Briefings

Australian AI Governance Briefing: Week Ending 17 May 2026

The 2026-27 Federal Budget commits $70 million to AI development and confirms TGA AI deployment in medicines approvals, while cutting the OAIC's funding by 8 per cent as three major regulatory expansions land on its desk.

6 stories

The defining event of the week was Treasurer Jim Chalmers’ 2026-27 Federal Budget, delivered Tuesday 12 May. The Budget pairs new AI investment — up to $70 million for “AI Accelerator” grants via the Cooperative Research Centres program, the reaffirmed $29.9 million Australian AI Safety Institute, and AI deployment within government — with an 8 per cent cut to OAIC funding to $36.576 million. The mismatch is the week’s most consequential compliance signal: the privacy regulator is heading into 13 months that bring APP 1.7–1.9 automated decision-making transparency obligations, the Children’s Online Privacy Code, and an AML/CTF Tranche 2 expansion that adds tens of thousands of reporting entities, with fewer resources to enforce them.

The Budget also explicitly endorsed AI for substantive Commonwealth regulatory decisions, with the TGA to use AI to evaluate medicines already approved by overseas regulators — the first Commonwealth regulator publicly committed to AI-assisted approvals. On Monday 11 May, MinterEllison became the first major Australian law firm to publicly attribute a graduate-intake reduction to AI, cutting its 2025-26 cohort from over 100 to 72. And across the week, Clayton Utz, MinterEllison, and Norton Rose Fulbright published alerts framing the prior week’s ASIC and APRA AI letters as a supervisory step-change from framework to targeted expectations.

The week in review

A Budget that funds AI but underfunds its privacy regulator

The 2026-27 Federal Budget consolidates the Albanese Government’s AI posture: investment-led, regulation-light, with the Commonwealth itself becoming an AI deployer. The headline AI commitment is up to $70 million for “AI Accelerator” rounds of the Cooperative Research Centres program — a CRC Projects round in 2026, then a CRC round in 2027 — building on the initial $20 million March 2026 allocation, the $47 million Next Generation Graduates Program, and earlier ecosystem investments. Chalmers cited the Productivity Commission’s December 2025 Harnessing Data and Digital Technology interim report, which projected an additional $116 billion in GDP over the next decade if Australia closes its AI-productivity gap. The previously announced $29.9 million Australian AI Safety Institute was reaffirmed in the Budget papers; the Institute will sit within DISR with an advisory, evaluation-focused remit and no enforcement powers, consolidating the path away from EU AI Act-style hard rules.

The fiscal signal for the privacy regulator runs the other way. The Office of the Australian Information Commissioner was allocated $36.576 million in 2026-27, down from $39.753 million in 2025-26 — an approximately 8 per cent reduction — with staffing essentially flat at 175 FTE. A separate $22.2 million Digital ID privacy oversight allocation sits within the broader $654.3 million four-year Digital ID envelope, but that money is ring-fenced for a specific function. The cut lands as the OAIC faces three major workload drivers in the next 13 months: APP 1.7–1.9 automated decision-making transparency obligations commencing 10 December 2026, the Children’s Online Privacy Code due for registration by the same date, and the 1 July 2026 commencement of AML/CTF Tranche 2 — which Norton Rose Fulbright has projected will bring roughly 80,000 to 90,000 new reporting entities into the regime, dramatically expanding the personal-information handling that falls under OAIC oversight. The practical implication for organisations is that OAIC enforcement will be sharply risk-based and prioritised, not comprehensive. Expect Carly Kind to use Senate Estimates and public commentary to frame which sectors and conduct attract regulatory attention; entities outside those priorities should not mistake limited OAIC bandwidth for permission.

Other regulator funding lines reinforce the divergence. The ACCC receives $67.7 million in new funding over four years, plus $98 million for its Digital ID regulator role and continuation of the National Anti-Scam Centre and Consumer Data Right work. APRA and ASIC share $206 million in data and cyber capability uplift — directly underwriting the active supervisory posture both regulators signalled in their April and May AI letters. The pattern across the Budget is consistent: regulators positioned to enable AI deployment or police market conduct receive material new funding; the regulator policing personal information handling absorbs a cut at exactly the moment its mandate widens.

Primary sources: Treasurer’s Budget Speech | Productivity chapter, Budget 2026-27 | IDM Magazine — OAIC funding squeeze | iTnews tech budget summary

The Commonwealth as AI deployer: TGA leads, ADM transparency follows

Beyond grants and institutes, the most concrete AI policy decision in the Budget was the Treasurer’s announcement that the Therapeutic Goods Administration will use AI to evaluate medicines already approved by similar regulators overseas — FDA, EMA, MHRA, Health Canada. The forecast administrative saving is $340 million per year. The Budget framing positioned TGA AI deployment alongside parallel uses in environmental approvals under the EPBC Act and in making the National Construction Code easier to use, but the medicines example is the most consequential: it is the first time the Commonwealth has publicly committed a regulator to using AI in product-approval decisions that materially affect access to therapeutic goods.

The compliance significance sits at the intersection of TGA’s existing AI/SaMD guidance and the APP 1.7–1.9 automated decision-making obligations that commence 10 December 2026. From that date, agencies and businesses must update their privacy policies to identify the personal information their automated systems use, the types of decisions those systems make, and which of those decisions could significantly affect a person’s rights or interests. The rules apply to rule-based software, machine learning models, and generative AI tools. A TGA AI-assisted approvals process will fall squarely within scope where personal information feeds the model — and the TGA will need to publish how AI informs decisions and what human-oversight arrangements apply. For other Commonwealth regulators, the TGA announcement establishes precedent. The combination of fiscal pressure on internal capacity, public Budget endorsement of AI deployment, and an emerging set of cross-government ADM guardrails makes broader Commonwealth regulator AI use the most likely growth area in Australian public-sector AI over the next 18 months.

Primary sources: Treasurer’s Budget Speech 12 May 2026 | Productivity chapter, Budget 2026-27 | SmartCompany — Federal budget AI accelerator

Law firms reframe the ASIC and APRA AI letters as supervisory step-change

The other current running through the week was the legal industry’s digestion of the prior week’s APRA (30 April) and ASIC (8 May) AI letters. Three Big-Six firms published alerts during 11–17 May that converged on a common reading. Clayton Utz framed APRA’s letter as “the most prescriptive AI-specific intervention APRA has made,” describing a “meaningful shift in supervisory posture: from ‘AI risk is covered by the existing framework’ to ‘here, specifically, is what APRA expects on AI.’” MinterEllison ran an analytical piece on APRA “sharpening expectations” on AI governance and risk management. Norton Rose Fulbright’s Regulation Tomorrow blog published a 14 May commentary on the ASIC letter focused on the immediacy of cyber resilience expectations and the elevation of cyber to a board-level licensing matter.

The shared framing matters because it is now the operating advice that boards, audit committees, and chief risk officers in APRA-regulated and ASIC-regulated entities will receive from their external counsel. The expected sequence in coming weeks is formal tabling of both letters at ultimate risk and board governance committees, gap analyses against the eight ASIC cyber priorities and APRA’s prudential expectations, a fresh look at AI vendor concentration risk, and a continuous-disclosure assessment for listed entities where AI-cyber exposure is material. Supervisory engagement is expected to follow; supply-chain push-down to non-regulated vendors of APRA-regulated clients was already foreshadowed in early May coverage and is likely to intensify as gap assessments surface dependencies.

Primary sources: Clayton Utz — APRA’s AI letter | MinterEllison — APRA sharpens AI expectations | Norton Rose Fulbright — ASIC cyber resilience

On Monday 11 May, MinterEllison became the first major Australian law firm to publicly attribute a graduate-intake reduction to AI. Chief People Officer Rachel Banks — appointed November 2025 — has linked the cut from over 100 to 72 in the 2025-26 cohort, a roughly 28 per cent reduction, directly to AI automation of the routine document review, basic research, and discovery work that has historically anchored junior lawyer training. The firm’s framing is that client demand is not the problem; the structural shift is in how legal work is executed. Other top-tier firms have reduced intakes citing “seasonal” or post-COVID factors; MinterEllison’s public attribution to AI is the development.

For Australian compliance professionals, three implications follow. First, the labour-market signal is now public: firms that have privately reduced graduate intake on AI grounds will find it harder to maintain the “seasonal correction” framing in their own communications. Second, the structural change in how high-end legal work is staffed will reach in-house teams — clients should expect leveraged junior hours on routine work to compress, with implications for billing models, fee structures, and the seniority profile of external counsel teams. Third, the workforce implications loop back to the regulatory agenda. APRA’s letter highlighted AI literacy concerns. The Fair Work Commission has noted a 40 per cent increase in lodgements over the three-year average, with AI cited as a workload driver. Standards Australia and the Tech Council have flagged Australia’s tech-workforce gap — the ACS Digital Pulse projects a need for 1.3 million tech workers by 2030. MinterEllison’s announcement makes a concrete contribution to a national conversation that is moving from “if” to “how fast” on AI-driven workforce change.

Primary sources: LawFuel — MinterEllison graduate cut | The Aussie Corporate — Big Law AI threat | Information Age — tech industry budget reaction

Stories

OAIC funding cut to $36.576 million as three major mandate expansions loom

The Office of the Australian Information Commissioner was allocated $36.576 million in the 2026-27 Federal Budget, down from $39.753 million in 2025-26 — an approximately 8 per cent reduction — with staffing essentially flat at 175 FTE. The cut lands as the OAIC faces APP 1.7–1.9 automated decision-making transparency obligations commencing 10 December 2026, the Children’s Online Privacy Code due for registration by the same date, and the 1 July 2026 commencement of AML/CTF Tranche 2, which is projected to add roughly 80,000 to 90,000 new reporting entities. Organisations should expect sharply risk-based, prioritised OAIC enforcement rather than comprehensive coverage; limited regulator bandwidth is not permission for non-compliance.

Source: idm.net.au

Federal Budget commits $70 million to AI Accelerator grants via CRC program

The 2026-27 Federal Budget delivered Tuesday 12 May by Treasurer Jim Chalmers commits up to $70 million for “AI Accelerator” rounds of the Cooperative Research Centres program — a CRC Projects round in 2026 followed by a CRC round in 2027. The Treasurer cited the Productivity Commission’s projection that closing Australia’s AI-productivity gap could add $116 billion in GDP over the next decade. The Budget reaffirms the $29.9 million Australian AI Safety Institute within DISR — advisory only, no enforcement powers — and confirms the Government’s investment-led, regulation-light AI posture. Potential applicants should monitor CRC-P guidelines for opening dates.

Source: budget.gov.au

TGA to use AI to evaluate overseas-approved medicines, forecasting $340M annual saving

The Treasurer’s Budget speech confirmed that the Therapeutic Goods Administration will use AI to evaluate medicines already approved by similar regulators overseas, including the FDA, EMA, MHRA, and Health Canada, with a forecast administrative saving of $340 million per year. It is the first time the Commonwealth has publicly committed a regulator to AI-assisted decisions in product approvals. The deployment intersects directly with APP 1.7–1.9 automated decision-making transparency obligations commencing 10 December 2026, requiring the TGA to publish how AI informs decisions and the human-oversight arrangements that apply. The announcement sets precedent for other Commonwealth regulators considering AI deployment in substantive decisions.

Source: smartcompany.com.au

MinterEllison cuts graduate intake by nearly one-third, citing AI

MinterEllison reduced its 2025-26 graduate intake from over 100 positions to 72 — a roughly 28 per cent cut — with Chief People Officer Rachel Banks publicly attributing the reduction to AI automation of the routine document review, basic research, and discovery work that has historically anchored junior lawyer training. It is the first time a major Australian law firm has publicly attributed a headcount reduction to AI, breaking the “seasonal variation” framing used by peers. The development is a concrete labour-market signal and feeds the AI Employment and Workplaces conversation that APRA, the Fair Work Commission, and Standards Australia have each flagged from different angles.

Source: lawfuel.com

ACCC receives $67.7M plus $98M Digital ID role in Budget tech envelope exceeding $2.4 billion

The ACCC receives $67.7 million in new funding over four years, plus $98 million for its Digital ID regulator role within the broader $654.3 million four-year Digital ID envelope. The National Anti-Scam Centre receives a further 12 months of funding and the Consumer Data Right work continues for two years. Across the Budget, APRA and ASIC share $206 million in data and cyber capability uplift, directly underwriting the active supervisory posture both regulators signalled in their April and May AI letters. Total Budget technology measures exceed $2.4 billion. The funding pattern places ACCC, APRA, and ASIC in a stronger position to enforce against AI-related conduct than the OAIC.

Source: itnews.com.au

Big-Six law firms frame ASIC and APRA AI letters as supervisory step-change

Clayton Utz, MinterEllison, and Norton Rose Fulbright published in-week alerts framing APRA’s 30 April letter and ASIC’s 8 May letter as a meaningful shift in regulatory posture — from “AI risk is covered by the existing framework” to specific, targeted AI expectations. Clayton Utz described APRA’s letter as “the most prescriptive AI-specific intervention APRA has made.” The convergent framing is now the operating advice boards, audit committees, and chief risk officers in regulated entities will receive from external counsel. APRA-regulated and ASIC-regulated entities should expect supervisory engagement to test gap analyses against the eight ASIC cyber priorities and APRA’s prudential AI expectations, including vendor concentration risk.

Source: claytonutz.com


This briefing was researched and written with AI assistance.

Stay across Australian AI governance

Get the briefing delivered to your inbox every week. No spam, unsubscribe any time.