Most organisations have filed artificial intelligence under governance. It sits with the privacy review, the procurement checklist and a policy about acceptable use. It is a technology decision with a compliance wrapper.
Safe Work Australia has just made that filing incomplete. Its new guidance on AI and digital technologies treats these systems as something a work health and safety duty holder has to manage: a source of physical and psychological hazards, subject to the ordinary risk management process, and requiring consultation with the workers affected.
That is a different conversation, with different people in the room.
What the guidance says
The guidance sets out the opportunities and the risks, and explains how duty holders can apply the standard WHS risk management process so these technologies are introduced and used safely. Two things in that sentence do the work.
“The standard WHS risk management process.” No new framework. The same identify, assess, control, review cycle already applied to plant, chemicals and manual handling. If you have a functioning WHS system, AI goes through it. If AI has instead gone through a governance committee that has never done a risk assessment, it has not been through the process at all.
“In consultation with workers and their representatives.” Consultation is a duty under the WHS Act, not a courtesy. It is also the step most AI rollouts skip entirely, because they are run as IT projects with a change-management communications plan attached. Telling people about a system is not consulting them on it.
The scope is broader than chatbots. It covers algorithmic management, workplace monitoring, automation and robotics. If software is allocating work, setting pace, scoring performance or watching people, it is in scope.
The hazards are not hypothetical
Physical risks are the easy ones to see. Automation and robotics introduce plant hazards, and those are well understood.
The psychological ones are where most organisations have no controls at all, and they are the ones the guidance draws out:
- Work pace and intensity set by an algorithm that does not know a worker is unwell, new, or covering for someone.
- Monitoring and surveillance, and the effect of being measured continuously.
- Loss of autonomy and control, which is one of the best-evidenced psychosocial hazards there is.
- Job insecurity during a rollout that nobody has explained properly.
- Unclear accountability when a system makes a call and no human can say why.
Those map directly onto psychosocial hazards that are already regulated across Australian jurisdictions. Which means for many organisations this is not a new duty. It is an existing duty arriving through a door nobody was watching.
NSW has already legislated
Guidance is guidance. But the direction of travel is no longer speculative.
New South Wales passed the Work Health and Safety Amendment (Digital Work Systems) Act 2026 on 12 February 2026, imposing specific WHS duties on PCBUs that use AI, algorithms, automation or online platforms to allocate work.
If you operate in NSW, or you have workers there, the question is no longer whether AI sits inside your WHS obligations. It is whether you can demonstrate you have treated it that way.
Where ISO 42001 and ISO 45001 meet
This is the practical problem, and it is an organisational one before it is a technical one.
ISO 42001, the AI management system standard, handles the governance side properly: what AI you have, what it is for, who owns it, how risk is assessed, what happens when it behaves unexpectedly. Its Annex A controls cover impact assessment, data governance and human oversight.
ISO 45001 handles the safety side: hazard identification, consultation, the hierarchy of controls, incident reporting.
In most organisations those two live in different buildings. The AI register sits with IT or legal. The risk register sits with the safety team. The AI system that sets work pace appears in the first one as a productivity tool and does not appear in the second one at all.

That is the gap the guidance closes, and closing it is not complicated:
One register, or two registers that talk. Every AI or algorithmic system that touches how work is allocated, paced, monitored or assessed should appear in your WHS hazard identification, not only in your AI inventory.
Consultation that satisfies the WHS Act. Health and safety representatives involved before deployment, not briefed after it. Records kept, because consultation you cannot evidence did not happen as far as a regulator is concerned.
Psychosocial risk assessment as standard. Treat an algorithmic management tool the way you would treat a change to rosters or workload, because functionally that is what it is.
Human oversight that is real. ISO 42001 asks for it. Make sure the person nominated can actually intervene, and has the authority and the time to do so.
A route for reporting. Workers need somewhere to raise that a system is producing unsafe pressure, and it needs to reach the safety function rather than a product backlog.
None of that requires new machinery if you already run a management system. It requires the two systems you have to stop ignoring each other.
Update, 4 September 2026. WorkSafe Victoria has charged a department store chain and a warehouse robotics supplier following the death of a worker at a Ravenhall distribution centre in September 2024, in which a man was crushed while responding to a jammed item on an automated stock collection robot. The matter is before the courts and nothing is proven. The regulator has not named either business and neither do we.
What is worth noting now is the shape of it. The robotics supplier has been charged alongside the operator. The upstream duties on those who design, manufacture and supply plant are not new, but this is them reaching an automation vendor. If you buy an automated system, that vendor sits inside your safety duty and you sit inside theirs. Under ISO 42001 the same relationship is a third party risk requiring documented instructions and oversight, and under ISO 45001 it is a plant and procurement question under clause 8.1. One vendor, two duties, and most contracts address neither. That is worth settling before an incident rather than afterwards, and it does not depend on how this prosecution ends.
The straightforward question
If a regulator asked tomorrow how you had assessed the health and safety risks of the AI you have deployed, and how you had consulted workers about it, could you answer with documents?
For most organisations the honest answer today is that the AI decision is well documented and the safety assessment does not exist, because nobody thought it was that kind of decision.
It is now.
We work with organisations on ISO 42001 AI management systems and on ISO 45001, and increasingly on the join between them, which is where this particular duty actually gets discharged.
Sources
- Safe Work Australia, New AI and digital technologies guidance now available
- Carroll & O’Dea, AI and workplace safety: NSW extends WHS duties to digital systems
Stay in the Loop
Get an email when we post an article. Your email address will not be used for marketing, and you can unsubscribe at any time.
We handle your details in line with our privacy policy.











