Voluntary AI Safety Standard (10 Guardrails)¶
Purpose: Detailed control catalogue for implementing Australia's 10 AI safety guardrails Audience: Governance, risk, compliance and technical teams | Time: 45-60 minutes for full review
Australia's Voluntary AI Safety Standard (VAISS) provides 10 practical guardrails organisations can adopt to develop, deploy and use AI safely and responsibly.
The National AI Centre, within the Department of Industry, Science and Resources, published VAISS on 5 September 2024. The Department updated the online publication in December 2025 to point readers to the newer Guidance for AI Adoption.
The standard is voluntary and does not create new legal duties. It complements existing Australian law by helping organisations identify risks, controls and relevant obligations.
Importantly, the 10 guardrails are consistent with leading international standards and frameworks, including:
Current status
On 21 October 2025 the National AI Centre released the Guidance for AI Adoption, which sets out 6 essential practices (AI6) for responsible AI governance and adoption. The Department describes it as updated and simplified guidance that evolves VAISS.
The AI6 implementation guidance includes an appendix that maps the original VAISS controls to the new practices. The 10 guardrails are best used as a detailed control set and historical reference, especially where contracts, risk registers or external frameworks still refer to VAISS.
A consultation process for a proposed VAISS v2 ran in early 2025. As at 22 July 2026, the Government's publication catalogue does not contain a standalone VAISS v2. Use the published AI6 guidance for current implementation work and the original VAISS guardrails where a detailed or legacy mapping is useful.
Australian Standards for AI framework announced — July 2026
On 15 July 2026, the Government announced plans to legislate a framework for large data centres and AI training, including future mandatory requirements for large AI data centres. The announcement does not withdraw or make the VAISS guardrails mandatory. Organisations can continue using these guardrails and AI6 as non-binding guidance while complying with existing law. (Prime Minister of Australia; PM&C Office of AI, accessed 22 July 2026)
Why this matters¶
Adopting the guardrails early helps organisations build trust, resilience and regulatory readiness. By embedding these practices now, businesses can:
- 🛡️ Reduce risks from bias, errors and misuse of AI
- 🤝 Strengthen transparency and customer confidence
- 🚀 Build evidence of systematic AI governance and risk management
- ⭐ Demonstrate leadership in responsible AI adoption
The 10 guardrails¶
- Establish, implement and publish an accountability process, including governance, internal capability and a strategy for regulatory compliance.
- Establish and implement a risk management process to identify and mitigate risks.
- Protect AI systems, and implement data governance measures to manage data quality and provenance.
- Test AI models and systems to evaluate model performance and monitor the system once deployed.
- Enable human control or intervention in an AI system to achieve meaningful human oversight across the life cycle.
- Inform end users about AI-enabled decisions, interactions with AI and AI-generated content.
- Establish processes for people impacted by AI systems to challenge use or outcomes.
- Be transparent with other organisations across the AI supply chain about data, models and systems so they can address risks.
- Keep and maintain records to allow third parties to assess compliance with the guardrails.
- Engage stakeholders and evaluate their needs and circumstances, with a focus on safety, diversity, inclusion and fairness.
What the guardrails do
- ✅ Encourage transparency and accountability for AI systems
- ✅ Require risk assessment, testing and human oversight before and after deployment
- ✅ Promote record-keeping and supplier due-diligence across the AI supply chain
- ✅ Emphasise stakeholder engagement and ongoing monitoring as systems evolve
How this maps to the 6 essential practices (AI6)¶
The Guidance for AI Adoption condenses the 10 VAISS guardrails into 6 essential practices. The table below is a practical SafeAI-Aus summary, not a substitute for the detailed crosswalk in the official AI6 implementation guidance.
| AI6 practice | Closest VAISS guardrails and themes |
|---|---|
| Decide who is accountable | 1. Accountability; 9. Records |
| Understand impacts and plan accordingly | 2. Risk management; 7. Challenge processes; 10. Stakeholder engagement |
| Measure and manage risks | 2. Risk management; 3. System and data protection |
| Share essential information | 6. End-user information; 8. Supply-chain transparency; 9. Records |
| Test and monitor | 3. System and data protection; 4. Testing and monitoring |
| Maintain human control | 5. Human control; 7. Challenge processes |
How to use this mapping
- 📊 Use AI6 as your top-level framework when explaining AI governance to boards, executives and regulators
- 📋 Use the 10 guardrails in this page as a control library when:
- building or updating AI policies and standards
- designing AI risk assessments and risk registers
- writing contractual clauses and supplier questionnaires
- 🔗 Check the official AI6 crosswalk before claiming exact equivalence between a VAISS control and an AI6 action
How to use this in your business
- ✅ Assess each AI initiative against all 10 guardrails and apply controls proportionate to its risks
- 📝 Update policies and procurement to reflect supplier alignment with the guardrails
- 🔄 Integrate testing, documentation and oversight into your normal change-management
- 📅 Review systems at least annually or on material change
SME-scaled implementation approach¶
While the 10 guardrails apply to all organisations, SMEs can adopt them at different maturity levels. The levels below are a practical SafeAI-Aus scaling model, not part of the official VAISS.
Guardrail 1: Establish, implement and publish an accountability process
- Minimum: Designate an AI responsible person
- Better: Create simple AI governance policy
- Best: Regular board/leadership AI updates
Guardrail 2: Establish and implement a risk management process
- Minimum: Complete a documented AI risk and impact assessment
- Better: Review risks on material change and at a defined cadence
- Best: Integrate AI risks and controls into enterprise risk management
Guardrail 3: Protect AI systems and implement data governance measures
- Minimum: Apply existing privacy, cybersecurity and data governance controls
- Better: Add controls for AI-specific data, model and prompt risks
- Best: Verify data provenance, access controls and security measures throughout the AI life cycle
Guardrail 4: Test AI models and systems
- Minimum: Test against documented acceptance criteria before deployment
- Better: Monitor performance and review after incidents or material changes
- Best: Use ongoing, risk-proportionate evaluation and independent review where warranted
Guardrail 5: Enable human control or intervention
- Minimum: Define when and how a person can pause, override or escalate the system
- Better: Require meaningful human review for significant decisions
- Best: Design and test risk-proportionate human oversight across the life cycle
Guardrail 6: Inform end-users regarding AI-enabled decisions
- Minimum: Tell people when they interact with AI or receive AI-generated content
- Better: Explain the AI system's role, capabilities and limitations in plain language
- Best: Tailor accessible explanations and disclosures to affected stakeholder needs and risk
Guardrail 7: Establish processes for people to challenge use or outcomes
- Minimum: Provide a channel to question or complain about AI use or outcomes
- Better: Document response, escalation and correction processes
- Best: Offer review independent of the original AI-assisted decision where the risk warrants it
Guardrail 8: Be transparent with other organisations across the AI supply chain
- Minimum: Ask suppliers for system purpose, limitations, data and testing information
- Better: Put information-sharing and incident obligations in contracts
- Best: Use ongoing assurance or audit for material suppliers and higher-risk systems
Guardrail 9: Keep and maintain records
- Minimum: Maintain an AI inventory with an owner, purpose, risk rating and review date
- Better: Record assessments, controls, tests, incidents and approvals
- Best: Maintain evidence proportionate to external assurance and regulatory needs
Guardrail 10: Engage your stakeholders and evaluate their needs
- Minimum: Identify people and groups who may be affected
- Better: Seek feedback during design, deployment and review
- Best: Use inclusive engagement or co-design where impacts or stakeholder needs warrant it
Regulatory outlook and the future of the guardrails¶
As at 22 July 2026, Australia still has no general AI Act and VAISS remains voluntary.
The National AI Plan retains existing technology-neutral laws and sector regulators — including privacy, consumer law, financial services, safety and anti-discrimination frameworks — as the foundation for managing AI-related harms. The Australian AI Safety Institute is operating within the Department of Industry, Science and Resources to analyse AI capabilities, risks and harms and support regulators and agencies.
In July 2026, the Government separately announced plans for Australian Standards for AI. Published material focuses on a proposed framework for large data centres and AI training, including future mandatory requirements for large AI data centres. The final scope, duties and commencement arrangements remain subject to design, National Cabinet consideration and legislation.
The 2024 consultation on mandatory guardrails for high-risk AI remains useful policy history, but its proposed guardrails and definition of high-risk AI are not current legal requirements.
In practical terms, organisations should:
- treat the 10 guardrails and AI6 as voluntary guidance, not proof of legal compliance
- focus on integrating these controls into existing privacy, risk, safety, security and compliance processes
- monitor the Office of AI, AI Safety Institute, NAIC and relevant sector regulators for changes.
Assess risk by use and context¶
The 2024 mandatory-guardrails proposal is not a current legal risk classification. For operational decisions, use the current AI6 screening and risk-assessment approach instead.
Do not assume a use is lower-risk because the technology is common. Assess the specific purpose, data, affected people, degree of human reliance and the likelihood, severity and scale of harm. Reassess when the system, use or operating context changes.
Further reading and official resources¶
- Guidance for AI Adoption: implementation guidance (National AI Centre)
- Voluntary AI Safety Standard – Overview and guardrails (Department of Industry)
- The 10 guardrails – full guidance and examples (Department of Industry)
- Legal landscape for AI in Australia (Department of Industry)
- Archived 2024 consultation: mandatory guardrails for high-risk settings (Australian Government)
- Australian AI Safety Institute
Legal status
VAISS and AI6 are voluntary guidance and do not replace legal advice. Existing Australian laws and sector-specific obligations continue to apply.