
Updated 28 August 2026: National Cabinet has now agreed the national framework. It sets minimum requirements for large data centres rather than rules for how ordinary businesses use AI, despite being reported in places as “AI standards”, though the legislation will also carry conditions on delivering AI training that have not yet been defined. A federal parliamentary inquiry is open, with submissions closing 14 September 2026, and South Australia’s royal commission is due to begin on 1 October. All three, and what none of them changes for you, are set out below.
Buried in the Prime Minister’s AI announcement in July was a phrase that made every auditor in the country sit up: a “streamlined process for verifying compliance.” Politicians do not usually talk like that. Auditors do. Six weeks on we know what sits behind it, and it is a good deal narrower than the headlines suggested.
On 15 July 2026, Anthony Albanese announced that Australia will set up an Office of AI inside the Department of the Prime Minister and Cabinet, and build what he called a “world-first” national framework. He framed it as replacing the current issue-by-issue, sector-by-sector approach to the location, energy and water obligations that fall on large data centres, and as making Australia more attractive to investors. In his words, getting it right would deliver “greater clarity and speed for approvals, and a streamlined process for verifying compliance.”
What was announced
The concrete parts are these. An Office of AI sits inside the Department of the Prime Minister and Cabinet. PM&C describes its job as coordinating across government agencies to design and legislate the new Australian AI standard and to unlock AI training in Australia, working with the Minister for Industry and Innovation, the Assistant Minister for Science, Technology and the Digital Economy, and the Department of Industry, Science and Resources. Those standards are to include mandatory requirements for large AI data centres, covering energy and water, with copyright protections for Australian creators.
The framework turned out to be narrower than its name, and this is the part most of the coverage got wrong. National Cabinet agreed it on 26 August 2026, and what it sets is minimum requirements for large data centres: mandatory standards for energy, water and land use, with Commonwealth legislation designed to complement rather than duplicate state and territory planning and approval processes. It was reported in several places as Australia agreeing “AI standards”, which invites the reader to assume rules for businesses using AI. It is infrastructure regulation. One caveat the coverage also missed: the communique says the legislation, expected early in 2027, will include conditions associated with delivering AI training. Those conditions have not been defined, so if you train or develop AI rather than simply use it, this may yet reach you.
What is not there is any general obligation on a business that uses AI. The December 2025 National AI Plan had already decided not to proceed at this time with mandatory guardrails for high-risk AI, leaving AI use to the laws that already apply: privacy, consumer, anti-discrimination, work health and safety, copyright and sector regulation. Those have not gone anywhere, and they bite according to what you do with AI rather than because you use it. What has not appeared is a business-facing AI verification regime, and none is currently proposed.
How governments usually verify compliance
When a government says it wants a streamlined, credible way to verify that businesses are doing the right thing, it almost never invents the verification method from scratch. It reaches for standards and conformity assessment, because that machinery already exists and is trusted. It is how we verify that a building is safe, that a laboratory’s results can be relied on, and that a company protects the data it holds. You write your system to a recognised standard, and an independent third party checks that you actually do what it says.
Apply that pattern to AI, and one standard is already sitting on the shelf. ISO/IEC 42001 is the world’s first certifiable management system standard for artificial intelligence, and Australia has already adopted it as AS ISO/IEC 42001. It asks an organisation to work out the risks its AI creates, put controls and governance around them, and keep improving. If Australia ever does decide to verify how businesses govern their own AI, and the federal inquiry is the live route to that rather than the data centre framework, a certifiable management system is the machinery governments usually reach for. Be clear that this is a reasonable expectation based on how verification has worked in every other field, not a stated intention. No Australian government source has named ISO 42001 as a verification mechanism.
One distinction is worth pausing on, because it is the sort of thing that trips businesses up. Conforming to a standard and complying with the law are not the same thing. When you certify to ISO 42001 you are demonstrating conformity, which means your AI management system meets the requirements of the standard. Legal compliance is a separate obligation sitting over and above any standard you choose to adopt, and for AI it currently comes from the laws that already apply to you. We have written before about the difference between compliance and conformity. Certifying does not make you compliant by itself. What it does is hand you the machinery to prove it, because the register of obligations, the controls and the audit evidence are already in place.
You have seen this movie before
If you have spent time in a compliance-facing business, the shape of this is familiar. Something starts as voluntary guidance, becomes the thing everyone is quietly expected to have, and then hardens into a requirement. The Essential Eight began as advice and is now the baseline that government buyers and insurers assume. Climate reporting went from optional to mandatory under AASB S2, and the Scope 3 questionnaires are already flowing down supply chains. The businesses that read the direction of travel early were not the ones scrambling at the deadline. It is worth saying that the traffic does not only move one way: mandatory AI guardrails were proposed here and then shelved, and they may stay shelved.
What it means for you now
Nothing here forces you to certify to ISO 42001, and on the current position nothing is about to. So the case for standing up an AI management system now is not a looming deadline, and anyone selling it to you as one is overreaching. It is simpler than that. It gets your own AI risk under control, it gives you something concrete to show the customers, insurers and investors who are already asking how you govern AI, and if the federal inquiry does recommend obligations in November you will be answering questions rather than starting to gather evidence.
The sensible first step is not certification, it is knowing where you stand. A gap analysis against ISO 42001 shows you the distance between how you use AI today and what a credible AI management system looks like, in priority order. From there you can build it with us, or have your own people build it with our ISO mentoring and the independent internal audit it needs. Our ISO 42001 service page sets out what an AI management system actually involves.
Update, August 2026: three processes now, and none of them lands on you
On Monday 10 August 2026 the South Australian Premier, Peter Malinauskas, announced Australia’s first royal commission into artificial intelligence. It is intended to commence on 1 October 2026 and to report no later than 1 July 2027. Three commissioners are to be appointed and the cost has been reported at around $3 million. Commissioners and final terms of reference had not been published at the time of writing, so what follows is the proposed shape rather than the settled one.
The proposed focus areas run to policy and regulatory settings, education, public services, skills and workforce, and the energy, water and grid consequences of AI. The Premier has separately said the commission will not examine data centres themselves, on the basis that the question of how the technology is used in society is “far more consequential than where a data centre gets built”. Treat the infrastructure boundary as unsettled until the terms are published.
Ten days later the Commonwealth opened a second front. The Joint Select Committee on Artificial Intelligence was appointed on 20 August 2026 by resolution of both houses. Submissions close on 14 September 2026 and it reports by 30 November 2026. Item (d) of its terms of reference asks about the barriers to AI adoption faced by small, medium and family businesses, and item (i) asks whether existing law is adequate. That is the one date on this page you can act on, and we have set out what the inquiry is asking and how to make a submission.
The third process is the one that gets mis-reported, so it is worth being precise. National Cabinet agreed the national framework on 26 August 2026, and what it sets is minimum requirements for large data centres: mandatory standards for energy, water and land use, with legislation designed to complement state and territory planning and approval rather than duplicate it. Several outlets described this as Australia agreeing “AI standards”. It is infrastructure regulation and it imposes nothing on a business that merely uses AI, with the one caveat that the legislation is also to carry undefined conditions on delivering AI training. Copyright and control of training data remain unresolved and sit with the Copyright and AI Reference Group, which advises rather than decides.
So the three live processes have almost inverted scopes. One is the infrastructure. One is proposed to cover everything except the infrastructure. One is asking why adoption is slow. Worth adding that the December 2025 National AI Plan stepped back from mandatory guardrails for high-risk AI use cases and left AI use to the laws that already apply, so the direction of travel here is not the one-way ratchet it is often assumed to be.
None of them answers the question a client actually has to answer, which is: how does this business show that its own use of AI is governed, assessed and controlled?
That question is already being asked, not by a regulator but by customers, insurers, investors and tender panels, and it has to be demonstrated rather than asserted. Demonstrated means documented scope, assessed risks, defined roles, controls that exist and evidence that they work. None of that can be produced retrospectively on the week somebody asks.
That is a management system, and ISO 42001 remains the only certifiable one on the shelf. Nothing announced in August changes that. The gap between three live processes and zero obligations on the individual organisation is precisely why the case for building one rests on commercial demand rather than on a regulatory deadline.
One practical note if you are watching this. The date to diarise is not July 2027. It is 14 September 2026, when submissions to the federal inquiry close, because that is the only point at which anything you say changes what any of these three processes hears.
Frequently asked questions
Is ISO 42001 mandatory in Australia now?
No, and nothing currently proposed would change that. The national framework National Cabinet agreed on 26 August 2026 sets minimum requirements for large data centres, not rules for AI use by ordinary businesses, and the December 2025 National AI Plan stepped back from mandatory guardrails for high-risk AI use cases in favour of the laws that already apply. ISO 42001 certification is voluntary. Its value today is in answering the customers, insurers and investors who ask how you govern AI, and in being ready if the position changes.
What is “verifying compliance” likely to look like?
On what has been agreed since, it does not look like anything aimed at you. The phrase came from the Prime Minister’s July announcement, and the framework behind it turned out to govern approvals and large data centres. There is no business-facing AI verification regime and none is currently proposed. If general obligations do arrive, the federal inquiry reporting on 30 November 2026 is the likeliest route. Governments usually verify through recognised standards and independent conformity assessment rather than bespoke checks, so a certifiable standard is a reasonable bet, but no government source has said so and anybody telling you otherwise is guessing.
Does the new law apply to us if we train or build AI?
Possibly, and this is the part worth watching. The National Cabinet communique says the Commonwealth intends to legislate the AI standards in early 2027 “including conditions associated with delivering AI training”. No bill or exposure draft has defined those conditions. If your business trains or develops AI, rather than only using it, keep an eye on the draft when it appears.
What is the first thing we should do?
A gap analysis against ISO 42001. It is quick, it does not commit you to certification, and it tells you where your real exposure sits today, which is with the customers, insurers and investors already asking how you govern AI rather than with any regulator.
Speak with an experienced ISO auditor
If the AI announcement has you wondering where your business stands, we can help you find out. Email hello@streamline.business or call us. You will deal directly with an experienced ISO auditor.
- Brisbane 07 3667 8280
- Sydney 02 8315 7780
- Melbourne 03 9034 3990
Sources
- Prime Minister of Australia, “AI in Australia’s interests”, 15 July 2026.
- Department of the Prime Minister and Cabinet, Office of AI, for the office’s remit.
- National Cabinet communique, 26 August 2026, for the agreed framework and the AI training conditions.
- Parliament of Australia, Joint Select Committee on Artificial Intelligence, for the inquiry dates and terms of reference.
- South Australian Department of the Premier and Cabinet, royal commission announcement, August 2026.
- National AI Plan, December 2025, for the decision not to proceed at this time with mandatory guardrails.
Related reading
Stay in the Loop
Get an email when we post an article. Your email address will not be used for marketing, and you can unsubscribe at any time.
We handle your details in line with our privacy policy.











