The Changing Governance and Risk Landscape of AI and HR in Australia

The Changing Governance and Risk Landscape of AI and HR in Australia

Australia still does not have a single, general AI Act governing employment. That does not leave employers in a legal vacuum. AI-enabled HR decisions already sit inside a web of privacy, discrimination, Fair Work, surveillance and work health and safety obligations—and that web is tightening.

For HR leaders, the central governance question is no longer whether the organisation uses AI. It is whether the organisation can identify where AI is used, explain how it influences people decisions, and demonstrate that a responsible person remains accountable for the outcome.

This article provides general information, not legal advice. Organisations should obtain advice on their particular systems, workforce and jurisdiction.

The regulatory direction is becoming clearer

Australia’s approach remains distributed across existing laws and newer AI-specific guidance. In May 2026, the Australian Government published updated Guidance for AI Adoption, with six essential practices for responsible AI governance and stronger implementation guidance for complex and higher-risk uses. The guidance is not, by itself, a substitute for legislation—but it is a useful signal of the governance standard organisations will increasingly be expected to meet.

The Australian Government describes the guidance as a framework for governance, testing, monitoring, accountability, human oversight and supply-chain controls. See Guidance for AI Adoption.

The practical implication is that HR cannot treat AI as solely an IT procurement issue. Recruitment, performance, rostering, remuneration, monitoring and workforce change all affect people’s rights and working conditions. The control environment needs HR, legal, privacy, technology, WHS, procurement and business owners at the table.

Privacy: a significant transparency change arrives in December 2026

From 10 December 2026, organisations covered by the Australian Privacy Principles will have new privacy-policy obligations where they arrange for a computer program to use personal information to make, or do a thing substantially and directly related to making, a decision that could reasonably be expected to significantly affect an individual’s rights or interests.

Privacy policies will need to describe the kinds of personal information used and the kinds of significant decisions involved. For HR, this could be relevant to automated or substantially automated processes involving applicants, access to opportunities, eligibility, performance or other consequential outcomes, depending on the facts.

The OAIC is developing guidance ahead of commencement. See OAIC guidance on APP 1 automated-decision obligations.

There is an important Australian complication: a private-sector employer’s handling of employee records is generally exempt from the Privacy Act when directly related to a current or former employment relationship. That exemption is not universal. Job applicants, contractors, service providers and uses outside the direct employment relationship may be treated differently; government-sector arrangements also differ. Employers should map coverage rather than assume all workforce data is exempt.

For the scope and limits of the exemption, see the OAIC employee-records guidance.

Fair Work and discrimination law already apply

Using an algorithm does not displace the employer’s obligations. A dismissal must still have a valid reason and a fair process. Adverse action remains unlawful when taken for a prohibited reason. Federal, state and territory discrimination laws still apply to recruitment, promotion, pay, performance management, termination and access to development.

AI creates particular exposure because it can reproduce patterns from historical data at scale. A system trained on previous “successful” candidates or leaders may learn proxies for age, sex, race, disability or caring responsibilities even when protected attributes have been removed. Generative tools can also produce subtly different assessments when demographic details change.

The Australian Human Rights Commission provides a practical AI and recruitment compliance checklist.

A human clicking “approve” is not enough. Meaningful human oversight requires the reviewer to understand the inputs and limitations, have authority to disagree, receive enough time and information to challenge the output, and record the reason for the final decision.

Digital monitoring is becoming a WHS issue—not just a privacy issue

AI-enabled monitoring can allocate work, score performance, track location, analyse communications or infer behaviour. Those systems can affect work intensity, autonomy, role clarity, perceived fairness and psychological safety.

WHS duties already require organisations to manage risks to physical and psychological health so far as reasonably practicable. New South Wales has gone further with the Work Health and Safety Amendment (Digital Work Systems) Act 2026. The reform places an explicit focus on risks arising from digital work systems. Some provisions are subject to staged commencement, so organisations should confirm which requirements apply and when.

See the enacted NSW Work Health and Safety Amendment (Digital Work Systems) Act 2026.

For employers outside NSW, the change is still a useful directional signal. A productivity tool may create a WHS risk even when its data processing is lawful. Consultation, work design and psychosocial-risk assessment belong in the implementation plan—not as an afterthought once employee trust has deteriorated.

Vendor assurance does not transfer accountability

HR technology is often purchased as a service, creating a dangerous assumption that the vendor has already solved the risk. In reality, the employer chooses the purpose, configures the workflow, supplies local data, decides how much weight to give the output and acts on the result.

Due diligence should go beyond asking whether the vendor is “AI compliant”. Organisations should ask:

  • What data was the system trained, tested or tuned on, and how relevant is it to our workforce?
  • What inputs and proxy variables influence the output?
  • How is performance tested across demographic groups and edge cases?
  • Can we explain and reconstruct a particular result?
  • Where is workforce data stored, and is it used to train the vendor’s models?
  • What changes can the vendor make to the model or service without our approval?
  • How are errors, security incidents and material model changes reported?
  • Can a qualified person override the output, and is that override recorded?
  • What evidence will the vendor provide if a decision is challenged?

Contracts should support these requirements through audit rights, incident notification, data-use restrictions, change controls, service levels, deletion arrangements and access to evidence. A contractual warranty is useful; it is not a governance system.

Five controls HR leaders should establish now

1. Maintain an AI use-case register

Record every HR use case, including shadow or embedded AI features. Capture the purpose, owner, vendor, data involved, affected groups, decision impact, risk rating, human approval point and review date.

2. Require human ownership for consequential decisions

Anything affecting recruitment, pay, promotion, discipline, redundancy, performance ratings, access to work or termination should have a named decision-maker. Define what evidence they must review and when they must disregard or escalate the AI output.

3. Make outcomes reconstructable

Keep enough information to reproduce the pathway to a decision: relevant source data, system or model version, material settings, prompt or workflow instructions, output, human changes, approval and reasons. If the organisation cannot explain an outcome, it will struggle to investigate, correct or defend it.

4. Test for bias, accuracy and drift

Test before launch and at a risk-based cadence after launch. Compare error rates and outcomes across relevant groups, use counterfactual tests by changing demographic details, and monitor whether performance changes as data, roles or the vendor’s model evolves.

5. Be transparent and provide recourse

Tell people when AI materially informs a process affecting them, explain the role it plays in plain language, and provide a channel to ask questions or seek human review. Transparency is becoming a formal privacy requirement in some automated-decision contexts; it is also fundamental to workforce trust.

A proportionate governance model

Not every use of AI needs an executive committee. Drafting a generic event invitation is different from ranking applicants or recommending a performance outcome. Governance should scale with the stakes, the sensitivity of the data, the level of automation, the number of people affected and the difficulty of reversing harm.

A practical model is to classify uses into three categories:

  • Automate: repeatable, low-stakes tasks with clear rules, reliable sources and easy correction.
  • Verify: analytical or drafting tasks where AI helps, but a competent person checks the evidence and context before use.
  • Protect: consequential, judgement-heavy decisions where AI may provide limited support but a human owns the reasoning and outcome.

The governance standard is moving before a single AI Act arrives

Australian employers should not wait for one comprehensive piece of AI legislation. The obligations that matter most to HR already arise from the decision being made, the data being used, the effect on the worker and the design of the work—not from whether the technology carries an “AI” label.

The organisations best prepared for the next regulatory step will be those that can already answer five questions: Where is AI used? What data does it touch? Who can be affected? Who owns the decision? Can we explain and review the outcome?

That is not bureaucracy around innovation. It is the operating discipline that allows HR to use AI with confidence.