Australian Government agencies must complete an AI impact assessment for in-scope AI use cases — and finalise it before deployment. This sets out precisely who is bound, what the assessment contains, the three dates that actually apply, and what it means if you supply AI-enabled products to the Commonwealth.
The Policy for the responsible use of AI in government (v2.0) took effect on 15 December 2025, replacing v1.1. It applies to all non-corporate Commonwealth entities as defined by the Public Governance, Performance and Accountability Act 2013.
Corporate Commonwealth entities are encouraged to apply it, not required to. The defence portfolio and the national intelligence community sit outside it. And it is a policy, not legislation — it creates no statutory duty and is read alongside existing law.
The policy binds agencies. It does not bind their suppliers, and there is no mechanism by which it flows down. If you supply government, your obligations come from your contract — not from this policy.
"AI impact assessments become mandatory in December 2026" is the version in circulation, and it is misleading in both directions — it overstates what happens in 2026 and understates what is already required.
| When | What is required |
|---|---|
| Already in force | For an in-scope use case, the assessment must be finalised — and agreed risk treatments applied — before the solution is deployed. Assessment begins at the design stage. |
| 15 December 2026 | Agencies must have begun assessing AI use cases, and must have designated an accountable use case owner for each in-scope case and created the internal register. |
| 30 April 2027 | Existing use cases not yet assessed must be determined in or out of scope, with all relevant policy actions applied. |
The practical consequence: an agency deploying an in-scope AI system today cannot wait for 2026. The pre-deployment obligation already bites.
Agencies must assess every new AI use case against the in-scope criteria and document the determination during design. Meeting any one criterion brings the use case into scope.
Excluded: incidental and lower-risk uses — the policy names off-the-shelf features such as grammar checking and AI-assisted internet search — and genuine early experimentation that does not commit to proceeding, risk harm, or add privacy or security risk.
The Australian Government tool runs to twelve sections, structured as a threshold test followed — only where warranted — by a full assessment.
Basic information, purpose and expected benefits, inherent risk assessment, and the threshold outcome. Section 1 captures the accountable use case owner, the approving officer, the AI technology type, and — where AI automates an administrative decision — the legislative authority for it.
Section 3 rates eight inherent risk areas on consequence and likelihood, each with written rationale: service accessibility and inclusion · unfair discrimination · stereotyping or demeaning representation · harm · privacy · security (data) · security (system) · reputation and public confidence. Overall inherent risk is the highest of the eight, not an average.
If every inherent risk is rated low, the assessment can conclude at section 4 with approving officer endorsement.
Triggered where any inherent risk is medium or high: fairness · reliability and safety · privacy protection and security · transparency and explainability · contestability · human-centred values · accountability · review and next steps.
The DTA is explicit that the tool "does not replace a comprehensive risk management plan," and that agencies should not treat it as legal advice or as authorising the proposed AI use. It is a threshold and impact instrument — not the whole governance system.
Agency-level, and already in force since 30 November 2024. Accountable for implementing the policy, notifying the DTA of new high-risk use cases, and acting as the whole-of-government contact point.
A distinct, per-use-case role, required by 15 December 2026. Registers the use case with the accountable official and applies the impact assessment actions.
A register of in-scope use cases, shared with the DTA every six months. Internal — not published.
Mandatory since 28 February 2025, reviewed at least annually. Agencies are not required to list individual use cases in it.
Reported to the accountable official and the DTA, governed through a designated board or senior executive, and reviewed at least every 12 months.
Agencies may use the DTA tool or an internal process that integrates all its provisions and yields the same or higher risk outcome.
The policy imposes nothing on you directly. But your buyer now has obligations they cannot meet without information from you — and the mechanism by which that reaches you is the contract.
The DTA's procurement guidance is strongly recommended to agencies and points buyers to model AI and cyber risk clauses. Those model clauses are optional — the DTA does not require agencies to use them — but where a buyer does adopt them, one option requires the seller to maintain an AI management system in accordance with ISO/IEC 42001:2023, and to provide evidence of compliance on request within a short, specified window.
No Australian Government policy requires ISO/IEC 42001. It appears nowhere in the AI in government policy, the impact assessment tool, or the AI technical standard. What it is: the AI management system standard the Commonwealth's own model contract clauses reach for when a buyer wants a supplier to evidence AI governance — and the standard the National AI Centre's guidance states its practices are aligned with.
The commercially useful reading is simple. You cannot be "compliant with the policy" — that is not a status available to a supplier. What you can be is ready to evidence how you govern AI, on a buyer's timeline rather than your own.
No. The requirement applies to in-scope use cases only. An agency must first assess each new use case against the policy's in-scope criteria and document that determination during the design phase.
The policy expressly excludes incidental and lower-risk uses — it gives off-the-shelf features such as grammar checking and AI-assisted internet search as examples — and early-stage experimentation that does not commit to proceeding or introduce privacy or security risk.
No, and this is widely misread. Three separate timings apply. For an in-scope use case, the assessment must be finalised before the solution is deployed — that obligation is live now, not in 2026. Agencies must have begun assessing use cases by 15 December 2026. Existing use cases not yet assessed must be brought into line by 30 April 2027.
No. An agency may use the Australian Government AI impact assessment tool, or an internal process that integrates all of the tool's provisions and produces the same or a higher risk outcome for inherent and residual risk.
Not individually. Two different artefacts are often conflated. The AI transparency statement is public and must be reviewed at least annually — but agencies are not required to list individual use cases in it. The register of in-scope use cases is internal, and is shared with the DTA every six months rather than published.
Not directly. The policy binds non-corporate Commonwealth entities; it imposes no obligations on suppliers and contains no flow-down mechanism. In practice your exposure comes through the contract, not the policy.
That distinction matters commercially: what you need is not "compliance with the policy" — which is not a thing a supplier can have — but the ability to evidence your own AI governance when a buyer asks.
No, and anyone telling you otherwise is overselling. The policy, the impact assessment tool and the Australian Government AI technical standard do not reference ISO/IEC 42001 at all. The obligation sits with agencies and is met by completing the assessment.
Where 42001 does carry weight is on the supplier side: it is the AI management system standard the Commonwealth's own optional model contract clauses name when a buyer wants a seller to evidence AI governance.
We cite primary sources only — legislation, official government policy, regulator guidance and published standards. No blogs, no consultant commentary, no marketing articles. If you want to challenge anything above, these are the documents to check.
| Statement on this page | Primary source |
|---|---|
| Policy version, effective date, who is bound, in-scope criteria, accountability and register obligations | Policy for the responsible use of AI in government (v2.0) — Digital Transformation Agency |
| The 15 December 2026 date, assessment structure and the twelve sections | Australian Government AI impact assessment tool — Digital Transformation Agency |
| Model AI contract clauses, including the ISO/IEC 42001 option, and their optional status | AI model clauses & resources — BuyICT (DTA), as summarised by the Australian Government Solicitor, Legal update no. 327 |
| ISO/IEC 42001 as an AI management system standard | ISO/IEC 42001:2023 — referenced by clause. We do not reproduce the standard's text; it is copyright ISO/IEC and available for purchase from ISO or Standards Australia. |
Where we could not verify something against a primary source, we have not asserted it. Notably: Australia has no AI Act, and the mandatory guardrails for high-risk AI proposed in 2024 have not been legislated — so we make no claim about what regulation is "coming".
Whether you are an agency working through in-scope use cases or a supplier expecting the question in your next tender, a gap assessment shows where your AI governance stands and what it would take to answer credibly — in plain language, from a BSI-certified ISO/IEC 42001 Lead Implementer.