AI Governance
Who Owns AI Risk in Australia?
The Question Canberra Must Answer
Independent policy analysis | Updated 4 August 2026
This article expresses my personal view and is not legal, regulatory or employer advice.
Key message Australia does not need to choose between the European and American approaches to AI governance. We need a distinctly Australian model: clear ownership, practical implementation, strong safeguards for high-risk use and room for innovation. We should build it as a delivery program—with an accountable owner, a defined structure and a timeline.
If an AI system harms an Australian tomorrow—misprices an insurance claim, embeds discrimination in a hiring decision or denies a benefit a person was entitled to—which regulator owns the failure? Who answers to Parliament?
Today, my honest answer is: it depends. The Office of the Australian Information Commissioner might see the privacy dimension. The ACCC might see the consumer harm. APRA might see the prudential exposure. Each would act within its mandate. None would own the system that caused the harm.
That is the real AI governance question facing Canberra. It is not whether to regulate artificial intelligence—Australia already does, in more places than the public debate acknowledges—but whether anyone owns the risks that sit above any single regulator’s mandate.
The policy balance is genuinely difficult. Move too slowly and Australians remain exposed to harms that can spread faster than traditional regulatory cycles respond. Move too aggressively and we risk constraining investment, adoption and domestic capability before the benefits are realised.
Australia’s position is distinctive. We are not the United States, with a frontier-model industrial base and a venture-scale technology ecosystem. Nor are we the European Union, with the market size to export regulatory norms globally. Australia is predominantly an adopter of AI built and governed elsewhere. Our strategic task is different: build a governance model that protects public trust, enables responsible adoption and gives government and industry an operating framework they can implement.
So the question I want to answer is: what kind of AI governance model does Australia need—and, just as importantly, how do we build it?
My argument in one line: Australia’s governance gap is ownership, not activity—and closing it is a delivery program, not a drafting exercise.
1. Australia Already Governs AI. It Just Does Not Have One Accountable Owner.
I often hear the argument that Australia has not begun regulating artificial intelligence. In my experience, that is simply not accurate.
Australia already manages many AI-related risks through privacy, consumer protection, competition, anti-discrimination, cyber security, workplace, prudential, health and online safety frameworks.[1] The current model is not a regulatory vacuum. It is a distributed system built on existing legal and institutional machinery, consistent with Australia’s preference for technology-neutral regulation: apply enduring legal principles to new technologies wherever possible rather than write a new statute for every technological wave.
The strength of this model lies in its specialist competence. The OAIC understands privacy and has issued guidance on developing generative AI models and deploying commercial AI products.[2] APRA has written to banks, insurers and superannuation trustees on AI risk governance and operational resilience.[3] The TGA regulates AI-enabled medical device software by intended purpose, not by technology.[4] The ACCC pursues misleading AI claims and market conduct. This expertise took decades to build and should not be displaced lightly.
The Australian Government launched the National AI Plan in December 2025.[5] It emphasises existing, largely technology-neutral legal frameworks, regulators’ expertise and voluntary guidance for responsible adoption. The September 2024 proposals paper, including its proposed definition of high-risk AI and ten proposed guardrails, remains an important reference point; the Plan retains an explicit safety goal alongside its growth agenda.[6]
Australia has moved furthest inside government. The Digital Transformation Agency’s updated policy for the responsible use of AI took effect on 15 December 2025 for non-corporate Commonwealth entities. It strengthens requirements for accountable officials, internal registers and impact assessments, with measures phasing in through 2026.[7] This matters because government does not simply deploy technology—it exercises public authority.
The accurate description of Australia today is this: there is no single AI Act, but there is an increasingly dense governance structure. There is plenty of activity. The open question is whether activity amounts to ownership.
2. Australia Has Plenty of AI Governance Activity. What It Lacks Is Ownership.
What are we actually trying to do here? Strip the debate back to first principles and the answer is short: when an AI system causes harm, someone identifiable must be accountable for detecting it, containing it and fixing it—and Australians must know whose door to knock on.
Measured against that test, the distributed model has a potential structural gap. Each regulator sees its slice; no single body owns risks that cross regulatory boundaries. When harm falls between mandates, accountability becomes difficult for the public to locate and for government to coordinate.
The exposure is not narrow. AI risk will emerge across health, finance, employment, education, digital platforms, cyber security, critical infrastructure, social services and democratic processes. A regulator will clearly own some risks. Others will sit awkwardly between mandates.
Australia has coordination structures—but coordination is not ownership. The Digital Platform Regulators Forum convenes the ACCC, ACMA, eSafety Commissioner and OAIC, and its principal output is working papers.[8] The DTA’s AI Review Committee, launched in June 2026, provides expert, non-binding advice to agencies on high-risk, sensitive, novel or complex use cases.[9] These mechanisms are valuable, but they do not create one accountable owner for risks that cross regulatory boundaries.
In practice, AI failures rarely arrive labelled by regulator. They appear as operational problems: an unexplained lending decision, a biased recruitment outcome, a disputed benefit assessment or an unexpected third-party model change. These become regulatory issues, but they begin as failures of ownership, controls and escalation.
There is also a strategic cost to leaving the gap open. If Canberra does not define Australia’s operating model, US technology providers, European compliance expectations, global cloud platforms and multinational procurement terms will increasingly set the practical rules of AI adoption. A slower domestic legislative path does not preserve maximum policy freedom. In practice, it transfers the pen. Australia is choosing whether to remain a downstream rule-taker or build a model of its own.
The technology does not change this. AI never absorbs accountability—humans do.
If Australia needs clearer ownership, can it simply adopt an overseas model? The answer is no. Washington and Brussels offer useful lessons, but neither provides a complete template.
3. Australia Should Learn from Washington and Brussels, Not Copy Them
The two most influential global models reflect different opening questions.
The European Union starts by asking how to protect citizens. Its AI Act is a comprehensive, risk-based framework: it prohibits certain uses and subjects high-risk systems to stringent obligations, while treating transparency and human oversight as design requirements rather than optional extras.[10] Its philosophy is explicit—public trust is a condition for sustainable adoption, not a by-product of it.
The United States starts by asking how to maintain leadership. Its model is decentralised: executive direction, voluntary standards, sector regulators, state initiatives and market-led implementation. Its philosophy is equally explicit—preserve speed, attract investment and maintain strategic advantage.
| European Union | United States |
|---|---|
| Protect citizens first | Promote innovation first |
| Comprehensive risk-based legislation | Decentralised, sector-led governance |
| Human rights, transparency and accountability | Competitiveness, investment and speed |
| Trust enables innovation | Innovation builds capability |
Neither approach is simply right or wrong, and neither should be imported wholesale. A purely American approach leaves too many harms unresolved for a country whose legal culture prizes fairness, consumer protection and institutional trust. A purely European approach imposes an administrative weight that smaller Australian firms cannot absorb. Australia needs the discipline of the first without its weight, and the dynamism of the second without its gaps.
4. AI Sovereignty Depends on Implementation, Not Legislative Independence
Canberra may already be running out of time to make that choice.
The Brussels Effect describes the European Union’s ability to shape global business practice beyond its borders. Because the EU is one of the world’s largest markets, companies frequently apply European standards globally rather than operate multiple compliance frameworks in parallel. GDPR is the proven example: organisations worldwide adopted GDPR-inspired privacy controls because maintaining several privacy regimes became more expensive than maintaining one.
The same dynamic is emerging for AI. The EU AI Act already applies to organisations that place AI systems into the European market, wherever they are headquartered.[10] For multinational technology providers, one global governance framework is simpler than dozens of regional variations. The consequence for Australia is straightforward. Even without equivalent domestic legislation, Australian organisations may operate under many EU AI Act principles because customers demand them, suppliers require them, technology providers embed them globally and international partners expect them.
This lands harder in Australia than in many economies because Australia is predominantly a consumer and adopter of AI designed, developed and governed offshore. The most influential AI platforms inside Australian organisations are not governed from Australia.
Sovereignty is more than the power to write domestic rules. It requires the capability to interpret, adapt and implement them in Australia’s national interest. Without that capability, Australia retains policy independence on paper while operationally absorbing standards designed in Brussels, Washington and Silicon Valley. Rule-making is a right. Rule-shaping is a capability.
Those international models clarify the trade-offs. Australia still needs an operating model designed for its own institutions and economy.
5. Australia Needs a Governance Spine, Not a Super-Regulator
If the gap is ownership, two remedies present themselves immediately. Both fail.
The first is a single AI mega-regulator that absorbs the expertise of privacy, competition, prudential, health, online safety and workplace regulators. That replaces coordination failure with competence failure. A new regulator built from scratch would take years to establish and far longer to acquire the domain depth APRA, the TGA and the OAIC already hold. The transition window would be the period of greatest risk.
The second is another voluntary coordination forum. Australia already has those, and their structural limit is clear: forums analyse problems without owning outcomes. Scaling the model reproduces the defect at greater expense—everyone contributes staff; nobody contributes accountability. In delivery terms, it is a steering committee without an empowered delivery owner. Its record would be measured in meetings, not outcomes.
I propose a model that combines three instincts: European-style safeguards for high-risk use, American-style encouragement of innovation and Australian-style delivery pragmatism. Its missing ingredient is a regulatory spine: a binding horizontal framework for high-risk and general-purpose AI, a clear owner for technical oversight of frontier AI models and a statutory process for escalating gaps between existing regulators.
A practical Australian model has three layers:
| Layer | Role in the model |
|---|---|
| Sector regulators | Retain domain enforcement across privacy, consumer, prudential, safety, health, cyber and sector-specific obligations: APRA on prudential model risk; the OAIC on privacy; the ACCC on consumer harm; and the TGA on medical devices. |
| Statutory AI coordination authority | Own risks that cross regulatory boundaries, set binding cross-sector standards, maintain a process for escalating regulatory gaps and report unresolved systemic risks to ministers, Parliament and the public. |
| Australian AI Safety Institute | Provide frontier-model capability, systemic-risk analysis, testing and evidence-based advice for the narrow technical domain no existing regulator owns, building on its current role within the Department of Industry.[11] |
Australia has already seen what happens when accountability is distributed but not owned. The Robodebt experience demonstrated how long a systemic failure can persist when responsibility is fragmented across institutions. AI creates the same governance risk at greater speed and scale. If an AI system harms a person, distorts a market or undermines trust in public decision-making, Australians should not have to determine which regulatory door to knock on.
AI governance is not only a legal problem. It is a delivery problem.
My experience with complex transformation programs has taught me that organisational design is the easy part. The difficult work is establishing authority, funding, decision rights and measurable delivery milestones.
Designing the model is only the first step. The harder task is building it.
6. Build AI Governance as a Delivery Program, Not Another Consultation
A practical route to building that spine would not start from a blank organisational chart or wait for consensus to emerge from forums. It would apply a machinery-of-government pattern Australia has used before: an interagency taskforce that designs and establishes a statutory authority from existing capability rather than recruiting from scratch.
Ministers would commission the taskforce with formal terms of reference: regulatory capability from the OAIC, ACCC, APRA, ASIC and eSafety Commissioner; technical depth from the AI Safety Institute; and a practical implementation model from the DTA—the only body in Australia currently running a mandatory AI governance regime of registers, impact assessments and accountable officials.[7] Critically, the terms would make participating agency heads jointly accountable for delivering the framework, organisational structure and timeline. That top-down accountability is what separates a delivery program from another coordination forum.
Parliament should establish a statutory AI authority. Secondments could provide its initial workforce before permanent transfers build enduring capability, supported by its own appropriation. The sequencing matters. Home agencies recall secondees during crises, and a body without its own funding line can hollow out within two budget cycles. The authority’s head should answer directly to Parliament for risks that cross regulatory boundaries and currently have no owner.
This is not an untested proposition. The government assembled the Australian Cyber Security Centre from capability across ASD, the AFP, ACIC and ASIO. The National Anti-Corruption Commission moved from implementation taskforce to operations in roughly eighteen months. The government established the eSafety Commissioner from capability within the ACMA. These examples suggest that an 18-to-24-month build is a plausible planning assumption with political will; it is not a forecast.
Any serious delivery program requires an accountable owner, a defined structure, a timeline and a go/no-go decision—not permanent consultation.
The Question Canberra Must Answer
An AI system harms an Australian tomorrow. Who owns the failure? Who contains the harm? Who answers to Parliament?
Today, the answer depends on the type of harm and which regulator’s mandate applies. That is not a regulatory vacuum, but it is an accountability gap.
Australia does not need to copy Brussels or Washington. Nor does it need a super-regulator that replaces decades of specialist expertise. It needs a governance spine: sector regulators retaining their mandates, a statutory authority owning risks that cross regulatory boundaries, and an AI Safety Institute providing technical oversight where existing capability falls short.
Building that model will require more than policy intent. It will require an accountable owner, clear decision rights, dedicated funding, measurable milestones and a firm implementation timeline.
Boards and executives should not wait for Canberra. They should identify who owns AI outcomes now, test whether escalation arrangements work and ensure every high-risk use has an accountable decision-maker.
After more than two decades working across governance, risk and transformation, I have learned that frameworks rarely fail because they are incomplete. They fail because nobody owns the outcome.
Australia’s AI governance test is therefore simple: when AI causes harm, accountability must have a name.
Sources
-
Department of Industry, Science and Resources, AI and Australian law, industry.gov.au/science-technology-and-innovation/technology/artificial-intelligence/ai-and-australian-law.
-
Office of the Australian Information Commissioner, Guidance on privacy and developing and training generative AI models; Guidance on privacy and the use of commercially available AI products, oaic.gov.au.
-
Australian Prudential Regulation Authority, Letter to industry on artificial intelligence, apra.gov.au/news-and-publications/apra-letter-industry-artificial-intelligence-ai.
-
Therapeutic Goods Administration, Artificial intelligence and medical device software regulation, tga.gov.au.
-
Department of Industry, Science and Resources, National AI Plan, launched December 2025, industry.gov.au/publications/national-ai-plan.
-
Department of Industry, Science and Resources, Mandatory guardrails for safe and responsible AI—proposals paper, 5 September 2024; Voluntary AI Safety Standard, industry.gov.au.
-
Digital Transformation Agency, AI Policy Update: Strengthening responsible use across government, 12 January 2026, dta.gov.au/articles/ai-policy-update-strengthening-responsible-use-across-government.
-
Australian Competition and Consumer Commission, Digital platform regulators release working papers on algorithms and AI, accc.gov.au.
-
Digital Transformation Agency, AI Review Committee, digital.gov.au/policy/ai/ai-review-committee; New AI Review Committee: Enhancing oversight of government AI use, 22 June 2026.
-
European Commission, Regulatory framework for AI, digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai.
-
Department of Industry, Science and Resources, Australia’s AI Safety Institute, industry.gov.au/science-technology-and-innovation/technology/artificial-intelligence/ai-safety-institute.