AI is increasingly being used to make or support significant decisions across financial services, healthcare, defence, government and professional services. Billions of dollars of investment are pouring into the technology. Its rapid adoption is creating new commercial opportunities, but it is also exposing gaps in governance, contracting and risk allocation. In many areas, the technology has developed faster than the policies, systems and legal frameworks intended to manage but governments and regulators are catching up.
Australia’s regulatory approach is taking shape. The establishment of an Office of Artificial Intelligence within the Department of the Prime Minister and Cabinet in July 2026 marked a shift towards more coordinated national oversight. The Office will lead the development of Australian Standards for AI and bring together policy work across areas including energy and data centres, intellectual property, productivity, education and labour rights.
While the National AI Plan (December 2025) confirmed that Australia will not introduce a dedicated AI Act, regulation will work through existing legal frameworks, with targeted sector-specific interventions layered on top. That means the obligations that matter are already in force: privacy law, director duties, financial services licensing, healthcare device approvals, employment law, and contract liability. AI does not sit outside them.
For boards and executive teams, the implication is clear. Governance frameworks, contracts, procurement arrangements and liability structures that were designed for a pre-AI operating environment require review. The question is not whether AI creates legal risk. It is whether that risk has been correctly identified, allocated and documented.
Key issues we are tracking
Governments around the world are moving quickly to shape the future of artificial intelligence, balancing the need to encourage innovation and investment with concerns about privacy, intellectual property, cybersecurity, competition, consumer protection and the impact of AI on jobs and society.
The Australian Government's approach is centred on making Australia an attractive destination for AI investment while maintaining trust in the technology. The sector is expected to generate billions of dollars in development and become a major contributor to the economy.
Rather than introducing a standalone AI Act, the Government is considering world-leading regulation, strengthening existing laws, developing national AI standards and coordinating policy across areas including data centres, energy, copyright, privacy, education and workforce development. The establishment of the Office of Artificial Intelligence within the Department of the Prime Minister and Cabinet reflects a whole-of-government strategy designed to provide greater regulatory certainty for businesses and investors.
As governments continue to refine their approach, organisations should expect ongoing legislative reform, new regulatory guidance and evolving technical standards.
Agentic AI, systems that initiate actions, make decisions and interact with third parties without direct human instruction, is the most significant current challenge to Australian liability frameworks. The common-law doctrine of agency assumes the agent is a legal person acting within a defined scope of authority. Agentic systems satisfy neither assumption, yet can bind organisations contractually, breach consumer law, mishandle personal information and cause harm at scale and speed.
The exposures are not hypothetical. International precedent is already forming, as in the Air Canada chatbot case where the airline was held responsible for representations made by its AI chatbot. The risks run across the Australian Consumer Law, the Privacy Act, tort, contract and directors’ duties. Each requires deliberate legal design: who is responsible, on what authority, and what evidence supports that position if it is later challenged.
ASIC has made clear that AI governance is a board-level concern. Its October 2024 report Beware the Gap: Governance Arrangements in the Face of AI Innovation identified a widening gap between AI adoption and risk management among AFS and credit licensees. ASIC’s 2026 Key Issues Outlook reinforces the message, flagging AI-driven decision-making and AI-powered cybercrime as system-wide risks, and governance and directors’ duties failures remain an enduring enforcement priority.
Director duties under the Corporations Act do not carve out technology decisions. A board that has not actively considered how AI is being used in its organisation, what risks it creates, and how accountability is assigned may face difficulty defending that position if harm follows. The governance obligation is not technical. It is one of informed oversight and documented decision-making.
Three distinct IP questions are now live for organisations using or building AI systems.
First, whether AI-generated outputs are protectable under Australian copyright law. Current law requires a human author. The position on AI-assisted works, where a human provides substantial creative direction, is less settled.
Second, whether training data used to develop AI models was lawfully acquired and licensed. Organisations that have trained models on publicly available material may carry undisclosed copyright risk.
Third, what rights attach to embeddings, model weights and proprietary AI systems. The IP strategy for AI assets requires deliberate structuring rather than reliance on default positions.
The Privacy and Other Legislation Amendment Act 2024 introduced new requirements relating to automated decision-making, including obligations to disclose when significant decisions are made using automated processes. Those obligations do not commence until 10 December 2026, giving organisations a closing window to map their automated decision-making, update privacy policies and prepare customer-facing disclosures. Further reform is anticipated.
Organisations that use AI to make or inform decisions about individuals, including credit assessments, claims processing, recruitment screening and healthcare triage, need to understand how existing and incoming obligations apply and what changes are required to data governance, privacy policies and customer communications.
Read more: The copyright dilemma of AI: a deep dive into the new Copyright and AI Consultation Paper
The Therapeutic Goods Administration has continued to refine its Software as a Medical Device (SaMD) framework. Organisations developing AI-enabled diagnostics, clinical decision support tools or automated monitoring systems must navigate lifecycle governance, post-market surveillance obligations and real-world performance monitoring requirements that apply specifically to adaptive algorithms.
The regulatory pathway for healthcare AI in Australia is becoming more defined, but it remains technically demanding. Early engagement with the regulatory framework at the design stage is materially less costly than retrospective remediation.
Organisations operating in defence or critical infrastructure sectors face a distinct and more demanding regulatory environment. The Security of Critical Infrastructure Act 2018 imposes uplifted obligations in relation to risk management, incident reporting and system integrity. AI systems that are embedded in critical operational environments engage those obligations directly.
Defence procurement arrangements involving AI, autonomous systems or AI-enabled capabilities require careful legal structuring to address safety obligations, liability allocation and compliance with Commonwealth procurement frameworks.
How we advise
Our advice on AI and legal design draws on practice depth across intellectual property, privacy and data, technology and digital innovation, employment, financial services, healthcare regulation, defence and government. We advise from the position that AI is a legal infrastructure problem, not a technology compliance problem. The questions are who is responsible, how is that documented, and whether the organisation can defend its decisions if they are scrutinised.
Advising boards and executive teams on AI governance structures that satisfy ASIC's current expectations and withstand external scrutiny.
Reviewing and redesigning governance frameworks where AI systems are involved in consequential decisions.
Conducting liability assessments across AI procurement, development and deployment arrangements to identify and resolve accountability gaps.
Supporting boards in meeting AI-related audit, reporting and ESG disclosure obligations.
Drafting and negotiating AI procurement agreements that correctly allocate liability for system failures, data issues and third-party model risks.
Advising on the legal implications of SaaS-based AI tools, third-party model access arrangements and embedded AI in commercial products.
Structuring AI development agreements between deployers, developers and data providers.
Developing defensible IP strategies for AI models, training data, embeddings and AI-generated outputs.
Advising on copyright risk arising from training data acquisition and the use of publicly available material.
Structuring IP ownership arrangements in AI development joint ventures and collaborative research projects.
Advising on Privacy Act obligations as they apply to automated decision-making and profiling.
Reviewing data governance frameworks for organisations deploying AI systems that process personal information at scale.
Assisting with privacy impact assessments for AI systems prior to deployment.
Advising on SaMD regulatory pathways, lifecycle governance and post-market obligations for healthcare AI systems.
Assisting defence and critical infrastructure operators with SOCI Act obligations as they apply to AI-enabled systems.
Advising financial services licensees on AI-related obligations under the Corporations Act, ASIC guidance and the Financial Accountability Regime.