Two Stories Running at Once
There are two entirely separate stories in Australian technology this winter, and they are moving in opposite directions.
The first is policy: after years of consultation papers and voluntary guidance, the government has announced it will legislate AI standards and bring large data centres under national rules. Slow, deliberate, aimed at 2027.
The second is practice: Australian organisations have already turned AI on, in large numbers, mostly without deciding anything about it. Fast, unplanned, and happening right now inside tools people already pay for.
The interesting question is not which story wins. It is what a normal Australian business should do in the gap between them — where the rules are coming but not here, and the technology is here but not governed.
The gap this article is about
The Rules: AI Standards Head Into Legislation
On 15 July 2026, the Prime Minister announced the government intends to legislate Australian Standards for AI, and established an Office of AI within the Department of the Prime Minister and Cabinet to coordinate the framework across government.
That is a real change of posture. Australia’s AI settings had been voluntary: the National AI Centre published its Guidance for AI Adoption in October 2025, setting out six essential practices known as the AI6, and that remains the primary government reference for responsible adoption. What changed in July is the stated intention to put standards into law.
What this does and does not mean if you employ eight people
It does not mean an AI compliance burden arriving next quarter. Legislation is expected in early 2027 and the framework targets high-risk uses and large infrastructure. What it does mean is that the direction is settled: using AI on customer data will be regulated in Australia rather than unregulated. The decisions you make now — where your AI runs, whose data it touches, what records it keeps — are the ones you will be asked about later. Choosing tools that already handle it properly costs nothing extra today and quite a lot to retrofit.
The Infrastructure: Data Centres Go to National Cabinet
The concrete half of the July announcement. The government has proposed bringing large AI data centres under nationally consistent rules covering location, supporting infrastructure, energy use and water consumption.
The reported proposals would require large data centres to underwrite new power supplies, cover their share of grid connection costs, and add at least as much electricity to the grid as they consume, plus minimise water use, improve energy efficiency and fund additional water infrastructure they need. The Prime Minister is seeking agreement from state and territory leaders at National Cabinet in August 2026, with legislation expected in Parliament in early 2027.
2×
Australian data centre capacity is on track to double between 2026 and 2030
A$25bn
Microsoft’s Australian expansion commitment, April 2026
A$20bn
AWS’s Australian commitment, June 2025
Early 2027
When legislation is expected in Parliament
Why this belongs in a briefing for ordinary businesses: the reason that capacity is being built here is the same reason it matters to you. Compute located in Australia is compute inside Australian jurisdiction. As AI arrives inside everyday business tools — including call transcription and AI phone agents — the country in which your customers’ voices are processed stops being an abstraction and becomes a line in your privacy policy. That is the practical form of the data sovereignty argument, and it is set out for phone systems in we own the network.
The contested element is energy. AI data centres are large concentrated loads landing on a grid already under strain, and modelling has warned of upward pressure on prices where capacity is added without matching generation — which is precisely what the add-as-much-as-you-consume proposal is meant to address, and why the states need to be at the table.
The Reality: Everyone Already Switched It On
While policy moves toward 2027, here is where organisations actually are.
| Finding | Figure | Reading |
|---|---|---|
| AI agent deployment across Australia and New Zealand (Salesforce) | ~50% of organisations | Mainstream, not experimental |
| How many of those have formal governance | Often little or none | The exposure is the gap, not the technology |
| Australian organisations with AI assistants past pilot (Proofpoint 2026) | 87% | This is not a future conversation |
| Describing their AI security posture as catching up, inconsistent or reactive | 52% | More than half know they are behind their own rollout |
| Australian enterprises with architecture too rigid for AI (Google Cloud) | 58% | Against 83% globally needing upgrades for agentic AI |
Read those together and the picture is consistent: adoption is broad, shallow and largely undecided. Which is neither a crisis nor a triumph — it is a state of affairs with a specific and cheap fix.
Why the Gap Exists (It Is Not Recklessness)
It would be easy to read those numbers as carelessness. That is not what is happening.
AI arrived through the side door. Nobody ran an AI project. Somebody enabled an assistant inside a tool the business already paid for, because a panel appeared offering to summarise something. From the inside it does not feel like deploying artificial intelligence; it feels like ticking a box in existing software. No project, no policy, no decision — because from the user’s point of view no decision was required.
The version that bites a business with six staff
You do not need an enterprise AI strategy to have this problem. You need one person pasting a customer list into a public chatbot to draft a mail-out. That is a disclosure of personal information, not a shortcut — the OAIC has been explicit that privacy obligations attach both to what you put into an AI system and to output containing personal information. The fix is not a governance framework. It is one sentence, said out loud, to everyone: customer information goes only into tools we have chosen, never into a public one.
The Boring Blocker: Nothing Is Connected
Beneath the governance gap sits a duller and more consequential one. Google Cloud’s finding that 58% of Australian enterprises have architectures too rigid for AI translates, out of enterprise language, into something very simple: the systems do not talk to each other.
An AI tool is only as useful as the data and actions it can reach. In most businesses the customer record, the booking system, the phone system and the accounting package are four islands joined by a person copying between them. Put an AI on top of that and it can draft an email; it cannot book a job, update a record or close a loop.
The one question that predicts everything
Can your systems be joined by an API, or only by a human? That answer forecasts whether AI will do anything useful for you better than any vendor demo.
Small businesses often start ahead
Fewer systems, newer systems, no twenty-year-old middleware. A six-person business running four cloud tools is frequently better positioned than a large firm with a decade of custom integration debt.
The phone is usually the most isolated
Calls happen, and nothing about them reaches anywhere else unless somebody types it. It is the biggest island and usually the cheapest bridge.
What to do about it
Whenever you replace anything, treat open APIs as a requirement rather than a bonus. It is the cheapest AI investment available, because it makes every later one possible.
The OAIC Starts Reading Privacy Policies
The Office of the Australian Information Commissioner has begun its first-ever compliance sweep — a targeted review of selected businesses’ privacy policies to test whether they meet the requirements.
A sweep is not an investigation. It is a regulator reading documents that are supposed to be public and accurate, and finding out how many are neither. Most businesses will fall into one of three categories: no privacy policy at all; a policy copied from a template years ago describing practices you abandoned; or a policy that is silent on the AI tools you have since started using.
Three questions, twenty minutes
Open your privacy policy and ask: does it describe what you actually do with personal information today? Does it mention any AI or automated processing you now use? Does it tell people how to contact you and how to complain? A “no” to any of those is a thing to fix before somebody else reads it. General information rather than legal advice — take your own, particularly if you handle health information.
What Lands on 10 December
The item most likely to catch Australian businesses unprepared, because it has had almost no coverage outside legal newsletters.
From 10 December 2026, entities covered by the Australian Privacy Principles that use personal information in automated decisions capable of significantly affecting an individual must set out in their privacy policy the kinds of personal information used and the kinds of decisions made. OAIC guidance is expected around September 2026. The OAIC has separately been working toward registering the Children’s Online Privacy Code by the same date, following an exposure draft on 31 March 2026 with submissions closing 5 June.
| Question | Short answer |
|---|---|
| Does it apply to me? | If you are an APP entity. The $3 million turnover small business exemption still exists as at writing, but many small businesses are covered regardless of turnover â including health service providers of any size and businesses that trade in personal information â and abolishing the exemption has been on the reform agenda for years. |
| What is an automated decision? | One made by a system rather than a person, using personal information, where the outcome could significantly affect someone: eligibility, credit, prioritisation, prices that vary by individual. |
| Does an AI phone agent count? | Generally not if it answers, takes details and routes. It begins to if it decides who gets served, who is turned away, or who is quoted differently. The test is whether a decision is being made about the person. |
| What do I have to do? | Disclose it in the privacy policy: the kinds of information used, the kinds of decisions made. A transparency obligation, not a prohibition. |
Practical advice: between now and December, write down every place where software makes a decision about a person with no human looking at it. For most small businesses that list is short or empty and takes an hour to produce. For the businesses where it is not empty, an hour in August is a great deal cheaper than a scramble in December.
The wider risk backdrop is unchanged: OAIC data recorded 532 notifiable data breaches in the first half of 2025, each affecting an average of more than 10,000 individuals, while reporting through 2026 has described Australian privacy teams shrinking even as AI-related risk grows.
Why This Keeps Coming Back to the Phone
It might seem odd for a phone company to write a technology briefing. There is a structural reason the two subjects keep colliding.
The telephone is simultaneously the most personal-information-dense system in most businesses and the least connected to anything else. Every call is somebody stating their name, their address, their problem, and often their health or financial circumstances. Modern systems record and transcribe all of it. And in most organisations none of it flows anywhere — it sits in a recording nobody classified, with no retention rule, inside a system nobody ever thought of as a data store.
Recordings are personal information
So are transcripts and AI summaries. Where they live, how long you keep them and who can listen are privacy questions rather than IT questions. Australian call recording law is state-based and specific, and worth reading once.
Processing location is a fact you should know
If an AI agent transcribes an Australian customer’s call, the country that happens in is something you should be able to state without checking.
Retention is the free win
Most businesses keep every recording forever because nobody ever chose otherwise. Choosing a retention period takes five minutes and permanently reduces risk â deleted data cannot be breached, subpoenaed or disclosed.
And it is the island worth bridging first
Connecting the phone to the CRM turns the least-integrated system into the most useful one, and it is usually the cheapest integration on the list.
The One-Day Checklist
Everything above, reduced to work a business owner could finish between the morning and the afternoon.
- Say the sentence. To everyone, out loud: customer information goes only into tools we have chosen, never into a public chatbot. Five minutes, and it is the highest-value item on this list.
- Inventory the AI you already have. Every AI feature switched on across the business, including the ones inside software you already paid for. Thirty minutes, and most people are surprised by the length.
- List the automated decisions. Anywhere software decides something about a person with no human reviewing it. Usually short. Occasionally not, and that is exactly what you want to know before December.
- Read your privacy policy as the regulator would. Fix what is no longer true, add what is now true. One to two hours.
- Ask every vendor holding customer data one question in writing. Which country is it processed and stored in? Twenty minutes to send, and the answers are informative in themselves.
- Set a retention period for call recordings and transcripts. And apply it. Thirty minutes, permanent benefit.
None of that is an AI strategy and it is not trying to be. It is the small set of decisions that determine whether the next two years of AI in your business happen deliberately or by accident. If you would rather start with the practical side than the policy side, where a small business should start with AI is the companion, and the August telco briefing covers the rest of the month.
Frequently Asked Questions
Is Australia legislating AI?
Yes, and the direction was settled in July 2026. On 15 July the Prime Minister announced the government intends to legislate Australian Standards for AI, and established an Office of AI within the Department of the Prime Minister and Cabinet to coordinate the framework across government. That follows a period of voluntary settings - the National AI Centre published its Guidance for AI Adoption in October 2025, setting out six essential practices known as the AI6, which remains the primary government reference for responsible adoption. Alongside the standards work sits a proposed national framework for large AI data centres going to National Cabinet in August 2026, with legislation expected in Parliament in early 2027. For a business with a handful of staff, this does not mean a compliance burden arriving next quarter, since the framework targets high-risk uses and large infrastructure. What it does mean is that using AI on customer data will be regulated in Australia rather than unregulated, so decisions made now about where your AI runs and whose data it touches are decisions you will be asked about later.
What are the proposed rules for AI data centres in Australia?
The government has proposed bringing large AI data centres under nationally consistent rules covering their location, supporting infrastructure, energy use and water consumption. The reported proposals would require large data centres to underwrite new power supplies, cover their share of grid connection costs, and add at least as much electricity to the grid as they consume, along with obligations to minimise water use, improve energy efficiency and fund any additional water infrastructure they require. The Prime Minister is seeking agreement from state and territory leaders at National Cabinet in August 2026, with legislation expected in Parliament in early 2027. The scale behind it is significant: Australian data centre capacity is on track to double between 2026 and 2030 with AI workloads the primary driver, against major commitments including Microsoft's A$25 billion Australian expansion in April 2026 and AWS's A$20 billion in June 2025. Energy is the contested part, because these are large concentrated loads arriving on a grid already under strain, which is what the add-as-much-as-you-consume proposal is designed to address.
How many Australian organisations are using AI without governance?
A striking proportion. Research from Salesforce puts AI agent deployment at around 50% of organisations across Australia and New Zealand, frequently with little or no formal governance in place. Proofpoint's 2026 report found 87% of Australian organisations have deployed AI assistants beyond the pilot stage, while 52% describe their own AI security posture as catching up, inconsistent or reactive - meaning more than half know they are behind their own rollout. Google Cloud separately found 58% of Australian enterprises have IT architectures too rigid to support AI properly, against 83% globally needing upgrades for agentic AI. Read together, adoption is broad, shallow and largely undecided. The reason is not recklessness: AI arrived through the side door, when somebody enabled an assistant inside a tool the business already paid for because a panel appeared offering to summarise something. From the inside that does not feel like deploying artificial intelligence, it feels like ticking a box in existing software, so no project was filed and no policy was written.
What is the privacy obligation starting on 10 December 2026?
From 10 December 2026, entities covered by the Australian Privacy Principles that use personal information in automated decisions capable of significantly affecting an individual must set out in their privacy policy the kinds of personal information used and the kinds of decisions made. OAIC guidance is expected around September 2026, and the OAIC has separately been working toward registering the Children's Online Privacy Code by the same date, following an exposure draft released on 31 March 2026 with submissions closing 5 June. Two clarifications matter. Whether it applies depends on whether you are an APP entity: the $3 million turnover small business exemption still exists as at writing, but many small businesses are covered regardless of turnover, including health service providers of any size and businesses that trade in personal information. And it is a transparency obligation rather than a prohibition - you are being asked to disclose, not to stop. An AI phone agent that answers, takes details and routes calls generally would not trigger it; one that decides who gets served or who is quoted differently starts to. General information, not legal advice.
Why do Australian businesses struggle to get value from AI?
Usually because nothing is connected, rather than because the AI is inadequate. Google Cloud found 58% of Australian enterprises have IT architectures too rigid to support AI properly, against 83% globally needing upgrades for agentic AI. Translated out of enterprise language, the systems do not talk to each other: in most businesses the customer record, the booking system, the phone system and the accounting package are four islands joined by a person copying between them. Put an AI tool on top of that and it can draft an email, but it cannot book a job, update a record or close a loop, because it cannot reach anything. The single question that predicts whether AI will be useful to you is whether your systems can be joined by an API or only by a human. Smaller businesses frequently start ahead here, running fewer and newer systems without a decade of custom integration debt. The phone system is usually the most isolated island of all, and also the cheapest bridge to build.
What is the OAIC compliance sweep and should I worry about it?
It is the Office of the Australian Information Commissioner's first-ever compliance sweep: a targeted review of selected businesses' privacy policies to check whether they meet the requirements. Worry is the wrong response, but action is warranted, because a sweep is simply a regulator reading documents that are meant to be public and accurate and discovering how many are neither. Most businesses fall into one of three categories - no privacy policy at all, a policy copied from a template years ago describing practices that have since changed, or a policy that says nothing about the AI tools the business has started using. Checking your own takes about twenty minutes. Open it and ask three questions: does it describe what you actually do with personal information today, does it mention any AI or automated processing you now use, and does it tell people how to contact you and how to complain. A no to any of those is something to fix before somebody else reads it. Take your own legal advice, particularly if you handle health information.
What should a small business do about AI and privacy before December?
Six things, and together they fit in a single working day. Say the sentence out loud to everyone: customer information goes only into tools we have chosen, never into a public chatbot - five minutes, and the highest-value item on the list, because a staff member pasting a customer list into a public tool is a disclosure of personal information rather than a shortcut. Inventory every AI feature switched on across the business, including those inside software you already paid for, which takes about thirty minutes and usually produces a longer list than expected. Write down anywhere software makes a decision about a person with no human reviewing it, which is what the 10 December obligation turns on. Read your privacy policy as the regulator would and fix what is no longer true. Ask every vendor holding customer data, in writing, which country it is processed and stored in. And set a retention period for call recordings and transcripts, then apply it, because deleted data cannot be breached, subpoenaed or disclosed.