Guide
Register an AI use case: Australian Government AI policy
The Policy for the responsible use of AI in government applies to all non-corporate Commonwealth entities, with some exceptions. Version 2.0 took effect on 15 December 2025, and every AI use case your agency adopts now starts in the same place: a documented check of whether the policy applies to it, and, if it does, an entry on your agency's internal register.
This guide takes you through that work in a practical order. Each requirement is marked the way the policy words it: must (mandatory), should (expected) or may (optional). It summarises the policy; it does not replace it. Always check the current pages on digital.gov.au, linked under each step.
The deadlines at a glance
| Date | What the policy requires |
|---|---|
| 15 December 2025 | Version 2.0 of the policy takes effect. |
| By 15 December 2026 | Agencies must begin AI use case assessments (within 12 months of the policy taking effect). |
| By 30 April 2027 | For existing use cases not yet assessed, agencies must decide whether each is in scope and apply every relevant policy action. |
| Every 6 months | Agencies must share the register with the DTA, starting from when the register is created. |
Where practicable, agencies should implement the requirements ahead of these deadlines.
Who does what
| Role | What they do |
|---|---|
| Accountable official | Accountable for implementing the policy in the agency; notifies the DTA of high-risk use cases; the DTA's contact point. |
| Accountable use case owner | Makes sure the use case is registered; accountable for its impact assessment, monitoring, re-validation and, if needed, the high-risk actions. |
| Assessing officer | Completes the impact assessment, coordinates it end to end and is the contact point for queries. |
| Approving officer | Has the authority to approve the assessment, including the inherent risk ratings. |
| Expert contributors | Give input and peer review as needed: technical, data, risk, policy or domain experts, internal or external. |
Each impact assessment must have an identified assessing officer and approving officer, and the assessing officer should consult relevant experts, recording who was consulted at question 1.10 of the tool. The accountable use case owner is a separate role from the two assessment roles, although the owner may also serve in one of them.
Step 1: Decide what the use case is
The policy defines an AI use case as “a specific application of an AI system or systems to achieve certain objectives or perform certain tasks”, and uses the OECD's definition of an AI system.
One product can hold several use cases. For a general-purpose tool such as a workplace AI assistant, the policy lets you choose either:
- to treat the product as one complex use case, applying the actions for its highest level of risk; or
- to treat each use case separately, with its own accountable use case owner and each in-scope use case registered on your internal register.
Choose deliberately, and record why.
Source: Appendix B: Definitions
Step 2: Run the policy scope check
Agencies must assess every new AI use case against the policy's in-scope criteria (Appendix C). The assessment must be documented and must take place during the design phase, while requirements are being developed. The DTA's impact assessment tool calls this the pre-assessment: “Before assessing an AI use case, check if it is within the scope of the AI policy.”
At a minimum, a use case is in scope if any of these apply:
- The use, misuse or failure of AI could lead to more than insignificant harm to individuals, communities, organisations, the environment or the collective rights of cultural groups, including First Nations peoples.
- The use of AI will materially influence administrative decisions that affect any of them.
- It is possible the public will directly interact with, or be significantly affected by, the AI or its outputs without human review.
- The AI is designed to use personal or sensitive data (as defined by the Privacy Act 1988) or security classified information (as defined by the Protective Security Policy Framework).
- The DTA has directed that it is an elevated risk AI use case.
Agencies should also carefully consider AI use in these areas. They are not automatically high risk, but are more likely to need careful attention:
- recruitment and other employment-related decision making
- automated decision making of discretionary decisions
- administration of justice and democratic processes
- law enforcement, profiling individuals and border control
- health
- education
- critical infrastructure.
What the policy excludes
- Incidental and lower-risk uses that do not meet the criteria, which may include off-the-shelf software with AI features, such as grammar checks or AI-assisted internet search.
- Early-stage experimentation that does not commit to proceeding or to design decisions that would affect implementation, does not risk harming anyone, and does not introduce or worsen privacy or security risks. If there is a likelihood of proceeding with the use case while experimenting, the policy says you should apply it, along with the AI technical standard.
Agencies may also apply the policy to use cases that do not meet the criteria, for example where factors unique to their operating environment would benefit from an impact assessment and governance actions.
Source: Appendix C: In-scope AI use cases; AI use case impact assessment requirements
Step 3: Name an accountable use case owner
Each in-scope use case must have designated accountability registered with the agency's accountable official as an accountable use case owner. The owner must:
- ensure the use case is registered with the accountable official
- be accountable for applying the impact assessment actions: conducting the AI use case impact assessment, regularly monitoring and evaluating the use case, re-validating the assessment when required, and applying the high-risk actions if the use case has an inherent high-risk rating.
Accountability may be split between roles, for example between business and technology areas, and may change over the use case's lifecycle. The DTA recommends involving your technology area. Owners must be familiar with Australia's AI Ethics Principles, the impact assessment tool and the policy. Owners of high-risk use cases must be able to identify and manage risks and emerging issues. The owner's actions may be delegated to other suitable staff.
Source: Standard for accountability
Step 4: Add it to your internal register
Agencies must keep a register of AI use cases that are in scope of the policy. The Standard for accountability sets the minimum fields:
| Field | What to record |
|---|---|
| Use case name | A clear, specific name for the use case. |
| Agency identifier | Your reference number. |
| Description | What the AI does, its business objective and, if applicable, the underlying product's name. |
| AI technology type | Generative AI, machine learning, natural language processing and/or computer vision. |
| Lifecycle stage | Discover, Operate or Retire. |
| Use of the Technical standard for government's use of artificial intelligence | Not applied, partially applied or fully applied. |
| Domain | As defined in the Standard for AI transparency statements. |
| Usage pattern | As defined in the Standard for AI transparency statements. |
| Accountable use case owner | Name and email address. |
| In-scope criteria met | Which Appendix C criteria the use case met. |
| Inherent risk rating | From the AI use case impact assessment. |
| Residual risk rating | From the AI use case impact assessment. |
| Date the impact assessment was last updated | If applicable. |
Use cases with an inherent high-risk rating must also record the date of last review and the date of next review. Agencies must update the register as required, including risk rating and owner changes.
Source: Standard for accountability
Step 5: Assess it: start at design, finish before deployment
For an in-scope use case, agencies must conduct an AI use case impact assessment. It starts at the design stage and must be finalised, with any agreed risk treatments applied, before the solution is deployed. Agencies may use the Australian Government AI impact assessment tool or an internal process that integrates all of its provisions. An agency that integrates the tool must make sure its process is consistent and delivers the same or a higher risk outcome for inherent and residual risk, and must be able to revise it when the tool is updated.
Threshold assessment: sections 1 to 4. These rate the inherent risks and decide whether a full assessment is needed.
- If all inherent risks are low, the assessing officer may recommend that a full assessment is not required. The approving officer can then endorse concluding the assessment at section 4 and proceeding with the use case, with appropriate plans for monitoring, evaluation and re-validation.
- If any risk is medium or higher, the assessing officer must either:
- complete a full assessment
- amend the scope or function until the threshold assessment results in a low risk rating, or
- decide not to accept the risk and not proceed with the use case.
You may also consider seeking legal advice on whether the proposed use of AI complies with relevant laws and regulations before proceeding to the full assessment. The approving officer must review the recommendation, confirm whether they are satisfied with the supporting analysis, and agree whether a full assessment is necessary.
Full assessment: sections 5 to 12. Completed when the threshold assessment requires it.
If the inherent rating is medium, the agency should consider whether the use case would benefit from being governed through a designated board or a senior executive.
Step 6: If the inherent risk is high
If the inherent rating is high, the agency must:
- report the use case to the accountable official, with the reasons for the rating, the proposed mitigations and the residual risks
- govern the use case through a designated board or a senior executive.
Once the agency decides to deploy it, the agency must also:
- report the use case to the DTA through the accountable official, by emailing ai@dta.gov.au
- establish a system to review the use case at least every 12 months. The review must report to the governing board or senior executive on whether the use case is operating as intended and whether risks are being effectively managed, and must also consider the impact assessment and any revisions to it.
The accountable official must also notify the DTA when an existing use case is re-assessed as high risk, or is no longer high risk. The notification should include the type of AI, its intended application, how the agency arrived at the high-risk rating, and any sensitivities. The DTA states this is not intended to prevent agencies adopting the use case.
Source: AI use case impact assessment requirements; Standard for accountability
Step 7: Keep it current once it's running
- Monitor. When deploying an in-scope use case, agencies must regularly monitor and evaluate it to make sure it is operating as intended and risks are being effectively managed.
- Re-validate. Agencies must re-validate the impact assessment, checking its accuracy and updating it, when there is a material change in the use case's scope, usage or operation. If re-validation changes the assessment, the relevant officer or governance body must re-approve the changes. Agencies should also watch for changes they did not start, such as vendor updates and changes in regulation.
- Share the register. Agencies must share the register with the DTA every 6 months, by emailing ai@dta.gov.au or through a method agreed in advance with the DTA, and should keep it up to date through periodic review.
Source: AI use case impact assessment requirements; Standard for accountability
A worked example (fictional)
A fictional agency, used only to illustrate the steps. A service-delivery agency plans a generative AI assistant that summarises incoming citizen correspondence and suggests a routing category for an officer to confirm.
- Use case: “Correspondence summarisation and routing suggestions”, recorded as one use case.
- Scope check (documented at design): the AI will read personal information from correspondence, which meets criterion 4, so the use case is in scope. The team records every criterion it considered, noting, for example, that criterion 3 is not met because an officer confirms every routing before it takes effect.
- Owner: the director of the correspondence team, with the technology area sharing accountability.
- Register: entered with every minimum field. Technology type: generative AI and natural language processing. Lifecycle stage: Discover.
- Threshold assessment: one inherent risk is rated medium and none is high. The highest rating sets the overall inherent rating, so it is medium. The assessing officer recommends a full assessment and the approving officer agrees. Because the overall rating is medium, the agency considers governance through a senior executive.
- High risk? No, so the Step 6 actions do not apply. The register records the inherent and residual ratings once the assessment is approved.
- After deployment: the team monitors routing accuracy, and re-validates when it expands the assistant to a new correspondence stream.
Frequently asked questions
- Is the policy scope check the same as the threshold assessment?
- No. The policy scope check (the tool's pre-assessment) asks whether the policy applies at all, using Appendix C. The threshold assessment is sections 1 to 4 of the impact assessment, done only for in-scope use cases, and decides whether a full assessment is needed.
- Do out-of-scope use cases go on the register?
- Not required: the register must hold in-scope use cases, and you may add others. The scope check itself must still be documented, and if you adopt an out-of-scope use case you must assess whether it has become in scope whenever its scope, usage or operation changes materially. Meanwhile, comply with existing obligations such as privacy and security.
- Is a general-purpose AI assistant one use case or many?
- Either. The policy lets you treat a general-purpose tool as one complex use case at its highest level of risk, or treat each use case separately, with its own owner and register entry.
- How often does the register go to the DTA?
- Every 6 months, starting from when you create the register, by email to ai@dta.gov.au or a method agreed in advance with the DTA.
- When must existing use cases be assessed?
- By 30 April 2027, agencies must decide whether each existing, not-yet-assessed use case is in scope and apply all relevant policy actions.
How Remit helps
Remit is an AI governance platform built first for Australian Government agencies. It runs the policy scope check using Appendix C's own wording, keeps the register in the Standard for accountability's fields, and takes each use case through the impact assessment and approval. It then links each use case to the systems that run it, so the register can be checked against what is operating. Remit's private preview is coming soon: Register interest in the private preview.
Sources
This guide summarises the Policy for the responsible use of AI in government, published by the Digital Transformation Agency, as at September 2026. It is general information, not legal advice. Always check the current policy on digital.gov.au. Remit is independent of the DTA and not endorsed by it.