All writing
30 min read

AI Reporting Obligations for Australian Regulated Industries: The Verified Rules, Dates and Sources to 2027

Every current and confirmed AI reporting rule for Australian regulated industries, sector by sector, with dates and links to the primary regulator source.

KP
Managing Director and co-founder

Every conversation about AI regulation in Australia is happening under the same fog. Some rules are already law. Some are voluntary guidance. Some were proposed and shelved. Some sit inside existing prudential and privacy regimes and only look new because AI has amplified them. The result is that most regulated entities are unsure what they actually have to report, to whom, and by when.

This article is the answer. Every rule, deadline and threshold below is traceable to a primary source. Nothing has been included that could not be verified against a regulator or department publication. Where a proposal was withdrawn, that is stated as well. If your legal team wants to check any claim, follow the linked source directly.

The direct answer for boards and executives

Australia has no dedicated AI statute in force. AI-related reporting obligations are being delivered through existing regulators applying existing law with new expectations, plus a small number of new specific instruments passed since 2024. The rules a regulated Australian entity has to attend to right now sit across nine tracks.

APRA regulated banks, insurers and superannuation trustees are governed by APRA's Letter to Industry on Artificial Intelligence dated 30 April 2026 and the operating standards it flags (CPS 230, CPS 234, CPG 235, CPS 510). AFS licensees and market participants are governed by ASIC Report 798 "Beware the Gap" and ongoing ASIC statements on AI and cyber. Any APP entity using personal information in automated decisions gets a new transparency obligation from 10 December 2026. AI as software as a medical device is regulated by the TGA under a technology neutral framework, updated in February 2026. All 94 non-corporate Commonwealth entities have mandatory AI use case registers, training and impact assessments phasing in through 2026 under the DTA Policy for the Responsible Use of AI in Government version 2.0. Critical infrastructure operators report cyber incidents under SOCI Act 12 hour and 72 hour timeframes. Ransomware payments are reportable within 72 hours under the Cyber Security Act 2024. Banks, telcos and designated digital platforms are subject to the Scams Prevention Framework Act 2025. Registered health practitioners follow AHPRA's AI professional obligations guidance issued in August 2024.

The rest of this article is the sector by sector detail, in the order most boards will need it.

Financial services: APRA's operating standards apply, and the AI letter tightens them

APRA does not regulate AI through a dedicated prudential standard. It regulates AI use inside its existing operational risk, information security and outsourcing framework, and reinforced its position through a formal industry letter this year.

On 30 April 2026 APRA issued its Letter to Industry on Artificial Intelligence (AI), drawn from a targeted supervisory engagement with selected large banks, insurers and superannuation trustees. In the accompanying statement, APRA called for a "step-change in AI-related risk management and governance" and warned that current practice was "not sufficiently keeping pace with the scale, speed and complexity of AI adoption". The letter sets out expectations across four observation areas: cyber and information security, governance, supplier risk, and change management and assurance.

The operative point for regulated entities is that AI is not treated as a separate regime. As the Clayton Utz analysis of the letter notes, "while AI is not subject to separate governance requirements, IT services leveraging AI need to be managed in accordance with existing prudential authorities such as CPS 230 and CPS 234". The relevant instruments are:

  • CPS 230 Operational Risk Management, which applies to APRA regulated entities in respect of contracted service providers from 1 July 2026, with pre-existing material service provider contracts required to comply by the earlier of next renewal or 1 July 2026.
  • CPS 234 Information Security, which governs cyber controls and incident notification, and applies to AI dependent systems in the same way as any other.
  • CPG 235 Managing Data Risk, which frames data governance expectations including for training and inference data.
  • CPS 510 Governance, which underpins board accountability for the above.

APRA's supplier risk expectation specifically requires entities to "map and maintain visibility over the full AI supply chain, including material, third-party and fourth-party dependencies". Boards are also expected to move past reliance on vendor presentations and to interrogate risks such as unpredictable model behaviour and the impact on critical operations.

Financial services and listed companies: ASIC's position from REP 798 forward

ASIC's foundational position on AI in financial services is set out in Report 798 "Beware the Gap: Governance Arrangements in the Face of AI Innovation", published on 29 October 2024. The accompanying media release 24-238MR confirms ASIC reviewed AI use by 23 AFS and credit licensees across retail banking, credit, general and life insurance and financial advice, analysing 624 use cases and warning that "licensees are adopting AI faster than they are updating their risk and compliance frameworks".

REP 798 does not create a new reporting rule. It sets the expectation used in subsequent supervisory work. That work has continued through 2026. ASIC's Corporate Finance Update Issue 29, June 2026 documents ongoing focus on disclosure quality for AI risks, and ASIC issued an open letter to licensees on 8 May 2026 calling for urgent strengthening of cyber resilience as frontier AI models intensify the cyber risk environment.

For listed entities, AI risk sits inside the existing continuous disclosure regime. There is no separate ASIC filing for AI incidents. Where AI use creates a material effect on share price under ASX Listing Rule 3.1, disclosure obligations attach in the same way as any other operational matter. Directors' duties under sections 180 to 184 of the Corporations Act 2001 also apply to AI governance decisions, which ASIC has been explicit about.

Every APP entity: the Automated Decision Making transparency rule from 10 December 2026

The most concrete new obligation for the widest set of Australian organisations is the automated decision making (ADM) transparency requirement introduced by the Privacy and Other Legislation Amendment Act 2024. New APP 1.7, 1.8 and 1.9 take effect on 10 December 2026.

From that date, an APP entity that uses personal information in a "substantially automated" decision that "could reasonably be expected to significantly affect the rights or interests" of an individual must include specific content in its privacy policy. That content covers the kinds of personal information used, the kinds of decisions made, and how the decisions are made. The obligation is a disclosure requirement, not a prohibition. It applies prospectively to any decision made on or after 10 December 2026, regardless of when the underlying system was deployed.

The OAIC has been publishing supporting guidance. On 21 October 2024, the OAIC released Guidance on privacy and the use of commercially available AI products and Guidance on privacy and developing and training generative AI models. Both guidances reinforce that the Australian Privacy Principles already apply to any use of personal information with AI systems. The OAIC has separately opened Consultation on Guidance for Transparency in Automated Decision Making ahead of the December 2026 commencement.

Under APP 1, entities have long been required to have a clearly expressed and up to date privacy policy. The new obligation extends that policy to cover ADM. It does not require reporting to the OAIC in the ordinary course, but it does create a public transparency artefact that regulators, litigants and journalists will read against actual practice.

Healthcare: the TGA regulates AI as software as a medical device, and AHPRA regulates the practitioner

Australia's healthcare AI reporting stack has two layers.

The Therapeutic Goods Administration regulates AI when it forms software as a medical device (SaMD). The TGA's Artificial Intelligence (AI) and medical device software regulation page confirms Australia's technology neutral position: regulation is triggered by the manufacturer's intended purpose, not by the presence of AI. Software intended for diagnosis, monitoring or treatment must be included in the Australian Register of Therapeutic Goods (ARTG) before it can be supplied, and manufacturers must assess intended purpose, risk class, and compliance with international standards including IEC 62304 and ISO 14971. The February 2026 update clarified when clinical decision support, chatbots and LLM based tools fall inside the medical device perimeter. SaMD is one of 12 priority focus areas for TGA compliance and enforcement activity in 2026 to 2027.

At the practitioner layer, AHPRA issued Meeting your professional obligations when using Artificial Intelligence in healthcare in August 2024. The guidance applies to all registered health practitioners, including medical practitioners, dentists, allied health, pharmacists and psychologists. AHPRA's position is that "regardless of what technology is used in providing healthcare the practitioner remains responsible for delivering safe and quality care". Practitioners must apply human judgement to AI output, understand the tools they use, inform patients when AI is involved in their care, and obtain informed consent before any AI tool processes a patient's personal information. The guidance does not create separate AHPRA reporting, but breaches feed the existing notifications regime under the Health Practitioner Regulation National Law.

The Aged Care Act 2024 commenced on 1 November 2025 and does not itself contain AI-specific obligations. Aged care providers using AI in decisions that significantly affect residents' rights or interests will be captured by the OAIC ADM rule described above.

Government agencies: the DTA Policy for Responsible Use of AI in Government is now mandatory in phases

Every non-corporate Commonwealth entity is subject to the Policy for the responsible use of AI in government, administered by the Digital Transformation Agency. This is the first set of compulsory, enforceable AI governance requirements applied consistently across a large group of Australian organisations.

Version 1.1 commenced on 1 September 2024 and required agencies to designate AI Accountable Officials within 90 days (by 30 November 2024) and publish AI transparency statements within six months (by 28 February 2025).

Version 2.0 came into effect on 15 December 2025, tightening the requirements. Under the updated policy, the mandatory timetable is:

  • From 15 June 2026: every non-corporate Commonwealth entity must maintain an internal AI use case register with a named accountable owner for each use case, and every APS staff member must complete foundational AI training.
  • From 15 December 2026: agencies must complete an AI Impact Assessment before deploying any in-scope AI system, implement formal approval and oversight processes, and report AI incidents.

The AI Impact Assessment tool and updated procurement guidance have been published by the DTA. The policy applies to 94 non-corporate Commonwealth entities and, indirectly, to their contracted service providers.

Critical infrastructure: 12 hours and 72 hours under SOCI

Operators of a critical infrastructure asset are subject to the Security of Critical Infrastructure Act 2018, with mandatory cyber security incident reporting timeframes documented by the Cyber and Infrastructure Security Centre in the SOCI obligations factsheet.

The rule is:

  • A cyber security incident having a "significant impact" on the availability of a critical infrastructure asset must be reported to the Australian Signals Directorate's Cyber Security Centre within 12 hours of the responsible entity becoming aware.
  • A cyber security incident having a "relevant impact" must be reported within 72 hours.

These timelines run from awareness, not from confirmation, and they apply in parallel with any other reporting obligations under the Privacy Act's Notifiable Data Breaches scheme or the ASX continuous disclosure regime. Where AI is a component of the affected asset or of the attack path, no additional SOCI notification exists; the rules apply as normal. Responsible entities also operate under a Critical Infrastructure Risk Management Program (CIRMP) with defined uplift categories including cyber and information security.

Ransomware payments: 72 hours under the Cyber Security Act 2024

Australia's Cyber Security Act 2024 introduced a mandatory ransomware payment reporting obligation. The reporting rule applies to businesses carrying on a business in Australia with annual turnover of AUD 3 million or more, plus every entity responsible for a critical infrastructure asset regardless of turnover.

Under the Home Affairs factsheet on ransomware payment reporting, a reporting business entity must file within 72 hours of making the payment or becoming aware that a payment has been made, via cyber.gov.au. The reporting obligation commenced on 30 May 2025, with an education first phase to 31 December 2025 and civil penalty enforcement of up to AUD 19,800 applying from 2026 for non-reporting.

The reports themselves attract limited-use protections. Content cannot be used to prosecute the reporting entity for the payment itself, though other regulatory and criminal exposures remain.

Banks, telcos and designated digital platforms: the Scams Prevention Framework Act 2025

The Scams Prevention Framework Act 2025 commenced on 21 February 2025. It creates enforceable obligations on regulated entities to take reasonable steps to prevent, detect, disrupt and respond to scams. The first designated sectors are banks (ADIs), telecommunications providers (carriers and CSPs), and digital platforms initially covering social media, instant messaging and search.

The confirmed dates are:

Maximum civil penalties reach AUD 50 million per contravention. ASIC oversees the banking sector, ACMA oversees telcos, and the ACCC is the overarching regulator.

The SPF does not prescribe specific AI controls, but the "reasonable steps" test will almost certainly require investment in synthetic content detection given the growth of AI generated impersonation scams. ACMA has published three occasional papers on AI in telecommunications, media and interactive gambling on 21 April 2026 signalling the AI-related use cases and risks it is monitoring under its existing remit.

The voluntary layer: AI Safety Standard and Assurance Framework

Two voluntary instruments frame board expectations even where they do not create legal obligations.

The Voluntary AI Safety Standard was released by the Department of Industry, Science and Resources on 5 September 2024. It comprises 10 guardrails covering accountability, risk management, data governance, testing, human oversight, user transparency, contestability, supply chain transparency and record keeping. The standard does not create new legal obligations, but it sets the reference practice most Australian regulators will now measure AI governance against.

The DTA has also published an AI Assurance Framework and supporting guidance piloted from September 2024 to help agencies assess the impact of AI use cases against Australia's AI Ethics Principles. Private sector organisations can adopt the same framework where useful, though it is only mandatory for the Commonwealth entities covered by the DTA policy.

What was proposed and did not become law

Boards frequently ask whether Australia has mandatory guardrails for high-risk AI. As of August 2026 the answer is no.

In September 2024, Home Affairs and the Department of Industry ran the Introducing mandatory guardrails for AI in high-risk settings consultation proposing 10 mandatory guardrails aligned with the voluntary standard, with conformity assessments and public certification. That proposal did not proceed as originally drafted. The government's subsequent National AI Plan, released on 2 December 2025, redirected the approach toward using existing laws (Privacy Act, Consumer Law, financial services regulation), plus a non-binding AI Safety Institute and the coordinating Office of AI.

Two AI-specific federal instruments have passed: the deepfake sexual material offence under the Criminal Code Amendment (Deepfake Sexual Material) Act 2024, and the ADM transparency amendments to the Privacy Act that take effect on 10 December 2026. Everything else is either existing law being applied to AI use, sector guidance, or voluntary standards.

What is coming: Office of AI, National Cabinet, and legislation in early 2027

The forward calendar is defined by three items.

The Office of AI was established on 15 July 2026 inside the Department of the Prime Minister and Cabinet. It coordinates AI policy across portfolios, including Treasury, Industry, Home Affairs, Attorney-General and Digital.

The AI Safety Institute was announced on 25 November 2025 with roll out in early 2026, funded at just under AUD 30 million from the National AI Plan. It coordinates with regulators, joins the International Network of AI Safety Institutes, and supports risk based regulatory responses.

National Cabinet is scheduled to consider the framework in August 2026 and legislation for mandatory Australian Standards for AI, initially targeting large scale AI data centres, is expected to be introduced to Parliament in early 2027. The voluntary National Data Centre and AI Infrastructure Expectations were published on 23 March 2026 and sit ahead of the legislative pathway.

The board readiness map

A single artefact organises this well. Every regulated entity should hold a current one page map that answers, for each of the nine tracks above, who owns the obligation internally, what the deadline is, and what the current state of readiness is.

The rows are: APRA (if applicable), ASIC (if applicable), OAIC ADM by 10 December 2026, TGA (if a SaMD manufacturer), AHPRA (if a healthcare organisation), DTA (if a Commonwealth entity or supplying one), SOCI (if a responsible entity for a critical infrastructure asset), Cyber Security Act ransomware payment reporting, and SPF (if a bank, telco or digital platform).

The columns are: rule reference, responsible internal owner, next milestone date, current readiness state, and evidence artefact. Boards that hold this artefact live and dated do not need to redo the exercise every time a regulator sends a letter.

Frequently asked questions

What AI reporting obligations do Australian regulated industries currently have?

There is no single Australian AI reporting regime. Obligations arrive via existing regulators applying existing law. The current confirmed set for regulated entities covers APRA's operational risk, information security and outsourcing standards (with the 30 April 2026 AI letter framing expectations), ASIC's existing licensee obligations and continuous disclosure, the OAIC's ADM transparency rule from 10 December 2026, the TGA's medical device framework for AI in SaMD, AHPRA's August 2024 practitioner guidance, the DTA policy for Commonwealth agencies, SOCI cyber incident reporting, Cyber Security Act ransomware reporting, and the Scams Prevention Framework for banks, telcos and designated digital platforms.

When does APRA require AI risk reporting?

APRA does not require separate AI risk reporting. Its expectations are set out in the 30 April 2026 industry letter, and it examines AI risk under the operational risk (CPS 230, which applies to contracted service providers from 1 July 2026), information security (CPS 234), data risk (CPG 235) and governance (CPS 510) standards.

What does ASIC expect on AI governance for AFS licensees?

The primary source is Report 798 "Beware the Gap", published on 29 October 2024. ASIC expects licensees to update governance and risk management frameworks to address algorithmic bias, transparency, data quality and ethics, and to close the gap between AI adoption speed and control maturity. ASIC has continued the message through 2026, including its 8 May 2026 cyber resilience letter to licensees and market participants.

When does the Australian Privacy Act automated decision making rule start?

The transparency obligation under new APP 1.7, 1.8 and 1.9 takes effect on 10 December 2026. From that date, APP entities that use personal information in substantially automated decisions that could reasonably be expected to significantly affect an individual's rights or interests must disclose specified information in their privacy policy.

Does the TGA regulate AI as a medical device in Australia?

Yes, when the AI is used for a purpose that would qualify the software as a medical device. The framework is technology neutral: regulation is triggered by intended purpose, not by the presence of AI. The TGA guidance page and the February 2026 update confirm the position. Software intended for diagnosis, monitoring or treatment must be included in the ARTG.

What are the mandatory AI requirements for Australian government agencies?

Under the DTA Policy for the responsible use of AI in government version 2.0, all 94 non-corporate Commonwealth entities must, from 15 June 2026, maintain an AI use case register with a named accountable owner and complete foundational staff AI training. From 15 December 2026, agencies must also complete an AI Impact Assessment before deploying any in-scope AI system, apply formal approval and oversight processes, and report AI incidents. Accountable AI Officials were required to be named by 30 November 2024 and AI transparency statements published by 28 February 2025.

How quickly must a critical infrastructure operator report a cyber incident?

Under the SOCI obligations factsheet, an incident with significant impact must be reported to the Australian Signals Directorate within 12 hours of awareness, and an incident with relevant impact must be reported within 72 hours. These timelines run from awareness, not confirmation.

When do banks and telcos have to comply with the Scams Prevention Framework?

Sector obligations for banks, telcos and designated digital platforms are targeted from 1 July 2026, with the SPF Rules commencing on 1 September 2026 and AFCA scam complaint handling from 1 January 2027. Maximum penalties are AUD 50 million per contravention. Source: Gilbert + Tobin analysis of the legislated framework.

What is the Voluntary AI Safety Standard in Australia?

The Voluntary AI Safety Standard, published by the Department of Industry, Science and Resources on 5 September 2024, is a set of 10 voluntary guardrails covering accountability, risk management, data governance, testing, human oversight, user transparency, contestability, supply chain transparency and record keeping. It does not create legal obligations, but it is the reference practice most Australian regulators will use.

Did Australia pass mandatory AI guardrails for high-risk settings?

No. The September 2024 consultation on introducing mandatory guardrails for AI in high-risk settings proposed 10 mandatory guardrails, but that proposal did not proceed as drafted. The government's National AI Plan of 2 December 2025 instead directs enforcement through existing laws, supported by the AI Safety Institute and the Office of AI, with data centre standards to be legislated in early 2027.

What ransomware payment reports are mandatory in Australia?

Under the Cyber Security Act 2024, businesses with annual turnover of AUD 3 million or more, plus every entity responsible for a critical infrastructure asset, must report ransomware payments within 72 hours of making the payment or becoming aware that a payment has been made. The reporting obligation commenced on 30 May 2025 with civil penalties of up to AUD 19,800 for non-reporting.

Sources

Every claim in the article traces to one of the following. Regulator and department sources are marked as primary. Legal analysis and factsheets are marked as secondary, and were used only where the underlying rule is quoted or cited from a primary regulator source.

Primary sources:

Secondary sources (used to quote or contextualise primary rules):

Where a fact could not be verified against a primary or credible secondary source, it has been left out. If any date, threshold or wording above should update as regulators publish further guidance, follow the linked source directly.

Keep reading

More writing.

A few more pieces along the same thread. See the full index for everything.

Subscribe

One short note, as it happens.

The writing above, delivered to your inbox when we publish it. No other emails, no tracking pixels, and you can leave in a click.