The Voluntary AI Safety Standard: The 10 Guardrails Australian Startups Should Adopt Before Mandatory AI Rules Land

The Voluntary AI Safety Standard: The 10 Guardrails Australian Startups Should Adopt Before Mandatory AI Rules Land

An AI startup closing its first enterprise deal receives a vendor questionnaire from the customer’s procurement team. Alongside the usual security and privacy questions sits a new section: “Describe how your organisation addresses the guardrails in the Voluntary AI Safety Standard, or the practices in the Guidance for AI Adoption.” The founder has never read either document. The deal doesn’t die — but it stalls for six weeks while the company reverse-engineers a governance story it could have built in a fortnight.

That is how “voluntary” standards actually operate in the Australian market. The government may have stepped back from an AI-specific Act, but the ten guardrails in the Voluntary AI Safety Standard are quietly becoming the shared vocabulary that customers, investors, and regulators use to ask whether your AI product is trustworthy. This article explains what the standard requires, where Australian AI policy has landed after the National AI Plan, and why adopting the guardrails early is one of the cheapest pieces of insurance a startup can buy.

Where the Standard Sits in 2026

The Voluntary AI Safety Standard (VAISS) was published in September 2024 by the National AI Centre, within the Department of Industry, Science and Resources. It sets out ten voluntary guardrails for organisations that develop or deploy AI systems, written to be consistent with international frameworks such as ISO/IEC 42001 and the US NIST AI Risk Management Framework.

Two later developments frame how founders should read it. In October 2025 the National AI Centre released the Guidance for AI Adoption, which replaced the standard as the Australian Government’s current voluntary framework. The Guidance distils the ten guardrails into six essential practices — decide who is accountable, understand impacts and plan accordingly, measure and manage risks, share essential information, test and monitor, and maintain human control — and the National AI Centre has published a mapping from the guardrails to the new practices, so organisations that built VAISS-aligned programs have not wasted the work. Then in December 2025 the National AI Plan confirmed the government would not proceed with a standalone AI Act or the mandatory guardrails for high-risk AI settings proposed in its September 2024 proposals paper, Introducing mandatory guardrails for AI in high-risk settings. Instead, Australia is relying on existing technology-neutral laws, sector regulators, the new Australian AI Safety Institute, and voluntary guidance — with targeted reform reserved for genuine gaps.

So the honest position is this: mandatory AI rules have not landed, and may not land in the form once proposed. But the substance of the guardrails is not going anywhere. They are the material from which the six practices were distilled, the proposed mandatory guardrails for high-risk settings closely mirrored them, and any future targeted rules will almost certainly be built from the same template. Enterprise questionnaires and investor due diligence lists still reference them by name. A startup that builds to the guardrails today — and can describe that program in the Guidance’s six-practice language — is pre-complying with whatever arrives, and satisfying the market in the meantime.

The Ten Guardrails, Translated for Founders

The six practices tell you what the government now expects; the ten guardrails underneath them tell you what to actually build. They group naturally into four clusters.

Governance foundations (guardrails 1–3). Establish and publish an accountability process, including governance arrangements and a regulatory compliance strategy; implement a risk management process to identify and mitigate AI risks; and protect AI systems with data governance measures covering data quality and provenance. For a startup this means a named accountable owner (usually a founder), a short AI policy, a live risk register, and the ability to say where your training and input data came from and what rights you have to use it.

Operational discipline (guardrails 4–5). Test AI models and systems before deployment and monitor them once deployed; and enable human control or intervention so there is meaningful human oversight across the life cycle. Evaluation logs, regression tests for model updates, and defined human-in-the-loop checkpoints for consequential outputs are the concrete artefacts here.

People-facing obligations (guardrails 6–7). Inform end users about AI-enabled decisions, interactions with AI, and AI-generated content; and give people impacted by your AI system a way to challenge its use or outcomes. In practice: disclosure in your product UI and terms, and a working complaints and review channel that a human actually answers.

Ecosystem obligations (guardrails 8–10). Be transparent with other organisations across the AI supply chain about data, models, and systems; keep records that would let a third party assess your compliance; and engage stakeholders with a focus on safety, diversity, inclusion, and fairness. Guardrail 8 cuts both ways for startups — you owe transparency to your enterprise customers, and you are entitled to demand it from your model and data vendors.

Why “Voluntary” Is Doing Less Work Than You Think

Four forces are converting the guardrails into de facto obligations.

Procurement. Enterprise and government buyers increasingly embed guardrail-shaped requirements into vendor onboarding and contract terms. The Commonwealth’s own policy for AI use in government pushes agencies toward suppliers who can evidence responsible-AI practices, and large corporates are following. If your growth plan includes enterprise or public-sector customers, the guardrails are already part of your sales cycle.

Investor due diligence. AI-specific due diligence is now standard in Australian venture rounds. Term sheets don’t cite the VAISS, but the diligence questionnaires behind them ask for exactly what it prescribes: model documentation, data provenance, evaluation results, incident logs, and human oversight design.

Existing law. The guardrails map onto duties that already bind you. Misleading claims about what your AI can do engage the Australian Consumer Law (Schedule 2 to the Competition and Consumer Act 2010 (Cth)). Personal information in training data or model outputs engages the Privacy Act 1988 (Cth) — and from 10 December 2026, reforms to the Australian Privacy Principles will require APP entities to disclose in their privacy policies certain automated decisions that use personal information and significantly affect individuals’ rights or interests. Discriminatory outputs in hiring or lending tools engage federal and state anti-discrimination law. Directors of AI companies also carry duties of care and diligence under the Corporations Act 2001 (Cth) that are hard to discharge without something resembling guardrails 1, 2, and 4.

The next round of reform. The Australian AI Safety Institute is monitoring for gaps, sector regulators are publishing AI-specific guidance, and targeted rules for genuinely high-risk settings remain on the table. When narrow mandatory rules do land, they will land on the guardrail template.

A Two-Week Adoption Plan

For most early-stage companies, meaningful adoption is a fortnight of focused work, not a compliance programme. Name an accountable owner and write a two-page AI policy (guardrail 1). Stand up a simple risk register and run your product through it (guardrail 2). Document your data sources and licences (guardrail 3). Keep your eval results and set a pre-release testing gate (guardrail 4). Map where a human can intervene and make sure at least one point exists for consequential decisions (guardrail 5). Add AI disclosure to your UI and terms (guardrail 6), plus a contact route for challenges (guardrail 7). Prepare a one-page supply-chain summary you can hand to customers, and ask your upstream vendors for theirs (guardrail 8). Store all of it somewhere retrievable (guardrail 9), and sanity-check impacts on the actual users and communities your product touches (guardrail 10). When you describe the finished program to customers and investors, frame it in the Guidance for AI Adoption’s six-practice language — that is the current reference point — and keep the guardrail mapping in your back pocket for questionnaires that still use the older numbering.

The Bottom Line

Australia chose guidance over legislation — for now. That is not a reprieve; it is a head start. The startups that treat the ten guardrails as engineering and governance hygiene will close enterprise deals faster, survive due diligence intact, and be ready if targeted mandatory rules arrive. The ones that wait for a statute to force the issue will discover that their customers got there first.


Viridian Lawyers advises Australian startups and technology companies on AI governance, regulation, and commercial deployment. If you need help implementing the guardrails or responding to AI due diligence, get in touch.

Recent Articles

blog-image
Fixed-Term Employment Contract Limits: How the Fair Work Act's Two-Year Cap Catches Out Australian Startups

A founder with eighteen months of runway offers a new engineer a two-year contract “to be safe”, with an option to extend if the next round lands. It feels prudent — the company only …

blog-image
The Voluntary AI Safety Standard: The 10 Guardrails Australian Startups Should Adopt Before Mandatory AI Rules Land

An AI startup closing its first enterprise deal receives a vendor questionnaire from the customer’s procurement team. Alongside the usual security and privacy questions sits a new section: …

blog-image
Cyber Security Act 2024: What Ransomware Payment Reporting and Limited Use Obligations Mean for Australian Startups

Until 2024, Australia regulated cyber security sideways — through privacy law, critical infrastructure law, directors’ duties and APRA standards. The Cyber Security Act 2024 (Cth) is the first …