For the better part of two years, the working assumption in Australian boardrooms was that a dedicated set of artificial intelligence rules was on its way. Companies deploying AI in hiring, lending, insurance and healthcare were told to expect mandatory guardrails for high-risk uses, complete with testing, transparency and human oversight obligations. A new legal update from global law firm White & Case argues that assumption no longer holds, and that Canberra has quietly changed course.
The firm’s Australian AI update reads the recent signals from government as a decisive move away from AI-specific legislation and towards a model that leans on the laws already on the books. Rather than building a standalone regime in the style of the European Union’s AI Act, the picture the firm paints is one of Australia stretching existing consumer, privacy, corporations and anti-discrimination law to cover the risks that AI creates, and filling gaps only where a clear case can be made.
How we got here
The starting point was the previous government position under then Industry and Science Minister Ed Husic, whose department floated a proposals paper on mandatory guardrails for AI in high-risk settings. That work canvassed a possible Australian AI Act, or at least a set of binding obligations aimed at the most consequential uses of the technology. Industry welcomed the clarity of intent while warning about the compliance cost, and civil society groups argued the guardrails did not go far enough.
The mood in Canberra has since cooled on prescriptive rules. After a ministerial reshuffle handed the industry and innovation portfolio to Tim Ayres, the emphasis shifted towards productivity and adoption. The Productivity Commission‘s work on harnessing digital technology added weight to the pivot, cautioning against rushing to regulate a fast-moving field before the harms and the benefits are properly understood, and urging governments to use the tools they already have before reaching for new ones. That framing, which treats AI as an economic opportunity to be captured rather than primarily a hazard to be contained, now sits at the centre of federal thinking.
What the change actually looks like
White & Case’s central point is that the change is less a formal announcement than a change of posture, and that this matters for how businesses should plan. Instead of waiting for a single AI statute to tell them what compliant looks like, organisations are being pushed to map their AI use against a patchwork of existing obligations. The Privacy Act reforms already underway capture automated decision-making. Australian Consumer Law bites on misleading AI outputs and unsafe products. Directors’ duties, work health and safety rules, and sector regulators covering finance, health and communications all reach into AI without ever mentioning it by name.
The firm’s reading is that voluntary standards will carry much of the load in the near term, backed by the AI safety guidance and voluntary safety standard that the government has already published. For legal teams, the takeaway is that the absence of a bespoke AI law is not the same as an absence of risk. If anything, a principles-based, technology-neutral approach places more of the interpretive burden on companies and their advisers, because there is no tidy checklist to work through.
Two ways to read the shift
Business groups have generally welcomed a lighter touch. The argument, long made by technology industry bodies and larger employers, is that heavy AI-specific rules risk freezing investment and pushing development offshore at exactly the moment Australia is trying to lift flat productivity. On this view, leaning on existing law avoids duplicating regulation, gives firms room to experiment, and keeps Australia aligned with pragmatic jurisdictions rather than the more prescriptive European model.
The counter-view, pressed by digital rights advocates, unions and some academics, is that technology-neutral law leaves real gaps. Existing statutes were not written with opaque models, training data or automated decisions in mind, and enforcement bodies are already stretched. Critics worry that without clear guardrails, the burden of proving harm falls on the people least able to carry it, whether that is a worker screened out by an algorithm or a consumer denied credit by a system nobody can fully explain. For them, a change of course looks less like pragmatism and more like a retreat.
What it means for Australia
For Australian organisations, the practical consequences are immediate. A bank rolling out an AI lending tool, a hospital trialling diagnostic software, or a retailer using generative models in customer service cannot point to a single AI rulebook and tick the boxes. They have to assemble compliance from privacy, consumer, discrimination and corporations law, and increasingly from their own governance frameworks. That favours large firms with deep legal benches and leaves smaller operators guessing, which is a familiar pattern in Australian regulation and one worth watching as adoption spreads.
There is also a sovereignty dimension. Australian companies that sell into Europe will still have to meet the EU’s binding obligations regardless of what Canberra does, so the local approach does not remove the compliance load for exporters, it simply moves the goalposts depending on the market. A lighter domestic regime may attract investment and talent, but it also means Australia is, to a degree, importing its de facto AI standards from larger jurisdictions rather than setting its own.
What is next
The direction is set, but the detail is not. Expect the government to keep refining voluntary standards, to press ahead with privacy reform that touches automated decisions, and to lean on existing regulators to clarify how their remits apply to AI. The open question is whether that proves enough, or whether a high-profile failure, an algorithmic discrimination case or a consumer harm that existing law struggles to reach, forces a return to the guardrails conversation. Law firms including White & Case are advising clients to treat the current calm as a window to get their AI governance in order, not as a reason to relax.
For a country that has spent two years bracing for prescriptive AI rules, the message is that the rules were always going to be there, just scattered across the statute book rather than gathered into one law. Whether that is nimble or negligent will depend on how well the existing framework holds when the first serious test arrives.
Sources: White & Case LLP, via GNews.


















































