NSW AI Assessment Framework
The mandatory framework for NSW government agencies, redesigned in 2024\u20132025 with CSIRO Data61. The most operational risk-classification taxonomy in Australian AI governance.
What it is
The NSW AI Assessment Framework (NSW AIAF) is a structured assessment process that NSW government agencies must apply to any AI system they intend to use. It was introduced in March 2022 as part of the NSW AI Strategy and was redesigned in 2024 and 2025 in collaboration with CSIRO's Data61. The redesigned framework introduced a clearer four-level risk taxonomy, defined "pause conditions" for the highest-risk classification, automatically classified generative AI as elevated risk, and routed high-risk systems through the NSW AI Review Committee for independent review before deployment.
How it's structured
The framework asks an agency to assess any proposed AI system against a set of risk factors covering the system's purpose, the data it uses, the populations it affects, and the consequences of its decisions. The output of the assessment is a risk level from one to four, with progressively heavier governance requirements at each level.
- Level 1: Low risk. Internal-facing systems with limited or no impact on individuals. Standard agency governance applies.
- Level 2: Medium risk. Systems that affect individuals indirectly or in low-stakes ways. Agency-level review and documentation are required.
- Level 3: High risk. Systems that materially affect individuals, particularly in service delivery, eligibility decisions, or compliance contexts. Mandatory review by the NSW AI Review Committee before deployment.
- Level 4: Extreme risk. Systems where the framework's pause conditions apply. Deployment is paused pending escalated review and, where required, ministerial decision.
The pause conditions
The Level 4 pause conditions are designed to stop deployment when an AI system carries enough risk that proceeding without ministerial sight would be unacceptable. They include factors like irreversible harm potential, deployment against vulnerable populations, autonomous decision-making in high-stakes domains, and limited ability to test or audit the system before it goes live. A Level 4 classification is not a permanent block. It's a stop-and-elevate signal.
Generative AI is elevated by default
One of the most significant changes in the 2024\u20132025 redesign was the automatic classification of generative AI as at least elevated risk, regardless of the specific application. The reasoning is that generative AI systems carry irreducible uncertainty about their outputs, and that uncertainty introduces governance risks that the framework treats as material until the agency can demonstrate sufficient mitigations. Agencies wanting to deploy generative AI cannot start at Level 1.
Why it matters beyond NSW
The framework is mandatory only for NSW agencies, but its structure has been picked up well beyond the NSW public sector. Other Australian jurisdictions have used it as a reference point when developing their own assessment processes, and private-sector organisations are increasingly using it as a defensible structure for their own AI risk taxonomies because no equivalent framework exists at the Commonwealth level. The NSW AIAF is, in effect, Australia's most operational risk-classification standard for AI, and its widespread informal adoption reflects that.
Common misreadings
"It only applies to NSW agencies, so we can ignore it." Mandatory only for NSW agencies, but most Australian governance programs end up using its risk taxonomy because it's the most operational one available. Choosing to use a different taxonomy is fine, but you'll spend longer defending it than you would have spent adopting NSW AIAF.
"Level 4 means we can't use the system." Level 4 means the deployment is paused for elevated review, not blocked outright. Many systems initially classified as Level 4 are deployed after the review process, with appropriate mitigations, oversight arrangements and ministerial sight where needed.
"Our risk assessment process already covers this." Possibly, but the NSW AIAF risk factors are calibrated specifically for AI systems and pick up issues that generic risk assessments miss, particularly around data provenance, training data assumptions, and the failure modes of probabilistic systems.
Completing the self-assessment
For the agency-facing walkthrough of the workbook itself, section by section, see how to complete a NSW AIAF self-assessment.
How Aicura supports work against it
Aicura uses the NSW AI Assessment Framework as the primary risk taxonomy across the product. The AI Register captures a Level 1\u20134 risk reading per system, the Risk Assessments module generates a draft NSW AIAF level reading with reasoning as part of every assessment, and the Governance Policies scanner uses NSW AIAF criteria when reviewing AI Risk Assessment Policies. Generative AI systems registered in the product are flagged for elevated-risk treatment in line with the framework's default classification.
A note on this page
This is Aicura's reading of the framework, written to help you understand what the product is wired into. It is not legal advice and it is not the framework itself. Read the primary source. Where Aicura's interpretation differs from yours or from your advisors', go with theirs.
For a more complete picture of what Aicura does and doesn't do for any framework, see the boundaries page.
Get started with Aicura.
Sign up and start the work. From your first session, you can catalogue your AI systems, run your privacy policy through Aicura's guidance and put your first risk assessments in place.