December 2026: the Commonwealth AI use-case register and impact assessment, and how MeshGov and AIG Sentinel prepare for it
Version 2.0 of the Policy for the responsible use of AI in government took effect on 15 December 2025. Its first new mandatory requirement fell due on 15 June 2026, and, as the DTA put it in January, "all remaining requirements" come into effect in December 2026. That is ten weeks away.
The policy applies to all non-corporate Commonwealth entities, with carve-outs for the defence portfolio and the national intelligence community; corporate Commonwealth entities are encouraged to apply it.
What the policy requires, and when
Agency-level accountability came first. Agencies "must designate accountable official(s) to take accountability for implementing this policy", and must publish an AI transparency statement, reviewed "annually or sooner", notifying the DTA when it changes. The strategic position on AI adoption was due "within 6 months of this policy taking effect", which is the June 2026 date.
The twelve-month requirements are the ones that matter now. Agencies "must designate an accountable use case owner for each in-scope AI use case within 12 months of this policy taking effect", and "must create a register of in-scope AI use cases" in the same period, then share that register with the DTA every six months. In the same window they must operationalise responsible AI and implement mandatory training for all staff.
The AI impact assessment is the substantive new obligation. For every in-scope use case, agencies "must conduct an AI use case impact assessment", commenced at design and finalised before deployment, using the DTA's AI impact assessment tool or an internal process that integrates all of its provisions and delivers the same or a higher risk outcome. The tool's guidance states that agencies "are required to implement the AI impact assessment requirement for in-scope use cases by 15 December 2026". Existing use cases not yet assessed must be brought into scope "by 30 April 2027". A high-risk rating must be reported to the accountable official, governed through a designated board or senior executive, reported to the DTA, and reviewed at least every 12 months.
On procurement, the policy's position is a recommendation rather than a mandate: it is "strongly recommended that agencies refer to the Guidance on AI procurement in government".
What the products produce
AIG Sentinel holds the register the policy asks for, with an accountable use case owner against every entry, the inherent and residual risk ratings, and the date of the last change, which is what the six-monthly share to the DTA needs. The assessment itself is captured as evidence on a tamper-evident chain: who assessed, who approved, what treatments were agreed and when they were closed, and the twelve-month review for high-risk cases scheduled from the deployment date. The NSW AIAF is the framework pack built today; the Commonwealth tool's twelve sections are mapped next, and until that pack ships the completed assessment is attached to the register entry as a document and the chain records it. Aligned, not certified.
MeshGov takes the register one step further, because the policy's transparency statement and accountability requirements are generated from it rather than written beside it. On app.meshgov.com two public pages already exist: "How we use AI", a versioned AI transparency statement generated from the AI register and republished when the register changes, and "Accountability", which names the accountable roles behind each service. When a use case is added, re-rated or retired in the register, the statement changes with it.
A plain statement of status: MeshGov's twenty-one services run as demonstrations today, and the transparency and accountability pages are generated from demonstration data until a real deployment replaces it.
See AIG Sentinel and MeshGov, or contact us to see the register and the generated statement side by side.
Sources
- Policy for the responsible use of AI in government, Version 2.0 (Implementation; Strategy and oversight; Preparedness and operations; AI use case impact assessment). Digital Transformation Agency, Australian Government. Effective 15 December 2025, last updated 1 December 2025. digital.gov.au
- AI Policy Update: Strengthening responsible use across government. Digital Transformation Agency. 12 January 2026. dta.gov.au
- AI impact assessment tool and Introduction. Digital Transformation Agency. Last updated 1 December 2025. digital.gov.au
- MeshGov AI transparency statement and Accountability pages. Arrochar Labs. Accessed 5 October 2026. app.meshgov.com/ai-transparency, app.meshgov.com/accountability
See what our products can do for you.
Tell us which product you're interested in and we'll walk you through it against your own use cases.
A demo, not a pitch
We show the product end to end against your own use cases - no account managers, no pressure. You decide in your own time.
Fast to value
AIG Sentinel is live in 24 hours. See governed, audit-ready AI without a long procurement cycle.