The Guardrail #3: Privacy draft closes, California orders AI kill switch

The Guardrail · Issue 3 · Week ending 20 September 2026

Canberra spent the week on privacy: the tranche 2 exposure draft consultation closed and the Information Commissioner put a number on how few agencies disclose automated decisions. Overseas, California and Westminster both moved on frontier AI oversight and the shape of AI law.

AUAustralia · Privacy

Tranche 2 submissions close; the Bill is now in Canberra’s hands

The Attorney-General’s Department closed consultation on the exposure draft Privacy Amendment (Personal Data Protection) Bill 2026 on 18 September, after a short window that opened on 31 August. The department says the reforms target emerging risks from artificial intelligence and wearables such as smart glasses. The next step is introduction of the Bill to Parliament.

Why it matters

Do not wait for Royal Assent. Map how your AI systems collect and reuse personal information now, because the exposure draft signals the tests your data pipelines will need to pass.

Source: Attorney-General’s Department, Privacy Reform consultation · 18 September 2026

AUAustralia · Automated decisions

OAIC: only 17 per cent disclose automated decision-making

Information Commissioner Elizabeth Tydd told the Law Council of Australia on 15 September that an OAIC desktop review found only 17 per cent of agencies disclosed their use of automated decision-making. From 10 December 2026 privacy policies must describe substantially automated decisions that significantly affect people’s rights. Tydd said the OAIC will target emerging and latent harms.

Why it matters

Your privacy policy has twelve weeks to catch up. Inventory every decision an algorithm substantially makes about customers or staff, and draft the disclosure before the regulator starts asking.

Source: OAIC, speech to the Law Council of Australia · 15 September 2026

USUnited States · Frontier AI

California orders onsite audits and an AI kill switch

Governor Gavin Newsom signed Executive Order N-9-26 on 18 September, directing the Government Operations Agency to fast-track independent verification of frontier AI labs. It calls for onsite audits by independent verification organisations, an emergency shutdown mechanism for frontier models, and loss-of-control events to count as critical safety incidents. Expert recommendations are due within two months.

Why it matters

Third-party AI assurance is becoming a real market. Ask your frontier model vendors whether they will accept independent audits, and check your incident definitions cover loss of control.

Source: Office of Governor Gavin Newsom · 18 September 2026

UKUnited Kingdom · Legislation

Westminster committee wants an AI Bill and a single regulator

Parliament’s Joint Committee on Human Rights published its report on AI and human rights on 14 September, calling for a risk-based AI Bill, outright bans on subliminal manipulation and inappropriate biometric profiling, due diligence duties across the whole AI supply chain, and a single AI regulator with enforcement powers. The Government has not committed to an AI Bill.

Why it matters

Supply chain due diligence is the recommendation most likely to reach you first, as a customer contract clause. Check your vendor assessments can evidence it before a UK client asks.

Source: UK Parliament, Joint Committee on Human Rights · 14 September 2026

Also this week

USNew York’s Attorney General invited workers to file confidential whistleblower complaints about unsafe AI development, ahead of the RAISE Act commencing 1 January 2027. Source

AUThe Senate elected David Pocock to the Joint Select Committee on AI crossbench seat, 49 votes to 12, after a Greens urgency motion failed. Source

EUThe European AI Board’s ninth meeting on 17 September covered enforcement priorities, market surveillance coordination and a cybersecurity plan for frontier AI. Source

Dates to diarise

20 Oct 2026 Fair Work Commission: new requirements in its AI guidance note apply to parties in proceedings.
26 Oct 2026 Colorado: comments close on draft rules under the Automated Decision-Making Technology and Chatbot Safety Acts.
By 30 Nov 2026 Joint Select Committee on AI: report due. Watch for the recommendations and the government’s response.
2 Dec 2026 EU AI Act: bans on AI-generated intimate imagery and CSAM apply; synthetic content transparency deadline for earlier systems.
10 Dec 2026 Privacy Act: automated decision-making transparency obligations commence. Privacy policies must disclose substantially automated decisions that significantly affect people.

DEWR providers: know where you stand

The free Governance Works RFFR AI check

A short triage of how your organisation’s AI use lines up with the Right Fit for Risk requirements. About ten minutes, and you get a plain English picture of where the gaps are.

Run the free AI check →

Disclaimer: AI is used in the development of this newsletter, and while it is reviewed by a human, you should still independently verify all information before taking action.

The Guardrail is written and sent weekly by Paul Berryman, Governance Works. Subscribe at governanceworks.com.au/the-guardrail · hello@governanceworks.com.au

Governance Works · Liability limited by a scheme approved under Professional Standards Legislation.


.