Australia Sets Rules for AI. The Hard Part Comes Next.

Australian writers, musicians and journalists will keep ownership of their work. Large AI data centres will have to pay for their own power and water. A new Office of AI will coordinate policy across the government. Legislation is expected in early 2027.

That is the headline version of what Prime Minister Anthony Albanese announced on 15 July 2026 at the University of Sydney. The speech, titled AI in Australia’s interests, marked the clearest signal yet that Australia is shifting from voluntary guidance towards mandatory national AI rules.

But the gap between an announcement and an operational regulatory framework is wide. Most of the detailed obligations have not been designed, let alone legislated. The critical questions about enforcement, coverage, penalties and consumer protection remain unanswered. This article separates what has actually changed from what is still to come.

Australia has drawn a line around AI

The centrepiece of the announcement is the proposed Australian Standards for AI. The government describes this as the first national framework in the world to bring the economic, social, national security and environmental dimensions of AI into a single regulatory structure.

This is a notable shift in direction. The National AI Plan, released in December 2025, had confirmed that Australia would rely on existing laws and voluntary guidance rather than introduce a standalone AI Act. The Productivity Commission’s interim report in August 2025 had recommended against mandatory guardrails, arguing they could chill innovation.

The 15 July announcement reverses that trajectory. As Norton Rose Fulbright noted, Australia is now moving beyond regulating AI at the point of deployment and is instead developing national rules focused on the infrastructure and inputs on which large-scale AI depends.

What has actually changed?

The answer depends on how you measure change.

Already operating: The Office of AI was established within the Department of the Prime Minister and Cabinet on 15 July. As the PM&C website confirms, the office will coordinate across government agencies to design and legislate the new standards. Its role is policy coordination, not enforcement. The published materials do not identify licensing, investigation, audit or penalty powers.

Already established: The AI Safety Institute, created under the National AI Plan in late 2025, has commenced safety testing of frontier AI systems in partnership with the CSIRO, the Gradient Institute and the International Network for Advanced AI Measurement, Evaluation and Science.

Proposed but not yet law: The mandatory obligations for large data centres. These include requirements to underwrite new power supply, pay full grid connection costs, be net generators of energy, minimise water use and pay for additional water infrastructure. The government says these would apply to the “next generation” of facilities, suggesting the regime will be forward-looking.

Announced but not yet designed: The copyright protections. The Prime Minister stated categorically that Australian writers, musicians, artists and journalists must retain ownership and control of their work, and the government is not considering a text-and-data-mining exception. But the licensing mechanism, the territorial reach and the treatment of overseas AI providers are yet to be developed.

Still to come: Broader AI safety measures for consumers, workplaces and government. The AI consumer safety priorities released on 20 July confirmed the government will legislate a Digital Duty of Care, pursue workplace AI safety, examine consumer protections and develop a framework for automated decision-making in federal agencies. All of these remain work in progress.

Timeline: National Cabinet is expected to consider the approach in August 2026. Legislation is expected to be introduced to Parliament in early 2027. That is a significant gap, and as Professor Toby Walsh of UNSW noted, implementing the framework effectively will require significant work and it may come too late.

Data centres must carry their real costs

The most concrete proposals concern large data centres. This is where the government has its most direct regulatory leverage: the land, energy and water that these facilities require all sit within Australia’s jurisdiction.

As I wrote in June, the data centre investment pipeline in Australia is an estimated $155 billion over the next decade. Microsoft alone has committed $25 billion. These facilities currently account for 2.8 per cent of electricity consumption on the east coast, a figure the Australian Energy Market Operator projects will exceed 10 per cent by the mid-2030s.

Under the proposed framework, covered data centres would be required to underwrite their own new power supply, pay their full share of grid connection costs so that household energy bills are not affected, and put at least as much energy into the grid as they take out. The Prime Minister described them as needing to be “net generators, not net users.”

As White & Case observed, the word “build” appears in the Prime Minister’s speech, which is a stronger formulation than mere “underwrite.” A standard renewable power purchase agreement with existing generation is unlikely to be sufficient if it does not demonstrably support additional new capacity.

The open questions are significant. The threshold for “large” remains undefined. Whether the obligations apply to expansions of existing facilities is unresolved. How the obligation will be allocated between data centre developers and hyperscaler tenants is yet to be determined. How a national framework will interact with state planning systems, local approvals and electricity market rules remains unclear.

Australian creative work is not free training data

The copyright announcement was unusually categorical for a Prime Ministerial speech. The government has confirmed it is not considering a text-and-data-mining exception. The Prime Minister stated that Australian creative works cannot be used to train AI without the artist’s control, including control over the price and value of their work.

As I covered in July, Australian musicians including the Hoodoo Gurus and Paul Dempsey have been discovering their entire catalogues were fed into AI systems without permission or payment. The creative sector has been calling for the government to enforce existing copyright law rather than carve out an exception for AI companies.

The government’s position creates an interesting tension. As MinterEllison noted, the most advanced frontier models from OpenAI, Anthropic and Google were trained on vast quantities of publicly available content before any legislative framework was in place. Once copyrighted material has been ingested into model parameters, it cannot simply be extracted. The recent Anthropic settlement in the United States, where the company agreed to pay USD 1.5 billion but was not required to modify its models, illustrates what commentators have described as a “train now, pay later” dynamic.

The practical question is whether the legislation will have real force for future training runs and create genuine leverage for Australian creators to negotiate compensation, or whether it will largely entrench the advantage of companies that have already trained without constraint.

What technology companies will need to prepare for

Although the detailed legislation is still to come, the direction of travel is clear. McCullough Robertson summarised it as “the clearest indication to date of Australia’s policy on AI.” Companies developing, deploying or commercialising AI in Australia should expect:

Training-data obligations. Records of data provenance, rights clearance and licensing arrangements will become increasingly important.
Copyright compliance. The government has ruled out a free data mining exception. AI companies will need to demonstrate they have appropriate rights for Australian content used in training.
Environmental obligations for data centre projects. New facilities will be required to demonstrate net energy contribution, water efficiency, appropriate location and community consultation.
Governance and transparency expectations. While AI6 remains non-binding guidance, the Consumer Safety Priorities confirm the government will legislate a Digital Duty of Care and examine automated decision-making.

I would not recommend treating these as already mandatory. But I would recommend treating them as inevitable and preparing accordingly.

What cyber security and risk leaders should do now

For organisations deploying AI in Australia, the announcement changes the timeline, not the destination. Most of what the government is proposing was already foreseeable. Here is a practical readiness list:

1. Establish an inventory of AI systems and use cases. You cannot govern what you have not catalogued.
2. Identify accountable owners for each system. Someone needs to own the risk.
3. Classify systems by risk and potential harm. Not every AI tool needs the same level of oversight.
4. Review model and supplier contracts. Understand what rights your vendors have to your data, and what obligations they have around training data provenance.
5. Document data sources and training-data rights. This will become a compliance requirement.
6. Assess privacy and security implications for each use case, especially automated decision-making affecting individuals.
7. Establish human oversight for higher-risk applications. Document who reviews AI outputs and how.
8. Define AI incident-response procedures. Treat an AI failure like any other security incident.
9. Monitor upcoming legislation and standards. The Office of AI will publish consultation material in the coming months.
10. Preserve evidence of testing and governance decisions. When legislation arrives, organisations that can demonstrate good-faith compliance will have a significant advantage.

The most important gaps

The framework has drawn a mixed response. Greens Senator David Shoebridge argued the government had “totally missed the moment” and called for an independent AI regulator with real powers. Independent MP Kate Chaney welcomed the move but urged action on the data centre challenge. The Climate Council supported strong safeguards.

The gaps that concern me most are:

Consumer protection. The government will examine options in consumer law for surveillance pricing and agentic commerce, but this is a scoping exercise, not action. Meanwhile, AI chatbots and AI companions sit in a regulatory blind spot.

High-risk AI. Unlike the European Union’s AI Act, which prohibits specific high-risk systems, the Australian framework does not identify a general mandatory framework for high-risk AI. Most deployed AI remains subject only to existing technology-neutral laws.

Digital Duty of Care. Professor Toby Walsh has urged Australia to “expedite discussions on a digital duty of care and apply it to AI tools, including AI chatbots, AI companions and AI therapists.” The government has confirmed it will legislate a Digital Duty of Care, but no draft legislation has been published.

Enforcement and penalties. No regulator has been identified as the principal enforcement body. The Office of AI has a coordination role, not an enforcement one. It remains unclear who will monitor compliance, investigate breaches and impose penalties.

Automated decisions in government. The Robodebt Royal Commission demonstrated the real-world harm of poorly governed automated systems. The government has committed to developing a framework for automated decision-making in federal agencies, but this is early stage work.

Regulation can be an advantage if Australia gets it right

There is a reasonable case that well-designed regulation can support innovation. Clear rules create investment certainty, build public trust and prevent a race to the bottom. As Professor Walsh put it, a lack of regulation could turn the public against AI and ultimately hinder innovation.

But there is also a risk that this framework, if poorly designed, could either suppress useful innovation or leave people carrying risks they did not choose. The balance will be determined by the detail that has not yet been written.

The government’s decision to focus first on areas where it has practical leverage – land, energy, water and copyright-protected works – makes strategic sense. But the areas it has deferred or left vague raise legitimate questions about whether the framework will keep pace with AI deployment.

What I think

Australia has made a choice that many countries are still debating. It has decided that AI should be managed, not simply adopted. It has established institutional machinery to coordinate policy. It has drawn lines around data centres and creative works.

But the hard part – the legislation, the enforcement, the consumer protections, the workplace rules, the automated decision-making safeguards – has barely begun. The gap between an announcement and an operating regulatory system is where the real work happens.

The question that will define whether this framework succeeds is not whether the government has set the right direction. It is whether the government can move from announcement to implementation before the technology moves past the rules designed to govern it.

> The measure of this framework will not be the ambition of the speech. It will be the quality of the legislation, the effectiveness of the enforcement, and whether Australians retain agency, rights and safety in the AI economy. That is the test that matters, and it is still to come.

Subscribe

Related articles

NVIDIA, Microsoft, Meta, and 50+ Companies Tell Washington Not to Lock Down Open AI

More than 50 tech companies including NVIDIA, Microsoft, Meta, and Google published a joint letter urging Washington to protect open-weight AI models. The only notable holdout? Anthropic. Here is what the fight is actually about.

Europe Just Drew a Red Line on AI and Cybersecurity. Here Is What It Means

The EU Action Plan on Cybersecurity and AI sets nine actions across three pillars, with enforcement starting 2 August 2026. Fines climb to 3% of global turnover or 15 million euros for non-compliance. Here is what every security leader needs to know.

FLUX 3: How Black Forest Labs Is Bridging Video AI and Real-World Robots

Black Forest Labs' FLUX 3 is expanding from video and image generation into robot control for Audi factories, with an open-weight model planned for factory hardware.

The Open Source AI Revolution: When the World’s Biggest Models Became Free

Chinese open-source AI models led by Moonshot Kimi K3 have functionally closed the gap with proprietary systems from OpenAI and Anthropic, with profound consequences for geopolitics, global markets, and the future of autonomous AI agents.