The Digital Transformation Agency’s Policy for the responsible use of AI in government (v2.0) reaches full effect on 15 December 2026. From that date, every in-scope APS AI use case must first pass a formal AI Impact Assessment against Australia’s AI Ethics Principles, be recorded in an internal register, and be assigned an accountable owner (Digital Transformation Agency, 2026a). The requirement is short to state and long to satisfy. It is also the point at which APS AI readiness stops being a strategic ambition and becomes a binding operational test.
In Brief
- From 15 December 2026, every in-scope APS AI use case must pass a formal Impact Assessment under the DTA policy.
- Assessment capability draws from legal, procurement, ICT, and policy — it belongs to none of them.
- Agencies that discover the gap in November 2026 will not have time to build the capability the policy assumes.
- APRA (April 2026) and ASIC (May 2026) issued matched AI governance expectations — AI assessment capability is now a whole-of-economy expectation.
- The executive who scopes assessment capacity now has options the executive at the deadline does not.
Most agencies are treating the deadline as a policy compliance event. The framing that surfaces in executive discussions is procedural: what document must exist, who must sign it, where it must be registered. That framing is not wrong. It is incomplete — and in a specific way that will only become visible when the deadline arrives.
The AI Impact Assessment is a capability, not a form
The AI Impact Assessment is not a form. It is a capability. The DTA’s supporting guidance is explicit that the assessment must identify, weigh, and manage the risks a proposed AI use case presents against a set of ethical, legal, and operational principles — before deployment, per use case, with an accountable owner named for each (Digital Transformation Agency, 2026b). Discharging that obligation requires people who can read a proposed AI use case at the design layer: what the model does, where its outputs enter a decision, which cohorts are affected, what recourse is available when the output is wrong, and what oversight the agency actually has once the system is in production.
That set of skills does not sit inside any current APS operating model. Legal teams can test whether the use case is lawful. Procurement can test whether the contract is defensible. ICT can test whether the system is deployable. Policy can test whether the use case aligns with government direction. None of those tests is the same as the ethical impact assessment the DTA policy requires. Run in isolation, none of them satisfies it. The competency the policy assumes lives across all four functions and inside none.
This is the assessment capacity gap. What is missing is not guidance, templates, or willingness. What is missing is the specific interdisciplinary capability that reads an AI use case as a system of consequences rather than as a procurement item or a technical deployment. Across the APS, that capability is thin, unevenly distributed, and not currently on any agency’s workforce plan.
The gap hides behind reassuring signals
The condition persists because the surface signals look reassuring. Most agencies can point to an AI policy, an AI ethics statement, a working group, a nominated AI lead, and in many cases a piloted use case with a documented risk register. The visible infrastructure of AI governance exists. What it does not do — yet — is process a new use case end-to-end through a formal impact assessment that would hold up to independent scrutiny from the DTA, the Australian National Audit Office (ANAO), or a parliamentary committee.
The gap is invisible for a further reason: no in-scope use case has been formally assessed and rejected yet. Until the requirement is binding, every proposed use case still moves through the existing pathway — an internal risk conversation, a legal check, a procurement sign-off, an executive endorsement. That pathway produces decisions. It does not produce impact assessments in the form the policy defines. Agencies operating in good faith read the pathway working and infer the capability is present. The inference is understandable and wrong.
Volume surfaces the gap when it is already too late to close it. Once the deadline binds, every in-scope APS AI use case an agency wants to deploy becomes an assessment task. A moderately AI-active agency may have twenty or more in-scope use cases in flight by late 2026 — some new, some already in production and now requiring retrospective assessment. Each requires a full impact assessment, an accountable owner, and a register entry. The question is whether the volume surfaces the capacity gap in October 2026, when there is still time to act, or in the last week of November, when there is not.
An unaddressed gap lets the deadline decide
The immediate consequence is a decision the executive did not know they were making. From 15 December 2026, an in-scope AI use case that has not passed a documented impact assessment cannot be deployed within policy. An agency that arrives at the deadline without the assessment capability faces one of three outcomes. It can pause deployment of AI use cases that had been on track. It can deploy anyway and accept the policy exposure. Or it can procure the assessment capability externally at whatever the market will bear. Only the first outcome is defensible against ANAO review.
The escalating cost is harder to see and more consequential. Once the deadline binds, every subsequent AI decision the agency makes — approving a new use case, extending an existing one, changing a model, changing a data source — passes through the same assessment gate. An agency without internal assessment capability is not solving a single-quarter compliance problem. It is deciding whether to build the capability once, or to purchase it every time a new AI decision arrives. Purchase pricing over three years exceeds the build cost in the first, and each engagement locks the agency into external interpretation of its own risk position.
The regulatory frame has already shifted around the APS. On 30 April 2026, the Australian Prudential Regulation Authority (APRA) issued a formal industry letter calling for a step-change in AI risk management, governance, and assurance across banks, insurers, and superannuation trustees (APRA, 2026). Within days, the Australian Securities and Investments Commission (ASIC) issued a matched letter to licensees, sharpening expectations around AI-related cyber and operational resilience (ASIC, 2026). The APRA AI guidance and the ASIC letter name what the DTA policy now mandates for the APS: a governed inventory of AI use cases, defined ownership across the AI lifecycle, and human accountability for high-risk decisions. AI assessment capability has become a whole-of-economy regulatory expectation. The APS is one instance of a broader pattern, not the exception to it.
The sequencing window closes in December
The most useful move an APS executive can make between now and December 2026 is to assess their own agency’s assessment capacity honestly before the deadline makes the choice for them. Three questions surface the answer. How many in-scope AI use cases does the agency have or expect to have by December? Who inside the agency could, today, run a full impact assessment against the AI Ethics Principles on any one of them? And what does the queue look like when every one of those use cases arrives at that same set of people?
The answer determines the executive’s options. Where assessment capacity is thin and the pipeline is heavy, the choice is between building the capability now, at deliberate cost and pace, or purchasing it later at whatever the market charges once every other agency has arrived at the same realisation. The market for interdisciplinary AI assessment capability was already tight before the DTA policy was mandated. Post-deadline demand is not modelled by any current workforce assumption.
An executive who has read this early can also make a second move that will not be available at the deadline: sequencing. An agency that starts building its assessment capability twelve months out can choose which use cases to formalise first, which owners to appoint first, and which registers to seed first. An agency that starts three months out responds to whatever arrives in its queue in whatever order arrival dictates. One agency is running its AI portfolio. The other is having its portfolio run it.
The difficulty is that the capability sits across four functions that do not, in most agencies, share a workforce plan. Each of legal, procurement, ICT, and policy holds part of the assessment competency. None holds all of it. Building integrated APS AI impact assessment capability requires a governance move — naming where the assessment sits, who convenes it, and who signs it — that most agencies have not yet made. That move is available in an environment where the leadership team can still choose its pace. It is not available inside a compressed queue in the last weeks before the deadline.
The executive who scopes their agency’s AI assessment capacity now is working with a wider set of options than the executive who waits. The deadline decides which position the agency ends up occupying.
What this means for senior leaders
- Treat the 15 December 2026 DTA deadline as a capability question, not a documentation question. The AI Impact Assessment is a competency your agency either has or does not have — no template supplies it.
- Read your agency’s assessment capacity honestly by October 2026. Count in-scope AI use cases, identify the people who could run a full impact assessment today, and manage the queue when volume arrives.
- Assume APS AI readiness is now measured against the same standard as APRA-regulated entities and ASIC licensees. The APRA AI guidance (April 2026) and ASIC letter (May 2026) confirm the whole-of-economy direction of travel.
- Decide once whether to build assessment capability internally or purchase it per engagement. The three-year cost of external purchase exceeds the first-year cost of internal build, and each purchase cedes interpretation of your agency’s risk position.
- Use the twelve months to sequence the AI portfolio deliberately. Agencies that start twelve months out choose which use cases to formalise first. Agencies that start three months out are chosen by their queue.
References
Australian Prudential Regulation Authority. (2026, April 30). APRA calls for a step-change in AI-related risk management and governance.
Australian Securities and Investments Commission. (2026, May 8). ASIC calls for urgent cyber uplift as AI accelerates cyber threats (Media release 26-092MR).
Digital Transformation Agency. (2026a). Policy for the responsible use of AI in government — version 2.0. Australian Government.
Digital Transformation Agency. (2026b). Artificial intelligence impact assessment tool: Introduction. Australian Government.