Australia replaced ten AI guardrails with six practices. Most coverage lists them. This is what each one actually costs you to do — and which ones organisations quietly fail.
The National AI Centre published Guidance for AI Adoption on 21 October 2025. It streamlined the ten guardrails of the Voluntary AI Safety Standard down to six essential practices. Most of the commentary since has been a list of the six. This is about what they cost you to actually do.
Start with the thing that is most often got wrong.
AI6 is voluntary. It creates no new general duties for organisations using AI. If someone has told you that AI6 compliance is now a legal obligation, check what they are selling.
But voluntary is not the same as optional, for a reason that has nothing to do with AI. Your existing obligations already apply to decisions your AI makes: privacy law, consumer law, anti-discrimination law, directors' duties, and whatever your sector regulator expects. None of those paused while the technology changed. What AI6 gives you is the most defensible available articulation of what reasonable practice looks like. If a decision your system made is ever questioned — by a regulator, a customer, or a court — “we followed the National AI Centre's guidance” is a materially better position than “we hadn't got to that yet.”
That is the real argument for adopting it, and it is a stronger one than compliance theatre.
The practice: name a person, at executive level, accountable for AI governance.
What it costs: this is the cheapest of the six to write down and the most expensive to mean. A name in a policy document is free. A named executive who can actually stop a deployment, who has budget for the testing the other five practices require, and who is measured on it, is a real organisational decision.
Where organisations fail: they assign it to whoever is most enthusiastic about AI rather than whoever can say no. Accountability without a veto is decoration.
The practice: assess impacts before deployment — across privacy, safety, fairness, security and employment — and plan for what you find.
What it costs: real time from people who are not on the project. An impact assessment written by the team that wants to ship is a business case with a different cover.
Where organisations fail: they assess the model and not the system. The harm rarely lives in the model weights. It lives in what happens to the person on the other end of a wrong answer, and in whether anyone will notice.
The practice: put AI risks in the enterprise risk register, with defined thresholds.
What it costs: less than people fear. You already have a risk function and it already has a language. The work is translation — turning “the model may drift” into a risk with an owner, a threshold and a review cadence that your existing process can carry.
Where organisations fail: they build a separate AI risk process beside the real one. It is diligently maintained for two quarters and then quietly abandoned, because nothing in the business depends on it.
The practice: disclose AI use to affected people, and maintain a register of AI systems.
What it costs: the register is genuinely hard, and not for technical reasons. Most organisations of any size cannot currently produce a list of where AI is being used, because adoption happened through individual tools, embedded vendor features and people quietly using what works.
Where organisations fail: the first honest attempt at a register is usually alarming, so it is downgraded to a list of sanctioned projects. That list is not a register. It is a wish.
The practice: test before deployment for accuracy, bias and robustness; monitor continuously after.
What it costs: this is the expensive one. Pre-deployment testing is a project cost you can scope. Continuous monitoring is an operating cost that never ends, and it requires someone to look at the output and be empowered to act.
Where organisations fail: they build the dashboard and never staff the watching. A monitoring system nobody reads is a more expensive way of not knowing.
The practice: keep people responsible for decisions, in the loop or on the loop, with the ability to override.
What it costs: throughput. Genuine human control means sometimes being slower than the system could be, and that cost is real and should be argued about honestly rather than assumed away.
Where organisations fail: they preserve the override button and remove the conditions for using it. If the reviewer sees two hundred cases an hour, has no context beyond the recommendation, and is measured on agreement rate, the human is in the loop on paper and rubber-stamping in practice. This is the most commonly faked of the six.
If you are starting from nothing, do them in this order: name the accountable executive, then build the register. Those two are prerequisites for the rest being real rather than aspirational. You cannot manage risk in systems you cannot enumerate, and you cannot enumerate them without someone whose job it is to care.
The guidance comes in two levels — a foundational set for organisations beginning, and extended practices for those scaling. Start foundational. The most common failure in AI governance is not insufficient rigour; it is a rigorous framework adopted wholesale, applied to nothing in particular, and abandoned.
National AI Centre, Guidance for AI Adoption, 21 October 2025, published by the Department of Industry, Science and Resources. It supersedes and condenses the Voluntary AI Safety Standard, whose ten guardrails remain available as a more granular control catalogue for organisations that want them.