For a technology that is reshaping how Australians work, bank, study and consume news, the question of who sets the rules remains stubbornly unresolved. More than two years after generative AI arrived in the mainstream, the country still has no dedicated law governing artificial intelligence, and no firm date for when one might appear. That gap, and the government’s careful footwork around it, is the subject of a pointed assessment published this week by techAU, which argues that Canberra’s attempts to regulate AI have so far produced more consultation than clarity.
How we got here
The federal government began its formal engagement with AI risk in earnest during 2024, when it canvassed the idea of mandatory guardrails for AI used in high-risk settings such as hiring, policing, health and essential services. The pitch was straightforward enough: low-risk uses of AI would be left largely alone, while systems capable of doing real harm to people would face testing, transparency and accountability obligations before and after they were deployed. Alongside that, the government released a voluntary AI safety standard, a set of practices that businesses could adopt now while the harder questions of legislation were worked through.
What has not followed is a bill. The voluntary standard remains voluntary, the guardrails remain a proposal, and the machinery of government has moved on to other priorities. Part of that reflects a change of personnel. After last year’s federal election, the industry and innovation portfolio passed to Tim Ayres, with Ed Husic, who had championed the earlier work, dropped from the ministry. New ministers tend to want their own settings, and the reset has cost momentum.
The news: caution over commitment
The through-line of the techAU piece, written by founder Jason Cartwright, is that the government appears to have quietly cooled on the idea of a standalone AI Act modelled on Europe’s. Instead, the favoured approach now looks like adapting the laws Australia already has, privacy, consumer protection, anti-discrimination, corporations and online safety rules, to cover AI-specific harms as they emerge. Advocates of that approach argue it is faster and less likely to freeze a fast-moving field in place. Critics counter that stitching AI into a patchwork of ageing statutes leaves obvious gaps, and that a business trying to do the right thing has no single, coherent rulebook to follow.
The practical effect, as the article frames it, is uncertainty. Companies do not know whether a dedicated law is coming, so they cannot plan for it. Consumers do not know what protections they are owed when an algorithm knocks back their loan application or an AI voice clone is used to defraud a relative. And regulators are left interpreting decades-old legislation for problems its drafters never imagined.
Two sides of the argument
Business groups have generally welcomed the slower pace, and their reasoning is not hard to follow. Australia is a small market that competes for capital and talent against the United States, which is stripping back AI oversight, and against a European Union whose AI Act has drawn complaints about compliance costs from the very tech firms it is meant to bind. Industry voices, echoed by the Productivity Commission‘s work on data and digital technology, have warned that heavy, AI-specific rules risk deterring investment and locking out smaller local players who cannot afford large compliance teams. On this view, the government’s caution is a feature, not a bug.
Rights advocates, unions and a good many technologists see it very differently. They point to the harms already landing on Australians: sexually explicit deepfakes made of teachers and students, AI-generated child abuse material working its way through the courts, automated systems making consequential decisions with no obligation to explain them, and facial recognition trials sweeping up the biometric data of tens of thousands of people. For this camp, every month without enforceable guardrails is a month in which the technology outruns the protections meant to contain it. They argue that voluntary standards, however well-intentioned, are ignored by exactly the actors most likely to cause harm.
What it means for Australia
The stakes here are not abstract. The country is in the middle of a data centre building boom, from Western Sydney out to regional New South Wales, and the government has been talking up sovereign AI capability as a matter of national resilience. Yet the same government has struggled to answer basic questions about how AI should be procured and used inside its own agencies, a tension laid bare in recent debates over sovereign large language models and public sector contracts. Regulation is the connective tissue between those ambitions and public trust. Without it, Australians are being asked to accept AI in their banks, hospitals, schools and government services largely on faith.
There is also a distinctly local economic angle. Small and medium businesses, which make up the bulk of the Australian economy, are being urged to adopt AI to lift flagging productivity. Many are willing, but they are also risk-averse, and ambiguity about the rules is its own kind of brake. A clear, proportionate framework would give a cafe chain or a regional accountant confidence to deploy AI tools without fearing they have unknowingly broken a law that has not been written yet. The absence of one tends to reward the largest and best-resourced firms, precisely the opposite of what a productivity agenda is supposed to achieve.
What’s next
The immediate signal to watch is whether the government commits to a legislative pathway or continues to lean on the existing-laws approach dressed up with sector-specific tweaks. Movement on privacy reform, which has been promised in stages, will be an early tell, because a modernised Privacy Act is the most plausible vehicle for the automated-decision transparency that rights groups want. Watch too for how Australia positions itself internationally, whether it drifts toward the American deregulatory posture, holds closer to Europe’s rules-first model, or tries to carve out a middle path suited to a mid-sized economy.
For now, the honest summary is the one techAU lands on: Australia is attempting to regulate AI, but attempting is doing a lot of work in that sentence. The consultations have been thorough, the intentions sound, and the output thin. Until that changes, the country’s approach to the defining technology of the decade will remain a work in progress, and everyone from boardrooms to living rooms will keep guessing at the rules.
Sources: techAU.


















































