Briefings

Australian AI Governance Briefing: Week Ending 7 June 2026

The OAIC's Children's Online Privacy Code consultation closed and Senate Estimates put the Australian AI Safety Institute under its first sustained scrutiny in an otherwise quiet week.

5 stories

Australian AI governance entered a holding pattern this week, with the heavy regulatory output of April and May now moving into its response phase rather than generating fresh obligations. The single most consequential domestic event was the closing of the OAIC’s consultation on the draft Children’s Online Privacy Code on Friday 5 June — the formal pivot from stakeholder feedback to Code finalisation ahead of the statutory registration deadline of 10 December 2026.

The week’s other substantive development came from Senate Budget Estimates, where Independent Senator David Pocock pressed Industry and Innovation Minister Tim Ayres on the funding, independence and leadership of the Australian AI Safety Institute, drawing public confirmation that the body is advisory only and that Dr Kate Conroy has been appointed its inaugural General Manager. A separate estimates exchange over an algorithmic aged-care assessment tool revived familiar concerns about removing human oversight from automated government decisions.

For compliance teams, the practical message is one of preparation, not reaction. No new binding obligations landed this week, but the consultations now closing — and the December 2026 commencement of both the Children’s Online Privacy Code and the Privacy Act’s automated decision-making transparency rules — make the next six months the window in which to get ready.

The week in review

Children’s Online Privacy Code consultation closes

The OAIC’s mandatory public consultation on the exposure draft of the Privacy (Children’s Online Privacy) Code 2026 closed on Friday 5 June, with the bulk of the regulator’s virtual stakeholder roundtables having run across the closing week from 31 May. The close moves the Code out of its feedback phase and into finalisation: the OAIC must now work through submissions and complete a regulatory impact analysis ahead of the statutory deadline to register the final Code by 10 December 2026. A compliance commencement date has not been announced, and several firms used their submissions to press for a defined transition period.

The substance of the draft has been canvassed extensively over April and May, so the practical significance of the close is procedural rather than new. What it confirms is the timeline. The Code reaches well beyond obvious social platforms to capture any APP entity offering a service likely to be accessed by children — extending on its face to school management systems, EdTech and connected devices — and layers a “best interests of the child” standard, default high-privacy settings, stricter destruction obligations and age-assurance expectations on top of the Australian Privacy Principles. Organisations whose services children are likely to use now have a fixed horizon to map their obligations, because the drafting choices being settled over the coming months will determine the eventual compliance burden.

The close also bookends a busy fortnight for the OAIC’s AI-adjacent work. The regulator’s separate Issues Paper on the new automated decision-making transparency obligation under APP 1 — released 18 May — remains open for submissions until 15 June, and signals an expansive reading of what counts as a substantially automated decision. Together with the children’s code, it represents the bulk of the OAIC’s 2026 guidance workload, and both feed the same 10 December 2026 commencement cliff.

Primary sources: OAIC — Children’s Online Privacy Code | OAIC — Draft Children’s Online Privacy Code consultation

Senate Estimates scrutinises the AI Safety Institute — and an aged-care algorithm

Budget Estimates delivered the week’s only real parliamentary action on AI. Appearing before the Senate Economics Legislation Committee on Tuesday 2 June, Industry and Innovation Minister Tim Ayres faced sustained questioning from Independent ACT Senator David Pocock on the design of the Australian AI Safety Institute. Pocock argued that housing the Institute inside the Department of Industry, Science and Resources, rather than establishing it as an independent body, leaves it exposed to the priorities and budget decisions of the government of the day. Ayres defended the structure by pointing to the comparable UK and Canadian safety institutes, which also sit within parent departments, and maintained the department could provide frank advice.

Two points of substance emerged for compliance professionals. First, Ayres confirmed the Institute is advisory — it will monitor, test and make recommendations on AI risks and trends, but will not act as a regulator, leaving existing regulators with jurisdiction intact. Second, the hearing publicly confirmed that Dr Kate Conroy, previously the Royal Australian Air Force’s responsible-AI lead, has been appointed the Institute’s inaugural General Manager — an appointment Pocock noted had not been announced. The exchange also surfaced the funding gap that has dogged the Institute since launch: its A$29.9 million over four years sits well below the resourcing of the UK and Canadian counterparts it is modelled on, a disparity Pocock used to argue the government is out of step with public concern about AI.

A separate estimates thread carried a sharper compliance lesson. Questioning of the health portfolio focused on the Integrated Assessment Tool, an algorithmic instrument used in aged-care assessments, with officials acknowledging that human oversight had been removed without consulting providers or advocates, and that a substantial share of assessments are now conducted remotely. With roughly a thousand review requests recorded by the end of March, the episode reads as a live reminder of the Robodebt-era risks of automated government decision-making — and a concrete illustration of why the incoming ADM transparency regime matters.

Primary sources: PS News — AI, algorithms and service caps in Senate Estimates | Senate Economics — 2026–27 Budget Estimates

The international backdrop

Two offshore developments framed the week without demanding any immediate Australian response. On 2 June, US President Donald Trump signed an executive order titled “Promoting Advanced Artificial Intelligence Innovation and Security”, directing federal agencies toward AI-enabled cyber defence and frontier-model security frameworks while expressly disclaiming any mandatory licensing or pre-clearance regime for new models. A day earlier, on 1 June, the European Commission set out the independent expert machinery that will support enforcement of the EU AI Act ahead of its full applicability on 2 August.

The contrast is the useful part. The EU — and, in its own technology-neutral way, Australia through the children’s code, ADM transparency and the online safety regime — is layering specific obligations onto existing law, while the US under the current administration is doubling down on an innovation-first posture with no licensing. For Australian boards relying on US-headquartered AI vendors, the divergence is worth tracking: the compliance expectations attaching to the same model can now differ sharply by jurisdiction.

Primary sources: The White House — Promoting Advanced AI Innovation and Security | European Commission — AI Act regulatory framework

Stories

Children’s Online Privacy Code consultation closes 5 June

The OAIC’s consultation on the exposure draft of the Privacy (Children’s Online Privacy) Code 2026 closed on Friday 5 June, ending the feedback phase and moving the Code into finalisation ahead of its statutory registration deadline of 10 December 2026. The Code imposes stricter consent, data-minimisation, best-interests and age-assurance obligations on services likely to be accessed by children, with a drafted scope extending to school management systems and connected devices. No compliance commencement date has yet been announced, leaving organisations to prepare against the registration timeline.

Source: oaic.gov.au

Senate Estimates scrutinises the Australian AI Safety Institute

At Senate Economics Budget Estimates on 2 June, Senator David Pocock pressed Minister Tim Ayres on the funding, independence and leadership of the Australian AI Safety Institute, which sits within the Department of Industry, Science and Resources. Ayres confirmed the Institute is advisory rather than a regulator and defended its departmental structure by reference to the UK and Canadian models. The hearing also publicly confirmed Dr Kate Conroy’s appointment as inaugural General Manager and highlighted the Institute’s A$29.9 million budget relative to better-funded overseas counterparts.

Source: psnews.com.au

Aged-care algorithmic assessment tool questioned at Estimates

Estimates questioning of the health portfolio focused on the Integrated Assessment Tool, an algorithmic instrument used in aged-care assessments, with officials acknowledging that human oversight had been removed without consulting providers or advocates and that many assessments are now conducted remotely. Roughly a thousand review requests had been recorded by the end of March. The exchange is a practical reminder of the risks of automated government decision-making and underscores the relevance of the Privacy Act’s incoming ADM transparency obligations.

Source: psnews.com.au

Trump signs executive order on AI innovation and security

US President Donald Trump signed an executive order on 2 June directing federal agencies toward AI-enabled cyber defence and frontier-model security frameworks, while expressly disclaiming any mandatory licensing, pre-clearance or permitting requirement for new AI models. The order reinforces the divergence between the US innovation-first posture and the obligation-layering approach of the EU and Australia. Australian organisations relying on US-based AI vendors should note that compliance expectations for the same model increasingly differ by jurisdiction.

Source: whitehouse.gov

European Commission sets out AI Act enforcement support

On 1 June the European Commission detailed the independent expert structures that will support enforcement of the EU AI Act, ahead of the Act’s full applicability on 2 August. The move firms up the governance machinery behind Europe’s risk-based AI regime. Australian organisations supplying or deploying high-risk AI systems into the EU should factor the approaching applicability date and enforcement readiness into their planning.

Source: europa.eu


This briefing was researched and written with AI assistance.

Stay across Australian AI governance

Get the briefing delivered to your inbox every week. No spam, unsubscribe any time.