Briefings

Australian AI Governance Briefing: Week Ending 31 May 2026

Australia and the UK signed an AI safety and security MoU on 25 May, giving the new Australian AI Safety Institute its first bilateral arrangement in an otherwise quiet domestic week.

2 stories

The week’s defining development was international in character but domestic in consequence. On Monday 25 May, the Australian and UK governments signed a Memorandum of Understanding on AI safety and security — the first concrete bilateral instrument for the Australian AI Safety Institute being stood up inside the Department of Industry, Science and Resources. The agreement ties the Institute to the more mature UK AI Security Institute, opening shared research, joint risk-testing methods and staff exchanges, and was framed explicitly against new findings about AI-enabled cyber threats.

For compliance professionals, the MoU creates no new binding obligations. What it does is signal where the Commonwealth’s AI assurance and testing capability is heading, and confirm that the “build on existing laws, coordinate internationally” posture of the December 2025 National AI Plan is being operationalised rather than left on paper.

Domestically, the week was genuinely quiet. Parliament was occupied with Senate Budget Estimates rather than AI legislation, and no new regulator guidance, enforcement action or court decision touching AI landed within the window. The one live compliance deadline worth tracking is the OAIC’s Children’s Online Privacy Code consultation, which entered its final days ahead of a 5 June close.

The week in review

Australia and the UK formalise AI safety cooperation

The single substantive Australian AI-governance event of the week was the signing of a Memorandum of Understanding between the Australian and UK governments on the responsible development, deployment and governance of safe and trustworthy AI. Signed Monday 25 May during a visit to Australia by UK Minister for AI and Online Safety Kanishka Narayan, the MoU was announced jointly by Minister for Industry and Innovation Tim Ayres and Assistant Minister for Science, Technology and the Digital Economy Andrew Charlton.

The agreement deepens cooperation between the Australian AI Safety Institute — being established within the Department of Industry, Science and Resources and backed by a A$29.9 million commitment — and the UK AI Security Institute. Under the MoU, the two countries will share information and expertise on emerging AI capabilities and risks and on best practice for testing AI systems; conduct joint research, including novel approaches to measure, test and manage risk; and jointly support the International Network for Advanced AI Measurement, Evaluation and Science, of which both are founding members. The UK release confirmed the arrangement will also open the door to staff exchanges between the two institutes. The British side tied the timing to fresh UK AI Security Institute research finding that advanced AI systems are rapidly improving their ability to carry out sophisticated cyberattacks.

The practical significance for Australian organisations is indirect but real. This is the Australian AI Safety Institute’s first bilateral instrument since it was announced in November 2025, and it imports the testing and evaluation methods of a considerably more developed counterpart. Where APRA and ASIC spent late April and early May warning regulated entities about frontier-model and AI-enabled cyber risk, this MoU is the supply side of that same concern — the government building the capability to measure and test the systems it expects boards to govern. It also confirms the trajectory of the National AI Plan: regulation where necessary, reliance on existing law, and international coordination as the primary near-term lever rather than a dedicated AI Act. Compliance teams should read it as a signal about the direction and sophistication of future government assurance expectations, not as a new obligation to act on this quarter.

Primary sources: Minister for Industry — Australia and UK partner to strengthen AI safety and security | GOV.UK — UK and Australia pact on fast-moving AI security risks | Capital Brief — Australia and UK governments ink agreement on AI safety and security

Children’s Online Privacy Code consultation enters its final days

The OAIC’s public consultation on the exposure draft of the Privacy (Children’s Online Privacy) Code 2026 ran through its closing stretch this week, ahead of submissions closing on 5 June. The Code, which the Information Commissioner must register by 10 December 2026, will impose stricter consent, data-minimisation, transparency and best-interests obligations on online services likely to be accessed by children, supplementing the Australian Privacy Principles. Its drafted scope reaches beyond obvious social platforms to capture services primarily concerned with children’s activities, such as school management systems and internet-connected baby monitors, and it contemplates age-assurance measures and notification where a parent consents on a child’s behalf or tracks a child’s geolocation.

For any organisation operating a service that children are likely to use, the final week of the consultation was the practical deadline for finalising a submission. Breaches of the registered Code will attract penalties of up to A$3.3 million, with higher exposure for serious interferences with privacy, so the drafting choices being settled now matter directly to the eventual compliance burden. The Code also sits alongside the broader children’s-safety agenda — including the social media minimum age regime now in its enforcement phase — that has made under-18 data handling one of the most active areas of Australian regulatory attention.

Primary sources: OAIC — Children’s Online Privacy Code | OAIC — Draft Children’s Online Privacy Code consultation

Stories

Australia and UK sign AI safety and security Memorandum of Understanding

The Australian and UK governments signed an MoU on safe and trustworthy AI on Monday 25 May, linking the new Australian AI Safety Institute to the UK AI Security Institute. The agreement covers shared information and testing expertise, joint research on measuring and managing AI risk, staff exchanges, and joint support for the International Network for Advanced AI Measurement, Evaluation and Science. It is the first bilateral instrument for the A$29.9 million Institute since its November 2025 announcement and signals the direction of future Commonwealth AI assurance and testing capability rather than creating any new obligation on business.

Source: minister.industry.gov.au

Children’s Online Privacy Code consultation closes 5 June

The OAIC’s consultation on the exposure draft of the Privacy (Children’s Online Privacy) Code 2026 entered its final days this week ahead of a 5 June submissions deadline. The Code will impose stricter consent, data-minimisation, transparency and best-interests obligations on online services likely to be accessed by children, with a drafted scope extending to school management systems and connected devices, and must be registered by 10 December 2026. Breaches will attract penalties of up to A$3.3 million, making the consultation directly relevant to any organisation whose services children are likely to use.

Source: oaic.gov.au


This briefing was researched and written with AI assistance.

Stay across Australian AI governance

Get the briefing delivered to your inbox every week. No spam, unsubscribe any time.