Whenever a federal minister is asked how Australia intends to deal with artificial intelligence, the same word keeps surfacing: manage. The government does not talk about banning the technology, and it has cooled on the idea of writing a single sweeping AI law of the sort the European Union has passed. Instead it promises to “manage” the risks while capturing the productivity gains. It sounds reassuring. It is also doing a lot of heavy lifting, because almost everything of consequence hangs on what that verb turns out to mean in practice.
A new analysis published by The Conversation picks apart exactly that question, and it lands at an awkward truth. Australia has spent the better part of three years consulting, discussion-papering and road-mapping its way around AI, and it still has not settled on the shape of the rules. The direction of travel, though, is becoming clearer, and it points away from bold new legislation and towards patching the laws we already have.
How Canberra got here
The story starts with a burst of ambition. After the arrival of generative tools such as ChatGPT, the then industry minister released a proposals paper canvassing mandatory “guardrails” for AI used in high-risk settings, things like hiring, policing, healthcare and access to essential services. The pitch was that developers and deployers of the riskiest systems would face binding obligations around testing, transparency, human oversight and accountability, rather than being left to police themselves through voluntary codes.
That framing implied a dedicated regime, possibly even a standalone Australian AI Act. Since then the tone has shifted. Ed Husic, who drove much of the early work, left the cabinet in last year’s reshuffle, and responsibility now sits with Industry and Innovation Minister Tim Ayres. The government has grown noticeably more cautious about anything that might be branded as a handbrake on investment at a moment when it is desperate for productivity growth. The language of “management” is the diplomatic middle ground between the tech lobby, which wants light touch, and civil society groups, which want enforceable rights.
Two roads: new law or old law stretched
Broadly, there are two ways to manage a technology this pervasive. The first is to build something new, a purpose-designed framework that classifies AI by risk and imposes duties accordingly. That is essentially the European model, and it has the virtue of clarity: everyone knows the rules apply to AI, and to whom.
The second road, and the one Australia looks increasingly likely to take, is to treat AI as just another thing that existing laws already cover. Privacy law governs how systems handle personal data. Consumer law bites when an AI product misleads or causes harm. Anti-discrimination law applies when an algorithm produces biased outcomes. Corporations, copyright, defamation and work health and safety law all reach into the picture. On this view the job is not to invent a new rulebook but to audit the current one, find the gaps and plug them.
The appeal is obvious. It is faster, it avoids a years-long fight over a single mega-bill, and it leans on regulators and courts that already exist. The catch is just as obvious. Laws written before large language models were imaginable often struggle to grapple with systems that are opaque, probabilistic and built on data scraped from the entire internet. When an AI model denies someone a loan or a job, working out who is legally responsible, the developer, the business that deployed it, or the person who clicked accept, is far from settled. Rights that exist on paper are worth little if no one can practically enforce them.
Where the disagreement sits
Industry groups have generally welcomed the softer posture, arguing that Australia is a small market that cannot afford to scare off global AI firms with idiosyncratic rules, and that heavy regulation would entrench the very tech giants it is meant to restrain by making compliance too expensive for local challengers. They point to the risk of duplicating obligations that privacy and consumer law already impose.
Consumer advocates, unions, legal academics and human rights bodies see it differently. Their worry is that “management” becomes a synonym for drift, in which harms accumulate faster than the patchwork can respond. The robodebt catastrophe hangs over this debate as a warning of what happens when automated decision-making meets public power without adequate safeguards. From that vantage point, waiting for the courts to slowly test old laws against new machines is not caution, it is exposure.
What it means for Australians
For ordinary Australians, the choice is not abstract. AI is already screening job applications, triaging health referrals, setting insurance premiums, moderating the content people see and, increasingly, shaping decisions made by government agencies. Whether the country writes crisp new obligations or relies on stretched existing law will determine how easily a person can find out that an algorithm made a call about them, challenge it, and get a human to look again.
There is also a sovereignty dimension that FluentSea readers will recognise from the broader national conversation. Most of the foundation models in question are built offshore, largely in the United States and China. A management approach that never bites means Australia effectively imports someone else’s risk settings while its data centres, energy grid and public sector become ever more dependent on those tools. Getting the domestic rules right is part of how the country keeps some agency over technology it does not build.
Small and medium businesses, which make up the bulk of the economy, sit in a particularly tricky spot. Many are adopting AI quickly to keep up, often without the legal firepower to know whether they are complying with a dozen overlapping laws. A clear, single framework would arguably help them more than a scattered set of obligations they have to reconstruct from privacy, consumer and workplace statutes.
What’s next
The government has flagged further work on automated decision-making in the public sector, reforms to the Privacy Act that touch directly on AI, and continued consultation on where mandatory guardrails might still apply. The unresolved question is whether any of it hardens into enforceable duties with real penalties, or stays at the level of principles and voluntary standards.
Managing AI is not a neutral, technical exercise. It is a decision about who carries the risk when the technology gets it wrong, the companies profiting from it or the citizens on the receiving end. Australia has been slow to answer, and the longer the answer stays vague, the more the answer is being made by default.
Sources: The Conversation.


















































