On the fifteenth of July the Prime Minister ended a two-year guessing game: Australia will legislate national Standards for AI, coordinated by a new Office of AI inside the Department of the Prime Minister and Cabinet. National Cabinet considers the design next month, draft standards and guidance are expected late this year, legislation goes to Parliament in early 2027, and enforcement is staged from there. After the National AI Plan's lighter touch, the direction has reversed, and it has reversed with machinery attached.
The announced pillars are instructive. Hard infrastructure rules for large AI data centres: their power, their grid connection, their water. Consent and compensation rules for training on Australian creative work. And, for the broad economy, the signalled shape is governance: a current register of the AI in use across a business and the data it touches, named accountable owners, impact assessments, audit trails, incident reporting. The exact perimeter will move through consultation. The grammar of it, registers, owners, evidence, is not going to move, because it is the same grammar every mature governance regime converges on.
When the regulator asks how your AI is governed, the answer should already be a file, not a scramble.
What changes now
The honest answer for most organisations: the obligations were already forming, and this announcement converts "eventually" into a date. Existing law has applied to AI use all along. The voluntary standard and the six essential practices sketched the expected shape. ISO 42001 made it certifiable. What early 2027 adds is compulsion, and staged enforcement through 2028 means the comfortable-sounding runway is shorter than it looks: registers take a quarter to build honestly, remediation takes longer, and evidence, by definition, cannot be backdated.
The head start that costs nothing
Everything worth doing now is worth doing even if the final Standards land narrower than signalled. Inventory the AI in the business, including what arrived embedded in other software. Classify each use by consequence to real people. Put a named owner against every system. Wire the evidence: what was tested, what was decided, what went wrong and what was done about it. Organisations that run this way negotiate better with vendors, answer customers faster and sleep better under the laws that already apply. The Standards simply make the same work mandatory, on someone else's schedule.
We built our own platforms under these disciplines because we wanted them, not because Canberra asked: deterministic calculation behind every number, evaluation gates before every release, audit trails as a matter of course. That experience is why our governance work is engineering first: the register, the gap assessment against the Standards trajectory and ISO 42001, the evidence pack a board can sign against, and the standing assurance that keeps it current while the law finalises.
What to do about it
- Put AI governance on the board agenda this quarter, with a named executive owner.
- Build the register and risk classification now; they anchor everything the Standards will ask.
- Run a gap assessment against the signalled shape and ISO 42001, and sequence remediation by exposure.
- Start the evidence file today. In 2027, its date of creation will itself be evidence.
Mandatory was always the destination; it now has a timetable. The organisations that will find 2027 uneventful are the ones acting like it is already here.