From 10 December 2026, many Australian businesses and government agencies will be required to disclose more information about how computer programs use personal information in decision-making. The reforms introduce APP 1.7, 1.8 and 1.9 into the Australian Privacy Principles contained in the Privacy Act 1988.
The changes arrive as Australia moves away from its earlier proposal to impose a separate set of mandatory guardrails on high-risk artificial intelligence. Instead, the Australian Government’s December 2025 National AI Plan emphasises existing, largely technology-neutral laws, supplemented by targeted reforms and voluntary responsible-AI guidance.
Together, these developments produce an important message for Australian businesses: the absence of a general Australian AI Act does not mean that automated systems are unregulated. Privacy, consumer, discrimination, employment, corporate and sector-specific laws can already apply, while the new automated decision-making disclosure obligations will make certain uses of personal information more visible.
What changes on 10 December 2026?
The new provisions apply where an Australian Privacy Principle entity has arranged for a computer program to use personal information to make, or undertake something substantially and directly related to making, a decision that could reasonably be expected to significantly affect an individual’s rights or interests.
Where those conditions are satisfied, the entity must include additional information in its publicly available privacy policy.
Under APP 1.8, the policy must explain:
- the kinds of personal information used in the operation of the relevant computer programs;
- the kinds of decisions made solely through the operation of those programs; and
- the kinds of decisions for which a program performs something substantially and directly related to making the decision.
The provisions apply to decisions made from 10 December 2026 even if the automated arrangement was established earlier or the information was collected before that date. Businesses cannot assume that legacy systems will be grandfathered out of the reforms. The Office of the Australian Information Commissioner’s APP 1 guidance confirms the commencement date and describes the new privacy-policy requirements.
The rules are broader than “AI regulation”
The legislation refers to a “computer program,” not merely artificial intelligence. Consequently, a business may be covered even if its decision-making system does not use generative AI, machine learning or a sophisticated predictive model.
A traditional rules engine may be sufficient. Examples could include software that automatically rejects an application when a score falls below a threshold, changes a customer’s price according to their risk profile, assigns priority to patients or clients, or recommends whether a person should proceed to the next stage of recruitment.
This technology-neutral language is significant. A business should not limit its compliance review to products marketed as AI. It should consider algorithms, scoring tools, workflow software, fraud filters, automated eligibility checks and other programmed processes.
The rules can also extend beyond completely automated decisions. If software performs something “substantially and directly related” to making a significant decision, the process may be captured even where a person provides final approval. A nominal human sign-off may therefore be insufficient to take a system outside the disclosure obligation when the computer-generated score, ranking or recommendation substantially determines the outcome.
Which decisions could significantly affect a person?
The legislation does not create a closed list. Whether a decision could reasonably be expected to have a significant effect will depend on its nature, consequences and context.
The OAIC identifies examples involving admission to a country, eligibility for a housing benefit, rights under a life insurance contract and access to healthcare services. In a commercial setting, potentially relevant decisions could include:
- approving or refusing credit, insurance or finance;
- determining an insurance premium or claim;
- selecting or screening employment candidates;
- suspending a customer’s account because of suspected fraud;
- determining access to housing, healthcare, education or essential services;
- setting an individualised price with substantial financial consequences;
- prioritising people for assistance or investigation; and
- approving, restricting or terminating an important contractual service.
APP 1.9 makes clear that “making a decision” includes refusing or failing to make one. The obligation can also apply whether the outcome benefits or disadvantages the person. An automated approval system is not automatically excluded merely because successful applicants receive a benefit.
Routine decisions with minor consequences are less likely to qualify. For example, automated product recommendations or the ordering of general advertising may not normally significantly affect a person’s rights or interests. However, context matters. Marketing technology that affects access to essential financial products or exploits sensitive personal circumstances may present a different risk.
Not literally every Australian business is covered
The reform is extensive, but it should not be described as applying automatically to every business using automation.
It applies to “APP entities.” Some small businesses with annual turnover of $3 million or less are exempt from the Privacy Act, although important exceptions apply. A smaller organisation may still be covered because of its activities, including where it provides a health service, trades in personal information, is related to a larger covered entity or has opted into Privacy Act coverage.
The automated process must also use personal information about the relevant individual. A system using only genuinely anonymised information may fall outside these particular provisions, although purportedly anonymised data can sometimes still permit identification.
Finally, the decision must be one that could reasonably be expected to significantly affect a person’s rights or interests. Not every automated email, administrative workflow or low-consequence recommendation will meet that threshold.
Australia’s broader AI policy direction
In 2024, the Australian Government consulted on ten proposed mandatory guardrails for AI in high-risk settings. The proposals contemplated requirements involving accountability, risk management, testing, human oversight, transparency and contestability, potentially implemented through existing legislation, framework legislation or a dedicated AI law.
The December 2025 National AI Plan did not proceed with that proposed cross-economy mandatory guardrail framework. Instead, it states that Australia has strong, largely technology-neutral laws and proposes practical, risk-based and targeted responses to emerging harms. The Plan focuses on applying and adapting existing regulatory frameworks, strengthening oversight, addressing particular risks and promoting responsible practices. The Government’s current approach is explained in the National AI Plan.
This does not amount to permanent deregulation of AI. The Government says it will continue assessing the suitability of existing laws and introduce targeted measures where necessary. AI-enabled products and decisions may already be regulated by privacy law, the Australian Consumer Law, anti-discrimination legislation, employment law, corporations law, online safety rules and specialised regimes governing areas such as credit, healthcare and financial services.
The Government has also retained voluntary governance guidance. Its current Guidance for AI Adoption recommends practices including clear accountability, risk management, testing, monitoring, human oversight and supply-chain controls.
What businesses should do now
Updating a privacy policy should be the final step, not the beginning of compliance. An organisation cannot accurately describe its automated decisions unless it first knows what systems it operates.
Businesses should create an inventory of programs that process personal information and contribute to decisions about individuals. This review should include systems operated by external vendors, software embedded in customer platforms and tools introduced informally by individual departments.
For each system, the business should record:
- its purpose and responsible business owner;
- the personal information it uses or generates;
- the decisions or recommendations it produces;
- how influential its output is;
- whether a human genuinely reviews the result;
- the possible effects on individuals;
- the vendor and contractual arrangements;
- testing, monitoring and error-correction procedures; and
- available review or complaint mechanisms.
Particular attention should be given to recruitment, credit, insurance, fraud prevention, pricing, healthcare, customer eligibility and service-access systems.
Businesses should also examine vendor contracts. An organisation may have “arranged for” a computer program to perform relevant work even where a third-party supplier hosts or operates it. The business may need sufficient contractual rights to understand the program’s operation, identify the categories of information used, investigate errors and keep its disclosures accurate.
Transparency is only the starting point
The new provisions primarily create a privacy-policy transparency obligation. They do not, by themselves, establish a general right to demand human review or a detailed explanation of every automated result. Nevertheless, disclosure can make automated practices easier for customers, regulators, employees and advocacy groups to scrutinise.
A privacy policy that reveals significant automated decision-making may prompt questions about accuracy, bias, necessity, security and fairness. Misleading descriptions could also create consumer-law and reputational risks.
The practical effect of APP 1.7–1.9 will therefore extend beyond adding several paragraphs to a website. The reforms give organisations a reason to identify automated systems that may previously have been invisible to legal, privacy and governance teams.
Australian businesses have until 10 December 2026 to prepare. The strongest approach is to treat the new requirements as part of a broader automated decision-governance program: identify the systems, understand their consequences, document accountability, test for errors and unfair outcomes, and communicate their use clearly.

Leave a Reply