Most business owners I speak with think AI regulation in Australia is still years away. On the transparency of automated decisions, it is not. There is a hard date, it applies to ordinary businesses, and the clock is already running.
If you use software to help decide who gets a loan, a job interview, an insurance quote, a refund, or a service, this one is for you. The change is quiet, it is not a headline-grabbing AI Act, and that is exactly why it keeps catching people off guard.
In short: from 10 December 2026 the Privacy Act requires businesses to tell people, in their privacy policy, when personal information is used in automated decisions that significantly affect those people, and to explain what kinds of information and decisions are involved.
Let me walk through what this actually means, who it hits, and what you should be doing between now and the deadline. I am not a lawyer and this is general information, not legal advice, so treat it as a practitioner’s map rather than a compliance sign-off.
What is the reform, exactly?
The reform is a new transparency obligation added to Australian Privacy Principle 1, requiring qualifying businesses to disclose their use of automated decision-making in their privacy policy.
It came in through the Privacy and Other Legislation Amendment Act 2024, which passed federal Parliament in late 2024 as the first substantial rewrite of the Privacy Act in years. Most of that Act deals with things like a new statutory tort for serious invasions of privacy and stronger enforcement powers for the regulator. Buried in it is a set of new clauses, APP 1.7 through 1.9, that create the automated decision-making rules.
The important framing: this is a disclosure rule, not a prohibition. Australia has deliberately not gone down the path of the European Union’s AI Act with mandatory risk tiers and bans. You are not being told you cannot automate decisions. You are being told you have to be honest, in public, about the fact that you do.
The detail of how to write these disclosures is being shaped by the Office of the Australian Information Commissioner, which ran a public consultation on transparency in automated decision-making that closed in mid 2026, with formal guidance expected before the rules commence.
When do the new ADM rules start?
The automated decision-making transparency requirements commence on 10 December 2026.
That is not a soft target or a phased rollout. It is a fixed commencement date set in the legislation. As I write this in July 2026, that leaves under five months.
One point that trips people up: the obligation applies to qualifying decisions from that date regardless of history. It does not matter whether you built the system before or after commencement, whether the data was collected years ago, or whether the model was trained last week. If on 10 December 2026 you are running an automated decision that meets the test, the disclosure obligation is live. There is no grandfathering for legacy systems.
What counts as a substantially automated decision?
A decision is caught when a computer program makes it, or does something substantially and directly related to making it, using personal information, and the outcome could reasonably be expected to significantly affect a person’s rights or interests.
Break that into the three parts the OAIC uses, because all three have to be present:
- Software is doing the deciding, or a big part of it. This covers fully automated decisions and decisions where a human signs off but the software did the heavy lifting. A human rubber-stamping a model’s recommendation does not put you in the clear.
- Personal information is used. The program draws on information about the individual to reach the outcome.
- The effect is significant. The decision could reasonably be expected to significantly affect the person’s rights or interests.
That third limb is the one worth sitting with. Based on the way the OAIC and law firms are reading it, “significant” reaches into legal rights, financial interests, employment, access to services, educational outcomes, and reputation. Real examples that keep coming up: an automated system deciding whether to grant a loan, software screening job applicants before a human sees the shortlist, an algorithm setting insurance premiums, a system deciding eligibility for a benefit or a hardship arrangement, and automated marking of an exam.
Here is the trap. The rule is not limited to generative AI or to fancy machine learning. A rules-based spreadsheet or an old scoring engine that decides who gets a service can be just as caught as a large language model. If it is software, it uses personal information, and the outcome matters to the person, assume it is in scope until you have reason to think otherwise.
Who is affected?
Any APP entity that uses automated decisions of this kind is affected, which means most medium and large Australian businesses, plus government agencies and many organisations that trade in personal information.
APP entities are the businesses and agencies already bound by the Australian Privacy Principles. Today that generally means organisations with annual turnover above three million dollars, along with a set of others regardless of size, such as health service providers and businesses that buy or sell personal information.
The honest caveat: the small business exemption that keeps many smaller operators outside the Privacy Act is itself under review and widely expected to shrink or disappear in a later tranche of reform. So if you are a smaller business today and technically exempt, I would still map your automated decisions now. It is much cheaper to know where you stand than to scramble later.
| What is changing | Who it applies to | Deadline | Action required |
|---|---|---|---|
| New privacy policy disclosure for automated decisions (APP 1.7 to 1.9) | APP entities using personal information in significant automated decisions | 10 December 2026 | Update your privacy policy with plain-language ADM disclosures |
| Regulator can issue compliance and infringement notices for non-compliant policies | All APP entities | Enforcement powers already live | Make sure your policy is accurate before the deadline |
| Broader reach if the small business exemption is narrowed | Currently exempt small businesses | Future tranche, not yet law | Map your automated decisions now so you are ready |
What do I need to put in my privacy policy?
You must disclose, in plain language, the kinds of personal information used in automated decisions and the kinds of decisions the software makes on its own or substantially supports.
Drawing on how the new clauses are structured and the analysis from law firms tracking this, your privacy policy needs to cover three things:
- The kinds of personal information your systems use when making these decisions.
- The kinds of decisions made solely by automated systems, where no meaningful human judgement is involved.
- The kinds of decisions substantially supported by automation, where the software performs a function substantially and directly related to the decision but a human is still in the loop.
The skill here is pitching the language at the right altitude. Too vague (“we may use automated tools”) and it fails the transparency purpose. Too specific (“our model uses features X, Y and Z with these weights”) and you will be rewriting the policy every time your team ships an update. Aim for categories a reasonable customer would understand: what you decide, what information feeds it, and roughly how automated it is.
How does this connect to the broader AI rules?
This transparency obligation does not sit on its own. It slots into a wider Australian approach that leans on guidance rather than heavy prescription.
In December 2025 the government released its National AI Plan, a whole-of-government roadmap that pointedly chose voluntary standards and existing regulators over a standalone AI Act. Alongside it sits the Voluntary AI Safety Standard and its follow-on adoption guidance, which set out practical governance practices for organisations using AI: accountability, risk assessment, human oversight, record keeping, and transparency.
Read together, the message is consistent. Australia is regulating AI mostly through existing law, and privacy law is the sharpest tool in the box right now. The Privacy Act’s ADM rule is one of the few pieces of this landscape that carries a firm date and real enforcement teeth. If you treat the voluntary standard as the “how we govern AI well” playbook and the Privacy Act change as the “here is the bit that is mandatory” line, you will have the right mental model. I have written more on stitching these together in my Australian business AI governance framework and on how this maps onto quality systems in AI governance on ISO 9001.
A practical readiness checklist
Here is the sequence I would run with a client between now and December. None of it requires a law degree to start.
- Inventory your automated decisions. List every place software makes or substantially shapes a decision about a person. Include the boring rules-based systems, not just the AI ones.
- Apply the significance test. For each one, ask whether the outcome could reasonably be expected to significantly affect the person’s rights or interests. Flag the ones that clearly do and the ones that are borderline.
- Check the human-in-the-loop reality. Be honest about whether your human review is genuine judgement or a rubber stamp. That determines which disclosure bucket each decision falls into.
- Draft the disclosure language. Write the three categories (information used, solely automated decisions, substantially supported decisions) at a sensible level of generality.
- Update the privacy policy. Fold the disclosures in cleanly rather than bolting on a disconnected AI section.
- Set up a review cadence. Automated decisions change as your tools change. Put a recurring check in place so the policy does not drift out of date.
- Watch for the OAIC guidance. Adjust your wording once the regulator publishes its final guidance, expected before commencement.
If you use general-purpose AI tools inside these decision workflows, it is also worth pressure-testing whether those tools are safe to feed personal information into at all, which I covered in is ChatGPT safe for Australian business.
The key takeaways: the deadline is 10 December 2026, it is a disclosure rule and not a ban, it reaches ordinary businesses and not just AI companies, human oversight does not automatically exempt you, and the cheapest move you can make today is simply to write down where you use automated decisions. Do that inventory now and the rest becomes a manageable drafting job rather than a December panic.
I help Australian organisations get their AI governance and compliance in order without stalling the projects that matter. If you want a second set of eyes on your automated decisions before December, get in touch.