1. What counts as AI for legal purposes
  2. Who is accountable when your AI gets it wrong
  3. Who owns what AI produces
  4. Privacy obligations when AI meets personal information
  5. Which law applies when AI crosses borders
  6. What regulation is on the way
  7. How an AI-focused lawyer can help
  8. The AI is not a separate legal person

Your business has started using artificial intelligence. Maybe there is a chatbot answering customer questions, a drafting tool producing marketing copy, or a model being trained on records your business already holds. It works well, which is exactly when the legal questions start: who is responsible if the chatbot gives a customer wrong information, who owns the content the tool generates, and what happens if customer data ends up in a model you do not control.

There is no single "AI law" in Australia that answers these questions. Instead, a patchwork of existing laws applies, and the regulators are increasingly looking at how those laws reach artificial intelligence. This article works through the issues in the order a business most often meets them.

Australian legislation does not define artificial intelligence. The Government's stated approach, set out in the National AI Plan, is that the country's "robust existing legal and regulatory frameworks" remain the foundation for dealing with AI-related risks, and that those frameworks are technology-neutral. In practical terms, that means the law does not ask what your system is called. It asks what the system does and who is responsible for it.

The closest thing to a global baseline is the definition in the European Union's AI Act, which came into force on 1 August 2024. It describes an AI system as a machine-based system that infers, from the input it receives, how to generate outputs such as predictions, content, recommendations or decisions. Australian businesses do not have to comply with the Act just because it exists, but the definition matters for two reasons: it is becoming the reference point for regulators worldwide, and the Act itself can reach Australian providers whose systems are placed on the European market (more on that below).

Who is accountable when your AI gets it wrong

The first question most businesses ask is liability: if the AI makes a mistake, who pays? The short answer is that the law looks past the machine to the business that deployed it.

Section 18 of the Australian Consumer Law (ACL), which is Schedule 2 of the Competition and Consumer Act 2010 (Cth), prohibits a person from engaging, in trade or commerce, in conduct that is misleading or deceptive or likely to mislead or deceive. When a chatbot tells a customer your product does something it does not, or an AI-written advertisement overstates what your service can do, the "person" who engaged in that conduct is your business. The ACCC investigates misleading conduct, and civil penalties for a corporation can reach $50 million. There is no "the robot said it, not us" defence.

The same logic runs through the consumer guarantees. Goods supplied to a consumer must be of acceptable quality, meaning they are fit for purpose, free from defects, safe and durable, and services must be provided with due care and skill and be fit for their stated purpose. Whether an AI-enabled product is treated as "goods" or "services" for these purposes affects which guarantees apply, and that characterisation question is one the Treasury examined in its review of AI and the Australian Consumer Law.

That review, finalised in October 2025, concluded that Australians enjoy the same strong consumer protections for AI products and services as they do for traditional ones, and that the ACCC already has the tools it needs to manage AI-related risks. The Government identified only minor opportunities to clarify the rules. The message for business is that the existing consumer law framework is expected to do the work, so compliance effort should go into making sure AI-assisted selling and marketing meets the standards the ACL already sets.

Some of the older speculation about how competition law would stretch to AI has also been settled. One example is third line forcing, where a supplier requires a customer buying one product to also buy another. It used to be prohibited outright, but since the 2017 competition law reforms it is assessed under the exclusive dealing rules in s 47 of the Competition and Consumer Act 2010 (Cth), which only catch conduct that substantially lessens competition. Cartel conduct, by contrast, remains a live concern: if two competitors agree to use the same pricing algorithm to fix prices, the arrangement can still amount to a cartel provision, because the law looks at what the businesses agreed, not the technology they used to carry it out.

There is also a governance dimension. The Government's Guidance for AI Adoption flags that general law, including directors' duties of care and diligence, applies to how a company manages AI risk. An organisation that deploys AI without oversight, testing or a clear accountability structure may find its directors answering for the consequences. And in a contract dispute, an AI failure that means you did not deliver what you promised is simply your breach. None of this creates new law; it is existing law applied to a new tool.

Who owns what AI produces

Intellectual property is where the law's assumptions about human creators collide most directly with the technology.

Copyright protects works that are "original", and Australian courts have held that originality requires a human author. In Acohs Pty Ltd v Ucorp Pty Ltd [2012] FCAFC 16, the Full Federal Court found that computer-generated source code was not a literary work capable of copyright protection because it had not been authored by a human. The practical consequence for your business: content generated entirely by an AI tool may have no copyright protection in Australia at all. Anyone can copy it, and if a competitor does, you may have nothing to enforce. The more human input and direction goes into the final work, the stronger the claim to protection.

Patents have produced the same answer. In Commissioner of Patents v Thaler [2022] FCAFC 62, the Full Federal Court held that an "inventor" under the Patents Act 1990 (Cth) must be a natural person, so the AI system DABUS could not be named as the inventor of the products it generated. A person who uses AI as a tool while conceiving and developing an invention can still be the inventor; the machine cannot take the role itself.

The ownership question is also a contract question. The terms of the AI tools you use will say something about who owns the inputs you feed in and the outputs they produce, and many platforms reserve rights to use content to improve their own models. If you paste client documents or confidential information into a public tool, you may be giving away more than you intend, and you may be breaching obligations to your own clients at the same time.

The Government has not yet changed the Copyright Act 1968 (Cth) for AI. It is consulting through the Copyright and AI Reference Group and has ruled out a text and data mining exception, but for now the human authorship requirement stands.

Privacy obligations when AI meets personal information

If your AI touches personal information, the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs) apply. That covers most businesses with an annual turnover above $3 million, as well as some smaller ones such as health service providers. The APPs that matter most here are APP 11, which requires you to take reasonable steps to secure personal information, and APP 6, which limits how personal information you collected for one purpose can be used or disclosed.

Feeding customer records into a model to train it, or into a chatbot to answer enquiries, raises a real question under APP 6: is that a use or disclosure the individual would reasonably expect? If the model is hosted overseas, APP 8 also requires you to take reasonable steps to ensure the overseas recipient handles the information in accordance with the APPs. The Office of the Australian Information Commissioner (OAIC) published two guidance documents in October 2024, one on developing and training generative AI models and one on using commercially available AI products, and both make clear that existing privacy obligations apply without modification to AI. A privacy impact assessment before you deploy is the practical way to test whether your data flows are defensible.

The notifiable data breach scheme in Part IIIC of the Privacy Act 1988 (Cth) also applies. If there is unauthorised access to, unauthorised disclosure of, or loss of personal information that is likely to result in serious harm to any individual, you must notify the affected individuals and the OAIC. A data breach involving an AI system is assessed the same way as any other: the question is whether the harm threshold is met, not how the breach happened.

Which law applies when AI crosses borders

AI rarely respects borders, and neither do the disputes it generates. Australian courts will often have jurisdiction where conduct affects Australian consumers, and the Competition and Consumer Act 2010 (Cth) has provisions extending its reach to conduct outside Australia by corporations carrying on business here. In practice, if your AI misleads an Australian customer, the ACCC or that customer can usually reach you even if the software runs on servers in another country.

The harder issues are contractual. When you buy an AI system from a foreign vendor, the contract will usually select a governing law and a forum, and those clauses decide where a dispute about the system is heard. Enforcement across borders is difficult and expensive, which is a good reason to review vendor contracts before signing, not after a problem emerges.

Australian businesses selling into Europe should also be aware that the EU AI Act has extra-territorial reach. It applies to providers placing AI systems on the European market and to users whose systems produce outputs used in the EU, regardless of where the provider is based. An Australian software company with European customers may need to work out which of the Act's risk-based obligations apply to it.

What regulation is on the way

Australia is not standing still. The Voluntary AI Safety Standard, published in September 2024, set out ten guardrails for organisations developing, procuring and deploying AI, covering areas such as accountability, testing, transparency and human oversight. In October 2025 it was evolved into the Guidance for AI Adoption, which distils the expectations into six essential practices. The standard is voluntary, but it is the clearest statement available of what regulators and the market expect of businesses using AI, and it is a sensible starting point for a governance policy.

The Government has also consulted on introducing mandatory guardrails for AI in high-risk settings, is establishing an AI Safety Institute to monitor and test AI systems, and has announced it will legislate a Digital Duty of Care placing obligations on digital platforms to prevent online harms. The direction of travel is towards more targeted, AI-specific rules over time. For now, though, the obligations that actually bind your business are the ones that already exist: the ACL, the Privacy Act 1988 (Cth), copyright and patent law, contract law and directors' duties.

How an AI-focused lawyer can help

Working out where AI leaves your business requires judgement calls this article cannot make for you. A lawyer can help with the assessment of whether AI-generated marketing claims would survive an ACCC investigation, whether using customer data to train a model is permitted under the APPs, and whether the outputs of a particular tool are protectable. They can review and negotiate AI vendor contracts, particularly around ownership of inputs and outputs, data use, liability caps and governing law. They can run privacy impact assessments, build data breach response plans, and draft AI governance policies aligned with the Voluntary AI Safety Standard. And when a dispute does arise, whether a misleading conduct claim, a data breach notification or an ownership fight over AI-generated work, they can advise on the strength of the position before it becomes a regulator's case study.

The single most misunderstood element of AI and the law is this: artificial intelligence does not create a new legal person. No matter how autonomous the system seems, the law looks past it to the business that deployed it. That business engages in the conduct, supplies the goods, holds the personal information and owns the resulting liability. The belief that "the AI made the mistake" is a defence is the misstep that costs the most, because it is usually discovered after a penalty notice, a breach notification or a demand letter has already arrived.

The key points to hold onto are these. Australia has no AI-specific statute yet, so your existing obligations under consumer law, privacy law, intellectual property law and directors' duties apply to AI without modification. Your business answers for what its AI says and does. Content generated entirely by AI may have no copyright protection, and a machine cannot be named as an inventor. Privacy obligations bite when personal information is fed into a model. And while voluntary standards and targeted reforms are on the way, the rules that bind you today are the ones you already know.