Briefings

Australian AI Governance Briefing: Week Ending 12 April 2026

ASIC reports a 90 per cent surge in AI-powered scam website takedowns as the Attorney-General signals copyright licensing reform and OpenAI's UK infrastructure pause raises questions for Australia.

10 stories

The week in review

The week ending 12 April was defined by a sharp enforcement signal from ASIC, a notable policy pivot on copyright from the Attorney-General, and an international infrastructure setback that carries direct implications for Australia’s AI ambitions.

ASIC draws a line on AI-powered scams

ASIC’s media release 26-063MR, published 8 April, delivered the week’s most concrete enforcement data point. The regulator reported coordinating the removal of 11,964 phishing and investment scam websites between January and December 2025 — a 90 per cent increase on the prior year’s 6,270 takedowns. More than 25,000 scam websites have now been removed since the takedown service launched in 2023, alongside over 1,100 fraudulent investment ads pulled from social media platforms last year.

The release is notable for ASIC’s explicit framing of AI as a threat multiplier. Commissioner Alan Kirkland warned that “scammers are using artificial intelligence to make fake investment ads look more polished, more convincing and harder to spot,” citing deepfake celebrity endorsement videos, AI-generated fake news pages, and automated “AI trading bot” schemes promising passive income. Australians lost $2.18 billion to scams in 2025, with $837.7 million attributable to investment scams — though ASIC noted an 11 per cent decline in reported investment scam losses, suggesting its takedown program is beginning to bite.

For organisations in the AI governance space, the release underscores two realities. First, ASIC is developing specialist enforcement capability for AI-era financial fraud, including 24/7 monitoring through third-party providers. Second, the regulator is confronting a whack-a-mole problem: AI allows scammers to rapidly reconstitute taken-down sites and generate convincing new content at minimal cost. The 90 per cent year-on-year increase in takedowns may reflect the problem scaling as much as the response scaling.

Attorney-General Michelle Rowland gave an interview to the Australian Financial Review, published around 7 April, that marked a subtle but significant evolution in the government’s copyright position. While reaffirming that the government will not introduce a text and data mining exception — the carve-out AI developers worldwide have lobbied for — Rowland signalled that she is “looking at other ways in which the copyright system can be improved in the age of AI.”

This matters because it shifts the framing from “no change” to “change, but on our terms.” Rowland positioned the reform conversation around licensing frameworks rather than exceptions, telling the AFR: “We all want to get to the same endpoint here… we do want to realise the benefits of innovation and the benefits that AI can bring to productivity. But we also need to recognise that our creative industries, our media, our artistic ventures in this country, they are the lifeblood of our culture and of our economy, and we will not be selling them short.”

The response from rights holders was swift and broadly positive. Copyright Agency CEO Josephine Johnston said collective licensing could “enable AI developers to obtain licences for content from a multitude of rights holders efficiently while ensuring creators are paid.” Nine CEO Matt Stanton put it bluntly: “if you want to use our intellectual property for your commercial benefit, then pay for its commercial value.” APRA’s public affairs executive director Nicholas Pickard called for mandatory transparency, arguing that platforms should be required to disclose what copyright material they use to train AI systems. News Corp Australasia executive chairman Michael Miller struck a more cautious note, warning that a “gap is widening between acknowledging rights holders in principle and protecting them in practice.”

The comments came in the same week that Anthropic CEO Dario Amodei continued his Australian engagement, meeting with Assistant Minister for Science, Technology and the Digital Economy Andrew Charlton on 10 April to discuss AI expansion and copyright. Amodei had earlier told an audience at Parliament House that he was “not trying to change Australia’s mind on copyright,” though rights holders received this with visible scepticism. The timing — the Attorney-General firming up a licensing-based reform path while the CEO of a major AI developer continued to make the case for access — captures the central tension in Australian AI copyright policy. The Copyright and AI Reference Group (CAIRG) continues its work across three priority areas: licensing arrangements, copyright certainty for AI-generated material, and lower-cost enforcement mechanisms.

OpenAI’s UK infrastructure pause raises Australian questions

On 9 April, OpenAI confirmed it was pausing its Stargate UK data centre project, citing “the cost of energy” and an unfavourable regulatory environment — specifically unresolved copyright rules for AI training. The project, announced in September 2025 in partnership with Nvidia and British GPU firm Nscale, was to deploy up to 8,000 GPUs initially, scaling to 31,000.

The decision carries direct relevance for Australia. OpenAI’s “OpenAI for Countries” initiative — the vehicle through which Stargate UK was structured — is also working with Australia. Several international outlets flagged the spillover risk. Engadget reported that “it’s unclear if those plans are affected as well, but it’s worth noting that the initiative, OpenAI for Countries, is also working with Australia.”

The pause effectively validates the Australian Government’s decision to set clear expectations before major investments land. The data centre expectations framework published 23 March established five national expectations — including requirements for developers to support the energy transition, invest in Australian skills, and prioritise national security. Anthropic explicitly agreed to align with these expectations under its MOU. The contrast with the UK, where regulatory and energy uncertainty led to a project pause, suggests Australia’s proactive framework may offer greater investment certainty.

But the energy challenge is not hypothetical for Australia either. The Tech Council of Australia’s February survey found only 7 per cent of tech leaders believed Australia currently had the infrastructure capability to meet AI demand “to a great extent.” Clayton Utz published an analysis on 10 April examining approximately 70 submissions to the NSW parliamentary inquiry into data centre regulation, noting NSW alone has a $29.4 billion pipeline of State Significant Development applications for data centre projects. The energy demand, community impact, and sustainability questions raised in those submissions mirror the concerns that ultimately stalled the UK project.

Doubled penalties shift the enforcement calculus

The Treasury Laws Amendment (Doubling Penalties for ACCC Enforcement) Act 2026, which took effect 28 March, continued to generate analysis through the week. Ashurst published a detailed overview noting that maximum civil and criminal penalties for competition and consumer law breaches have doubled from $50 million to $100 million per contravention. The change applies broadly — covering cartel conduct, anti-competitive behaviour, misleading or deceptive conduct, unfair contract terms, and failures to notify acquisitions under the new mandatory merger regime.

While not AI-specific, the doubling has immediate implications for AI-related enforcement. The ACCC’s ongoing case against Microsoft — alleging the company misled 2.7 million Australian subscribers by concealing cheaper plans when bundling its Copilot AI assistant into Microsoft 365 subscriptions — now carries significantly larger potential penalties. More broadly, any AI-powered dark patterns, algorithmic pricing manipulation, or misleading AI product claims face a materially different risk profile. Read alongside the Unfair Trading Practices Bill introduced on 1 April — which specifically targets manipulative design practices in digital interfaces — the enforcement framework for AI-related consumer harms is tightening from multiple directions simultaneously.

Children’s Online Privacy Code draws deeper industry scrutiny

While the OAIC’s Children’s Online Privacy Code consultation launched on 31 March, the week of 6–12 April saw the first substantial law firm analyses engaging with the detail of the exposure draft. Allens published a detailed assessment on 9 April warning that the proposed Code will have a “material impact” on how many online services operate. The analysis identified several particularly significant obligations: age-gating assessments, data minimisation (collecting only “strictly necessary” personal information from children), privacy-by-default configurations, mandatory privacy impact assessments, and children’s rights to deletion.

For AI-powered services, the COPC creates a specific tension. The requirement for age assurance may drive increased use of AI-based age estimation technologies, while the data minimisation requirements constrain the data available to train and operate such systems. Organisations offering AI chatbots, recommendation engines, or personalised content services that may be accessed by children will need to fundamentally reassess their data practices before the Code’s 10 December 2026 registration deadline. The consultation remains open until 5 June.

eSafety sharpens its position on AI-generated harmful content

The eSafety Commissioner published an updated version of its Online Safety Codes and Standards Regulatory Guidance in April 2026. The update, which follows the six Age-Restricted Material Codes that came into effect on 9 March, explicitly includes AI-generated content within the scope of regulated online material — stating that covered material “includes written, video, audio and/or image-based material, whether it is real or fake (including AI-generated content).” The guidance outlines compliance reporting timelines, enforcement approach, and categorisation of services. Breaches can attract civil penalties up to $49.5 million for corporations. For platforms deploying generative AI features, this clarifies that AI-generated content is not a regulatory grey area under the online safety codes — it falls squarely within scope.

IAPP assessment underlines the framework gap

The International Association of Privacy Professionals published an analysis on 7 April that provided an authoritative independent assessment of Australia’s AI regulatory position. The piece noted that Australia lacks specific AI laws, that the Voluntary AI Safety Standard and mandatory guardrails proposals had not progressed beyond a September 2024 consultation, and warned that “without an enforceable AI-specific regime, Australia may struggle to achieve the regulatory cohesion and effectiveness currently aspired to by government.” Coming in the same week as the Attorney-General’s copyright comments, the ASIC scam data, and the OpenAI UK pause, the IAPP assessment provided useful external framing for the gap between Australia’s regulatory ambition and its current toolkit.

What didn’t move

No significant new developments were identified from APRA, AUSTRAC, the ASD, or the AI Safety Institute during the week. The Tax Practitioners Board’s consultation on draft AI guidance for registered tax practitioners (TPB(I) D62/2026) continued, with The Mandarin publishing a reminder on 10 April that submissions close 21 April, but no new substance emerged. Privacy Act Tranche 2 remains under development with no Bill introduced.

Stories

ASIC reports record AI-powered scam takedowns as losses hit $2.18 billion

ASIC published media release 26-063MR on 8 April reporting that it coordinated the removal of 11,964 phishing and investment scam websites in 2025 — a 90 per cent increase on the prior year. Commissioner Alan Kirkland warned AI is “super-charging” scam threats, with scammers deploying deepfake celebrity endorsements, AI-generated fake news pages, and fraudulent AI trading bot schemes. Australians lost $2.18 billion to scams in 2025, with $837.7 million from investment scams alone, though reported investment scam losses declined 11 per cent.

Source: asic.gov.au

Attorney-General Rowland signals copyright licensing reform for the AI age

Attorney-General Michelle Rowland told the Australian Financial Review around 7 April that the government is “looking at other ways in which the copyright system can be improved in the age of AI,” while reaffirming no text and data mining exception will be introduced. The comments mark a shift from “no change” to “change on our terms,” with the reform conversation centred on licensing frameworks. Rights holders responded positively, with the Copyright Agency highlighting collective licensing as a practical solution and Nine’s CEO demanding AI developers pay for the commercial value of content they use.

Source: mumbrella.com.au

OpenAI pauses Stargate UK data centre project over energy costs and regulatory uncertainty

OpenAI confirmed on 9 April it is pausing its Stargate UK AI data centre project, citing high energy costs and unresolved copyright rules for AI training. The project, announced in September 2025 with Nvidia and Nscale, was to deploy up to 31,000 GPUs. The pause raises questions for Australia, which is also working with OpenAI’s “OpenAI for Countries” initiative. The contrast with Australia’s proactive data centre expectations framework, published 23 March, highlights how regulatory clarity — or its absence — can determine where sovereign AI infrastructure investment lands.

Source: theregister.com

Doubled ACCC penalties raise enforcement stakes for AI-related consumer violations

The Treasury Laws Amendment (Doubling Penalties for ACCC Enforcement) Act 2026, effective 28 March, doubled maximum civil and criminal penalties for competition and consumer law breaches from $50 million to $100 million per contravention. Ashurst’s analysis noted the change applies to misleading conduct, unfair contract terms, and anti-competitive behaviour — all directly relevant to AI product claims, algorithmic pricing, and dark patterns. The ACCC’s ongoing case against Microsoft over Copilot AI bundling now faces a materially higher penalty ceiling.

Source: ashurst.com

Allens warns Children’s Online Privacy Code will have material impact on online services

Allens published a detailed analysis on 9 April of the OAIC’s Children’s Online Privacy Code exposure draft, warning it will require fundamental changes to how many online services handle children’s data. Key obligations include age-gating assessments, collection of only “strictly necessary” personal information, privacy-by-default configurations, and children’s deletion rights. The analysis noted a tension for AI services: age assurance requirements may drive uptake of AI-based age estimation while data minimisation rules constrain the data available to operate such systems. The consultation closes 5 June 2026.

Source: allens.com.au

Anthropic CEO Amodei meets Minister Charlton as Australian AI diplomacy continues

Anthropic CEO Dario Amodei met with Assistant Minister for Science, Technology and the Digital Economy Andrew Charlton on 10 April to discuss AI expansion and copyright policy in Australia. The meeting followed the signing of the Anthropic–Australian Government MOU on 1 April and came in the same week that Attorney-General Rowland signalled copyright licensing reform. Amodei has previously said he is “not trying to change Australia’s mind on copyright,” though rights holders have received this with scepticism given the commercial stakes involved.

Source: nationaltoday.com

eSafety Commissioner updates regulatory guidance to explicitly cover AI-generated content

The eSafety Commissioner published an updated version of its Online Safety Codes and Standards Regulatory Guidance in April 2026, explicitly confirming that AI-generated content falls within the scope of regulated online material — covering “written, video, audio and/or image-based material, whether it is real or fake (including AI-generated content).” The update follows the six Age-Restricted Material Codes that came into effect on 9 March. Breaches can attract civil penalties up to $49.5 million for corporations.

Source: esafety.gov.au

Clayton Utz unpacks NSW Data Centre Inquiry’s 70 submissions

Clayton Utz published an analysis on 10 April of approximately 70 submissions to the NSW parliamentary inquiry into data centre regulation. NSW hosts more than 90 data centres — a third of Australia’s capacity — with a $29.4 billion pipeline of State Significant Development applications. The analysis identified energy demand, community impact, and sustainability as dominant themes, and noted the inquiry’s final report (due September 2026) will likely shape state-level regulation of AI infrastructure. The piece connects the national data centre expectations framework with emerging state-level scrutiny.

Source: claytonutz.com

IAPP assessment highlights gaps in Australia’s AI regulatory framework

The International Association of Privacy Professionals published an analysis on 7 April of Australia’s AI regulatory landscape, noting the country lacks specific AI laws and that the mandatory guardrails proposals floated in September 2024 had not progressed. The assessment warned that “without an enforceable AI-specific regime, Australia may struggle to achieve the regulatory cohesion and effectiveness currently aspired to by government,” providing an authoritative external perspective on the gap between Australia’s stated ambitions and its current regulatory toolkit.

Source: iapp.org

TPB AI guidance consultation enters final stretch ahead of 21 April deadline

The Tax Practitioners Board’s consultation on exposure draft TPB(I) D62/2026 — covering the use of artificial intelligence and the Code of Professional Conduct — is approaching its 21 April deadline, with The Mandarin publishing a reminder on 10 April. The draft guidance, which applies to more than 80,000 registered tax agents, makes clear that AI tools do not transfer professional responsibility away from the practitioner and addresses competency, confidentiality, and integrity obligations when using AI.

Source: tpb.gov.au

Stay across Australian AI governance

Get the briefing delivered to your inbox every week. No spam, unsubscribe any time.