If voluntary principles did not prevent the failures they were designed to address — what is the mandatory regime trying to do instead?
The voluntary era of AI governance lasted approximately five years. It produced some of the most carefully written principles in the history of technology policy. Australia's eight AI Ethics Principles are thorough. The OECD alignment was unprecedented in scope. IBM, Google, and Microsoft all published responsible AI frameworks. And during that period, Robodebt ran. Watson for Oncology failed. COMPAS continued assigning biased risk scores in courtrooms. The EU AI Act — passed in 2024, with mandatory compliance timelines staggered through to 2026 — represents the conclusion that description was not enough. Australia's automated decision-making legislation due December 2026 follows the same logic.
| Year | Event | Jurisdiction | Binding? |
|---|---|---|---|
| 2019 | Australia publishes 8 AI Ethics Principles; OECD AI Principles agreed by 42 countries | Australia / International | Voluntary |
| 2021 | OECD updates and reaffirms AI Principles; G20 adopts | International | Voluntary |
| 2024 | EU AI Act passed — mandatory risk-tiered regulation with penalties up to €35M or 7% of global revenue | European Union | Mandatory |
| Oct 2025 | Australia's National AI Centre publishes implementation guidance — six practices, three risk tiers | Australia | Technically voluntary; anticipatory of mandatory regime |
| July 2026 | Australia announces Office of AI within PM&C; national AI standards in development; data centre obligations set | Australia | Structural — not yet legislation |
| Dec 2026 | Automated Decision-Making (ADM) legislation due — mandatory accountability for AI decisions affecting Australians | Australia | Mandatory |
The placement of Australia's Office of AI inside the Department of the Prime Minister and Cabinet — not a technology portfolio — is a deliberate signal. Algorithmic governance is being treated as a machinery of government question, not a technology procurement question.
The EU AI Act organises AI systems into four risk tiers. The tier determines the governance obligations — from no requirements to outright prohibition. The architecture avoids banning AI innovation while requiring accountability where the stakes are highest.
Australia's National AI Centre published six essential practices in October 2025 for organisations deploying AI. These are currently voluntary guidance but are explicitly framed as anticipating the mandatory December 2026 regime.
| # | Practice | What it requires |
|---|---|---|
| 1 | Name one person | For each AI system, name one accountable person — not a team, one individual. Accountability diluted across a team is accountability that belongs to no one. |
| 2 | Understand who is affected | Map who the system affects — including people who are not users — and build in the ability for them to understand and contest decisions that affect them. |
| 3 | Screen the risk | Before deployment, conduct a structured risk assessment. Use the seven diagnostic questions (see below) to determine what governance tier the use case requires. |
| 4 | Share essential information | Disclose what AI systems are in use and why. Not technical specifications — operational transparency about what role AI is playing in decisions affecting users. |
| 5 | Test before deployment | Testing must include adversarial scenarios and edge cases, not just standard use. Tay was not adversarially tested. Robodebt was not tested on variable-income scenarios. |
| 6 | Monitor after deployment | Maintain meaningful human oversight after go-live. Bias and reliability problems frequently emerge post-deployment, not at launch. Continuous auditing, not a one-time gate. |
The voluntary era produced good principles and poor outcomes. The mandatory era — already live in the EU, arriving in Australia December 2026 — is a response to that gap. For organisations deploying AI, the question is no longer whether regulation is coming. It is whether your governance framework can withstand regulatory scrutiny when it arrives. The time to build that framework is before the legislation, not in response to it.
Describe the four tiers of the EU AI Act — including the governance requirements for each tier and an example of a system in each tier.
What are the six NAIC essential practices for AI governance — and what specific failure does each one address?
Why is Australia's Office of AI being placed inside the Department of the Prime Minister and Cabinet — rather than a technology or digital portfolio — and what does that placement signal about how government is framing AI governance?