Hi.
Australian AI Standards

Drafting instructions: template and worked example

Drafting instructions are what a department actually sends the Office of Parliamentary Counsel: prose statements of what a provision must achieve, its mechanics, its defined terms and its edge cases - never draft clauses. This document is both a reusable template (the headings) and a worked example (the content). It covers the two provisions our published analysis identifies as the framework's gaps: the generalisation of the data-licensing chapter beyond creative works, and the automated-determination safeguards. A drafting officer can lift the structure, the content, or both.


Instruction set 1: General consent grants for data

Policy authority. [Template: cite the Cabinet decision or ministerial announcement.] Worked: the Government's announced principle that no company should use Australian works without the creator's control, including of price and value; this instruction extends that consent principle from creative works to data generally, consistent with the Consumer Data Right precedent.

Objective. The Act should provide that use of data belonging to, or about, a person or organisation requires a consent grant; that a grant is a record with mandatory elements; and that a deficient grant is unenforceable by its grantee.

Mechanics the provisions must achieve:

  1. Define consent grant as a record with five elements: grantee, data covered, purpose, period (or review interval), and revocation method. Drafters should resist any formulation in which consent is an event rather than a record; the record is the operative object.
  2. Deficiency asymmetry: absence of any element renders the grant unenforceable by the grantee while remaining enforceable by the grantor. Instructing officers draw attention to this deliberately one-sided consequence - it places the risk of poor drafting on the party who drafts the consent, and is the provision's principal behavioural mechanism.
  3. Purpose limitation: use outside the stated purpose contravenes, notwithstanding any other asserted lawful basis, except where expressly compelled by law - in which case the compelled-access provisions (instruction set 3, not included here) apply.
  4. Detail - what constitutes adequate statement of each element, sectoral phase-in, and record formats - is left to the Standards (legislative instruments), for which a published model exists.

Defined terms to adopt: consent grant, grantor, grantee, mandate, revocation. Definitions with testable referents are available in a published glossary with drafting rationale per term.

Edge cases the drafter should provide for:

  • organisational grantors (the provisions apply equally)
  • data about a person held by a third party (the person is a grantor notwithstanding non-possession)
  • successive grantees (assignment requires a fresh grant)
  • interaction with the Privacy Act's consent concepts (this regime specifies the record; it does not disturb APP consent thresholds)

Worked example for the explanatory memorandum. A person grants an insurer access to their activity data for premium calculation, for two years, revocable via the insurer's portal. Use of the same data for marketing contravenes purpose limitation. If the insurer's consent flow never stated a period, the grant is unenforceable by the insurer - it cannot rely on the data - while the person retains every right the grant gave them.


Instruction set 2: Automated determinations

Policy authority. [Template as above.] Worked: the human-oversight and contestability guardrails (proposals paper, September 2024); the findings of the Royal Commission into the Robodebt Scheme regarding decisions without identifiable authors; the Privacy Act's incoming automated-decision transparency obligations.

Objective. The Act should provide that every determination affecting a person, made with the assistance of an automated system, records an identified author; that a determination with no author is an automated determination attracting mandatory safeguards; and that review of a determination means review by a person with the power to substitute.

Mechanics the provisions must achieve:

  1. Define determination (conclusion adopted by a person or body with standing, from which consequences follow) and author (the identified person or body answerable). The grammatical test the definitions must survive: any compliant decision record can be read aloud with a human subject.
  2. Define inferred result as a model-produced conclusion recorded as such, and require that systems distinguish inferred results from determinations structurally - including that a determination cannot be populated from an inferred result except by an author's act of adoption. Field-level structures demonstrating feasibility exist in commercial deployment and are published.
  3. Automated determinations, where the Act permits them for a decision class at all, carry three safeguards: notice, a statement of what produced the determination, and review with the power to substitute. Drafters should define review such that a reviewer lacking authority, information or time to reach a different conclusion has not conducted one.
  4. A schedule of decision classes for which automated determination is never available regardless of consent - decisions over liberty, the use of force, the exercise of mercy, and the framing of law - with the schedule amendable by instrument above a statutory floor.

Edge cases:

  • bulk determinations (each requires an author; one author may adopt many, and the record shows the adoption, not merely the batch)
  • delegated authors (the delegate is the author, and the instrument of delegation is referenced)
  • machine-assisted triage that never becomes a determination (inferred results with no adoption are permitted and remain visibly inferred)
  • legacy records (authorship derived from ownership metadata suffices for records predating commencement, and only those)

Worked example for the explanatory memorandum. A benefits officer reviews a model-flagged discrepancy. The system shows the flag as an inferred result with its provenance. The officer examines the file and determines no overpayment occurred; the record shows the officer as author, the inferred result as considered and not adopted. Had the system instead raised a debt with no officer's adoption, that is an automated determination, and unless the decision class permits automation, it is invalid - which is the Robodebt fact pattern, made structurally impossible rather than administratively discouraged.


Written with model assistance. Read and edited by a human - though I'm not an editor, so tell me what I've missed: get in touch. The template headings follow standard Commonwealth instructing practice; corrections from serving or former instructing officers are particularly welcome.

Reviewed and checked by the human author: 2026-07-20.


Back to the reader's guide  ·  Home