An Australian insurer's legal team signs off on an AI agent that triages incoming claims, routing straightforward ones to auto-approval and flagging complex ones for a human adjuster. Legal's review focuses on the usual: data security, vendor contracts, a line in the privacy policy about 'using technology to process your information.' Nobody flags that from 10 December 2026, that line isn't enough, because a specific new transparency obligation under the Privacy Act 1988 requires the business to name, in its privacy policy, the actual kinds of personal information and the actual kinds of decisions the automated system is making about real customers.
What exactly changes under Australia's Privacy Act on 10 December 2026?
From that date, APP entities, businesses and agencies bound by the Australian Privacy Principles, that use personal information in automated decision-making with the potential to affect a person's rights or interests must disclose this specifically in their privacy policy: the kinds of personal information used, and the kinds of decisions made using automated decision-making. This comes from new provisions, APP 1.7 to 1.9, added by amendments to the Privacy Act 1988 that passed in November 2024, with the transparency obligation itself commencing on a fixed date rather than immediately.
The OAIC's own consultation page on guidance for transparency in automated decision-making confirms the regulator ran a formal consultation through mid-2026 and expects to publish detailed guidance around September 2026, three months before the obligation itself takes effect, which leaves a narrow window between knowing exactly what the regulator expects and having to already comply.
Which AI agents actually count as 'automated decision-making' under the amendment?
- Fraud detection systems that flag or block a transaction without a human reviewing it first.
- Client and customer onboarding agents that approve, reject or route an application.
- Insurance claims triage or assessment tools that determine payout eligibility or route a claim.
- Patient intake or triage assistants that influence clinical prioritization.
- Contract review agents that flag or clear terms as part of an approval decision.
- Customer support agents and personalization or recommendation engines that materially shape what a person is offered.
Does this only apply to AI and machine learning systems?
No, and this is the detail most teams miss. MinterEllison's analysis of the OAIC's consultation notes the amendment applies broadly to computer-based decision-making, which captures rule-based software and deterministic scoring logic just as much as it captures an LLM-based agent. A business can't treat this as an 'AI problem' scoped narrowly to generative AI tools and assume its older rules engines are exempt; if a computer is materially involved in a decision affecting someone's rights or interests, the disclosure obligation is in scope regardless of what kind of system is making the call.
That breadth is exactly why an audit now, mapping every existing automation, not only the newest AI agent, against this checklist matters more than waiting for the OAIC's final guidance to arrive in September.
What does an audit-ready compliance architecture look like before the deadline?
- Update the privacy policy now to name, in plain language, the categories of personal information used and the categories of decisions made via automated systems, don't wait for the OAIC's final guidance to start the drafting process, since legal review and stakeholder sign-off take longer than the remaining runway suggests.
- Log the input data, the model or rules-engine version, a confidence score where applicable, and whether a human overrode the automated outcome for every decision in scope, and retain those logs long enough to satisfy a regulator's request well after the fact.
- Build an actual human-override path into every workflow that makes an in-scope decision, not a generic 'contact us' link, a real mechanism for a person to intervene in a specific decision.
- Inventory every existing automation and AI agent against this list today, because the same transparency logic already underpins comparable regimes, the UK's Data (Use and Access) Act automated decision-making rules and Canada's AIDA and PIPEDA obligations, and regulators globally are converging on the same floor: transparency and a human override path are baseline requirements, not optional extras.
How AIBOOTSTRAPPER helps
The RAG-powered compliance engine we built for ComplyNexus exists for exactly this kind of problem: it continuously monitors regulatory change, maps new obligations to a client's actual controls, and surfaces gaps with a complete audit trail, the same '100% audit-ready traceability' a business now needs for every automated decision it makes about an Australian customer. The underlying discipline, log the decision, log the override, make the trail queryable, is what turns a looming deadline into routine documentation instead of a scramble in November.
If you're running AI agents or automated scoring logic that touch Australian customers and haven't mapped them against the new APP 1.7 to 1.9 obligations yet, book a call and we'll help you get audit-ready before 10 December 2026.
Want this done for you?
Book a free strategy call and we'll show you how to build and market your business with AI.
