AI Consulting in Australia After the AI Plan

Australia decided not to write an AI rulebook. That changed what a consultant is for.
For most of 2024 and 2025, Australian businesses planning an AI project were waiting for a rulebook. The Department of Industry, Science and Resources had released a proposals paper in September 2024 that set out ten mandatory guardrails for AI in high-risk settings, and a lot of boards decided to hold their programs until they knew what the law would require.
That rulebook is not coming, at least not as an AI-specific act. After a public consultation that drew substantial industry feedback, the Government decided not to proceed with the proposed mandatory guardrails, and in December 2025 it released the National AI Plan. The Plan leans on Australia's existing, technology-neutral laws rather than on a dedicated AI statute, and it points organisations toward voluntary guidance for the how. A national AI Safety Institute began standing up in early 2026 to monitor risks and work with international partners.
If you were waiting for the law to tell you exactly what to do, the waiting is the mistake. Nobody is going to hand you a compliance checklist stamped by Parliament. The obligations that already applied to your business still apply the moment you put an AI system in front of a customer, a job applicant, or a regulator. The job of an AI consultant in Australia has shifted accordingly. It is less about interpreting a new act and more about helping you self-govern in a country that has decided self-governance is the model.
This guide explains the current picture, what actually binds you, and what a scoped AI strategy engagement produces against it. If you are still comparing firms rather than obligations, our buyer's guide to AI consulting in Australia covers how to tell delivery partners apart.
How the rules landed: a short timeline
The direction of travel matters, because it explains why the burden now sits with you rather than with a regulator writing detailed rules.
Australian AI Governance, 2024 to 2026
Two things are worth reading carefully here. First, the voluntary material has not been abandoned. It has been refined. The Voluntary AI Safety Standard published on 5 September 2024 set out ten guardrails, and in October 2025 the National AI Centre replaced it with the Guidance for AI Adoption, which distils the same thinking into six essential practices and splits them into a Foundations track for organisations getting started and an Implementation track for technical and governance teams.
Second, choosing not to legislate AI specifically does not leave AI unregulated. The framework is the set of laws you already answer to: the Privacy Act 1988, the Australian Consumer Law, anti-discrimination law, work health and safety duties, and your sector's own rules. AI is simply another way your business can breach or comply with them. That distinction is the whole game.
What still binds you, regardless of the AI Plan
A consultant who tells you AI is now a free-for-all in Australia has misread the Plan. The technology-neutral approach means the existing statutes reach AI conduct directly. The practical question is which of them your particular use touches.
Voluntary Guidance vs Law That Already Binds You
| Metric | Guidance for AI Adoption | Existing law | Improvement |
|---|---|---|---|
| Status | Voluntary, no new penalty | In force, enforceable now | Binding |
| Personal information in prompts or training | Practice: data governance | Privacy Act 1988, APPs | Applies |
| AI-generated claims to customers | Practice: accountability | Australian Consumer Law, s18 | Applies |
| AI in hiring or credit decisions | Practice: human oversight | Anti-discrimination law | Applies |
| AI advice in a safety-critical setting | Practice: risk management | WHS duties, sector rules | Applies |
Read the right-hand column as the floor. The Voluntary AI Safety Standard and its successor guidance sit above that floor and help you meet it in a defensible way, but they do not replace it and they do not soften it. If an AI chatbot on your site tells a customer something untrue about a product, the fact that you followed voluntary guidance is useful evidence of good faith, and the misleading conduct provisions of the Australian Consumer Law still apply.
The Privacy Act deserves particular attention. Personal information that flows into a model, whether in a prompt, a fine-tuning set, or a retrieval index, is still personal information, and the Australian Privacy Principles still govern how you collect, use, disclose, and secure it. For any Australian organisation handling customer or employee data, where that data is processed becomes a governance question rather than a preference, which is one reason private AI infrastructure has become a common part of a scoped engagement.
The six essential practices, and what they ask of you
The Guidance for AI Adoption is the closest thing Australia has to a national baseline for responsible AI use. It is voluntary, and it is also the standard a court, a regulator, or an enterprise procurement team will reach for when they ask whether you acted reasonably. Treating it as optional is a commercial risk even though it is not a legal duty.
Guidance for AI Adoption: Six Essential Practices
None of these six is exotic. Organisations stumble because these are practices that need owners and habits, and a filed policy document satisfies none of them on its own. Accountability means a named person who can explain a decision the system made last Tuesday. Assessing impact means understanding who is affected before you deploy, including the people who never call you to complain and simply go elsewhere. Human oversight means someone with the authority and the tooling to override the model before harm reaches a customer. The guidance aligns with Australia's AI Ethics Principles and with international standards including ISO/IEC 42001 and the NIST AI Risk Management Framework, so an organisation that builds against it is also positioned for enterprise and export buyers who ask for those standards by name.
A capable consultant helps you turn each practice into something operational: an owner with a name, an impact assessment that a non-technical director can follow, a risk register that gets reviewed, a testing regime that runs on a schedule, and an override path that has been rehearsed. Our AI governance framework for Australian businesses walks through what a defensible version of each looks like in practice.
The two-track structure of the guidance is worth using rather than skimming. The Foundations track is written for directors and managers who need to understand the shape of the obligation without becoming engineers, and it is the right starting point for a board that wants to set expectations before a project begins. The Implementation track is written for the people who will build and run the systems, and it is where the testing regimes, logging, and oversight mechanisms get specified. Handing the whole document to the technical team and hoping governance emerges is the most common way organisations end up with practices that exist on paper and nowhere else.
Where your AI risk actually sits
Not every AI use carries the same weight. A model that drafts internal meeting notes is a different governance problem from one that helps decide who gets a loan. Spending equally on both wastes money and, worse, gives the low-risk system attention the high-risk one needed. This is where a short strategy engagement earns its fee, by sorting your uses before you build.
Prioritise Your AI Governance Effort
The pattern is straightforward once you name it. The closer an AI system sits to a decision that affects a person's rights, money, or safety, the more of the six essential practices you need to apply in full, and the more the existing law is watching. A business that maps its AI uses onto this before it writes a line of code spends its governance budget where the exposure is, and moves faster on the low-risk uses because it has already decided they are low-risk.
The uses you did not approve are still yours
The self-governance model has a blind spot that catches a lot of Australian organisations, and it is worth naming before the formal work begins. Long before a board approves an AI project, staff are already using consumer AI tools to draft emails, summarise documents, and answer customer questions, often by pasting company and customer information into services that store and may train on it. This is sometimes called shadow AI, and under the technology-neutral model it carries the same legal weight as anything you deploy deliberately.
If an employee pastes a spreadsheet of customer records into a public chatbot to clean it up, the Privacy Act obligations attach to that disclosure whether or not anyone signed off on it. If a customer-facing team member relies on an AI answer that turns out to be wrong, the Australian Consumer Law does not care that the tool was unofficial. Accountability, the first of the six essential practices, starts with knowing what is actually running in your business, and for most organisations the honest first answer is that they do not know.
An early output of a scoping engagement is usually an inventory: what tools are in use, what data is flowing into them, and which of those flows create exposure. That inventory is dull to produce and it is where the real risk often turns out to be hiding, well ahead of the flagship project everyone was worried about.
What an AI consulting engagement produces now
Because Australia chose guidance over legislation, the deliverable from a good engagement has changed shape. You are no longer buying an interpretation of a new law. You are buying a working system that meets the existing law and stands up against the voluntary baseline, plus the evidence that it does.
Consider a typical Australian services organisation with several hundred staff, running Xero, a CRM, and a document store, that wants to deploy an AI assistant across customer support and internal operations. A scoped engagement for that organisation usually delivers four things.
First, a use-case map that separates the high-risk applications from the low-risk ones, so effort follows exposure. Second, a data and hosting decision that satisfies the Privacy Act, which for many organisations means keeping processing onshore. Third, the built and integrated system itself, wired into the tools the business already runs so that work flows rather than piles up in a new silo. Fourth, the governance evidence: the named owners, the impact assessments, the testing schedule, and the override path that together let you show a regulator, an insurer, or an enterprise customer that you acted reasonably.
The last of those is the part organisations most often skip and most often regret. When something goes wrong with an AI system, and over a long enough horizon something will, the question is never whether you had a glossy AI policy. It is whether you can show what the system did, who was responsible, and how a person could have stopped it. That evidence is cheap to build in at design time and expensive to reconstruct afterward.
The value of self-governance is easy to underrate until you price the alternative.
Why Build Governance In, Not On
The private-infrastructure question
One recurring decision in Australian engagements is whether to send data to a large overseas model provider or to run models on infrastructure you control. The National AI Plan does not force this choice, but the Privacy Act, your sector rules, and your enterprise customers' security questionnaires often push toward keeping sensitive data onshore and inside your own boundary.
Running models in your own environment suits some workloads and leaves others better served by a managed provider, and a consultant who insists it always suits has stopped listening. It fits when the data is sensitive, when a contract or regulator requires onshore processing, or when you need an audit trail you fully control. We built RootCauseAI, our own on-premise investigation tool, precisely for teams that could not send incident data to an external service, and the pattern it demonstrates carries across to any organisation with the same constraint.
The practical test is simple. If you cannot answer, in writing, where your data is processed and who can see it, you are not ready to deploy, and that gap is a normal first output of a scoping conversation rather than a reason to feel behind.
Choosing a partner in the self-governance era
The shift toward self-governance raises the stakes on who you work with, because there is no regulator pre-approving the approach. A few questions separate a partner who understands the current Australian picture from one still selling a generic AI pitch.
Ask where your data will be processed and get it in writing. Ask them to name the six essential practices and show how their delivery method builds each one in. Ask for the override path on a system they have shipped, not a diagram of one. Ask what they told a previous client not to automate, because honest scoping is the clearest signal that a partner is optimising for your outcome rather than their invoice.
Location matters less than it used to for delivery, but understanding your regulatory environment does not. A partner working with an Adelaide defence or space supplier, for instance, needs to understand that sector's data handling expectations, which is why our Adelaide AI consulting page leads with sovereignty rather than generic automation promises. The same principle applies wherever you sit: the partner should understand the obligations attached to your industry, not just the technology.
If you want the fuller checklist for evaluating firms, engagement models, and red flags, start from the Solve8 homepage and follow through to the consulting work, or read our detailed guide on the topic.
The takeaway for Australian boards
Australia has made its choice for this cycle. There will be no AI-specific act handing you a checklist. Instead, the existing law reaches your AI conduct directly, and the Guidance for AI Adoption gives you the voluntary baseline that regulators, courts, insurers, and enterprise buyers will measure you against. The organisations that treat that baseline as the real standard, and build the evidence to prove they met it, will move faster and carry less risk than the ones still waiting for permission.
That is the work an AI consultant in Australia does now. Map the uses, meet the existing law, build against the voluntary baseline, and leave you with a system that runs and a file that stands up. If you want to scope what that looks like for your organisation, book a conversation with our team and we will start with your obligations, not our product list.