← BlogAI Consultancy

Australia's Privacy Act Now Forces You to Disclose Every AI Decision About a Customer by December 2026

By Aditya JhaAugust 28, 20268 min read

Australia's Privacy Act Now Forces You to Disclose Every AI Decision About a Customer by December 2026

An Australian insurer's legal team signs off on an AI agent that triages incoming claims, routing straightforward ones to auto-approval and flagging complex ones for a human adjuster. Legal's review focuses on the usual: data security, vendor contracts, a line in the privacy policy about 'using technology to process your information.' Nobody flags that from 10 December 2026, that line isn't enough, because a specific new transparency obligation under the Privacy Act 1988 requires the business to name, in its privacy policy, the actual kinds of personal information and the actual kinds of decisions the automated system is making about real customers.

What exactly changes under Australia's Privacy Act on 10 December 2026?

From that date, APP entities, businesses and agencies bound by the Australian Privacy Principles, that use personal information in automated decision-making with the potential to affect a person's rights or interests must disclose this specifically in their privacy policy: the kinds of personal information used, and the kinds of decisions made using automated decision-making. This comes from new provisions, APP 1.7 to 1.9, added by amendments to the Privacy Act 1988 that passed in November 2024, with the transparency obligation itself commencing on a fixed date rather than immediately.

The OAIC's own consultation page on guidance for transparency in automated decision-making confirms the regulator ran a formal consultation through mid-2026 and expects to publish detailed guidance around September 2026, three months before the obligation itself takes effect, which leaves a narrow window between knowing exactly what the regulator expects and having to already comply.

Which AI agents actually count as 'automated decision-making' under the amendment?

  • Fraud detection systems that flag or block a transaction without a human reviewing it first.
  • Client and customer onboarding agents that approve, reject or route an application.
  • Insurance claims triage or assessment tools that determine payout eligibility or route a claim.
  • Patient intake or triage assistants that influence clinical prioritization.
  • Contract review agents that flag or clear terms as part of an approval decision.
  • Customer support agents and personalization or recommendation engines that materially shape what a person is offered.

Does this only apply to AI and machine learning systems?

No, and this is the detail most teams miss. MinterEllison's analysis of the OAIC's consultation notes the amendment applies broadly to computer-based decision-making, which captures rule-based software and deterministic scoring logic just as much as it captures an LLM-based agent. A business can't treat this as an 'AI problem' scoped narrowly to generative AI tools and assume its older rules engines are exempt; if a computer is materially involved in a decision affecting someone's rights or interests, the disclosure obligation is in scope regardless of what kind of system is making the call.

That breadth is exactly why an audit now, mapping every existing automation, not only the newest AI agent, against this checklist matters more than waiting for the OAIC's final guidance to arrive in September.

What does an audit-ready compliance architecture look like before the deadline?

  • Update the privacy policy now to name, in plain language, the categories of personal information used and the categories of decisions made via automated systems, don't wait for the OAIC's final guidance to start the drafting process, since legal review and stakeholder sign-off take longer than the remaining runway suggests.
  • Log the input data, the model or rules-engine version, a confidence score where applicable, and whether a human overrode the automated outcome for every decision in scope, and retain those logs long enough to satisfy a regulator's request well after the fact.
  • Build an actual human-override path into every workflow that makes an in-scope decision, not a generic 'contact us' link, a real mechanism for a person to intervene in a specific decision.
  • Inventory every existing automation and AI agent against this list today, because the same transparency logic already underpins comparable regimes, the UK's Data (Use and Access) Act automated decision-making rules and Canada's AIDA and PIPEDA obligations, and regulators globally are converging on the same floor: transparency and a human override path are baseline requirements, not optional extras.

How AIBOOTSTRAPPER helps

The RAG-powered compliance engine we built for ComplyNexus exists for exactly this kind of problem: it continuously monitors regulatory change, maps new obligations to a client's actual controls, and surfaces gaps with a complete audit trail, the same '100% audit-ready traceability' a business now needs for every automated decision it makes about an Australian customer. The underlying discipline, log the decision, log the override, make the trail queryable, is what turns a looming deadline into routine documentation instead of a scramble in November.

If you're running AI agents or automated scoring logic that touch Australian customers and haven't mapped them against the new APP 1.7 to 1.9 obligations yet, book a call and we'll help you get audit-ready before 10 December 2026.

Want this done for you?

Book a free strategy call and we'll show you how to build and market your business with AI.

FAQ

Questions, answered

Everything you might want to know before we hop on a call.

The obligation under APP 1.7 to 1.9 of the Privacy Act 1988 commences on 10 December 2026. From that date, in-scope businesses must have their privacy policy updated to disclose the kinds of personal information and decisions involved in their automated decision-making.

No. It applies broadly to computer-based decision-making, which includes rule-based and deterministic automation, not only generative AI or machine learning models. Any system materially involved in a decision affecting a person's rights or interests can fall in scope.

The Privacy Act's existing enforcement powers, including OAIC investigations and penalties for non-compliance, apply to this obligation the same as other Australian Privacy Principle breaches. Given the OAIC has flagged this as an active enforcement priority, businesses that haven't updated their policies risk regulatory attention as soon as the obligation takes effect.

This transparency obligation is part of a first tranche of Privacy Act reforms; the Australian Government has already flagged further reforms addressing broader AI transparency and automated decision-making as a second tranche, so this deadline should be treated as a floor to build from, not the final compliance bar.

Keep reading

Let's talk

Ready to build and sell with AI?

Book a free 30 minute strategy call. We'll map the highest ROI AI move for your business, no pitch, just value.