Is Australia's Voluntary AI Safety Standard enough for enterprise risk?
Australia's Voluntary AI Safety Standard is not enough on its own to govern high-stakes AI in enterprise settings. It defines 10 guardrails for responsible AI and leaves the hardest technical and high-risk controls to each organization.
Published by the National AI Centre in September 2024, the standard is non-binding and maps to recognized international frameworks. It describes what good governance looks like without specifying how to secure, test, or classify the systems you run.
The gap matters because most enterprises already deploy AI inside tools they buy, often before governance catches up. This article covers what the standard requires, where it falls short for enterprise risk, and the controls worth adding beyond it.
What is Australia's Voluntary AI Safety Standard?
Australia's Voluntary AI Safety Standard is a set of 10 guardrails published by the Department of Industry, Science and Resources to help organizations develop and deploy AI safely and responsibly. It is non-binding, applies across the AI supply chain, and aligns with international frameworks including ISO/IEC 42001:2023 and the NIST AI Risk Management Framework.
The standard applies to both AI developers and deployers. It creates no new legal duties, but it complements existing Australian laws covering privacy, consumer protection, anti-discrimination, and workplace safety.
In October 2025, the government condensed the 10 guardrails into six essential practices under the updated Guidance for AI Adoption. That shift signals a move toward more prescriptive, lifecycle-oriented guidance.
Because the standard covers deployers, it reaches the third-party AI most Australian businesses already run. That is where governed access controls matter most: Glean Search enforces permission-aware results at the search layer, so people only see answers derived from data they are already authorized to access.
What the 10 guardrails require from enterprises
The guardrails ask you to put governance, testing, and transparency around every AI system you build, buy, or deploy. According to the National AI Centre, they group into three practical areas.
Governance, accountability, and risk management (guardrails 1-3)
- Establish and publish an accountability process that includes governance structures, internal capability, and a strategy for regulatory compliance.
- Implement a risk management process that identifies, assesses, and mitigates AI-specific risks proportionate to each system's potential impact.
- Protect AI systems through data governance measures covering data quality, provenance, privacy, and cybersecurity.
Testing, oversight, and transparency (guardrails 4-6)
- Test AI models before deployment and monitor performance metrics, including unintended bias, model drift, and copyright risks.
- Enable meaningful human control across the AI lifecycle, so people can pause, override, or escalate system decisions.
- Inform end users when they interact with AI, receive AI-enabled decisions, or view AI-generated content, using methods like disclosure statements or watermarking.
Contestability, supply chain, and stakeholder engagement (guardrails 7-10)
- Provide internal mechanisms for people affected by AI outcomes to challenge decisions, with adequate human oversight.
- Stay transparent with other organizations in the AI supply chain about data, models, and system behavior.
- Keep records that let third parties assess compliance, including AI inventories, design specifications, and capability descriptions.
- Engage stakeholders across the lifecycle with a focus on safety, diversity, inclusion, and fairness.
Guardrail 6 becomes practical when answers carry their sources. Cited responses that link each answer back to its source document let a reader verify where it came from instead of trusting an unverified summary.
How the voluntary standard compares to mandatory AI regulations
The voluntary standard carries no enforcement mechanism, which sets it apart from binding regimes. Unlike the EU AI Act, which imposes legal obligations and penalties in high-risk settings, Australia's standard relies entirely on voluntary adoption.
The government released a proposals paper alongside the original standard to explore mandatory guardrails for high-risk AI. As of mid-2026, no mandatory equivalent has been legislated.
The Productivity Commission's interim report argued that mandatory AI-specific legislation could slow innovation, which contributed to the government's cautious approach. That leaves enterprises operating across jurisdictions with a gap. The voluntary standard may meet Australian expectations, yet it does not constitute compliance with binding frameworks that trading partners or customers require.
Organizations that structure governance solely around voluntary guidance risk being unprepared if mandatory requirements arrive, particularly for high-risk AI in healthcare, financial services, or critical infrastructure. A single governed platform that applies permission enforcement, retention, and access controls consistently across connected applications reduces that exposure, so one program can support both Australian guidance and international frameworks.
Where the voluntary standard falls short for enterprise risk management
The standard tells you what to govern but rarely how, and the gaps concentrate in the areas enterprise security and risk teams care about most.
Gaps in technical security guidance
The standard does not prescribe specific technical security measures for AI systems. It points to existing cybersecurity controls like the Essential Eight. It does not address AI-specific attack vectors such as adversarial manipulation, data poisoning, prompt injection, or model inference attacks.
Security teams need supplementary references for those threats. The OWASP Top 10 for Large Language Model Applications and MITRE ATLAS catalog the tactics attackers use against AI systems. Permission-aware architecture, end-to-end encryption, and audit logging are baseline requirements for any deployment that handles sensitive data.
Missing explainability and environmental requirements
The standard does not explicitly require AI systems to be explainable or interpretable. That creates risk in regulated industries where an organization must justify automated decisions.
It also carries no explicit requirement for environmental impact or societal wellbeing beyond stakeholder engagement. Enterprises running large-scale AI compute get no guidance on the sustainability dimensions of that footprint.
Insufficient depth for high-risk use cases
The guardrails apply uniformly across risk levels. They do not differentiate controls for high-risk applications versus low-risk internal tools, which puts the burden on each organization to determine proportionality without a formal risk classification framework.
Enterprises deploying AI that affects legal rights, health outcomes, or financial standing need controls that go well beyond a one-size-fits-all standard.
What enterprises should implement beyond the voluntary standard
Treat the standard as a floor and build three layers on top of it: a governed architecture, AI risk inside your existing risk program, and continuous testing in production.
Build a permission-aware, governed AI architecture
- Enforce existing access controls upstream of any language model, so users only see outputs derived from data they are authorized to access.
- Maintain audit trails of every AI interaction, search query, and generated output to support compliance reviews and incident response.
- Set contractual zero-day data retention with AI providers to keep enterprise data out of model training.
Enforcing permissions at the search layer, rather than filtering results after the model responds, addresses data leakage at the architecture level.
Integrate AI risk into enterprise risk management
- Treat AI risk as a first-class category inside your existing risk framework rather than a standalone initiative.
- Assess risk by specific use, data sensitivity, affected populations, and degree of human reliance instead of generic tiers.
- Establish clear escalation paths and human override for AI-assisted decisions in hiring, customer eligibility, financial advice, or safety-critical operations.
AI agents that plan, adapt, and act within admin-defined guardrails and existing permissions keep a person in control of sensitive steps.
Operationalize continuous testing and monitoring
- Move beyond pre-deployment testing to continuous evaluation for drift, bias amplification, and hallucination rates in production.
- Ground AI answers in verified enterprise knowledge with citations, so every output traces back to a source the reader can check.
- Run red-team testing for adversarial robustness and set automated alerts when outputs fall outside defined thresholds.
Grounded, cited answers make monitoring concrete, since a reviewer can trace any output to its source and confirm it against production performance instead of auditing unverifiable text.
How to assess your organization's AI governance readiness
Start with an inventory. List every AI system in use, including AI embedded in third-party tools, and assign each one an owner, a risk rating, and a review cadence.
- Map current controls against the 10 guardrails and the six essential practices, using the government's published crosswalk as a reference.
- Check whether your AI platform enforces permissions natively or relies on manual workarounds that introduce risk at scale.
- Assess supplier contracts for transparency obligations, incident notification, and data-handling commitments that match your risk appetite.
- Schedule governance reviews at least annually, or whenever a material change occurs in a system, its data sources, or its operational context.
Native permission enforcement is the control that scales. Access controls applied consistently across every connected application mean a governance review reflects what users can actually see rather than a policy no one enforces.
Frequently asked questions
Does adopting the voluntary standard mean my organization is legally compliant?
No. The standard is non-binding and does not replace legal obligations under existing Australian privacy, consumer, anti-discrimination, or workplace safety laws. Treat it as a governance baseline, not a compliance certificate.
Will Australia introduce mandatory AI regulations?
The government announced plans in July 2026 for a framework covering large AI data centres and training infrastructure. The scope, duties, and timeline remain subject to legislation, and no general AI Act exists as of mid-2026.
How does the voluntary standard map to international AI governance frameworks?
The guardrails align with ISO/IEC 42001:2023 and the NIST AI Risk Management Framework. Organizations that implement the standard's controls are better positioned for international compliance, but should verify alignment with the specific jurisdictional requirements they face.
What additional measures matter most for enterprises handling sensitive data?
Permission-aware architecture that respects existing access controls, end-to-end encryption, audit logging, grounded answers with source citations, and contractual data retention limits with AI providers are the most critical controls beyond what the standard addresses.
Should enterprises wait for mandatory regulations before investing in AI governance?
No. Organizations that build governed AI now reduce remediation costs later, earn stakeholder trust earlier, and avoid the disruption of retrofitting compliance into systems already in production.
Adopting the guardrails is easier when governance is built into the AI your teams already use, rather than bolted on afterward. We built Glean so permission enforcement, cited answers, and audit-ready records come standard across search, assistant, and agents. Request a demo to explore how Glean and AI can transform your workplace.









.webp)
.jpg)
