Australian Government · AI Policy

Need to meet the AI impact assessment requirement?

Australian Government agencies must complete an AI impact assessment for in-scope AI use cases — and finalise it before deployment. This sets out precisely who is bound, what the assessment contains, the three dates that actually apply, and what it means if you supply AI-enabled products to the Commonwealth.

The three dates What suppliers need

Verified against primary sources · Last reviewed 29 July 2026

Who the policy actually applies to

The Policy for the responsible use of AI in government (v2.0) took effect on 15 December 2025, replacing v1.1. It applies to all non-corporate Commonwealth entities as defined by the Public Governance, Performance and Accountability Act 2013.

Corporate Commonwealth entities are encouraged to apply it, not required to. The defence portfolio and the national intelligence community sit outside it. And it is a policy, not legislation — it creates no statutory duty and is read alongside existing law.

The distinction most commentary gets wrong

The policy binds agencies. It does not bind their suppliers, and there is no mechanism by which it flows down. If you supply government, your obligations come from your contract — not from this policy.

Three dates, not one

"AI impact assessments become mandatory in December 2026" is the version in circulation, and it is misleading in both directions — it overstates what happens in 2026 and understates what is already required.

WhenWhat is required
Already in forceFor an in-scope use case, the assessment must be finalised — and agreed risk treatments applied — before the solution is deployed. Assessment begins at the design stage.
15 December 2026Agencies must have begun assessing AI use cases, and must have designated an accountable use case owner for each in-scope case and created the internal register.
30 April 2027Existing use cases not yet assessed must be determined in or out of scope, with all relevant policy actions applied.

The practical consequence: an agency deploying an in-scope AI system today cannot wait for 2026. The pre-deployment obligation already bites.

Which use cases are in scope

Agencies must assess every new AI use case against the in-scope criteria and document the determination during design. Meeting any one criterion brings the use case into scope.

Excluded: incidental and lower-risk uses — the policy names off-the-shelf features such as grammar checking and AI-assisted internet search — and genuine early experimentation that does not commit to proceeding, risk harm, or add privacy or security risk.

What an AI impact assessment contains

The Australian Government tool runs to twelve sections, structured as a threshold test followed — only where warranted — by a full assessment.

Stage one: sections 1–4

Basic information, purpose and expected benefits, inherent risk assessment, and the threshold outcome. Section 1 captures the accountable use case owner, the approving officer, the AI technology type, and — where AI automates an administrative decision — the legislative authority for it.

Section 3 rates eight inherent risk areas on consequence and likelihood, each with written rationale: service accessibility and inclusion · unfair discrimination · stereotyping or demeaning representation · harm · privacy · security (data) · security (system) · reputation and public confidence. Overall inherent risk is the highest of the eight, not an average.

If every inherent risk is rated low, the assessment can conclude at section 4 with approving officer endorsement.

Stage two: sections 5–12

Triggered where any inherent risk is medium or high: fairness · reliability and safety · privacy protection and security · transparency and explainability · contestability · human-centred values · accountability · review and next steps.

What it does not do

The DTA is explicit that the tool "does not replace a comprehensive risk management plan," and that agencies should not treat it as legal advice or as authorising the proposed AI use. It is a threshold and impact instrument — not the whole governance system.

What sits around the assessment

Accountable official

Agency-level, and already in force since 30 November 2024. Accountable for implementing the policy, notifying the DTA of new high-risk use cases, and acting as the whole-of-government contact point.

Accountable use case owner

A distinct, per-use-case role, required by 15 December 2026. Registers the use case with the accountable official and applies the impact assessment actions.

Internal register

A register of in-scope use cases, shared with the DTA every six months. Internal — not published.

Public transparency statement

Mandatory since 28 February 2025, reviewed at least annually. Agencies are not required to list individual use cases in it.

High-risk use cases

Reported to the accountable official and the DTA, governed through a designated board or senior executive, and reviewed at least every 12 months.

Choice of method

Agencies may use the DTA tool or an internal process that integrates all its provisions and yields the same or higher risk outcome.

What this means if you sell AI to government

The policy imposes nothing on you directly. But your buyer now has obligations they cannot meet without information from you — and the mechanism by which that reaches you is the contract.

The DTA's procurement guidance is strongly recommended to agencies and points buyers to model AI and cyber risk clauses. Those model clauses are optional — the DTA does not require agencies to use them — but where a buyer does adopt them, one option requires the seller to maintain an AI management system in accordance with ISO/IEC 42001:2023, and to provide evidence of compliance on request within a short, specified window.

The honest position on ISO/IEC 42001 and government

No Australian Government policy requires ISO/IEC 42001. It appears nowhere in the AI in government policy, the impact assessment tool, or the AI technical standard. What it is: the AI management system standard the Commonwealth's own model contract clauses reach for when a buyer wants a supplier to evidence AI governance — and the standard the National AI Centre's guidance states its practices are aligned with.

The commercially useful reading is simple. You cannot be "compliant with the policy" — that is not a status available to a supplier. What you can be is ready to evidence how you govern AI, on a buyer's timeline rather than your own.

Frequently asked questions

Does every use of AI need an impact assessment?

No. The requirement applies to in-scope use cases only. An agency must first assess each new use case against the policy's in-scope criteria and document that determination during the design phase.

The policy expressly excludes incidental and lower-risk uses — it gives off-the-shelf features such as grammar checking and AI-assisted internet search as examples — and early-stage experimentation that does not commit to proceeding or introduce privacy or security risk.

Is the December 2026 date a deadline for completing assessments?

No, and this is widely misread. Three separate timings apply. For an in-scope use case, the assessment must be finalised before the solution is deployed — that obligation is live now, not in 2026. Agencies must have begun assessing use cases by 15 December 2026. Existing use cases not yet assessed must be brought into line by 30 April 2027.

Must agencies use the DTA tool?

No. An agency may use the Australian Government AI impact assessment tool, or an internal process that integrates all of the tool's provisions and produces the same or a higher risk outcome for inherent and residual risk.

Do agencies have to publish their AI use cases?

Not individually. Two different artefacts are often conflated. The AI transparency statement is public and must be reviewed at least annually — but agencies are not required to list individual use cases in it. The register of in-scope use cases is internal, and is shared with the DTA every six months rather than published.

We are a supplier, not an agency. Does this apply to us?

Not directly. The policy binds non-corporate Commonwealth entities; it imposes no obligations on suppliers and contains no flow-down mechanism. In practice your exposure comes through the contract, not the policy.

That distinction matters commercially: what you need is not "compliance with the policy" — which is not a thing a supplier can have — but the ability to evidence your own AI governance when a buyer asks.

Does ISO/IEC 42001 satisfy the impact assessment requirement?

No, and anyone telling you otherwise is overselling. The policy, the impact assessment tool and the Australian Government AI technical standard do not reference ISO/IEC 42001 at all. The obligation sits with agencies and is met by completing the assessment.

Where 42001 does carry weight is on the supplier side: it is the AI management system standard the Commonwealth's own optional model contract clauses name when a buyer wants a seller to evidence AI governance.

Where every statement on this page comes from

We cite primary sources only — legislation, official government policy, regulator guidance and published standards. No blogs, no consultant commentary, no marketing articles. If you want to challenge anything above, these are the documents to check.

Statement on this pagePrimary source
Policy version, effective date, who is bound, in-scope criteria, accountability and register obligations Policy for the responsible use of AI in government (v2.0) — Digital Transformation Agency
The 15 December 2026 date, assessment structure and the twelve sections Australian Government AI impact assessment tool — Digital Transformation Agency
Model AI contract clauses, including the ISO/IEC 42001 option, and their optional status AI model clauses & resources — BuyICT (DTA), as summarised by the Australian Government Solicitor, Legal update no. 327
ISO/IEC 42001 as an AI management system standard ISO/IEC 42001:2023 — referenced by clause. We do not reproduce the standard's text; it is copyright ISO/IEC and available for purchase from ISO or Standards Australia.

Where we could not verify something against a primary source, we have not asserted it. Notably: Australia has no AI Act, and the mandatory guardrails for high-risk AI proposed in 2024 have not been legislated — so we make no claim about what regulation is "coming".

Ready to evidence how you govern AI?

Whether you are an agency working through in-scope use cases or a supplier expecting the question in your next tender, a gap assessment shows where your AI governance stands and what it would take to answer credibly — in plain language, from a BSI-certified ISO/IEC 42001 Lead Implementer.

Book a gap assessment About ISO 42001 certification