INSIGHT · AI GOVERNANCE & COMPLIANCE

Six essential practices.
Each one asks you to keep a record.

The National AI Centre's Guidance for AI Adoption, published on 21 October 2025, sets out six essential practices: decide who is accountable, understand impacts and plan accordingly, measure and manage risks, share essential information, test and monitor, and maintain human control. The Department describes it as "guidance for industry". Its Foundations version tells organisations to "Keep clear records of the actions you take under each practice." For a residential builder using AI to draft quotes, read documents or sort email, six principles become six kinds of record.

Two people reviewing printed documents marked up with a red pen

Analysed 28 September 2026 · Guidance for AI Adoption dated October 2025 in both versions, and 21 October 2025 by the Department of Industry, Science and Resources · downloadable PDFs listed as published 5 May 2026 · AI policy, AI register and screening templates listed as published 22 April 2026 · all pages read 28 September 2026.

Key takeaways

  • It is guidance, and it says what it is for: The implementation guidance describes itself as "the core guidance for the responsible adoption of AI across Australia's economy". It evolves the Voluntary AI Safety Standard, condensing 10 guardrails into 6 essential practices. The pages we read attach no penalty or obligation of their own; existing laws continue to apply to AI use regardless.
  • Two versions, the same six practices: Foundations is for teams "starting to use AI" or "using AI in low-risk ways". The implementation guidance is for teams that "build or customise AI systems" or "manage higher-risk use cases". A builder using off-the-shelf tools to draft and sort is the reader Foundations describes.
  • The record is part of the instruction: The Foundations PDF says: "You should document every activity in these essential practices that you carry out." Each practice's getting-started actions produce something that can be written down: a named owner, a policy, a screening outcome, a register row, a test note, an override point.
  • Governance attaches to a use, not a product: "The same AI tool can create different risks depending on how you use it." One tool that drafts a quote and also sorts the inbox is, on the guidance's own logic, two uses to screen and record.
  • We would start with the register, one row per use: Our system-design recommendation, not a statement of what the guidance requires: record each AI use with its accountable person, its screening answers, where a person confirms the output, and its test and review dates.

What the guidance is,
and what it says it is for

The Guidance for AI Adoption is published by the National AI Centre (NAIC), part of the Department of Industry, Science and Resources. The Department's Voluntary AI Safety Standard page states: "On 21 October 2025, we published the Guidance for AI Adoption, which outlines 6 essential practices for safe and responsible AI governance." Both PDF versions are dated October 2025.

The NAIC's own "AI and Australian law" page lists general laws that may apply to AI harms, including privacy, consumer, negligence and work health and safety law. Following the guidance does not establish that any of them is met.

  • An update, not a new regime: The Foundations PDF calls it "the first update to Australia's Voluntary AI Safety Standard (VAISS), launched in 2024", and lists three changes: "condensed 10 guardrails into 6 essential practices", "removed redundant language" and "expanded our audience to developers as well as deployers".
  • Guidance for industry: The implementation guidance opens: "Best-practice industry guidance plays an important role in building the confidence and capability of Australian workers and organisations to adopt and use AI". The National AI Plan (2 December 2025) says the government will "explore practical ways to support responsible deployment, including through voluntary measures and shared guidance".
  • It does not stand in for other frameworks: "This guidance does not replace your other essential governance frameworks such as those for data, privacy, and cybersecurity." The six practices "focus on governance matters specific to AI and its unique characteristics".
  • Proportionate by design: "You don't need to do everything at once. Adapt each practice to fit your organisation's size, use cases and risk profile."

Six practices,
and the record each one leaves

The middle column quotes the Foundations version's "getting started" actions. The right-hand column is our reading of what each action leaves behind if it is actually done.

PracticeGetting started, as publishedThe record it leaves
1. Decide who is accountable"Assign a senior leader as the overall AI governance owner" and "Create an AI policy"A named owner, and a written policy saying what AI may and may not be used for
2. Understand impacts and plan accordingly"Carry out a stakeholder impact assessment" and "Create contestability channels"Who each use could affect, and how a person raises a problem with an AI output
3. Measure and manage risks"Create a risk screening process to identify and flag AI systems and use cases that pose unacceptable risk or require additional governance attention"A screening outcome for each use, with the answers behind it
4. Share essential information"Create and maintain an AI register" and "Disclose your use of AI"A register row per system and use, and the words used to tell people AI was involved
5. Test and monitor"Ask for proof", "Test before you deploy a system" and "Monitor your system after you deploy it"Supplier test evidence, an acceptance test note, and a monitoring log
6. Maintain human control"Ensure meaningful human oversight" and "Build in human override points"Where a person reviews, and how the use is paused, overridden, rolled back or shut down

What the register template
actually asks for

The NAIC's AI register template (spreadsheet version, listed as published 22 April 2026) has twelve columns: Name and version; Owner; Status; Source; Purpose/business goals; Intended use case(s); Known limitations and prohibited use; foreseeable misuse; Data sources and type; Registered date; Screening outcome; and Key stakeholders affected. Its instructions say to "Add fields that you need for compliance or other reasons" and that anyone procuring or managing a new AI system "should log it on the AI register once the AI system or tool is approved".

The template's example row names a specific commercial model; we do not reproduce it. One column heading reads "Any forseeable misuse" in the published template; we give it above as foreseeable misuse and quote the other eleven exactly.

  • Embedded AI counts: Foundations says the register "should also cover AI that might be embedded in other systems, like human resources and customer engagement tools". The register page adds "AI features embedded in common software packages".
  • The implementation list is longer: Practice 4.1.1 of the implementation guidance adds, among others, "acceptance criteria and test results", "any impact and risk assessments and outcomes" and "dates of review".
  • A register is not the whole job: "An AI register is about transparency and documentation. It should not replace more in-depth governance activities such as impact assessments and risk management."

Four ordinary uses
in a residential construction business

The guidance contains no residential construction examples. Its one construction reference we found is an autonomy example in the implementation guidance PDF: "A construction site deploys autonomous forklifts to move pallets in a warehouse." The uses below are the ones a builder is more likely to have, described in general terms. The third column points to questions from the NAIC's seven-question screening tool worth answering first; it is not a screening result.

The screening tool states: "Answering 'yes' to any question means you should pay careful attention to governance processes around this use case or system." Its web page adds: "There are no scores or automatic outcomes."

AI useWhat it touchesScreening questions worth answering firstWhere a person confirms
Drafting a quote from drawings and specificationsClient plans, supplier prices, marginsQ1 (confidential information as input); Q6 (harm from a wrong decision difficult to contest or reverse, once a figure is sent)An estimator checks and issues the quote
Extracting fields from contracts, specifications or supplier documentsCommercial terms, dates, quantitiesQ1 (confidential information as input)A person confirms each extracted field before it is relied on
Suggesting a programme or crew sequenceTrades' availability, site datesQ3 (acts autonomously, for example executing actions across multiple systems rather than only suggesting); Q6 (harm difficult to reverse)A scheduler accepts or rejects the suggestion
Sorting and drafting replies to inbound emailClient and subcontractor correspondence, personal informationQ1; Q2 (interacts directly with end users with freedom to respond without meaningful human oversight, if replies go out unreviewed)A person reads and sends any reply

Why the record is per use,
not per product

Foundations gives two examples of the same technology carrying different risk. "Using AI to draft marketing emails is different to using it to assess job applications." And a chatbot answering simple questions in business hours, "when it can be monitored by a staff member, is a low-risk use of AI. The risks expand, however, if that chatbot operates 24/7, without human oversight, and answers more complex questions." The construction equivalent is ordinary: an email tool that labels messages is one use; the same tool sending replies to a client is another.

One legislated obligation sits alongside the guidance. The NAIC's "AI and Australian law" page notes privacy law transparency requirements "with specific provisions for some automated decision making to apply from 10 December 2026". We covered what those provisions ask of a privacy policy in a separate reading, linked below; the register described here is the kind of record that reading relies on.

  • Autonomy is the lever the guidance keeps returning to: The implementation guidance's "Level of autonomy" questions ask: "Does the system make decisions without any meaningful human oversight or validation?" A use where an agent drafts and a named person confirms answers that question differently from one where output goes straight out.
  • Human oversight is scaled, not uniform: Practice 6: "This could mean automated monitoring for low-stakes applications, and mandatory human review for high-stakes decisions." Recording which uses sit where is itself the record.
  • Suppliers are part of the record: Practice 1 asks businesses to "Clarify supply chain accountabilities"; practice 5 to "ask the developer or supplier to show proof that it's been properly tested". For a builder buying tools rather than building them, the supplier's evidence, alongside the business's own acceptance check, is the test record it can point to.

What we would put in a system

For each AI use in the business, not each product, we would test for five fields.

Where agents help here is narrow. An agent can read a supplier's product documentation and a short description of the proposed use, and draft a register row: purpose, data sources, intended use, stated limitations. A person answers the screening questions, names the accountable owner and confirms the row. No agent decides whether a use is high-risk, whether disclosure is needed, or whether any law applies to it; those are judgements for the business and its advisers.

FieldWhy it is load-bearing
The use, with the tool's name and versionThe guidance screens uses, not products, and a tool's behaviour can change between versions. A row that says only the product name cannot show which use was assessed.
The accountable person for that useFoundations' next step is to "Make a specific person accountable for every AI system your organisation uses". A role title with no name cannot answer who approved it.
The screening answers, with their dateThe template has a "Screening outcome" column; the answers to the seven questions are what make that outcome explainable later.
Where a person confirms, and what the AI may not doPractice 6 asks for "clear intervention points". The confirmation step, and the outputs that always need it, should be stated rather than assumed.
Test evidence and the next review datePractice 5 asks for testing before deployment and monitoring after it; the implementation list includes "dates of review".

Questions worth asking
of your own business

For a builder's director: who is named as accountable for each AI use, and does the name appear anywhere in writing?

Foundations starts with a senior owner for AI overall and moves to "a specific person accountable for every AI system". If the answer is "whoever set it up", the first practice has not produced its record.

For an estimator: when a drafted quote is changed before it goes out, is the change recorded?

The confirmation step is the human control the guidance describes. A record of what the draft said, what was changed and who issued it is what lets a business show the step happened.

For an office or operations manager: which AI features are already switched on inside software the business uses?

The register is meant to cover "AI that might be embedded in other systems". Features that arrived in a software update are the ones most likely to be missing from any list.

For whoever buys software: did the supplier provide proof of testing, and where is it filed?

"Ask for proof" is a getting-started action in practice 5. For a business that does not build its own tools, the supplier's evidence and the business's own acceptance check are the test record.

For a construction group: is there one register across entities, or one per entity?

The guidance does not prescribe either. What matters for the record is that each use has one owner and one row, so the same tool used differently in two entities is not recorded as a single use.

What this analysis
does and does not show.

Evidence note

What it shows
That the National AI Centre's Guidance for AI Adoption is published as guidance, sets out six essential practices in a Foundations and an implementation version, and asks organisations to keep records of the actions taken under each practice; and how those records map to four ordinary AI uses in a residential construction business.
Key facts quoted
Six essential practices, named as published; first update to the Voluntary AI Safety Standard, condensing 10 guardrails into 6 practices; published 21 October 2025 per the Department; both versions dated October 2025; "Keep clear records of the actions you take under each practice"; AI register template with twelve columns, listed as published 22 April 2026; seven screening questions; privacy provisions for some automated decision making from 10 December 2026, as stated on the NAIC's AI and Australian law page.
  • The mapping of practices to construction uses, and the screening questions suggested for each use, are our reading. The guidance documents we read contain no residential construction examples, and nothing here is a screening result for any real use.
  • None of the primary pages we read states the legal status of the Guidance for AI Adoption itself.
  • The Department dates the guidance 21 October 2025 and both PDFs say October 2025. The guidance web pages show no last-updated date, and the downloadable PDFs are listed as published 5 May 2026.
  • This is federal guidance only. We did not review state or territory AI guidance, sector-specific rules, or any legislation, and we did not re-read the privacy provisions that commence on 10 December 2026.
  • We have no data on how many construction businesses use AI, follow the guidance, or keep an AI register, and we make no claim about what following it costs.
  • Nothing here is legal advice. It does not determine whether any AI use is high-risk, whether any disclosure is required, or whether any law applies.

What to watch next

The statements about the future below are dates and commitments the publishers have made themselves.

  • 10 December 2026: The date the NAIC's "AI and Australian law" page gives for "specific provisions for some automated decision making" under privacy law. Unlike the guidance, those provisions are legislated.
  • The guidance pages themselves: The web pages carry no last-updated date, and the downloadable PDFs are listed as published 5 May 2026. The National AI Plan says the government "will periodically review and update guidance and standards"; a register built on today's practice names should record which version it was built against.

Bring us the AI uses
you already run.

List the places AI already drafts, extracts, suggests or sorts in your business, including features inside software you already pay for. We will show you what a register row for each would contain, who would be named on it, and where a person confirms the output today.

This is general information about published federal guidance. It is not legal advice, it does not determine whether any AI use is high-risk or requires disclosure, and it does not determine whether any law applies. Australia (Commonwealth) only. Pages read 28 September 2026.

Send us your list · AI agents for construction

Sources

Suggested citation: National AI Centre, Guidance for AI Adoption (Foundations and implementation guidance) and associated templates, ai.gov.au, as read 28 September 2026. Six practices, ten guardrails and seven screening questions are as published. Derived figure: the twelve register columns, our count of the published template's column headings.