Skip to main content
Rules Mate

Who must comply with Mandatory AI guardrails for high-risk AI (in development)?

The applicability test for Mandatory AI guardrails for high-risk AI (in development), computed across 35 industries, 9 business structures and 6 size bands.

Short answer: Only if

Applies when the business has automated decisions about people.

What the obligation is

Australian Mandatory Guardrails for High Risk AI Settings — Treasury consultation in 2024/2025.

In 2024 the Department of Industry, Science and Resources consulted on proposed mandatory guardrails for AI in high-risk settings and published the Voluntary AI Safety Standard. The government's National AI Plan, released on 2 December 2025, did not adopt a standalone AI Act. Its stated approach is to build on existing, largely technology-neutral laws, with each regulator remaining responsible for AI harms in its own domain, supported by a new AI Safety Institute that monitors and tests advanced AI. The plan lists targeted measures instead: enforceable online safety industry codes, criminalising non-consensual deepfake material, clarifying how the Australian Consumer Law applies to AI products, and reviews of copyright, healthcare and medical device software rules. For a business, the practical obligation today is to apply privacy, consumer, workplace, anti-discrimination and sector laws to its AI systems; the National AI Centre's Guidance for AI Adoption is the government's voluntary reference.

The applicability test

Applies when the business has automated decisions about people.

How the regulator frames it: No business is currently bound by an AI-specific mandatory guardrails law. Developers and deployers of AI systems remain bound by the existing laws that apply to what the system does (for example privacy, consumer protection, workplace, anti-discrimination, online safety and therapeutic goods law).

What triggers it: Status only: a mandatory regime would apply only if the government introduces and Parliament passes legislation. Until then, deploying AI triggers the obligations of whichever existing law governs the activity.

Jurisdiction: Commonwealth law, so the test is the same in every state and territory.

Which industries are in or out

Outcome across the 35 industries Rules Mate maps (35 of 35: no).

The answer is the same in every industry: no. Industry does not change who must comply.

Business structure and size

Structure does not change the answer across all industries: for every structure the answer is "no".

Size does not change the answer across all industries: at every size band the answer is "no".

Worked examples

Each line is one run of the Rules Mate applicability engine for a single business profile, with the reason the engine gives:

  • Pty Ltd company in real estate agents with 6–19 employees, turnover $1M–$3M: does not apply. Requires automated decisions about people.

Answers that bring it into scope

Starting from a small or large professional services company that does not otherwise meet the test, each of these single facts changes the engine's answer:

  • The business uses AI or automated decision-making about individuals: it then applies (uses AI / automated decisions about people).

What you must do, and when

When due
No commencement date. The National AI Plan (2 December 2025) relies on existing laws and targeted reforms; monitor DISR and the AI Safety Institute for any change of position.
Frequency
Ongoing
Evidence to keep
AI system inventory and risk register; records showing how privacy, consumer law and sector obligations were assessed for each AI use; human oversight and testing records; alignment with the Guidance for AI Adoption (voluntary).
Status
Upcoming (not yet in force)
Priority
Medium

Penalty for not complying

Maximum penalty: No AI-specific penalty exists. Penalties arise under the existing law breached by an AI system (for example the Privacy Act 1988 or the Australian Consumer Law).

Audit or assurance level

Rules Mate has not yet classified the audit or assurance level for this obligation. Any audit, review or certification requirement is set by the regulator source listed below.

Where it sits in the corpus

Rules Mate tracks 3 published obligations tagged "ai", 1 of them rated critical. For a professional services Pty Ltd company with 6–19 employees operating in every state, 0 of those apply outright. This obligation is rated medium priority, and is an ongoing duty.

Regulator, legislation and tools

Free tools that help with this obligation:

Questions

Who must comply with Mandatory AI guardrails for high-risk AI (in development)?
Applies when the business has automated decisions about people.
Does Mandatory AI guardrails for high-risk AI (in development) apply to sole traders?
No. Across every industry and every size band, the engine's answer for a sole trader is: no.
Does Mandatory AI guardrails for high-risk AI (in development) apply to businesses with 1–5 employees?
No (1–5 employees, turnover $100K–$1M).
When is "Mandatory AI guardrails for high-risk AI (in development)" due?
No commencement date. The National AI Plan (2 December 2025) relies on existing laws and targeted reforms; monitor DISR and the AI Safety Institute for any change of position.

Related

Sources

Computed by the Rules Mate applicability engine from the published obligation corpus; facts last checked 3 October 2026. Rules Mate is not a law firm and this is general information, not legal advice. Confirm your position with the regulator source or a qualified adviser before acting.