Briefings

Australian AI Governance Briefing: Week Ending 2 August 2026

The OAIC issued its first update since 2024 to facial recognition guidance for retail, converting the Bunnings tribunal decision into a tighter set of assessment expectations rather than a relaxation.

4 stories

A quiet week federally, with Parliament in winter recess until 11 August, but a substantive one for regulators. The Office of the Australian Information Commissioner published updated facial recognition guidance for retail on 29 July — the first revision since 2024 — implementing the Administrative Review Tribunal’s decision in the Bunnings matter. Retailers hoping the tribunal outcome had loosened the position will not find that in the guidance. The OAIC has used the decision to sharpen how the consent exceptions should be applied rather than to widen them, and the Privacy Commissioner’s framing remains precautionary.

The eSafety Commissioner commenced civil penalty proceedings against Telegram in the Federal Court on 30 July, seeking penalties of up to $54.6 million for alleged breaches of the Relevant Electronic Services Standard. It is the first time the systemic safety obligations — duties to prevent, detect, deter and disrupt unlawful material at a systems level — have been tested in court against a global platform.

Offshore, the EU AI Act reached its general application date on 2 August, days after the Digital Omnibus entered into force and deferred the high-risk obligations to late 2027. The transparency duties were not deferred. Australian organisations supplying AI into the EU market face live obligations now.

The week in review

Facial recognition: a tribunal decision turned into tighter guidance

The OAIC published updates on 29 July to its guidance for Australian Privacy Principle entities considering facial recognition technology in high volume, publicly accessible physical spaces such as retail shopfronts. It is the first revision since the guidance was issued in 2024, and it implements the findings of the Administrative Review Tribunal in the Bunnings Group Limited matter, which concerned the retailer’s use of the technology across up to 62 stores between November 2018 and November 2021. The tribunal affirmed aspects of the Privacy Commissioner’s November 2024 determination and confirmed that there is a high bar for deploying facial recognition in Australia.

The substance of the update is narrow but consequential. It provides greater clarity on how the exceptions to the obligation to obtain consent when collecting sensitive information — including biometric information — should be applied in retail settings. That is the provision on which the Bunnings matter turned, and it is the provision retailers have been reading optimistically since the tribunal ruled. The guidance forecloses the optimistic reading. Exception pathways are narrow and must be assessed against the facts of the particular deployment; the regulator explicitly acknowledges that entities will continue to need to make contextual assessments of legality, and positions the guidance as support for making those assessments rather than as a safe harbour.

The assessment framework the guidance sets out will be familiar to anyone who has run a privacy impact assessment properly, and unfamiliar to anyone who has treated one as a formality. Entities are directed to conduct a privacy impact assessment at the outset and to implement its recommendations. The questions to be answered before deployment include the primary purpose of the collection, whether the function or activity can be performed without collecting biometric information at all, whether the purpose can be achieved through less intrusive means, whether alternatives have genuinely been considered, and whether the benefits justify the intrusion. Beyond the necessity analysis, the guidance directs attention to system effectiveness, the accuracy of images and watchlists, demographic bias, data security and deletion practices. Transparency obligations apply whether collection proceeds on consent or on an exception, and governance arrangements must be implemented, documented and reviewed as the system or its operating conditions change.

Two boundaries are worth noting. The guidance addresses facial identification in physical commercial settings; the OAIC observes that age assurance and other biometric applications may collect different information and require separate analysis. And the Bunnings matter is not the end of the line — a separate determination issued against Kmart in August 2025 concerning its use of the technology remains under review in the tribunal, with hearings scheduled for early 2027. That case concerns watchlist-based deployment and could shift the analysis again.

The Privacy Commissioner anchored the update in community expectation as much as in law, noting that a precautionary approach is required under Australian law and pointing to the 2026 Australian Community Attitudes to Privacy Survey, in which 45 per cent of Australians identified facial recognition as one of the biggest privacy risks they face — up from 27 per cent in 2023. For compliance teams, the practical read is that a documented, contemporaneous necessity and proportionality assessment is now the minimum defensible artefact for any biometric deployment in a public-facing space, and that the absence of one will be difficult to explain if the regulator comes asking.

Primary sources: OAIC — Privacy Commissioner publishes updated guidance on facial recognition in retail spaces | Inside Retail — Retailers gain clarity around facial recognition rules

The EU AI Act splits in two, and the half that applies now is the transparency half

The EU AI Act reached its general date of application on Sunday 2 August 2026. Five days earlier, on 27 July, Regulation (EU) 2026/1744 — the Digital Omnibus on AI — entered into force, amending the Act on the eve of that date. The two events are frequently collapsed in commentary, and the distinction matters for anyone planning against European exposure.

The Omnibus, adopted on 8 July and published in the Official Journal on 24 July, took effect on the third day after publication rather than the customary twentieth, precisely because the general application date was imminent. It amends the AI Act along with the aviation and machinery regulations, and its central change is a rewrite of the transitional provisions in Article 113. Obligations for standalone high-risk systems listed in Annex III — the category that captures AI used in employment, education, credit assessment, law enforcement and critical infrastructure — move from 2 August 2026 to 2 December 2027. High-risk systems embedded in regulated products under Annex I move to 2 August 2028. Systems already in service before the new dates remain outside the obligations until they undergo significant design changes, though any such pre-existing high-risk system used by a public authority must comply by 2 August 2030 regardless.

What did not move is at least as important. The general application date remained 2 August 2026. The prohibitions in force since February 2025 were untouched, as were the obligations on general-purpose AI models. And the Article 50 transparency obligations became applicable on 2 August: disclosing to people that they are interacting with an AI system, labelling deepfakes, and disclosing AI-generated text published to inform the public on matters of public interest. The single concession is the machine-readable marking of synthetic content under Article 50(2), which is given until 2 December 2026 for systems already on the market before 2 August 2026. The enforcement architecture switched on alongside.

For Australian organisations the exposure is the familiar extraterritorial one: providers placing AI systems on the EU market, and deployers whose system output is used in the EU, are within scope regardless of where they sit. Any Australian business running a customer-facing conversational agent, generating synthetic media, or publishing AI-generated content into European markets has obligations that are live now, not in 2027. The deferral of the high-risk timetable has been widely read as relief; for the transparency layer it is nothing of the sort.

There is a domestic dimension too. The Australian Standards for AI announced in mid-July are due to go to National Cabinet this month, with legislation flagged for early 2027. The EU recalibration will be cited on both sides of that argument — as evidence that comprehensive horizontal regulation is difficult to implement on schedule, and as evidence that transparency obligations are achievable even when the heavier machinery slips. Australian drafters now have the benefit of watching which parts of the European timetable held.

Primary sources: EUR-Lex — Regulation (EU) 2026/1744 (Digital Omnibus on AI) | Hunton — EU Digital Omnibus on AI enters into force

eSafety takes the systemic safety obligations to court

The eSafety Commissioner commenced civil penalty proceedings in the Federal Court against Telegram FZ-LLC on 30 July, following a year-long investigation. The allegation is that Telegram failed to detect and remove pro-terror material, including videos of terrorist executions and mass shootings, and that this amounts to a failure to comply with systemic safety obligations under the Online Safety Act’s Relevant Electronic Services Standard. The regulator alleges that publicly posted unlawful material remained accessible after the platform was put on notice by Australian users, that known material including footage of the 2019 Christchurch attack and the 2022 Buffalo shooting was not detected, that terms of service did not prohibit the conduct, and that complainants were not notified of outcomes. eSafety is seeking declarations of contravention of section 146(1) of the Online Safety Act 2021 and a penalty to be determined by the court, with the statutory maximum at $54.6 million. Telegram has denied the allegations and says it will contest the proceedings.

This is not an AI matter, and it should not be reported as one. It is relevant to AI governance for a structural reason: the obligations being litigated are systems obligations. The Standard requires services to take steps to prevent, detect, deter and disrupt the proliferation of unlawful material — a proactive, architecture-level duty rather than a reactive takedown duty — and this is the first time that construction has been tested against a global platform in an Australian court. The proposed Digital Duty of Care is built on the same conceptual foundation, as are the systemic obligations that any future Australian AI standards would most plausibly adopt. Whatever the court says about what “reasonable steps” means at a systems level, and about how a regulator proves a systemic failure from a sample of individual reports, will shape the drafting and the enforcement of the next generation of Australian digital obligations well beyond online safety.

The commercial signal is separate and simpler. eSafety has moved from infringement notices to court proceedings, has been publicly willing to discuss its unused power to seek orders that a service cease operating in Australia, and has chosen a defendant with a demonstrated appetite for litigation. Platforms and services with Australian users should not assume that engagement short of compliance will hold.

Primary sources: eSafety — Civil penalty proceedings commenced against Telegram

The governance gap, measured

ServiceNow released Australian findings from its Enterprise AI Maturity Index on 30 July, drawn from a survey of 4,500 executives across 19 countries and 12 industries, including 350 in Australia. It is vendor-sponsored research and should be read as such, but the shape of the numbers is consistent with what regulators have been saying from the supervisory side. Australian AI spending rose 115 per cent year on year, five per cent above the global average, and the country’s maturity score rose 15 points to 51 out of 100. Against that, 23 per cent of Australian organisations reported having testing or auditing processes for AI, 17 per cent reported a system for tracking governance and compliance, 18 per cent had integrated AI across business functions and 8 per cent had moved to autonomous workflows.

The relevant point for compliance teams is the gap between the first set of figures and the second. Investment is compounding faster than the control environment, and the specific control that is scarcest — a system for tracking governance and compliance — is precisely the one that the December 2026 automated decision-making transparency obligations will require organisations to have. An entity cannot describe the kinds of substantially automated decisions it makes, or the kinds of personal information used in them, if it does not know where its automated decisions are. On this data, roughly four in five Australian organisations do not.

Primary sources: ServiceNow — Australia’s AI investment surges, yet governance is holding productivity back

Stories

OAIC updates facial recognition guidance for retail, implementing the Bunnings tribunal decision

On 29 July 2026 the OAIC published its first update since 2024 to guidance for APP entities considering facial recognition technology in high volume, publicly accessible spaces such as retail shopfronts. The update implements the Administrative Review Tribunal’s decision in the Bunnings matter and clarifies how the exceptions to consent for collecting sensitive biometric information apply in retail settings, without widening them. Entities are directed to complete a privacy impact assessment before deployment and to document necessity, proportionality, less intrusive alternatives, system effectiveness, watchlist accuracy, demographic bias, security and deletion. The Privacy Commissioner reiterated that a precautionary approach is required under Australian law, citing survey data showing 45 per cent of Australians now rank facial recognition among their biggest privacy risks.

Source: oaic.gov.au

EU AI Act reaches general application as the Digital Omnibus defers high-risk obligations

Regulation (EU) 2026/1744, the Digital Omnibus on AI, entered into force on 27 July 2026, five days before the AI Act’s general application date of 2 August. The Omnibus moves standalone Annex III high-risk obligations to 2 December 2027 and Annex I embedded systems to 2 August 2028, but leaves the general application date, the existing prohibitions and the general-purpose AI obligations unchanged. Article 50 transparency duties — AI interaction disclosure, deepfake labelling and disclosure of AI-generated public-interest text — applied from 2 August, with machine-readable synthetic content marking deferred to 2 December 2026 for systems already on the market. Australian providers and deployers with EU market exposure have live obligations now.

Source: eur-lex.europa.eu

eSafety commences Federal Court proceedings against Telegram over alleged systemic safety failures

The eSafety Commissioner commenced civil penalty proceedings in the Federal Court on 30 July 2026 against Telegram FZ-LLC, alleging failure to detect and remove pro-terror material in breach of systemic safety obligations under the Online Safety Act’s Relevant Electronic Services Standard. Following a year-long investigation, the regulator alleges reported material remained accessible after notice, that known content including Christchurch and Buffalo footage was not detected, and that complainants were not notified of outcomes; the statutory maximum penalty is $54.6 million. The matter is not an AI case, but it is the first court test of Australia’s proactive, systems-level digital safety obligations against a global platform — the same architecture underpinning the proposed Digital Duty of Care. Telegram denies the allegations and will contest the proceedings.

Source: esafety.gov.au

Survey finds Australian AI spending outpacing governance controls

ServiceNow published Australian results from its Enterprise AI Maturity Index on 30 July 2026, based on a survey of 4,500 executives across 19 countries including 350 in Australia. Australian AI spending rose 115 per cent year on year and the national maturity score rose 15 points to 51 out of 100, but only 23 per cent of organisations reported AI testing or auditing processes and only 17 per cent reported a system for tracking governance and compliance. The research is vendor-sponsored and self-reported, but the governance-tracking figure is directly relevant to the automated decision-making transparency obligations commencing 10 December 2026, which assume an organisation can identify where its substantially automated decisions sit.

Source: newsroom.servicenow.com


This briefing was researched and written with AI assistance.

Stay across Australian AI governance

Get the briefing delivered to your inbox every week. No spam, unsubscribe any time.