The essential practices are the Australian Government’s guidance for responsible AI use. They help organisations put appropriate governance, oversight and transparency in place.
Essential AI practices
Why this matters
AI can improve efficiency, support better services and open new opportunities. But long-term value depends on trust. These practices help organisations:
- align AI use with business goals
- put governance in place early
- manage risk based on AI use
- strengthen oversight, accountability and decision-making
- be clear about when and how AI has been used to create or modify content.
They align with Australia’s AI Ethics Principles and relevant international standards. This gives organisations a shared, trusted baseline for responsible AI use.
Show Transcript
As your organization implements AI, are you ready to navigate your ethical, legal, and regulatory responsibilities, whether you're a company director or senior business leader or play a key role in developing, procuring, or implementing AI systems, you should know your obligations under Australian and international law. If you don't, your business may be exposed to significant risks, and you might face individual consequences, too. Of course, managing risks and seeing opportunities require you to understand what AI systems are operating within your organization and how they create value. This is fundamental to ensuring that your AI use is legally compliant.
So, how do you know what obligations apply to you? First, it's important to remember that all the traditional laws that govern how your business operates also apply to AI systems. Your AI solution must therefore comply with the full range of consumer privacy, anti-discrimination, workplace, intellectual property, and any other laws that apply to your industry or products. For example, if your AI system accidentally leaks customer information, you and your business could be in breach of privacy and cyber security laws. Misleading statements made by AIdriven advertising or promotions could violate consumer laws. While harms caused by an AI system in the workplace could trigger workplace safety issues. Of course, additional rules will apply depending on the industry or sector you work in.
For example, AI used in legal practice must not breach client privilege and confidentiality rules. If you're working in healthare, AI systems must comply with patient safety and privacy laws. Moreover, if you are a company director, you personally have a duty under section 180 of the Corporations Act that requires you to act with care and diligence. This includes ensuring that adequate governance systems exist to manage the risks created by your AI systems. Second, international regulations can also impact how you operate your AI system, especially if you're doing business with overseas clients.
A prime example is the European Union's General Data Protection Regulation or GDPR, which applies to EU citizens globally. If your business interacts with EU citizens, your AI systems must also be GDPR compliant. As more countries explore and develop AI specific regulations, you are more likely to be exposed to international regulation. Third, you should make sure you understand the expectations that your customers and other stakeholders have for you and your organization. The more you engage with the people and communities who will be impacted by your AI systems, the better you will understand the concerns and expectations that may point to legal risk. Working directly with those affected by your systems will also help to build trust and confidence in your organization's use of AI. In some cases, it will be essential that you actually co-create AI systems with your customers. A useful reference of what Australians care about regarding how AI systems behave can be found in Australia's eight AI ethics principles. So, how can you ensure you're doing your duty as a director, executive, or manager?
Most importantly, if you're unsure of any of your legal obligations concerning AI systems, you should always seek legal advice, starting with your organization's legal team. However, even the world's best legal council won't be able to help unless you can comprehensively explain to them the purpose of the system, the data it relies on, and how it works in practice. This means that you or someone in your organization must understand how the system works and how it could cause harm. This is the case even if a third party provides your AI system. As we will discuss in the next videos, you should also ensure that your organization has implemented policies, guidelines, and standards to help ensure you can meet your legal obligations and customer expectations. Finally, ensuring that your AI systems are compliant is not a set and forget process. The way that AI systems are trained means that they can go out of date and become less effective. It's important to monitor the performance of AI systems to ensure they are working as intended.
Explore the guides
Choose the guidance that matches how your organisation is using AI today and the level of risk involved.
How to decide where to start
Here is each option in more detail to help you decide which guidance fits your situation.
Start with the foundations
If you’re early in planning or trialling AI, begin with our foundations guidance.
Use it to:
- connect AI use to business outcomes
- understand governance roles
- identify risks early
- put controls in place before scaling.
Move to implementation
If your team already uses AI and needs stronger controls, use our implementation guidance.
Use it to strengthen:
- governance processes
- technical oversight
- monitoring and assurance
- risk controls across systems and workflows
- responsible day-to-day practices.
Be clear about AI use
People need to know when AI has been used in a way that affects them.
Our guidance helps you decide when and how to tell customers, staff and the public that you’ve used AI to create or modify content. This helps build trust through clear and appropriate disclosure.