The short answer
Australia now has three AI processes running with dates attached. The nearest is the closest thing to an actual deadline: submissions to the federal Joint Select Committee on Artificial Intelligence close on 14 September 2026. The committee reports by 30 November 2026, a South Australian royal commission is due to start on 1 October 2026, and Commonwealth AI legislation, centred on large data centres, is expected early in 2027.
Reviewed August 2026. Dates confirmed against the Parliament of Australia committee page and the National Cabinet communique of 26 August 2026.

For most of this year, Australian AI policy has been a series of announcements with no dates on them. That changed in August. There are now three separate processes running, each with a published calendar, and one of them is asking a question aimed squarely at small and medium business.
The dates that now exist
| What | When | Why it matters to you |
|---|---|---|
| Federal inquiry: submissions close | 14 September 2026 | The only date on this list you can act on directly |
| SA Royal Commission: intended commencement | 1 October 2026 | Expected to begin hearing evidence and receiving submissions from business |
| Federal inquiry: final report | 30 November 2026 | Recommendations land, including on whether existing law is adequate |
| Commonwealth AI legislation | expected early 2027 | Sets minimum standards for large data centres, and will include conditions on delivering AI training that are not yet defined. Not a governance regime for businesses that use AI |
| SA Royal Commission: final report | intended no later than 1 July 2027 | Longest running of the three |
What the federal inquiry is asking
The Joint Select Committee on Artificial Intelligence was appointed on 20 August 2026 by resolution of both the House of Representatives and the Senate. It has fourteen terms of reference.
Most of the coverage led on deepfakes, national security and consumer protection. That is not what the terms of reference lead on. Read in order, the inquiry opens on opportunity: lifting Australia’s resilience, productivity growth, economic competitiveness and living standards; spreading the benefits across the suburbs and regions; driving research, new industries and exports in agriculture, resources, health and medical research, advanced manufacturing, financial services and defence industry; building sovereign AI capability; and the potential of narrow, domain-specific models trained on Australian data.
Risk appears, and it is serious. Fraud and scams, deepfakes, and the safety of children and vulnerable Australians sit at item (k). National security, foreign interference, and the resilience of supply chains and critical infrastructure sit at (l). Item (m) names the Australian AI Safety Institute and asks whether regulators and the security community can identify and respond to emerging risks.
But the balance matters if you are deciding whether to engage. This is predominantly an adoption and competitiveness inquiry with a risk annexe, not a crackdown. Going in expecting to defend yourself would be reading it wrong.
One term of reference names your business
Item (d) asks the committee to inquire into and report on:
the rate and extent of AI adoption across the Australian economy, and the barriers to adoption, faced by small and medium businesses and family businesses
That is an open invitation, with a closing date. If cost, skills, uncertainty about liability, insurance, client contracts or plain confusion about what is permitted has slowed you down, a committee has asked to hear about it and will report to Parliament in November.
Item (i) runs alongside it, asking about the adequacy of Australia’s existing laws and regulatory frameworks as they apply to AI and whether there are any gaps that warrant reform. Those two together are the whole argument: what is stopping you, and is the law part of the reason.
Submissions do not need to be long or written by a lawyer. A short, specific account of what your business tried, what stopped it and what would have helped is more useful to a committee than a polished document saying nothing.
The South Australian royal commission
Separately, on 10 August 2026 South Australia announced Australia’s first royal commission into artificial intelligence. It is intended to commence on 1 October 2026 and to report no later than 1 July 2027. Commissioners and final terms of reference had not been published at the time of writing, so the scope below is what has been proposed rather than what has been settled.
It is expected to hear evidence and receive submissions from a broad cross-section of the community, including business, industry bodies, unions, technology developers, academics and creative industries. The proposed focus areas run to policy and regulatory settings, education, public services, skills and workforce, and the energy, water and grid consequences of AI. The Premier has separately said it will not examine data centres themselves, on the basis that how the technology is used matters more than where a data centre gets built, so treat the infrastructure boundary as unsettled until the terms are published.
A royal commission is a heavier instrument than a parliamentary committee, and it runs longer. If you operate in South Australia, that is a second forum and a second timetable.
What to do while the law does not exist yet
Here is the part that gets misread in both directions. Some businesses will freeze until there is a statute to comply with. Others will decide nothing has changed. Both are wrong, for the same reason.
You cannot build a compliance response to a law that has not been drafted. You can build the management system that any version of it will land on.
All three processes are circling the same underlying questions, and they are the questions an auditor already asks:
- What AI is in use across the business, including the tools nobody formally approved?
- Who owns each one, and who decided it was acceptable?
- What decisions does it make, or influence, about people?
- What happens when it is wrong, and who notices?
- How would you evidence any of the above to somebody who asked, without a month’s notice?
Be clear about why those questions are worth answering, because it is not that a regulator is coming. On what has been agreed, none of these three processes imposes anything on a business that uses AI, and the December 2025 National AI Plan decided not to proceed with mandatory guardrails for high-risk AI at this time. The questions are worth answering because your customers, insurers, investors and tender panels are already asking them. ISO 42001 remains the only certifiable AI management system standard on the shelf, which is why an inventory and a governance structure is a no-regrets move whatever the three processes recommend, and it would still be worth doing if all three reported tomorrow that nothing needs to change. If you already hold ISO 27001, most of the management system backbone is already built, which is how the two fit together.
What an auditor would ask for now
If I were assessing your AI governance tomorrow, well before any of this is law, this is the thread I would pull. It works as a self-test.
- The inventory. Every AI tool in use, including the ones people signed up for on a corporate card. Most businesses have no list at all, which is the shadow AI problem.
- The owner. A named person per tool, not a department.
- The decision record. Who assessed it, against what, and when.
- The data question. What goes into it, whether that includes personal information, and what the vendor does with it.
- The failure case. One real example of the tool being wrong, and what happened next.
- The review. Whether any of this reached management review, and whether anything changed.
Points 1 and 5 are where nearly everyone stops. A policy that says AI use must be approved, with no list of what was approved and no instance of anything being rejected, is a document rather than a control.
AI regulation in Australia: frequently asked questions
Is AI regulated in Australia yet?
There is no single AI Act, and no obligation is triggered simply because you use an AI tool. That does not make AI use unregulated: privacy, consumer, anti-discrimination, work health and safety, copyright and sector regulation already apply according to what you are doing. The federal inquiry is examining whether those frameworks are adequate. On the Commonwealth legislation expected early in 2027, be careful with the reporting. National Cabinet agreed on 26 August 2026 to a nationally consistent framework setting minimum requirements for large data centres, covering energy, water and land use. The communique also says the legislation will include conditions associated with delivering AI training, and those conditions have not been defined, so it may reach organisations that train or develop AI. On what has been published, it does not impose AI governance obligations on a business that uses AI.
Should we wait for the law before doing anything?
There is no law to wait for, and that is the point rather than a reason to relax. Nobody can tell you what the inquiry will recommend in November, so do not build an AI inventory because a regulator is coming. Build it because customers, insurers, investors and tender panels are already asking how you govern AI, because those questions cannot be answered retrospectively, and because if obligations do arrive you will be starting from a list rather than from nothing.
Can a small business make a submission?
Yes, and item (d) of the terms of reference specifically asks about barriers faced by small, medium and family businesses. Submissions close 14 September 2026. Check the committee page on aph.gov.au for the current lodgement process before you write.
Does ISO 42001 certification make us compliant?
No standard makes you compliant with a law, and nobody should sell it that way. What ISO 42001 gives you is the governance structure and the evidence trail that a customer, an insurer or a future regulatory regime would ask you to produce: an inventory, assigned ownership, risk assessment, controls and a record of them operating.
What does ISO 42001 cost and how long does it take?
In our experience, three to six months for most small to medium Australian businesses. Cost varies more than the older standards because the practice is newer, and it drops substantially if you already hold ISO 27001. See our ISO 42001 certification cost guide for current ranges.
Where Streamline fits
Streamline is run by a practising ISO Lead Auditor, so you get the view from the other side of the audit table rather than a forecast of what the law might say.
Most organisations we speak to about AI have a capable person who has been told to get across AI governance and does not know where to start. That is what ISO mentoring is for: we coach your own people through building the ISO 42001 management system, the knowledge stays with you, and the cost stays down. We also run independent gap analysis audits if you want to know where you stand first, and provide the independent internal audit required under clause 9.2.
Start with the inventory. If you cannot produce a list of the AI tools in use across your business this week, that is the finding, and it is worth a conversation.
Sources
- Parliament of Australia, Joint Select Committee on Artificial Intelligence committee page, including the resolution of appointment of 20 August 2026, the terms of reference, the submissions closing date of 14 September 2026 and the reporting date of 30 November 2026.
- South Australian Department of the Premier and Cabinet, Royal Commission into Artificial Intelligence announcement, 10 and 11 August 2026, for the intended 1 October 2026 commencement, the intended report date of no later than 1 July 2027 and the proposed focus areas. Commissioners and final terms of reference were not published at the time of writing.
- Prime Minister of Australia, “AI in Australia’s interests”, 15 July 2026, foreshadowing national standards for large data centres covering power supply, grid connection costs, demand reduction, water efficiency and siting, and establishing the Office of AI within the Department of the Prime Minister and Cabinet.
- National Cabinet communique, 26 August 2026, agreeing a nationally consistent framework of minimum requirements for large data centres covering energy, water and land use, with Commonwealth legislation intended in early 2027 “including conditions associated with delivering AI training”.
- National AI Plan, December 2025, and the mandatory guardrails consultation, for the decision not to proceed at this time with mandatory guardrails for high-risk AI and to rely on existing law.
- ISO/IEC 42001, artificial intelligence management systems.
Dates in this article were confirmed against the Parliament of Australia committee page and the National Cabinet communique of 26 August 2026, and are current as at 28 August 2026. Timetables move and the South Australian terms of reference are not yet published, so check the primary source before relying on a date. This article is general information from an auditing and management system perspective and is not legal advice.
Stay in the Loop
Get an email when we post an article. Your email address will not be used for marketing, and you can unsubscribe at any time.
We handle your details in line with our privacy policy.











