Public sector AI

AI in government in Australia: the responsible AI rules every agency leader needs to know

Clutch Events Editorial
Editorial team, Clutch Events
October 5, 2026
AI in government in Australia: the responsible AI rules every agency leader needs to know

Quick answer: AI in government in Australia is governed by existing law plus a layer of policy rather than a standalone AI Act. For Commonwealth agencies the core instrument is the DTA's Policy for the responsible use of AI in government (version 2.0, effective 15 December 2025), which requires an accountable executive, a public AI transparency statement, an AI impact assessment for in-scope use cases with high-risk cases reported to the DTA, and procurement that makes suppliers disclose and account for AI. NSW agencies must complete the NSW AI Assessment Framework; the National framework for the assurance of AI in government aligns all jurisdictions.

The pace changed in the last quarter of 2025. In six weeks the Commonwealth released the APS AI Plan (12 November), the National AI Plan (2 December) and version 2.0 of the Policy for the responsible use of AI in government (15 December), alongside a new AI impact assessment tool and procurement guidance. Every agency now has, or is appointing, a Chief AI Officer, GovAI Chat is rolling out to public servants, and the Robodebt Royal Commission's legacy means automated decision-making is under more scrutiny than any other category of technology.

This guide is for the people accountable for making AI in government work safely: agency CIOs, CDOs and Chief AI Officers, heads of digital and transformation, governance and assurance leads, and the procurement and legal teams who sit alongside them, across Commonwealth, state and territory agencies and in New Zealand. It maps the instruments, what each one requires, and an operating model that satisfies them without stalling delivery.

The Australian AI governance landscape for the public sector

  • Australia's AI Ethics Principles (8 principles) — Owner: Dept of Industry, Science and Resources · Applies to: All sectors, voluntary; referenced by every government framework · Status: 2019, still the reference set
  • National framework for the assurance of AI in government — Owner: Data and Digital Ministers (all jurisdictions) · Applies to: Commonwealth, states and territories · Status: June 2024
  • Policy for the responsible use of AI in government — Owner: Digital Transformation Agency · Applies to: Non-corporate Commonwealth entities (mandatory); corporate entities encouraged · Status: v1.1 Sept 2024; v2.0 effective 15 Dec 2025
  • Australian Government AI impact assessment tool and guidance — Owner: DTA · Applies to: Commonwealth agencies · Status: Dec 2025
  • Guidance on AI procurement in government (with checklist aligned to the Digital Sourcing Lifecycle) and AI model clauses — Owner: DTA · Applies to: Commonwealth buyers · Status: Dec 2025 (clauses from 2024)
  • Australian Government AI technical standard — Owner: DTA · Applies to: Teams designing, building and deploying AI · Status: 2025
  • APS AI Plan — Owner: Dept of Finance, DTA, APSC · Applies to: Australian Public Service · Status: 12 Nov 2025
  • National AI Plan — Owner: Commonwealth · Applies to: Whole economy; includes public sector adoption measures · Status: 2 Dec 2025
  • Voluntary AI Safety Standard (10 guardrails) — Owner: Dept of Industry / National AI Centre · Applies to: All organisations, voluntary · Status: Sept 2024
  • NSW AI Assessment Framework and AI Ethics Policy — Owner: NSW Dept of Customer Service · Applies to: NSW Government agencies (mandatory) · Status: Updated 1 July 2024 (DCS-2024-04)
  • Public Service AI Framework and Responsible AI Guidance (GenAI) — Owner: NZ Government Chief Digital Officer · Applies to: NZ public service · Status: Jan and Feb 2025

Beneath all of this sits general law that already binds agencies: the Privacy Act (with automated decision-making transparency obligations commencing December 2026), administrative law and the lessons of Robodebt, anti-discrimination law, the Protective Security Policy Framework and Information Security Manual, and records legislation.

What does the Policy for the responsible use of AI in government require?

Version 1.1 (effective 1 September 2024) established the baseline: each agency designated an accountable official, published an AI transparency statement by February 2025, and committed to staff training. Version 2.0, effective 15 December 2025, turned the policy from disclosure into assurance. Its main requirements are:

  • Accountability. A senior executive accountable for the agency's AI, now converging with the APS AI Plan's commitment to a Chief AI Officer in every agency.
  • Transparency. A public AI transparency statement, kept current, describing how the agency uses AI, its governance and how the public can find out more.
  • AI impact assessment. Agencies must assess in-scope AI use cases using the Australian Government AI impact assessment tool or an equivalent internal process, before deployment, and must report high-risk use cases to the DTA and review them at least every 12 months. The assessment is built around the AI Ethics Principles and produces a risk rating that drives the controls required.
  • Use case governance. A formal approval process for each in-scope use case, an internal register, and reporting of AI incidents.
  • Procurement. Alignment with the DTA's AI procurement guidance so that suppliers disclose where AI is used in delivering government services and accept accountability for it.
  • Staged commencement. The DTA set staged dates through 2026 for the new mandatory elements, with the before-deployment impact assessment requirement applying to new in-scope systems from December 2026. Check the DTA's implementation timetable for your agency's obligations.

What counts as "in-scope" matters. The policy is aimed at AI that affects people, decisions or services, not every spell-checker. The impact assessment tool is where that line is drawn, and most agencies are finding that a meaningful share of their generative AI pilots, contact-centre assistants and triage tools land in the elevated tiers.

AI impact assessments and the national assurance framework

The National framework for the assurance of AI in government, agreed by Data and Digital Ministers in June 2024, is what keeps Commonwealth, state and territory approaches compatible. It commits every jurisdiction to the AI Ethics Principles and to five cornerstones of assurance: governance, data governance, a risk-based approach, procurement, and standards. In practice it means an agency in Canberra, Sydney or Brisbane should be running broadly the same risk-tiered process even if the forms differ.

A good AI impact assessment, whichever jurisdiction's template you use, answers the same questions:

  1. What decision, service or person does the system affect, and how reversible is the effect?
  2. What data does it use, where did it come from, and is the use consistent with the Privacy Act and the collection notice?
  3. How will fairness be tested across the populations the agency serves, including First Nations communities and people with disability?
  4. Who is the human in the loop, and can they actually override the system?
  5. How will the system be explained to the affected person, and how do they contest an outcome?
  6. What is the supplier dependency, and what happens if the model changes or is withdrawn?
  7. How is performance monitored after go-live, and when is the assessment repeated?

Treat the assessment as a living artefact tied to the use case register, not a gate passed once.

What is the NSW AI Assessment Framework?

The NSW AI Assessment Framework (AIAF) is the most mature state-level instrument. Updated on 1 July 2024 under Department of Customer Service Circular DCS-2024-04 to cover generative AI, it is mandatory for all NSW Government agencies across the full AI lifecycle, whether or not the AI is part of a formal project. Agencies complete a structured self-assessment against five principles (community benefit, fairness, privacy and security, transparency and accountability), rate residual risk, and must refer high and very high residual-risk systems to the NSW AI Review Committee. It is wired into the NSW Digital Assurance Framework, so AI risk is reviewed alongside the rest of a programme's assurance.

Other jurisdictions have their own instruments at different levels of maturity. Queensland, Victoria, Western Australia, South Australia and the ACT have published AI policies, principles or risk-assessment tools for their agencies; check your jurisdiction's digital or customer service agency, and expect them to converge on the national framework's five cornerstones.

New Zealand: the Public Service AI Framework

New Zealand took a guidance-first route. The Public Service AI Framework (January 2025) sets a vision and five principles drawn from the OECD AI Principles and a six-pillar work programme; the Responsible AI Guidance for the Public Service: GenAI (February 2025) covers governance and assurance, security, procurement, capability, misinformation and hallucination, accountability, fairness, accessibility and Te Tiriti and Māori data perspectives. Both sit beside the Algorithm Charter for Aotearoa New Zealand (2020) and the Privacy Act 2020, and within the national AI strategy launched in July 2025. The obligations are less prescriptive than Australia's, but the documentation and transparency expectations are similar in substance.

How should government agencies procure AI?

Procurement is where most AI risk enters an agency, because most government AI is bought or embedded in SaaS rather than built. The DTA's December 2025 Guidance on AI procurement in government and its checklist aligned to the Digital Sourcing Lifecycle, together with the AI model clauses, set the expectations. In practice:

  • Ask whether AI is present at all. Many suppliers embed AI features into existing products between contract renewals. Require disclosure of AI use in delivering the service, now and at each change.
  • Make the impact assessment a procurement input. Run the assessment before approach to market so the risk tier shapes requirements and evaluation, not just the contract.
  • Contract for transparency and control. Model clauses covering data use and training restrictions, data residency, notification of model changes, performance and bias testing evidence, audit and access rights, incident notification, exit and transition.
  • Address dependency. Lock-in to a single model provider is a service-continuity risk; require portability of data, prompts and evaluation sets, and plan the fallback.
  • Apply the security baseline. PSPF and ISM classification, IRAP assessment for hosted services where data classification demands it, and the Essential Eight for the surrounding environment.
  • Build internal capability alongside. The APS AI Plan's "People" pillar and GovAI exist because agencies that cannot evaluate what they buy cannot govern it.

An operating model that satisfies all of it

  1. One register, one assessment pipeline. Every AI use case, including embedded vendor features and internal GenAI, recorded once with owner, tier, data classification, assessment status and reassessment date.
  2. Tier by consequence. Three or four tiers from internal productivity to decisions affecting rights and entitlements, with controls that scale with the tier. The same logic Australia's regulated industries use; see our guide to governing AI under APRA CPS 230 for the parallel.
  3. A Chief AI Officer with a board, not a committee of everyone. Delegated approval for low tiers, board review for elevated tiers, incident reporting to both.
  4. Human oversight that is tested. For every elevated-tier system, name who can override or switch it off and rehearse it.
  5. Transparency by design. Update the transparency statement, the privacy collection notices and the customer-facing explanation at the same time as the system.
  6. Evidence by default. Assessment, approval, testing, monitoring and incident records organised so that an ANAO audit, a parliamentary question or a DTA reporting cycle can be answered in days.
  7. Engineering discipline. Agencies building or configuring AI need the same version control, evaluation harnesses and release practices as any software; the DTA's AI technical standard and our guide to AI coding assistants in engineering teams are useful starting points.

Common mistakes

  • Treating the transparency statement as the whole policy.
  • Assessing only "projects" and missing the AI inside existing vendor platforms.
  • Letting the impact assessment become a one-off compliance form with no reassessment date.
  • No contractual right to be told when a supplier changes the model.
  • Automated decision-making deployed without a tested human override and a contestability path, the exact failure Robodebt made unforgivable.
  • Running GenAI pilots on personal accounts outside the register.

Key takeaways

  • Australia governs AI in government through existing law plus policy: the DTA policy v2.0 for the Commonwealth, the NSW AIAF for NSW, and the national assurance framework tying jurisdictions together.
  • Version 2.0 shifted the Commonwealth from disclosure to assurance: impact assessments, high-risk reporting to the DTA, use case approval and incident reporting.
  • Procurement is the main risk entry point; use the DTA guidance and model clauses to force supplier disclosure, model-change notification and exit rights.
  • Run one register and one tiered assessment pipeline under a Chief AI Officer, with tested human override for anything touching rights or entitlements.
  • New Zealand's Public Service AI Framework is guidance-led but expects the same documentation and transparency in substance.

Join your peers at the Clutch AI in Government Summits 2027

Clutch Events runs free-to-attend, invite-curated, practitioner-led AI in Government summits for senior technology, data and AI leaders across federal, state and local government in Australia and New Zealand:

See all upcoming Clutch events · More guides on Clutch Events Insights

Frequently asked questions

What is the Policy for the responsible use of AI in government?

It is the Digital Transformation Agency's mandatory policy for non-corporate Commonwealth entities on how they adopt and govern AI. Version 2.0, effective 15 December 2025, requires an accountable senior executive, a public AI transparency statement, AI impact assessments for in-scope use cases with high-risk cases reported to the DTA and reviewed at least annually, use case approval and incident reporting, and procurement aligned to the DTA's AI procurement guidance.

What changed in version 2.0 of the AI in government policy?

Version 1.1 (2024) focused on accountable officials, transparency statements and training. Version 2.0 added mandatory AI impact assessments using the new Australian Government AI impact assessment tool, reporting of high-risk use cases to the DTA with 12-monthly review, formal use case approval and incident reporting, and procurement guidance requiring suppliers to disclose and account for AI, with staged commencement through 2026.

What is an AI transparency statement?

An AI transparency statement is a public document each Commonwealth agency must publish and keep current under the DTA policy. It explains how the agency uses AI, the governance and safeguards in place, how it complies with the policy, and how the public can learn more or raise concerns. Agencies first published them by February 2025 and update them as their AI use changes.

When is an AI impact assessment required?

Under policy v2.0, a Commonwealth agency must complete an impact assessment, using the DTA tool or an equivalent process, for any in-scope AI use case before deployment, with the before-deployment requirement for new systems applying from December 2026 under the DTA's staged timetable. High-risk use cases must be reported to the DTA and reassessed at least every 12 months. NSW agencies must complete the NSW AI Assessment Framework for any system with AI components.

What is the NSW AI Assessment Framework?

The NSW AI Assessment Framework (AIAF) is a mandatory, risk-based self-assessment for all NSW Government agencies using AI, updated on 1 July 2024 under circular DCS-2024-04 to cover generative AI. Agencies assess against five principles (community benefit, fairness, privacy and security, transparency, accountability), rate residual risk, and must refer high and very high risk systems to the NSW AI Review Committee.

How should government agencies procure AI?

Run the impact assessment before approaching the market, require suppliers to disclose AI use in delivering the service and at each change, use the DTA's AI procurement guidance, checklist and model clauses for data use, residency, model-change notification, testing evidence, audit rights, incident notification and exit, apply PSPF and ISM security requirements, and plan for supplier dependency with data and evaluation-set portability.

Does the Commonwealth AI policy apply to state governments?

No. The DTA policy binds non-corporate Commonwealth entities. States and territories run their own instruments, most prominently the mandatory NSW AI Assessment Framework, but all jurisdictions signed the National framework for the assurance of AI in government in June 2024, which commits them to the same AI Ethics Principles and five assurance cornerstones, so approaches are converging.

Related event

Hear this live at the Melbourne AI in Government Summit 2027

Melbourne AI in Government Summit 2027

May 19, 2027
More insights

Keep reading

Events & community
Tech conferences in Australia 2027: the IT leadership events worth attending

The IT conferences in Australia worth a senior leader's time in 2027: CIO, AI, cyber, data, DevOps and government events, with typical dates and costs.

October 5, 2026
Public sector AI
AI in government in Australia: the responsible AI rules every agency leader needs to know

AI in government in Australia: DTA responsible AI policy v2.0, impact assessments, transparency statements, NSW AI Assessment Framework and procurement.

October 5, 2026
Engineering & DevOps
AI coding assistants in enterprise engineering teams: rollout, measurement and governance

AI coding assistants for large engineering organisations: what the evidence says about productivity, and how to roll out, measure and govern them.

October 5, 2026
Engineering & DevOps
DORA metrics and developer productivity: how to measure engineering without gaming it

DORA metrics explained: the five delivery metrics, how to measure them, how SPACE and DevEx complete the picture, and how to avoid gaming them.

October 5, 2026
All insights →
AI in government in Australia: the responsible AI rules every agency leader needs to know
AI in government in Australia: DTA responsible AI policy v2.0, impact assessments, transparency statements, NSW AI Assessment Framework and procurement.
Clutch Events Editorial
Editorial team, Clutch Events
October 5, 2026
ai-in-government-australia-responsible-ai-policy
Public sector AI