| EU Artificial Intelligence Act | Binding EU law | Obligations vary by regulated role, system classification and application date. | Classification, transparency, records, human oversight and technical evidence. |
|---|
| Australian Guidance for AI Adoption | Voluntary government guidance | Australian developers and deployers; it does not create new legal duties. | Accountability, risk, stakeholder engagement, transparency, testing and monitoring. |
|---|
| OAIC privacy and AI guidance | Regulator guidance | Interprets Privacy Act and Australian Privacy Principles duties for entities in scope. | Privacy by design, vendor diligence, personal information, retention and transparency. |
|---|
| APRA Letter to Industry on Artificial Intelligence | Supervisory letter | APRA-regulated entities; published 30 April 2026. | Accountability, materiality, inventories, controls, third parties and operational resilience. |
|---|
| ASIC REP 798 and RG 271 | Regulatory findings and guidance | Financial firms and complaint handling within the stated regulatory scope. | Governance observations, customer impact, complaint recognition, records and escalation. |
|---|
| ISO/IEC 42001 and ISO/IEC 23894 | Voluntary international standards | Management-system and AI risk references unless adopted by contract, policy or regulation. | Management review, lifecycle risk, monitoring, corrective action and continual improvement. |
|---|
| NIST AI Risk Management Framework | Voluntary US Government framework | Globally usable operating reference; cite the edition used. | Govern, Map, Measure and Manage; evaluation and generative-AI risk treatment. |
|---|
| ASD secure AI development guidance | Non-binding cyber guidance | Whole-lifecycle secure design and operation guidance published by ASD's ACSC. | Threat modelling, supply chain, asset records, secure defaults and incident management. |
|---|