Brad Ferris.au
The Director's LensEdition 16 · AI Regulation

The Standard Will Arrive Before the Statute

Australia will regulate AI through standards rather than a standalone Act, with legislation flagged for early 2027. Most boards will diarise the 2027 date. It is the wrong one, because a standard becomes the benchmark for reasonable care long before any Act commences.

Published17 July 2026
Read5 minutes
All editions
The Governance Story

On 15 July, the federal government set out its national AI framework in a statement titled AI in Australia's Interests: a new Office of AI inside the Department of the Prime Minister and Cabinet, a set of Australian Standards for AI rather than a standalone AI Act, obligations on data centres to underwrite their own power supply, and protection for Australian creative work against training without consent. National Cabinet considers it in August. Legislation is flagged for early next year. Most board papers will record this as a 2027 item.

That is the wrong date, and the reason is the mechanism rather than the politics. A standards-led framework does not behave like a statute. Standards are drafted by technical committees rather than debated in Parliament. They are incorporated into procurement schedules, contract warranties, insurance conditions and regulator guidance long before any Act commences. And once a recognised Australian standard exists, it becomes the reference point for what a reasonable board should have been doing, which means it can shape a duty-of-care argument well ahead of its own legal commencement. The clock a director should be watching started in August, not in 2027.

The second thing worth noticing is the framing. The government sold this as pro-investment: faster approvals, clearer compliance, and an explicit line that AI will create jobs rather than take them. Read that as a director rather than as a citizen. When a government positions AI regulation as a tailwind, the political and reputational cost of not adopting rises alongside the cost of adopting badly. Doing nothing stops being the conservative option. Boards that have been using regulatory uncertainty as grounds to defer have just lost the argument, because direction, mechanism and rough timing have all now been given.

There is a third feature that belongs in the risk register rather than the strategy paper. Data-centre approvals, copyright, energy and skills are being pulled into a single office inside PM&C. The coordination is genuinely useful; fragmented policy has been a real cost to Australian business. It also means an organisation's AI compliance assumptions now hang on one political channel, and machinery-of-government changes are not rare events here. A framework concentrated in one office can be re-scoped by a reshuffle.

Questions I'd Ask in the Boardroom
  • Our AI plans assume the rules land in 2027. If a recognised Australian standard exists well before that, and our insurer, our largest customer or a regulator starts referencing it, what changes for us, and when would we find out?
  • National Cabinet considers this framework in August. Who is representing our industry in that process, are we connected to them, and have we put a view in, or will we simply receive the standard and react to it?
  • If training on Australian creative work now requires consent, which of our current or planned AI uses touches content we do not own? Can anyone in the business answer that today, or would we be discovering it under pressure?
  • We have deferred AI decisions partly on regulatory uncertainty. The government has now given us direction, mechanism and timing. Is that reason still valid, or are we using it to avoid a harder conversation about capability?
  • Our AI capability depends on Australian compute. If data centres must underwrite their own power and curb draw at peak, what does that do to the cost and availability we have assumed in our business case?
Red Flags & Watch Points
  • An AI programme whose compliance milestone is keyed to the legislation date. The standard is the operative benchmark and it arrives first, so a plan built around early 2027 is already late.
  • Nobody in the organisation can say what its AI tools were trained on. A consent rule for Australian creative work turns that from an interesting question into a live exposure.
  • The board hearing about the framework through a law firm's client alert rather than from management. When a national regulatory development in your own operating environment reaches the board via external commentary, the horizon-scanning function is not working.
  • Treating a standards-led approach as lighter-touch because it is not an Act. It is less predictable, not less demanding, precisely because it can move without a parliamentary process.
  • Data-centre energy obligations discussed as a supplier's problem. If your AI capability rests on Australian compute, its cost and siting constraints have just become a regulatory variable in your own plan.
Opportunity & Risk Balance

The upside is unusually accessible. Australia has told the market its direction, its mechanism and roughly its timing, which is more than most jurisdictions have given their boards. A board that spends one meeting before Christmas mapping where the organisation touches the four named areas, compute, copyright, energy and skills, and assigns a named owner to track the standards as they are drafted, will be ready before the standard exists rather than scrambling once it does. The work is cheap, it is largely a matter of asking management for an inventory, and it converts a regulatory unknown into an ordinary planning input. Organisations that do it will still be deploying while competitors pause to work out what applies to them.

The downside has the familiar shape of regulatory drift. Nothing goes wrong for eighteen months. The framework is noted, filed and assigned to nobody, because the legislation is not due until 2027 and there is always something closer. Then a standard is published, a major customer writes it into a contract schedule, an insurer asks a question the organisation cannot answer, and the board discovers it holds an AI estate nobody has mapped against a benchmark that is already operative. The work at that point is the same work, done under time pressure, in public, with a duty-of-care argument running against you rather than for you. The cost is not the compliance. It is the position you are in when you start.

Director's Recommendation
My position

Reset the date. Take this off the 2027 shelf and treat August as the live moment, because the standard, not the Act, is what your contracts, your insurer and any future duty-of-care argument will reference, and it is being shaped now while nobody from your board is in the room. Do three things concretely. Ask management for an inventory of where the organisation touches compute, copyright, energy and skills, including an honest answer on what the AI tools already in use were trained on. Assign one named owner to track the standards as they are drafted and report to the board quarterly, rather than waiting for a commencement date to trigger activity. And retire regulatory uncertainty as a reason for deferring AI decisions, because the government has now supplied direction, mechanism and timing, and continuing to plead uncertainty is a choice rather than a constraint. None of this requires knowing what the standard will say. It requires the board to be positioned to answer on the day it says it.

Researched and drafted by Brad's agentic AI team. Edited and published by Brad Ferris.