Guide

Is it legal to use AI in your Australian business?

Yes. Australia has no AI Act, so the Privacy Act, Consumer Law, Spam Act and your industry's rules apply. What is legal, use by use, and what is coming.

Want this done for you? Book a free 30-minute AI audit

In short

Yes. Australia has no standalone AI Act: the National AI Plan of 02/12/2025 relies on existing laws and regulators, so AI is legal to use in your business as long as what it does on your behalf complies with the Privacy Act, the Australian Consumer Law, the Spam Act and your profession’s rules. On Autopilot, a Melbourne AI consultancy, builds AI agents for Australian small businesses inside those rules, from $497.

Is there an AI Act in Australia?

No. The federal government’s National AI Plan, released on 02/12/2025, chose to rely on existing laws and regulators rather than a standalone AI Act, and did not pursue the mandatory guardrails it proposed in September 2024. The main AI-specific document for business is the National AI Centre’s Guidance for AI Adoption, which is voluntary. Your legal obligations come from privacy, consumer, spam and professional law applied to what your AI does.

DateWhat happenedWhat it means for a small business
05/09/2024Voluntary AI Safety Standard (10 guardrails) and a proposals paper on mandatory guardrailsVoluntary only
21/10/2025Guidance for AI Adoption replaces the voluntary standardA voluntary six-practice checklist
25/11/2025Australian AI Safety Institute announced, inside the industry departmentNo new duties for business
02/12/2025National AI Plan: existing laws and regulators, no AI ActComply with the laws you already know
20/07/2026AI consumer-safety priorities announced, including a legislated Digital Duty of Care and privacy tranche 2Watch for bills

Sources: the National AI Plan, the Guidance for AI Adoption and the minister’s AI consumer-safety priorities, checked October 2026.

The guidance’s six essential practices are: decide who is accountable, understand impacts and plan accordingly, measure and manage risks, share essential information, test and monitor, and maintain human control. For a ten-person business, that means a named owner for each AI tool, a list of what each touches, and a person checking anything that matters.

Which regulators oversee AI use in Australia?

There is no single AI regulator. The OAIC enforces the Privacy Act, the ACCC the Australian Consumer Law, and the ACMA the Spam Act and Do Not Call rules. Health practitioners also answer to AHPRA, and the TGA regulates AI software that suggests diagnoses. Financial services licensees answer to ASIC, lawyers to their legal profession regulators and courts, and tax agents to the Tax Practitioners Board. Each applies its existing rules to AI.

RegulatorLaw or roleWhat it means for AI
OAICPrivacy Act, Australian Privacy Principles, Notifiable Data BreachesPersonal information going into or out of AI is covered. Its AI guidance recommends keeping personal and sensitive information out of public AI tools
ACCCAustralian Consumer LawYou are responsible for claims your AI writes or says, and AI-written fake reviews are fake reviews
ACMASpam Act, Do Not Call RegisterAI-written marketing emails and SMS need consent, sender identification and a working unsubscribe (ACMA)
AHPRAHealth practitioner standards and advertisingThe practitioner stays responsible and AI scribes need informed consent (AHPRA); testimonials about clinical aspects are banned
TGAMedical devicesA digital scribe that suggests diagnoses or treatment must be in the ARTG
ASICFinancial services and credit licenseesGovernance must keep pace with AI use (REP 798, 29/10/2024)
Legal profession regulators and courtsConduct rules and court practice notesNo confidential or privileged information into public AI tools, and lawyers verify every output (NSW, WA and Victorian joint statement, 06/12/2024)
Tax Practitioners BoardCode of Professional ConductThe registered agent stays responsible for AI-assisted work

Yes, with conditions attached to each. The law regulates what the AI does on your behalf, not the fact that you used it. Marketing still has to meet the Spam Act, claims still have to be true under the Consumer Law, personal information is still handled under the Privacy Act, and health, legal and tax professionals stay personally responsible for AI-assisted work. The table below gives the condition for each common use.

Using AI forLegal?The condition
Drafting customer emails and repliesYesA plan that does not train on your data, sensitive details kept out, and a person checking refunds, complaints and promises
Marketing emails and SMSYesConsent, your business identified, and a free unsubscribe actioned within 5 working days
Ads, web copy and product claimsYesEvery claim must be true and able to be backed up; AI-written claims are your claims
A website chatbot or AI receptionistYesSay it is AI, keep it to answers you have approved, and hand anything unusual to a person
Asking for and replying to reviewsYesNo fake reviews, no reviewing yourself or competitors, disclose incentives, never suppress negative ones (ACCC)
Clinical notes with an AI scribeYes, with conditionsInformed patient consent noted in the record, every note checked, and any scribe that suggests diagnoses must be in the ARTG
Health practice marketingYes, with limitsNo testimonials about clinical aspects, and you are responsible for reviews on platforms you control (AHPRA)
Legal research and draftingYes, with limitsNo confidential or privileged material in public AI tools, every output verified; in NSW, no AI-generated content in affidavits, witness statements or character references (SC Gen 23)
Bookkeeping and tax workYesThe Tax Practitioners Board’s Code still applies and the registered agent stays responsible
Screening job applicantsYes, with careAnti-discrimination law applies to the decision whoever or whatever makes it; have a person review rejections
Decisions that significantly affect peopleYesFrom 10/12/2026, covered businesses must disclose substantially automated decisions in their privacy policy
AI-voiced sales callsYes, with limitsDo Not Call Register rules apply to telemarketing calls
AI-generated or edited imagesYesImages must not mislead; NSW rental listings altered to hide faults will need disclosure, expected from early 2027 (NSW Government)

On chatbots, the warning case is Moffatt v. Air Canada (2024), where a Canadian tribunal held the airline responsible for wrong refund advice from its website chatbot. It is not Australian law, but it shows the risk. On customer data, the AI plan you choose decides whether the privacy conditions are met: our guide on whether customer data is safe in ChatGPT or Claude covers plans, the never-paste list and a privacy policy template.

What are the penalties for getting it wrong?

The largest are under the Australian Consumer Law. For conduct on or after 28/03/2026, a company can be fined up to the greater of $100 million, three times the benefit gained, or 30% of adjusted turnover. Privacy penalties are now tiered, from OAIC infringement notices up to civil penalties for serious interferences with privacy, and individuals can sue for serious invasions of privacy. Spam breaches are actively enforced too.

  • Consumer Law. Conduct before 28/03/2026 falls under the earlier $50 million regime (ACCC fines and penalties).
  • Privacy Act. The 2024 amendments added OAIC infringement and compliance notices and a mid-tier civil penalty, and a statutory tort for serious invasions of privacy started on 10/06/2025 (OAIC).
  • Spam Act. Lululemon paid $702,900 in March 2026 over more than 370,000 emails, including order emails carrying marketing content, sent without an unsubscribe (ACMA). AI makes it easier to send more messages, and easier to repeat a mistake at scale.
  • Professional rules. Regulators such as AHPRA and the legal profession boards can take disciplinary action, which for a practitioner can matter more than a fine.

What AI and privacy rules are coming?

Three things are moving. From 10/12/2026, privacy policies must disclose substantially automated decisions that significantly affect people. The privacy tranche 2 exposure draft, released on 31/08/2026, proposes a fair-and-reasonable test for handling personal information and 72-hour breach notification, but is not yet in Parliament. And on 20/07/2026 the government named a legislated Digital Duty of Care among its AI consumer-safety priorities.

WhenChangeStatus
10/06/2025Statutory tort for serious invasions of privacyIn force
10/12/2026Privacy policies must disclose substantially automated decisions that significantly affect people (APP 1)Legislated
By 10/12/2026Children’s Online Privacy CodeDue
Exposure draft, 31/08/2026Privacy tranche 2: fair-and-reasonable test, 72-hour breach notification, erasure right against large platforms only, small business exemption keptConsultation closed 18/09/2026; not yet in Parliament
Announced 20/07/2026Legislated Digital Duty of CareGovernment priority
Early 2027 (expected)NSW: disclose AI-generated or altered rental listing images that hide faults, penalty up to $22,000Passed September 2026

Sources: the Parliamentary Library’s bills digest on the 2024 amendments and the Attorney-General’s Department’s privacy reform consultation, checked October 2026.

What should an Australian small business do now?

Name one person responsible for each AI tool, list what data each tool touches, move customer data onto business plans or API-based systems, write a one-page staff rule, check AI-written claims before they go out, keep marketing inside the Spam Act, keep a person on decisions that matter, and update your privacy policy before 10/12/2026. For routine AI use, that covers most of the legal risk.

  1. Name an owner for each AI tool (the guidance’s first practice).
  2. Keep a one-page AI register: tool, plan, purpose, what data goes in.
  3. Put customer data on a business plan or API-based system that is not used for training by default.
  4. Write the never-paste rule: tax file numbers, card and bank details, health information and privileged material stay out of chat apps.
  5. Tell people when they are dealing with AI. Never let a bot pose as a person.
  6. Check every claim before it is published. Prices, results and “Australia’s best” must be true and provable.
  7. Keep marketing inside the Spam Act: consent, your business name and a working unsubscribe.
  8. Keep a person on judgement calls: refunds, complaints, job application rejections, and clinical, legal, financial or tax advice.
  9. Update your privacy policy: AI use, overseas processing and, from 10/12/2026, substantially automated decisions.
  10. Check your professional body’s guidance. Our guides to AI for allied health practices, AI for law firms and AI for accountants using Xero go deeper for each profession.

Get advice before you build anything that makes decisions about people (credit, eligibility, hiring), processes health or other sensitive information at scale, gives regulated advice, or creates brand-defining assets such as a logo, where Australian law on who owns AI output is unsettled. This guide is general information, not legal advice.

How On Autopilot can help

On Autopilot builds AI agents that work inside these rules. Our AI Front Desk ($1,500 setup plus $199 a month) never pretends to be a person, never asks for payment details, never asks for more health information than your own intake form already does, and hands anything unusual to your team. The AI Lead Engine ($2,000 setup plus $499 a month) qualifies each enquiry and drafts a reply in your voice, with your rules deciding what goes out straight away and what waits for a person. Both run on the Claude API, which is not used for training by default. We are not lawyers, but the free 30-minute AI audit with Jenn Yang flags the privacy and professional limits in your industry before anything is built. Managed AI starts at $1,500 a month.

Common questions

Do I need customer consent to use AI in my business?

Not as a general rule. No Australian law requires consent simply because you use AI. Consent is needed in specific situations: health practitioners using AI scribes need informed patient consent under AHPRA's guidance, marketing emails and SMS need consent under the Spam Act, and businesses covered by the Privacy Act generally need consent to collect sensitive information such as health details. Telling customers how you use AI is still good practice.

Can my business be liable for what an AI chatbot tells a customer?

Yes. A chatbot speaks for your business, so a wrong answer about prices, refunds or warranties can be misleading conduct under the Australian Consumer Law, just as if a staff member had said it. Keep the bot to answers you have approved, have it say it is AI, keep a log of its conversations, and make sure anything outside its script goes to a person.

Do I need a licence or registration to use AI in Australia?

No licence is needed to use AI in an ordinary business. The exception is health software: under the TGA's rules, a digital scribe that suggests diagnoses or treatment the clinician did not state is a medical device and must be included in the Australian Register of Therapeutic Goods. A scribe that only transcribes is not. Licensed professions keep their existing licences and duties.

Who owns content that AI creates for my business?

Australian law has not settled this. You can use AI-written copy and AI-generated images in your business, subject to the provider's terms and the Consumer Law, but whether anyone can own and protect that output is an open question. For brand-defining assets such as a logo or signature artwork, get legal advice before relying on AI-generated work.

Want this built for your business?

Book a free 30-minute AI audit call with Jenn Yang. We map where your time goes, name the first systems worth building and give you fixed AUD prices. No obligation.

Book a free AI audit

Or have us run it for you, end to end: On Autopilot is Australia's outsourced AI department.