The Regulatory Reckoning for Artificial Intelligence
Until recently, artificial intelligence operated in a regulatory vacuum. That era has ended. The EU AI Act1 (the "EU AI Act") - a landmark regulation comprising 180 recitals, 113 articles and 13 annexes - has fundamentally recast the relationship between AI systems and the law and will reshape how organisations develop, deploy, and govern algorithmic decision-making for the immediate future.
TLDR:
- The EU AI Act applies to Australian organisations if their AI outputs are used in the EU - extraterritorial reach is real and enforcement is coming.
- AI systems are classified by risk level: prohibited, high-risk, limited risk, and minimal risk - classification determines your compliance burden.
- Australia hasn't enacted AI-specific legislation yet, but existing laws (consumer protection, privacy, anti-discrimination) already apply to AI systems.
- Start now: conduct an AI inventory, assess risk classifications, and build governance frameworks before mandatory requirements crystallise and enforcement kicks off in earnest.
- Use our AI Compliance Checklist for Australian Organisations to assess your level of compliance.
The implications for Australian organisations are immediate and significant. The extraterritorial reach of the EU AI Act means any AI system whose "output produced by the AI system is used in the Union" "irrespective of whether those providers are established or located within the Union or in a third country." will trigger compliance obligations regardless of where the system operator is headquartered.2 This represents a regulatory shift comparable to the GDPR's transformation of global data protection practice.
What is the EU AI Act?
The EU AI Act introduces a risk-based classification system for AI applications. At the apex sit "prohibited" systems under Article 5 - those deemed fundamentally incompatible with European values, including AI systems deploying "subliminal techniques beyond a person's consciousness" or "purposefully manipulative or deceptive techniques",3 social scoring systems,4 and certain forms of real-time biometric identification in publicly accessible spaces.5 Below these, "high-risk" AI systems face mandatory conformity assessments, technical documentation requirements, and ongoing monitoring obligations.
The Act defines "AI system" as "a machine-based system that is designed to operate with varying levels of autonomy and that may exhibit adaptiveness after deployment, and that, for explicit or implicit objectives, infers, from the input it receives, how to generate outputs such as predictions, content, recommendations, or decisions that can influence physical or virtual environments."6 This definition captures a broad range of systems - from sophisticated machine learning models to simpler rule-based decision systems exhibiting autonomy.
What You Need to Know: The EU AI Act's definition of "AI system" is deliberately broad. If your software makes predictions, recommendations, or automated decisions - even using relatively simple inference - it may fall within scope.
However the EU AI Act does seek to distinguish inference from simpler traditional software. For example, inference should not extend to systems that are based solely on rules to automatically execute operations.
Many Australian organisations operating customer-facing tools, automated workflows, or decision-support systems will need to assess whether their technology qualifies.
High-Risk Systems
An AI system used for things such as:
- Biometrics
- Critical infrastructure including safety, road traffic or the management of water, gas or electricity
- Credit scoring
- Access to essential private and public services such as healthcare
- Law enforcement
- Systems assisting with migration and asylum rights and applications
- Judicial decision making and alternative dispute resolution
- Employment and recruitment
- Elections, including systems intended to influence elections
will be considered a High-risk AI system7 and face substantially greater regulatory burden than one deployed for content recommendation or customer service automation.
What You Need to Know: If your organisation deploys "high-risk" systems accessible in the EU, this triggers mandatory requirements including risk management documentation, data quality standards, transparency measures, and human oversight mechanisms - regardless of where you're based.
There are also important exclusions to the concept of High Risk AI Systems8 that may provide relief from more stringent requirements although such exceptions require careful legal assessment and product planning.
What Does the EU AI Act Require for High-Risk Systems?
High-risk AI systems face substantial compliance obligations under Chapter III of the Act. Providers must establish, implement, document and maintain a "risk management system" that operates as "a continuous iterative process planned and run throughout the entire lifecycle" of the AI system.9
Data governance requirements mandate that high-risk systems "be developed on the basis of training, validation and testing data sets that meet the quality criteria" specified in Article 10.10 Technical documentation must be "drawn up before that system is placed on the market or put into service and shall be kept up-to date."11
Transparency obligations require that high-risk systems "be designed and developed in such a way as to ensure that their operation is sufficiently transparent to enable deployers to interpret a system's output and use it appropriately."12 Human oversight provisions mandate design enabling "effectively overseen by natural persons during the period in which they are in use," with the aim of "preventing or minimising the risks to health, safety or fundamental rights."13
Conformity assessment under Article 43 requires providers to demonstrate compliance with these requirements before placing high-risk systems on the market - through self-assessment where harmonised standards exist, or third-party assessment for certain categories including biometric identification systems.14
How Does Australian Law Approach AI Regulation?
Australia has not yet enacted comprehensive AI-specific legislation, though the policy direction is becoming more clear. The federal government's 2024 consultation on "mandatory guardrails" for high-risk AI applications signals intent to regulate, but leaves fundamental questions such as the scope, enforcement mechanisms and interaction with existing regimes - unresolved for now.
In the interim, AI systems remain subject to a patchwork of existing laws. Consumer protection provisions under the Competition and Consumer Act 2010 (Cth) apply to AI-driven marketing claims. Privacy legislation governs automated processing of personal information under the Privacy Act 1988 (Cth). Anti-discrimination law reaches algorithmic decision-making that produces discriminatory outcomes.
Financial services regulation captures AI deployed in credit assessment or financial advice under the Corporations Act 2001 (Cth) and National Consumer Credit Protection Act 2009 (Cth).
What You Need to Know: Don't assume the absence of AI-specific Australian legislation means your AI systems are unregulated. Consumer guarantees, privacy principles, anti-discrimination provisions, and sector-specific rules (financial services, healthcare, employment) all apply to algorithmic decision-making. A single AI system may trigger obligations under multiple regulatory frameworks simultaneously.
This fragmented landscape creates both risk and opportunity. Risk arises in AI systems because regulatory exposure may lurk in unexpected places that are only discovered on application of the system. There is also significant opportunity, because organisations that establish robust compliance foundations now - drawing on emerging international standards - will be better positioned when domestic regulation crystallises.
Our Approach to AI Compliance
Daimon Legal approaches AI regulation in close collaboration with clients.
We advise on risk classification assessments - analysing AI system functionality against Article 6 classification rules and Annex III categories to determine applicable requirements.15
For high-risk systems, we assist with conformity documentation including technical files required under Article 11, quality management systems, and post-market monitoring arrangements under Article 72.
Where AI governance frameworks are required, we help design structures that satisfy regulatory expectations while remaining operationally practical.
Our work extends to regulatory strategy - helping organisations anticipate how regulators will approach novel AI applications, and positioning for constructive engagement once regulations take shape.
The Intersection of AI and Existing Regulatory Regimes
As you may have noticed from the categories of High-Risk AI systems under the EU AI Act, the breadth of services covered could potentially cut across many otherwise innocuous service offerings.
An AI-powered robo-advisor implicates financial services licensing requirements. Clinical decision support systems engage therapeutic goods regulation. Automated hiring tools raise employment law considerations.
These intersections demand lawyers who understand both the AI-specific regulatory layer and the underlying sectoral regime. Generic AI compliance advice that ignores industry context risks missing critical obligations; industry-specialist advice that treats AI as merely another technology tool may underestimate the distinctive challenges AI systems present.
Daimon Legal brings expertise across multiple regulated sectors - alongside deep engagement with AI-specific regulatory developments.
What Should Organisations Do Now?
The common refrain that AI regulation remains "emerging" should not counsel inaction. Organisations deploying AI in consequential applications face regulatory exposure today, whether from the extraterritorial reach of EU or other regulatory regimes, the application of existing domestic laws to algorithmic systems, or the reputational risks of AI failures in an increasingly scrutinised environment.
A measured response begins with understanding what AI systems the organisation operates, how those systems might be classified under emerging frameworks, and what gaps exist between current practice and anticipated requirements. This assessment provides the foundation for prudent investment in compliance. The significant rewards to service providers offering AI systems will soon come with equal levels of responsibility.
Daimon Legal works with organisations at every stage of this journey - from initial AI inventory and risk assessment through governance framework implementation to ongoing regulatory monitoring and response.
Engaging with AI Regulation
Government consultations, law reform inquiries, and regulatory guidance all present opportunities for organisations to shape the frameworks that will govern their operations. Participation in these processes - done thoughtfully - can influence outcomes while building constructive regulatory relationships.
We can assist clients engaging with AI policy development, whether through formal submissions, industry working groups, or direct regulatory dialogue.
AI Compliance Checklist for Australian Organisations
The following checklist provides a practical starting point for organisations seeking to assess and strengthen their AI compliance posture. It is not exhaustive, but covers the foundational elements most organisations should address.
Inventory and Classification
- Compile a comprehensive inventory of all AI systems currently deployed or under development
- Map each AI system to its business function and the decisions it influences
- Assess whether any systems produce outputs used by EU residents (triggering EU AI Act obligations)
- Classify each system under the EU AI Act risk taxonomy: prohibited, high-risk, limited risk, or minimal risk
- Identify which Australian regulatory regimes apply to each AI system (privacy, consumer protection, sector-specific)
Governance and Accountability
- Designate internal ownership and accountability for AI compliance
- Establish an AI governance framework with clear roles, escalation pathways, and decision-making authority
- Implement policies for AI procurement, development, and deployment approval
- Create documentation standards aligned with EU AI Act technical file requirements
- Develop incident response procedures for AI system failures or unintended outcomes
Risk Management
- Conduct risk assessments for each high-risk AI system covering accuracy, bias, and safety considerations
- Implement ongoing monitoring for model drift, performance degradation, and emerging risks
- Establish processes for regular review and updating of AI systems
- Document risk mitigation measures and their effectiveness
Data Governance
- Audit your organisation's training data for quality, representativeness, and potential bias
- Ensure data handling complies with the Privacy Act 1988 (Cth) and applicable privacy principles. If collecting data from EU residents, ensure privacy policies and data handling comply with relevant provisions of the GDPR.
- Implement data retention and deletion policies for AI training and operational data
- Document data provenance and processing for regulatory scrutiny
Transparency and Human Oversight
- Implement disclosure mechanisms to inform individuals when AI is used in decisions affecting them
- Design human oversight processes enabling meaningful review of AI-generated recommendations
- Ensure AI system outputs are explainable at a level appropriate to the decision context
- Establish appeal or review mechanisms for individuals affected by automated decisions
Regulatory Preparedness
- Monitor Australian government AI policy developments and consultation opportunities
- Track EU AI Act implementation timelines and enforcement guidance
- Engage proactively with relevant industry bodies and regulatory consultations
- Budget for compliance investment as regulatory requirements crystallise
How Daimon Legal Can Help
Navigating AI regulation requires more than general legal knowledge - it demands lawyers who understand both the technology and the rapidly evolving regulatory landscape. Daimon Legal provides practical, commercially-focused advice across the full spectrum of AI compliance challenges.
AI System Classification and Risk Assessment We analyse your AI systems against EU AI Act classification criteria and Annex III categories, providing clear determinations of applicable requirements and compliance pathways. This assessment forms the foundation for proportionate compliance investment.
EU AI Act Compliance Programs For organisations with high-risk AI systems, we develop comprehensive compliance programs including risk management systems, technical documentation, quality management frameworks, and conformity assessment preparation - all aligned with the Act's specific requirements.
AI Governance Framework Design We help design governance structures that satisfy regulatory expectations while remaining operationally practical. This includes policy development, accountability frameworks, approval processes, and board-level reporting mechanisms.
Regulatory Gap Analysis We assess your current AI practices against anticipated Australian requirements and international standards, identifying gaps and prioritising remediation efforts for maximum compliance readiness.
Cross-Regime Compliance Our expertise spans a wide range of service categories - enabling integrated advice where AI systems implicate multiple regulatory frameworks simultaneously.
Regulatory Engagement and Strategy We can assist with submissions to government consultations, engagement with regulators, and strategic positioning as the regulatory landscape evolves. Proactive engagement shapes better outcomes and builds constructive regulatory relationships.
Incident Response and Regulatory Defence When AI systems produce unintended outcomes or attract regulatory attention, we provide rapid response support including regulatory liaison, remediation planning, and public comms strategies.
For a confidential discussion about your organisation's AI compliance requirements, contact Daimon Legal.
The information on this page is general in nature and does not constitute legal advice. Please review our Legal Disclaimer for important information about the limitations of this content and the terms governing your use of this website.
Footnotes
-
Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act), OJ L, 2024/1689, 12.7.2024. ↩
-
EU AI Act, art 2(1)(c). ↩
-
EU AI Act, art 5(1)(a). ↩
-
EU AI Act, art 5(1)(c). ↩
-
EU AI Act, art 5(1)(h). ↩
-
EU AI Act, art 9(1)-(2). ↩
-
EU AI Act, art 14(1)-(2). ↩