Attending Digital Health Festival? Click here.
The voice of business news for healthcare
Graphic of AI system

Inside MSIA’s voluntary AI code – and what it signals for healthcare decision-makers

×

Share this article

read time 4 min

Key takeaways

  • The MSIA–MTAA Voluntary AI Governance Code sets organisational standards for how AI systems are governed in Australian healthcare.
  • It applies to AI systems used in a health context that are not regulated as medical devices and does not replace Therapeutic Goods Administration requirements.
  • The Code aligns with Australia’s National AI Plan and adopts a risk-calibrated, principles-based approach.
  • For healthcare leaders, it provides clarity about governance expectations and supports confident, responsible AI adoption.

Artificial intelligence is no longer experimental in Australian healthcare. It is embedded in documentation tools, workflow automation, analytics platforms and patient engagement systems. In some settings, it supports diagnostic or decision-making processes. In others, it operates quietly in the background, reducing administrative burden.

But, many clinics, health services and executive teams, feel some trepidation about AI use and its medico-legal implications. The tools may save time but do they increase risk?

The uncertainty is understandable. Some AI tools are regulated as medical devices. Others are not. Some sit squarely within existing Therapeutic Goods Administration frameworks. Others fall outside that specific scheme but remain subject to privacy, competition, consumer and professional regulation.

The MSIA–MTAA Artificial Intelligence Governance Code, released on 1 December 2025, is designed to bring clarity.

For healthcare leaders, the Code is not an additional compliance burden. It is a high-level governance framework that clarifies how AI systems should be managed at an organisational level, particularly those that sit outside formal TGA medical device regulation.

Understanding how different AI tools are regulated

As Emma Hossack, CEO of the Medical Software Industry Association (MSIA), explains, regulatory status hinges on how a tool is used. 

“When AI systems engage directly in diagnostics or clinical decision-making, they become Software as a Medical Device and are subject to TGA oversight. Where they are used for lower-risk functions such as appointment scheduling, documentation or population-level insights, they do not fall under that specific regulatory scheme. 

“That does not mean they operate in a vacuum. They remain subject to privacy law, competition and consumer protections, professional standards and other regulatory safeguards.”

That distinction is critical for decision-makers. Not all AI carries the same regulatory weight. Governance expectations should reflect risk profile and intended use.

Without that clarity, organisations risk either overestimating exposure and delaying adoption unnecessarily or underestimating governance responsibilities.

Profile image of Emma Hossack
Pictured: Emma Hossack, CEO of MSIA

What the voluntary code sets out to achieve

Developed jointly by MSIA and the Medical Technology Association of Australia, the Artificial Intelligence Governance Code sets organisational standards for AI governance in a health context

It outlines expectations across:

  • Accountability and executive oversight
  • Risk management across the AI lifecycle
  • Data governance and cybersecurity
  • Testing, monitoring and human oversight
  • Transparency and contestability
  • Record-keeping and stakeholder engagement

Importantly, the Code applies at the organisational level, not the product level. It does not apply to regulated medical devices, which remain under TGA oversight. 

In Hossack’s view the Code brings clarity and reassurance.

“By reading what is a truly short Code of 5 pages, users can be assured that the software companies have developed and deployed their products in line with the multiple professional codes and guidelines and plethora of laws which govern healthcare technology and data in Australia.”

In practical terms, the Code acts as a trust signal. A vendor that is a signatory or accredited under the Code is committing to defined governance standards that sit alongside existing legal obligations.

Why now?

The Code was released on 1 December 2025, one day before the Australian Government published its National AI Plan.

The National AI Plan adopts a principles-based model and emphasises that regulation should be calibrated to risk. It does not call for sweeping new sector-specific laws. Instead, it encourages industries to develop governance mechanisms that dovetail with existing regulatory frameworks.

In Hossack’s view, the National AI Plan “reflects the MSIA recommendations and endorses the approach taken with our voluntary AI Code.”

Introducing a voluntary industry code at this stage provides early clarity. It reduces the likelihood of fragmented responses and demonstrates that the healthcare technology sector is prepared to articulate its own governance standards.

It also challenges a common narrative that industry-led frameworks are inherently weak.

Hossack argues, “this is not a case of the wolves governing the sheep – and we have an accreditation code which will be administered by a third party when the demand justifies.”

Addressing both risk and opportunity

AI in healthcare is often framed in extremes – either transformational or dangerous.

The reality is more nuanced. Risks around bias, misuse, data protection and patient safety are legitimate. The Code addresses these directly through structured requirements around testing, monitoring, transparency and oversight.

At the same time, healthcare systems are under sustained strain. Workforce shortages, burnout and growing demand are structural challenges.

In Hossack’s opinion, we must recognise that, “for Australians to receive the best care, doctors, pharmacists and other health professionals need to have as much of the administrative burden as possible removed. AI tools can alleviate this burden as well as reduce burn out.”

The Code recognises that well-governed AI is not simply a compliance issue. It is a workforce and sustainability issue. For Hossack, “The biggest risk is not using AI.”

What this means for healthcare leaders

AI is already present in most healthcare environments, often embedded within existing software rather than introduced as a standalone initiative.

The strategic question is no longer whether AI will feature in care delivery or operations. It is whether governance frameworks are deliberate, proportionate and transparent.

The MSIA–MTAA Voluntary AI Governance Code clarifies three essential points:

  • Existing laws and regulators continue to apply
  • Not all AI systems are medical devices — their regulatory pathway depends on their clinical implications
  • Organisational accountability and oversight are central to responsible use.

For boards and executive teams, practical next steps include:

  • Mapping current AI-enabled tools across clinical and operational workflows
  • Clarifying which tools are regulated as medical devices and which are not
  • Assessing whether vendors align with recognised governance standards such as the MSIA–MTAA Code.

The voluntary Code does not introduce new statutory obligations. It articulates expectations that already sit within Australia’s broader regulatory architecture.

In a sector built on trust, the ability to demonstrate structured, risk-calibrated AI governance is increasingly part of executive responsibility. Leaders who take the time to understand how the Code fits within Australia’s regulatory landscape will be able to approach AI adoption with greater clarity, stronger governance and fewer blind spots.

Find out more  

MSIA and the Medical Technology Association of Australia (MTAA), in collaboration with MinterEllison, the lawyers who drafted the Code, are hosting an open educational webinar on the MSIA–MTAA Voluntary AI Governance Code.

The session will explore what the Code does, how it supports both consumers and providers, and where it sits within Australia’s broader healthcare regulatory framework. It is an opportunity for healthcare leaders, boards and digital health founders to hear directly from those behind the framework and ask practical questions about implementation.

Event details:
Tuesday 17 March
12:30pm AEDT
Microsoft Teams

Join here:
https://teams.microsoft.com/meet/43738135609698?p=tPoCPVZ1d4zMoHfteU

Meeting ID: 437 381 356 096 98
Passcode: Jd7x2dY3

 

Sources:

×

Share this article