Guardrails & Gap Analyses

An assessment of Australia’s approach to AI regulation

In December 2025, the Australian Government announced it would not proceed with mandatory guardrails for artificial intelligence (AI) and instead rely on existing laws to address AI harms. This decision was informed by a ‘gap analysis’ of where laws and regulations needed to be reformed in light of the impact of AI. It was also premised on extensive work being undertaken across the Commonwealth to review and reform regulatory frameworks. 

Global Shield Australia has produced the first independent assessment of that December 2025 decision and catalogue of work underway to uplift Australia’s regulatory response to AI risk. 

The Guardrails & Gap Analyses report is informed by freedom of information requests to forty Commonwealth agencies and extensive desktop research that identified 50 separate processes considering the impact of AI on Australia’s regulatory environment. 

Our report finds that work on the impact of AI is underway across almost all Commonwealth portfolios. However, the depth and quality of this work vary considerably. Significant issues raised by experts remain unaddressed, and measures to prevent serious and catastrophic threats require greater prioritisation and urgency. Overall, in the absence of AI-specific regulation, the report recommends that greater coordination, transparency, and urgency of regulatory reforms are needed for Australia to keep pace with the speed of AI’s development. It also finds there remains a strong case for AI-specific legislation, if Australia aims to lead on responsible, safe and secure AI.  

Global Shield Australia will be hosting a webinar on 3 September at 12 noon (AEST) to discuss our findings and recommendations. Register your attendance here.

Read our full report here:

Key Findings

The report finds that:

  1. The analysis undertaken in 2025 provided a valuable starting point for understanding Australia’s exposure to AI risk, but its focus on actualised harms was overly narrow.
  2. There is work underway in most Commonwealth portfolios to review regulatory frameworks in light of the impact of AI, but this work would benefit from clearer prioritisation and improved visibility of harms and ‘near misses’. 
  3. Clear central coordination is needed to ensure that reviews and reforms are not inconsistent or duplicative.
  4. Transparency associated with AI-related regulatory processes has been mixed, limiting public engagement and reducing trust. 
  5. Several previous reviews of regulatory frameworks have identified the value of economy-wide AI regulation. 
  6. Increased funding and urgency are needed for key review and reform processes.

Recommendations

The report recommends that the Government:

Recommendation 1: The Office of AI should commission and publish a National AI Risk Assessment (NAIRA) 

The Office of AI should commission and publish a comprehensive assessment of Australia’s exposure to AI-related risk, considering the full range of AI risks — including prospective, cross-cutting and potentially catastrophic risks — and the effectiveness of Australia’s regulatory frameworks. This analysis would establish a shared basis for prioritising and funding reviews and reforms.

Recommendation 2: The Government should legislate mandatory monitoring and reporting of serious AI incidents

The Government should establish a mandatory monitoring and reporting mechanism for serious AI incidents, harms, and near misses, to give agencies the visibility needed to prioritise reforms. The National AI Plan commits the Australian AI Safety Institute (AISI) to monitor AI risks and harms, and regulators to identify, assess and address AI-related harms. AI incident monitoring and reporting would provide the evidence base to enable these bodies to do this work. Established models, in specific sectors in Australia and for AI overseas, could inform the design of such a mechanism. These include Australia’s reporting regimes for aviation, therapeutic goods, and ransomware payments, and the incident reporting obligations in the European Union’s AI Act and California’s Transparency in Frontier Artificial Intelligence Act.

Recommendation 3: The Department of Industry, Science and Resources (DISR) or the Office of AI should coordinate and publicly report on AI-related reviews and reforms

DISR or the Office of AI should be funded to coordinate and track the ongoing reviews and reforms of regulatory frameworks. This should also involve a public, whole-of-government register of AI-related reforms and reviews, and annual reports to Parliament.

Global Shield Australia has set out the benefits of such a scheme and how it would work. Read our brief here: AI Incident Monitoring & Reporting for Australia

Recommendation 4: The Joint Select Committee on AI should use its inquiry to examine options for mitigating risk created primarily at the model level of the AI supply chain

The Joint Select Committee on AI’s inquiry is a key opportunity to review the role of frontier AI developers and the regulatory interventions available to mitigate risk at the level of AI models, where controls can be most effective across multiple policy areas. The Committee should consider and make recommendations on Australia’s ability to regulate frontier AI developers, how best to address model-level risk, and options for Australia to contribute to international rules and norms on AI. The Committee should also review obligations legislated in overseas jurisdictions (including the European Union, South Korea, Vietnam, California and New York) and identify which may be suitable for Australia to adopt. This is particularly important to inform the design of the Australian Standards for AI, which are expected to come to Parliament in early 2027. 

Recommendation 5: The Government should provide specific funding for AI-related reviews and reforms and set clear timeframes for their conclusion

The Australian Government should fund priority review and reform processes, based on the NAIRA (Recommendation 1), with dedicated expertise and clear timeframes. Increased funding for the AISI would also enable it to better achieve its mandate to support agencies in their reviews and reforms.

Recommendation 6: The Government should enact framework or coordinating legislation to support the AI-related reviews and reforms

The Government should enact framework legislation setting baseline, cross-cutting expectations, definitions, and obligations to support the range of AI-related reviews and reforms taking place. This could include rules on attribution and liability for AI agents, information-sharing provisions, and foundational obligations (such as to manage risk when developing or deploying AI models). It could also include mandatory incident monitoring and reporting (Recommendation 2), obligations arising from the review of frontier AI developers (Recommendation 4), and empower a coordinating body to oversee and report on Australia’s AI-related reforms.

As the capabilities of AI systems continue to rapidly increase, risks that were once just speculative are becoming present dangers. This includes risks of catastrophic-level harms that cannot be easily responded to or recovered from. The National AI Plan’s third pillar commits the Government to “keep Australians safe”. This report provides an assessment of Australia’s progress towards meeting that aim and concrete actions to enable the Government to deliver on that commitment.

The FOI Material

The Guardrails & Gap Analyses report is informed by FOI requests with 40 Commonwealth agencies across the full range of portfolios. The request sought documents and communications relating to the AI gaps analysis process referenced by Minister Tim Ayres in Senate Estimates in February. Of the 40 submitted requests, only three resulted in document releases: namely, the Department of Home Affairs, the Digital Transformation Agency, and IP Australia. 

The documents released are available here:

Table of Identified Commonwealth Regulatory Processes related to AI
#ActionAgencyStatusKind
1APRA Letter to Industry on Artificial Intelligence (AI) (30 April 2026)APRACompletedPolicy Statement
2Open Letter to AFS Licensees and Market Participants (8 May 2026)ASICCompletedPolicy Statement
3Consultation on Proposed Amendments to the ASIC Market Integrity Rules: Trading Systems and Automated Trading (CP 386) (27 August 2025)ASICUnderwayRegulatory Reform
4Report: Beware the Gap – Governance Arrangements in the Face of AI Innovation (REP 798) (29 October 2024)ASICCompletedReview / Consultation
5Copyright and AI Reference Group (CAIRG) Consideration of Copyright and AI Policy Issues (28 October 2025)Attorney-General's DepartmentUnderwayRegulatory Reform
6Automated Decision-Making Reforms (in response to the Robodebt Royal Commission) (13 November 2024)Attorney-General's DepartmentUnderwayRegulatory Reform
7Criminal Code Amendment (Deepfake Sexual Material) Act 2024 (Cth) (2 September 2024)Attorney-General's DepartmentCompletedRegulatory Reform
8Modernisation and Clarification of the Privacy Act 1988 (Cth) (16 February 2023)Attorney-General's DepartmentUnderwayRegulatory Reform
9Commercial Radio Code of Practice 2026 (AI-disclosure rules) (February 2026)Australian Communications and Media AuthorityCompletedRegulatory Reform
10Digital Platform Services Inquiry 2020-25 (Final Report) (March 2025)Australian Competition and Consumer CommissionCompletedReview / Consultation
11Ethical Artificial Intelligence in the Australian Signals Directorate (January 2023)Australian Signals DirectorateCompletedPolicy Statement
12Automated Decision-Making Better Practice Guide (March 2025)Commonwealth OmbudsmanCompletedAdvice / Guidance
13Policy Settings for Responsible Use of Artificial Intelligence in Defence (March 2026)Department of DefenceCompletedPolicy Statement
14Australian Framework for Generative Artificial Intelligence (AI) in Schools (17 November 2023)Department of EducationCompletedPolicy Statement
15AI Employment and Workplaces Forum (28 April 2026)Department of Employment and Workplace RelationsUnderwayReview / Consultation
16National Framework for the Assurance of Artificial Intelligence in Government (21 June 2024)Department of FinanceCompletedPolicy Statement
17Advisory Note: Sanctions Risks from Misuse of AI and New Technologies (6 November 2025)Department of Foreign Affairs and TradeCompletedAdvice / Guidance
18Australian Government Strategy for International Engagement and Regional Leadership on Artificial Intelligence (2026)Department of Foreign Affairs and TradeUnderwayPolicy Statement
19Safe and Responsible Artificial Intelligence in Health Care — Legislation and Regulation Review: Final Report (23 July 2025)Department of Health, Disability and AgeingCompletedReview / Consultation
20Electronic Surveillance Framework Reforms (4 December 2020)Department of Home AffairsUnderwayRegulatory Reform
21Independent Review of the Security of Critical Infrastructure Act 2018 (2 February 2026)Department of Home AffairsCompletedReview / Consultation
22Cyber Security Legislative Package (29 November 2024)Department of Home AffairsCompletedRegulatory Reform
232023-2030 Australian Cyber Security Strategy: Horizon 2 Action Plan (11 June 2026)Department of Home AffairsCompletedReview / Consultation
24Protective Security Policy Framework (AI-related amendments) (24 July 2025)Department of Home AffairsCompletedPolicy Statement
25Security of Critical Infrastructure Legislation Amendment (Enhanced Critical Infrastructure Risk Management Program) Rules 2026 (4 June 2026)Department of Home AffairsCompletedRegulatory Reform
26Synthetic Biology and AI Protection and Security Effort (SYNAPSE) (3 April 2025)Department of Home Affairs (lead)UnderwayReview / Consultation
27Review of AI-Related Incidents under the Australian Government Crisis Management Framework (AGCMF) (December 2025)Department of Home Affairs (lead)UnderwayReview / Consultation
28Expectations of Data Centres and AI Infrastructure Developers (23 March 2026)Department of Industry, Science and ResourcesCompletedPolicy Statement
29Consultation on Safe and Responsible AI in Australia: Proposals Paper for Introducing Mandatory Guardrails for AI in High-Risk Settings (September 2024)Department of Industry, Science and ResourcesCompletedReview / Consultation
30Commitment to Restrict Access to 'Nudify' and Online Stalking Tools (2 September 2025)Department of Infrastructure, Transport, Regional Development, Communications, Sport and the ArtsUnderwayRegulatory Reform
31Digital Duty of Care Reforms (26 May 2026)Department of Infrastructure, Transport, Regional Development, Communications, Sport and the ArtsUnderwayRegulatory Reform
32Online Safety (Basic Online Safety Expectations) Amendment Determination 2024 (30 May 2024)Department of Infrastructure, Transport, Regional Development, Communications, Sport and the ArtsCompletedRegulatory Reform
33Policy for the Responsible Use of AI in Government (1 September 2024)Digital Transformation AgencyCompletedPolicy Statement
34Technical Standard for Government's Use of Artificial Intelligence (22 August 2025)Digital Transformation AgencyCompletedPolicy Statement
35Internet Search Engine Services Online Safety Code (Class 1A and Class 1B Material) (12 September 2023)eSafety CommissionerCompletedRegulatory Reform
36Unlawful Material Standards (Designated Internet Services and Relevant Electronic Services, Class 1A/1B) 2024 (19 June 2024)eSafety CommissionerCompletedRegulatory Reform
37Age-Restricted Material Codes (9 September 2025)eSafety CommissionerCompletedRegulatory Reform
38Guidance Note: Use of Generative Artificial Intelligence in Commission Cases (24 March 2026)Fair Work CommissionUnderwayRegulatory Reform
39Practice Direction: Use of Artificial Intelligence (PD-AI) (29 May 2026)Federal Circuit and Family Court of AustraliaCompletedRegulatory Reform
40Use of Generative Artificial Intelligence Practice Note (GPN-AI) (16 April 2026)Federal Court of AustraliaCompletedRegulatory Reform
41Patent Manual Update: Inventions Produced by AI (s.5.4.3) (8 January 2025)IP AustraliaCompletedPolicy Statement
42Automated Vehicle Safety Law (AVSL) Reform (April 2024)National Transport CommissionUnderwayReview / Consultation
43Guidance on Privacy and the Use of Commercially Available AI Products (21 October 2024)Office of the Australian Information CommissionerCompletedAdvice / Guidance
44Guidance on Privacy and Developing and Training Generative AI Models (21 October 2024)Office of the Australian Information CommissionerCompletedAdvice / Guidance
45Preliminary Inquiry — Use of Artificial Intelligence by Intelligence Agencies (29 May 2024)Office of the Inspector-General of Intelligence and SecurityCompletedReview / Consultation
46Best Practice Review of the Model Work Health and Safety Laws (1 September 2025)Safe Work AustraliaUnderwayReview / Consultation
47Automation and Artificial Intelligence Strategy 2025-27 (May 2025)Services AustraliaCompletedPolicy Statement
48Draft Guidance: The Use of Artificial Intelligence and the Code of Professional Conduct (July 2026)Tax Practitioners BoardUnderwayAdvice / Guidance
49Clarifying and Strengthening the Regulation of Medical Device Software including Artificial Intelligence (AI) - Outcomes from the Review of Therapeutic Goods Legislation, Regulation and Guidance (30 July 2025)Therapeutic Goods AdministrationCompletedReview / Consultation
50Review of AI and the Australian Consumer Law (3 October 2025)TreasuryCompletedReview / Consultation