In September 2024, Australia's government proposed mandatory guardrails for AI used in high-risk settings, ten of them, covering everything from accountability and risk management to human oversight and record-keeping. By December 2025, the National AI Plan quietly dropped that mandatory framework. The government confirmed it will not proceed with AI-specific legislation. No dedicated AI Act is coming, at least not on the timeline or in the form that was originally proposed.
It would be easy to read that as Australia deciding AI doesn't need governing. That's not what happened, and treating it that way is the mistake we see AI vendors and buyers both making right now.
What actually fills the gap
The government's position is that existing law already governs AI outcomes, and that sector regulators enforce it within their own remit rather than a single new AI regulator doing it centrally. Privacy, consumer protection, anti-discrimination, and sector-specific prudential rules all apply to what an AI system does, regardless of whether the word "AI" appears anywhere in the relevant statute. For a bank, an insurer, or a super fund, that means APRA's existing prudential standards, CPS 230 for operational risk and CPS 234 for information security, apply to AI the same way they apply to any other system or process the entity relies on. For every organisation handling personal information, the Privacy Act 1988 and its Australian Privacy Principles apply regardless of whether that information passed through a model.
No AI Act does not mean no AI law
CPS 230 has been in force since July 2025, independent of anything the National AI Plan did or didn't legislate. An APRA-regulated entity deploying AI without a service-provider register entry for its model vendor, or without evidence it can reconstruct an AI-assisted decision on demand, is already exposed under a standard that has nothing to do with the shelved AI Act.
The voluntary standard that's doing more work than its name suggests
Alongside the mandatory guardrails, the government also published a Voluntary AI Safety Standard in September 2024, ten guardrails covering accountability, risk management, data protection, testing, human oversight, transparency, contestability, supply chain transparency, record-keeping, and stakeholder engagement. With the mandatory version shelved, this voluntary standard is now the closest thing Australia has to a named, government-endorsed AI governance reference. It carries no legal force, but it's what a board, an auditor, or a regulator reaches for when the question "is this AI governed properly" comes up, and "voluntary" has not stopped it from becoming the de facto benchmark.
What we did about it
OBEL's in-app compliance report maps 87 controls across nine frameworks. Two of those frameworks exist specifically because of this decision: APRA CPS 230 and CPS 234, paragraph-cited, eight controls each, and the AU Voluntary AI Safety Standard's ten guardrails, mapped control by control with an honest satisfied, partial, or planned status on each one. When we first ran that mapping, two of the ten guardrails came back planned: a way for someone affected by an AI decision to challenge it, and a documented process for engaging the people OBEL's decisions actually affect. We didn't leave them planned. Challenging an AI decision is now a real intake in OBEL's own product, logged to an auditable record, not just an email. Stakeholder engagement is now a documented quarterly review. Both are covered in more detail elsewhere on this site.
That's the practical difference between reading a policy shift as a talking point and reading it as a specification. Australia told every organisation operating there exactly which laws now carry the weight an AI Act would have carried. We mapped our controls to the actual paragraphs of those laws instead of waiting for legislation that, as of the December 2025 decision, wasn't coming.
Worth watching
In July 2026, the Prime Minister announced plans to legislate "Australian Standards for AI" and established an Office of AI within the Department of the Prime Minister and Cabinet. Whether that becomes a formal AI-specific statute or another layer on top of existing law is still unclear. Either way, the mapping approach doesn't change: map controls to whatever's actually in force, not to what a plan says might eventually arrive.
“A shelved AI Act doesn't create a gap. It just makes the existing law the whole answer, and most AI vendors haven't checked whether their controls actually map to it.”
- ninthLABS Ventures
10
Mandatory AI guardrails proposed Sept 2024, dropped in the Dec 2025 National AI Plan
8
Paragraph-cited controls each for APRA CPS 230 and CPS 234 in OBEL's compliance report
10
Guardrails in the Voluntary AI Safety Standard, all ten now mapped against OBEL's own controls
Where to look
OBEL's full nine-framework compliance mapping is available in-app under Settings > Compliance for any paid org, generating a dated report scoped to any date range. See useobel.ai/enterprise for how it works.
This piece was prepared by the OBEL editorial team at ninthLABS Ventures, drawing on public reporting of Australia's National AI Plan and OBEL's own in-app compliance mapping.
References
- [1]Why Australia Abandoned Mandatory AI Guardrails for Technology-Neutral Regulation
- [2]Australia Abandons Proposed Mandatory AI Rules in New Plan
- [3]AI governance in Australia: what boards must do now the guardrails were shelved
- [4]The 10 guardrails or the 6 practices: which Australian AI framework applies to you?
More in Intelligence Brief