For a few years, "responsible AI" in Australia was a voluntary affair: principles, guidance, the occasional discussion paper, and no real consequence for ignoring all of it. That era is ending. The Commonwealth has stood up an Office of AI, announced its first mandatory AI standards in July 2026, and signalled broader AI legislation for 2027. If you run security or risk for an organisation that builds or buys AI, the sensible planning assumption is now that within two budget cycles some of your AI systems will be subject to enforceable obligations, and someone will ask you to evidence compliance.
The good news is that this is a movie CISOs have seen before. Privacy went from principles to enforcement. Critical infrastructure went from guidance to SOCI obligations. The playbook for getting ahead of a regulatory wave is well understood: inventory what you have, map it to the frameworks the regulation will almost certainly reference, close the gaps that are cheap now and expensive later, and generate evidence as you go rather than reconstructing it under deadline.
The less good news is that most organisations cannot currently answer the first question, "what AI systems do we run, and what do they touch?", with any confidence. Shadow AI has outpaced shadow IT because the barrier to adoption is a browser tab and a corporate credit card. Before any standard bites, the inventory problem has to be solved, and it is worth solving well because every subsequent obligation hangs off it.
This post sets out a pragmatic sequence for the next eighteen months: what to inventory, which frameworks to align to now (ISO/IEC 42001, the Government's AI Technical Standard, NIST AI RMF), where adversarial testing fits, and what to leave until the legislation lands. Ironbark Cyber does this work for a living, and here is the roadmap we wish more organisations had started earlier.
What has actually been announced?
Strip away the commentary and the shape is clear enough to plan against. Australia has established an Office of AI to coordinate AI policy across government. It has moved from voluntary principles toward the first mandatory AI standards, with broader AI legislation expected around 2027. Running alongside are instruments already in force for the public sector: the DTA's Policy for the responsible use of AI in government, which mandates AI Impact Assessments, transparency statements and accountable officials, and the National AI Centre's voluntary Guidance for AI Adoption for the private sector.
The direction of travel is clear even where the fine print is not yet settled: a risk-based regime, heavier obligations on higher-risk uses, and a clear expectation that organisations can demonstrate, rather than merely assert, that their AI is governed and safe. You do not need the final legislative text to start preparing for that.
Who gets captured first?
Regulation of this kind almost always tiers by risk, and the pattern from comparable regimes (including the EU AI Act, which matters directly if you export) is instructive. The obligations bite hardest where AI makes or heavily influences consequential decisions about people: credit, employment, health, essential services, safety. The precise Australian thresholds and definitions will firm up as the standards and legislation land, so treat any specific tier as provisional.
The safe planning move is not to guess the threshold precisely but to identify which of your AI systems would obviously sit in a high-risk tier under any reasonable definition, and prioritise those. If a system decides who gets a loan, who gets hired, or what a patient is told, assume it will be in scope and prepare accordingly.
Step one: solve the AI inventory
Every obligation that is coming hangs off one question: what AI do you run? Most organisations cannot answer it, because AI adoption has been bottom-up and invisible. Staff use hosted assistants through a browser. Teams wire third-party model APIs into products without a security review. Vendors quietly add AI features to tools you already licensed. This is shadow AI, and it is worse than shadow IT because it needs no installation and no budget line.
A usable AI inventory records, for each system: what it is and who owns it, what data it can reach, whether it takes consequential actions, which third parties and models sit behind it, and how it is monitored. Building it is part discovery (network, procurement, expense and SaaS data) and part conversation (asking teams what they have quietly switched on). It is unglamorous, and it is the foundation for everything else. Do it first, and keep it current.
Framework triage: what do you anchor on?
You cannot align to everything at once, so triage. Anchor on the framework that gives you the most leverage for your situation and map the others to it.
- ISO/IEC 42001 if you sell to enterprise or government and want a certificate buyers recognise. It is the most durable hedge, because whatever the legislation requires, a certified AI management system will already cover most of it.
- NIST AI RMF if you want a practical, non-certifiable structure for identifying and managing AI risk without committing to an audit yet.
- The AU AI Technical Standard if the Commonwealth is in your market. It is the technical baseline your systems will be judged against.
These overlap heavily, so the work compounds. We break down the first choice in ISO 42001 vs NIST AI RMF.
Why evidence beats assertions
The through-line of every emerging AI obligation is demonstration. It is easy to write that your guardrails work, your model resists misuse and your outputs are monitored. It is harder to prove it, and proof is what an assessor, a regulator or a nervous enterprise customer will want. That is where adversarial testing earns its place. An AI assurance claim grounded in a real red team or LLM penetration test is evidence; the same claim grounded in a policy document is an opinion. Build testing into the delivery pipeline now, so the evidence accumulates as a by-product rather than a scramble.
What to budget for in FY27
A realistic AI-compliance line for the next two cycles has four parts: the inventory and its upkeep (mostly internal effort plus some tooling); a framework alignment programme (42001 readiness or equivalent); adversarial testing of your highest-risk systems; and governance capacity, meaning someone who owns AI risk and keeps the apparatus running. None of it is enormous individually. The cost of skipping it is doing all of it at once under a legislative deadline.
A 90-day starting plan
- Days 1–30: stand up the AI inventory and get executive sponsorship for AI governance. Identify your obviously-high-risk systems.
- Days 31–60: pick your anchor framework and run a gap assessment against it. Assign an owner for AI risk.
- Days 61–90: adversarially test your two or three highest-risk AI systems, and start closing the cheap gaps. Book an executive AI security briefing so the board understands what is coming.
None of this requires the final legislation to exist. The organisations that will handle Australia's AI regulation calmly are the ones treating the next eighteen months as preparation rather than waiting. Ironbark Cyber runs the inventory-to-evidence sequence above for organisations that would rather be early than surprised. Being early, as every previous regulatory wave has shown, is much cheaper than being caught out.
FAQ
Frequently asked questions
When do Australia's mandatory AI standards take effect?
The Commonwealth announced its first mandatory AI standards in 2026 and has signalled broader AI legislation around 2027. Exact scope and thresholds are still firming up, so plan on a risk-based regime arriving within two budget cycles.
Which of our AI systems will be regulated first?
Regimes like this tier by risk, with the heaviest obligations on AI that makes or heavily influences consequential decisions about people. Credit, employment, health, essential services, safety. Prioritise any system that would obviously sit in a high-risk tier.
What should we do before the legislation lands?
Build an AI inventory, pick an anchor framework (ISO 42001, NIST AI RMF or the AU AI Technical Standard) and run a gap assessment, adversarially test your highest-risk systems, and assign an owner for AI risk. Most of that work counts toward whatever the law requires.
Does ISO 42001 help with the coming Australian regulation?
Yes. A certified AI management system already covers most of what a risk-based AI regime is likely to require, so certifying now is largely pre-compliance work you will not have to repeat.
Put this into practice
A senior Ironbark Cyber consultant will scope your engagement on a free 30-minute call and give you a fixed quote within one business day.