Industry Solutions

Selling AI Into Australian Government

Selling AI Into Australian Government

Australian government AI compliance and governance layers

The Highest Compliance Bar in the Country

Selling AI into Australian government, federal, state, or local, means clearing the highest compliance bar in the country. The bar has at least five layers stacked on top of each other: mandatory IRAP assessment for systems handling OFFICIAL: Sensitive or higher, the Digital Transformation Agency's 2024 Policy for the Responsible Use of AI in Government, the Protective Security Policy Framework, federal and state privacy law, and the Commonwealth Procurement Rules with their associated panel structures.

Most vendors do not discover this stack until they are halfway through a procurement they have already started bidding, which is the worst possible time to learn the rules. By then the response timeline cannot absorb a 12-month IRAP path, and the bid either disqualifies or wins on a technicality the buyer is uncomfortable with.

This article is the map Australian vendors need before the next bid. It is part of our series on running AI agents in regulated Australian industries. If you have not yet read Operating AI Agents in Production or AI Agent Governance, Data Access, Privacy, and Human Override, start there. This piece builds on both and is the third regulated-vertical article in the series, following Financial Services AI Compliance under APRA and ASIC and Healthcare Practice AI and Patient Automation.

What this article covers

The five compliance layers an Australian vendor must clear, the Robodebt lesson and what it now means for AI bids, what the DTA Policy actually requires, the IRAP path and its real cost, state-by-state variation, the four AI risk classes government buyers will assess, a bid-readiness decision tree, and a 12-question pre-bid checklist.


Part 1: The Five Layers an AU Vendor Must Clear

Government compliance runs across five overlapping regimes, each with a different owner and a different consequence if it is missed.

The Five Compliance Layers for AI Vendors to Australian Government

Metric
Layer / What It Requires
Owner & Consequence If Missed
Improvement
1. Security: IRAP / PSPF / ISMIndependent assessment of system against ISM controls; protective security policy compliance; classification handlingASD/ACSC and Attorney-General's Dept. Cannot host OFFICIAL: Sensitive or higher data without it.Mandatory
2. AI-specific governance: DTA Policy for the Responsible Use of AI in Government (2024)Accountable AI official, public transparency statements, use-case assessment, risk classificationDigital Transformation Agency. Non-corporate Commonwealth entities are bound. Bidders must support buyer obligations.Mandatory for federal
3. Procurement: CPRs, IPP, AusTender, panelsEligibility to bid; value for money; Indigenous Procurement Policy thresholds; panel membershipDepartment of Finance. Outside the panel, you often cannot bid at all.Gating
4. Privacy: Federal Privacy Act + state actsAustralian Privacy Principles; NSW PPIPA; VIC PDPA; QLD IPA; data breach notificationOAIC plus state privacy commissioners. Notifiable breaches, financial penalties, contract termination.Mandatory
5. Records: Archives Act 1983 federal, state public records actsRecords of decisions made by or with AI must be captured, retained, and disposable per scheduleNational Archives and state archives. Records failures can void administrative decisions.Often missed

A bid that addresses only IRAP misses four of the five layers. The procurement layer is the most common surprise: a technically excellent, IRAP-assessed solution still cannot be bought directly if the buyer is required to source from a specific panel and the vendor is not on it.

For deeper context on the privacy layer specifically, see our GDPR vs Privacy Act comparison for Australian business.


Part 2: The Robodebt Lesson and What It Means for AI Vendors

The Royal Commission into the Robodebt Scheme (Final Report, July 2023) did not name AI as the culprit, but its findings now shape how every Australian government buyer evaluates algorithmic and AI-assisted systems. The scheme used automated income-averaging to raise debts against welfare recipients. The Royal Commission found the program was unlawful and caused profound harm.

For AI vendors, the practical effect is that government buyers now look for specific evidence before they will buy. The questions below are already appearing in tender response schedules across federal and state agencies.

What government buyers will now ask:

  1. Documented evidence the model or algorithm was tested on a population representative of the affected cohort. Generic accuracy numbers are not enough.
  2. Human-in-the-loop with meaningful review. The reviewer needs the authority to override, the training to know when to, and enough time in the day to do it.
  3. A documented right of review and an appeal pathway for any person affected by an automated or AI-assisted decision.
  4. Algorithmic transparency. Buyers will ask for plain-English explanations of what the system does, what data it uses, and what it will not do.
  5. Active mitigation of automation bias. Evidence that human reviewers are trained to disagree with the model and that disagreement is logged and respected.

If you have read our governance article, you already know the human-override pattern. The Robodebt context raises the stakes: in government it is the price of admission.

The international parallel often cited in 2024 procurement guidance is the New York City MyCity small-business chatbot, which gave business owners advice that contradicted the law. The lesson there is the same as Robodebt: an AI system deployed by government without rigorous testing against the population it affects becomes a public-sector incident very quickly.


Part 3: The DTA AI Policy: What It Actually Requires

The Policy for the Responsible Use of AI in Government, issued by the Digital Transformation Agency in 2024, is the federal whole-of-government baseline. It applies to non-corporate Commonwealth entities and informs procurement requirements that flow down to vendors.

Vendors do not implement the policy. The agency does. But agencies expect vendors to support and evidence the agency's obligations. A vendor who shows up unable to do this is a problem to be removed from the shortlist.

The five things the DTA Policy requires the buyer to do, and what a vendor must support:

  1. Designated accountable official. Each entity nominates an accountable senior officer for AI use. Vendors should expect to interact with this role, provide documentation to support it, and accept that approval gates exist outside the project team.
  2. AI inventory transparency. Entities maintain and publish a public inventory of AI use cases. Vendors must accept their work will likely appear there and must not require commercial-in-confidence treatment of the basic existence and purpose of a system.
  3. Use case assessment. Before deployment, each use case is assessed against the policy. Vendors must provide system descriptions, data flows, model lineage, and intended use boundaries in writing.
  4. Risk classification. Each AI use case is classified by risk. Higher risk classes require deeper controls (see Part 6).
  5. Public statements for high-risk uses. Where a system materially affects individuals, the entity must publish a statement describing the system. Vendors must be comfortable having their solution described publicly and must support drafting of that statement.

Aligning to this in vendor documentation is straightforward and it lifts bid quality a long way. Treating it as a tick-the-box exercise late in the process is a common way for otherwise strong bids to come apart.

For broader context on regulator expectations of AI, our piece on the DISR Voluntary AI Safety Standard and ACCC consumer guarantees covers the consumer-facing parallel that increasingly informs government procurement language.


Part 4: IRAP and the Hosting Reality

The Information Security Registered Assessors Program (IRAP) is the Australian Signals Directorate's mechanism for assessing systems against the Information Security Manual (ISM) and the PSPF. IRAP assessment is mandatory for any cloud or hosted system handling government information at OFFICIAL: Sensitive or higher classifications.

Several things about IRAP tend to surprise vendors coming to it for the first time:

  • IRAP is a point-in-time assessment, not a certification. ASD does not certify; an assessor issues a report and the consuming agency decides whether to accept the residual risk.
  • The major hyperscalers (AWS, Microsoft Azure, Google Cloud) hold IRAP assessments for specific services in specific Australian regions. The assessment covers the cloud platform, not your application. Your application built on top still needs its own IRAP assessment for the workload.
  • The Hosting Certification Framework (which replaced earlier cloud panels for hosting government data) restricts which providers can host certain classifications. Strategic-level certification is required for the most sensitive hosting arrangements.
  • Costs are substantial and the calendar dominates the budget.

From No IRAP to Assessed for OFFICIAL: Sensitive (Typical Vendor Path)

1
Months 0 to 2
Gap analysis
Map current controls against ISM. Identify the assessment scope (boundary, data flows, integrations). Decide classification target.
2
Months 2 to 6
Remediation
Implement missing technical controls. Build the System Security Plan, Statement of Applicability, Security Risk Management Plan, Incident Response Plan, and SOPs.
3
Months 6 to 9
Engage IRAP assessor
Select from the ACSC list of endorsed assessors. Scoping engagement and pre-assessment workshops.
4
Months 9 to 12
Assessment fieldwork
Evidence review, interviews, technical testing. Initial findings and remediation cycle.
5
Months 12 to 15
Final assessment report
Assessor issues the report. Vendor and consuming agency negotiate residual-risk treatment.
6
Months 15 to 18
Agency acceptance
Buyer's accountable authority accepts (or declines) the residual risk. System cleared for use at the assessed classification.

Realistic budget for a vendor running this end to end is typically several hundred thousand dollars in direct costs (assessor fees, remediation, documentation), plus substantial internal time. Re-assessment is generally required every two years and after material change.

If the system is intended to handle data above OFFICIAL: Sensitive (PROTECTED or above), expect a more expensive assessor engagement and longer remediation cycle. Most vendors target OFFICIAL: Sensitive as the entry point.

For an in-depth view of where the data actually lives, see our pillar guide on data sovereignty in Australia.


Part 5: State Variations (Federal Is Not the Whole Picture)

Every state operates its own framework on top of, or instead of, the federal stack. Selling into a state government means a different policy, a different cloud certification process, a different privacy regime, and a different panel.

State-by-State Variation for AI Vendors

Metric
State / Framework
Procurement & Notes
Improvement
NSW: AI Assurance Framework (NSW Government 2024), NSW Cyber Security Policy, PPIPA, HRIPAMost mature state AI policy. Mandatory AI assurance for projects exceeding thresholds. Cyber Security Policy aligned closely with PSPF/ISM.buy.nsw panels; AI/ICT supplier panels; threshold-based assurance reviewHigh maturity
VIC: OVIC IPP guidance, Vic PDPA, Victorian Protective Data Security Standards (VPDSS)OVIC (Office of the Victorian Information Commissioner) sets privacy and protective data security expectations. AI guidance issued by OVIC and DGS.Buying for Victoria panels; eServices RegisterStrong on privacy
QLD: Queensland Government Information Security Manual, Information Privacy Act 2009 (IPA)Queensland ISMS aligned with ISM but state-specific. AI guidance evolving through DESBT and chief information security officer.QITC framework and panelsAligned to ISM
WA: WA Government Cyber Security Policy, no state Privacy Act (Privacy Act federal applies in defined contexts)Cyber policy informed by ASD ISM and Essential Eight. Privacy regulated narrowly; expect Privacy Act 1988 applied where Commonwealth-funded.GovNext-ICT and DPC panelsLighter privacy regime
SA: SA Cyber Security Framework, Information Privacy Principles Instruction (administrative, not statutory)Cyber framework aligns with ISM. Privacy regime is administrative direction rather than statute. Defence and space heavy.ICT contracts directory; whole-of-government panelsAdministrative privacy

The practical implication: an IRAP-assessed system is necessary but not sufficient at the state level. A vendor selling into NSW Health will also need to engage with the AI Assurance Framework and PPIPA-specific clauses. A vendor selling into Victorian agencies will deal with VPDSS and OVIC. Plan for state-specific assurance work on top of any federal baseline.


Part 6: The Four AI Risk Classes Government Buyers Will Assess

The DTA Policy, the NSW AI Assurance Framework, and the DISR Voluntary AI Safety Standard (2024) all converge on a similar risk-class model. The names vary; the substance is the same. A vendor who walks into a bid able to self-classify is enormously easier to procure from than one who needs the buyer to do that work.

The Four AI Risk Classes Buyers Will Assess Against

Metric
Risk Class / Example
Control Expectations
Improvement
Low: Internal productivity (summarising meeting notes, drafting non-decision documents)Minimal external effect. No automated decisions about people.Basic governance: acceptable use policy, data classification, no PII unless cleared, staff training.Light touch
Medium: Internal decision support (triage suggestions, ranked recommendations to a human decision-maker)Output influences but does not make a decision affecting a person.Documented model lineage, accuracy monitoring, override logging, bias review, periodic re-validation.Documented oversight
High: External-facing or affecting individuals (chatbots giving public guidance, eligibility screening, fraud flags routed to investigators)Output reaches the public or directly informs a decision about a person.Pre-deployment impact assessment, public transparency statement, human-in-the-loop with meaningful authority, audit trail, right of review, ongoing bias monitoring.Robodebt-grade controls
Critical: Automated decisions affecting rights, benefits, or safety (automated debt raising, automated benefit cancellation, safety-critical operational AI)AI materially determines outcomes that affect statutory rights or safety.Generally avoided. If pursued, requires legal basis review, Royal-Commission-grade testing, parliamentary or accountable-officer sign-off, statutory review pathway, real-time monitoring, kill switch.Avoid by default

A useful internal exercise before bidding: classify every component of your proposed solution against this table. If any single component lands in "Critical", the bid response must lead with the controls, not the features.

For the broader human-oversight pattern that supports the High and Critical classes, our AI agent governance article covers the override and audit-log patterns in detail.


Part 7: Are You Ready to Bid? Decision Tree

Bid-Readiness Decision Tree

Are you ready to bid on this Australian government AI tender?
No IRAP assessment for the data classification involved (and tender requires it)
→ Do not bid this round. Start the IRAP path. Target the next refresh of this panel or a comparable tender in 12 to 18 months.
IRAP in place but no eligibility for the relevant panel / supplier list
→ Partner with an existing panel member as a subcontractor, or apply when the panel reopens. Do not assume direct-engagement waivers.
AI use case is High or Critical risk and you cannot evidence human-in-the-loop, review pathway, and population-representative testing
→ Not ready. Re-scope to lower-risk components or do the assurance work before bidding.
Hosting is outside Australian regions (and tender requires onshore)
→ Re-architect to an IRAP-assessed Australian region of AWS, Azure, or Google Cloud before bidding. Offshore hosting is a disqualifier for most government workloads.
All four above resolved: IRAP, panel, risk class evidenced, onshore hosting
→ You are bid-ready. Continue to the 12-question pre-bid checklist in Part 8.

If three of the four conditions are unresolved, the bid is not winnable on its merits. It is winnable only if the buyer waives requirements, which no vendor should bank on.


Part 8: 12-Question Pre-Bid Readiness Checklist

For the bid lead or CIO, before committing the response team to the tender:

  1. Have we identified every panel, framework agreement, or supplier list the buyer is required to use, and confirmed we are on it (or can subcontract through someone who is)?
  2. Do we hold a current IRAP assessment for the data classification this tender involves, and is the assessment scope a match for the proposed workload?
  3. Have we classified our AI use case against the four risk classes (Low / Medium / High / Critical) and can we evidence the corresponding controls?
  4. Can we name the Australian region (AWS Sydney, Azure Australia East/Southeast, Google Cloud Sydney/Melbourne) where every part of the workload, including training and inference, will run?
  5. Do we have a documented human-in-the-loop design, a review pathway, and an audit log that survives discovery?
  6. Have we mapped our data flows against the Australian Privacy Principles and any applicable state privacy act (PPIPA, PDPA, IPA)?
  7. Are our records-keeping obligations (Archives Act 1983 or state equivalent) addressed in our solution architecture?
  8. Do we have personnel with the right security clearance levels, or a credible plan to obtain them within the contract timeline?
  9. Have we identified any Indigenous Procurement Policy thresholds that apply to this tender and how we will address them?
  10. Can we provide an algorithmic-transparency statement in plain English that the buyer could publish?
  11. Do we have a documented incident response plan, tested in the last 12 months, that aligns to ISM and the buyer's expected severity classifications?
  12. Have we modelled the full cost of compliance (IRAP, panel fees, ongoing assurance, clearance maintenance) into our bid price, not just delivery cost?

A "no" on any of items 1, 2, 3, or 4 should pause the bid decision until resolved.


A Note on Cost, Realistically

For a vendor stepping into government work for the first time, the realistic first-year compliance investment runs to several hundred thousand dollars in direct cost, plus substantial internal time. IRAP, documentation, clearances, and ongoing assurance compound. The compensating factor is that government contracts typically run 3 to 5 years with extension options, and the same compliance posture unlocks multiple sectors (defence-adjacent, critical infrastructure, regulated commercial buyers) that the vendor could not otherwise approach.

For context on how to structure the financial argument internally, our automation business case template for Australian businesses covers the framework, including how to model multi-year compliance amortisation.


How Solve8 Helps Vendors Approach Government

We work with Australian businesses on the architecture and governance posture required for regulated and government-adjacent AI. That includes:

  • Pre-IRAP gap assessment and scoping advice (we do not perform IRAP assessments; we help you be ready for one).
  • DTA AI Policy alignment in the agent and system design, so buyer obligations are supportable from day one.
  • Human-in-the-loop and audit-log architecture matched to the relevant risk class.
  • State-specific framework alignment (NSW AI Assurance Framework, VPDSS, QLD ISMS).
  • Bid response review for technical compliance language.

If you are considering a government bid in the next 12 to 18 months and want a frank read on readiness, book a consultation. We will not pretend the path is short, but we will tell you what is achievable in the time you have.


Related Reading:


Sources:

This article synthesises guidance from the Digital Transformation Agency's Policy for the Responsible Use of AI in Government (2024), the Australian Signals Directorate Information Security Manual and IRAP program documentation, the Attorney-General's Department Protective Security Policy Framework, the Department of Industry, Science and Resources Voluntary AI Safety Standard (2024), the NSW Government AI Assurance Framework (2024), the Royal Commission into the Robodebt Scheme Final Report (July 2023), the Commonwealth Procurement Rules, the Office of the Australian Information Commissioner guidance on the Australian Privacy Principles, and state-level frameworks from OVIC (Victoria), QLD DESBT, and the WA Office of Digital Government.