artificial intelligence law

AI compliance programs: one size does not fit all

by

reviewed by

Malcolm Burrows

Reading Time:

7–10 minutes

Australia does not have any standalone legislation addressing how businesses can safely implement Artificial Intelligence (AI).  Use of AI by Australian businesses is, however, regulated, not by a patchwork combination of Federal and State legislation, industry-specific legislation and standards, professional body rules and guidance issued by government departments and other regulators.  This article discusses the most relevant legislative guardrails that need to be considered when implementing an AI compliance program and why no two (2) compliance programs will be the same.

Federal and State Legislation

There is a myriad of legislation that “could” be relevant for businesses adopting AI.   It would for be possible, for example, that the implementation of AI in a business may breach an individuals human rights under anti-discrimination laws such as the Australian Human Rights Commission Act 1986 (Cth).  This article will consider only the main or significant pieces of legislation likely to be relevant; however it is not an exhaustive list of laws that may apply to a business’s use of AI.

AML/CTF law: A business providing a “designated service” as a reporting entity under section 6 of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth) (AML/CTF Act) is responsible for supervising any AI tool it uses to automate customer identification under sections 32–38 (customer due diligence) or transaction screening under sections 41–43 (suspicious matter reporting), and remains liable for the outcomes of that AI tool’s work.  This extends to the Tranche 2 professions, including accountants, lawyers and trust and company service providers, from 1 July 2026.

Tax law: Businesses handling tax file number (TFN) information are bound by the confidentiality protections in Division 355 of Schedule 1 to the Taxation Administration Act 1953 (Cth), the data security requirements of the Privacy Act 1988 (Cth) and the rules in the Privacy (Tax File Number) Rule 2015 (Cth).[1]  These obligations apply regardless of whether an AI tool is involved, and extend to any AI system that processes or stores TFN or other tax-related personal information and it is the business – not the developer or supplier of the AI tool that is liable for a breach of these obligations.

Consumer law: All businesses are bound by the misleading and deceptive conduct provisions of the Australian consumer law.[2]  Where a business that uses an AI chatbot to communicate with customers, the obligation extends to ensuring information and statements made by the AI are not misleading or deceptive.

Privacy law: Businesses that turn over $3 million or more, or are otherwise captured as a non-exempt small business under section 6D of the Privacy Act 1988 (Cth) (Privacy Act), and AML/CTF reporting entities are all “APP entities” (entities subject to the Australian Privacy Principles (APPs).[3]  Where client data is fed into AI tools, an APP entity must ensure that the AI tool’s handling of that information complies with the relevant Australian Privacy Principles.

Surveillance and recording device law: Using AI software to record and transcribe meetings is becoming more and more commonplace.  Each state and territory regulates the recording of conversations separately.  Businesses using AI tools to record, transcribe or listen to meetings or calls must comply with the regime that applies where the conversation takes place.  In Queensland, the Invasion of Privacy Act 1971 (Qld) prohibits the use of a listening device to overhear, record, monitor or listen to a private conversation unless the person operating the device is a party to the conversation and prohibits a party from communicating or publishing that conversation unless the other parties have consented.[4]  New South Wales regulates the same conduct under the Surveillance Devices Act 2007 (NSW).[5]  Businesses operating across state lines should check the applicable regime in each jurisdiction before using an AI meeting-recording or call-transcription tool.

Industry-specific obligations

AI compliance is necessarily industry-specific and use-specific.  For example, accounting practices are subject to the Tax Agent Services Act 2009 (Cth), the Tax Practitioners Board’s Code of Professional Conduct and the Accounting Professional and Ethical Standards Board which impose codes of conduct and ethical standards.[6]  Law firms are subject to obligations under the Australian Solicitors Conduct Rules and receive guidance from the Queensland Law Society as to how AI should be used in legal practice.[7]  Financial services have specific obligations arising under the Corporations Act 2001 (Cth) and the Australian Securities and Investments Commission Act 2001 (Cth).  Merchants including e-commerce businesses carry obligations specific to their activities under Australian consumer law while healthcare providers face more stringent obligations under the APPs due to handling “sensitive information”.[8]  The industries and obligations referred to above are illustrative only and are not an exhaustive survey of industry-specific AI obligations.

Government guidance

The Australian Government has taken steps to address the governance of AI by establishing specialist bodies to provide guidance.  The Digital Transformation Agency (DTA) – an executive agency within the Department of Finance portfolio and the AI Safety Institute (AISI) – a body sitting within the Department of Industry, Science and Resources, have each published guidance and standards that businesses can use to benchmark their AI governance practices, including:

Additionally, Standards Australia has adopted AS ISO/IEC 42001:2023 (AI management systems) and AS/NZS ISO/IEC 27001:2023 (information security management), and ISO/IEC 23894:2023 (AI risk management) is available through its store.[10]

ATO compliance: Businesses using software interfaces connected to the (ATO) online platform to transmit tax, payroll, or superannuation data, including integrated AI tools, must adhere to the security baselines set out in the ATO’s Digital Service Provider Operational Security Framework.[11]  Non-compliance or an unmanaged vulnerability introduced by an AI tool risks having that access suspended or revoked.

One size does not fit all

Notwithstanding the guidance available, AI compliance obligations vary from business to business.  Risk exposure is a question of circumstance, variables including the nature, scale and complexity of the business, how AI tools are implemented across operations, what data is being handled, which AI tools are in use, will inform the appropriate approach to compliance.  

For example, a recruiter using AI to screen job candidates engages anti-discrimination law and privacy obligations around the collection and use of personal information, given the direct impact on an individual’s rights.  By contrast, a construction company using an AI document comparison tool to compare successive versions of tender documents, is unlikely to be handling personal information at all, but faces higher risks around the accuracy and contestability of automated decision-making output, and potential liability for misleading conduct under the Australian Consumer law if tender outcomes are communicated inaccurately.

Key takeaways

The examples above illustrate the range of regulatory triggers, standards and practical controls that differ by industry.  These variations leave little room for a one-size-fits-all approach to AI compliance.

The legal, regulatory and operational risks associated with AI depend on how the technology is used and the obligations that apply to each business.

Dundas Lawyers can assist in designing and implementing a bespoke AI compliance programme that aligns with your business operations, regulatory obligations and unique risk profile.

This may include developing AI governance frameworks, policies, controls, monitoring processes and staff guidance to help ensure AI is used safely, responsibly and in compliance with applicable legal and professional standards.

Links and further references

Legislation

Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth)

Australian Human Rights Commission Act 1986 (Cth)

Australian Securities and Investments Commission Act 2001 (Cth)

Australian Solicitors Conduct Rules 2012 (Qld)

Competition and Consumer Act 2010 (Cth)

Corporations Act 2001 (Cth)

Invasion of Privacy Act 1971 (Qld)

Privacy Act 1988 (Cth)

Surveillance Devices Act 2007 (NSW)

Tax Agent Services Act 2009 (Cth)

Other referenced material

Accounting Professional and Ethical Standards Board, APES 110 Code of Ethics for Professional Accountants (including Independence Standards) (at May 2025)

Australian Taxation Office (Cth), Digital Service Provider Operational Security Framework (2 June 2022)

Department of Industry, Innovation and Science (Cth), Australia’s AI Ethics Principles (7 November 2019)

Department of Industry, Science and Resources (Cth), Voluntary AI Safety Standard (September 2024)

Digital Transformation Agency (Cth), Technical Standard for Government’s Use of Artificial Intelligence (August 2025)

International Organization for Standardization and International Electrotechnical Commission, Information Technology — Artificial Intelligence — Guidance on Risk Management ISO/IEC 23894:2023

Queensland Law Society, Guidance Statement No 37: Artificial Intelligence in Legal Practice (30 May 2024), Guidance Statement No 37.

Standards Australia, Artificial Intelligence — Management System AS ISO/IEC 42001:2023

Standards Australia and Standards New Zealand, Information Technology — Security Techniques — Information Security Management Systems — Requirements AS/NZS ISO/IEC 27001:2023

Tax Practitioners Board (Cth), Code of Professional Conduct (Explanatory Paper TPB(EP) 01/2010, 30 April 2026)

Further information

If you need advice on AI governance and compliance contact us for a confidential and obligation‑free discussion.

Doyles Recommended TMT Lawyer 2024

[1] Privacy (Tax File Number) Rule 2015 (Cth)

[2] Competition and Consumer Act 2010 (Cth), Schedule 2, sections 18 and 29.

[3] Privacy Act 1988 (Cth), sections 6 and 6E(1A).

[4] Invasion of Privacy Act 1971 (Qld) sections 43 and 45.

[5] Surveillance Devices Act 2007 (NSW) sections 7 and 11.

[6] Tax Practitioners Board (Cth), Code of Professional Conduct (Explanatory Paper TPB(EP) 01/2010, 30 April 2026),

Accounting Professional and Ethical Standards Board, APES 110 Code of Ethics for Professional Accountants (including Independence Standards) (at May 2025).

[7] Legal Profession Uniform Law Australian Solicitors’ Conduct Rules 2015 (at 22 April 2022), Queensland Law Society, Guidance Statement No 37: Artificial Intelligence in Legal Practice (30 May 2024).

[8] Privacy Act 1988 (Cth), section 6.

[9] Department of Industry, Innovation and Science (Cth), Australia’s AI Ethics Principles (7 November 2019), Department of Industry, Science and Resources (Cth), Voluntary AI Safety Standard (September 2024), Digital Transformation Agency (Cth), Technical Standard for Government’s Use of Artificial Intelligence (August 2025).

[10]Standards Australia, Artificial Intelligence — Management System (AS ISO/IEC 42001:2023, 2023),Standards Australia and Standards New Zealand, Information Technology – Security Techniques – Information Security Management Systems – Requirements (AS/NZS ISO/IEC 27001:2023, 2023), International Organization for Standardization and International  Electrotechnical Commission, Information Technology — Artificial Intelligence — Guidance on Risk Management (ISO/IEC 23894:2023, 2023).

[11]Australian Taxation Office, Digital Service Provider Operational Security Framework (2 June 2022).


Related insights about Artificial Intelligence law

  • AI compliance programs: one size does not fit all

    AI compliance programs: one size does not fit all

    Australia does not have any standalone legislation addressing how businesses can safely implement Artificial Intelligence (AI).  Use of AI by Australian businesses is, however, regulated, not by a patchwork combination of Federal and State legislation, industry-specific legislation and standards, professional body rules and guidance issued by government departments and other regulators.  This article discusses the…

    Read more …

  • AI evidence misleading Court:  Ba v Sterling Parts Australia

    AI evidence misleading Court: Ba v Sterling Parts Australia

    On 17 June 2026, Symons J delivered judgment in the case of Ba v Sterling Parts Australia Pty Ltd [2026] FedCFamC2G 1245 (Ba v Sterling Parts).  Ba v Sterling Parts was a proceeding brought by Weiman Ba (Applicant) in the second division of the Federal Circuit and Family Court of Australia (Court).  Symons J dismissed…

    Read more …

  • Office of AI announced by Federal Government

    Office of AI announced by Federal Government

    On 15 July 2026, Prime Minister Anthony Albanese (Prime Minister) announced by media release an expansion of the Federal Government’s (Government) existing artificial intelligence (AI) governance framework, including the establishment of a new Office of AI as well as plans to legislate national standards governing large-scale data centres, AI training and the use of Australian…

    Read more …

  • Federal Court publishes GenAI Practice Note

    Federal Court publishes GenAI Practice Note

    On 16 April 2026, the Federal Court of Australia (Court) published the Use of Generative Artificial Intelligence Practice Note (GPN-AI) (Cth) (GenAI Practice Note). 

    Read more …

  • AI businesses should have duty of care

    AI businesses should have duty of care

    In a recent interview with InnovationAus.com, Victorian Senator Michelle Ananda-Rajah (Senator) emphasised the need to adopt digital duty of care laws for artificial intelligence (AI) companies.[1]  As a representative of the ALP and former AI start-up founder, the Senator calls for the proposed digital duty of care to apply to AI companies.  If implemented, the…

    Read more …

  • Federal Court orders winding up of crypto mining investment scheme

    Federal Court orders winding up of crypto mining investment scheme

    The Federal Court of Australia delivered judgment in Australian Securities and Investments Commission v NGS Crypto Pty Ltd (No 5) [2025] FCA 1611, on 18 December 2025 ordering the winding up of two (2) cryptocurrency related entities after finding that they operated an unlicensed financial services business and an unregistered managed investment scheme in contravention…

    Read more …

  • Online Safety – is your online business a DIS or a RES?

    Online Safety – is your online business a DIS or a RES?

    Whether your online business has to comply with the obligations contained in the Online Safety Act 2021 (Cth) (OSA), and related standards and industry codes will largely depend on how your business is classified because of the functionality it provides to end users in Australia.

    Read more …

  • Bill to allow victims of AI deepfakes to sue for emotional damages

    Bill to allow victims of AI deepfakes to sue for emotional damages

    On 24 November 2025, Senator David Pocock introduced a private Senator’s bill, the Online Safety and Other Legislation Amendment (My Face, My Rights) Bill 2025 (Cth) (Bill) to amend the Online Safety Act 2021 (Cth) (Online Safety Act) and the Privacy Act 1988 (Cth) (Privacy Act). 

    Read more …

  • Malcolm Burrows on ABC’s “Legal Eagles” segment – Deepfakes

    Malcolm Burrows on ABC’s “Legal Eagles” segment – Deepfakes

    On 3 December 2025, Malcolm Burrows appeared live on Katherine Feeney’s ABC Radio program, “Legal Eagles” as the Technology and Intellectual Property Lawyer to discuss the proposed amendments to the Online Safety Act 2021 (Cth) through the introduction of the Online Safety and other legislation Amendment (My Face Rights) Bill (Cth) 2025 (My Face Rights…

    Read more …

Recent Federal Court decisions regarding AI compliance programs: one size does not fit all

  • Yarrawah Interactive PL v Epiphany Games PL(Costs)[2026] FCA 700

    COSTS – proceedings dismissed – indemnity costs sought by successful respondents – offer to compromise made under rule 25.01(1) Federal Court Rules 2011 (Cth) – when offer made, no defence had been filed – not unreasonable to fail to accept offer having regard to amount of offer and quantum of claim – indemnity costs refused

  • Chan v Moore [2026] FCA 496

    CORPORATIONS – rejection by liquidator of proof of debt – where proof of debt based on contested balance in director loan account – where director claims advances made to company by a related company in Hong Kong were capital contributions made by her, or on her behalf, and should be treated as credits to her…

  • Australian Competition and Consumer Commission v Qteq Pty Ltd (Penalty) [2026] FCA 356

    COMPETITION – imposition of pecuniary penalties and related orders under s 76(1) of the Competition and Consumer Act 2010 – where respondents found to have induced or intended to induce contraventions of the cartel prohibitions – where business and assets of contravenor were divested after the liability judgment and penalty hearing – relevant penalty considerations…

 

Send this to a friend