The AI governance frameworks Aicura is wired into.
Only the frameworks the product actually uses, with no logos for frameworks we haven't done the work on, no placeholders, and no 'coming soon' sections.
ADM transparency (APP 1.7–1.9)
The amendments to Australian Privacy Principle 1 that take effect on 10 December 2026. Every APP entity must update its privacy policy to disclose the kinds of personal information used in automated decisions and the kinds of decisions being made. This is the most urgent framework Aicura is wired into.
Read the explainer→DeadlineThe 10 December 2026 deadline
10 December 2026 is the day the Privacy Act ADM transparency provisions commence. Every APP entity needs an updated privacy policy, an inventory of AI systems making automated decisions, and disclosure of those decisions ready by then. The OAIC is preparing a compliance scan for the day after.
Read the explainer→Privacy ActNotifiable Data Breach scheme
Part IIIC of the Privacy Act. Obliges APP entities to assess suspected data breaches within thirty days and notify the OAIC and affected individuals when serious harm is likely. The framework AI incident response runs into when personal information is involved.
Read the explainer→DISR8 AI Ethics Principles
Australia's eight voluntary AI Ethics Principles, published by the Department of Industry, Science and Resources in November 2019. The conceptual baseline that most other Australian guidance points back to. Aicura uses them as a guidance source for governance policy reviews and per-system risk assessments.
Read the explainer→NSWNSW AI Assessment Framework
The mandatory framework for NSW government agencies, redesigned in 2024–2025 with CSIRO Data61. Defines a Level 1–4 risk classification with pause conditions for the highest tier, and auto-classifies generative AI as elevated risk. Aicura uses its risk taxonomy across the AI Register and per-system risk assessments.
Read the explainer→CSIROAI6 Essential Practices
Six essential practices for AI governance published by the CSIRO National AI Centre in the Guidance for AI Adoption (GfAA) in October 2025. Voluntary but referenced widely across Australian guidance. Aicura uses AI6 as a source for governance policy scanning and per-system risk assessments.
Read the explainer→DTAAustralian Government AI guidance
The Digital Transformation Agency's policy and guidance for responsible use of AI in government, covering accountable officials, AI transparency statements and whole-of-government expectations that reach vendors through procurement. Aicura uses it as a guidance source for assessments and policy reviews.
Read the explainer→InternationalISO/IEC 42001:2023
The international standard for AI management systems, adopted in Australia as AS ISO/IEC 42001:2023. The first certifiable AI management system standard. Aicura uses it as a guidance source for risk assessment work and as a bridge framework for Australian organisations with international operations.
Read the explainer→InternationalNIST AI Risk Management Framework
The voluntary US framework for managing AI risks, organised around four core functions: Govern, Map, Measure, Manage. Used by Aicura as a guidance source alongside Australian frameworks for risk assessment work, particularly for organisations with US operations or US-facing supply chains.
Read the explainer→EnterpriseEU AI Act
Regulation (EU) 2024/1689 is the world's first comprehensive AI statute, covering risk tiers, obligations on high-risk systems and serious incident reporting, with reach that can catch Australian organisations serving Europe. Available in Aicura on the Enterprise tier.
Read the explainer→EnterpriseUnited Kingdom
The UK's principles-based approach, built on five cross-sector principles applied by existing regulators, with UK GDPR and ICO expectations on AI and automated decision-making doing much of the work. Available in Aicura on the Enterprise tier.
Read the explainer→EnterpriseSingapore
The Model AI Governance Framework, the 2024 Generative AI framework and AI Verify, all voluntary, practical and disproportionately influential across Asia. Available in Aicura on the Enterprise tier.
Read the explainer→EnterpriseUS state AI laws
The American patchwork, spanning Colorado's AI Act, Texas, Utah, Illinois and New York City employment rules and California's transparency laws, on top of federal agency enforcement. Available in Aicura on the Enterprise tier.
Read the explainer→Cross-walksHow the frameworks relate
Read on their own, the frameworks look like separate obligations. Read together, they share a spine. A discipline-by-discipline map of the overlap between the Privacy Act ADM provisions, the NAIC essential practices, the NSW AIAF, ISO/IEC 42001 and the NIST AI RMF.
Read the explainer→Why only these?
Because these are the ones the product uses. Aicura doesn't list a framework unless the product draws on it, whether that is scanning documents against its rules, pulling content from it for risk assessments or monitoring its issuing body for news. The Australian frameworks are part of every tier's work, and the EU, United Kingdom, Singapore and US state frameworks are available on the Enterprise tier. In Aicura, frameworks are loaded content rather than hardcoded logic, which is what lets the same governance work be read through more than one jurisdiction's lens.
Get started with Aicura.
Sign up and start the work. From your first session, you can catalogue your AI systems, run your privacy policy through Aicura's guidance and put your first risk assessments in place.