Privacy policies need an automated decision-making section by 10 December 2026.
Draft yours free

Generative AI in Australian schools, the rules in 2026
AI Regulation

Education, October 2026

The Australian Framework for Generative AI in Schools, explained

A national framework that is policy rather than law, three state systems that make it binding in different ways, and a university regulator that has stopped merely guiding. Here is the whole picture.

Responsible AI Australia • 6 Oct 2026 • 10 min read

Australian education has no single AI law, which is why the question “are we allowed to use this?” gets a different answer in a Sydney public school, a Melbourne independent college and a Brisbane TAFE. Schools work under a national framework endorsed by every education minister. State departments turn it into binding rules for their own schools. Universities answer to TEQSA for the integrity of their awards. Privacy law and the eSafety Commissioner apply on top of all of it. This guide walks through each layer and what a provider should do about it in 2026.

The national framework. Six principles, no penalties

The Australian Framework for Generative Artificial Intelligence in Schools was released on 1 December 2023 and applies across government, Catholic and independent schools. It is organised around six principles.

  • Teaching and learning. Tools are used to support, not replace, teaching and the development of students' own capabilities.
  • Human and social wellbeing. Use benefits students and does not harm them, including through over-reliance.
  • Transparency. Schools and communities understand when and how tools are used.
  • Fairness. Access and outcomes are equitable and bias is addressed.
  • Accountability. Humans remain responsible for decisions, and tools are tested and monitored.
  • Privacy, security and safety. Student data is protected and tools meet safety expectations.

Education ministers endorsed a review of the framework in June 2025 that found it fit for purpose. No revised framework has been published in 2026. The active work is happening in the AI Taskforce working groups, funded through Education Services Australia, which are developing national product expectations for edtech AI tools. For a vendor selling into schools, those expectations will matter more than the framework text.

The framework is national policy, not legislation. Nothing in it can be breached. What can be breached are the binding state policies built on it, the Privacy Act and the Online Safety Act.

What the states add

New South Wales. One sanctioned tool

NSW public schools use NSWEduChat, a department-owned generative AI tool hosted in the department's own Sydney cloud environment. It reached all staff in Term 4 2024 and students in Years 5 to 12 in Term 4 2025, and all data stays in Australia. Other free generative AI tools are neither endorsed nor recommended for staff, and student use of external AI on department networks stays restricted unless a tool passes the department's Safe AI Ethics Assessment.

Victoria. Consent first

The Department of Education's Generative Artificial Intelligence policy is binding on Victorian government schools. Schools must obtain opt-in consent from a parent or carer before using any generative AI tool that collects personal information beyond a school email address and password. Staff must not upload or generate media depicting students, staff or parents, must not use generative AI to communicate directly with families, and must not use it to judge student achievement or write student reports. Tools assessed as high risk under the Safer Technologies 4 Schools program cannot be used. The independent sector's VINE Generative AI Guidelines followed in April 2026.

Queensland. Corella

Queensland state schools use Corella, a departmental generative AI tool operating inside the department's secure environment with data stored in Australia, available statewide through 2026. Students in Years 7 to 10 can be given access at the principal's discretion once parental consent is received. Practice is anchored to the national framework and QCAA guidance on AI in assessment.

The pattern across the three largest systems is the same: a sovereign, department-controlled tool for everyday use, consent gates for student data, and restrictions on public tools. An independent or Catholic school writing its own policy would do well to copy it.

Universities. TEQSA stops guiding and starts regulating

TEQSA required every registered higher education provider to submit a credible institutional action plan, overseen by appropriate governance, addressing the risk generative AI poses to the integrity of their awards. In May 2025 it announced a shift to a regulatory-led approach from 2026, meaning action plans are now examined as part of the regulator's ordinary oversight rather than collected as sector intelligence. Its assessment reform series reached its third instalment on 24 June 2026, Assuring quality learning in a gen AI-integrated future, which focuses on adaptive capabilities rather than detection.

The enforceable layer remains the Higher Education Standards Framework (Threshold Standards). A provider without a current, governed action plan is now exposed on those standards, not merely out of step with good practice.

Privacy. The rules that apply regardless of sector

The Australian Privacy Principles apply in full to AI tools. Entering a student's personal information into a tool engages the purpose-limitation rules. Information a tool generates or infers about a person, including hallucinated content and deepfakes, counts as a collection that must comply with the Act. The OAIC's best practice is not to enter personal or sensitive information into publicly available chatbots and to clearly identify public-facing AI tools as AI. Private providers with turnover above $3 million are covered, as are all APP entities handling student data.

From 10 December 2026 the automated decision-making disclosure also applies: if a computer program makes or substantially shapes decisions that significantly affect students, such as admissions ranking, scholarship allocation or academic integrity flags, the privacy policy must list the kinds of decisions and the kinds of personal information used. The OAIC's final guidance of 30 September 2026 confirms that a staff member signing off does not remove the duty where the program's output was a material input. The free builder does the drafting. The Children's Online Privacy Code must also be registered by 10 December 2026, with commencement to be announced.

Deepfakes and image misuse

eSafety publishes advisories on AI-generated abuse in schools, including so-called nudify apps, with response steps and a deepfake guide in its Toolkit for Schools. In July 2026 it warned that school photo posts are being harvested for AI misuse, after more than 100 reports in early 2026 of anonymous accounts targeting schools and staff. Sharing non-consensual explicit deepfakes is a criminal offence, platform obligations under eSafety's industry standards carry penalties up to $54.6 million, and on 8 September 2026 the Government released an exposure draft of the Online Safety Amendment (Digital Duty of Care) Bill 2026, which names services that let users generate and share AI material among those owing a duty of care.

For a school the obligations are practical: an incident response plan, a risk-based approach to posting student and staff imagery, and a clear path to eSafety's reporting channels.

What is coming

  • 30 November 2026. The Joint Select Committee on Artificial Intelligence reports. Its terms of reference ask directly whether Australia's education system is adequate for an AI economy.
  • 10 December 2026. Automated decision-making disclosure commences, and the Children's Online Privacy Code must be registered.
  • 1 July 2027. South Australia's Royal Commission into Artificial Intelligence, which commenced on 1 October 2026 under Dr Iain Ross AO, reports. Schools and tertiary education are in its scope.
  • Not education-specific. The Australian Standards for AI, now in consultation until 9 October 2026, target data centres and AI training. They do not impose obligations on schools or universities that deploy AI.

The full list is on our deadlines tracker.

A checklist for schools and providers

  • Map every AI tool against the six principles and document how each one addresses them.
  • Run privacy due diligence before procurement: where data is stored, whether inputs train the model, and which third parties receive it.
  • Prohibit entering student or staff personal information into public tools, and prohibit uploading or generating media depicting students, staff or parents.
  • Get informed opt-in consent from parents and carers where a tool collects personal information beyond a school email and password.
  • Keep humans in the loop on judgements: no AI marking decisions, no AI-written reports, no AI replacing teacher communication with families.
  • Universities: keep a governed generative AI action plan current and align assessment redesign with TEQSA's series.
  • Have a deepfake and image-misuse response plan, and publish the automated decision-making section of the privacy policy before 10 December 2026 if any system makes significant decisions about students.

Edtech vendors selling into this market face the same list from the other side. Independent certification against Australia's AI Ethics Principles is one way to answer a school's procurement questions before they are asked. Enrola, a certified student-recruitment platform, shows how in our case study.

Questions people ask

What is the Australian Framework for Generative AI in Schools?

A national policy framework released on 1 December 2023 that applies to all Australian schools, built on six principles: teaching and learning, human and social wellbeing, transparency, fairness, accountability, and privacy, security and safety. Education ministers endorsed a June 2025 review that found it fit for purpose. It is policy rather than legislation; states and school systems implement it through their own binding rules.

Is AI allowed in Australian schools?

Yes, within each system's rules. NSW public schools use the department-owned NSWEduChat and restrict other tools. Queensland state schools use Corella, with parental consent for students in Years 7 to 10. Victorian government schools must obtain opt-in parental consent before using any generative AI tool that collects personal information beyond a school email and password, and staff may not use AI to judge achievement or write reports. Independent and Catholic schools set their own policies under the national framework.

What does TEQSA require universities to do about generative AI?

TEQSA required every registered higher education provider to submit a credible, governed institutional action plan addressing the risk generative AI poses to award integrity, and from 2026 it examines those plans as part of its regulatory oversight. Its assessment reform series, most recently Assuring quality learning in a gen AI-integrated future (24 June 2026), guides assessment redesign. The enforceable layer is the Threshold Standards.

Can teachers put student work into ChatGPT?

Only if it contains no personal information and the school's policy permits the tool. The OAIC's best practice is not to enter personal or sensitive information into publicly available chatbots. NSW and Queensland direct staff to their department-owned tools instead, and Victoria prohibits uploading media depicting students and requires parental consent for tools that collect student data.

Do the Australian Standards for AI apply to schools?

Not as framed. National Cabinet agreed on 26 August 2026 that the Commonwealth will legislate mandatory standards for large data centres and conditions on AI training in early 2027. The Office of AI's consultation paper, open until 9 October 2026, is infrastructure-focused and does not impose obligations on organisations that deploy AI. Education's rules remain the national framework, TEQSA and state policies.

What should a school do about deepfakes?

Follow eSafety's advisories and its Toolkit for Schools deepfake guide, keep an incident response plan, take a risk-based approach to posting student and staff imagery, and report through eSafety's channels. Sharing non-consensual explicit deepfakes is a criminal offence. An exposure draft of the Online Safety Amendment (Digital Duty of Care) Bill 2026 was released on 8 September 2026.

Go deeper

Sources

  1. Australian Government Department of Education, Australian Framework for Generative Artificial Intelligence in Schools
  2. Education Services Australia, investment to guide generative AI technology in schools
  3. NSW Department of Education, NSWEduChat
  4. Victorian Department of Education, Generative Artificial Intelligence policy
  5. Queensland Department of Education, generative AI in schools
  6. TEQSA, Assuring quality learning in a gen AI-integrated future (24 June 2026, PDF)
  7. TEQSA, gen AI knowledge hub: academic integrity and assessment reform
  8. OAIC, new resources on transparency for use of AI and automated decision-making (30 September 2026)
  9. OAIC, Children's Online Privacy Code
  10. eSafety Commissioner
  11. Parliament of Australia, Joint Select Committee on Artificial Intelligence

This guide is general information, not legal advice. It restates official instruments and regulator guidance as they stood on 6 October 2026. How a rule applies to a particular organisation is a judgement for its own adviser.