Australian AI Governance Briefing: Week Ending 5 July 2026
A creator-sector coalition rallied at Parliament House to hold the line on copyright as AI companies pushed for a training exception.
A quiet week turned on a single date. On 1 July, a broad coalition of Australia’s creative and media organisations — led by APRA AMCOS and joined by ARIA, the Australian Society of Authors, the Australian Writers’ Guild and the Copyright Agency, among others — took its case to Parliament House, urging the Albanese Government to hold firm on the existing copyright framework and resist pressure from AI companies to introduce a text-and-data-mining exception. The delegation arrived with an open letter carrying more than 12,100 signatures.
The rally is the clearest sign yet that copyright, not a standalone AI Act, is where Australia’s most consequential AI-governance contest is being fought. The government has repeatedly ruled out a text-and-data-mining exception; the sector’s message this week was to keep it that way and build a licensing model instead. For any organisation training or fine-tuning models on Australian content, the licence-don’t-scrape posture is visibly hardening.
The same date brought a compliance milestone for financial institutions. APRA’s CPS 230 transition window for legacy material service-provider contracts closed on 1 July, and targeted amendments to the standard and its guidance commenced. For regulated entities, the AI and data vendors that support critical operations now sit squarely inside an enforceable operational-risk regime — a reminder that AI governance in finance runs through third-party risk.
The week in review
Creators take the copyright fight to Parliament
The week’s defining event was a show of force. On 1 July 2026, a coalition of Australia’s creative and media sectors gathered at Parliament House in Canberra to press the government to defend the country’s existing copyright settings against AI companies seeking to train models on Australian works without permission or payment. The delegation was led by APRA AMCOS and drew in ARIA, the Australian Society of Authors, the Australian Writers’ Guild, the Australian Music Publishers Association, the Copyright Agency, Mushroom Group and a long list of artists and authors including William Barton, Anna Funder, Mark Seymour, Mahalia Barnes and Holly Rankin. They carried an open letter that had gathered more than 12,100 signatures from songwriters, composers, authors, journalists, photographers and creative businesses.
The coalition’s demand was specific and narrow: hold firm on the existing copyright framework, resist pressure to reopen or weaken it, and rule out — permanently — a text-and-data-mining exception that would let AI developers ingest copyrighted works without a licence. The sector’s alternative is not prohibition but a licensing model, drawing on a century of collective-licensing infrastructure that has already adapted to radio, television and streaming. APRA AMCOS chief executive Dean Ormston framed the stakes bluntly, describing the unlicensed use of members’ works as the largest intellectual-property theft in the industry’s history and rejecting as “simply not true” the claim by Atlassian co-founder and Tech Council chair Scott Farquhar that current law makes it impossible to train AI in Australia.
The rally did not arrive in a vacuum. It followed reporting by The Atlantic that millions of Australian and New Zealand musical works had been swept into large datasets used to train AI models without consent, naming artists from Midnight Oil and Cold Chisel to Tame Impala and Yothu Yindi. It also lands on a government that has already staked out a position: the Commonwealth has repeatedly said it has no plans to weaken copyright protections and has explicitly ruled out a text-and-data-mining exception. For compliance teams, the practical read is that Australia’s most active AI-governance battleground is copyright, not a dedicated AI statute, and the direction of travel is toward licensing rather than exemption. Any organisation building, fine-tuning or procuring models trained on Australian creative or editorial content should treat provenance and licensing of training data as a live governance question, not a theoretical one.
Primary sources: APRA AMCOS — Open letter to government | Limelight — Australian creatives call on Parliament to hold firm
APRA’s CPS 230 deadline lands for legacy vendor contracts
The financial sector reached its own 1 July milestone. That date marked the close of APRA’s transition window for pre-existing material service-provider arrangements under Prudential Standard CPS 230 Operational Risk Management: legacy contracts had to be brought into compliance by the earlier of their next renewal or 1 July 2026. CPS 230 itself has been in force since 1 July 2025, consolidating the older outsourcing and business-continuity standards into a single operational-risk regime for banks, insurers and superannuation trustees. With the transition period now expired, the flexibility that let institutions defer contract uplift on legacy arrangements is gone; the bar shifts from remediation activity to demonstrable assurance.
Landing on the same day were APRA’s targeted amendments to CPS 230, the CPG 230 practice guide and the material service provider register template, finalised on 30 April 2026 and commencing 1 July. The amendments introduce a limited exemption from specific contractual requirements for material arrangements with certain non-traditional service providers — government agencies, regulators, central banks, clearing and settlement facilities, payment systems and financial messaging infrastructures — where bespoke contractual terms are not practicable to negotiate. The relief is narrow: it touches only the specified contractual clauses, and every other CPS 230 obligation, including active management of the operational risk those dependencies create, continues to apply.
For AI governance, the relevance is the third-party lens. AI and data-analytics vendors that support a regulated entity’s critical operations are material service providers, and the contractual obligations now in full effect — audit and regulator access, incident notification, exit and contingency planning, ongoing monitoring — apply to them like any other critical dependency. As financial institutions push AI deeper into fraud detection, credit decisioning and customer operations, CPS 230 is the standard under which the resilience and controllability of those systems will be tested. The message for compliance teams is that operational-risk governance of AI in APRA-regulated entities is no longer a transition project; it is a live, enforceable expectation.
Primary sources: APRA — Operational risk management | APRA — Final targeted amendments to CPS 230
Stories
Creative sector rallies at Parliament House to defend copyright against AI
On 1 July 2026, a coalition led by APRA AMCOS and including ARIA, the Australian Society of Authors, the Australian Writers’ Guild and the Copyright Agency took an open letter with more than 12,100 signatures to Parliament House, urging the government to hold firm on the existing copyright framework and rule out a text-and-data-mining exception for AI training. The move follows revelations that large volumes of Australian works were used in AI training datasets without permission, and reinforces that copyright is the primary battleground for AI governance in Australia. Organisations training or fine-tuning models on Australian content should treat training-data provenance and licensing as an active compliance issue.
APRA’s CPS 230 transition deadline closes for legacy vendor contracts
APRA’s transition window for pre-existing material service-provider contracts under Prudential Standard CPS 230 closed on 1 July 2026, and targeted amendments to CPS 230 and CPG 230 — introducing a limited contractual exemption for certain non-traditional service providers — commenced the same day. Legacy contracts must now meet the standard’s operational-risk requirements in full, with no further transition relief. For APRA-regulated entities, AI and data vendors supporting critical operations fall squarely within these enforceable third-party obligations, from audit access to exit planning.
This briefing was researched and written with AI assistance.
Stay across Australian AI governance
Get the briefing delivered to your inbox every week. No spam, unsubscribe any time.