At a data and AI conference recently, I heard a speaker talk about automated decision-making reform as if the Privacy Act was moving towards a ban on AI use. Afterwards, someone I met there asked me whether that was true, and what it meant for AI if regulation was heading that way. The exchange stayed with me because it exposed 2 equal and opposite mistakes at once: the alarmist reading that privacy reform is shutting AI down, and the opportunistic reading that, because Australia still has no dedicated AI regulation, businesses are effectively free to do what they like.
The current Australian position on AI regulation is awkward to discuss plainly. Most businesses understand it anyway.
For now, the absence of a dedicated AI Act gives many organisations more room than the public debate suggests. That room is real. It is also temporary.
The mistake is treating it as safety.
My answer was that the position is more nuanced than either of those readings allows. If you were a more aggressive business, you could look at the current Australian settings and see a window to do almost whatever you wanted with AI. The room is real. But it is still only a window, and the ADM debate matters because it signals something larger: the Privacy Act is beginning to flex into automated decision-making, which means the expectation to get your house in order is arriving before a dedicated AI regime does.
That is the point many organisations are in danger of missing. The absence of a dedicated AI Act does not leave a blank space; it creates a period in which the legal perimeter is still lighter, the scrutiny is less consolidated, and the smarter move is to build while the environment is still giving you room to do it.
The Window Is Real
Australia hasn’t asked organisations to absorb a new cross-cutting AI statute with unfamiliar definitions, conformity obligations and a fresh supervisory model. Organisations are still operating mainly through concepts they already know: privacy, consumer and conduct risk, sector obligations, discrimination, contract, cyber and board accountability.
A known legal environment is easier to build into than a new one. The Privacy Act is changing, but it is still a body of law organisations know how to work with, and large organisations already have muscle memory around privacy assessments, incident pathways, data governance and legal review. For firms used to GDPR-style regulation, the Australian position is not as novel or alarming as current debate can make it sound. It also remains below stronger global benchmarks in important respects, which gives some organisations more latitude to experiment, slower regulatory confrontation, and fewer immediate surprises than they would face under a more prescriptive set of rules.
It’s better to be honest about that than to pretend everyone is paralysed by uncertainty.
The current position gives organisations time to build.
Breathing Room Is Not Safety
The absence of a dedicated AI Act doesn’t take pressure off. Organisations are still making decisions inside privacy obligations, conduct risk, discrimination law, sector-specific compliance settings and customer expectations, while government policy and voluntary guidance are getting more specific even where they stop short of creating a private-sector AI Act.
What the current environment delays is some of the formal specificity, not the need to make those calls. Some organisations will use the room well; others will treat the absence of a dedicated AI regime as permission to leave the hard decisions for later, which is a much riskier bet than it sounds.
You still need to decide how data is being used, how automated decisions are governed, how customer impact is assessed, and how the organisation will explain itself later if challenged. Those calls don’t become optional just because the law hasn’t yet been consolidated into one AI statute.
What Stronger Organisations Do Now
Stronger organisations use the window to build while the perimeter is still relatively stable.
That means getting the basics into shape while the cost is still lower than it will be once reform becomes more prescriptive. Privacy and data governance foundations need to be stronger, AI use cases need to be treated as enterprise governance questions rather than technical experiments to regularise later, and inventory discipline and risk assessment need to improve in the areas where future scrutiny is most likely to land.
For organisations already operating under stronger global expectations, the opportunity is clearer. If a business is used to more demanding privacy, transparency or governance requirements elsewhere, the current Australian position gives it time to work those practices into local operations before those choices are forced under pressure and before the regulatory environment becomes less forgiving.
Some organisations will use the current position to strengthen accountability. Others will use it to postpone design decisions, tolerate immature governance, and rely on the fact that the perimeter hasn’t yet tightened enough to expose them.
When the window closes, only one of those positions will hold.
How The Window Closes
The window may not close through one dramatic AI Act.
It may close through privacy reform, regulator guidance, customer expectation, sector rules, litigation, procurement pressure, government policy, or board intolerance for weak AI governance. The point doesn’t depend on predicting the exact mechanism. It depends on recognising that the current position is unlikely to be the last word.
The phrase “no AI regulation” is misleading. It sounds like an absence (which is why it is such a comfortable phrase), but organisations are still operating inside dense obligations and exposures. What they lack, for now, is one dedicated Australian AI regime that makes the pressure more explicit and more expensive to ignore.
The organisations that understand it won’t confuse breathing room with safety. They’ll treat the current environment as a period of relative certainty in which they can tighten data discipline, set clearer decision rules and build governance before the next obligation forces those choices under pressure.
The same breathing room a more aggressive business might read as permission is the breathing room a serious one uses to get its house in order. Waste it, and those same decisions will be forced later, under pressure, at higher cost, and with much less room to move.