Grafison

Australia's Voluntary AI Safety Standard, in plain language

3 min readAlok

What is Australia's Voluntary AI Safety Standard?

The Voluntary AI Safety Standard is Australian government guidance setting out ten guardrails for organisations developing or deploying AI. It is not law. It describes how to govern AI responsibly, and it is the clearest signal available of what mandatory obligations for high-risk AI are likely to look like.

If you run AI in an Australian organisation, this is the document your board will eventually ask you about. It is worth understanding before that happens.

Is the Voluntary AI Safety Standard law?

No. It is guidance, published by the Australian government to help organisations deploy AI responsibly. Nothing in it creates an obligation on its own.

That does not make it optional in practice. Two things give it weight. First, the government has separately consulted on mandatory guardrails for AI in high-risk settings, and those proposed obligations closely track the voluntary ones. An organisation that adopts the voluntary standard now is doing most of the work that a future obligation would require. Second, procurement teams have started asking about it. If you sell into government or into a large regulated enterprise, someone will put it in a questionnaire.

What do the guardrails actually ask for?

The standard is organised around ten guardrails. Read together, they describe an organisation that can answer four questions about any AI system it runs: who is accountable for it, what could go wrong, how a person stays in control, and what evidence exists that any of this is true.

In practice they cover:

  • Accountability. A named owner, a governance process, and a strategy that someone senior has actually signed.
  • Risk management. A repeatable way to identify and treat AI risks, including risks to people affected by a decision rather than only risks to the business.
  • Data governance. Knowing what data trains and feeds a system, and protecting it.
  • Testing and monitoring. Evaluating a system before it goes live and continuing to watch it afterwards, against defined measures.
  • Human control. Meaningful oversight, with a person able to intervene rather than merely to observe.
  • Informing end users. Telling people when AI is being used and what it is doing.
  • Contestability. A route for a person affected by an AI-assisted decision to challenge it.
  • Supply chain transparency. Knowing what is inside the AI you bought, and telling your customers what is inside what you sell.
  • Record keeping. Documentation good enough for a third party to assess.
  • Stakeholder engagement. Involving the people the system affects, including on safety, diversity and fairness.

Most organisations find the first three easier than they expected, and the last four harder. Contestability and supply chain transparency are usually where the real work is, because both require you to know things about your vendors that your contracts may not currently entitle you to.

How does this relate to the proposed mandatory guardrails?

The mandatory guardrails proposed for high-risk settings mirror the voluntary ones closely, with one significant addition: conformity assessment. Where the voluntary standard asks you to engage stakeholders, the mandatory proposal adds a requirement to demonstrate and certify compliance.

That difference matters for planning. Adopting the voluntary standard builds the controls. It does not, on its own, build the evidence trail that a conformity assessment would need. If you think you operate in what would be classed as a high-risk setting, keep records as though someone external will read them.

Where should an organisation start?

Not with a policy. Start with an inventory.

You cannot apply ten guardrails to systems you have not identified, and an organisation almost always runs more AI than its own register shows. The models your data team built are the easy part. The harder part is the AI that arrived inside software you bought, where a vendor added a feature and nobody recorded it as an AI decision.

Once the inventory exists, tier it by consequence rather than by technology. A model that ranks internal documents and a model that affects someone's credit, employment or care are not the same problem, and treating them the same wastes effort on the first while under-serving the second.

What this does not tell you

The standard describes what good governance looks like. It does not tell you whether your particular use of AI is lawful. Privacy obligations, anti- discrimination law, sector regulation and your own licence conditions all continue to apply, and they are where the enforceable risk currently sits.

Treat the guardrails as the operating model, and get specific legal advice on the obligations underneath them.

Start with an assessment, not a proposal.

Tell us what you are building and what you are accountable for. If we are not the right people for it, we will say so and point you at who is.