The Government's National AI Plan landed this month, and the headline most executives took from it was relief: no Australian AI Act, no economy-wide mandatory guardrails, existing regulators to carry the load. The proposed mandatory guardrails for high-risk AI, consulted on through 2024, have been set aside in favour of a technology-neutral approach and a new AI Safety Institute to test systems and find the genuine gaps.

Relief is the wrong reading. What the Plan actually says is that your AI use is governed by every law you were already subject to, applied by regulators who are getting better at seeing AI inside ordinary conduct. Privacy law governs what your systems ingest and infer. Consumer law governs what your automated decisions and marketing claims do to customers. Anti-discrimination law does not care whether the bias came from a person or a model. Directors' duties extend to understanding material risks, and AI in your critical processes is exactly that.

The absence of an AI Act is not the absence of obligation. It is the absence of a checklist.

Harder, not easier

In some ways a single AI law would have been more comfortable: one scope, one set of definitions, one compliance program. Technology-neutral regulation is harder to satisfy because it requires judgement. You have to look at each use of AI in the business and ask which existing duties it touches, with no bright-line list to hide behind. That analysis does not happen by itself, and "the vendor said it was fine" has never impressed a regulator.

What sensible organisations are doing this quarter

The organisations we rate are treating this window as preparation time. They are building a register of every AI system in use, including the ones that arrived embedded in office software, with the data each touches and a named owner. They are classifying uses by consequence: what happens to a real person if this is wrong. And they are keeping evidence, because the voluntary standard of today has a way of becoming the expectation of tomorrow, and the AI Safety Institute's gap analysis will inform what gets regulated next.

None of this is wasted if the rules stay light. A register, a risk view and an evidence trail make your AI use cheaper to manage and easier to defend under the laws that already apply. If the rules harden, and the political signal is that they will, you are simply early.

What to do about it

  • Inventory every AI system in use, official and unofficial, with data flows and a named owner.
  • Risk-rate each use by consequence to real people, not by how impressive the technology is.
  • Map each significant use against privacy, consumer and discrimination duties you already carry.
  • Start an evidence file now: decisions, testing, incidents. Retrofitting one later is miserable.

Our AI governance practice builds exactly these foundations. The law is still moving; the direction has not been ambiguous for a year.