
The 15 July framework binds data centres: where they sit, what power and water they draw, what they pay for the grid, plus training on Australian creative work. It puts no new obligation on anyone building with models. What already binds you is the law you have: consumer law, APRA, ASIC, the Privacy Act. Neither document says who gets to say no.
Australia announced a world first in AI last Wednesday. I spent the weekend reading it against our own National AI Plan from December. Turns out the framework covers the shed your AI runs in: the power draw, the water, the grid connection. Your actual model still sits under the same consumer law and sector regulators it always did. Here's what lands on you and what I'd do about it this morning.
Last Wednesday I watched my own Prime Minister announce a world first and felt like an extra in somebody else's movie.
That was five days ago. The takes were up within hours and most of them said the same three things: historic, world first, about time. I had a version of that in my head too.
Then I spent the weekend actually reading both documents. What I came away with isn't in any of the coverage.
Let me back up. A few days earlier I'd watched Daniel Kokotajlo on Diary of a CEO. He co-wrote AI 2027, the scary high-p(doom) forecast and his team is just out with AI 2040: Plan A, an optimistic recommendation this time, not so doomy.
Then Anthony Albanese walked onto a stage at Sydney Uni and announced mandatory Australian Standards for AI, an Office of AI inside PM&C, a national framework he called a first for any country on earth.
And somewhere between the podcast and the PM's speech I realised the real contest is between two giants, the US and China. Everyone else is just a tenant holding a lease.

If you want the long version of that idea, AI 2040: Plan A and Australia 2032 do it better than I can and Ben Reid's Rest of World critique is the counterpunch. Go read them. That's the scenery.
I'm not going to write another opinion about whether Canberra is doing a good job. I'm in a strange spot to have one anyway.
raxIT is an AI-native company. We build with agents, we ship agents and every obligation in this post lands on us the way it lands on you. We're also who other companies call in to secure their agents, here and in jurisdictions that made completely different bets. Every control we ship maps to the EU AI Act and NIST, because our customers don't get the luxury of only caring about Australia.
I read the speech twice. Once as someone who has to comply with it, once as someone who has to explain it to a customer tomorrow.
The question I needed answered was narrower than whether the policy is any good.
Does any of this land on me and what do I do about it?
So I read both documents end to end. Here's what I found.
Australia published a National AI Plan on 2 December 2025. It was completely clear about who was in charge.
"Agencies and regulators will retain responsibility for identifying, assessing, and addressing potential AI-related harms within their respective policy and regulatory domains."
Seven months later, here's the Prime Minister:
"AI touches on the work of every Minister and Department, so it is only natural that, up until now, our response has been issue-by-issue, sector by sector."
"Effective today, I am establishing The Office of AI in my own Department of the Prime Minister and Cabinet."
Same government. Same year. The architecture the Plan defended is the one the PM now calls "issue-by-issue, sector by sector." The Plan isn't named in the speech. Not once.
Credit where it's real though. The data-centre rules genuinely hardened. Principles promised in December, expectations in March, legal obligation now. Large data centres will have to underwrite new power, pay their full grid connection and put back at least as much energy as they take out. That's a real burden and it's new.
But that's not your problem yet.
Trace the antecedents in the speech. "This will bring them into one regulatory framework" refers to large AI data centres. "First country in the world to bring these issues into a single, national framework" refers to "these location, energy and water obligations."
The mandatory perimeter is concrete and copper. Where the shed goes, what it draws off the grid, what it puts back, what water it needs. Plus training on Australian creative work.
There is no new obligation in that speech on anyone who builds, fine-tunes, deploys or sells a model or an agent. Nothing on evaluations. Nothing on incident reporting. Nothing on high-risk classification or transparency.
If you're one of the handful of companies actually building large data centres here, this is your whole world and you've read it twice already. Fair enough. It's a real burden and it's aimed squarely at you.
For everyone else, the people who take a model and build something with it, this framework does not touch you. Ship an agent into an Australian bank next quarter and not one line of it applies.
That's the headline nobody wrote. We're first in the world at regulating the shed the AI runs in.
So if the new thing doesn't bind you, what does?
This is the part I wish someone had just written down. Almost none of it is new. Nearly all of it applies today and the rest has a date. It's sitting in the December plan in plain sight, because December's whole thesis was that established laws remain the foundation.
Consumer law already covers your AI. The December Plan puts it plainly: Treasury's Review of AI and the Australian Consumer Law found Australians "enjoy the same strong consumer protections for AI products and services as they do for traditional goods and services, including safety protections." Your model counts as a product or a service. Treasury flagged that the line between the two is blurry enough that it wants the definition of "goods" tightened. Either way you're inside the ACL. If it misleads a customer or causes harm, the law was already there. Nobody needed a new AI Act for that.
If you're in financial services, your regulator is already looking. The Plan says APRA and ASIC "provide guidance for AI use in banking, insurance, and financial services, including operational risk and governance standards." That's not coming. That's live. APRA went further in April with a letter to industry setting AI-specific expectations on governance, supplier risk, assurance and cyber. ASIC got there in 2024 with REP 798, which found licensees adopting AI faster than they were updating the frameworks meant to govern it.
Privacy already reaches automated decisions and it has a date on it. From 10 December 2026, under APP 1.7, if you use personal information in a computer program that makes decisions significantly affecting someone's rights or interests, your privacy policy has to say so. That is not a proposal. It passed in the Privacy and Other Legislation Amendment Act 2024 and the OAIC can issue infringement notices and chase civil penalties. The Attorney-General is still modernising the rest of the Act, though tranche 2 has no Bill and no timetable. Watch the commenced obligation, not the Office of AI.
Sector regulators keep their patch. Medical device software still sits with the TGA and online harms still run through the enforceable industry codes under the Online Safety Act. Commonwealth systems answer to the same Protective Security Policy Framework they always did, the one that sets requirements for authorising AI inside non-corporate Commonwealth entities. None of that moved an inch this week.
The voluntary stuff is where the standard gets drafted from. The National AI Centre's Guidance for AI Adoption has six essential practices: decide who is accountable, understand impacts and plan accordingly, measure and manage risks, share essential information, test and monitor, maintain human control. Voluntary today. Also the most likely skeleton of whatever becomes mandatory in 2027. Read it now and you're reading next year's exam paper.
Then there's the copyright change and it lands in 2027.
If you train on Australian books, music, art or journalism, the artist keeps control, including of price. "Anything less," the PM said, "is theft." If your data pipeline touches Australian creative content, that's your 2027 problem.

Worth knowing how that sausage is being made. Two days before the speech, an FOI request surfaced a Treasury note. Anthropic's planned A$21.6B build here is "contingent on clarity of copyright settings," driven by wanting "certainty over their liability to rights holders."
Anthropic didn't ask to steal. They flagged a "long tail" of smaller rights holders which, they say, "impedes efforts to identify and purchase licensing rights."
The moral language is for the artist. What's driving Treasury's attention is the balance sheet, the certainty over liability Anthropic wants locked down before that A$21.6B build goes ahead. Whichever way it settles, it settles on your training data.
The standards aren't drafted. National Cabinet next month, legislation early next year. So nobody can tell you what's in them.
Except that's not really true. This is the part where being a middle power is actually useful, because we get to read everyone else's homework first.
Every serious attempt to pin down what good AI governance looks like has landed on roughly the same seven things. Two of them are law: the EU AI Act and Korea's AI Basic Act. Two are voluntary and still the ones everyone actually builds against: NIST's AI Risk Management Framework and ISO 42001. They argue about thresholds and penalties and who counts as high risk. Then they all quietly agree on the same skeleton:
Korea's law only has four of them outright and gates those to high-impact systems. The EU has most of them too, gated to high-risk systems and mostly pointed at whoever builds the thing, not whoever runs it. Fine. The shape still rhymes across all four.
Now go back and look at the six essential practices our own government already published. Decide who is accountable. Understand impacts and plan accordingly. Measure and manage risks. Share essential information. Test and monitor. Maintain human control.
That's the whole skeleton, already written down, in Australia, today. The inventory is in there too, at 4.1, "Maintain an AI register", right down to a downloadable template.
So we already agree on what good looks like. Almost nobody's actually built the register. That's the one you need first because every other practice on the list assumes it exists.
The standard doesn't matter yet. What matters is which of these gets teeth and what the penalty is when it does. Australia would have to work unusually hard to invent an eighth thing nobody else thought of.
Which means the honest answer to "what's coming" is: this, roughly, with an Australian accent and a 2027 date on it. You can start now and be early, or start in 2027 and be late. Nobody gets to be surprised.
Read the verbs, because they decide how all of this actually reaches you.
December, on the AI Safety Institute:
"The AISI will monitor, test and share information on emerging AI capabilities, risks and harms."
"The Institute will support existing regulators with independent advice to ensure AI companies are compliant with Australian law and uphold legal standards around fairness and transparency."
July, on the Office of AI:
"To co-ordinate the design of our new Australian Standards. And to bring together the work that Ministers across Government are undertaking."
Monitor. Test. Share. Advise. Co-ordinate. Bring together.
The Plan does reach for compliance in that last clause. Read the verb though. The Institute supports regulators to ensure compliance. It doesn't do the ensuring. The power stays exactly where it already was.

Two bodies, seven months apart and not one verb in either document that says who says no.
And the one promise that should matter most to anyone running AI here:
"getting this right will enhance our appeal to international investors. By delivering greater clarity and speed for approvals. And a streamlined process for verifying compliance."
Look where that sentence lives. Verifying compliance shows up inside a pitch about investor appeal, sitting next to "speed for approvals." No body owns it. No power behind it. No method described.
That's your problem, not just a political one.
When nobody can say no, the burden doesn't disappear. It moves. It turns into a request to prove. That's what "a streamlined process for verifying compliance" means once you translate it out of speechwriter and into engineering. Every Australian company is going to have to demonstrate its AI meets a standard, with logs and artefacts, whenever someone asks.
That obligation lands at deployment. Exactly where you live.
Nobody's coming to audit your model weights, but somebody, a regulator, a customer's procurement team, an insurer, is eventually going to ask you to show your working.
It is Monday, so here goes. Almost none of this is about 2027. Most of it is what you'd want anyway.
Fair warning before the list. This is what we do for customers and what we do to ourselves, so I have skin in this in both directions. Read the next six paragraphs knowing that. I'd still rather you did all of it with a spreadsheet and a stubborn engineer than not do it at all. This is roughly the order I see it work, in our shop and everyone else's.
Treat the regulation as the floor. This is the one I'd put on a wall. Whatever lands in 2027 is the bare minimum a government could get agreement on and it isn't even drafted yet. Every customer I work with ends up above it and not because they're virtuous. Their board asks harder questions than Canberra does. So does their insurer. So does the enterprise customer running a vendor assessment on them before signing. Compliance is the floor. The bar gets set by whoever can walk away from your deal. I wrote up how the three big regulatory philosophies actually differ back in December. The gap between the strictest customer and the strictest regulator has only widened since.
Find the agents first. You cannot assess what you cannot see and this is the thing customers ask us for more than anything else. Somebody in your org is already building with an API key and a company card. Not out of malice, they're just fast. I called it shadow coding and it is the single most common thing I find that nobody had on a list. Before any governance conversation means anything you need the list: every agent, every model, every tool it can reach, every integration it inherited. No inventory, no risk assessment. No risk assessment, nothing to prove later.
Threat model each agent on its own. Skip the org-wide "AI strategy" workshop and go agent by agent instead. We use MAESTRO for the agentic layers and STRIDE where it still fits, because a lot of what goes wrong is boring and old. What can this thing reach. What happens when someone talks it into something. What does it do at 2am when nobody's watching. Every agent gets its own treatment because every agent has its own blast radius. Most of the blast radius comes from building one agent that can do everything, which is the argument in Kill the God Agent.
Hand over specs, not PDFs. This is where most security programs quietly die. Your engineers are moving at coding-agent speed and you're handing them a 40-page report. Nobody reads it. Write the mitigations as a spec the coding agent can actually consume, at design time, in the loop where the thing is being built. Security that shows up after the PR is just an opinion.
Track posture per application, not per company. Scrappy POC through to production. Which agents are covered, which are lagging, which shouldn't ship yet. If one is lagging, it doesn't ship. That's the gate. It doesn't go to production carrying risk nobody modelled. On what to actually measure per application, here's how we use safety benchmarks to turn a technical result into a business risk.
Then answer one question honestly. Can you say who did what, when and why for a single AI action from last Tuesday? Skip the architecture diagram, go find one real log line for one real action. Something that survives being read by someone who wasn't there:
actor=svc-claims-agent on_behalf_of=alice@bank action=policy.read
object=cust-88213 decided_by=rule-42 at=2026-07-14T09:41:22Z
If you can't produce that, that's the project and it stays the project no matter what the standard says in 2027. That question is the one I keep coming back to, and I built a four-layer model of agent identity around it, because proving who did what turns out to be four separate problems wearing a trench coat. This isn't my invention either. ISO 42001 has a control called "AI system recording of event logs" (A.6.2.8) and the EU AI Act calls it traceability (Art 12).
None of this is exotic. It's ordinary risk-based security, the same shape it's had for twenty years. The only genuinely new part is that the assets move on their own and spawn other assets, so the inventory is never finished and the threat model has a shelf life.
Done properly none of this slows anyone down. The engineer shipping the agent never fills in a governance form. The spec just shows up in their editor next to the code they're already writing, speed doesn't drop and the evidence piles up behind them. When the standard finally arrives in 2027 you're not scrambling, because you already had the answer sitting in a log.
The scramble is the expensive part. And the scramble is what happens to everyone who waits for the government to tell them what good looks like.
We don't out-build Washington or Beijing. Nobody is proposing Australia trains a frontier model and there's no budget for it. That was never the ask. But the audit sits at deployment, in our own courts and our own regulators. Doing it well doesn't take a GPU cluster. That's the one layer a middle power can own. I'd rather we owned it on purpose than discovered it in 2027.
Two documents. Seven months. Monitor, test, share, advise, co-ordinate, bring together.
Somebody has to be able to say no. Until someone can, the person who has to prove it is you.
Could be wrong. Tell me where.
This reads a speech against a plan, not legislation against legislation. The 15 July announcement is a statement of intent and the standards it promises do not exist yet. Where I say something is mandatory, I mean the perimeter the speech named: data centre location, energy, water, grid costs, plus training on Australian creative work. If the drafting lands wider than that, this post ages badly and I would rather be wrong in public than vague.
The Capital Brief piece on Anthropic's FOI returns a paywall for non-subscribers. The facts in it check out against syndicated reporting, so if you hit the wall, TechXplore carried the same story.
Sources: AI in Australia's interests (PM's speech, 15 Jul 2026) · National AI Plan (2 Dec 2025) · Guidance for AI Adoption · AI register template · Expectations for data centres and AI infrastructure developers · Review of AI and the Australian Consumer Law (Treasury) · APRA letter to industry on AI · ASIC REP 798 · OAIC consultation on automated decision-making transparency · EU AI Act · NIST AI Risk Management Framework · Anthropic's Australian ambitions and the copyright wall (Capital Brief) · AI 2040: Plan A · Australia 2032
Working out which of your AI systems already sit under APRA, ASIC or Privacy Act obligations, and whether you could produce the log line that proves it? to discuss your specific deployment context and governance needs.