Australia has no single AI statute. What it has for businesses deploying AI is a mix of existing law (privacy, consumer, discrimination, sector rules such as APRA’s operational risk requirements for financial entities) and voluntary guidance. The most useful piece of guidance for a practical deployment is the Voluntary AI Safety Standard published by the Department of Industry, Science and Resources in 2024, which sets out ten guardrails. They are written for AI generally, but they map cleanly onto agents, which are the case where the stakes of getting them wrong are highest.
Here is each guardrail against what it looks like when an agent is actually running. The wording below is our paraphrase, so read the published text for the authoritative version.
1. Accountability and governance. A named owner, an AI policy and a strategy for where AI is used. For agents: each one has an accountable person, and the policy answers who can approve a new one. See who should own AI agent policy.
2. Risk management. Identify and manage risks across the life of the system. For agents: a risk assessment per use case that includes what happens when the agent is confidently wrong, not a generic AI risk register.
3. Data governance and protection. Quality, provenance and security of data. For agents: the agent is grounded in your own sources, those sources are owned and kept current, and access to personal or confidential data is scoped to the task.
4. Testing and monitoring. Test before deployment, monitor after. For agents: test against the awkward edge cases, not the happy path, and watch behaviour in production because agents drift as the systems and documents around them change.
5. Human oversight. Meaningful human control. For agents: approval gates at defined thresholds, with a named approver and the agent’s reasoning attached. “Meaningful” is the word that fails most often: a rubber-stamp queue is not oversight. See approval gates.
6. Inform end-users. Tell people when AI is involved in decisions or interactions. For agents: customers and staff know when an agent is acting, and what it does.
7. Challenge. A way for affected people to contest outcomes. For agents: a person can ask why a decision was made and get an answer that exists before they ask, which depends on records made at the time. See audit trails before autonomy.
8. Transparency across the supply chain. Understand and share information about the models, tools and vendors involved. For agents: you know which model, which vendor and which data flows are inside each workflow, including where data is processed. Keeping execution inside your own infrastructure simplifies this.
9. Records. Keep the documentation that lets others assess your compliance. For agents: an audit trail of actions, authority and outcomes, kept for a stated period, plus the agent register. The difference between logs and a real trail is covered in logs versus audit trail.
10. Stakeholder engagement. Consider the people affected, including safety, fairness and diversity. For agents: the people whose work or outcomes an agent changes are consulted before it launches, not told afterwards.
What the guardrails don’t tell you
They don’t tell you how to build any of this, and being voluntary they don’t tell you what’s required of you specifically. Some of the other pieces are binding: the Privacy Act’s automated decision-making transparency rules are scheduled for December 2026, and regulated sectors have their own obligations. The guardrails are best used as a yardstick: a way to check that a deployment has the basics, and a common vocabulary when a customer or board asks how you govern AI.
Using it in practice
The quick test is to pick one live agent and score yourself against the ten, honestly, with evidence rather than intent. Most businesses find strong coverage on data and security, thin coverage on oversight, challenge and records, because those only exist if they were designed in.
If you’d like help with that, the readiness check takes two minutes, the Security and Governance Audit does it against your real systems, and you can book a free intro call to talk through where you’d begin.
General information, not legal advice. Confirm against the current published standard and your own obligations.