Answer index

Glossary terms

125 questions answered. Plain-English definitions of Australian regulatory terms.

  • Are model Codes of Practice legally binding?

    Not by themselves. A model Code of Practice must be approved as a code of practice in a jurisdiction before it has legal effect there. Approved codes are not law, but they are admissible in court proceedings, and courts may rely on them to determine what is reasonably practicable. From What are the model WHS laws?

  • Are the model WHS laws actually law?

    No. The model WHS laws are a template. They only become legally binding when the Commonwealth, a state or a territory enacts them as its own legislation. Safe Work Australia maintains the model laws but does not regulate or enforce them. Enforcement sits with the WHS regulator in each jurisdiction. From What are the model WHS laws?

  • Can an accountable person be held responsible for AI failures?

    FAR does not name AI, but accountability follows the area of responsibility. If an AI system sits within an accountable person's remit and produces harm through poor governance, that can be treated as a failure to act with care, skill, and diligence. Ownership and oversight of AI systems should therefore be clearly mapped. From What is Financial Accountability Regime?

  • Can an award or contract provide less than the NES?

    No. The Fair Work Ombudsman states that other workplace instruments cannot provide for conditions less than the National Employment Standards, including an award, an employment contract, an enterprise agreement or another registered agreement. Those instruments also cannot exclude the NES. The NES applies regardless of what instrument covers the employee. From What is the Fair Work Act 2009?

  • Can I rely on AI to find ART cases for a submission?

    Only with verification. AI tools can fabricate case names, party names, and tribunal references, or misstate the outcome of a real case. Always confirm each citation against the published decision on AustLII or the Tribunal record before relying on it, and de-identify any claim material before entering it into an AI tool. From What is Administrative Review Tribunal?

  • Can I use AI to draft SRC Act determinations?

    AI can assist with summarising evidence, drafting plain-English explanations, and structuring analysis against the statutory tests. It cannot make the determination. An authorised delegate must decide, a human must review every AI-assisted draft, and claimant data must be de-identified before it enters any general AI tool. From What is Safety, Rehabilitation and Compensation Act 1988?

  • Can prompt injection be fully prevented?

    Probably not. OWASP says prompt injection is possible due to the nature of generative AI, and that given the stochastic influence at the heart of the way models work, it is unclear if there are fool-proof methods of prevention. The realistic goal is impact reduction through least privilege, human approval for high-risk actions, output validation, segregation of external content and adversarial testing. From What is prompt injection?

  • Can psychosocial hazards combine with each other?

    Yes. Safe Work Australia warns that psychosocial hazards may interact or combine to create new, changed or higher risks. Some hazards may not create risk on their own but may do so when combined with others, and some may only create risk on their own when severe. Assessing hazards one at a time therefore understates the real exposure workers face. From What are psychosocial hazards?

  • Can the ART review a Comcare decision before reconsideration?

    No. The SRC Act uses a three-tier process: determination, then reconsideration producing a reviewable decision, then ART review. Under section 64 of the SRC Act, the ART can only review reviewable decisions. A first-tier determination must go through internal reconsideration before the Tribunal has jurisdiction to review it. From What is Administrative Review Tribunal?

  • Do Australian rules cover agentic AI specifically?

    No Australian instrument names agentic AI. The Guidance for AI Adoption, published 21 October 2025, sets six essential practices including maintaining human control, and it is voluntary. Existing duties still apply, so an agent acting inside a regulated process inherits that process and its obligations. From What is agentic AI?

  • Do psychosocial hazards apply to AI at work?

    They can. The Australian Work Health and Safety Strategy 2023 to 2033 warns that while automation may reduce physical risk, workers overseeing that technology could face more psychosocial hazards from increased or more complex interpersonal interactions. AI changes job demands, job control and role clarity, all named hazards. From What are psychosocial hazards?

  • Do the Australian Privacy Principles apply to small businesses?

    Generally the APPs bind organisations with an annual turnover above $3 million. Smaller operators are still caught where an exception applies, including private sector health service providers, credit reporting bodies, businesses that buy or sell personal information, Commonwealth contracted service providers, and businesses that have opted in. From What are the Australian Privacy Principles?

  • Do the model WHS laws cover artificial intelligence?

    They do not mention AI, but the duties are technology neutral and apply to it. The Australian Work Health and Safety Strategy 2023 to 2033 names the rise of AI and automation as an emerging challenge, warning that new technology needs appropriate design and oversight so workers face no new WHS risks. From What are the model WHS laws?

  • Does a human making the final call remove the obligation?

    Not automatically. APP 1.7 reaches a computer program that does a thing substantially and directly related to making a decision, not only one that decides. The OAIC's issues paper puts exactly this to consultation, using an example where staff rely on a chatbot's eligibility recommendation before deciding. From What is automated decision-making?

  • Does a refusal to decide count as automated decision-making?

    Yes. APP 1.9 states that making a decision includes refusing or failing to make a decision, and that doing a thing includes refusing or failing to do a thing. A system that automatically rejects, defers or silently drops an application is therefore within scope. From What is automated decision-making?

  • Does APP 8 apply when staff use an overseas AI chatbot?

    APP 8 sets out the steps an APP entity must take before personal information is disclosed overseas. Where an AI tool is hosted outside Australia and staff enter personal information into it, that is a cross-border disclosure, so the APP 8 accountability and reasonable steps obligations need to be worked through first. From What are the Australian Privacy Principles?

  • Does AUSTRAC use AI?

    AUSTRAC's AI transparency statement says it has not yet deployed AI that directly interacts with the public or is involved in decision making and administrative action without human intervention. It is trialling enterprise generative AI, and applies controls so no sensitive or classified information enters public generative AI systems. From What is AUSTRAC?

  • Does Comcare use artificial intelligence to make decisions?

    No. Comcare's AI Transparency Statement says it does not at present use AI for any of its core functions, and that AI is not used in compliance, auditing or decision-making processes without human oversight. Staff are not permitted to input sensitive employee or customer information into AI technologies. From What is Comcare?

  • Does CPS 230 apply to AI vendors?

    CPS 230 does not mention AI, but AI vendors and AI-enabled services fall within its service provider obligations. Where an AI tool supports a critical operation, the arrangement can be a material service provider arrangement, requiring a formal agreement, service levels, monitoring and oversight of fourth-party dependencies. From What is APRA CPS 230?

  • Does CPS 234 apply to AI tools and vendors?

    Yes, where an AI tool or vendor processes, stores or transmits regulated information assets it falls inside the information security framework CPS 234 governs. Third-party AI services attract the same assurance expectations as any other outsourced information asset, and AI failures can be material incidents. From What is APRA CPS 234?

  • Does DDO apply to AI-driven product distribution?

    Yes. AI used to target, score, or personalise offers is part of distribution, so it must stay consistent with the target market determination. An automated model that reaches consumers outside the target market does not escape DDO. The reasonable steps obligation applies regardless of automation. From What is Design and Distribution Obligations?

  • Does de-identification make it safe to put claims data into an AI chatbot?

    No. The OAIC notes information can be at risk of re-identification even when de-identified or anonymised, and that once data enters a generative AI system it is very difficult to control and potentially impossible to remove. Best practice is to keep personal and sensitive information out of public tools. From What is de-identification?

  • Does FAR replace other obligations like director duties?

    No. FAR sits alongside existing duties, including directors' duties under the Corporations Act and licensing obligations. It adds a specific personal accountability layer for senior executives in regulated financial entities. Practitioners should treat it as additional to, not a substitute for, their other regulatory obligations. From What is Financial Accountability Regime?

  • Does RAG stop AI from hallucinating?

    No. RAG reduces fabrication by grounding answers in retrieved passages, and the 2020 paper reported more factual language than a parametric-only baseline. The model can still misread a passage, blend sources, or answer confidently when retrieval returns nothing useful. Citations make errors easier to catch, not impossible. From What is retrieval-augmented generation (RAG)?

  • Does removing names and addresses de-identify a dataset?

    Not on its own. The OAIC warns that removing name, address or other direct identifiers alone may not result in de-identification for the purposes of the Privacy Act. A second step is needed, either altering other identifying information or applying controls and safeguards in the data access environment. From What is de-identification?

  • Does retrieval-augmented generation increase prompt injection risk?

    It can. NIST identifies RAG systems and internet-connected agents as the classic settings for indirect prompt injection, because the model pulls in outside resources an attacker may control. A poisoned document in a knowledge base becomes an instruction the model may follow at retrieval time. From What is prompt injection?

  • Does the ART decide the matter fresh or just check for error?

    The ART conducts merits review, which means it stands in the shoes of the original decision maker and decides the correct or preferable decision on the material before it. This is broader than judicial review, which examines only whether the decision was lawful. The ART can affirm, vary, set aside, or remit the decision. From What is Administrative Review Tribunal?

  • Does the EU AI Act apply to Australian organisations?

    It can. Article 2 extends the regulation to providers and deployers established in a third country where the output produced by the AI system is used in the Union, and to anyone placing an AI system on the Union market. Australian establishment alone does not put an organisation outside it. From What is the EU AI Act?

  • Does the Fair Work Act 2009 regulate AI in the workplace?

    The Act does not name AI. It bites indirectly, through unfair dismissal tests that ask whether a dismissal was harsh, unjust or unreasonable, through general protections, through award consultation obligations on major change, and through the right to disconnect where AI-enabled tooling extends contact beyond working hours. From What is the Fair Work Act 2009?

  • Does the Fair Work Commission have rules about using AI in a case?

    The President published an exposure draft Guidance Note on the use of generative AI in Commission cases in March 2026, with comments due by 10 April 2026. The draft would require a party who used generative AI to prepare a document to tell the Commission and to check that all details are correct and relevant. From What is the Fair Work Commission?

  • Does the NIST AI RMF matter in Australia?

    Yes, indirectly. Australia's Voluntary AI Safety Standard, published on 5 September 2024, states it draws on and is aligned with AS ISO/IEC 42001:2023 and NIST AI RMF 1.0, with each guardrail requirement aligned to relevant international and local standards. The department has since published Guidance for AI Adoption, on 21 October 2025, which it describes as evolving that standard. Australian legal obligations still come from Australian law. From What is the NIST AI Risk Management Framework?

  • Does the OAIC handle the statutory tort for privacy invasions?

    No. The statutory tort for serious invasions of privacy commenced on 10 June 2025 and sits in Schedule 2 of the Privacy Act, but the OAIC states it does not have a direct role in administering the tort. Individuals pursuing it are directed to seek independent legal advice. From What is the Office of the Australian Information Commissioner?

  • Does the Privacy Act 1988 cover AI tools?

    Yes. The OAIC states the Privacy Act applies to all uses of AI involving personal information, covering both what an organisation puts into an AI system and what the system generates. Inferred or hallucinated information about an identifiable person is still personal information and must be handled under the Australian Privacy Principles. From What is the Privacy Act 1988?

  • Does the Privacy Act 1988 cover employee records?

    In some situations the Act does not cover an organisation's handling of employee records connected to a current or former employment relationship. The exemption is narrow and does not remove other obligations, so employers running AI over workforce data need to confirm whether the exemption applies before relying on it. From What is the Privacy Act 1988?

  • Does the standard align with international frameworks?

    Yes. The guardrails are aligned with AS ISO/IEC 42001:2023, the leading international standard on AI management systems, and with the United States NIST AI Risk Management Framework 1.0. The National AI Centre says this supports organisations operating internationally by aligning Australian practice with other jurisdictions and their expectations. From What is the Voluntary AI Safety Standard?

  • Does using AI for transaction monitoring change my AML/CTF obligations?

    No. The obligation to apply appropriate risk-based controls remains with the reporting entity, not the tool. If you use AI for monitoring or customer due diligence, you must be able to explain its outputs, govern the model, keep records of escalation decisions, and maintain human oversight so the system supports rather than replaces your compliance program. From What is AML/CTF regime?

  • Has prompt injection caused a real vulnerability?

    Yes. CVE-2025-32711, published 11 June 2025, records an AI command injection flaw in Microsoft 365 Copilot allowing an unauthorised attacker to disclose information over a network. It is classified CWE-74 and scored 9.3 critical by Microsoft and 7.5 high by NIST in the national vulnerability database. From What is prompt injection?

  • Has the OAIC published guidance on AI?

    Yes. The OAIC has published guidance on privacy and the use of commercially available AI products, and separate guidance on privacy and developing and training generative AI models. Its stated position is that the Privacy Act applies to all uses of AI involving personal information, covering both inputs and generated outputs. From What is the Office of the Australian Information Commissioner?

  • Has the Voluntary AI Safety Standard been replaced?

    It has been evolved rather than withdrawn. On 21 October 2025 the government published Guidance for AI Adoption, which condenses the 10 guardrails into 6 essential practices and extends the audience to developers as well as deployers. The standard pages remain live and carry a banner pointing to the newer guidance. From What is the Voluntary AI Safety Standard?

  • How do I challenge a Comcare decision under the SRC Act?

    First seek reconsideration of the determination through the original decision-maker. If you still disagree, apply to the Administrative Review Tribunal, which reviews Commonwealth workers compensation decisions on the merits. The ART replaced the Administrative Appeals Tribunal in October 2024. Check current timeframes on the ART website before lodging. From What is Safety, Rehabilitation and Compensation Act 1988?

  • How does CPS 230 relate to business continuity for AI tools?

    CPS 230 requires business continuity plans that keep critical operations within defined tolerance levels through severe but plausible disruptions, tested regularly. If a critical operation depends on an AI model or vendor, the entity should define tolerances for that dependency and confirm a workable fallback if the AI fails. From What is APRA CPS 230?

  • How is agentic AI different from a chatbot?

    A chatbot returns text for a person to act on. An agent takes the action itself, calling tools, writing files, sending messages or moving money, often across many turns. That shifts the control question from whether the output is accurate to whether the action was authorised. From What is agentic AI?

  • How is the Fair Work Commission different from the Fair Work Ombudsman?

    They are separate bodies. The Commission is the tribunal that hears and decides matters, sets minimum wages, maintains awards and approves enterprise agreements. The Fair Work Ombudsman provides information about workplace rights and obligations and enforces compliance with those laws. The Ombudsman does not investigate unfair dismissal claims. From What is the Fair Work Commission?

  • How long do I have to apply to the ART for a Comcare decision?

    You generally have 60 days from receiving the reviewable decision, which is the decision made after reconsideration under the SRC Act. The Tribunal can grant extensions in limited circumstances, but you should treat the 60-day period as firm and lodge early rather than relying on an extension being granted. From What is Administrative Review Tribunal?

  • How long does an employee have to lodge an unfair dismissal claim?

    An employee must apply to the Fair Work Commission within 21 days of the dismissal. Eligibility also requires at least 6 months of service with that employer, or 12 months where the employer is a small business employer with fewer than 15 employees. The Commission decides the case. From What is the Fair Work Act 2009?

  • How many Australian Privacy Principles are there?

    There are 13 Australian Privacy Principles, set out in Schedule 1 of the Privacy Act 1988. They run from open and transparent management of personal information at APP 1 through to correction of personal information at APP 13, covering collection, notification, use, disclosure, cross-border transfer, quality, security and access. From What are the Australian Privacy Principles?

  • How many businesses does Tranche 2 bring in?

    AUSTRAC stated in March 2026 that from 1 July the number of businesses it regulates would grow from around 19,000 to close to 100,000 nationwide. AUSTRAC described the reforms as the most significant overhaul of Australia's AML/CTF framework in more than 20 years. From What are the AML/CTF Tranche 2 reforms?

  • How quickly must we notify APRA of a security incident under CPS 234?

    You must notify APRA within 72 hours of becoming aware of a material information security incident, including any incident already notified to another regulator. Separately, material control weaknesses you cannot remediate in a timely way must be notified within 10 business days. From What is APRA CPS 234?

  • Is AUSTRAC a law enforcement agency?

    AUSTRAC is a regulator and a financial intelligence unit rather than a police force. It collects and analyses financial reports and other data to create targeted, actionable intelligence that supports law enforcement and national security investigations. Its intelligence functions form part of the national intelligence community. From What is AUSTRAC?

  • Is CPS 234 the same as CPS 230?

    No. CPS 234 covers information security and took effect in 2019. CPS 230 covers operational risk management, including service provider management and business continuity, and took effect on 1 July 2025. They are complementary, so AI security and AI operational resilience should be managed together. From What is APRA CPS 234?

  • Is de-identification the same as anonymisation?

    Not necessarily. The OAIC notes several terms are used in Australia for similar processes, including anonymisation and confidentialisation, and advises checking that all parties understand the terminology consistently. The Privacy Act test is whether an individual remains reasonably identifiable, not which label the parties use. From What is de-identification?

  • Is de-identified information still personal information?

    No, provided the de-identification is robust. The OAIC's position is that information which has undergone an appropriate and robust de-identification process is not personal information and is not subject to the Privacy Act. The same data can be personal in one release context and de-identified in another. From What is de-identification?

  • Is prompt injection the same as jailbreaking?

    They overlap but are not identical. NIST defines a jailbreak as a direct prompting attack intended to circumvent restrictions placed on model outputs, such as circumventing refusal behaviour. Prompt injection is the broader mechanism of exploiting untrusted input concatenated onto higher-trust instructions, and indirect injection usually aims at data theft or unauthorised action rather than rude answers. From What is prompt injection?

  • Is RAG safe for confidential or regulated data?

    It depends on the controls around the index, not on RAG itself. Retrieval can surface any document the permissions allow, so access control must be enforced at retrieval time. NIST also identifies RAG knowledge bases as a route for indirect prompt injection, where poisoned documents carry hidden instructions. From What is retrieval-augmented generation (RAG)?

  • Is stress a psychosocial hazard?

    Stress is a response, not a hazard and not an injury in itself. Safe Work Australia explains that psychosocial hazards can create stress, and that stress can cause psychological or physical harm where workers are stressed often, over a long time, or at a high level of intensity. From What are psychosocial hazards?

  • Is the Comcare scheme a no-fault scheme?

    Yes. Comcare describes the SRC Act scheme as a no fault scheme with limited access to common law. It takes an integrated approach across injury prevention, occupational rehabilitation and workers' compensation, with employers responsible for the occupational rehabilitation and return to work of their employees. From What is Comcare?

  • Is the NIST AI Risk Management Framework mandatory?

    No. NIST states the framework is intended to be voluntary, rights-preserving, non-sector-specific and use-case agnostic. It was produced as directed by the National Artificial Intelligence Initiative Act of 2020 and offers a resource rather than a compliance obligation, even for organisations in the United States. From What is the NIST AI Risk Management Framework?

  • Is the Voluntary AI Safety Standard mandatory?

    No. The standard states that being voluntary, it does not create new legal duties about AI systems or their use. It asks organisations to commit to understanding their AI use, engaging stakeholders, running risk and impact assessments, testing, and adopting appropriate controls. Existing law still applies regardless. From What is the Voluntary AI Safety Standard?

  • Is there a NIST framework for generative AI?

    Yes. NIST released NIST AI 600-1, the Generative AI Profile, on 26 July 2024. It is a companion to the AI RMF that helps organisations identify risks specific to generative AI and proposes actions for managing them in line with their own goals and priorities. From What is the NIST AI Risk Management Framework?

  • What are the 6 essential practices in Guidance for AI Adoption?

    Decide who is accountable, understand impacts and plan accordingly, measure and manage risks by implementing AI-specific risk management, share essential information, test and monitor, and maintain human control. Two versions exist, a foundations edition for low-risk and early AI use, and an implementation guidance edition for complex and higher-risk use. From What is the Voluntary AI Safety Standard?

  • What are the core obligations for a reporting entity?

    A reporting entity must enrol and register with AUSTRAC, develop and maintain a risk-based AML/CTF program, conduct customer due diligence, report suspicious matters, report threshold transactions such as large cash dealings, and keep supporting records. The exact services that trigger these obligations are the designated services listed in the Act. From What is AML/CTF regime?

  • What are the four functions of the NIST AI RMF?

    Govern, Map, Measure and Manage. Govern cultivates a culture of risk management and sets the structures that align AI work with organisational policy. Map establishes the context to frame risks. Measure analyses, benchmarks and monitors those risks. Manage allocates resources to treat them and plans incident response. From What is the NIST AI Risk Management Framework?

  • What are the National Employment Standards under the Fair Work Act?

    The NES are the minimum entitlements for employees in the national system. They cover maximum weekly hours, flexible working requests, casual employment, parental leave, annual leave, personal, carer's, compassionate and family and domestic violence leave, community service leave, long service leave, public holidays, superannuation, notice and redundancy, and the required information statements. From What is the Fair Work Act 2009?

  • What are the penalties under the EU AI Act?

    Article 99 sets three tiers. Breaching the Article 5 prohibitions can draw fines up to 35 million euro or 7 per cent of total worldwide annual turnover, whichever is higher. Most other breaches reach 15 million euro or 3 per cent, and supplying misleading information 7.5 million euro or 1 per cent. From What is the EU AI Act?

  • What are the seven trustworthy AI characteristics?

    NIST lists valid and reliable, safe, secure and resilient, accountable and transparent, explainable and interpretable, privacy-enhanced, and fair with harmful bias managed. Validity and reliability is treated as the base condition, and accountability and transparency relates to all the others. The characteristics must be balanced by context of use. From What is the NIST AI Risk Management Framework?

  • What are the top security risks of agentic AI?

    OWASP published a Top 10 for Agentic Applications in December 2025. It runs from agent goal hijack and tool misuse through identity and privilege abuse, supply chain vulnerabilities, unexpected code execution, memory and context poisoning, insecure inter-agent communication, cascading failures, human-agent trust exploitation, and rogue agents. From What is agentic AI?

  • What changes under the Tranche 2 reforms and when?

    The AML/CTF Amendment Act 2024 extends the regime to more professions, including certain lawyers, accountants, conveyancers, real estate professionals, and dealers in precious metals and stones. Broader reforms commenced 31 March 2026, and newly regulated Tranche 2 businesses are regulated by AUSTRAC from 1 July 2026, subject to transitional rules. From What is AML/CTF regime?

  • What counts as significantly affecting rights or interests?

    The Privacy Act gives examples: a decision under an Act or legislative instrument to grant or refuse a benefit, a decision affecting rights under a contract, agreement or arrangement, and a decision affecting access to a significant service or support. Beneficial effects count, not just adverse ones. From What is automated decision-making?

  • What disputes can the Fair Work Commission deal with?

    Common matters include unfair dismissal, bullying, sexual harassment, dismissal under general protections, unfair deactivation or termination for regulated workers, disputes about flexible work or unpaid parental leave, changes from casual to permanent employment, and right to disconnect disputes. It also handles industrial action and bargaining disputes. From What is the Fair Work Commission?

  • What does a RAG pipeline do at query time?

    AWS describes four stages. Create external data as vector representations in a database, retrieve relevant information by relevancy search, augment the prompt by adding the retrieved data in context, and update the external data asynchronously through real-time processes or periodic batch, so it does not go stale. From What is retrieval-augmented generation (RAG)?

  • What does APP 1 require of an organisation using AI?

    APP 1 requires open and transparent management of personal information, which in practice means a current privacy policy and documented practices and procedures. From 10 December 2026 it also requires entities using personal information in automated decision making affecting rights or interests to describe that use in the policy. From What are the Australian Privacy Principles?

  • What does AUSTRAC stand for?

    AUSTRAC stands for the Australian Transaction Reports and Analysis Centre. It describes itself as having a dual role, acting as Australia's anti-money laundering and counter-terrorism financing regulator and as the national financial intelligence unit, using both regulation and intelligence to detect, deter and disrupt serious crime. From What is AUSTRAC?

  • What does Comcare do?

    Comcare is the national work health and safety and workers' compensation authority. It acts as a regulator, claims manager, scheme manager and insurer. It is established under the Safety, Rehabilitation and Compensation Act 1988 and holds functions, compliance and enforcement powers under both that Act and the Work Health and Safety Act 2011. From What is Comcare?

  • What does the EU AI Act count as an AI system?

    Article 3 defines it as a machine-based system designed to operate with varying levels of autonomy, that may exhibit adaptiveness after deployment, and that infers from the input it receives how to generate outputs such as predictions, content, recommendations or decisions influencing physical or virtual environments. From What is the EU AI Act?

  • What does the Fair Work Commission do?

    It describes itself as Australia's independent workplace relations tribunal and registered organisations regulator. Its responsibilities span dispute resolution, labour standards including annual wage reviews and modern awards, bargaining and enterprise agreements, and the regulation of registered organisations through its General Manager. From What is the Fair Work Commission?

  • What does the OAIC actually do?

    The OAIC regulates privacy, freedom of information and government information policy. Its work includes conducting investigations, reviewing decisions, handling complaints, and providing guidance and advice. It administers the Privacy Act 1988, receives notifiable data breach notifications, and publishes the Australian Privacy Principles guidelines that entities are expected to follow. From What is the Office of the Australian Information Commissioner?

  • What duty does an employer have for psychosocial hazards?

    Under the model WHS laws a person conducting a business or undertaking must eliminate psychosocial risks, or if that is not reasonably practicable, minimise them so far as is reasonably practicable. The model WHS Regulations require PCBUs to have regard to all relevant matters when choosing control measures. From What are psychosocial hazards?

  • What has to go in the privacy policy?

    Three things under APP 1.8: the kinds of personal information used in the operation of such computer programs, the kinds of decisions made solely by those programs, and the kinds of decisions for which a program does something substantially and directly related to making the decision. From What is automated decision-making?

  • What is a material service provider under CPS 230?

    A material service provider is one the entity relies on to undertake a critical operation, or one that exposes the entity to material operational risk. For AI, this can include a hosted model or AI-enabled service supporting claims, underwriting or customer decisions. The Material Service Provider Register should capture these arrangements. From What is APRA CPS 230?

  • What is a rogue agent?

    Rogue agents is the tenth OWASP agentic risk, ASI10. It covers agents that begin showing misalignment, concealment and self-directed action. OWASP is explicit that the entry focuses on loss of behavioural integrity and governance once drift begins, not on the initial intrusion that may have started it. From What is agentic AI?

  • What is a self-insured licensee under the SRC Act?

    The SRC Act allows eligible corporations and Commonwealth authorities to hold a licence to self-insure their workers' compensation liabilities, claims management, or both. The relevant minister must first declare a corporation eligible, after which it applies to the Safety, Rehabilitation and Compensation Commission for the licence. From What is Comcare?

  • What is a target market determination under DDO?

    A target market determination, or TMD, is the document an issuer must make under Part 7.8A. It defines the class of consumers a financial product suits, the distribution conditions and restrictions, the review triggers, and the information distributors must report. Distribution must stay consistent with it. From What is Design and Distribution Obligations?

  • What is the AML/CTF regime in Australia?

    It is Australia's framework for preventing money laundering and terrorism financing, set out in the AML/CTF Act 2006 and administered by AUSTRAC. Regulated businesses, called reporting entities, must enrol with AUSTRAC, maintain a compliance program, verify customers, and report suspicious and threshold transactions. From What is AML/CTF regime?

  • What is the definition of a psychosocial hazard?

    Safe Work Australia defines a psychosocial hazard as anything that could cause psychological harm, for example harm to someone's mental health. Psychosocial hazards can arise from the design or management of work, the work environment, plant at a workplace, or workplace interactions and behaviours. From What are psychosocial hazards?

  • What is the difference between an AI agent and a workflow?

    Anthropic draws the line at who controls the path. Workflows are systems where models and tools are orchestrated through predefined code paths. Agents are systems where models dynamically direct their own processes and tool usage, keeping control over how they accomplish tasks. Workflows are predictable, agents are not. From What is agentic AI?

  • What is the difference between an issuer and a distributor under DDO?

    An issuer designs and offers the financial product and must prepare and maintain the target market determination. A distributor deals in or arranges the product, including AFS licensees and advisers, and must take reasonable steps to distribute consistently with the TMD and report relevant information back to the issuer. From What is Design and Distribution Obligations?

  • What is the difference between direct and indirect prompt injection?

    Direct injection comes from the person using the system, whose input changes how the model behaves. Indirect injection arrives through content the model processes, such as a web page, email or document carrying hidden instructions. NIST notes that in indirect attacks the primary user is often the one harmed. From What is prompt injection?

  • What is the difference between FAR and BEAR?

    BEAR, the Banking Executive Accountability Regime, applied only to banking and was administered by APRA. FAR replaced BEAR and extended the accountability model to insurance and superannuation, with joint administration by both APRA and ASIC. FAR also adds a conduct regulator dimension that BEAR did not have. From What is Financial Accountability Regime?

  • What is the difference between RAG and fine-tuning?

    Fine-tuning changes the model weights by training on additional examples. RAG leaves the model unchanged and supplies information at query time from an external index. NIST notes RAG lets the internal knowledge of a model be modified without retraining, so updating a document updates the answer immediately. From What is retrieval-augmented generation (RAG)?

  • What is the difference between the ART and the AAT?

    The Administrative Review Tribunal replaced the Administrative Appeals Tribunal on 14 October 2024 under the Administrative Review Tribunal Act 2024 (Cth). It performs the same core function of independent merits review of Commonwealth decisions, but under a new governing Act with revised structure and procedures. The AAT no longer exists. From What is Administrative Review Tribunal?

  • What is the reasonable administrative action exclusion under the SRC Act?

    Section 5A defines injury and excludes conditions suffered as a result of reasonable administrative action taken in a reasonable manner against the employee. It covers actions like performance management, transfers, and discipline. The exclusion frequently determines psychological claims, so the action's reasonableness must be assessed on the evidence. From What is Safety, Rehabilitation and Compensation Act 1988?

  • What is the SRC Act in workers compensation?

    The SRC Act 1988 is the Commonwealth law that runs the federal workers compensation scheme. It governs liability for injury, disease, rehabilitation, and compensation for employees of the Australian Government and corporations licensed to self-insure under it. Comcare administers claims for many Commonwealth agencies under the Act. From What is Safety, Rehabilitation and Compensation Act 1988?

  • What is the statutory tort for serious invasions of privacy?

    Introduced by Schedule 2 of the Privacy Act and commenced on 10 June 2025, it lets an individual sue for intrusion upon seclusion or misuse of information where they had a reasonable expectation of privacy. Courts may award damages, an injunction or an order requiring an apology. The OAIC does not administer it. From What is the Privacy Act 1988?

  • What is Tranche 2 in AML/CTF?

    Tranche 2 is the expansion of Australia's AML/CTF regime into industries recognised domestically and globally as high risk for criminal exploitation. It covers certain designated services provided by real estate professionals, dealers in precious stones and metals, lawyers, conveyancers, accountants, trust and company service providers, and some virtual asset businesses. From What are the AML/CTF Tranche 2 reforms?

  • What law establishes the OAIC?

    The Australian Information Commissioner Act 2010, Act No. 52 of 2010, establishes the Office of the Australian Information Commissioner. The Office consists of three information officers, the Information Commissioner, the Freedom of Information Commissioner and the Privacy Commissioner, with the Information Commissioner as head of the Office. The OAIC sits as an independent agency within the Attorney-General's portfolio. From What is the Office of the Australian Information Commissioner?

  • What must a newly regulated business actually do?

    From 1 July 2026 newly regulated businesses must comply with obligations under the AML/CTF laws, including implementing AML/CTF programs, conducting customer due diligence, reporting suspicious matters and keeping records. Most only need to enrol, though remittance and virtual asset service providers must also apply for registration. From What are the AML/CTF Tranche 2 reforms?

  • What obligations does AUSTRAC enforce?

    Reporting entities must implement AML/CTF controls and report to AUSTRAC. Core obligations include maintaining an AML/CTF program, conducting customer due diligence, submitting suspicious matter reports, threshold transaction reports and international funds transfer reports, and keeping records. AUSTRAC requires a business to apply to enrol no later than 28 days after the day it starts providing a designated service. From What is AUSTRAC?

  • What Privacy Act change starts on 10 December 2026?

    From 10 December 2026, APP entities that use personal information in a computer program to make a decision that could reasonably be expected to significantly affect an individual's rights or interests must set out in their privacy policies the kinds of personal information used and the kinds of decisions made that way. The OAIC consulted on guidance during 2026. From What is the Privacy Act 1988?

  • When did CPS 230 take effect?

    CPS 230 came into force on 1 July 2025. There is a transitional arrangement for existing material service provider contracts, which runs to 1 July 2026 at the earliest of the next renewal date. Separate targeted amendments for non-traditional service providers also take effect on 1 July 2026. From What is APRA CPS 230?

  • When did CPS 234 come into effect?

    CPS 234 took effect on 1 July 2019. APRA allowed a transition period until 1 July 2020 for information assets managed by third parties, recognising that entities needed time to obtain assurance over systems and data they relied on but did not directly control. From What is APRA CPS 234?

  • When did the Design and Distribution Obligations commence?

    DDO commenced on 5 October 2021 under Part 7.8A of the Corporations Act 2001 (Cth). The regime was introduced by the Treasury Laws Amendment (Design and Distribution Obligations and Product Intervention Powers) Act 2019. ASIC administers it and published Regulatory Guide 274 to set out its expectations. From What is Design and Distribution Obligations?

  • When did the Financial Accountability Regime start?

    FAR commenced in two stages. It applied to the banking sector, including authorised deposit-taking institutions, from 15 March 2024. It then applied to the insurance and superannuation sectors from 15 March 2025. The underlying Act received Royal Assent on 14 September 2023. From What is Financial Accountability Regime?

  • When did the right to disconnect start?

    The right to disconnect applied from 26 August 2024 for employees of non-small business employers, and from 26 August 2025 for employees of small business employers, meaning those with fewer than 15 employees. It lets employees refuse to monitor, read or respond to out of hours contact unless refusing is unreasonable. From What is the Fair Work Act 2009?

  • When did the Tranche 2 reforms start?

    Parliament passed the AML/CTF Amendment Bill 2024 on 29 November 2024, amending the Anti-Money Laundering and Counter-Terrorism Financing Act 2006. Newly regulated businesses could enrol with AUSTRAC from 31 March 2026 and became subject to obligations from 1 July 2026. Changes for existing reporting entities started 31 March 2026. From What are the AML/CTF Tranche 2 reforms?

  • When do the EU AI Act's high-risk rules apply?

    Later than originally legislated. Regulation (EU) 2026/1744, the Digital Omnibus on AI adopted on 8 July 2026, moved the high-risk obligations for standalone Annex III systems to 2 December 2027 and for AI embedded in regulated products under Annex I to 2 August 2028. From What is the EU AI Act?

  • When do you have to notify the OAIC of a data breach?

    Under the notifiable data breaches scheme, an entity covered by the Privacy Act must notify affected individuals and the OAIC when a data breach involving personal information is likely to result in serious harm. The notification to individuals must include recommendations about the steps they should take in response. From What is the Office of the Australian Information Commissioner?

  • When does the automated decision-making privacy obligation start?

    The obligation commences on 10 December 2026. It was introduced by the Privacy and Other Legislation Amendment Act 2024 and sits in Australian Privacy Principle 1. The OAIC published an issues paper on 18 May 2026 to inform its guidance, with submissions closing on 15 June 2026. From What is automated decision-making?

  • When does the Privacy Act require de-identification?

    APP 11.2 requires an entity that no longer needs personal information for any permitted purpose to take reasonable steps to destroy or de-identify it. That obligation does not apply where the information sits in a Commonwealth record, or where an Australian law or a court or tribunal order requires the entity to retain it. APP 4.3 and APP 6.4 also refer to de-identification. From What is de-identification?

  • Where did the term RAG come from?

    From a paper submitted in May 2020, Retrieval-Augmented Generation for Knowledge-Intensive NLP Tasks, by Patrick Lewis and colleagues. It described models that combine pre-trained parametric memory, a sequence-to-sequence model, with non-parametric memory, a dense vector index of Wikipedia accessed by a neural retriever. From What is retrieval-augmented generation (RAG)?

  • Which Australian Privacy Principles matter most for AI?

    APP 3 governs collection, and the OAIC treats AI-generated or inferred personal information as a collection. APP 6 limits use and disclosure to the primary purpose unless consent or reasonable expectation applies. APP 8 covers overseas disclosure, which most hosted AI triggers. APP 11 requires reasonable security steps. From What are the Australian Privacy Principles?

  • Which businesses does AUSTRAC regulate?

    AUSTRAC regulates reporting entities across accountants, banks, casinos, conveyancers, dealers in precious stones, metals and products, financial service providers, legal professionals, pubs, clubs and bookmakers, real estate, remittance service providers, superannuation providers and virtual asset service providers. Regulation follows the designated service provided, rather than the industry label a business uses. From What is AUSTRAC?

  • Which entities does CPS 234 apply to?

    It applies to all APRA-regulated entities across five industries: authorised deposit-taking institutions, general insurers, life companies and friendly societies, private health insurers, and superannuation RSE licensees. It also reaches information assets managed on their behalf by related parties and third parties. From What is APRA CPS 234?

  • Which EU AI Act rules already apply?

    The prohibitions on unacceptable-risk practices and the AI literacy duty applied from 2 February 2025. Obligations for general-purpose AI models, governance arrangements, notified bodies and penalties applied from 2 August 2025. The regulation itself entered into force on 1 August 2024. From What is the EU AI Act?

  • Which jurisdictions have adopted the model WHS laws?

    Safe Work Australia states that the model WHS laws have been implemented in all jurisdictions except Victoria. Some jurisdictions have made variations, often to stay consistent with their own drafting protocols and other laws. The model WHS Act Cross-Comparison Table published by Safe Work Australia summarises those differences. From What are the model WHS laws?

  • Who administers the SRC Act?

    Comcare administers the SRC Act for the Australian Government and many of its agencies. Corporations holding a self-insurance licence under the Act determine their own claims. Both apply the same legislation. State schemes use separate workers compensation laws, so always confirm which scheme a claim falls under first. From What is Safety, Rehabilitation and Compensation Act 1988?

  • Who are the members of the Fair Work Commission?

    The Commission is led by a President, who under section 629A of the Fair Work Act has the same status as a Judge of the Federal Court, supported by Vice Presidents, Deputy Presidents and Commissioners based in Adelaide, Brisbane, Canberra, Hobart, Melbourne, Newcastle, Perth and Sydney. Expert Panel Members are appointed part-time for periods of not more than five years, and some state industrial tribunal members hold dual appointments. From What is the Fair Work Commission?

  • Who does the Privacy Act 1988 apply to?

    It applies to most Australian Government agencies and to private sector organisations with an annual turnover of more than $3 million, together called APP entities. Some smaller operators are also covered, including private health service providers, credit reporting bodies, businesses that buy or sell personal information, and Commonwealth contracted service providers. From What is the Privacy Act 1988?

  • Who does the Voluntary AI Safety Standard apply to?

    All organisations across the AI supply chain, though the first version focuses on AI deployers rather than developers. A deployer is an individual or organisation that supplies or uses an AI system to provide a product or service, whether the deployment is internal to the organisation or external. From What is the Voluntary AI Safety Standard?

  • Who enforces DDO and what are the consequences?

    ASIC enforces DDO. It can issue stop orders that halt distribution of a product where the target market determination is deficient or distribution is inconsistent with it, and it has commenced litigation. ASIC has issued multiple DDO stop orders since the regime began in October 2021. From What is Design and Distribution Obligations?

  • Who enforces the model WHS laws?

    The Commonwealth, state and territory regulators enforce WHS laws in their own jurisdictions, supported by the National Compliance and Enforcement Policy. Safe Work Australia is not a regulator and cannot advise on workplace WHS issues. In the Commonwealth jurisdiction the regulator is Comcare, which administers the Work Health and Safety Act 2011. From What are the model WHS laws?

  • Who has to comply with CPS 230?

    All APRA-regulated entities must comply. That covers authorised deposit-taking institutions (banks), general insurers, life insurers, private health insurers, and superannuation trustees. The standard sits within the existing risk management framework under CPS 220 and SPS 220. From What is APRA CPS 230?

  • Who is an accountable person under FAR?

    An accountable person is an individual who holds a position of senior executive responsibility within an accountable entity, such as a CEO, a senior risk or compliance executive, or a head of a major business line. Their specific responsibilities must be set out in the entity's accountability statements and accountability map. From What is Financial Accountability Regime?

  • Who is covered by the Comcare scheme?

    The Safety, Rehabilitation and Compensation Act 1988 covers employees of the Australian Government, of Australian Government authorities and corporations, and of corporations holding a licence to self-insure under that Act. A separate Parliamentary Injury Compensation Scheme covers parliamentarians and the Prime Minister's spouse. From What is Comcare?

  • Who is newly regulated under Tranche 2?

    AUSTRAC names real estate professionals, dealers in precious stones, metals and products, lawyers, conveyancers, accountants, trust and company service providers, and businesses providing certain virtual asset services beyond the previously regulated digital to fiat currency exchange services. Regulation attaches to the designated service provided, not the profession. From What are the AML/CTF Tranche 2 reforms?

  • Who regulates AML/CTF compliance in Australia?

    AUSTRAC, the Australian Transaction Reports and Analysis Centre, is the regulator. It is both Australia's financial intelligence unit and the supervisor of reporting entities. AUSTRAC publishes the AML/CTF Rules, guidance, and program starter kits, and it takes enforcement action against businesses that fail to meet their obligations. From What is AML/CTF regime?

← All practice areas