

What privacy and AI governance professionals need to know about Australia’s new agentic AI standard.
Artificial intelligence has been evolving rapidly, but few developments signal a more fundamental shift than the emergence of agentic AI. Unlike conventional AI systems that respond to a single prompt and return a result, agentic AI can plan, reason across multiple steps, use tools, take actions in the real world, and collaborate with other AI agents. And all of this happens usually with minimal human intervention along the way.
That shift from AI as a passive analytical tool (which a lot of us are using like an advanced Google search) to AI as an active, decision-making participant changes everything, particularly from a governance perspective. It raises new questions for AI governance like: Who is accountable where there is a chain of autonomous agents taking an action that ultimately causes harm? How do you audit a decision that emerged from dozens of intermediate reasoning steps? What happens when one agent passes sensitive data to another without any human reviewing that exchange?
These are no longer hypothetical concerns, as agentic AI moves from research labs into ordinary operational environments, including in government. Recognising the real risks of getting agentic AI governance wrong, Australia’s Digital Transformation Agency (DTA) has published an Agentic AI Addendum to its existing AI Technical Standard, giving dedicated guidance for government agencies deploying or exploring these systems. But useful for all organisations going down the agentic AI path, particularly those operating in regulated environments.
This blog posts looks at DTA’s new Agentic AI guidance in more detail.
For those interested in the highlights, the following are the main points for privacy and governance professionals from the new guidance:
The Digital Transformation Agency is the Australian Government’s lead body for digital policy and transformation. Among its responsibilities is the development and maintenance of technical standards that guide how government agencies design, procure, and use technology including AI.
The DTA’s AI Technical Standard provides a lifecycle-based framework covering everything from design and data management through to evaluation, integration, monitoring, and decommissioning. It sits alongside broader obligations including the Australian Government’s Policy for the Responsible Use of AI, the Australian Privacy Principles, the Information Security Manual, and the Protective Security Policy Framework.
The new Agentic AI Addendum extends that existing standard rather than replacing it. All prior requirements continue to apply; the addendum layers on additional criteria specifically tailored to the distinctive risks and characteristics of agentic systems. This approach is sensible: it avoids creating siloed compliance pathways and ensures that agentic AI is assessed through the same foundational lens as other AI, while acknowledging where it genuinely differs.
The addendum defines an agentic AI system as one that perceives its environment, maintains an internal state, reasons across multiple steps, and executes a series of actions independently to achieve predefined objectives. Crucially, these systems operate with varying levels of autonomy and can coordinate with other agents, humans, or external services.
The fundamental operating cycle is described as Perceive, Reason, and Act (PRA): the agent takes in inputs, evaluates them against its goals and constraints, and then executes actions, using APIs, databases, code execution, or other tools, before incorporating feedback and repeating the cycle.
In government and regulated industries, the potential applications of agentic AI systems are significant. These systems can handle high-volume administrative tasks, process complex multi-document queries, coordinate compliance workflows, triage correspondence, or manage procurement processes, all tasks that currently require significant human time and are prone to inconsistency.
The addendum identifies specialised agent types that might work together within a single system: planner agents that decompose goals into tasks; executor agents that carry out permitted actions; researcher agents that retrieve and synthesise information; supervisor agents that monitor progress and trigger rollbacks; and monitoring agents that track anomalies, costs, and failures in real time.
The very features that make agentic AI powerful also make it risky to deploy without rigorous governance controls. Key concerns include:
The addendum is structured around eight statements, each tied to specific lifecycle phases and supported by mandatory criteria (what agencies ‘must’ do) and recommended criteria (what they ‘should’ do). The following summarises the key requirements.
The foundational requirement is that every agent must have clearly defined responsibilities and every decision must have a human accountable for it. This is not merely about assigning a responsible officer at the system level, it requires documentation of what each agent is authorised to do, how accountability traces back through agent actions, and how accountability is handled when external systems or third-party agents are involved. Agencies are also required to explain agentic decision-making processes, including capturing reasoning chain outputs where LLMs are used, while ensuring that reasoning logs do not themselves expose personal or sensitive data.
One of the addendum’s more distinctive elements is its focus on memory governance. Agentic systems may retain information across sessions in short-term buffers, long-term databases, or vector stores. The guidance requires agencies to define what may be stored, for how long, under what sovereignty and access controls, and with what purge mechanisms. Conflict resolution rules must be established for contradictory memory states, and mechanisms must exist to remove outdated information to prevent agents from acting on stale or incorrect data.
Before deploying an agentic system, agencies must map the logical sequence of tasks and agents, define each agent’s role and access privileges, identify conditional branches and decision points, and embed self-correction mechanisms including kill switches, automatic rollbacks, and alerting systems. Each agent must be assigned a unique identity with least-privilege access: agents should not be able to self-assign elevated permissions. Fail-safes and feedback loops must be auditable.
Agent-to-agent data exchange must be governed by robust authentication and encryption protocols, with classification and sovereignty controls applied throughout. The guidance requires agencies to define which components are responsible for routing decisions and to ensure that data flows between agents, tools, APIs, and memory stores remain secure, governed, and traceable.
Agencies must evaluate the appropriate agent type and underlying model for each use case, explicitly weighing trade-offs including capability, cost, latency, data residency, FOI exposure, and vendor lock-in risk. Prompt engineering is treated as a governance matter: prompts should be logged, versioned, approved, and capable of rollback. The guidance recommends techniques such as chain-of-thought prompting and ReAct to improve reliability, transparency, and explainability.
Continuous evaluation is described as essential, not optional. Requirements include testing agents against adversarial scenarios, measuring success rates for task completion, evaluating tool selection accuracy, assessing agent-environment interactions, and reviewing how effectively agents manage and retrieve information from memory. Evaluation must be ongoing, not just at initial deployment.
Tools used by agents must be selected based on authorised scope, provided with only necessary permissions, and accessed through approved interfaces with full audit logging. The guidance acknowledges the rapidly evolving landscape of inter-agent communication protocols — including MCP, Agent2Agent (A2A), and Agent Communication Protocol (ACP) — and requires agencies to ensure these are governed for alignment and interoperability.
Continuous monitoring must cover individual agents, inter-agent interactions, tool use, memory integrity, and environmental changes. The guidance recommends establishing a ‘control tower’: a centralised governance layer providing end-to-end observability, real-time dashboards, audit trails, error tracing, and compliance reporting across the entire agentic system.
Whether you are in government or the private sector, the addendum provides a useful blueprint for responsible adoption of agentic AI.
The following steps reflect its key requirements translated into practical action:
Agentic AI has the potential to transform how organisations deliver services and manage complex processes. But that potential will only be realised responsibly if governance keeps pace with capability. The DTA’s addendum is a meaningful step in that direction and for any organisation operating in a regulated environment, it provides a practical and principled framework worth taking seriously.
For more information on how Privacy 108 can assist your organisation with AI governance, privacy impact assessments, or agentic AI readiness, please contact us via the below form.
"*" indicates required fields
"*" indicates required fields
Privacy 108 collects your name and email to send you our newsletter. If you do not provide this information, we will be unable to send it to you. We may use third-party service providers (such as email marketing platforms) to distribute our communications. Some providers may store information overseas, including in the United States. For more information about how we handle your personal information, including how to access or correct it or make a complaint, please see our Privacy Policy or contact us at hello@privacy108.com.au. You can unsubscribe at any time using the link in our emails or by contacting hello@privacy108.com.au.