Voluntary AI Safety Standard, plain-English definition from TheAICommand
← Glossary
Definition

What is the Voluntary AI Safety Standard?

The Voluntary AI Safety Standard is Australian guidance published by the National AI Centre on 5 September 2024, setting 10 voluntary guardrails for organisations that develop or deploy AI. It creates no new legal duties. On 21 October 2025 the government published Guidance for AI Adoption, which condenses the guardrails into 6 essential practices.

Quick answer

The Voluntary AI Safety Standard is Australian guidance published by the National AI Centre on 5 September 2024. It sets 10 voluntary guardrails covering accountability, risk management, data governance, testing, human oversight, disclosure, contestability, supply chain transparency, record keeping and stakeholder engagement. It creates no new legal duties.

What is the Voluntary AI Safety Standard?

The Voluntary AI Safety Standard is practical guidance for Australian organisations that develop or deploy artificial intelligence. It was published by the National Artificial Intelligence Centre on 5 September 2024 and last updated on 2 December 2025. It sits inside the Safe and Responsible AI agenda, which followed the government's 2023 consultation on safe and responsible AI in Australia.

The standard consists of 10 voluntary guardrails that apply across the AI supply chain. In order, they require an organisation to establish, implement and publish an accountability process covering governance, internal capability and regulatory compliance; establish a risk management process to identify and mitigate risks; protect AI systems and implement data governance covering data quality and provenance; test models and systems before deployment and monitor them afterwards; enable human control or intervention to achieve meaningful oversight across the lifecycle; inform end users about AI-enabled decisions, AI interactions and AI-generated content; establish processes for people affected by AI systems to challenge use or outcomes; be transparent with other organisations across the supply chain about data, models and systems; keep records that let third parties assess compliance; and engage stakeholders with a focus on safety, diversity, inclusion and fairness.

The word voluntary is doing real work. The standard says plainly that being voluntary, it does not create new legal duties about AI systems or their use. Adopting it fully means adopting all 10, and the guardrails are framed as ongoing activities rather than a one-off project.

Who does the Voluntary AI Safety Standard apply to?

All organisations throughout the AI supply chain, but the first version deliberately focuses on AI deployers rather than developers. A deployer is an individual or organisation that supplies or uses an AI system to provide a product or service, whether that deployment is internal to the organisation or reaches customers and other people outside it.

That focus was a response to consultation feedback. Deployers make up the majority of Australian organisations using AI and had the greatest need for practical guidance, so each guardrail also carries procurement guidance for working with suppliers whose systems you are deploying.

One change matters more than the rest. On 21 October 2025 the government published Guidance for AI Adoption, which the department describes as updated and simplified guidance that evolves the Voluntary AI Safety Standard. It condenses the 10 guardrails into 6 essential practices: decide who is accountable, understand impacts and plan accordingly, measure and manage risks through AI-specific risk management, share essential information, test and monitor, and maintain human control. It also extends the audience to teams that build or customise AI systems, and ships in a foundations edition for low-risk and early AI use and an implementation guidance edition for complex and higher-risk use. The standard pages remain live, each carrying a banner pointing to the newer guidance. Anyone writing an AI policy in 2026 should be working from the newer document and treating the standard as the fuller reference behind it.

Where does the Voluntary AI Safety Standard fit alongside Australian regulation?

It fills a gap rather than creating an obligation. Australia has no dedicated AI Act, so AI use is governed by instruments that were written without AI in mind: privacy, consumer law, anti-discrimination, work health and safety, corporations law, and the prudential standards. The guardrails give organisations a consistent way to demonstrate they have thought about AI risk inside those existing duties.

The alignment is deliberate. The guardrails map to AS ISO/IEC 42001:2023, the international standard on AI management systems, and to the United States NIST AI Risk Management Framework 1.0, so an organisation building one control set can satisfy several audiences. For regulated entities the overlap with existing obligations is heavy: guardrail 3 on protecting AI systems and data governance runs alongside CPS 234, while guardrails 1, 2 and 8 on accountability, risk management and supply chain transparency sit close to the operational risk and service provider expectations in CPS 230.

The introduction is also candid about intent. The standard sets expectations for what future legislation may look like while the government considers options on mandatory guardrails for high-risk settings, and the first 9 voluntary guardrails were aligned closely with those proposed mandatory guardrails. Adopting them now is partly preparation.

What should practitioners do about the Voluntary AI Safety Standard?

Start at guardrail 1, which the standard itself nominates as the foundation. Name a single accountable owner for AI, write an AI strategy, and identify the training the organisation needs. Leaders cannot delegate or outsource accountability for safe and responsible AI, which is the same principle the prudential standards apply to operational risk.

Then build the two artefacts everything else depends on. An AI inventory, because guardrail 9 expects records that let a third party assess compliance and you cannot govern a system nobody has listed. And a risk assessment process anchored to how each system is actually used, because guardrail 2 asks you to assess AI impact and risk based on how you use the system. An internal drafting assistant and an AI screen in hiring are not the same risk, whatever the licence says.

Work the disclosure and contestability guardrails early, since they are the ones most often missed. If AI shapes a decision about a person, tell them, and give them a route to challenge it. For anyone assessing where their organisation currently sits, the AI readiness assessment covers governance and oversight against the same themes.

Bottom line

The Voluntary AI Safety Standard is practical Australian guidance rather than law, setting guardrails that run from accountability and risk management through data governance, testing, human control, disclosure, contestability, supply chain transparency, record keeping and stakeholder engagement. Voluntary is doing real work in that sentence, because the standard creates no new legal duties, but Australia has no dedicated AI Act, so the guardrails are how an organisation demonstrates it has thought about AI risk inside the duties it already carries under privacy, consumer, anti-discrimination, work health and safety, corporations and prudential law. Its alignment with the international AI management system standard and the United States risk management framework means one control set can satisfy several audiences, and adopting the guardrails now is partly preparation for what mandatory rules may look like. Start with the accountability guardrail and a named owner, build the AI inventory and a risk assessment anchored to how each system is actually used, and work the disclosure and contestability guardrails early because they are the ones most often missed.

TheAICommand. Intelligence, At Your Command.*

TheAICommand. Intelligence, At Your Command.

Frequently asked questions

Is the Voluntary AI Safety Standard mandatory?
No. The standard states that being voluntary, it does not create new legal duties about AI systems or their use. It asks organisations to commit to understanding their AI use, engaging stakeholders, running risk and impact assessments, testing, and adopting appropriate controls. Existing law still applies regardless.
Has the Voluntary AI Safety Standard been replaced?
It has been evolved rather than withdrawn. On 21 October 2025 the government published Guidance for AI Adoption, which condenses the 10 guardrails into 6 essential practices and extends the audience to developers as well as deployers. The standard pages remain live and carry a banner pointing to the newer guidance.
What are the 6 essential practices in Guidance for AI Adoption?
Decide who is accountable, understand impacts and plan accordingly, measure and manage risks by implementing AI-specific risk management, share essential information, test and monitor, and maintain human control. Two versions exist, a foundations edition for low-risk and early AI use, and an implementation guidance edition for complex and higher-risk use.
Does the standard align with international frameworks?
Yes. The guardrails are aligned with AS ISO/IEC 42001:2023, the leading international standard on AI management systems, and with the United States NIST AI Risk Management Framework 1.0. The National AI Centre says this supports organisations operating internationally by aligning Australian practice with other jurisdictions and their expectations.
Who does the Voluntary AI Safety Standard apply to?
All organisations across the AI supply chain, though the first version focuses on AI deployers rather than developers. A deployer is an individual or organisation that supplies or uses an AI system to provide a product or service, whether the deployment is internal to the organisation or external.

Primary sources

← Back to the glossary

General information and education only. Not legal, compliance, financial, or professional advice. Always confirm obligations against the primary source and current regulator guidance.