What does your privacy policy say about AI making decisions for you?
Probably nothing. Australian privacy law is changing that, and the deadline is closer than it feels.
This was written ahead of the OAIC's final guidance on these requirements. The commencement date below and the three-part disclosure requirement are settled law. Some interpretive detail may sharpen once that guidance lands, expected imminently as of publication. We will update this page when it does.
From 10 December 2026, if AI or automated systems help make decisions about your customers or staff, your privacy policy has to say so. Are you ready?
What's actually required
Australian privacy law is being updated, effective 10 December 2026. New Privacy Principles, APP 1.7 to 1.9, added by the Privacy and Other Legislation Amendment Act 2024, will require every APP entity to disclose automated decision-making in their privacy policy wherever it could significantly affect an individual's rights or interests.
That disclosure has three parts.
What data is used
The kinds of personal information used in the automated decision-making.
Fully automated decisions
The categories of decisions made solely by a computer program, with no human involved.
AI-assisted decisions
Categories where a computer program does something substantially and directly related to a human decision. Scoring, prioritising, recommending. Not only fully autonomous decisions.
Commercial-in-confidence system details do not need to be disclosed.
Who this affects
An APP entity is the standard Privacy Act coverage: generally, a business with more than $3,000,000 in annual turnover, plus health, education, and financial-services providers regardless of turnover.
In practice, this reaches further than most businesses expect. It is not only about fully autonomous systems.
- Hiring and recruitment tools that screen or rank candidates
- Credit or insurance scoring
- Customer service triage and routing
- Prioritisation or recommendation engines used to decide who gets contacted, offered, or escalated first
If a system does any of this and personal information is involved, the disclosure question applies, whether or not a human makes the final call.
What "ready" looks like
Getting ready is not a single document. It starts with an honest inventory.
- Where AI or automated systems touch personal information across the business
- For each one, whether the decision is made solely by the system or substantially shaped by it alongside a person
- A drafted disclosure that says so, in the privacy policy, before 10 December 2026
The privacy policy wording is the easy part. The harder requirement sits underneath it: the inventory has to be accurate now, and it has to stay accurate. A new tool someone quietly adopts next quarter, a workflow that starts leaning on AI without anyone formally deciding it should, and the disclosure is wrong the moment that happens, not just out of date. This is not a document you write once and file away.
If you have already built your AI Operating Map, this problem is already solved. Not partly. The AI Tool Register and AI Decision Register it produces are exactly the inventory this disclosure depends on: what data feeds each system, and whether the decision is solely automated or AI-assisted.
That is not a coincidence. The Map's Decision Register is built around this exact question, the same categories the disclosure requires. For an organisation that already has it, the disclosure is a drafting exercise against artefacts that already exist, not a new project.
It also does not stop at the day the disclosure is filed. The AI Framing Sprint installs an AI Champion and a live Tool Register precisely so someone owns catching the next new tool as it appears, which is why the disclosure stays true in March next year, not only in December this year. For an organisation that does not have any of this yet, the disclosure is the least of the problem it reveals.
Frequently asked
Does this apply to a small business?
Generally, no, unless your business is in health, education, or financial services, where the disclosure requirement applies regardless of turnover. Outside those sectors, the standard Privacy Act threshold applies: broadly, businesses with more than $3,000,000 in annual turnover. There are other Privacy Act exceptions that can bring a smaller business into scope, so this is worth checking against your specific situation rather than assuming either way.
What if we're only testing AI internally, not using it on customers or staff yet?
Testing that hasn't yet influenced a real decision about a real person is different from live use. But the moment a pilot starts shaping decisions, even in an assisting role, the disclosure question applies. Map it out while it is still a pilot, so you're not retrofitting a privacy policy the week it goes live.
What happens if we don't comply?
This sits under the Privacy Act, enforced by the OAIC, the same framework that already covers your existing privacy obligations. The specific consequences for a given business depend on the situation and are worth discussing with your own privacy counsel rather than assuming a generic answer here.
How is this different from GDPR?
GDPR's Article 22 gives individuals certain rights around solely automated decisions with significant effects, including a right to request human review. Australia's new rule is, at its core, a transparency obligation: you have to say, in your privacy policy, when and how automated decision-making is used. The two regimes overlap in subject matter but are not the same mechanism, so a GDPR-compliant privacy policy shouldn't be assumed to already satisfy this.
This isn't legal advice. It explains the regulation and what getting ready looks like. It does not tell your specific business whether it is in scope, or what to write in your own privacy policy. Talk to your own privacy counsel for how this applies to you.
Sources: OAIC consultation on ADM transparency guidance, Johnson Winter Slattery, Bird & Bird.
Get ready before the deadline, not after it.
An AI Framing Sprint or Map Guidance engagement builds the exact inventory this disclosure depends on: where AI touches personal information, which decisions are solely automated, and which are AI-assisted. Thirty minutes. No cost. No pitch. We confirm fit, scope, and timing.
Start the conversation →