Business Strategy

AI and the NSW Psychosocial WHS Code

AI and the NSW Psychosocial WHS Code

Abstract visualisation of workplace wellbeing signals surfacing from data streams, deep navy and indigo gradient with soft indicators

From 1 July 2026, a change that has been building for years finally has teeth in New South Wales. The state's approved codes of practice, including the SafeWork NSW Code of Practice: Managing psychosocial hazards at work, are now enforceable. The duty to protect workers from psychological harm did not appear overnight. What changed is that the standard a business is measured against is no longer advisory. It is the benchmark an inspector, and ultimately a court, will apply.

This guide is written for owners, people leaders, and operations managers at Australian midsize businesses who are trying to understand what the enforceable code actually requires, and where artificial intelligence has a legitimate role in meeting it. The honest answer is that AI can help with parts of the work, particularly the detection and documentation that most businesses do badly. It can also make the problem worse if it is deployed as surveillance rather than as a genuine risk control. Both sides of that ledger matter, and this article covers both.

Nothing here is legal advice. Psychosocial risk is fact specific and the reasonableness of any control depends on your circumstances. Where a situation is genuinely unclear, get advice from a WHS specialist or an employment lawyer.

What actually changed on 1 July 2026

The starting point is the Work Health and Safety Act 2011 (NSW). A new section 26A was inserted so that, from 1 July 2026, a person conducting a business or undertaking, a PCBU, must either comply with an approved code of practice or manage the relevant hazard in a way that achieves a standard of health and safety that is equivalent to or higher than the code. If you depart from the code, the burden sits with you to show your alternative is at least as good.

That is a meaningful shift. Before this change, a code of practice was admissible as evidence of what was reasonably practicable, but it was not itself a rule. Now, falling short of an applicable code can help establish a breach, and SafeWork NSW inspectors do not need to wait for an incident or an injury to act. The gap between "we meant to get to this" and "we have documented controls in place" is now the gap between compliant and exposed.

It is worth being precise about what did and did not start in 2026. The duty to manage psychosocial risk itself is older. Explicit psychosocial risk provisions were built into the WHS Regulation 2017 (NSW) and have been in force since 2022, and the general duty of care under the WHS Act has always covered psychological health. The 2026 change is about enforceability of the code that explains how to discharge that duty. Businesses that treated the code as optional guidance now need to treat it as the operating standard.

How Psychosocial WHS Duties Became Enforceable in NSW

1
2012
WHS Act in force
Duty of care covers psychological health from the start
2
2022
Regulation updated
Explicit psychosocial risk provisions added to the WHS Regulation 2017 (NSW)
3
Pre-2026
Code as guidance
SafeWork NSW psychosocial hazards code available, but advisory rather than enforceable
4
1 July 2026
Codes enforceable
Section 26A makes approved codes an enforceable benchmark
5
Ongoing
Inspection and review
Proactive inspection, unannounced visits, documented controls expected

The hazards the code names

One reason psychosocial risk is easy to underestimate is that it sounds abstract. The code makes it concrete by naming the hazards a PCBU is expected to manage. Drawing on the Safe Work Australia model code that NSW follows, the recognised psychosocial hazards include:

  • High or low job demands, where the workload is sustained at a level that is either overwhelming or so low it becomes harmful
  • Low job control, where workers have little say over how and when they do their work
  • Poor support from supervisors or colleagues
  • Lack of role clarity, where responsibilities and expectations are uncertain or conflicting
  • Poor organisational change management
  • Inadequate reward and recognition
  • Poor organisational justice, including inconsistent or unfair application of policies
  • Traumatic events or exposure to distressing material
  • Remote or isolated work
  • Poor physical environment
  • Violence and aggression
  • Bullying
  • Harassment, including sexual harassment
  • Conflict or poor workplace relationships

The point of the list is that these are conditions of work, not personality traits. The code asks a business to look at how work is designed, organised, and managed, and to treat harmful patterns as hazards to be controlled, in the same systematic way it would treat a trip hazard or an unguarded machine.

What the code requires you to do

The enforceable expectation is a systematic risk management process, applied to psychosocial hazards with the same rigour long expected for physical ones. In practice that means four repeating steps, plus a consultation duty that runs through all of them.

The Psychosocial Risk Management Cycle

Identify
Find psychosocial hazards in how work is done
Assess
Judge likelihood, severity, and who is exposed
Control
Apply the hierarchy of controls, design out where possible
Review
Check controls still work and revise after change

Identification means actively looking, not waiting for a complaint. Sources include worker consultation, incident and hazard reports, workers compensation and absence patterns, exit interviews, and workload and rostering data. Assessment means understanding how serious and how frequent a hazard is, and who is most exposed. Control means applying the hierarchy of controls: eliminate the hazard where you can by redesigning work, and only rely on training or individual resilience as a lower order control, not a substitute for fixing the work itself. Review means checking that controls are working and revisiting them after any significant change, such as a restructure, a new system, or a spike in demand.

Running through all four steps is the duty to consult workers, which the WHS Act treats as central. Workers and, where they exist, health and safety representatives must be genuinely involved in identifying hazards and deciding on controls. This matters enormously for the AI discussion that follows, because consultation is a duty you cannot automate away. A tool can inform the conversation. It cannot replace it.

Officers have their own exposure. Under the due diligence duty in the WHS Act, officers must take reasonable steps to understand the business's psychosocial risks and ensure resources and processes are in place to manage them. NSW also introduced a standalone industrial manslaughter offence in 2024, and the WHS Act's tiered offence structure means the most serious breaches carry penalties in the millions of dollars for a body corporate. The direction of travel is clear: psychosocial risk is being treated with the seriousness once reserved for physical safety.

Where AI genuinely helps

The strongest case for AI in psychosocial risk management is detection and documentation. Most midsize businesses are not short of relevant data. They are short of the capacity to notice patterns in it and to keep a defensible record of what they found and what they did. This is precisely the kind of work that suits AI, provided it is pointed at work design rather than at individuals.

Consider a typical 200-person services business with several teams, a rostering system, a payroll system, an HR case log, and an annual engagement survey. The signals of sustained high job demands are almost always sitting in that data already: chronic overtime concentrated in one team, leave that is accrued but never taken, a cluster of resignations from a single manager's area, a run of after-hours activity that never lets up. A human reviewing spreadsheets once a quarter will miss most of it. A well-scoped model that surfaces these patterns, and flags them for a person to investigate, turns latent data into an early warning.

Psychosocial Risk Detection: Manual Versus AI-Assisted

Metric
Manual, Periodic
AI-Assisted, Continuous
Improvement
Detecting sustained overloadNoticed after burnout or a resignationFlagged from rostering and leave patterns earlyEarlier
Survey analysisRead once, filed, forgottenThemes surfaced and tracked over timeContinuous
Risk register upkeepUpdated when someone remembersDraft entries and review reminders generatedConsistent
Audit readinessReconstructed under pressureDocumented as you goDefensible

Three uses stand out for midsize businesses.

The first is pattern detection across existing operational data. Rostering, timekeeping, and leave systems hold the clearest objective evidence of job demands. AI can watch for the combinations that the code cares about, sustained overtime plus unused leave plus concentrated absence, and route them to a manager or WHS lead as a hazard to assess. The output is a prompt for human judgement, not a verdict.

The second is making sense of qualitative feedback. Engagement surveys, exit interviews, and hazard reports contain rich signals that usually go unread at scale. Language models are genuinely good at grouping free-text responses into themes, tracking whether a theme is getting worse, and separating a one-off gripe from a structural problem. Used on aggregated, de-identified feedback, this strengthens the identification step without singling anyone out.

The third is documentation and cadence. The enforceable code rewards businesses that can show a live, maintained risk management process. AI can draft risk register entries from identified hazards for a human to review and approve, keep the review cycle on schedule with reminders, and assemble the evidence trail that demonstrates you have been doing the work. This is unglamorous and it is exactly where most businesses fail an inspection: not because they did nothing, but because they cannot prove what they did.

Our own perspective on this comes from building AI systems where the audit trail is the product, not an afterthought. The same discipline applies here. If a control cannot be evidenced, for compliance purposes it may as well not exist.

Where AI Effort Pays Back in Psychosocial Risk

Early detection of overload before it becomes a claimFewer incidents
Survey and feedback themes surfaced continuouslyBetter identification
Risk register and review cadence maintainedAudit ready
Documented, defensible controls in placeLower exposure

Where AI adds exposure instead of reducing it

The same capabilities that make AI useful make it dangerous when it is aimed at people rather than at work. This is the part most vendors will not tell you, and it is the part most likely to land a business in trouble.

The first risk is that monitoring becomes a hazard in its own right. Surveillance that workers experience as intrusive, opaque, or punitive is itself a recognised source of psychological harm. Deploying AI to watch keystrokes, screen time, tone of messages, or individual productivity in the name of wellbeing is close to self-defeating. It can manufacture the very low control and low trust conditions the code treats as hazards. If a control makes the psychosocial environment worse, it is not a control.

The second risk is legal, and it sits alongside WHS law. Analysing employee communications and behaviour engages the Privacy Act 1988 where personal information is involved, and in New South Wales the Workplace Surveillance Act 2005 imposes notice and other requirements on computer, camera, and tracking surveillance of workers. AI that quietly reads messages or monitors individuals can breach these obligations regardless of intent. Any system touching employee data needs the same governance discipline you would apply to customer data, a theme we cover in our guide to deploying AI agents responsibly.

The third risk is automating judgements that must stay human. A model may flag a team or a pattern, but decisions about individuals, performance, capability, or discipline, cannot be delegated to an algorithm, both because that is poor WHS practice and because automated decision making about people carries its own emerging compliance obligations, which we examine in our piece on automated decision making and privacy.

Is This an Appropriate Use of AI for Psychosocial Risk?

What is the AI being pointed at?
Aggregated work-design signals, reviewed by a human
→ Appropriate, keep humans in the loop
De-identified survey and feedback themes
→ Appropriate with privacy safeguards
Individual keystroke, message, or productivity monitoring
→ High risk, likely a hazard and a privacy problem
Automated decisions about a person's performance
→ Not appropriate, humans must decide

The fourth risk is the illusion of compliance. Buying a dashboard is not the same as managing risk. If a tool produces a wellbeing score that no one acts on, the business has added cost and a discoverable record of hazards it did not control, which is worse than not measuring at all. The code rewards action, consultation, and review, not measurement for its own sake.

A practical way to start

For a midsize business meeting the enforceable code for the first time, the sequence matters more than the tooling. The goal is a genuine, consultative risk management process that AI supports, not a technology project that produces a report.

A Realistic First 90 Days

1
Weeks 1-3
Consult and map
Involve workers and HSRs, identify hazards from real experience and existing data
2
Weeks 4-6
Assess and prioritise
Rank hazards by severity and exposure, decide what to control first
3
Weeks 7-10
Control at the source
Redesign work where possible, use the hierarchy of controls, record decisions
4
Weeks 11-13
Instrument and review
Add AI detection and documentation on top of a working process, set the review cadence

Notice that technology arrives last. That ordering is deliberate. Consultation and control come first because they are the substance of the duty. AI is layered on to make identification sharper and documentation defensible, once there is a real process for it to support. A business that starts with a monitoring tool and hopes a process will follow usually ends up with neither.

The connection to broader workforce policy is worth naming. Psychosocial risk overlaps with how a business handles after-hours contact, change, and workload, all of which have their own legal dimensions. Our guides to the right to disconnect, to Fair Work compliance and automation, and to managing AI-driven change with your people sit alongside this one, because the same design choices that protect psychological health also keep a business on the right side of employment law.

The bottom line

The enforceable code changes the question a NSW business has to answer. It is no longer "did something go wrong?" but "can you show you were systematically managing the risk?" That is a documentation and process challenge as much as a wellbeing one, and it is where AI earns its place: detecting patterns in data you already hold, making sense of feedback at scale, and keeping a defensible record of controls and reviews.

The same tools cause harm when they are turned into surveillance or used to automate judgements about individuals. The dividing line is simple to state and easy to cross: point AI at how work is designed, keep humans in every decision about people, and never let monitoring become a hazard of its own. Businesses that get this balance right will not just avoid an inspector's finding. They will build the kind of workplace the code was written to protect.


Related Reading