AI governance
Guidance for AI Adoption (AI6): Australia's six essential AI practices, explained
The National AI Centre's Guidance for AI Adoption is the government's main playbook for using AI responsibly. It updated the Voluntary AI Safety Standard in October 2025. Here are the six practices, the free templates and a 90-day plan for a small or mid-sized organisation.
By the AusGPT team · Updated · 7 min read
General information only, not legal advice. Check the primary sources linked below, and get advice for your situation.
The Guidance for AI Adoption is the Australian Government's main framework for using AI responsibly in organisations. The National AI Centre (NAIC), part of the Department of Industry, Science and Resources, published it on 21 October 2025. Its six "essential practices", often shortened to AI6, are:
- Decide who is accountable
- Understand impacts and plan accordingly
- Measure and manage risks
- Share essential information
- Test and monitor
- Maintain human control
It is the first update to the Voluntary AI Safety Standard (VAISS) from 2024. The NAIC says the update "condensed 10 guardrails into 6 essential practices", removed redundant language and expanded the audience to developers as well as deployers. If you were working towards the VAISS guardrails, this is now the version to use.
Who it's for and how it's structured
There are two versions:
- Foundations (about ten pages) is for "businesses and organisations in the early stages of adopting AI". Each practice has a few "getting started" actions and some "next steps".
- Implementation guidance is for teams that build or customise AI systems, use AI in more complex ways, manage higher-risk use cases or need stronger controls. It breaks each practice into detailed, numbered actions. Actions marked "(DEV)" apply to developers.
The guidance isn't legislation. The National AI Plan (2 December 2025) says the government's regulatory approach will "continue to build on Australia's robust existing legal and regulatory frameworks". In other words, privacy, consumer, workplace and anti-discrimination law already apply to AI, and AI6 is a practical way to show you're managing those risks. The Foundations document also says it "does not replace" your data, privacy and cyber security frameworks.
Commonwealth agencies are different. Non-corporate Commonwealth entities must follow the Digital Transformation Agency's Policy for the responsible use of AI in government, now at version 2.0 (effective 15 December 2025), with some exceptions.
The six practices in plain English
| Practice | What it asks for | First steps from the Foundations version |
|---|---|---|
| 1. Decide who is accountable | Someone senior owns AI governance, and every AI system has a named owner | Assign a senior AI governance owner. Create an AI policy. |
| 2. Understand impacts and plan accordingly | Know who your AI affects, and give them a way to raise problems | Carry out a stakeholder impact assessment. Set up channels to report problems or challenge AI decisions. |
| 3. Measure and manage risks | Screen use cases and apply controls that match the risk | Create a risk screening process, using the AI screening tool. |
| 4. Share essential information | Keep an AI register and tell people when AI is involved | Create and maintain an AI register. Disclose your use of AI. |
| 5. Test and monitor | Check AI works before and after you deploy it | Ask suppliers for proof of testing. Test before deploying. Monitor after. Extend data governance and cyber security to AI. |
| 6. Maintain human control | People can oversee, override or switch off AI | Ensure meaningful human oversight. Build in override points. |
A few points in the detail are worth knowing:
- Context matters more than the tool. The guidance's own example: using ChatGPT to draft marketing emails "is different from using it to assess job applications". Each use case needs its own checks.
- The register covers embedded AI. It should include AI you procured and AI built into other systems, such as HR and customer engagement tools, not just standalone chat tools.
- Transparency is about people affected. Disclosure is "especially important" where AI makes or influences decisions, generates content that can meaningfully affect people, or could be mistaken for a human.
- Oversight should match the stakes. That could mean automated monitoring for low-stakes uses and "mandatory human review for high-stakes decisions".
- Keep a fallback. Make sure critical functions can continue if an AI system fails or is retired.
The free templates and tools
The NAIC publishes practical resources on ai.gov.au:
- AI policy guide and template (Word). It covers principles, expected behaviours, roles, approval points and review. The NAIC's checklist says a finished policy should state what AI can and can't be used for, who approves higher-risk use cases, "what data staff can put into tools", when staff need to oversee AI use, how to report issues and when the policy will be reviewed.
- AI register template (Word and Excel). Recommended fields include system name and version, owner, status, source, purpose, intended use cases, limitations and prohibited uses, foreseeable misuse, data sources, registration date, screening result and affected stakeholders. It recommends appointing a register administrator and capturing "AI features embedded in common software packages".
- AI screening questions. Seven yes/no questions to run before a full risk assessment. A "yes" to any of them means the use case needs more governance attention. They cover personal, sensitive or confidential information, autonomy without meaningful human oversight, acting at scale, decisions affecting people in vulnerable circumstances, regulated areas or legal effects, harm that's hard to reverse, and general-purpose tools that are easily adapted.
- Planning tools: questions to ask AI suppliers, a data quality checklist, a business process mapping template and team scenario exercises.
Note that the first screening question is whether the system handles "personal, sensitive, or confidential information" as input. For most organisations using general-purpose AI chat tools, at least one answer will be yes. That doesn't mean "don't use it". It means approve the tool deliberately and set rules for it.
Applying AI6 to a general-purpose AI chat tool
Most small and mid-sized organisations start with a chat assistant for drafting, summarising and research. Under AI6, approving one comes down to a few questions, each tied to a practice:
| Question | Practice |
|---|---|
| Who owns this tool, and who approves new uses of it? | 1. Accountability |
| Will staff put personal, client or confidential information into it, and is that allowed by our policy? | 3. Risks (screening question 1) |
| Does the supplier use our inputs to train models, how long does it keep them, and where are they stored and processed? | 5. Test and monitor (ask for proof, extend data governance) |
| Can admins control access, remove leavers and turn off risky features? | 6. Human control |
| Is it in the register, with its approved and prohibited uses? | 4. Share essential information |
| Will its output be used to make decisions about people? If so, what review applies? | 2. Impacts and 6. Human control |
Write the answers down in your register and policy. The guidance asks you to document every activity in the essential practices, so you can audit and review your governance later.
A 90-day plan for a small or mid-sized organisation
This plan follows the Foundations "getting started" actions. Adjust the pace to your size and risk.
Days 1 to 30: get visibility and set the rules
- Name a senior AI governance owner with enough authority to say yes or no to AI use (practice 1.1).
- Find out what's already in use. Survey staff, including about personal accounts, and check your existing software for AI features.
- Start the AI register from the NAIC template. Record each system, its owner and its use cases (practice 4.1).
- Run each use case through the screening questions and record the result in the register (practice 3.1).
- Adopt an AI policy from the NAIC template (practice 1.2). Decide which tools are approved and what information may go into them.
- Move staff onto approved tools. Unapproved personal accounts are the most common gap. Our guide to whether ChatGPT is safe for business covers what to check.
Days 31 to 60: impacts, transparency and testing
- Do a stakeholder impact assessment for any use case that screened "yes", paying attention to vulnerable groups (practice 2.1).
- Set up a way to raise concerns about AI outputs or decisions, for customers and staff (practice 2.2).
- Disclose AI use where it matters: chatbots, AI-generated communications, and decisions about people. From 10 December 2026, the Privacy Act will require privacy policy disclosures for automated decisions that significantly affect people.
- Ask suppliers for evidence of testing, data handling and where data is stored and processed (practice 5.1). The NAIC's supplier questions help here.
- Test before rollout on your own realistic tasks, and define who reviews outputs and when (practices 5.2 and 6.1).
Days 61 to 90: embed and review
- Train staff on the policy, the approved tools and how to check AI output (practices 1.4 and 6.3).
- Set up monitoring and an incident process. Decide how problems are reported, investigated and fed back into your controls (practices 3.5 and 5.3).
- Build in override points and fallbacks for any AI that affects customers or operations (practices 6.2 and 6.4).
- Report to leadership. Share the register, screening results, open risks and next steps, and set a review cycle (quarterly is a reasonable starting point).
A good outcome at day 90 is modest: a named owner, a policy people understand, a register that's mostly complete, approved tools, and extra checks on the few uses that matter most.
Give your team an approved AI workspace, processed in Australia
AusGPT gives your team Claude AI with conversations and documents stored and processed in Australia. $29 per user per month, with a free trial.
How AI6 fits with your other obligations
AI6 doesn't create legal obligations, but it lines up with ones that already exist:
- Privacy Act: the register and screening work feeds directly into APP 1.7 automated decision-making disclosures, and the policy supports the security obligations in APP 11. See our summary of the 2026 Privacy Act reforms.
- Directors' duties: the NAIC notes that a company director's duty of care and diligence under section 180 of the Corporations Act includes making sure adequate governance systems exist to manage the risks of AI. A named owner, a register and documented decisions are evidence of that.
- Procurement: the supplier questions and "ask for proof" practice give you a consistent way to compare AI vendors, including on where your data is stored and processed.
The NAIC says you don't need to do everything at once. Start across all six practices at a basic level, document what you do, and add actions as your AI use grows.
Sources
- National AI Centre: Guidance for AI adoption, Foundations (October 2025, PDF)
- Department of Industry, Science and Resources: Guidance for AI adoption, implementation guidance
- Department of Industry, Science and Resources: Voluntary AI Safety Standard (updated 2 December 2025)
- National AI Centre: Planning tools and templates
- National AI Centre: AI screening questions (PDF)
- National AI Centre: Create an AI policy
- National AI Plan: Keep Australians safe (2 December 2025)
- National AI Centre: Essential AI practices (legal obligations overview)
- Digital Transformation Agency: Policy for the responsible use of AI in government, version 2.0
Frequently asked questions
- What is AI6?
- AI6 is a common shorthand for the six essential practices in the Guidance for AI Adoption, published by the National AI Centre on 21 October 2025: decide who is accountable, understand impacts and plan accordingly, measure and manage risks, share essential information, test and monitor, and maintain human control.
- Has the Voluntary AI Safety Standard been replaced?
- The Guidance for AI Adoption is described as the first update to the Voluntary AI Safety Standard (VAISS). It condensed the standard's 10 guardrails into 6 essential practices, removed redundant language and expanded the audience to developers as well as deployers. The VAISS is still online, but the department now points organisations to the new guidance.
- Is the Guidance for AI Adoption mandatory?
- It is guidance from the National AI Centre, not legislation, and it builds on the Voluntary AI Safety Standard. Existing laws such as the Privacy Act, consumer law and workplace law still apply to AI. Non-corporate Commonwealth entities have a separate, mandatory Policy for the responsible use of AI in government from the Digital Transformation Agency.
- Which version should a small business use?
- Start with the Foundations version, which is written for organisations in the early stages of adopting AI. Move to the Implementation guidance if you build or customise AI systems, manage higher-risk use cases or need more detailed controls.
- Where are the AI policy template and AI register template?
- The National AI Centre publishes an AI policy guide and template, an AI register template (Word and Excel) and AI screening questions on ai.gov.au, along with other planning tools such as questions to ask AI suppliers.
Keep reading
Secure AI for your team, processed in Australia
Claude AI, document chat and voice dictation, with your data stored and processed in Australia. $29 per user per month.