CSIRO AI6 Essential Practices
Six essential practices for AI governance from the CSIRO National AI Centre's Guidance for AI Adoption. Voluntary, but the functional baseline for Australian AI governance programs.
What it is
The AI6 are six essential practices for AI governance published by the CSIRO National AI Centre (NAIC) in the Guidance for AI Adoption (GfAA) in October 2025. The GfAA was the government's replacement for the ten mandatory AI guardrails proposed in September 2024 and shelved in the National AI Plan of December 2025. The guardrails were meant to be binding. The AI6 are voluntary. But they're referenced widely across Australian government guidance, embedded in procurement frameworks, and treated by regulators as a reasonable baseline for what good AI governance looks like.
The six practices
- Governance and accountability. Clear leadership accountability for AI use, with defined roles and responsibilities and integration of AI governance into existing organisational governance structures rather than as a separate silo.
- Impact assessment. Evaluating the potential impacts of an AI system on individuals and communities before deployment, not after. This is the practice that connects most directly to the Privacy Act's requirements and to NSW AI Assessment Framework expectations.
- Risk management. Identifying, assessing, and mitigating AI-specific risks throughout the lifecycle of a system: design, build, deployment, operation, retirement. Risk management is treated as ongoing, not one-off.
- Transparency. Informing users and affected individuals about AI use. This practice covers both internal transparency (your team knows what systems are in use) and external transparency (the public and affected individuals can find out).
- Testing and monitoring. Pre-deployment verification that the system does what it's supposed to do, and ongoing monitoring of its performance once it's live. Drift, bias and failure modes are assumed to emerge over time.
- Human oversight. Meaningful human control over AI systems, with the ability to intervene, override, or shut down. This is the practice that most directly echoes Robodebt's lessons: automation without human oversight is the failure mode that Australian policy now treats as most important to avoid.
Two versions
The GfAA comes in two forms. Foundations is the lighter version, intended for small and medium enterprises. Implementation Practices is the fuller version, intended for larger organisations with dedicated governance resources. Both cover the same six essential practices but at different levels of expected rigour. Aicura uses both as guidance sources: they feed the rule sets for AI Acceptable Use, AI Risk Assessment and AI Data Governance policy reviews, and they sit inside the curated risk content that drives per-system risk assessments.
Why voluntary frameworks still matter
A voluntary framework that regulators cite in their guidance and procurement officers reference in their tender documents is functionally binding for organisations that need to win government work or demonstrate due diligence. The AI6 occupy that position. They're also the clearest signal Australian policy has given about what "good AI governance" is supposed to look like in practice, so organisations building governance programs use them as the spine regardless of any legal obligation to do so.
Common misreadings
"Voluntary means optional." Technically true, practically false. You can skip the AI6 if you want, but when your next tender asks how you approach AI risk management, or when a regulator asks how you govern AI, the AI6 are the vocabulary of the answer you'll be expected to give.
"We have an AI ethics policy, so we're covered." A policy is not a practice. The AI6 are practices, meaning things your organisation does rather than documents it has. Having a policy about risk management doesn't mean you're doing risk management.
"We need to implement all six at once." The GfAA explicitly doesn't require this. The two-version structure (Foundations and Implementation Practices) exists because organisations should grow into the practices at a pace appropriate to their scale and risk profile.
How Aicura supports work against it
Three connections matter. First, the AI Register directly captures the structured metadata that impact assessments and risk management (practices 2 and 3) require. Second, the Governance Policies scanner uses the AI6 as a guidance source for reviewing your AI Acceptable Use, Risk Assessment, and Data Governance policies. Third, the Template Library generates policies that are structured around the AI6 practices, so even the generated drafts reflect the framework.
A note on this page
This is Aicura's reading of the framework, written to help you understand what the product is wired into. It is not legal advice and it is not the framework itself. Read the primary source. Where Aicura's interpretation differs from yours or from your advisors', go with theirs.
For a more complete picture of what Aicura does and doesn't do for any framework, see the boundaries page.
Get started with Aicura.
Sign up and start the work. From your first session, you can catalogue your AI systems, run your privacy policy through Aicura's guidance and put your first risk assessments in place.