Guidance for AI Adoption (AI6) – 6 Essential Practices¶
Purpose: Primary framework for implementing responsible AI governance in Australia Audience: Executive, governance, risk and compliance teams | Time: 30-45 minutes
Status
Federal government guidance published on 21 October 2025. It is the current general, non-binding guidance for responsible AI adoption in Australia.
Australian Standards for AI framework announced — July 2026
On 15 July 2026, the Government announced plans to legislate a framework for large data centres and AI training, including future mandatory requirements for large AI data centres. A new Office of AI has been established within PM&C to coordinate its design. National Cabinet is expected to consider the approach in August 2026, with standards expected to be legislated in early 2027.
The announcement does not withdraw or make AI6 mandatory. Organisations can continue using AI6 as current non-binding guidance while complying with existing law. (Prime Minister of Australia; PM&C Office of AI, accessed 22 July 2026)
What is the Guidance for AI Adoption?¶
On 21 October 2025 the National AI Centre (NAIC), within the Department of Industry, Science and Resources, released the Guidance for AI Adoption. It sets out six essential practices ("AI6") for responsible AI governance and adoption by organisations operating in Australia.
The Department describes this guidance as an updated and simplified framework that evolves the Voluntary AI Safety Standard (VAISS). The VAISS publication and its 10 voluntary guardrails remain available as a more detailed control catalogue.
There are two versions of the guidance:
- Foundations – for organisations getting started with AI or using AI in lower-risk ways
- Implementation guidance – detailed practices for organisations building or customising AI, using complex or higher-risk systems, or needing stronger controls
The official implementation guidance links to supporting resources including an AI screening tool, AI policy template and AI register template.
The six essential practices (AI6) in plain language¶
1. Decide who is accountable¶
Every AI use case should have clear owners.
- Nominate an executive accountable official for AI across the organisation
- Define who is responsible for approving, operating and monitoring each AI system
- Clarify decision rights between IT, business units, risk/compliance and vendors
- Make sure accountability appears in policies, job descriptions and governance forums (e.g. risk committee, digital steering group)
For SMEs
Even if you only have a few people, write down who:
- signs off AI use
- checks risks
- responds if something goes wrong
2. Understand impacts and plan accordingly¶
Before deploying AI, understand what could go wrong and who could be affected.
- Identify people and groups who may be impacted (customers, staff, suppliers, vulnerable communities)
- Consider impacts on privacy, safety, fairness, security, employment and reputation
- Classify each use case as lower-risk or higher-risk based on context and consequences
- Plan mitigations for high-impact scenarios, including fallback processes if the AI fails
For SMEs
Use a simple AI screening / intake form to document purpose, data, users and potential harms before you start building or buying.
3. Measure and manage risks¶
Treat AI use like any other material business risk.
- Add AI-related risks to your enterprise risk register (privacy, cyber, safety, conduct, IP, regulatory)
- Align to existing frameworks (privacy management, cyber security, WHS, consumer law, financial services)
- Define risk appetite for AI in different areas (e.g. marketing vs safety-critical operations)
- Record controls and safeguards and review them regularly
For SMEs
Start with a small standard set of AI risks and controls and reuse them across systems rather than reinventing the wheel each time.
4. Share essential information¶
Be open about how you use AI and what it means for people.
- Tell people when they are interacting with, or significantly affected by, an AI system
- Provide plain-language explanations of what the system does and its limitations
- Maintain an AI system register covering purpose, data sources, key risks, controls and owners
- Be transparent with suppliers and partners about expectations and seek equivalent transparency in return
For SMEs
A simple AI register and standard wording in privacy notices, contracts and internal policies will go a long way.
5. Test and monitor¶
AI systems must be tested before use and monitored over time.
- Test systems against accuracy, robustness, bias, security and usability criteria before going live
- Use realistic data and scenarios, including edge cases and stress tests
- Set up ongoing monitoring and periodic review, not "set and forget"
- Define incident thresholds and escalation paths (when to pause, roll back or retire a system)
For SMEs
For each important AI system, agree a short list of "things we will measure" and a cadence for checking them.
6. Maintain human control¶
People remain responsible for decisions and outcomes.
- Decide where humans must remain "in the loop" or "on the loop" (reviewing outputs, overruling decisions)
- Ensure staff using AI have training, guidance and authority to question or override it
- Avoid over-reliance on AI, especially in high-stakes domains (safety, financial hardship, employment, access to services)
- Make it easy for customers and staff to challenge or appeal outcomes influenced by AI
For SMEs
Be explicit about which decisions AI can never make on its own and build that into processes and systems.
How AI6 relates to the 10 voluntary guardrails¶
The Department describes the Guidance for AI Adoption as updated and simplified guidance that evolves VAISS. It:
- Condenses the 10 guardrails into 6 practices
- Groups detailed controls under the 6 practices and adds guidance for developers as well as deployers
- Includes a detailed VAISS-to-implementation-guidance crosswalk in its appendix
On SafeAI-Aus:
- The Voluntary AI Safety Standard (10 Guardrails) page is maintained as a detailed control catalogue and historical reference
- This AI6 page provides the current, higher-level framework that Australian organisations are encouraged to follow
If your organisation has already aligned to the 10 guardrails, you do not need to start again. Instead:
- Map existing policies, controls and risk registers into the 6 practices
- Use NAIC's implementation guidance to fill gaps
- Update internal documentation to reference AI6 as the primary framework
Where AI6 sits in the broader Australian landscape¶
AI6 aligns with:
- The Australian Government's AI Ethics Principles
- Existing technology-neutral laws and regulators (privacy, consumer law, workplace, safety, anti-discrimination, financial services, etc.)
- International AI governance frameworks such as ISO/IEC 42001 and the NIST AI Risk Management Framework
The National AI Plan released in December 2025 retained existing laws and sector regulators as the foundation for addressing AI-related risks, supported by voluntary guidance including AI6. The Australian AI Safety Institute is now operating within the Department of Industry, Science and Resources to analyse AI capabilities, risks and harms and support regulators and agencies.
The separate Australian Standards for AI announced in July 2026 are still being designed. Published material focuses on a proposed framework for large data centres and AI training; it does not turn AI6 into a mandatory standard or create general duties for organisations using AI.
See Australian Government AI Policy and Frameworks for the current policy position.
How to use this page
For most Australian organisations, a practical approach is:
- 📊 Adopt AI6 as your top-level framework for AI governance and risk management
- 📋 Use the SafeAI-Aus toolkit (AI use policy, AI risk register, vendor checklist and project intake templates) to operationalise the 6 practices
- 🔗 Refer to the 10 guardrails when you need more granular control statements or when external documents still reference VAISS
- 🔄 Review at least annually and after material changes against updates from NAIC, sector regulators, privacy and consumer regulators, the Office of AI and the AI Safety Institute
Official sources¶
- Guidance for AI Adoption: implementation guidance (National AI Centre)
- Voluntary AI Safety Standard (Department of Industry, Science and Resources)
- National AI Plan: Keep Australians safe (Department of Industry, Science and Resources)
- Australian AI Safety Institute
Legal status
AI6 is voluntary guidance and does not replace legal advice. Existing Australian laws and sector-specific obligations continue to apply.