The Guardrail #1: Brussels starts asking questions, Canberra’s regulators get louder

The Guardrail · Issue 1 · Week ending 8 September 2026

Welcome to the first issue of The Guardrail. Each week we pick the changes in AI law, regulation and governance that matter to Australian boards and executives, explain them in plain English, and say what to do about them.

AUAustralia · Competition and consumer

ACCC puts AI training data on notice

At the Law Council’s Competition and Consumer Workshop, ACCC Chair Gina Cass-Gottlieb said the regulator has identified concerns about personal data being used to train AI models without consumers’ meaningful knowledge or informed consent. She also warned that the growing ties between AI services and the big digital platforms can raise barriers to entry.

Why it matters

If your organisation feeds customer data into an AI tool, or lets a vendor do so, your privacy policy and contracts need to say so in words a customer would understand. The ACCC and the OAIC are now circling the same problem.

Source: ACCC speech · 3 September 2026

EUEuropean Union · Enforcement

The EU AI Office sends its first 30 letters

One month after most AI Act obligations took effect, the European Commission sent formal requests for information to more than 30 AI providers. One strand covers safety and security of the most advanced models; the other covers copyright and transparency, aimed at companies that skipped the Commission’s informal compliance dialogues.

Why it matters

Enforcement is no longer theoretical. Australian companies selling AI enabled products into Europe, or relying on EU hosted models, should confirm which AI Act category their systems fall into and what their vendors have told Brussels.

Source: Agence Europe · 1 to 2 September 2026

USUnited States · Policy

Washington asks the G20 to regulate less

At a G20 innovation meeting in Chapel Hill, North Carolina, the Trump administration launched the Carolina Principles, urging governments not to create new AI oversight bodies or sweeping rules. Elon Musk called Europe’s approach default illegal, and Politico reported Mark Zuckerberg privately argued against a proposed US national AI regulator.

Why it matters

The gap between the US and EU approaches now defines the global landscape. Australia’s model, national standards plus an AI office, sits in between. Expect vendors to lobby hard for the US version here.

Source: Al Jazeera · 1 to 2 September 2026

UKUnited Kingdom · Financial services

FCA: frontier AI finds holes faster than you can fix them

The UK Financial Conduct Authority published a multi firm review on frontier AI and cyber resilience. Its central finding: AI now discovers vulnerabilities faster than firms can fix them, and the value a firm gets depends less on the model and more on governance, clear ownership and human judgement. The FCA expects a named owner for AI in security.

Why it matters

Guidance, not a new rule, but the clearest statement yet from a major regulator on what good AI security governance looks like. APRA regulated entities should read it as a preview.

Source: FCA multi firm review · 2 September 2026

Also this week

SGSingapore will replace its voluntary AI governance model with binding law, including mandatory rules for autonomous AI systems. Details are due from the Ministry of Digital Development and Information in the coming months. Source

KRSouth Korea: a proposed amendment to the AI Basic Act would require explicit disclosure whenever a person is talking to a conversational AI. Source

INIndia’s Supreme Court set aside a customs penalty of more than 425 crore rupees because the order relied on AI hallucinated case law. A warning for anyone using AI to draft decisions. Source

Dates to diarise

10 Dec 2026 Privacy Act: privacy policies must disclose automated decisions that use personal information. OAIC guidance expected this month.
Early 2027 Australian AI standards legislation and AI data centre framework expected in Parliament.

DEWR providers: know where you stand

The free Governance Works RFFR AI check

A short triage of how your organisation’s AI use lines up with the Right Fit for Risk requirements. About ten minutes, and you get a plain English picture of where the gaps are.

Run the free AI check →

Disclaimer: AI is used in the development of this newsletter, and while it is reviewed by a human, you should still independently verify all information before taking action.

The Guardrail is written and sent weekly by Paul Berryman, Governance Works. Subscribe at governanceworks.com.au/the-guardrail · hello@governanceworks.com.au

Governance Works · Liability limited by a scheme approved under Professional Standards Legislation.


.