This is a concept website · Enquire about this domain

aiconsultancy.com.auAdopting AI, practice by practice

Entry 01 · The six practices

The Guidance for AI Adoption and its six essential practices

The Guidance for AI Adoption is the Australian Government’s guidance for responsible AI use: six essential practices, first published by the National AI Centre on 21 October 2025, beginning with deciding who is accountable. Its current web versions are dated 5 May 2026, and both ask an organisation to work through all six without doing everything at once; the foundations version adds that each practice can be fitted to the organisation’s size, uses of AI and risks.

Published by
National AI Centre, Department of Industry, Science and Resources
First published
21 October 2025; web versions dated 5 May 2026
Written for
Organisations using or building AI, from first trials to higher-risk systems

General information, not legal advice. The official place to check is the National AI Centre’s essential AI practices page, read for this guide on 9 October 2026.

Two versions

Foundations, and implementation

The same six practices come in two versions. The foundations version is written for teams that are starting to use AI, using it in low-risk ways, new to AI governance, or after practical guidance in a business setting. The implementation version suits teams that build or customise AI, use it in more complex ways, handle higher-risk uses, need tighter controls and oversight, or want more detailed guidance.

Some practices belong to the whole organisation, such as having an AI policy; others belong to each separate use of AI. The guidance stresses that one tool can carry quite different risks in different hands: drafting marketing emails with it is not the same as using it to assess job applications.

Before October 2025

The Voluntary AI Safety Standard

The guidance had a predecessor: the Voluntary AI Safety Standard, published on 5 September 2024. The department’s page for it, updated on 2 December 2025, now says the 2025 guidance is an updated, simplified version for industry that “evolves” the earlier standard. This site works from the current guidance, so the older standard’s own guardrails are not set out here.

The practices

Each practice, and where it starts

Each practice in the foundations version opens with “getting started” actions and then lists next steps. The guidance says there is no need to do everything at once.

The six practices in the foundations version. The middle column gives every getting-started action; the right column is a selection of the next steps, all of which are on the National AI Centre’s foundations page.
PracticeGetting startedAmong the next steps
1. Decide who is accountableMake a senior leader the overall AI governance owner, with the authority and understanding to oversee every use of AI. Write an AI policy that tells staff about AI risks and how to handle them.Name an accountable person for each AI system in use. Where vendors, developers or integrators are involved, settle who is responsible for each part of the supply chain.
2. Understand impacts and plan accordinglyAssess which groups of people a system may affect, paying particular attention to vulnerable or marginalised groups. Set up channels for people to report problems with, or challenge, AI decisions, matched to how serious the impact could be.Involve staff and customers early and keep involving them; watch patterns in feedback for problems that repeat.
3. Measure and manage risksCreate a risk screening process that flags systems and uses carrying unacceptable risk or needing more governance attention.Assess the risks of each use and plan how to reduce them; investigate AI-related incidents and learn from them.
4. Share essential informationKeep an AI register of every system and how it is used, including AI bought in and AI embedded in other tools such as human resources or customer engagement software. Make telling people about AI use the normal practice.Record and explain what each system can and cannot do; set up ways to explain outcomes that affect people.
5. Test and monitorWhen buying, ask the supplier for proof of proper testing. Test before deploying. Monitor after deploying, at a level that matches the risk. Extend data governance and cybersecurity practice to AI.Stress-test a system before others find its weak points; consider testing by a third party where a use needs extra attention.
6. Maintain human controlMatch human oversight to how much autonomy a system has and how much is at stake. Build in clear points where people can pause, override, roll back or shut it down.Train the people who oversee AI; keep critical functions able to run if a system fails or is retired.

Practice 1

Why accountability comes first

The guidance gives its reason plainly. AI systems can make automated decisions with a large effect on people, communities and businesses, and their complexity can leave gaps where nobody clearly owns the outcome, even though the organisation as a whole remains accountable.

The implementation version asks an organisation to name who is accountable, across the organisation and including contractors and third-party providers, for the operation of its AI management system, including:

  • the policies, practices and procedures for safe and responsible AI;
  • building and deploying every AI system, including ongoing human control and oversight;
  • overseeing how third parties develop and use AI systems;
  • testing AI systems across the organisation;
  • handling concerns, challenges and requests for redress;
  • how the AI management system performs and keeps improving.

Both versions ask for clear records of what is done under each practice, because good records support audits, reviews and improvement.

Practice 5’s first step, asking a supplier for proof, is worked through in buying an AI product; practice 4’s call to be open about AI use meets the consumer law in claims about AI.

Dated 15 July 2026

What has been announced since

On 15 July 2026 the Prime Minister announced that the Government will establish “a set of Australian Standards for AI”. He said they would bring the expectations for large AI data centres announced in March “into one regulatory framework”, “Clear, consistent and mandatory”, and that the Government would aim to bring the legislation to Parliament early next year: early 2027. The speech did not say how those standards would relate to the Guidance for AI Adoption, so check the National AI Centre’s pages for the current version before relying on either.

The guidance itself is already tied to the law: the National AI Centre says the practices line up with Australia’s AI Ethics Principles and relevant international standards, and that every law already governing a business applies to its AI. Two places where it is specific are privacy when training AI and governance for licensees.

Back to the registerThe six practices at a glance, each with an owner line.