If you run an Australian business and half-remember that mandatory AI rules were coming, here is the current answer, read directly from the government's own documents: they are not coming. Not in the National AI Plan, at least, which is the document that now defines the government's position. Nothing AI-specific and mandatory sits between you and deploying a high-risk AI system today. What binds you is the law that already existed: privacy, consumer, online safety, copyright, corporations law, and your sector's regulator.

That is a genuinely different position from the one the government proposed fifteen months earlier, and no document ever says so directly. You can only see the reversal by reading both papers end to end, so we did.

What was on the table in 2024

The Department of Industry, Science and Resources' September 2024 proposals paper, 69 pages, was blunt about its purpose: it proposed ten mandatory guardrails that would "require developers and deployers of AI in high-risk settings to take steps to ensure their products" are safe, running from accountability processes (Guardrail 1) through to certified conformity assessments (Guardrail 10). It then asked which of three mechanisms should make them law:

  • Option 1, domain-specific: adapt existing regulatory frameworks, sector by sector, to include the guardrails.
  • Option 2, framework legislation: a new framework Act, with existing laws amended to give it effect.
  • Option 3, whole of economy: "introducing a new cross-economy AI Act", the paper's own words, with the definitions, thresholds, guardrails and enforcement mechanisms in one statute.

The consultation ran through late 2024. Then, publicly, very little, until December 2025.

What the National AI Plan actually says

The National AI Plan, announced by the government on 2 December 2025, is the successor document. We read all 37 pages and then searched the full text. The word "guardrail" does not occur. Not repurposed, not softened: absent. There is no commitment to legislate the ten guardrails, no framework legislation, no AI Act, and no dedicated AI regulator.

What the plan says instead, in its "Keep Australians Safe" section, is this:

"The government's regulatory approach to AI will continue to build on Australia's robust existing legal and regulatory frameworks, ensuring that established laws remain the foundation for addressing and mitigating AI-related risks."

National AI Plan, December 2025, p. 27

And on new rules: "A proactive approach to harms as they emerge ensures that government is continuing to update and introduce targeted laws where needed." That is a case-by-case posture, respond to harms after they emerge, which is close to the opposite of the 2024 paper's ex-ante regime, where high-risk systems would have had to meet mandatory requirements before deployment.

The record, in order

Where the guardrails went: the paper trail, 2024 to 2026
  • SEP 2024DISR proposals paper: 10 mandatory guardrails for high-risk AI, 3 legislative options including a cross-economy AI Act.
  • OCT 2025National AI Centre publishes the Guidance for AI Adoption (21 October), 6 voluntary "essential practices" that evolve the 2024 Voluntary AI Safety Standard.
  • NOV 2025AI Safety Institute announced (25 November): it will "monitor, test and share information", operational early 2026. Advisory, not an enforcement body.
  • DEC 2025National AI Plan released (2 December): existing law remains the foundation. No mandatory guardrails, no AI Act, no AI regulator.
  • JUL 2026Status today: the 10 proposed mandatory guardrails bind no one. The 6 voluntary practices are guidance, not law.

Methodology: each entry is taken from the named primary document, linked in the source list below, all read in full and accessed 11 July 2026. The "guardrails" word count against the National AI Plan PDF was checked by full-text extraction of the published 37-page document: zero occurrences.

What replaced the guardrails

Two things, neither of which is law.

First, the Guidance for AI Adoption, published by the National AI Centre on 21 October 2025. It sets out six "essential practices": decide who is accountable, understand impacts and plan accordingly, measure and manage risks, share essential information, test and monitor, and maintain human control. The government's own Voluntary AI Safety Standard page describes the new guidance as having "evolved" that 2024 standard, whose ten voluntary guardrails it supersedes. Note the shape of that drift: ten mandatory guardrails proposed, ten voluntary guardrails published, six voluntary practices remaining.

Second, an AI Safety Institute, announced 25 November 2025 and operational from early 2026. Its own announcement describes a body that will "monitor, test and share information on emerging AI technologies, risks and harms" and serve as "a central hub". The plan adds that it "will support existing regulators with independent advice". Nothing in either document gives it power to gate, delay, approve or recall an AI system.

So what must a deployer actually do, right now?

Here is the position in practice, mid-2026. If you deploy AI in Australia, including in what the 2024 paper would have called a high-risk setting, your binding obligations are the ones that predate the AI debate: the Privacy Act, Australian Consumer Law, the Online Safety Act and its industry codes and standards, copyright law, and sector rules such as therapeutic goods regulation and financial services obligations. The six essential practices are worth doing and free to ignore. That is not our gloss; it is the plan's design, and the plan says the government prefers it that way.

Our view, stated as a view and built on the documents above: this is a policy reversal, and it deserved a sentence. A government that spent 2024 consulting the country on mandatory guardrails owed the same audience an explicit statement that it had decided against them, rather than a plan in which the central word of the previous two years simply never appears. Precision matters here, so we will be precise about what the plan does say: it frames itself as a beginning, and its safety section closes with a warning shot. "If more regulation is needed to address bad actors or broader harms, the government will not hesitate to intervene." The guardrails are gone, but the door is propped open, and this masthead will be reading whatever comes through it.