INNOVAREModule 5 · Ethical AI

Case 5: The Voluntary Era Closes

In 2019, Australia published principles. In 2024, the EU passed law. In December 2026, Australia follows. What changed — and what it means for every organisation deploying AI.

July 2026 · Case 5 of 6
As you read — hold this question

If voluntary principles did not prevent the failures they were designed to address — what is the mandatory regime trying to do instead?

3
dates mark the shift. 2019: voluntary principles. 2024: EU mandatory law. December 2026: Australia mandatory legislation. The direction of travel is not ambiguous.

The voluntary era of AI governance lasted approximately five years. It produced some of the most carefully written principles in the history of technology policy. Australia's eight AI Ethics Principles are thorough. The OECD alignment was unprecedented in scope. IBM, Google, and Microsoft all published responsible AI frameworks. And during that period, Robodebt ran. Watson for Oncology failed. COMPAS continued assigning biased risk scores in courtrooms. The EU AI Act — passed in 2024, with mandatory compliance timelines staggered through to 2026 — represents the conclusion that description was not enough. Australia's automated decision-making legislation due December 2026 follows the same logic.

The regulatory arc
Quiz: Regulation

From voluntary principles to mandatory obligations — the timeline

Year Event Jurisdiction Binding?
2019 Australia publishes 8 AI Ethics Principles; OECD AI Principles agreed by 42 countries Australia / International Voluntary
2021 OECD updates and reaffirms AI Principles; G20 adopts International Voluntary
2024 EU AI Act passed — mandatory risk-tiered regulation with penalties up to €35M or 7% of global revenue European Union Mandatory
Oct 2025 Australia's National AI Centre publishes implementation guidance — six practices, three risk tiers Australia Technically voluntary; anticipatory of mandatory regime
July 2026 Australia announces Office of AI within PM&C; national AI standards in development; data centre obligations set Australia Structural — not yet legislation
Dec 2026 Automated Decision-Making (ADM) legislation due — mandatory accountability for AI decisions affecting Australians Australia Mandatory

The placement of Australia's Office of AI inside the Department of the Prime Minister and Cabinet — not a technology portfolio — is a deliberate signal. Algorithmic governance is being treated as a machinery of government question, not a technology procurement question.

EU AI Act — four tiers

Risk-based regulation: not banning AI, requiring proportionate governance

The EU AI Act organises AI systems into four risk tiers. The tier determines the governance obligations — from no requirements to outright prohibition. The architecture avoids banning AI innovation while requiring accountability where the stakes are highest.

Unacceptable Risk
Prohibited. Social scoring systems ranking citizens' behaviour. Mass biometric surveillance in public spaces. AI designed to psychologically manipulate people. Subliminal techniques targeting vulnerable groups. These applications are banned entirely under the Act.
High Risk
Mandatory conformity assessment before deployment, plus registration in a public EU database. Employment AI (CV screening, performance monitoring). Credit scoring. AI in migration and border decisions. Judicial decisions and law enforcement. Biometric identification. These systems must demonstrate compliance before they can be used.
Limited Risk
Transparency obligations. Chatbots must disclose that users are interacting with AI. Deepfakes must be labelled. Emotion recognition and biometric categorisation systems have specific disclosure requirements. The user must be able to know AI is involved.
Minimal Risk
No specific requirements. Spam filters, AI in games, productivity tools, recommendation systems. The vast majority of current AI applications fall here. Voluntary codes of conduct are encouraged but not required.
NAIC guidance — six practices

Australia's practical pre-legislation framework

Australia's National AI Centre published six essential practices in October 2025 for organisations deploying AI. These are currently voluntary guidance but are explicitly framed as anticipating the mandatory December 2026 regime.

#PracticeWhat it requires
1Name one personFor each AI system, name one accountable person — not a team, one individual. Accountability diluted across a team is accountability that belongs to no one.
2Understand who is affectedMap who the system affects — including people who are not users — and build in the ability for them to understand and contest decisions that affect them.
3Screen the riskBefore deployment, conduct a structured risk assessment. Use the seven diagnostic questions (see below) to determine what governance tier the use case requires.
4Share essential informationDisclose what AI systems are in use and why. Not technical specifications — operational transparency about what role AI is playing in decisions affecting users.
5Test before deploymentTesting must include adversarial scenarios and edge cases, not just standard use. Tay was not adversarially tested. Robodebt was not tested on variable-income scenarios.
6Monitor after deploymentMaintain meaningful human oversight after go-live. Bias and reliability problems frequently emerge post-deployment, not at launch. Continuous auditing, not a one-time gate.
Seven questions before deployment
The NAIC guidance includes seven diagnostic questions. Answering yes to any is not a veto — it is a trigger to determine what governance level the use case requires. (1) Does it handle personal or sensitive information? (2) Does it interact autonomously with users? (3) Does it operate at scale? (4) Does it affect people in vulnerable circumstances? (5) Does it operate in a regulated domain? (6) If something goes wrong, is the harm hard to contest or reverse? (7) Could this system be repurposed beyond its original design? These questions are a diagnostic, not a checklist. The intent is to force the question of appropriate governance before deployment, not after a failure.
Take this away

The voluntary era produced good principles and poor outcomes. The mandatory era — already live in the EU, arriving in Australia December 2026 — is a response to that gap. For organisations deploying AI, the question is no longer whether regulation is coming. It is whether your governance framework can withstand regulatory scrutiny when it arrives. The time to build that framework is before the legislation, not in response to it.

Quick recall — without looking back

Test yourself on this case

Question 1 of 3

Describe the four tiers of the EU AI Act — including the governance requirements for each tier and an example of a system in each tier.

(1) Unacceptable risk — Prohibited entirely. No AI governance can make these applications permissible. Examples: social scoring systems that rank citizens' general behaviour; AI designed to psychologically manipulate people; mass biometric surveillance in public spaces. (2) High risk — Mandatory conformity assessment before deployment and registration in a public EU database. Examples: employment AI (CV screening, performance monitoring), credit scoring systems, AI in judicial or law enforcement decisions, biometric identification systems. (3) Limited risk — Transparency obligations. Chatbots must tell users they are interacting with AI. Deepfakes must be labelled. Examples: conversational AI used for customer service, AI-generated content tools. (4) Minimal risk — No specific requirements; voluntary codes of conduct encouraged. Examples: spam filters, AI in games, productivity tools, recommendation systems. Most current AI applications fall in this tier.
Question 2 of 3

What are the six NAIC essential practices for AI governance — and what specific failure does each one address?

(1) Name one accountable person — addresses the accountability gap where responsibility is diffused across teams with no one specifically answerable for system outcomes. (2) Understand who is affected — addresses systems like COMPAS that affected individuals who were not users and had no channel to contest decisions. (3) Screen the risk before deployment — addresses the pattern of deploying without formal risk assessment; the seven diagnostic questions operationalise this. (4) Share essential information — addresses lack of operational transparency about what AI is doing in decisions; people must be able to know AI is involved. (5) Test before deployment — addresses Tay (no adversarial testing) and Robodebt (no testing on variable-income scenarios). (6) Monitor after deployment — addresses the reality that bias and reliability failures emerge post-launch; continuous auditing rather than a single go-live gate.
Question 3 of 3

Why is Australia's Office of AI being placed inside the Department of the Prime Minister and Cabinet — rather than a technology or digital portfolio — and what does that placement signal about how government is framing AI governance?

The placement signals that AI governance is being treated as a machinery of government question, not a technology procurement question. By housing the Office of AI within PM&C — the department responsible for coordinating whole-of-government policy and advising the Prime Minister — the government is framing algorithmic accountability as a cross-cutting governance issue affecting every department, rather than an IT matter for a technology portfolio to manage. This mirrors the EU's framing: the AI Act was developed through the European Commission's DG CNECT (Digital) but enforced through national supervisory authorities with cross-sector reach. The implication for organisations is that AI governance will be assessed against political and legal standards set at the centre of government, not just technical standards set by a sector regulator — and that the ADM legislation due December 2026 will apply broadly, not only to technology firms.

Module 5 Videos

Module 5 · Short Video
Module 5 · Long Form · Whose Name Is On That Decision?

Sources

EU AI Act
European Parliament and Council (2024). Regulation (EU) 2024/1689 on Artificial Intelligence. Official Journal of the European Union.
NAIC
National AI Centre (2025). Essential Practices for Responsible AI. Commonwealth of Australia, October 2025.
Office of AI
Department of the Prime Minister and Cabinet (2026). Office of AI — Establishment and mandate. Commonwealth of Australia, July 2026.
Module content
BUSN9049 Module 5 — Ethical Considerations and Responsible AI. Flinders University, 2026.
Innovare Study
Long-form video: Whose Name Is On That Decision? Innovare Study, July 2026. youtu.be/tslQKmfxwk0