Back to Publications
Summary of Australian Integrated AI Regulation Approach
article

Summary of Australian Integrated AI Regulation Approach

Ali Mirzaei

October 30, 2024

Share / commentLinkedIn

Implementing AI regulations is a crucial step for Australia, aligning us with global leaders to ensure AI is safe, ethical, and transparent. This article summarisesย the current Australian AI regulatory guardrails for a quick view.

Keywords: AI, governance, regulation, Australia

For AI system developers or deployers working within Australia or with Australian industries/government, "Safe and Responsible AI in Australia" (currently 69 pages) provides a comprehensive regulatory framework. I have summarised the key points here for a quick overview.

The anticipated regulations in each country/region are crucial, as they will substantially affect technical, legal, and executive processes within the AI industry both domestically and globally.

๐—ข๐˜ƒ๐—ฒ๐—ฟ๐˜ƒ๐—ถ๐—ฒ๐˜„

This document:

  • is currently in confirmation process. I have condensed the content to retain the main points of September 2024 version, for further details refer to the full document here (PDF).

  • reflects/refers to approaches mainly from the EU and Canada (also UK and US) to maintain international consistency.
  • defines high-risk settings, 10 mandatory guardrails, and 3 possible approaches to mandate the guardrails.
  • differentiates between narrow AI systems and general-purpose AI (GPAI) models.
๐——๐—ฒ๐—ณ๐—ถ๐—ป๐—ถ๐—ป๐—ด ๐—ต๐—ถ๐—ด๐—ต-๐—ฟ๐—ถ๐˜€๐—ธ ๐—”๐—œ

Category 1: in which uses of the AI system or GPAI model are known or foreseeable and assessed as high-risk. The risk assessment for this category is based on the following principles, considering the adverse impacts to:

a.ย  an individualโ€™s rights recognised in Australian human rights law without justification, in addition to Australiaโ€™s international human rights law obligations

b.ย  an individualโ€™s physical or mental health or safety

c.ย  legal effects, defamation or similarly significant effects on an individual

d.ย  groups of individuals or collective rights of cultural groups

e.ย  the broader Australian economy, society, environment and rule of law

f.ย  severity and extent of those adverse impacts outlined in principles (a) to (e) above.

Category 2: advanced GPAI models where all possible applications and risks cannot be foreseen. GPAI is defined as:

๐˜ˆ๐˜ฏ ๐˜ˆ๐˜ ๐˜ฎ๐˜ฐ๐˜ฅ๐˜ฆ๐˜ญ ๐˜ต๐˜ฉ๐˜ข๐˜ต ๐˜ช๐˜ด ๐˜ค๐˜ข๐˜ฑ๐˜ข๐˜ฃ๐˜ญ๐˜ฆ ๐˜ฐ๐˜ง ๐˜ฃ๐˜ฆ๐˜ช๐˜ฏ๐˜จ ๐˜ถ๐˜ด๐˜ฆ๐˜ฅ, ๐˜ฐ๐˜ณ ๐˜ค๐˜ข๐˜ฑ๐˜ข๐˜ฃ๐˜ญ๐˜ฆ ๐˜ฐ๐˜ง ๐˜ฃ๐˜ฆ๐˜ช๐˜ฏ๐˜จ ๐˜ข๐˜ฅ๐˜ข๐˜ฑ๐˜ต๐˜ฆ๐˜ฅ ๐˜ง๐˜ฐ๐˜ณ ๐˜ถ๐˜ด๐˜ฆ, ๐˜ง๐˜ฐ๐˜ณ ๐˜ข ๐˜ท๐˜ข๐˜ณ๐˜ช๐˜ฆ๐˜ต๐˜บ ๐˜ฐ๐˜ง ๐˜ฑ๐˜ถ๐˜ณ๐˜ฑ๐˜ฐ๐˜ด๐˜ฆ๐˜ด, ๐˜ฃ๐˜ฐ๐˜ต๐˜ฉ ๐˜ง๐˜ฐ๐˜ณ ๐˜ฅ๐˜ช๐˜ณ๐˜ฆ๐˜ค๐˜ต ๐˜ถ๐˜ด๐˜ฆ ๐˜ข๐˜ด ๐˜ธ๐˜ฆ๐˜ญ๐˜ญ ๐˜ข๐˜ด ๐˜ง๐˜ฐ๐˜ณ ๐˜ช๐˜ฏ๐˜ต๐˜ฆ๐˜จ๐˜ณ๐˜ข๐˜ต๐˜ช๐˜ฐ๐˜ฏ ๐˜ช๐˜ฏ ๐˜ฐ๐˜ต๐˜ฉ๐˜ฆ๐˜ณ ๐˜ด๐˜บ๐˜ด๐˜ต๐˜ฆ๐˜ฎ๐˜ด.

The Australian Government proposes to apply mandatory guardrails to all GPAI models.

๐Ÿญ๐Ÿฌ ๐—บ๐—ฎ๐—ป๐—ฑ๐—ฎ๐˜๐—ผ๐—ฟ๐˜† ๐—ด๐˜‚๐—ฎ๐—ฟ๐—ฑ๐—ฟ๐—ฎ๐—ถ๐—น๐˜€ ๐—ณ๐—ผ๐—ฟ ๐—ต๐—ถ๐—ด๐—ต-๐—ฟ๐—ถ๐˜€๐—ธ ๐˜€๐—ฒ๐˜๐˜๐—ถ๐—ป๐—ด๐˜€

The goal of mandatory guardrails is to ensure:

  • Testing to meet performance metrics
  • Transparency on development process and application
  • Accountability for governance

These guardrails for both developers and deployers are:

1. Establish, implement and publish an accountability process including governance, internal capability and a strategy for regulatory compliance. Organisations must make their accountability processes publicly available which covers:

  • a documented approach to regulatory compliance
  • policies for data and risk management
  • clear roles, responsibilities and reporting structures for staff
  • details of the training organisations make available to staff

2. Establish and implement a risk management process to identify and mitigate risks arising from a high-risk AI system using the high-risk principles. This process includes assessing the impacts of risks, identification, application and monitoring of mitigation measures and mechanisms to identify new risks.

3. Protect AI systems, and implement data governance measures to manage data quality and provenance, data privacy and cybersecurity to ensure reliability of an AI model and unbiased discriminatory outputs.

4. Test AI models and systems to evaluate model performance and monitor the system once deployed (supported by methodologies outlined in known standards).

5. Enable human control or intervention in an AI system to achieve meaningful human oversight. AIโ€™s operations and outputs should be reversable by a human if necessary.

6. Inform end-users regarding AI-enabled decisions, interactions with AI and AI-generated content, how and where they have been used in a clear and accessible manner.

7. Establish processes for people impacted by AI systems to challenge use or outcomes, including internal complaint handing functions and human staff

8. Be transparent with other organisations across the AI supply chain about data, models and systems to help them effectively address risks. This includes transparent application guidelines from developers and failure reports from deployers.

9. Keep and maintain records to allow third parties to assess compliance with guardrails, including AI system description, design specifics, capabilities and limitations, testing methodologies and results, datasets details, risk management processes and human oversight measures.

10. Undertake conformity assessments to demonstrate and certify compliance with the guardrails, before placing a high-risk AI system, carried out by the developers themselves, by a third-party or by government entities or regulators. Organisations will need to periodically (or in case of a system change impacting compliance) repeat the assessment to ensure continued compliance.

Notes:

  • Developers and deployers will need to consider who their end-users are.
  • Users need to meet any legal obligations under existing laws.
๐—ฅ๐—ฒ๐—ด๐˜‚๐—น๐—ฎ๐˜๐—ผ๐—ฟ๐˜† ๐—ผ๐—ฝ๐˜๐—ถ๐—ผ๐—ป๐˜€ ๐˜๐—ผ ๐—บ๐—ฎ๐—ป๐—ฑ๐—ฎ๐˜๐—ฒ ๐—ด๐˜‚๐—ฎ๐—ฟ๐—ฑ๐—ฟ๐—ฎ๐—ถ๐—น๐˜€:

The proposal paper outlines three potential regulatory models to implement the guardrails:

1. A domain specific approach โ€“ Adopting the guardrails within existing regulatory frameworks as needed (sector-by-sector basis review of each relevant piece of legislation)

2. A framework approach โ€“ Introducing new framework legislation to adapt existing regulatory frameworks across the economy

3. A whole of economy approach โ€“ Introducing a new cross-economy AI-specific Act

Final notes:
  • This document proposes treating national security and defence applications separately from civilian applications, similar to US and EU.
  • See the original document for further details.
  • Future versions of this document may update or modify the contents outlined above.