Streamline ISO Consultants

  • Home
  • Security & AI
    • ISO 27001 Information Security
    • ISO 42001 AI Management
    • Cyber & Information Security Advisory
    • Essential Eight
    • SOC 2
    • TISAX
  • ISO Consulting Services
    • ISO Consultants Australia
    • ISO 9001 for US Companies
    • ISO Mentoring
    • Independent ISO Internal Audit Services Australia (Clause 9.2)
    • ISO Gap Analysis Audits: Know Where You Stand Before Stage 1
    • ISO Certification Auditors
    • ISO System Development
    • ISO Management System Maintenance & Ongoing Support
  • ISO Standards
    • ISO 9001 Quality Management
    • ISO 45001 Occupational Health and Safety
    • ISO 14001 Environmental Management
    • ISO 17025 Testing and Calibration
    • HACCP Food Safety
    • ISO 19443 Nuclear Supply Chain
  • Resources
    • All Articles
    • ISO Clause Guides
    • Quality Quotes
  • About
    • ISO FAQs
    • Quality Policy
    • Client Testimonials
    • ISO 9001 Certificate
  • Contact
    • Business Info
    • Privacy Policy

By Streamline ISO Consultants

A Federal Inquiry Just Asked What Is Stopping You Adopting AI

The short answer

Australia now has three AI processes running with dates attached. The nearest is the closest thing to an actual deadline: submissions to the federal Joint Select Committee on Artificial Intelligence close on 14 September 2026. The committee reports by 30 November 2026, a South Australian royal commission is due to start on 1 October 2026, and Commonwealth AI legislation, centred on large data centres, is expected early in 2027.

Reviewed August 2026. Dates confirmed against the Parliament of Australia committee page and the National Cabinet communique of 26 August 2026.

Miniature Australian parliamentary inquiry with a small-business representative presenting AI governance evidence
Submissions to the federal Joint Select Committee on Artificial Intelligence close on 14 September 2026. Its terms of reference name barriers to AI adoption faced by small, medium and family businesses.

For most of this year, Australian AI policy has been a series of announcements with no dates on them. That changed in August. There are now three separate processes running, each with a published calendar, and one of them is asking a question aimed squarely at small and medium business.

The dates that now exist

WhatWhenWhy it matters to you
Federal inquiry: submissions close14 September 2026The only date on this list you can act on directly
SA Royal Commission: intended commencement1 October 2026Expected to begin hearing evidence and receiving submissions from business
Federal inquiry: final report30 November 2026Recommendations land, including on whether existing law is adequate
Commonwealth AI legislationexpected early 2027Sets minimum standards for large data centres, and will include conditions on delivering AI training that are not yet defined. Not a governance regime for businesses that use AI
SA Royal Commission: final reportintended no later than 1 July 2027Longest running of the three
Federal committee dates confirmed on the Parliament of Australia committee page. Commonwealth legislation from the National Cabinet communique of 26 August 2026. Royal commission dates are as announced by the South Australian government and are yet to be formally established.

What the federal inquiry is asking

The Joint Select Committee on Artificial Intelligence was appointed on 20 August 2026 by resolution of both the House of Representatives and the Senate. It has fourteen terms of reference.

Most of the coverage led on deepfakes, national security and consumer protection. That is not what the terms of reference lead on. Read in order, the inquiry opens on opportunity: lifting Australia’s resilience, productivity growth, economic competitiveness and living standards; spreading the benefits across the suburbs and regions; driving research, new industries and exports in agriculture, resources, health and medical research, advanced manufacturing, financial services and defence industry; building sovereign AI capability; and the potential of narrow, domain-specific models trained on Australian data.

Risk appears, and it is serious. Fraud and scams, deepfakes, and the safety of children and vulnerable Australians sit at item (k). National security, foreign interference, and the resilience of supply chains and critical infrastructure sit at (l). Item (m) names the Australian AI Safety Institute and asks whether regulators and the security community can identify and respond to emerging risks.

But the balance matters if you are deciding whether to engage. This is predominantly an adoption and competitiveness inquiry with a risk annexe, not a crackdown. Going in expecting to defend yourself would be reading it wrong.

One term of reference names your business

Item (d) asks the committee to inquire into and report on:

the rate and extent of AI adoption across the Australian economy, and the barriers to adoption, faced by small and medium businesses and family businesses

That is an open invitation, with a closing date. If cost, skills, uncertainty about liability, insurance, client contracts or plain confusion about what is permitted has slowed you down, a committee has asked to hear about it and will report to Parliament in November.

Item (i) runs alongside it, asking about the adequacy of Australia’s existing laws and regulatory frameworks as they apply to AI and whether there are any gaps that warrant reform. Those two together are the whole argument: what is stopping you, and is the law part of the reason.

Submissions do not need to be long or written by a lawyer. A short, specific account of what your business tried, what stopped it and what would have helped is more useful to a committee than a polished document saying nothing.

The South Australian royal commission

Separately, on 10 August 2026 South Australia announced Australia’s first royal commission into artificial intelligence. It is intended to commence on 1 October 2026 and to report no later than 1 July 2027. Commissioners and final terms of reference had not been published at the time of writing, so the scope below is what has been proposed rather than what has been settled.

It is expected to hear evidence and receive submissions from a broad cross-section of the community, including business, industry bodies, unions, technology developers, academics and creative industries. The proposed focus areas run to policy and regulatory settings, education, public services, skills and workforce, and the energy, water and grid consequences of AI. The Premier has separately said it will not examine data centres themselves, on the basis that how the technology is used matters more than where a data centre gets built, so treat the infrastructure boundary as unsettled until the terms are published.

A royal commission is a heavier instrument than a parliamentary committee, and it runs longer. If you operate in South Australia, that is a second forum and a second timetable.

What to do while the law does not exist yet

Here is the part that gets misread in both directions. Some businesses will freeze until there is a statute to comply with. Others will decide nothing has changed. Both are wrong, for the same reason.

You cannot build a compliance response to a law that has not been drafted. You can build the management system that any version of it will land on.

All three processes are circling the same underlying questions, and they are the questions an auditor already asks:

  • What AI is in use across the business, including the tools nobody formally approved?
  • Who owns each one, and who decided it was acceptable?
  • What decisions does it make, or influence, about people?
  • What happens when it is wrong, and who notices?
  • How would you evidence any of the above to somebody who asked, without a month’s notice?

Be clear about why those questions are worth answering, because it is not that a regulator is coming. On what has been agreed, none of these three processes imposes anything on a business that uses AI, and the December 2025 National AI Plan decided not to proceed with mandatory guardrails for high-risk AI at this time. The questions are worth answering because your customers, insurers, investors and tender panels are already asking them. ISO 42001 remains the only certifiable AI management system standard on the shelf, which is why an inventory and a governance structure is a no-regrets move whatever the three processes recommend, and it would still be worth doing if all three reported tomorrow that nothing needs to change. If you already hold ISO 27001, most of the management system backbone is already built, which is how the two fit together.

What an auditor would ask for now

If I were assessing your AI governance tomorrow, well before any of this is law, this is the thread I would pull. It works as a self-test.

  1. The inventory. Every AI tool in use, including the ones people signed up for on a corporate card. Most businesses have no list at all, which is the shadow AI problem.
  2. The owner. A named person per tool, not a department.
  3. The decision record. Who assessed it, against what, and when.
  4. The data question. What goes into it, whether that includes personal information, and what the vendor does with it.
  5. The failure case. One real example of the tool being wrong, and what happened next.
  6. The review. Whether any of this reached management review, and whether anything changed.

Points 1 and 5 are where nearly everyone stops. A policy that says AI use must be approved, with no list of what was approved and no instance of anything being rejected, is a document rather than a control.

AI regulation in Australia: frequently asked questions

Is AI regulated in Australia yet?

There is no single AI Act, and no obligation is triggered simply because you use an AI tool. That does not make AI use unregulated: privacy, consumer, anti-discrimination, work health and safety, copyright and sector regulation already apply according to what you are doing. The federal inquiry is examining whether those frameworks are adequate. On the Commonwealth legislation expected early in 2027, be careful with the reporting. National Cabinet agreed on 26 August 2026 to a nationally consistent framework setting minimum requirements for large data centres, covering energy, water and land use. The communique also says the legislation will include conditions associated with delivering AI training, and those conditions have not been defined, so it may reach organisations that train or develop AI. On what has been published, it does not impose AI governance obligations on a business that uses AI.

Should we wait for the law before doing anything?

There is no law to wait for, and that is the point rather than a reason to relax. Nobody can tell you what the inquiry will recommend in November, so do not build an AI inventory because a regulator is coming. Build it because customers, insurers, investors and tender panels are already asking how you govern AI, because those questions cannot be answered retrospectively, and because if obligations do arrive you will be starting from a list rather than from nothing.

Can a small business make a submission?

Yes, and item (d) of the terms of reference specifically asks about barriers faced by small, medium and family businesses. Submissions close 14 September 2026. Check the committee page on aph.gov.au for the current lodgement process before you write.

Does ISO 42001 certification make us compliant?

No standard makes you compliant with a law, and nobody should sell it that way. What ISO 42001 gives you is the governance structure and the evidence trail that a customer, an insurer or a future regulatory regime would ask you to produce: an inventory, assigned ownership, risk assessment, controls and a record of them operating.

What does ISO 42001 cost and how long does it take?

In our experience, three to six months for most small to medium Australian businesses. Cost varies more than the older standards because the practice is newer, and it drops substantially if you already hold ISO 27001. See our ISO 42001 certification cost guide for current ranges.

Where Streamline fits

Streamline is run by a practising ISO Lead Auditor, so you get the view from the other side of the audit table rather than a forecast of what the law might say.

Most organisations we speak to about AI have a capable person who has been told to get across AI governance and does not know where to start. That is what ISO mentoring is for: we coach your own people through building the ISO 42001 management system, the knowledge stays with you, and the cost stays down. We also run independent gap analysis audits if you want to know where you stand first, and provide the independent internal audit required under clause 9.2.

Start with the inventory. If you cannot produce a list of the AI tools in use across your business this week, that is the finding, and it is worth a conversation.

Sources

  • Parliament of Australia, Joint Select Committee on Artificial Intelligence committee page, including the resolution of appointment of 20 August 2026, the terms of reference, the submissions closing date of 14 September 2026 and the reporting date of 30 November 2026.
  • South Australian Department of the Premier and Cabinet, Royal Commission into Artificial Intelligence announcement, 10 and 11 August 2026, for the intended 1 October 2026 commencement, the intended report date of no later than 1 July 2027 and the proposed focus areas. Commissioners and final terms of reference were not published at the time of writing.
  • Prime Minister of Australia, “AI in Australia’s interests”, 15 July 2026, foreshadowing national standards for large data centres covering power supply, grid connection costs, demand reduction, water efficiency and siting, and establishing the Office of AI within the Department of the Prime Minister and Cabinet.
  • National Cabinet communique, 26 August 2026, agreeing a nationally consistent framework of minimum requirements for large data centres covering energy, water and land use, with Commonwealth legislation intended in early 2027 “including conditions associated with delivering AI training”.
  • National AI Plan, December 2025, and the mandatory guardrails consultation, for the decision not to proceed at this time with mandatory guardrails for high-risk AI and to rely on existing law.
  • ISO/IEC 42001, artificial intelligence management systems.

Dates in this article were confirmed against the Parliament of Australia committee page and the National Cabinet communique of 26 August 2026, and are current as at 28 August 2026. Timetables move and the South Australian terms of reference are not yet published, so check the primary source before relying on a date. This article is general information from an auditing and management system perspective and is not legal advice.

General guidance only. This article is general information, not legal, financial, safety or compliance advice, and it does not take account of your specific circumstances. Streamline ISO Consultants are ISO management-system consultants, not lawyers or licensed advisers. Standards, laws and regulator guidance change, and details were correct only at the time of writing. Always seek professional advice before acting. See our full Disclaimer.

Stay in the Loop

Get an email when we post an article. Your email address will not be used for marketing, and you can unsubscribe at any time.

We handle your details in line with our privacy policy.

More ISO Certification Information

  • Tilt-shift miniature data centre with a glowing AI microchip, representing Australia's Office of AI and the national data centre framework
    Australia's Office of AI: What "Verifying…
  • ISO Frequently Asked Questions
    Frequently Asked Questions: ISO FAQs
  • ISO 14001 environmental management
    ISO 14001 Consulting, Environmental Audits and Mentoring
  • ISO certification bodies in Australia
    How to Choose an ISO Certification Body in Australia
  • Consultant guiding a business owner through their ISO management system at a laptop
    ISO Mentoring: Expert Guidance for DIY ISO Systems
  • ISO 45001 workplace safety inspection
    ISO 45001 Consulting, Safety Audits and Mentoring
  • ISO 27001 information security risk analysis
    ISO 27001 Consulting, Internal Audits & Mentoring
  • Tilt-shift miniature of an office where an oversized industrial valve marked OPEN pours paperwork over the desks, burying workers, while a figure carries papers into an empty meeting room nobody is using
    Psychosocial Hazards at Work: What Australian Law…
  • Tilt-shift miniature of a collapsed bridge with engineers at a drawing board tracing the failure back to the design
    ISO 9001 Clause 8.3: Design Inputs, Outputs, Review,…

Filed Under: Articles Tagged With: #auditing, #iso42001

Quick Information Request

Brisbane ISO Consultants

Level 14, 167 Eagle St
Brisbane Queensland 4000
Phone: 07 3667 8280
Email: hello@streamline.business

Sydney ISO Consultants

Level 5, 20 Bond Street,
Sydney NSW 2000
Phone: 02 8315 7780
Email: hello@streamline.business

Melbourne ISO Consultants

Level 8, 350 Collins Street
Melbourne, Victoria 3000
Phone: 03 9034 3990
Email: hello@streamline.business

Client and partner logos

KEY ISO ARTICLES

Articles, Deep Dives & More
Frequently Asked Questions
Quality Quotes
Funding Grants for ISO Certification
ISO Consultants
Strategic Planning - Mystical Art?
ISO Certification Auditors
How to get ISO 9001 Certification
ISO Certification Cost
How to tell if your ISO Cert is fake
4-year-olds and Root Cause Analysis
Fast ISO 9001 Certification
The Ultimate Guide to ISO 9001 Audit
ISO 45001 Certification Cost
Who's Interested in a Party?
How to use Smartsheet for ISO
Smarter Quality Objectives
Local Government QMS
Quality Assurance, Quality Control or QMS
ISO Certification in Sydney
ISO Certification in Melbourne
ISO Certification in Brisbane
SAI Global Consultant Affiliate Program

QUICKLINKS TO ISO INFO

ISO Consultants Australia
ISO Mentoring
ISO 27001 Certification Cost
ISO 9001 Quality Management
ISO 45001 Health & Safety
ISO 14001 Environment
ISO 17025 Testing & Calibration
ISO 27001 Information Security
ISO 42001 AI Management
ISO 22000 HACCP Food Safety

Search

FOLLOW OR GET IN TOUCH

linkedinmail
Smartsheet Platinum Partner

Copyright © 2026 Streamline · Log in

Privacy Policy · Terms of Use · Disclaimer

Call us Enquire