Skip to content
BlogAI

Victorian Government AI Policy: Supplier Guide

Victoria's AI rules reach suppliers through contract. What the VPS AI Assurance Framework and AI procurement guidance ask, and what you must evidence.

Jake Tracey3 August 2026AIGovernmentSecurity

Victorian Government AI Policy: Supplier Guide

Every AI instrument in Victoria is addressed to the agency, not to you. Read them cold and you would conclude supplier obligations are somebody else's problem. In fact they reach you three ways: the guideline that defines you as agency personnel, the assurance framework your buyer is told to complete at planning, and the contract clauses the procurement guidance tells them to write.

The instrument that names you directly

The Administrative Guideline for the safe and responsible use of Generative Artificial Intelligence in the Victorian Public Sector was made by the Secretary of the Department of Premier and Cabinet on 27 November 2024. Its scope clause is the part suppliers miss. It applies to all public service bodies and public entities under the Public Administration Act 2004, and to "all employees, contractors, consultants and volunteers engaged directly or indirectly by in-scope organisations with access to public sector information", collectively Personnel.

If you deliver into a Victorian agency and touch public sector information, you are Personnel. The guideline's statement carries six numbered requirements. Two of them sit with the organisation, on awareness and on monitoring. The other four reach you:

  • Agency-approved generative AI tools are to be used ahead of publicly available ones.
  • Only publicly available information can go into a tool the agency has not approved, and information put into an approved tool must not exceed the protective marking the organisation has determined is appropriate for that tool.
  • Personnel remain responsible and accountable for the accuracy and quality of their work, including advice, decisions and content created.
  • Personnel continue to meet every legislative, regulatory and administrative obligation they already had.

Outside the numbered list the guideline adds a line worth quoting to your delivery team: you should not use generative AI tools to make decisions, undertake assessments, or use them for other administrative actions.

The escalation path matters commercially. Under section 36A(3) of the same Act, an organisation operating inconsistently with the guideline must have its Head give written reasons to the Secretary of DPC. Your uncontrolled chatbot becomes your client's letter to a departmental Secretary.

The VPS AI Assurance Framework, and why you cannot read it

Victoria agreed to the National framework for the assurance of artificial intelligence in government at the Data and Digital Ministers Meeting on 21 June 2024, and the Victorian guidance on generative AI, updated 19 March 2025, noted that the Department of Government Services was building a local tool to apply it. That tool is now in circulation. Navigating AI in procurement on Buying for Victoria, updated 9 July 2026, tells buyers to complete the VPS AI Assurance Framework, include it with the procurement plan and formal approvals, undertake the other assessments it identifies, and review it periodically during delivery, quarterly being the example cadence.

Here is the wrinkle. The framework sits on the VPS Innovation Network AI Community of Practice, behind a VicGov ID login. Suppliers cannot open it. You will only see it refracted through the questions your buyer asks, so infer its shape from the national framework it implements and its five cornerstones of assurance.

CornerstoneWhat it asks of governmentWhat that makes your problem
GovernanceAdapt decision-making structures; designate lines of responsibilityName someone accountable for the AI, not just for the contract
Data governanceDatasets that are authenticated, reliable, accurate and representativeState what you index, where it came from, how it stays current
Risk-based approachCase by case, with reviews at transitions between lifecycle phasesRisk artefacts must survive re-review at every phase gate, not just at bid
StandardsAlign where practical to AS ISO/IEC 42001, 23894 and 38507Know these by number. Alignment is not certification, and say so
ProcurementClear accountabilities, transparency of data, access to information assets, proof of performance testingThe cornerstone written about you. Read it before drafting a response

The procurement cornerstone is the one to read twice. It tells governments to weigh knowledge transfer against lock-in, to check whether standard contractual clauses cover black-box risks, and to assess whether a vendor can support review of a system's outputs after an incident.

What a Victorian buyer will actually ask you

Navigating AI in procurement is the clearest public statement of supplier expectations Victoria has produced. The guidance groups its advice under procurement planning, market engagement and contract management, plus a section on additional AI risks. The stage labels below are ours, mapped to the artefacts you need:

StageWhat the buyer is told to doWhat you should have ready
PlanningComplete the assurance framework; run a privacy impact assessment and a security risk assessment; staff a team covering AI ethics, cyber, data governance, IP, law, privacy and sustainabilityThe inputs their assessments need: data flows, model and region, retention, subprocessors
Market engagementRequest technical information to assess AI risk, and evidence of the supplier's AI governance: internal policies, plans or processesA written governance pack. Not a paragraph in the response. Documents with versions and owners
EvaluationUse the multidisciplinary team to read risk in offers; ensure clauses address identified AI risksDraft clause language you can live with, so the legal round does not add six weeks
ContractA schedule of permitted AI uses; terms preventing new AI without approval; terms requiring an opt-out or disable pathA current inventory of every model and AI component you use, dependencies included
DeliveryManage model drift, bias and hallucination; require continuous monitoring, validation and human oversightAn evaluation harness, monitoring output and a defined human-in-the-loop, reported monthly

Two warnings in that guidance change how you should bid. Buyers are told that AI use can make a supplier appear more capable than they are, and to respond with site visits, presentations and reference checks. They are also warned about false but realistic AI-generated documents such as certificates of compliance or insurance, and told to check public databases or contact the relevant organisation to verify authenticity. Expect checks at source.

The guidance carries a worked example: a supplier delivers a report full of factual errors and fake references, then admits AI hallucinations caused it, having had no approval to use AI and no oversight of it. Your buyer read that before meeting you.

Privacy sits with OVIC, and it names contracted service providers

The Information Privacy Principles in the Privacy and Data Protection Act 2014 apply whenever a Victorian public sector organisation collects personal information to train a model, feeds it into a system, or uses AI to infer things about people. OVIC's Artificial Intelligence, Understanding Privacy Obligations sets the expectations: a privacy impact assessment run early and kept as a living document, a security risk assessment alongside it before implementing a third-party solution, and the rule that an outsourcing organisation stays primarily responsible for consistency with the PDP Act. That is why your buyer's questions get forensic. They carry the liability for your architecture.

Two further OVIC resources, both updated 26 June 2026, do the operational work. Use of publicly available Generative AI tools says organisations should ensure their "staff, contracted service providers and other personnel" do not enter personal information into publicly available tools, and enter only public sector information already publicly known or approved for release. It is explicit that such information is likely to be stored outside Victoria, engaging IPP 9 on transborder data flows. Use of enterprise Generative AI tools expects privacy impact assessments per function or business unit rather than one overarching assessment, caution where a tool would significantly influence or materially assist a decision, human review of outputs, and protective markings on newly generated information assets. Transborder is the question suppliers answer worst, which is why we wrote AI data sovereignty for Australian government.

Security flows down, and there is no certificate to buy

The Victorian Protective Data Security Standards set 12 mandatory requirements across governance, information, personnel, ICT and physical security. Issued under sections 86 and 87 of the PDP Act, they require contracted service providers with direct or indirect access to information to adhere to them.

OVIC's page on contracted service providers sets the shape of your exposure. Providers have no direct obligations under Part 4 of the PDP Act. The engaging agency decides what assurance it requires, and there is no certification process, so you may simply be asked to demonstrate adherence. Stop looking for a badge, map your controls to the 12 standards, and hand the map over on request.

Deploying AI systems securely, published 16 April 2024 by ASD's ACSC with the NSA, CISA, FBI and the Canadian, New Zealand and UK cyber centres, is written for organisations deploying AI systems developed by another entity, exactly your buyer's position. It tells them to require the primary developer to provide a threat model, to consider deployment environment security requirements when writing contracts for AI products or services, to validate and sanitise inputs against prompt injection on exposed APIs, and to collect logs covering inputs, outputs, intermediate states and errors. Those are supplier deliverables. See securing AI assistants in government for the control side.

Recordkeeping is separate again. Buyers are told to keep robust records of their AI use in alignment with the AI Technologies and Recordkeeping Policy from Public Record Office Victoria, which exists to enable explainable AI use and the production of full and accurate records. A system that returns good answers and writes nothing durable fails this. See AI knowledge management in government.

AI procurement in the Australian Government, if you also sell federally

No Commonwealth instrument binds a Victorian agency, but read them anyway: Victoria's framework is unpublished, and these are the most detailed public statements of what a government buyer means by responsible AI. The DTA's Policy for the responsible use of AI in government reached version 2.0 effective 15 December 2025, requiring non-corporate Commonwealth entities to have accountable officials, transparency statements, use case registers, staff training and use case impact assessment. The technical standard for government's use of AI organises its statements and criteria by lifecycle stage, design through decommission, and the Agentic AI addendum, updated 4 June 2026, extends it to greater autonomy. The OAIC's guidance on commercially available AI products is blunt that due diligence "should not amount to a 'set and forget' approach". For retrieval and agentic architectures, see agentic RAG for Australian government.

The evidence pack

Assemble these once and reuse them. Every buyer completing the assurance framework needs the same inputs.

  1. An AI governance policy with a version, an owner and an approval date.
  2. A schedule of permitted AI uses, plus the change-control process for adding to it.
  3. Named models, providers, regions and endpoint scope, including inside dependencies.
  4. What happens to prompts, outputs and logs: retention, access, and whether any of it trains a model.
  5. Your human oversight design: where a person sits, and what they see when they intervene.
  6. Evaluation evidence for accuracy, bias and drift, with the method written down.
  7. What the system records, in what format, and how it reaches the agency.
  8. Subcontractors and subprocessors, by name and jurisdiction.
  9. Incident response, including who the agency calls and how fast you can disable the AI.

Assume the invitation documents will ask whether you intend to use AI to deliver, now or in future. Buyers are told to establish exactly that. Answer completely. Introducing AI into a Victorian government contract without approval is a named risk in published guidance, and buyers are told they may restrict you to a schedule of permitted uses, or prohibit AI outright.

How we approach it

We run our AI workloads on Amazon Bedrock in ap-southeast-2, the Sydney region, which makes the residency answer a region code rather than a discussion. We are a Magnolia Platinum Partner and a Progress reseller through BlueChip Infotech, and we are building the Knowledge Sharing Platform for the Victorian Collaborative Centre for Mental Health and Wellbeing.

Suppliers rarely struggle in Victorian government because their technology is weak. They struggle because they cannot produce a document when a buyer with a half-finished assurance framework asks a reasonable question. The framework is not a hurdle in front of good work. It is a set of questions any competent delivery partner should be able to answer, and answering them well is an advantage.

If you want them answered against a specific architecture rather than in the abstract, that is what our AI for government practice is for.

Written by
Jake Tracey

Managing Director

Engineer-founder. Hands-on across architecture, AI tooling, and client delivery. Built Migration Accelerator and AgentDesk.

LinkedIn →