What is happening?

AI is increasingly being used to make or support significant decisions across financial services, healthcare, defence, government and professional services. Billions of dollars of investment are pouring into the technology. Its rapid adoption is creating new commercial opportunities, but it is also exposing gaps in governance, contracting and risk allocation. In many areas, the technology has developed faster than the policies, systems and legal frameworks intended to manage but governments and regulators are catching up.

Australia’s regulatory approach is taking shape. The establishment of an Office of Artificial Intelligence within the Department of the Prime Minister and Cabinet in July 2026 marked a shift towards more coordinated national oversight. The Office will lead the development of Australian Standards for AI and bring together policy work across areas including energy and data centres, intellectual property, productivity, education and labour rights.

While the National AI Plan (December 2025) confirmed that Australia will not introduce a dedicated AI Act, regulation will work through existing legal frameworks, with targeted sector-specific interventions layered on top. That means the obligations that matter are already in force: privacy law, director duties, financial services licensing, healthcare device approvals, employment law, and contract liability. AI does not sit outside them.

For boards and executive teams, the implication is clear. Governance frameworks, contracts, procurement arrangements and liability structures that were designed for a pre-AI operating environment require review. The question is not whether AI creates legal risk. It is whether that risk has been correctly identified, allocated and documented.

Key issues we are tracking

How we advise

Our advice on AI and legal design draws on practice depth across intellectual property, privacy and data, technology and digital innovation, employment, financial services, healthcare regulation, defence and government. We advise from the position that AI is a legal infrastructure problem, not a technology compliance problem. The questions are who is responsible, how is that documented, and whether the organisation can defend its decisions if they are scrutinised.