Briefings

Australian AI Governance Briefing: Week Ending 26 April 2026

Microsoft signed a non-binding AI collaboration MoU with the Commonwealth as ASIC, APRA, and the RBA publicly engaged with Anthropic's Mythos.

9 stories

Parliament remained in recess ahead of Budget week beginning 12 May, but the executive delivered the week’s defining development. The Albanese Government on 23 April signed a non-binding memorandum of understanding with Microsoft on AI collaboration, accompanied by Microsoft’s announcement of a A$25 billion Australian investment to end-2029. The MoU aligns Microsoft to the Commonwealth’s March 2026 expectations for data centres and AI infrastructure developers and commits both parties to technical exchanges with the Australian AI Safety Institute. It is the second hyperscaler MoU under the National AI Plan and the first concrete operational arrangement for AISI.

That arrangement landed alongside a parallel cycle that put its framing under stress. ASIC, APRA, and the Reserve Bank publicly confirmed they were monitoring Anthropic’s Mythos model — which Bloomberg reported on 21 April had been accessed by unauthorised users — in coordination with peer regulators. Home Affairs Minister Tony Burke confirmed direct government engagement with Anthropic and software providers, while the Lowy Institute’s Interpreter argued Australia’s existing settings are not keeping pace with autonomous-cyber capability.

Elsewhere, eSafety issued legally enforceable transparency notices to Roblox, Minecraft, Fortnite, and Steam; ACMA published three sector reports on AI use in telecommunications, media, and online gambling; and Commonwealth Bank confirmed a further round of AI-attributed job cuts. The week’s pattern is consistent: Australia’s “regulation-where-necessary” approach is being operationalised through MoUs, sectoral codes, and targeted enforcement powers — not a horizontal AI Act — and the first stress test of those settings is now arriving in the form of frontier-model risk.

The week in review

Microsoft signs an AI MoU with the Commonwealth alongside a A$25 billion investment

The Albanese Government’s signing of a memorandum of understanding with Microsoft on 23 April was the week’s defining development — and the second hyperscaler MoU concluded under the National AI Plan since its release in December 2025. Senator Tim Ayres, Minister for Industry and Science, and Assistant Minister for Science, Technology and the Digital Economy Andrew Charlton joined Satya Nadella at Microsoft’s AI Tour event at the ICC Sydney for an arrangement that runs in parallel with Microsoft’s separate announcement of A$25 billion in Australian AI infrastructure, security, and skills investment to end-2029.

The MoU itself is short and explicitly non-binding. It does not confer preferential treatment in Commonwealth procurement processes, grant programs, or regulatory decisions, and it confers no legal rights or obligations. Its substance lies in the alignment it forces. Microsoft commits to the Commonwealth’s March 2026 Expectations of Data Centres and AI Infrastructure Developers, which set the social-licence baseline for hyperscaler operations in Australia. It commits to technical exchanges with the Australian AI Safety Institute on frontier safety and security evaluations, and to specific work on human–AI interaction risks: overreliance, emotional dependency, and companion chatbots. It commits to industry-first dialogue with workers via the ACTU, and to delivery of the APS AI Plan.

Microsoft’s parallel investment announcement, which the company described as its largest in Australia in 41 years, includes Azure data centre expansion, extension of the Microsoft–Australian Signals Directorate Cyber-Shield (MACS) to additional federal agencies, deeper collaboration with Home Affairs and the Digital Transformation Agency, and a commitment to train three million Australians in AI by 2028. Industry endorsements were synchronised: the Tech Council of Australia, the Business Council of Australia, and Data Centres Australia each issued supporting statements alongside the Government’s release.

For compliance professionals the practical takeaway is structural. Australia’s National AI Plan operates without a horizontal AI Act and without mandatory guardrails; in their place, the Commonwealth is establishing what behaviour it expects from the world’s largest AI providers via published expectations, MoUs, and AISI partnerships. The Microsoft MoU, following Anthropic’s in March, suggests this template will continue to be the lever by which the Commonwealth shapes hyperscaler conduct. For Australian organisations procuring frontier AI services, the MoU does two things: it brings Microsoft inside the AISI evaluation perimeter for the first time, and it signals that downstream-deployer questions about model safety, data residency, and worker consultation are increasingly likely to be answered by reference to these published commitments.

Primary sources: Minister Charlton — media release | Minister Ayres — media release | DISR — MoU full text

Australian regulators move on Anthropic’s Mythos

The MoU’s framing of AISI partnership as the operative answer to frontier-AI risk was put into immediate context by a parallel news cycle. Anthropic’s Mythos model — released in early April with claimed autonomous capabilities for discovering and chaining software vulnerabilities — moved decisively up the Australian regulatory agenda this week.

ASIC and APRA confirmed on 20 April through statements reported by iTnews that both regulators were closely monitoring Mythos in conjunction with peer regulators. The next day, Bloomberg reported that the model was being accessed by unauthorised users, escalating the regulatory urgency. The Reserve Bank issued a statement on 22 April confirming that it would continue to assess the implications alongside peer regulators and government agencies — language that signalled coordinated engagement at the level Australia ordinarily reserves for systemic risk. Home Affairs Minister Tony Burke’s office confirmed the Government was working directly with software providers and Anthropic on emerging vulnerabilities, and the Australian Signals Directorate has issued board-level guidance on frontier-AI cyber risk.

The Lowy Institute’s Interpreter on 24 April published a counter-narrative to the MoU’s optimism, arguing Mythos demonstrates an inflection point in AI cyber-offensive capability and that Australia’s regulatory frameworks are not keeping pace. The piece called for an explicit reckoning with whether AISI’s funding settings — cited at A$29.9 million — and the existing-laws posture are adequate. The argument lands as the same regulators publicly engaging with Mythos prepare for the December 2026 commencement of the Privacy Act’s automated decision-making transparency obligations.

For boards in APRA-regulated entities, the immediate compliance frame is CPS 230 operational risk and CPS 234 information security: a frontier-model capability that materially changes the threat surface of every internet-connected system is squarely within the scope of operational risk profiles, third-party risk, and incident reporting obligations. For entities using Anthropic’s products at the enterprise level — and Anthropic was the first hyperscaler to sign an MoU with the Commonwealth, in March — the question of how to demonstrate adequate controls is no longer hypothetical.

Primary sources: iTnews — ASIC, APRA monitoring Mythos | Lowy Interpreter — AI danger no longer a myth

eSafety puts the gaming platforms on notice as ACMA reports across three regulated sectors

eSafety Commissioner Julie Inman Grant on 22 April issued legally enforceable transparency notices under the Basic Online Safety Expectations to Roblox Corporation, Microsoft (in respect of Minecraft), Epic Games (in respect of Fortnite), and Valve (in respect of Steam). The notices ask the four platforms to detail their systems, staffing, and safety-by-design choices for addressing grooming, sexual extortion, cyberbullying, online hate, and violent extremist radicalisation. Failure to respond may attract penalties of up to A$825,000 per day; non-compliance with codes or standards can trigger penalties of up to A$49.5 million per breach.

The notices are explicitly framed around the use of AI in moderation and age assurance, and around AI-generated extremist content. Roblox’s response acknowledged that its systems use AI to scan images, text, and avatar items for extremist iconography prior to publication. The notices follow Phase 2 industry codes that came into force in March 2026 and arrive in the run-up to the August and September 2026 milestones for the social media minimum age regime. For platforms operating in Australia, and for businesses that integrate platform safety APIs into their consumer-facing products, the notices set a high-water-mark precedent for the operational disclosure eSafety expects.

ACMA the day before — on 21 April — published three sector developments reports on AI use in telecommunications, media, and online gambling. The reports document accelerating use of AI for operational efficiency and revenue generation in telco; for personalised advertising and content production in media (with attendant misinformation and copyright concerns); and for predictive analytics, odds-setting, personalised promotions, and fraud and harm detection in gambling. ACMA noted that stakeholder feedback is calling for stronger governance, transparency, and safeguards — language compliance teams in the regulated communications and wagering sectors should read as foreshadowing potential code amendments and increased regulatory scrutiny.

Primary sources: eSafety — gaming giants media release | ACMA — AI in telecommunications report

The implementation layer: APS, workers, banks

Three further developments through the week confirmed that AI governance has shifted from policy design into operational delivery — inside the Commonwealth, in the boardroom, and on the shop floor.

The Digital Transformation Agency’s Deputy CEO for Strategy, Planning and Performance, Lucy Poole, delivered a keynote at the 12th Annual Aus Gov Data Summit on 22 April under the title “Accelerating Data and Digital AI Capability in the Australian Public Service.” Poole reaffirmed the staged commencement of the Policy for the Responsible Use of AI in Government v2.0, which took effect on 15 December 2025. First-wave compliance — covering accountable officers, AI use-case registers, and AI impact assessments — falls due on 15 June 2026; the remainder commences in December 2026. Vendors selling into Commonwealth agencies should have AI impact-assessment artefacts ready well in advance of the June milestone.

On 20 April, Microsoft Australia and the ACTU convened the first Workers’ Summit on AI under their January 2026 Framework Agreement, joined by NSW and Victorian peak union bodies and individual unions. The summit was cited three days later by the Government as the “industry-first dialogue with workers” element of the Microsoft MoU and is likely to be referenced in future Fair Work Act consultation disputes around algorithmic management and AI-driven role changes.

That dialogue is no longer abstract. On 23 April the Commonwealth Bank confirmed cutting approximately 119 further roles, including 43 at Bankwest, with the Finance Sector Union identifying positions directly impacted by AI-driven automation. The cuts come two months after the launch of CBA’s $90 million Future Workforce Program, and against the backdrop of CEO Matt Comyn’s earlier warning that AI will accelerate role changes over a five-year horizon. A FSU survey released alongside the announcement found that 72 per cent of CBA workers report concern about job security. The cuts are the highest-profile Australian AI-attributed workforce restructuring of the year-to-date and will inevitably feature in scrutiny of the National AI Plan’s worker-protection commitments and in CBA’s ongoing enterprise agreement negotiations.

Primary sources: DTA — Lucy Poole speech | Microsoft — ACTU Workers’ Summit | Bloomberg — CBA AI job cuts

Stories

Commonwealth signs AI MoU with Microsoft as company commits A$25 billion in Australian investment

The Albanese Government on 23 April signed a non-binding memorandum of understanding with Microsoft aligning the company to the Commonwealth’s expectations for data centres and AI infrastructure developers and committing both parties to technical exchanges with the Australian AI Safety Institute on frontier safety, security evaluations, and human–AI interaction research. Alongside the MoU, Microsoft announced A$25 billion in Australian AI infrastructure, security, and skills investment to end-2029, including extension of the Microsoft–Australian Signals Directorate Cyber-Shield to additional federal agencies and a commitment to train three million Australians in AI by 2028. The MoU is the second hyperscaler agreement signed under the National AI Plan and the first concrete operational arrangement for AISI, signalling that Australia’s “regulation-where-necessary” approach will be operationalised through published expectations and MoUs rather than a horizontal AI Act.

Source: industry.gov.au

ASIC, APRA, RBA, and ASD coordinate on response to Anthropic’s Mythos model

Australian financial and security regulators publicly confirmed during the week that they are monitoring Anthropic’s Mythos model — which Bloomberg reported on 21 April had been accessed by unauthorised users — in coordination with peer regulators. ASIC and APRA confirmed monitoring on 20 April, the Reserve Bank issued a statement on 22 April, and Home Affairs Minister Tony Burke confirmed direct government engagement with Anthropic and software providers. The Australian Signals Directorate has issued board-level guidance on frontier-AI cyber risk. For APRA-regulated entities, the development is squarely within the scope of CPS 230 operational risk and CPS 234 information security obligations.

Source: itnews.com.au

eSafety issues transparency notices to Roblox, Minecraft, Fortnite, and Steam

eSafety Commissioner Julie Inman Grant on 22 April issued legally enforceable transparency notices under the Basic Online Safety Expectations to the four largest gaming platforms, requiring detail on systems, staffing, and safety-by-design measures addressing grooming, sexual extortion, cyberbullying, online hate, and violent extremist radicalisation. The notices are explicitly framed around the use of AI in moderation and age assurance, and around AI-generated extremist content. Failure to respond may attract penalties of up to A$825,000 per day; non-compliance with codes or standards may attract penalties of up to A$49.5 million per breach.

Source: esafety.gov.au

ACMA publishes AI use reports across telecommunications, media, and gambling sectors

ACMA on 21 April released three sector developments reports documenting accelerating AI use in telcos (operational efficiency and revenue generation), media (personalised advertising and content production with attendant misinformation and copyright concerns), and online gambling (predictive analytics, odds-setting, personalised promotions, and fraud and harm detection). The regulator notes that stakeholder feedback is calling for stronger governance, transparency, and safeguards. Compliance teams in the regulated communications and wagering sectors should read the reports as foreshadowing potential code amendments and increased ACMA scrutiny of generative and predictive AI use.

Source: acma.gov.au

DTA Deputy CEO Lucy Poole reaffirms June 2026 first-wave deadline for APS AI policy compliance

At the 12th Annual Aus Gov Data Summit on 22 April, the Digital Transformation Agency’s Deputy CEO for Strategy, Planning and Performance, Lucy Poole, reaffirmed staged commencement of the Policy for the Responsible Use of AI in Government v2.0. First-wave compliance — covering accountable officers, AI use-case registers, and impact assessments — falls due on 15 June 2026, with the remainder commencing in December 2026. The speech is a clear signal to Commonwealth agencies and their vendors that AI impact-assessment artefacts must be in place well before the June milestone.

Source: dta.gov.au

Commonwealth Bank confirms further job cuts attributed to AI-driven simplification

Commonwealth Bank on 23 April confirmed cutting approximately 119 further roles, including 43 at Bankwest, with the Finance Sector Union identifying positions directly impacted by AI-driven automation. The cuts come two months after the launch of CBA’s $90 million Future Workforce Program, and against the backdrop of CEO Matt Comyn’s earlier warning that AI will accelerate role changes over a five-year horizon. A FSU survey released alongside the announcement found 72 per cent of CBA workers report concern about job security. The development is the highest-profile Australian AI-attributed workforce restructuring of the year-to-date and is likely to feature in scrutiny of the National AI Plan’s worker-protection commitments and in upcoming enterprise agreement negotiations.

Source: bloomberg.com

Microsoft and ACTU convene first AI Workers’ Summit under January 2026 framework

Microsoft Australia and the ACTU on 20 April convened the first Workers’ Summit on AI adoption under their January 2026 Framework Agreement, joined by NSW and Victorian peak union bodies and individual unions. The summit was cited three days later as the “industry-first dialogue with workers” element of the Microsoft–Commonwealth MoU. Microsoft committed to co-develop AI curriculum with the Australian Trade Unions Institute, setting a precedent likely to be referenced in future Fair Work Act consultation disputes about algorithmic management and AI-driven role changes.

Source: news.microsoft.com

Law Council of Australia publishes submission to Fair Work Commission on draft generative AI guidance note

The Law Council of Australia on 20 April published its submission to the Fair Work Commission on the President’s draft Guidance Note on the Use of Generative Artificial Intelligence in Commission Cases. The FWC draft, released by President Justice Adam Hatcher on 24 March, sets disclosure, verification, and witness-statement obligations for parties to FWC proceedings. The Law Council submission is the peak national legal body’s input to the first formal procedural rules from a major Commonwealth tribunal addressing the GenAI-driven surge in self-represented filings, and will shape final tribunal-wide AI compliance standards.

Source: lawcouncil.au

PwC AI Performance Study finds Australian companies lead on AI security but lag on ROI

PwC on 20 April released its global AI Performance Study, surveying 1,217 senior executives across 25 sectors. The study finds that 73 per cent of Australian organisations apply robust, up-to-date protections for data, models, and AI infrastructure (compared with 69 per cent of global “AI leaders”), but that 74 per cent of AI return on investment is captured by just 20 per cent of companies. Top-performing global enterprises are 1.7 times more likely to use a documented responsible-AI framework and 1.5 times more likely to operate a cross-functional AI governance board.

Source: pwc.com.au


This briefing was researched and written with AI assistance.

Stay across Australian AI governance

Get the briefing delivered to your inbox every week. No spam, unsubscribe any time.