The 6 practices. On 21 October 2025 the National AI Centre published the Guidance for AI Adoption, which the department describes as evolving the 2024 Voluntary AI Safety Standard and its 10 guardrails into 6 essential practices. Both are still published on industry.gov.au, which is exactly why people are confused. Neither is law. There is no Australian AI Act in force. That is changing: the government signalled a standards-led framework in July 2026 and supporting legislation is expected in Parliament in early 2027, so build to the 6 practices now.

Why there appear to be two answers

The Voluntary AI Safety Standard landed in September 2024 with 10 guardrails covering organisations across the whole AI supply chain, developers and deployers alike. It was written in deliberately technical language so that an Australian business complying with it would also line up with international standards.

Thirteen months later the National AI Centre published the Guidance for AI Adoption. The standard's own page now carries a notice saying the new guidance "evolves the Voluntary AI Safety Standard".

Note the verb. Not replaces, not withdraws. The older standard is still sitting there with its 10 guardrails intact, which is why half the advisory market is still quoting them and the other half has moved on. If someone is selling you a "guardrails gap assessment" in late 2026, they are working from the previous version.

The practical answer for an Australian business: the 6 practices are the current expression of the same thinking, they are shorter, and they are what the government points you at now.

The 6 essential practices

Straight from the guidance, in its own words:

Practice

What it is actually asking Smallest version that counts
1. Decide who is accountable A named person accountable for AI use, including where contractors and third party systems are involved One name against each AI system, written down, who knows they own it
2. Understand impacts and plan accordingly Assess what a given use could do to people before you turn it on A short written impact note per use case, not per tool
3. Measure and manage risks: implement AI-specific risk management AI risks that your normal risk register does not catch Add AI cases to the existing register rather than starting a parallel one
4. Share essential information Tell people what they need to know, inside and outside the business Disclosure to users, and something honest in your privacy policy
5. Test and monitor Check it works before launch and keep checking after A test set you rerun, plus logging you actually read
6. Maintain human control A person can intervene, override and stop it A documented override path that someone has used at least once

Two structural points the guidance makes that are worth more than the list itself.

Some of this is organisation wide and some is per system. Governance frameworks, clear roles, an AI register and supply chain accountability apply across the business. Impact, testing and oversight apply to each individual use.

The same tool creates different risks depending on use. The guidance's own example: an internal chatbot carries different risk from AI used in hiring or customer decisions. So a register of tools tells you very little. A register of uses tells you what you need.

That is the same mistake we described in what you have to disclose from 10 December 2026. Companies inventory their software and think they have inventoried their risk.

There are two versions of the guidance, and most people need the first

The Guidance for AI Adoption comes in two parts, and picking the wrong one is the fastest way to waste a quarter.

Foundations is for organisations earlier in their AI use. If you are running a handful of assistants, some workflow automation and a chatbot, this is you.

Implementation guidance is for teams that build or customise AI systems, use AI in more complex ways, manage higher risk use cases, or need stronger controls and oversight. It is considerably more demanding. Practice 1 alone asks you to assign and document accountability for the operation of an AI management system, for the development and deployment of every AI system, for oversight of third party AI, for testing across the organisation, for handling requests for redress, and for continuous improvement of the whole thing.

If you buy AI inside HubSpot, Microsoft or Google and configure it, you are a deployer, and Foundations is the right document. If you are building agents that touch customer data and make calls, you are in implementation territory whether you like the paperwork or not.

The part that is actually mandatory

Here is what gets lost in the framework argument. Voluntary means voluntary. Nobody will fine you for skipping the 6 practices.

Meanwhile, from 10 December 2026, the Privacy Act requires you to disclose in your privacy policy the kinds of automated decisions you make about people where those decisions could significantly affect their rights or interests. That is not guidance. That is APP 1, and the OAIC enforces it.

So if you have limited time this quarter, the order is: work out what automated decisions you make about people, get your privacy policy right for December, and use the 6 practices as the structure for doing it properly rather than as a separate project.

The frameworks are also doing quiet commercial work. Enterprise and government procurement questionnaires have started asking which one you follow. For where Australian mid-market adoption actually sits, we pulled the numbers separately. Being able to answer with a named framework, a register and an accountable person is increasingly the difference between shortlisted and not.

What is coming, and why that changes the calculation

Working to voluntary guidance is easy to defer. It is harder to defer once you know the direction.

On 15 July 2026 the Prime Minister used a keynote to signal a shift, framing a coordinated, standards-led framework for AI covering workers, creators and national security. Commentary since has been consistent that enforceable AI regulation is back on the agenda, with supporting legislation for national AI standards expected before Parliament in early 2027.

On 20 August 2026 both houses appointed a Joint Select Committee on Artificial Intelligence to examine the risks and opportunities of AI and review whether existing laws are adequate, including copyright and intellectual property. It is due to report on 30 November 2026.

If you are starting from nothing, the fastest useful artefact is a one page AI policy, which covers practices 1 and 4 between them.

So the honest read as at September 2026: nothing here is binding, and something probably will be within about eighteen months. An organisation that builds an AI register, names accountable people and documents its testing this year is not doing compliance theatre. It is doing the work early, in a year when it is cheap and nobody is checking.

What we do on client builds

  • A register of uses, not tools. One row per use case, with the accountable name, what personal information it touches, and whether a human decision sits downstream. It usually fits on one page and it is the artefact every other question gets answered from.
  • Foundations by default. We only push a client to the implementation guidance when they are genuinely building or customising, because the heavier version consumes attention that is better spent on the December deadline.
  • The override path gets tested. A human control that has never been exercised is a claim, not a control. We make someone use it before launch.
  • We keep the records the guidance asks for. Governance decisions, tests, incidents and monitoring, in the repo next to the build. Not in a document nobody opens.

The short version

Use the 6 essential practices from the Guidance for AI Adoption. The 10 guardrails are the earlier version of the same idea and you do not need to work to both. Start with Foundations unless you build or customise AI. Build a register of uses rather than tools, put one name against each, and make sure someone can turn it off.

Then remember the only hard date on the board is 10 December 2026, and it is a privacy obligation rather than an AI framework.

Frequently asked questions

Is the Voluntary AI Safety Standard still in force? It is still published, and the department describes the Guidance for AI Adoption as evolving it. Neither document is legally binding. For current work, use the 6 practices.

Do we have to comply with any Australian AI law right now? There is no Australian AI Act in force. Existing law still applies to AI, though, which is the part people miss: privacy, consumer law, anti-discrimination, work health and safety and sector rules all bite regardless. The automated decision-making transparency obligation in the Privacy Act commences 10 December 2026, and legislation for national AI standards is expected before Parliament in early 2027.

Which one do procurement teams ask about? Increasingly the 6 practices, though plenty of questionnaires still name the 10 guardrails because they were written earlier. Either way, what gets checked is whether you have an accountable person, a register and evidence of testing.

We are an APRA regulated entity. Does this cover us? Not on its own. CPS 230 treats AI vendors as material service providers and carries its own obligations with real deadlines. Voluntary guidance does not satisfy a prudential standard.

Sources


Most of the AI governance work we see is either far heavier than the business needs or missing the one obligation that has a date attached. If you are not sure which version applies to you, give us a shout and tell us what's broken.