DTA Australian Government AI guidance
The Digital Transformation Agency's policy and guidance for responsible use of AI across the Australian Government, covering accountable officials, transparency statements and expectations that reach vendors through procurement.
What it is
The Digital Transformation Agency (DTA) leads whole-of-government policy on AI use in the Australian Public Service. The anchor is the Policy for the responsible use of AI in government, which took effect on 1 September 2024 and binds non-corporate Commonwealth entities, supported by standards and guidance the DTA has continued to develop since. The policy's design principle is enable, engage and evolve, meaning adopt AI for public benefit, do it transparently and adjust the settings as the technology and the risks move.
What it asks of agencies
- Accountable officials. Each covered agency designates accountability for its AI use, so responsibility for the technology has a name rather than a committee.
- AI transparency statements. Agencies publish a statement of how they use AI and how they govern it, and keep it current. The statement presumes the agency knows where AI is in use, which makes an internal inventory the unstated prerequisite.
- Risk-based adoption. The guidance steers agencies to assess AI against its potential impact, with higher-stakes deployments carrying heavier assessment, human oversight and monitoring expectations.
- Staff capability. Training and awareness for people using AI in their work, so the governance is not a document nobody using the tools has read.
Why it reaches beyond the Commonwealth
The policy directly binds Commonwealth entities, and its practical reach is wider. Vendors selling AI-enabled products and services into government are increasingly asked, through procurement, to demonstrate governance consistent with the government's own expectations. State and territory governments read the DTA's work alongside their own frameworks, with NSW's AI Assessment Framework the most developed of those. And for the private sector, the DTA's documents are the clearest available signal of what the Australian Government considers responsible AI use to look like in operation, which is worth knowing before a regulator or a government customer asks.
Common misreadings
"This only matters if we're a Commonwealth agency." Directly, yes, the policy binds non-corporate Commonwealth entities. Practically, the DTA's expectations flow outward through procurement. Vendors selling AI into government are asked to show governance consistent with the policy, and state governments and regulated sectors read the same documents as a signal of what good looks like.
"Publishing a transparency statement is the whole job." The statement is the visible artefact. Behind it the policy expects an accountable official, awareness of where AI is in use, training and an approach to risk. A statement without the inventory and accountability underneath it is a claim waiting to be tested.
"The guidance is settled, so we can set and forget." Australian government AI guidance has been revised repeatedly and the National AI Plan signalled more to come. Treating any version as final is how an agency ends up attesting against a superseded document.
How Aicura supports work against it
The DTA guidance is one of the frameworks loaded into Aicura as framework content. The AI Register provides the inventory a transparency statement rests on, with each system and agent carrying its owner, so the accountable official question has a current answer. Risk and impact assessments carry the risk-based adoption work, governance policy reviews draw on the guidance as a source and the record of all of it lands in the Evidence Vault, so an agency or a vendor can show its position rather than assert it.
A note on this page
This is Aicura's reading of the framework, written to help you understand what the product is wired into. It is not legal advice and it is not the framework itself. Read the primary source. Where Aicura's interpretation differs from yours or from your advisors', go with theirs.
For a more complete picture of what Aicura does and doesn't do for any framework, see the boundaries page.
Get started with Aicura.
Sign up and start the work. From your first session, you can catalogue your AI systems, run your privacy policy through Aicura's guidance and put your first risk assessments in place.