Compliance

The AI rules, as they actually stand.

A working register for Australian teams: what applies today, what is still phasing in, and what quietly changed. Written for the people who have to answer for it, not for a press release.

10

Instruments tracked

5

Jurisdictions

Dec 2026

Next Australian deadline

August 2026

Register last reviewed

What changed, and when.

Two of these moved in directions most planning decks did not anticipate: Australia set its mandatory guardrails aside, and the EU deferred its high-risk regime a week before it was due to bite.

  1. Feb 2025

    EU AI Act prohibited practices begin to apply.

  2. Aug 2025

    EU obligations for general-purpose AI providers take effect.

  3. Aug 2025

    OVIC restricts public generative AI tools across its engagements.

  4. Sep 2025

    NSW establishes a dedicated Office for Artificial Intelligence.

  5. Dec 2025

    Australia’s National AI Plan sets aside mandatory guardrails.

  6. Jun 2026

    Colorado AI Act takes effect.

  7. Jul 2026

    EU Digital Omnibus defers the high-risk regime.

  8. Aug 2026

    EU AI Act transparency duties apply.

  9. Dec 2026

    Australian APP 1 automated-decision disclosure becomes enforceable.

  10. Dec 2027

    EU high-risk obligations for Annex III systems begin.

The register.

Australian instruments first (federal and state), with the EU and United States carried because they reach Australian businesses whose output crosses those markets. Open an entry for timing and what it means at the point of send.

10 instruments

Australia

Phasing in

Privacy Act: automated decision transparency

The Privacy and Other Legislation Amendment Act 2024 adds an APP 1 obligation to disclose substantially automated decisions that significantly affect an individual.

Read the Entry

Australia

Guidance

National AI Plan

The December 2025 plan set aside the ten mandatory guardrails proposed in 2024 in favour of existing law, sector regulators and the Australian AI Safety Institute, which advises rather than enforces.

Read the Entry

NSW

In force

AI Assessment Framework and AI Operational Policy

A mandatory, risk-based assessment covering all NSW Government use of AI across the solution lifecycle, administered by Digital NSW alongside the AI Operational Policy.

Read the Entry

Victoria

In force

OVIC guidance on generative AI

The Office of the Victorian Information Commissioner restricts publicly available generative AI tools in its engagements and permits securely managed enterprise tools under data governance controls.

Read the Entry

Victoria

In force

DFFH generative AI direction

The Department of Families, Fairness and Housing was directed to stop using generative AI tools after a child protection worker drafted a Children’s Court report in ChatGPT that contained sensitive information and proved inaccurate.

Read the Entry

European Union

In force

AI Act: transparency obligations

Article 50 transparency and AI-content labelling duties applied from 2 August 2026. Prohibited practices under Article 5 have applied since February 2025 and general-purpose AI obligations since August 2025.

Read the Entry

European Union

Phasing in

AI Act: high-risk obligations (deferred)

The Digital Omnibus, Regulation (EU) 2026/1744, deferred the high-risk regime. Annex III standalone systems move to 2 December 2027; Annex I systems embedded in regulated products move to 2 August 2028.

Read the Entry

United States

In force

Colorado AI Act

The first comprehensive US state AI statute, imposing duties on developers and deployers of high-risk systems around algorithmic discrimination.

Read the Entry

United States

In force

Texas Responsible AI Governance Act

A narrowed version of the original bill, focused on intentional harms and government use rather than the broad high-risk scheme first proposed.

Read the Entry

International

In force

ISO/IEC 42001

The management-system standard for AI, certifiable in the same way as ISO 27001, covering governance, risk treatment and operational control of AI use.

Read the Entry

Every one of these lands in the same place.

The instruments differ in scope and drafting, but the operational demand they make of you is remarkably consistent.

VISIBILITY

Disclosure Assumes Visibility

Every transparency duty starts by asking where automated processing happens. That question has no answer while staff use whatever tool they like from an unmanaged tab.

EVIDENCE

Evidence Is Contemporaneous or It Is Nothing

Regulators ask what was sent, by whom, and what the system did about it. A record written after the fact is a reconstruction; a decision logged at send time is evidence.

ENFORCEMENT

A Policy Nobody Can Enforce Is a Document

Most organisations already have an acceptable-use policy for AI. What they lack is anything standing between the policy and the send button.

Airentect ships policy packs mapped to ISO 42001, SOC 2 and APRA CPS 234 control language, and records every decision it makes at send time. That is a statement about the controls in the product, not a claim to hold those certifications ourselves. Our security and data-residency detail sets out what we store and where it lives.

Find out where you actually stand.

Fifteen questions on how AI is used across your organisation, scored against the same model our exposure reports use. No sales call attached.