⚡ Quick Summary
Published by the Digital Transformation Agency (DTA), this policy sets out how Australian Government agencies adopt and use artificial intelligence. It is described as a first step in positioning the Australian Government as an exemplar of safe and responsible AI use, designed to complement and strengthen rather than duplicate existing frameworks across the Australian Public Service (APS).
The policy organises its principles and requirements under an 'enable, engage and evolve' framework. Mandatory requirements include designating accountable official(s) within 90 days of the policy taking effect, notifying the DTA of new high-risk use cases, and publishing an AI transparency statement within 6 months that is reviewed and updated annually. Agencies are strongly recommended to run AI fundamentals training for all staff within 6 months. Scope is defined by entity type: all non-corporate Commonwealth entities must apply the policy, corporate Commonwealth entities are encouraged to, and the defence portfolio and national intelligence community are carved out.
Supporting material includes the OECD definition of an AI system, a list of related frameworks at Attachment A, and a 5x5 risk matrix with example risk questions at Attachment B.
🧩 What’s Covered
The policy runs to 18 pages across an introduction, policy aim, implementation, principles and requirements, references and two attachments.
- Introduction and policy aim: frames AI as reshaping the economy, society and government, records that public trust acts as a "handbrake on adoption" and that APS preparedness varies, and states the aim of safe, ethical and responsible use in line with community expectations, with three sub-aims: embrace the benefits, strengthen public trust, adapt over time.
- Implementation and application: states the policy takes effect on 1 September 2024, applies to all non-corporate Commonwealth entities under the Public Governance, Performance and Accountability Act 2013, encourages corporate Commonwealth entities to apply it, and carves out the defence portfolio and the national intelligence community, listing the bodies concerned including ONI, ASD, ASIO, ASIS, AGO, DIO and ACIC.
- Existing frameworks and AI definition: links the policy to the APS Code of Conduct, data governance, cyber security, privacy and ethics practices, requires it to be read alongside existing frameworks and laws, and adopts the OECD definition of an AI system verbatim, with a commitment to review it as the wider regulatory environment matures.
- enable and prepare: principles on productivity, explainability and accountability, plus mandatory designation of accountable officials within 90 days, notification of new high-risk use cases to the DTA by email, and strongly recommended AI fundamentals training for all staff within 6 months, with additional role-based training.
- engage responsibly: principles on protection from harm, proportionate and targeted mitigation, and transparent and explainable AI use; mandatory publication of an AI transparency statement within 6 months, reviewed and updated annually, covering compliance with the policy, monitoring of deployed systems and efforts to protect the public.
- evolve and integrate: principles on flexibility, ongoing review and feedback mechanisms, with recommended actions on reviewing internal governance, monitoring use cases for unintended impacts, keeping up to date with the policy environment and engaging in whole-of-government capability building.
- References and Attachment A: nine cited sources, including DISR's interim response, PM&C, OAIC, the Productivity Commission, ACOLA and OECD material, and a list of related frameworks such as Australia's AI Ethics Principles, the generative AI guidance, automated decision-making guidance and the Data and Digital Government Strategy.
- Attachment B: a risk matrix scoring consequence (insignificant to severe) against likelihood (rare to almost certain) into low, medium or high, instructions to consult stakeholders, an explicit statement that the policy does not prescribe which risks to assess, and ten example risk questions covering accessibility, discrimination, harm, privacy, security, decision-making influence, reputation and intellectual property.
💡 Why it matters?
The policy responds to a gap it states itself: AI adoption varies across the APS, public trust is low, and agencies lack a common baseline for governance, assurance and transparency. It hands accountable officials concrete deadlines and artefacts — a designated owner, a high-risk use case notification channel to the DTA, an annual transparency statement, staff training — that can be tracked and evidenced. Risk and assurance teams gain a shared rating scale and example risk questions, explicitly intended to be applied alongside existing privacy, protective security, record-keeping, cyber and data frameworks rather than in place of them.
❓ What’s Missing
The policy deliberately stops short of prescribing the risks agencies must assess or the method for reaching final risk outcomes, leaving that to the Commonwealth Risk Management Policy and internal agency approaches. It sets out no consequences for non-compliance and no monitoring mechanism beyond DTA visibility of notified high-risk use cases, and "high-risk use case" is not defined beyond the Attachment B matrix. Required content of the transparency statement is listed at a high level only. The policy is bound to a defined set of Commonwealth entities, with defence and national intelligence excluded, and its AI definition is flagged for future review.
👥 Best For
Accountable officials and AI governance leads in non-corporate Commonwealth entities who must implement the policy, together with their legal, compliance and risk advisers mapping the mandatory requirements and deadlines. It also serves agencies outside scope — corporate Commonwealth entities, or defence and national intelligence bodies considering voluntary adoption — and vendors or assurance providers who need to know what Australian Government agencies will be asked to evidence.
📄 Source Details
Policy for the responsible use of AI in government, Version 1.1, published by the Digital Transformation Agency, Commonwealth of Australia, September 2024; 18 pages, in English. No URL for the document itself is printed; page 2 carries a Creative Commons Attribution 4.0 International licence link and the contact address ai@dta.gov.au. The input was a text extraction covering the full 18 pages, from the cover through the contents, references and both attachments.