Briefings

Australian AI Governance Briefing: Week Ending 28 June 2026

A binding age-assurance deadline for search engines took effect, while the Senate's inquiry into AI and data centres closed its written submissions.

3 stories

A quiet week delivered one hard compliance milestone and one process deadline. On Saturday 27 June, the obligation requiring internet search engine services to apply age assurance to logged-in Australian account holders took full effect under the eSafety Commissioner’s Internet Search Engine Services Online Safety Code — the first binding age-check duty to land on the major search providers, carrying penalties of up to $49.5 million per breach. The day before, on Friday 26 June, written submissions closed to the Senate inquiry into artificial intelligence and data centres.

Neither event arrived with fanfare. No public compliance launch from Google or Microsoft, and no enforcement statement from eSafety, accompanied the search deadline — consistent with a co-regulatory code whose age checks are designed to run largely invisibly on data the providers already hold. The practical question now shifts to eSafety’s enforcement posture and whether providers can defend the methods they have chosen if challenged. For the Senate inquiry, the written evidence base is now locked; the committee reports on 16 November.

Beyond these two dates the week was thin. Minister Tim Ayres offered the usual signalling — a CEDA panel on research and development, an ABC interview on CSIRO and AI, and $12.7 million for quantum projects — but no new instruments. The December 2026 obligation cluster remains the anchor compliance teams should be planning to.

The week in review

A binding age-assurance deadline arrives for search engines

The week’s most consequential compliance fact was a date set a year in advance. On 27 June 2026, the requirement for internet search engine services to implement appropriate age assurance for logged-in account holders took full effect under the eSafety Commissioner’s Internet Search Engine Services Online Safety Code (Schedule 3), registered under section 140 of the Online Safety Act 2021 on 27 June 2025. The code took effect on 27 December 2025 with a six-month implementation window; that window has now closed. It is the first binding age-check obligation to bite on the major search providers — Google, Microsoft’s Bing, Yahoo and DuckDuckGo — and a breach of a direction to comply can attract penalties of up to $49.5 million.

The substance is narrower than the headline number suggests. The duty applies only to logged-in account holders, not to anonymous searching, and providers must apply their highest-level safety settings by default once their systems detect that an account holder is likely to be an Australian child. The code is deliberately technology-neutral: providers may use age verification (government ID, digital ID, credit-card checks), age estimation (facial or behavioural inference) or a combination, but self-declaration alone is not acceptable. That flexibility cuts both ways — providers choose their approach, but must be able to defend it if eSafety challenges the method’s effectiveness.

What is most notable is what did not happen. The deadline passed without a public compliance launch from Google or Microsoft, without an eSafety enforcement or commencement statement, and without meaningful coverage in the trade or general press. That silence is consistent with the co-regulatory, industry-developed character of the code — co-led by the Digital Industry Group Inc. and the Communications Alliance — and with eSafety’s own observation that many age checks occur invisibly, using data providers already hold. For compliance teams, the practical read is that the obligation is now live, the enforcement posture is untested, and the next signal to watch is whether eSafety issues information notices or pursues any provider for systemic non-compliance. The age-assurance accuracy concerns surfaced during the under-16 social-media rollout remain unresolved and will shape how robust any provider’s defence looks.

Primary sources: eSafety — Online Safety Codes regulatory guidance | The Conversation — Search engines will soon start filtering adult content

The Senate’s AI and data-centre inquiry closes its written window

The week’s other dated milestone was procedural but substantive. Written submissions closed on 26 June 2026 to the Senate inquiry into artificial intelligence and data centres, referred to the Environment and Communications References Committee on 13 May and chaired by Greens Senator Sarah Hanson-Young. The terms of reference are broad: the adequacy of existing regulatory frameworks for data-centre growth, energy and water consumption, community impacts, government AI procurement deals, and the overall fitness of Australia’s AI regulatory system. The committee is due to report on 16 November 2026.

With the written window now shut, the evidence base is fixed and the inquiry moves to hearings and analysis. Stakeholders who did not lodge — data-centre developers, hyperscalers, enterprise AI adopters, utilities and investors — have missed the primary opportunity to put a position on the record. The inquiry sits alongside the Commonwealth’s recently released, non-binding Expectations of data centres and AI infrastructure developers and a parallel NSW data-centre inquiry reporting on 30 September, and it is likely to probe whether voluntary expectations should be backed by legislation. The commercial stakes are real: Australia has been among the largest destinations for data-centre capital globally, which is precisely why questions of regulatory fragmentation across planning, environmental, energy and privacy regimes now command parliamentary attention.

Minister Tim Ayres reinforced the policy backdrop through the week without adding to the instrument set. He spoke to a CEDA panel on research and development within the Future Made in Australia frame on 25 June, used an ABC Breakfast interview the same day to flag CSIRO leaning further into artificial intelligence amid its reprioritisation, and announced $12.7 million for eight quantum technology projects — one of them targeting energy-efficient data-centre cooling, a neat illustration of the energy-and-infrastructure theme the Senate inquiry is now examining. None of this is a new obligation; it is signalling that the government’s “regulate where necessary, guide otherwise” posture is holding.

Primary sources: Parliament of Australia — AI and data centres inquiry | Clayton Utz — Unpacking the Senate’s data centre and AI inquiry | Minister Ayres — CEDA panel speech

Stories

Search-engine age-assurance obligation takes full effect

On 27 June 2026 the requirement for internet search engine services to apply age assurance to logged-in Australian account holders took full effect under eSafety’s Internet Search Engine Services Online Safety Code, closing the six-month implementation window that opened on 27 December 2025. Google, Bing, Yahoo and DuckDuckGo must now apply their highest safety settings by default for account holders their systems assess as likely to be Australian children, with penalties of up to $49.5 million for a breach of a compliance direction. The deadline passed without any public compliance launch or eSafety enforcement statement, leaving the regulator’s enforcement posture untested.

Source: esafety.gov.au

Senate inquiry into AI and data centres closes submissions

Written submissions to the Senate inquiry into artificial intelligence and data centres closed on 26 June 2026. The inquiry, chaired by Senator Sarah Hanson-Young, is examining the adequacy of regulatory frameworks for data-centre growth, energy and water use, community impacts and government AI deals, and reports on 16 November 2026. With the written window now closed, the evidence base is locked and stakeholders who did not lodge have missed the primary opportunity to be heard.

Source: aph.gov.au

Ayres signals on AI, CSIRO and infrastructure without new rules

Minister for Industry and Innovation Tim Ayres used a 25 June CEDA panel on research and development to situate AI within the Future Made in Australia agenda, and an ABC Breakfast interview the same day to flag CSIRO leaning further into artificial intelligence. He also announced $12.7 million for eight quantum technology projects, one targeting energy-efficient data-centre cooling. None of this introduced new regulatory obligations, but it reinforces the government’s existing-laws-plus-guidance posture ahead of the December 2026 obligation cluster.

Source: minister.industry.gov.au


This briefing was researched and written with AI assistance.

Stay across Australian AI governance

Get the briefing delivered to your inbox every week. No spam, unsubscribe any time.