should play an important part in managing the AI sector (despite not being an enforcement regulator). However, whether its role will expand, contract or remain stable, and the practical influence it will have on AI in Australia, could determine the overall changes to the AI governance landscape in the near future.
Given Australia’s land availability, technology vendors and property developers consider Australia as an important location for the construction of large-scale data centres and AI compute infrastructure. The rapid growth of these facilities is likely to become an increasingly important aspect of AI governance, as access to computing power is emerging as a strategic prerequisite for the development, training and deployment of advanced AI systems.
This raises a range of legal and policy issues extending beyond the regulation of AI models themselves, including cyber security, critical infrastructure protection, foreign investment scrutiny, data localisation, sovereign capability, energy consumption and access to trusted computing environments for government and industry. In this regard, the Australian Government’s National AI Plan places emphasis on strengthening Australia’s domestic AI capability and supporting the infrastructure necessary to enable AI adoption and innovation. As investment in Australian data centre capacity accelerates, AI governance is likely to expand beyond questions of algorithmic accountability and data use to encompass the physical infrastructure on which AI systems are trained, hosted and operated, and the extent to which Australia can maintain sovereign control over strategically important AI capabilities.
Maddocks has developed deep expertise in AI technologies, enabling us to deliver practical, tailored legal advice that helps clients navigate the evolving regulatory and governance landscape of AI.
Sonia has wide ranging experience advising on technology, cyber, telecommunication and general commercial matters, specialising in cyber and data resilience advice.
View profileOoma advises public and private sector clients in information technology, consumer markets and telecommunications sectors, particularly in relation to regulatory compliance and technology.
View profileGreg has broad expertise advising on technology, media, intellectual property, hospitality, travel, privacy, sports law and general commercial matters.
View profileNick advises government agencies on complex ICT procurements and disputes. He has drafted bespoke contracts and contracts based on SourceIT, ProcureIT and ASDEFCON templates.
View profileAvi is an experienced commercial lawyer specialising in complex procurement and contracting, with a particular focus on technology and telecommunications projects.
View profileShivani has extensive experience advising on a broad range of commercial matters with a focus on technology procurement, telecommunications, consumer laws, privacy and intellectual property protection.
View profileKeep up to date with our legal insights and events
Sign up
The key risks, common reseller models, and what customers can do to protect themselves.
This country-specific Q&A provides an overview of Capital Markets laws and regulations applicable in Australia.
The Federal Court’s Coles decision offers key lessons for businesses using ‘Was/Now’ pricing.
Providing important guidance on the operation of the good faith defence in section 588FG(2) of the Corporations Act 2001
Partner
Sydney